<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: people]]></title>
    <link>http://securityratty.com/tag/people</link>
    <description></description>
    <pubDate>Wed, 26 Nov 2008 17:30:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The "A"]]></title>
      <link>http://securityratty.com/article/1b9ddda67145b0350bba4d9bf6a096a3</link>
      <guid>http://securityratty.com/article/1b9ddda67145b0350bba4d9bf6a096a3</guid>
      <description><![CDATA[Information Security sits in a strange area somewhere between Business and IT in a little space that really hasn't been properly defined. It is exciting here

Generally, most people in Information...]]></description>
      <content:encoded><![CDATA[Information Security sits in a strange area somewhere between Business and IT in a little space that really hasn't been properly defined. It is exciting here.<br /><br />Generally, most people in Information Security today did not start out as pure Information Security people, they evolved. And where they evolved from gives one a clue as to their mindset and how they see themselves.<br /><br />Some come from an Audit background and you'll recognise these guys from their love of lists and frameworks - they dream of Cobit controls and little boxes that are waiting for ticks. Somehow they have tons of documentation and they know it all and can find it all. They generally drive Volvo's and like order.<br /><br />But most InfoSec guys come from an IT background and it shows. I guess that, having said that, most hackers come from an IT background too. And it shows.<br /><br />Now, lets consider the C-I-A triangle thingum. Quick lesson for those who don't know it - there are three aspects of information that Information Security wishes to preserve - the <span style="font-weight: bold;">C</span>onfidentiality, the <span style="font-weight: bold;">I</span>ntegrity and the <span style="font-weight: bold;">A</span>vailability. From my experience, most IT people are governed by Availability - the "A". In fact, when an IT contract is drawn up - there is no SLI or SLC but there will always be an SLA. With very specific terms, measurements and penalties.<br /><br />If the Firewall crashes and has to be rebuilt. What will the IT manager be most interested in? The A - how fast can you get the traffic moving again?<br /><br />So we have tools to measure uptime in 99.999999999999999s and such and anything that can cause network downtime (or if the network is up and the services such as mail are down - same difference) is taken care of. Spam, worms, viruses etc.<br /><br />I guess that hackers (those that define what we do) are also IT background people. They seem to be more concerned with big-bang, widely deployed DoS attacks and stealing IT resources. At least, they used to be, until they discovered that they could make money from stealing information. Actually, I may be naive but I don't believe that the hackers we have today are the same as those we had in the past... I believe that we have a new generation of hackers - criminals who merely use the Internet to steal money because that it where the money is easiest to steal.<br /><br />The problem is that we were lucky in a way that our old tools worked against the threats that we had - firewalls, antiviruses, etc etc. They don't work against people breaking into our networks and stealing information. For that we need a new generation of Information Security people (or the old generation to update their game)...<br /><br />Here is a quick poll to see which generation you are in:<br /><br />1. What is the one piece of information on your network that your competitors would love to see?<br />2. What is the percentage of mails coming into your network that are spam?<br />3. What mail is going to competitors?<br />4. What is the process for someone to order a pencil?<br />5. What is a blog?<br />6. Who in your organisation uses facebook for business?<br />7. How many of your PCs have up-to-date antivirus?<br />8. What is the worst virus out at the moment?<br />9. Do you believe that your Firewall is configured correctly?<br /><br />The answers are as follows:<br />1. This is ESSENTIAL to know if you want to be in the next generation. And you can't guess this. You may think that it is something financial but most financial information can be guessed by your competitors anyhow. You may think it is a recipe or special way of doing something but any established company has had their recipe ripped off anyhow and can beat any new competitor by competitive pricing. It may be new product information. It may be staff information. It may be the CEO's contact list. Don't guess - find out.