<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: phone]]></title>
    <link>http://securityratty.com/tag/phone</link>
    <description></description>
    <pubDate>Thu, 14 Aug 2008 06:32:51 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Anti-theft Protocols]]></title>
      <link>http://securityratty.com/article/2a0b13fdcf3d76640c70ce857f0644c4</link>
      <guid>http://securityratty.com/article/2a0b13fdcf3d76640c70ce857f0644c4</guid>
      <description><![CDATA[At last Fridays Security Group meeting, we talked about security protocols that are intended to deter or reduce the consquences of theft, and how they go wrong
Examples include
GSM mobile phones have...]]></description>
      <content:encoded><![CDATA[<p>At last Friday&#8217;s Security Group meeting, we talked about security protocols that are intended to deter or reduce the consquences of theft, and how they go wrong.</p>
<p>Examples include:</p>
<ul>
<li>GSM mobile phones have an identifier for the phone (separate from the identifier for the user) that can be blacklisted when the phone is stolen.</li>
<li>Some car radios will stop working when the battery is disconnected, and only start working again when a numeric code is entered. This is intended to deter theft of the radio.</li>
<li>In Windows Vista, Bitlocker can be used to encrypt files. One of  the intended applications for this is that if someone steals your laptop, it will be difficult for them to gain access to your encrypted files.</li>
</ul>
<p>Ross told a story of what happened when he needed to disconnect the battery on his car: the radio stopped working, and the code he had been given to reactivate it didn&#8217;t work - it was the wrong code.<br />
Ross argues that these reactivation codes are unecessary, because other measures taken by the car manufacturers - such as making radios non-standard sizes, and hence not refittable in other car models - have made them redundant.</p>
<p>I described how the motherboard on a laptop had needed to be replaced recently. The motherboard contains the TPM chip, which contains the encryption keys needed to decrypt files protected with Bitlocker. If you replace the motherboard, the files on your hard disk will become unreadable, even if the disk is physically OK. Domain-joined Vista machines can be configured so that a sysadmin somewhere within your organization is able to recover the keys when this happens.</p>
<p>Both of these situations suffer from classic usability problems: the recovery procedures are invoked rarely (so users may not know what they&#8217;re supposed to do), and, if your system is configured incorrectly, you only find out when it is <i>too late</i>: you key in the code to your radio and it remains a doorstop; the admin you hoped was escrowing your keys turns out not to have the private key corresponding to the public key you were encrypting under (or, more subtly: the person with the authority to ask for your laptop&#8217;s key to be recovered is not you, because the appropriate admin has the <i>wrong name</i> for the laptop&#8217;s owner in their database).</p>
<p>I also described what happens when an XBox 360 is stolen. When you buy XBox downloadable content, you buy <i>two</i> licenses: one that&#8217;s valid on any XBox, as long as you&#8217;re logged in to XBox live; and one that&#8217;s valid on just your XBox, regardless of who&#8217;s logged in. If a burglar steals your Xbox, and you buy a new one, you need to get another license of the <i>second</i> type (for all the other people in your household who make use of it). The software makes this awkward, because it knows that you already have a license of the <i>first</i> type, and assumes that you couldn&#8217;t possibly want to buy it again. The work-around is to get a new email address, a new Microsoft Live Account, and a new Gamer Tag, and use these to repurchase the license. You can&#8217;t just change the gamertag, because XBox live doesn&#8217;t let the same Microsoft Live account have two gamertags. And yes, I know, your buddies in the MMORPG you were playing know you by your gamertag, so you don&#8217;t want to change it.</p>
]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 12:18:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/xbox">xbox</category>
      <category domain="http://securityratty.com/tag/xbox downloadable content">xbox downloadable content</category>
      <category domain="http://securityratty.com/tag/wrong code">wrong code</category>
      <category domain="http://securityratty.com/tag/xbox live">xbox live</category>
      <category domain="http://securityratty.com/tag/wrong">wrong</category>
      <category domain="http://securityratty.com/tag/car">car</category>
      <category domain="http://securityratty.com/tag/car radios">car radios</category>
      <category domain="http://securityratty.com/tag/files">files</category>
      <category domain="http://securityratty.com/tag/microsoft live account">microsoft live account</category>
      <source url="http://www.lightbluetouchpaper.org/2008/09/03/anti-theft-protocols/">Anti-theft Protocols</source>
    </item>
    <item>
      <title><![CDATA[Sucking Data off of Cell Phones]]></title>
      <link>http://securityratty.com/article/4cbc1761652d9271a9311931f47b85b5</link>
      <guid>http://securityratty.com/article/4cbc1761652d9271a9311931f47b85b5</guid>
      <description><![CDATA[Don't give someone your phone unless you trust them: There is a new electronic capture device that has been developed primarily for law enforcement, surveillance, and intelligence operations that is...]]></description>
      <content:encoded><![CDATA[<p>Don't <a href="http://news.cnet.com/8301-1009_3-10028589-83.html?tag=newsEditorsPicksArea.0">give someone your phone</a> unless you trust them:</p>