<br /><br />2. Who cares? Certainly not the CEO. Maybe the CIO. "We are saving you x amount of bandwidth and your users x amount of time" is nice but won't save the business from closing down due to data loss. Operationalise this and get on with your job.<br /><br />3. Good to know. I'm sure that if you told your CEO/CIO "Last week we detected 5 large emails going to our competitors from inside our R&amp;D department" you'd have his full attention.<br /><br />4. Good to know. Who does the ordering? Who does the okaying? Who does the paying? If you know all of this then you know how business works. And when things go wrong - you'll be able to help.<br /><br />5. And do you want your staff to use them? And if they do, what can they put on them? What are they puting on them?<br /><br />6. This is an interesting question because Facebook is usually an issue of "The A" (productivity). But it can be an issue of C and I.<br /><br />7. Who cares? Again, this is an operational issue. Viruses that jump onto your radar are usually ones that attack "the A" but its the ones that are pushing information out of your organisation that are sneaky enough not to have sgnatures and not to be discovered. You will have PCs without up-to-date antivirus and you will have viruses. The trick is not to let your information be stolen by viruses. Also, keep backups so if a PC does get wiped out - you can get the information back again (but this is an operational issue again).<br /><br />8. Trick question - the answer is - the one you don't know about. Old generation InfoSec guys can rattle off names of viruses that are all in the top 10 at the moment.. New generation viruses are targetted and usually do their worst before a pattern is out.<br /><br />9. Old generation answer - yes. New generation answer - who cares? Information flows all over including in and out of the Firewall. Firewalls also usually rely on port security but most everything runs on port 80 anyhow so the Firewall should be configured but it doesn't kep us safe - more work needs to be done for that.<br /><br />I find that it is not very easy to move from old generation to new generation InfoSec. The main difference is that old generation was very technical and appealed to the technical nature of computer geeks. The new generation is business oriented and requires more interaction with people, more meetings, more time with people. Ouch.<br /><br />There will always be a place for technical people in Information Security but as the tools mature and "just work" there is less demand. And a background in technology is very useful when the technical guys try to "BS" you.<br /><br />And "the A" is very important too. Protecting your network from being brought down. Protecting information from disappearing. Stopping viruses. Etc. But the new generation will need to consider "the I" and "the C" as well because the attacks against these and the importance of protecting information against disclosure or manipulation will increase.<br /><br />This post was done to add my voice to what Rich says so quickly and concisely in the <a href="http://securosis.com/2008/11/10/the-two-kinds-of-security-threats-and-how-they-affect-your-life/">securosis blog</a>.<img src="http://feeds.feedburner.com/~r/SecurityThoughts/~4/471338550" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 10:57:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/financial information">financial information</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/generation infosec guys">generation infosec guys</category>
      <category domain="http://securityratty.com/tag/infosec guys">infosec guys</category>
      <category domain="http://securityratty.com/tag/information security people">information security people</category>
      <category domain="http://securityratty.com/tag/guys">guys</category>
      <category domain="http://securityratty.com/tag/staff information">staff information</category>
      <category domain="http://securityratty.com/tag/technical guys">technical guys</category>
      <source url="http://feeds.feedburner.com/~r/SecurityThoughts/~3/471338550/a.html">The "A"</source>
    </item>
    <item>
      <title><![CDATA[Communications During Terrorist Attacks are Not Bad]]></title>
      <link>http://securityratty.com/article/e01f90607bd82b3c845f42de9a92f9b5</link>
      <guid>http://securityratty.com/article/e01f90607bd82b3c845f42de9a92f9b5</guid>
      <description><![CDATA[Twitter was a vital source of information in Mumbai: News on the Bombay attacks is breaking fast on Twitter with hundreds of people using the site to update others with first-hand accounts of the...]]></description>
      <content:encoded><![CDATA[<p>Twitter was a vital <a href="http://technology.timesonline.co.uk/tol/news/tech_and_web/article5245059.ece">source of information</a> in Mumbai:</p>

<blockquote>News on the Bombay attacks is breaking fast on Twitter with hundreds of people using the site to update others with first-hand accounts of the carnage. 

<p>The website has a stream of comments on the attacks which is being updated by the second, often by eye-witnesses and people in the city. Although the chatter cannot be verified immediately and often reflects the chaos on the streets, it is becoming the fastest source of information for those seeking unfiltered news from the scene.</blockquote></p>

<p>But we simply have to be smarter than this:</p>

<blockquote>In the past hour, people using Twitter reported that bombings and attacks were continuing, but none of these could be confirmed. Others gave details on different locations in which hostages were being held. 

<p>And this morning, Twitter users said that Indian authorities was asking users to stop updating the site for security reasons.</p>

<p>One person wrote: "Police reckon tweeters giving away strategic info to terrorists via Twitter".</blockquote></p>

<p><a href="http://stephensonstrategies.com/2008/11/26/us-officials-must-monitor-learn-from-use-of-web-20-in-mumbai/">Another link</a>:</p>

<blockquote>I can't stress enough: people can and will use these devices and apps in a terrorist attack, so it is imperative that officials start telling us what kind of information would be relevant from Twitter, Flickr, etc. (and, BTW, what shouldn't be spread: one Twitter user in Mumbai tweeted me that people were sending the exact location of people still in the hotels, and could tip off the terrorists) and that they begin to monitor these networks in disasters, terrorist attacks, etc.</blockquote>

<p>This fear is exactly backwards.  During a terrorist attack -- during any crisis situation, actually -- the one thing people can do is exchange information.  It helps people, calms people, and actually reduces the thing the terrorists are trying to achieve: terror.  Yes, there are specific movie-plot scenarios where certain public pronouncements might help the terrorists, but those are rare.  I would much rather err on the side of more information, more openness, and more communication.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=slTEO"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=slTEO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=BvXZO"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=BvXZO" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 09:02:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/calms people">calms people</category>
      <category domain="http://securityratty.com/tag/twitter user">twitter user</category>
      <category domain="http://securityratty.com/tag/twitter">twitter</category>
      <category domain="http://securityratty.com/tag/helps people">helps people</category>
      <category domain="http://securityratty.com/tag/terrorist attacks">terrorist attacks</category>
      <category domain="http://securityratty.com/tag/twitter users">twitter users</category>
      <category domain="http://securityratty.com/tag/exchange information">exchange information</category>
      <source url="http://www.schneier.com/blog/archives/2008/12/communications.html">Communications During Terrorist Attacks are Not Bad</source>
    </item>
    <item>
      <title><![CDATA[Lessons from Mumbai]]></title>
      <link>http://securityratty.com/article/ca74a145bde98eb6902487f29715eaa3</link>
      <guid>http://securityratty.com/article/ca74a145bde98eb6902487f29715eaa3</guid>
      <description><![CDATA[I'm still reading about the Mumbai terrorist attacks, and I expect it'll be a long time before we get a lot of the details. What we know is horrific, and my sympathy goes out to the survivors of the...]]></description>
      <content:encoded><![CDATA[<p>I'm still reading about the Mumbai terrorist attacks, and I expect it'll be a long time before we get a lot of the details.  What we know is horrific, and my sympathy goes out to the survivors of the dead (and the injured, who often seem to get ignored as people focus on death tolls).  Without discounting the awfulness of the events, I have some initial observations:</p>

<ul><li>Low-tech is very effective.  <a href="http://www.schneier.com/essay-087.html">Movie-plot threats</a> -- terrorists with crop dusters, terrorists with biological agents, terrorists targeting our water supplies -- might be what people worry about, but a bunch of trained (we don't really know yet what sort of training they had, but it's clear that they <a href="http://www.news.com.au/couriermail/story/0,23739,24726093-954,00.html">had some</a>) men with guns and grenades is all they needed.

<p><li>At the same time, the attacks were surprisingly ineffective.  I can't find exact numbers, but it seems there were about 18 terrorists.  The latest toll is 195 dead, 235 wounded.  That's 11 dead, 13 wounded, per terrorist.  As horrible as the reality is, that's much less than you might have thought if you imagined the movie in your head.  Reality is <a href="http://www.pebbleandavalanche.com/weblog/2008/11/30/blog-20081130T1857">different</a> from the movies.</p>

<p><li>Even so, terrorism is rare.  If a bunch of men with guns and grenades is all they really need, then why isn't this sort of terrorism more common?  Why not in the U.S., where it's easy to get hold of weapons?  It's because terrorism is very, very rare.</p>

<p><li>Specific countermeasures don't help against these attacks.  None of the high-priced countermeasures that defend against specific tactics and specific targets made, or would have made, any difference: photo ID checks, confiscating liquids at airports, fingerprinting foreigners at the border, bag screening on public transportation, anything.  Even<a href="http://www.upi.com/Top_News/2008/11/29/Executive_says_Taj_hotel_warned_of_attack/UPI-97361228007685/">metal detectors and threat warnings</a> didn't do any good:</p>

<blockquote>"If I look at what we had, which all of us complained about, it could not have stopped what took place," he told CNN. "It's ironic that we did have such a warning, and we did have some measures."