<blockquote>There is a new electronic capture device that has been developed primarily for law enforcement, surveillance, and intelligence operations that is also available to the public. It is called the Cellular Seizure Investigation Stick, or CSI Stick as a clever acronym. It is manufactured by a company called Paraben, and is a self-contained module about the size of a BIC lighter. It plugs directly into most Motorola and Samsung cell phones to capture all data that they contain. More phones will be added to the list, including many from Nokia, RIM, LG and others, in the next generation, to be released shortly.</blockquote>

<p>Another <a href="http://www.physorg.com/news139460365.html">news article</a>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=FDP4FL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=FDP4FL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=WZ1UtL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=WZ1UtL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 02:03:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/phones">phones</category>
      <category domain="http://securityratty.com/tag/capture">capture</category>
      <category domain="http://securityratty.com/tag/electronic capture device">electronic capture device</category>
      <category domain="http://securityratty.com/tag/samsung cell phones">samsung cell phones</category>
      <category domain="http://securityratty.com/tag/news article">news article</category>
      <category domain="http://securityratty.com/tag/law enforcement">law enforcement</category>
      <category domain="http://securityratty.com/tag/intelligence operations">intelligence operations</category>
      <category domain="http://securityratty.com/tag/csi stick">csi stick</category>
      <category domain="http://securityratty.com/tag/clever acronym">clever acronym</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/sucking_data_of.html">Sucking Data off of Cell Phones</source>
    </item>
    <item>
      <title><![CDATA[A Costly Crush]]></title>
      <link>http://securityratty.com/article/cafa2263c602a0dce807786d68e28098</link>
      <guid>http://securityratty.com/article/cafa2263c602a0dce807786d68e28098</guid>
      <description><![CDATA[I've seen a few blog posts over the last couple of days, with people complaining about an application on Facebook charging them crazy amounts of money. Certainly, there's a lot of angry Facebook users...]]></description>
      <content:encoded><![CDATA[
        I've seen a few <a href="http://www.sokhodom.com/2008-09-02-bad-facebook-application-lead-to-heavy-phone-bill/">blog posts</a> over the last couple of days, with people complaining about an application on Facebook charging them crazy amounts of money. Certainly, there's a lot of angry Facebook users out there:<br /><br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/crushtracker01.html" onclick="window.open('http://blog.spywareguide.com/images/crushtracker01.html','popup','width=387,height=448,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/crushtracker0-thumb-287x332.gif" alt="crushtracker0.gif" class="mt-image-none" style="" height="332" width="287" /></a></span>
<br />Click to Enlarge<br /></div><br />Some more complaints? Sure, I can do that:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="hugecrush1.gif" src="http://blog.spywareguide.com/images/hugecrush1.gif" class="mt-image-none" style="" height="347" width="309" /></span></div><br /><br /><div align="left">There are many, many more like the above comments out there. One slight problem with all of this is that the complaints are scattered across a whole range of different Crush application forums - in short, they're <i>all</i> being blamed, but they can't <i>all</i> be doing this, can they? What's the alternative, though?<br /><br />A short while ago, I wrote about <a href="http://blog.spywareguide.com/2008/07/interesting-advert-placements.html">deceptive advert placements</a> with regards another facebook application. It seems we have a similar situation here, where an "enterprising" Ad network is placing Facebook-style buttons onto installer pages and hoping people will be fooled. As it turns out, it seems to be working. While attempting to install one randomly selected Crush application, I noticed the following advert at the top of the installer splash (highlighted in red):<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/hugecrush3.html" onclick="window.open('http://blog.spywareguide.com/images/hugecrush3.html','popup','width=660,height=320,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/hugecrush3-thumb-360x174.gif" alt="hugecrush3.gif" class="mt-image-none" style="" height="174" width="360" /></a></span><br />Click to Enlarge<br /></div><br />It's easy to imagine a regular Facebook user thinking this is part of the application install and clicking "Ok". Do that, and you're taken to a site called Amazingchat(dot)net that throws up a fake message regarding you having "7 New Crush Messages" (and uses geolocational technology to point a targeted message your way). If you look like you're in the UK, you'll see this:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/hugecrush41.html" onclick="window.open('http://blog.spywareguide.com/images/hugecrush41.html','popup','width=662,height=404,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/hugecrush4-thumb-362x220.gif" alt="hugecrush4.gif" class="mt-image-none" style="" height="220" width="362" /></a></span><br />Click to Enlarge<br /></div><br />Wow, FOUR of my (fake and non-existent) messages are from Sheffield! How about if I look like I'm in the States? You've guessed it....<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="hugecrush5.gif" src="http://blog.spywareguide.com/images/hugecrush5.gif" class="mt-image-none" style="" height="42" width="318" /></span></div>
<br /><br />Windy City, here I come!<br /><br />Not. It's looking promising so far, though. If we can just go to the next screen and see something utterly useless advertised in exchange for lots of money....<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/hugecrush666.html" onclick="window.open('http://blog.spywareguide.com/images/hugecrush666.html','popup','width=552,height=371,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/hugecrush666-thumb-352x236.gif" alt="hugecrush666.gif" class="mt-image-none" style="" height="236" width="352" /></a></span><br />Click to Enlarge<br /></div><br />Horoscopes for only ?9 / $15 a week? WOW!<br /><br />Also, there go your savings.<br /><br />Could this be the site at the heart of so many complaints? Well, let's quickly check who runs it...<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="hugecrush7.gif" src="http://blog.spywareguide.com/images/hugecrush7.gif" class="mt-image-none" style="" height="140" width="587" /></span><br /><br />"Sms-helpdesk", eh? I do believe I've seen a <a href="http://www.facebook.com/topic.php?uid=4874299673&amp;topic=3908">long thread</a> concerning people having issues with large bills for phone messages. Indeed, a rep from sms-helpdesk actually appears to be posting there:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="hugecrush8.gif" src="http://blog.spywareguide.com/images/hugecrush8.gif" class="mt-image-none" style="" height="479" width="370" /></span></div><br /><br />Shame it seems some people can't even get through to the supposed helpline. Perhaps "Denise" would be better off tackling the deceptive placement of adverts made to look like installer buttons, not to mention non-existent crush messages based around geolocational targeting?<br /><br />Just a thought...<br /></div>
        