<p>He said people were told to park away from the entrance and had to go through a metal detector. But he said the attackers came through a back entrance.</p>

<p>"They knew what they were doing, and they did not go through the front. All of our arrangements are in the front," he said.</blockquote></ul></p>

<p>If there's any lesson in these attacks, it's not to focus too much on the specifics of the attacks.  Of course, that's not the way we're programmed to think.  We <a href="http://www.schneier.com/essay-171.html">respond to stories</a> and not analysis.  I don't mean to be sympathetic; this tendency is human and these deaths are really tragic.  But eighteen armed people intent on killing lots of innocents will be able to do just that, and last-line-of-defense countermeasures won't be able to stop them.  Intelligence, investigation, and emergency response.  We have to find and stop the terrorists before they attack, and deal with the aftermath of the attacks we don't stop.  There really is no other way, and I hope that we don't let the tragedy lead us into unwise decisions about how to deal with terrorism.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=4dGOO"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=4dGOO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=qnl9O"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=qnl9O" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 05:03:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mumbai terrorist attacks">mumbai terrorist attacks</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/armed people intent">armed people intent</category>
      <category domain="http://securityratty.com/tag/people focus">people focus</category>
      <category domain="http://securityratty.com/tag/focus">focus</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/terrorism">terrorism</category>
      <category domain="http://securityratty.com/tag/terrorist">terrorist</category>
      <source url="http://www.schneier.com/blog/archives/2008/12/lessons_from_mu.html">Lessons from Mumbai</source>
    </item>
    <item>
      <title><![CDATA[Stampede Death at Wal-Mart]]></title>
      <link>http://securityratty.com/article/a5436ad4dbabae1cfd63a3bda7bfbafd</link>
      <guid>http://securityratty.com/article/a5436ad4dbabae1cfd63a3bda7bfbafd</guid>
      <description><![CDATA[The death of a Wal-Mart employee on Black Friday in New York should never have been allowed to happen

The Police are said to be reviewing tapes to see if they can identify who was responsible for...]]></description>
      <content:encoded><![CDATA[The death of a Wal-Mart employee on Black Friday in New York should never have been allowed to happen.<br /><span id="fullpost"><br />The Police are said to be reviewing tapes to see if they can identify who was responsible for trampling the poor man to death.  What will that achieve?  Obviously it was not done on purpose.  The findings are bound to result in an "accidental death" determination. <br /></span><br />Getting back to; who is responsible?  I think that is quite clear.  Wal-Mart has to accept responsibility.  UNLESS...they really did hire an outside security company and the employees of that company did such a poor job organizing that mob of "door busters", that they lost control of the situation.<br /><br />One thing is a given.  The family of the employee who lost his life is bound to bring a civil law suit against Wal-Mart.  If I were them, the first thing I would look to find out would be who(if anyone)was providing security on Thanksgiving night outside of the front door?  <br /><br />Unfortunately, many clients do not take the function of security very seriously and they delegate the responsibility to those with no security training or experience.  We have consulted for clients at arenas and found that ordinary ushers will be given a fluorescent vest or jacket with "SECURITY" written on the back and asked to provide security.  This is a libility claim waiting to be filed.<br /><br />If Wal-Mart did in fact outsource their security to an outside company, was the company allowed to provide an adequate number of officers to ensure that shoppers lined up in an orderly fashion?  One security officer to a couple of hundred people is another liability suit waiting to be filed.<br /><br />Next, they should be looking at the training that the security officers (Wal-Mart better hope that shelve stockers were not given the task)receieved.  Because it was Thanksgiving night, there is the possibility that the company couldn't get anybody else to work and used untrained and inexperienced personnel.  If that turns out to be the case, hopefully the company was legal and had adequate insurance coverage.<br /><br />Whatever happens regarding a civil law suit, one thing will remain unchanged.  A man lost his life in an incident that should have been prevented.  It is obvious that not everything was done to ensure the safety of the shoppers who traditonally lined up to get the best bargains when the store opened on "Black Friday".<br /><br />Whether it was Wal-Mart or the security company who may have been hired to prevent this very incident from happening - somebody failed to do their job. Whichever one it was, they should step up to the plate and apologize to the grieving family for letting them down.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 01:12:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/provide">provide</category>
      <category domain="http://securityratty.com/tag/provide security">provide security</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security company">security company</category>
      <category domain="http://securityratty.com/tag/wal-mart">wal-mart</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/security officers">security officers</category>
      <category domain="http://securityratty.com/tag/wal-mart employee">wal-mart employee</category>
      <category domain="http://securityratty.com/tag/death">death</category>
      <source url="http://www.thebulletproofblog.com/2008/11/stampede-death-at-walmart.html">Stampede Death at Wal-Mart</source>
    </item>
    <item>
      <title><![CDATA[Chairman Tata Surprised by Tricky Terrorists]]></title>
      <link>http://securityratty.com/article/7b4520b092d5aedad18be187c5cd3069</link>
      <guid>http://securityratty.com/article/7b4520b092d5aedad18be187c5cd3069</guid>
      <description><![CDATA[Chairman Rata Tata, whose company owns the Taj hotel in Mumbai, gave a frank and honest interview to CNN. I would imagine that the Tata Group's PR people and General Counsel are scrambling at the...]]></description>