    ]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 11:24:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/application">application</category>
      <category domain="http://securityratty.com/tag/facebook application">facebook application</category>
      <category domain="http://securityratty.com/tag/crush application">crush application</category>
      <category domain="http://securityratty.com/tag/facebook">facebook</category>
      <category domain="http://securityratty.com/tag/application install">application install</category>
      <category domain="http://securityratty.com/tag/regular facebook user">regular facebook user</category>
      <category domain="http://securityratty.com/tag/crush application forums">crush application forums</category>
      <category domain="http://securityratty.com/tag/angry facebook users">angry facebook users</category>
      <category domain="http://securityratty.com/tag/crush messages">crush messages</category>
      <source url="http://blog.spywareguide.com/2008/09/a-costly-crush.html">A Costly Crush</source>
    </item>
    <item>
      <title><![CDATA[While I Was Out: Compendium of the Last Week's News]]></title>
      <link>http://securityratty.com/article/9b2e491a24c669b08b8cfdf0d0df0b47</link>
      <guid>http://securityratty.com/article/9b2e491a24c669b08b8cfdf0d0df0b47</guid>
      <description><![CDATA[You wouldn't listen, but continued to generate products, news stories, and analysis about wireless networking in my absence: Here's the run down of the last week or so's Wi-Fi and wireless stories....]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><strong>You wouldn't listen, but continued to generate products, news stories, and analysis about wireless networking in my absence:</strong> Here's the run down of the last week or so's Wi-Fi and wireless stories. (Yes, I enjoyed my time off.)</p>