      <content:encoded><![CDATA[Chairman Rata Tata, whose company owns the Taj hotel in Mumbai, gave a frank and honest interview to CNN.  I would imagine that the Tata Group's PR people and General Counsel are scrambling at the moment trying to do as much damage control as possible. <br /><span id="fullpost"><br />The sad part of this unfolding story is the feeling one gets that the terrible loss of life at the hotel may have been prevented or at least mitigated had proper security measures been implemented and if the security that had been in place prior to the attack had not been removed.  <br /></span><br />One eye witness who stayed at the hotel a week before the terrorist assault spoke about metal detectors and baggage being checked.  The same witness then went on to say that those security measures had been removed within the last week, allowing people to enter without being checked.<br /><br />The most surprising news to surface must be the Chairman's comments regarding the terrible event. Unbelievably, he actually said; "They knew what they were doing and they did not go through the front.  All of our arrangements were on the front entrance".<br /><br />Who is Tata's security advisor, a kitchen worker?  Actually, he might have been better off if that were the case since the terrorists entered the hotel through the rear kitchen door.  ANNOUNCEMENT TO ALL CHAIRMEN AND CEO's; Terrorists are Tricky.  That is their job.  They are watching your businesses and will do the opposite to what you expect.  <br /><br />In the case of the TAJ HOTEL, you made it easy for them.  Did nobody in Mumbai ever stop to think that a bad person can go through the back door?  It is one thing for a cafe in a pedestrian area to be attacked as anyone can walk right by or walk through the front and open fire, but how can a major landmark that attracts Western vistors drop their security measures AFTER they have received terrorist alert warnings that the hotel may be the target of terrorsit attacks?  <br /><br />I don't know if it was the case with the Taj Hotel, but cutting corners where security is concerned is common place in corporate culture.  Security is often seen as a necessary evil and usually the first department to experience budgetary cutbacks.  It is very difficult to convince some clients that nothing happening is really a good thing and that by cutting out security may open the door to evil.<br /><br />This appears to have been the case with the Taj.  There is no doubt that the terrorists had conducted hundreds of hours of surveillance in and around Mumbai.  Was it a coincidence that the attack occurred the week after security measures had been removed?  What might have been the result if security had remained tight (if you could call watching the front entrance and disregarding the back as "tight security")?  Maybe the terrorists would have held back another month or two...maybe in that time they would have been detected...<br /><br />One thing is for certain, places like the Taj Hotel have to get serious about security.  Mr. Tata's claim that; "If I look at what we had...it could not have stopped what took place", must be replaced by more progressive, proactive thinking.  If the Tata Group had spent an adequate amount of funding on ensuring that a strict security policy was in force - if only for the period in question - then they might not now be facing a 5 Billion Rupee reconstruction bill.  Who knows how high the civil suits against the Taj will run when compensation and punitive costs are calculated.         <br /><br />Kudos though to Chairman Tata for at least recognizing that the Indian authorities may not be able to handle the situation on their own.  "These attacks underscore the need for Law Enforcement to seek outside expertise for training, equipment and strategic operations", he said.<br /><br />We agree Mr. Tata.  We also hope that you will recognize the need for the Tata Group to seek similar outside expertise to assist you with your security planning and training.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Sun, 30 Nov 2008 22:29:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security measures">security measures</category>
      <category domain="http://securityratty.com/tag/proper security measures">proper security measures</category>
      <category domain="http://securityratty.com/tag/tata">tata</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security advisor">security advisor</category>
      <category domain="http://securityratty.com/tag/chairman tata">chairman tata</category>
      <category domain="http://securityratty.com/tag/chairman rata tata">chairman rata tata</category>
      <category domain="http://securityratty.com/tag/taj">taj</category>
      <category domain="http://securityratty.com/tag/taj hotel">taj hotel</category>
      <source url="http://www.thebulletproofblog.com/2008/11/chairman-tata-surprised-by-tricky.html">Chairman Tata Surprised by Tricky Terrorists</source>
    </item>
    <item>
      <title><![CDATA[Tips for staying safe online this Holiday season]]></title>
      <link>http://securityratty.com/article/4601cb0e0df5f980983616dff3fecc59</link>
      <guid>http://securityratty.com/article/4601cb0e0df5f980983616dff3fecc59</guid>
      <description><![CDATA[Great article by Mr Walling. Take the time read the tips and maybe you wont become a statistic this season


clipped from www.marketwatch.com

Walling Datas Top Ten Safety Tips for Online Shopping


...]]></description>
      <content:encoded><![CDATA[<div > Great article by Mr Walling.<br/>Take the time read the tips and maybe you wont become a statistic this season </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/5CC9381E-01B3-4581-A29F-B6C7D9C85A8E/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/a9a2ac45-d36e-42ed-8102-6fd92fd5847c/5CC9381E-01B3-4581-A29F-B6C7D9C85A8E/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.marketwatch.com/news/story/Walling-Datas-Top-Ten-Safety/story.aspx?guid=%7B877022E1-B408-495D-A4F6-C49F6002D0AE%7D" href="http://www.marketwatch.com/news/story/Walling-Datas-Top-Ten-Safety/story.aspx?guid=%7B877022E1-B408-495D-A4F6-C49F6002D0AE%7D" style="font-size: 11px;">www.marketwatch.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.marketwatch.com/news/story/Walling-Datas-Top-Ten-Safety/story.aspx?guid=%7B877022E1-B408-495D-A4F6-C49F6002D0AE%7D -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Walling Data&#8217;s Top Ten Safety Tips for Online Shopping</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.marketwatch.com/news/story/Walling-Datas-Top-Ten-Safety/story.aspx?guid=%7B877022E1-B408-495D-A4F6-C49F6002D0AE%7D --><DIV class="p"><br />
            &#8220;The Internet is safe if you follow basic, fundamental rules of<br />
      using a computer safely,&#8221; says Luke Walling, Founder and President of Walling<br />
      Data, one of the largest distributors of online security products in<br />
      the country. &#8220;Many people think of their computer much like<br />
      they would an appliance, such as a microwave or stereo that behaves in a<br />
      predictable pre-programmed way. But, in reality computers<br />
      are dynamic devices that evolve dramatically with the installation of<br />
      each new program. It&#8217;s important to remember that viruses<br />
      and spyware are programs as well.&#8221;<br />
</DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/5CC9381E-01B3-4581-A29F-B6C7D9C85A8E/blog/" title="blog or email this clip"><img src="http://content6.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_281108043701"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=281108043701&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=281108043701&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=281108043701&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_281108043701" /></a></P>]]></content:encoded>
      <pubDate>Fri, 28 Nov 2008 13:37:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/online">online</category>
      <category domain="http://securityratty.com/tag/tips">tips</category>
      <category domain="http://securityratty.com/tag/online security products">online security products</category>
      <category domain="http://securityratty.com/tag/computer safely">computer safely</category>
      <category domain="http://securityratty.com/tag/safety tips">safety tips</category>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/dynamic devices">dynamic devices</category>
      <category domain="http://securityratty.com/tag/datas top">datas top</category>
      <category domain="http://securityratty.com/tag/safe">safe</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=665">Tips for staying safe online this Holiday season</source>
    </item>
    <item>
      <title><![CDATA[Mumbai terrorism, worm warning, holiday woe]]></title>
      <link>http://securityratty.com/article/ebe54e54bbcef669e418933a9402da10</link>
      <guid>http://securityratty.com/article/ebe54e54bbcef669e418933a9402da10</guid>
      <description><![CDATA[A wave of coordinated terrorist attacks across Mumbai late Wednesday dominated the news this week, with bloggers and people using Twitter helping to get information to families and friends of those...]]></description>
      <content:encoded><![CDATA[A wave of coordinated terrorist attacks across Mumbai late Wednesday dominated the news this week, with bloggers and people using Twitter helping to get information to families and friends of those affected. Multinational technology companies are not expected to change their business strategies as a consequence of the stunning attacks, which targeted westerners.]]></content:encoded>
      <pubDate>Thu, 27 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/multinational technology companies">multinational technology companies</category>
      <category domain="http://securityratty.com/tag/terrorist attacks">terrorist attacks</category>
      <category domain="http://securityratty.com/tag/business strategies">business strategies</category>
      <category domain="http://securityratty.com/tag/mumbai">mumbai</category>
      <category domain="http://securityratty.com/tag/consequence">consequence</category>
      <category domain="http://securityratty.com/tag/friends">friends</category>
      <category domain="http://securityratty.com/tag/twitter">twitter</category>
      <category domain="http://securityratty.com/tag/bloggers">bloggers</category>
      <source url="http://www.networkworld.com/news/2008/112808-mumbai-terrorism-worm-warning-holiday.html?fsrc=rss-security">Mumbai terrorism, worm warning, holiday woe</source>
    </item>
    <item>
      <title><![CDATA[Mayhem in Mumbai]]></title>
      <link>http://securityratty.com/article/b7902ee86f589ca527ebb734d591a745</link>
      <guid>http://securityratty.com/article/b7902ee86f589ca527ebb734d591a745</guid>
      <description><![CDATA[The total number of casualties rise in the financial capital of India after terrorists attack multiple locations