<p><a href="http://www.informationweek.com/news/services/data/showArticle.jhtml?articleID=210200880"><strong>Fourth US airline to go Wi-Fi:</strong></a> Aircell says they have a fourth airline--after American, Delta, and Virgin America--on board for its in-flight Wi-Fi service. The aerial broadband provider's latest partner will be announced soon. Aircell's service went live in 15 American Airlines planes two weeks ago, and there's been a surprising lack of reporting from regular travelers or journalists since the big splash at the launch.</p>

<p><a href="http://seattlepi.nwsource.com/business/376308_software25.html"><strong>Microsoft, two universities research methods for better Wi-Fi handoff for vehicles:</strong></a> The researchers developed a method they call Vi-Fi, writes the Seattle Post-Intelligencer's Todd Bishop, which allows a system to maintain connections with several base stations at once, using a primary access point for traffic until a discontinuity is predicted or encountered. This allows seamless handoffs and continuous voice conversations. </p>

<p><a href="http://www.nytimes.com/2008/08/24/technology/24digi.html?_r=1&oref=slogin"><strong>Speaking of autos and Wi-Fi, concerns raised about Chrysler's in-car Wi-Fi option:</strong></a> Randall Stross wrote nearly two weeks ago in The New York Times about the problem of distraction. With the Internet at your fingertips, can you restrain yourself? The only problem with the humorous and accurate analysis is that millions of business travelers have 3G access via laptop cards already, so you'd think we'd already be seeing the bad effects of automotive area networks.</p>

<p><a href="http://www.omaha.com/index.php?u_page=2798&u_sid=10415031"><strong>A Wi-Fi booster can't post availability signs on highway:</strong></a> The Nebraska town of Louisville has free Wi-Fi downtown, and wanted to post "Visitor Wi-Fi" on a highway sign as another amenity. The state highway department has a policy that doesn't allow the promotion of Wi-Fi, because they believe they'd be inundated. A resident who runs a local Internet firm installed his own signs on the highway; the roads department removed them; he remounted them; they were removed again. The idea of zoning and mounting a billboard apparently hasn't come to the city officials' minds (or perhaps they're prohibited).</p>

<p><a href="http://www.lisburntoday.co.uk/news/PRIMARY-PULLS-PLUG-ON-WIFI.4435678.jp"><strong>The folks spreading misinformation about Wi-Fi health effects cause Ulster school to disable network:</strong></a> I can understand why non-technical folks might think that Wi-Fi has been proven to be unsafe, given the kind of information that's available on the Internet about wireless safety. While there are ongoing studies about the safety of cellular signals--and I'm convinced at this point there's no increased risk to an adult's health by using a cell phone--there is no specific and credible research linked to Wi-Fi, which broadcasts signals at a far lower level than a cell phone, most of the time in most uses.</p>

<p><a href="http://blog.seattlepi.nwsource.com/thebigblog/archives/147374.asp"><strong>Washington state shuts down rest-area Wi-Fi:</strong></a> The $3 for 15 minutes, $7 per day, or $30 per month Wi-Fi service at 28 of Washington's 42 rest areas has been turned off after a year for lack of use. Figures. The fees charged by Parsons and Road Connect aren't unreasonable for a nationally scoped plan, but are ridiculous for limited use. States should either bite the bullet and offer these service for free, partner with national roaming operators who can resell service into large networks of business travelers, or use ads to support the service. Highways in remote areas can typically pick up cell data networks, and ongoing costs should be minimal to operate such networks.</p>

<p><a href="http://www.techworld.com/news/index.cfm?RSS&NewsID=103501"><strong>IEEE approves fast-roaming standard, 802.11r:</strong></a> This new standard is designed to improve the handoff of devices between base stations. This is accomplished in part by allowing base stations to communicate security and quality of service information so that a VoIP over WLAN phone can immediately reassociate without the delay of authentication and other handshaking.</p>

<p><a href="http://www.marketwatch.com/news/story/freefi-networks-releases-figures-wi-fi/story.aspx?guid={5252EF0E-2563-42B7-8A95-2F893580E6F6}&dist=hppr"><strong>Denver airport sees 7,000 connections on a single day last week due to Democratic National Convention:</strong></a> FreeFi released the usage figures recently to show how their service is operating. The network started with about 600 daily users when the switchover from fee to free happened 10 months ago, and now carries about 3,500 daily connections.</p>

<p><a href="http://www.centredaily.com/living/travel/story/804003.html"><strong>Coffee Bean & Tea Leaf goes free:</strong></a> The chain of about 700 cafes will have free Wi-Fi installed by now in all its company-owned stores (about 300).</p>]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 10:55:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/free wi-fi">free wi-fi</category>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/in-car wi-fi option">in-car wi-fi option</category>
      <category domain="http://securityratty.com/tag/wi-fi handoff">wi-fi handoff</category>
      <category domain="http://securityratty.com/tag/free wi-fi downtown">free wi-fi downtown</category>
      <category domain="http://securityratty.com/tag/month wi-fi service">month wi-fi service</category>
      <category domain="http://securityratty.com/tag/rest-area wi-fi">rest-area wi-fi</category>
      <category domain="http://securityratty.com/tag/wi-fi booster">wi-fi booster</category>
      <category domain="http://securityratty.com/tag/in-flight wi-fi service">in-flight wi-fi service</category>
      <source url="http://wifinetnews.com/archives/008428.html">While I Was Out: Compendium of the Last Week's News</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #82: Asterisk & Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...]]></title>
      <link>http://securityratty.com/article/ab8e0e22ebb1851ff664c3be0a3baa7d</link>
      <guid>http://securityratty.com/article/ab8e0e22ebb1851ff664c3be0a3baa7d</guid>
      <description><![CDATA[Synopsis: Blue Box #82: Asterisk &amp; Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more
Welcome to Blue Box: The VoIP Security Podcast...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #82: Asterisk & Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #82, a 47-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3">Download the show here</a> (MP3, 21MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on June 21, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>
<li>Programming notes:
	<ul>
	<li>Note about the production team &#8211; new special editions coming soon.</li>
		<li>Note about URLs for the media files</li>
	</ul>
<li><a href="http://downloads.digium.com/pub/security/AST-2008-008.html">AST-2008-008 &#8211; Remote Crash Vulnerability in <span class="caps">SIP</span> channel driver when run in pedantic mode</a></li>
		<li><a href="http://downloads.digium.com/pub/security/AST-2008-009.html">AST-2008-009 &#8211; Remote crash vulnerability in ooh323 channel driver</a></li>
		<li><a href="http://www.skype.com/security/skype-sb-2008-003.html">Skype-SB-2008-003 &#8211; Skype File <span class="caps">URI </span>Security Bypass Code Execution Vulnerability</a></li>

<p><li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002677.html">New version of SIPvicious</a></li><br />
		<li><a href="http://code.google.com/p/sipflanker/">Sipflanker &#8211; tool to find <span class="caps">SIP</span> devices with web GUIs</a></li><br />
<ul><br />
	<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002678.html">Discussion about VoIP Steganography</a> (pointed to by Craig Bowser)</li><br />
		<li>Geeks Are Sexy: <a href="http://www.geeksaresexy.net/2008/06/02/new-technology-hides-messages-in-internet-phone-calls/">New Technology Hides Messages in Internet Phone Calls</a> &#8211; and Switched: <a href="http://www.switched.com/2008/06/03/spies-to-use-skype-to-send-secret-messages/">Spies to Use Skype to Send Secret Messages?</a> &#8211; and <a href="http://www.theregister.co.uk/2008/06/03/voip_steganography/">The Register</a></li><br />
	<li>FierceVoIP: <a href="http://www.fiercevoip.com/story/voip-security-and-circle-trust/2008-05-06">VoIP Security and the Circle of Trust</a> pointing to Government Computer News: <a href="http://www.gcn.com/print/27_10/46209-1.html">Careful with the call</a></li><br />
	<br />
	<li>The Register: <a href="http://www.theregister.co.uk/2008/06/03/low_tech_phishing_scams/">&#8216;Untraceable&#8217; phone fraudsters eye your credit card</a></li><br />
	<br />
	<li>SearchUnifiedCommunications: <a href="http://searchunifiedcommunications.techtarget.com/news/article/0,289142,sid186_gci1315878,00.html">Disaster and recovery in the VoIP/IPT <span class="caps">RFP</span></a></li><br />
	<br />
	<li>Secure Computing: <a href="http://www.securecomputing.net.au/News/114221,voice-tools-under-enemy-fire.aspx">Voice tools under enemy fire</a></li><br />
	<br />
	<li>VNUnet: <a href="http://www.vnunet.com/computing/analysis/2217608/voip-application-worth-paying-4021945">A good VoIP application is worth paying for</a></li><br />
	<br />
	<li><a href="http://www.ofcom.org.uk/media/news/2007/12/nr_22071205">Ofcom confirms VoIP providers must provide access to 999 and 112</a></li><br />
	<br />
	<li><a href="http://blog.voipshield.com/">Bogdan Materna&#8217;s blog is live</a></li></p>