The latest figures suggest that at least 100 people have been killed and as many as...]]></description>
      <content:encoded><![CDATA[The total number of casualties rise in the financial capital of India after terrorists attack multiple locations.<br /><span id="fullpost"><br />The latest figures suggest that at least 100 people have been killed and as many as 900 injured.  Radio and television reporters are saying that it has all the hallmarks of an Al-Qaeda attack.  Locations included a railway station, a cinema, the Taj Hotel, and another very popular restaurant. <br /></span><br />It appears as if the terrorists singled out Westerners as they are reported to have taken British and American tourists hostages and brought them up to the 18th floor of the hotel.  This evening the hotel is on fire and the fate of the hostages is still unknown.<br /><br />The good news for some, is that they were able to escape form the hotel in the confusion.  It appears that the terrorists could have numbered dozens of heavily armed men.  This is definitely not a random attack but a well planned and executed operation aimed at causing mass casualties amnd hitting India's financial markets in much the same way as Wall Street was attacked on 9/11.<br /><br />We do not hear that much about India's terrorist problems in the West but I was made aware of it when I was invited to India to speak on Security matters this time last year.  I have since that time made clients and potenital clients aware of the  security situation.  <br /><br />There has been much outsourcing to India and many U.S. businesses are sending personnel over there as a result.  Those who can afford to have their own professional security protectors should consider that option very carefully.  It could very well turn out being more of a necessity than a luxury in these dangerous times.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Thu, 27 Nov 2008 02:48:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/india">india</category>
      <category domain="http://securityratty.com/tag/potenital clients aware">potenital clients aware</category>
      <category domain="http://securityratty.com/tag/taj hotel">taj hotel</category>
      <category domain="http://securityratty.com/tag/hotel">hotel</category>
      <category domain="http://securityratty.com/tag/clients">clients</category>
      <category domain="http://securityratty.com/tag/hostages">hostages</category>
      <category domain="http://securityratty.com/tag/mass casualties amnd">mass casualties amnd</category>
      <category domain="http://securityratty.com/tag/american tourists hostages">american tourists hostages</category>
      <category domain="http://securityratty.com/tag/aware">aware</category>
      <source url="http://www.thebulletproofblog.com/2008/11/mayhem-in-mumbai.html">Mayhem in Mumbai</source>
    </item>
    <item>
      <title><![CDATA[In Mumbai, bloggers and Twitter offer help to relatives]]></title>
      <link>http://securityratty.com/article/af66bfff259eea6672f58a47a634c5c8</link>
      <guid>http://securityratty.com/article/af66bfff259eea6672f58a47a634c5c8</guid>
      <description><![CDATA[Bloggers pitched in offering information and other help to people worldwide as Indian police and commandos battled it out Thursday with armed terrorists in two top hotels and a residential complex in...]]></description>
      <content:encoded><![CDATA[Bloggers pitched in offering information and other help to people worldwide as Indian police and commandos battled it out Thursday with armed terrorists in two top hotels and a residential complex in south Mumbai.]]></content:encoded>
      <pubDate>Wed, 26 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/armed terrorists">armed terrorists</category>
      <category domain="http://securityratty.com/tag/bloggers">bloggers</category>
      <category domain="http://securityratty.com/tag/south mumbai">south mumbai</category>
      <category domain="http://securityratty.com/tag/indian police">indian police</category>
      <category domain="http://securityratty.com/tag/top hotels">top hotels</category>
      <category domain="http://securityratty.com/tag/people worldwide">people worldwide</category>
      <category domain="http://securityratty.com/tag/residential complex">residential complex</category>
      <category domain="http://securityratty.com/tag/commandos">commandos</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <source url="http://www.networkworld.com/news/2008/112708-in-mumbai-bloggers-and-twitter.html?fsrc=rss-security">In Mumbai, bloggers and Twitter offer help to relatives</source>
    </item>
    <item>
      <title><![CDATA[Fun PCI FAQ - Good Reading]]></title>
      <link>http://securityratty.com/article/da094186d77259c94c369b90c9ddd6d5</link>
      <guid>http://securityratty.com/article/da094186d77259c94c369b90c9ddd6d5</guid>
      <description><![CDATA[Check out this cool PCI FAQ here , created by Andrew Plato. He reminds people about a few of the common &quot;PCI misconceptions&quot; (like, &quot;when is the PCI deadline? - Yesterday&quot;) and key facts (like, &quot;Do...]]></description>
      <content:encoded><![CDATA[Check out this cool PCI FAQ <a href="http://searchsecuritychannel.techtarget.com/generic/0,295582,sid97_gci1337635,00.html?track=NL-347&amp;ad=676695&amp;Offer=ISMpromo1125&amp;asrc=EM_UTS_5122985&amp;uid=6200574">here</a>, created by Andrew Plato. He reminds people about a few of the common "PCI misconceptions" (like, "when is the PCI deadline? - Yesterday") and key facts (like, <span class="a3">"Do organizations using third-party processors have to be PCI-compliant? - Yes</span>")<br /><br />Finally, I also love, love, love <a href="http://searchsecuritychannel.techtarget.com/generic/0,295582,sid97_gci1337635,00.html?track=NL-347&amp;ad=676695&amp;Offer=ISMpromo1125&amp;asrc=EM_UTS_5122985&amp;uid=6200574">his reminder</a> that there are no "PCI -compliant products" (unlike some <a href="http://www.networkworld.com/news/2007/121007-nss-labs-pci.html">assclowns</a> here think)<br /><br /><span class="a3"><b>"Q: What technologies are considered PCI-compliant?</b><br /><br /><span style="font-weight: bold;">A: There is no such thing as a PCI-compliant product</span>. The PCI standard does not certify products. Some products will help with PCI compliance, but there is no single product or group of products that will ensure complete PCI compliance. </span>"<br /><br /><a href="http://searchsecuritychannel.techtarget.com/generic/0,295582,sid97_gci1337635,00.html?track=NL-347&amp;ad=676695&amp;Offer=ISMpromo1125&amp;asrc=EM_UTS_5122985&amp;uid=6200574">Read it!</a><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=5hFkN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=5hFkN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=QrnuN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=QrnuN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=2eb9N"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=2eb9N" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/466951707" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 26 Nov 2008 17:30:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci -compliant products">pci -compliant products</category>
      <category domain="http://securityratty.com/tag/products">products</category>
      <category domain="http://securityratty.com/tag/pci-compliant product">pci-compliant product</category>
      <category domain="http://securityratty.com/tag/pci-compliant">pci-compliant</category>
      <category domain="http://securityratty.com/tag/cool pci faq">cool pci faq</category>
      <category domain="http://securityratty.com/tag/love">love</category>
      <category domain="http://securityratty.com/tag/pci compliance">pci compliance</category>
      <category domain="http://securityratty.com/tag/third-party processors">third-party processors</category>
      <category domain="http://securityratty.com/tag/single product">single product</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/466951707/fun-pci-faq-good-reading.html">Fun PCI FAQ - Good Reading</source>
    </item>
  </channel>
</rss>