<p><li>Realtime Community: <a href="http://www.realtime-websecurity.com/ESMWSv3.asp">The Essentials Series:<br />Messaging and Web Security<br />Volume <span class="caps">III</span></a></li><br />
		<li>Global Knowledge: <a href="http://images.globalknowledge.com/wwwimages/seminars/voipsec/player.html">On-Demand Webinar on VoIP Security</a> (hat tip to <a href="http://tfl09.blogspot.com/2008/06/voip-security-web-seminar.html">Thomas Lee</a> )</li><br />
		<li>SearchSecurity: <a href="http://searchsecurity.techtarget.com.au/articles/24883-The-threats-to-telcos-and-how-they-can-repel-them">The threats to telcos and how they can repel them</a></li><br />
		<li>TMCnet: <a href="http://www.tmcnet.com/news/2008/06/02/3476832.htm">Balancing Issues in World of Telepresence</a></li><br />
		<li>Network World: <a href="http://www.networkworld.com/buyersguides/guide.php?cat=898361">VoIP Security Buying Guide</a></li></p>

<p><li><a href="http://www.fiercewireless.com/press-releases/nortel-and-securelogix-team-deliver-voice-security-and-management-solutions-worldwide">Nortel and SecureLogix Team to Deliver Voice Security and Management Solutions to Worldwide Enterprise Market</a> (see also <a href="http://www.fiercevoip.com/story/nortel-adds-voip-security-thru-securelogix/2008-06-02?utm_medium=rss&#38;utm_source=rss&#38;cmp-id=OTC-RSS-FV0">this analysis</a> )</li><br />
		<li><a href="http://www.earthtimes.org/articles/show/sipera-partner-network-arms-resellers-with-comprehensive-uc-and-voip-security,428703.shtml">Sipera Partner Network Arms Resellers With Comprehensive UC and VoIP Security</a></li><br />
		<li><a href="http://www.webitpr.com/release_detail.asp?ReleaseID=8791">VIVOphone Deploys Paradial RealTunnel?? to Solve <span class="caps">NAT </span>Traversal Challenges for VoIP Services</a></li><br />
		<li><a href="http://www.networkworld.com/newsletters/converg/2008/061608converge1.html">Audiocodes joins the ranks of <span class="caps">SBC</span> vendors</a></li><br />
<li>SearchSecurity: <a href="http://searchnetworking.techtarget.com.au/articles/24906-Securing-the-new-network">Securing the new network</a> (interesting because it shows the layers of a defense in depth)</li><br />
<li>The Hindu Business News: <a href="http://www.thehindubusinessline.com/ew/2008/06/16/stories/2008061650050201.htm">Serious about Security</a></li><br />
<li>Shows:<br />
<ul><br />
	<li><a href="http://www.iptelephonyuniversity.com/home.html">IP Telephony University</a> &#8211; June 23-24, Alexandria, VA</li><br />
		<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002675.html">IPTComm 2008</a> &#8211; July 1-2, Heidelberg, Germany</li><br />
		<li><a href="http://www.thelasthope.org/index.php">The Last H.O.P.E.</a> &#8211; July 18-20, New York</li><br />
		<li><a href="http://www.speechtek.com/">SpeechTek</a> &#8211; August 18-20, New York</li><br />
	</ul><br />
<li><a href="http://article.gmane.org/gmane.comp.voip.security.voipsa/2562">Call for papers for Hack-in-the-box Malaysia</a> ends June 30th</li><br />
	<br />
	<li><a href="http://www.room362.com/archives/192-ShmooCon-2008-Videos-Hit-the-Shelves.html">SchmooCon 2008 videos available &#8211; several dealing with VoIP</a></li></p>

<p><li>No comments this week.<br />
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>47:09 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>
]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 16:53:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip security">voip security</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security tools">voip security tools</category>
      <category domain="http://securityratty.com/tag/voip steganography">voip steganography</category>
      <category domain="http://securityratty.com/tag/voip services">voip services</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/skype security vulnerabilities">skype security vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <source url="http://www.blueboxpodcast.com/2008/08/blue-box-82-ast.html">Blue Box #82: Asterisk &amp; Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #82: Asterisk & Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...]]></title>
      <link>http://securityratty.com/article/48c1a58b9d39348008877ad191ffcfea</link>
      <guid>http://securityratty.com/article/48c1a58b9d39348008877ad191ffcfea</guid>
      <description><![CDATA[Synopsis: Blue Box #82: Asterisk &amp; Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more
Welcome to Blue Box: The VoIP Security Podcast...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #82: Asterisk & Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #82, a 47-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3">Download the show here</a> (MP3, 21MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on June 21, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-082-2008-06-21.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>
<li>Programming notes:
	<ul>
	<li>Note about the production team &#8211; new special editions coming soon.</li>
		<li>Note about URLs for the media files</li>
	</ul>
<li><a href="http://downloads.digium.com/pub/security/AST-2008-008.html">AST-2008-008 &#8211; Remote Crash Vulnerability in <span class="caps">SIP</span> channel driver when run in pedantic mode</a></li>
		<li><a href="http://downloads.digium.com/pub/security/AST-2008-009.html">AST-2008-009 &#8211; Remote crash vulnerability in ooh323 channel driver</a></li>
		<li><a href="http://www.skype.com/security/skype-sb-2008-003.html">Skype-SB-2008-003 &#8211; Skype File <span class="caps">URI </span>Security Bypass Code Execution Vulnerability</a></li>

<p><li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002677.html">New version of SIPvicious</a></li><br />
		<li><a href="http://code.google.com/p/sipflanker/">Sipflanker &#8211; tool to find <span class="caps">SIP</span> devices with web GUIs</a></li><br />
<ul><br />
	<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002678.html">Discussion about VoIP Steganography</a> (pointed to by Craig Bowser)</li><br />
		<li>Geeks Are Sexy: <a href="http://www.geeksaresexy.net/2008/06/02/new-technology-hides-messages-in-internet-phone-calls/">New Technology Hides Messages in Internet Phone Calls</a> &#8211; and Switched: <a href="http://www.switched.com/2008/06/03/spies-to-use-skype-to-send-secret-messages/">Spies to Use Skype to Send Secret Messages?</a> &#8211; and <a href="http://www.theregister.co.uk/2008/06/03/voip_steganography/">The Register</a></li><br />
	<li>FierceVoIP: <a href="http://www.fiercevoip.com/story/voip-security-and-circle-trust/2008-05-06">VoIP Security and the Circle of Trust</a> pointing to Government Computer News: <a href="http://www.gcn.com/print/27_10/46209-1.html">Careful with the call</a></li><br />
	<br />
	<li>The Register: <a href="http://www.theregister.co.uk/2008/06/03/low_tech_phishing_scams/">&#8216;Untraceable&#8217; phone fraudsters eye your credit card</a></li><br />
	<br />
	<li>SearchUnifiedCommunications: <a href="http://searchunifiedcommunications.techtarget.com/news/article/0,289142,sid186_gci1315878,00.html">Disaster and recovery in the VoIP/IPT <span class="caps">RFP</span></a></li><br />
	<br />
	<li>Secure Computing: <a href="http://www.securecomputing.net.au/News/114221,voice-tools-under-enemy-fire.aspx">Voice tools under enemy fire</a></li><br />
	<br />
	<li>VNUnet: <a href="http://www.vnunet.com/computing/analysis/2217608/voip-application-worth-paying-4021945">A good VoIP application is worth paying for</a></li><br />
	<br />
	<li><a href="http://www.ofcom.org.uk/media/news/2007/12/nr_22071205">Ofcom confirms VoIP providers must provide access to 999 and 112</a></li><br />
	<br />
	<li><a href="http://blog.voipshield.com/">Bogdan Materna&#8217;s blog is live</a></li></p>

<p><li>Realtime Community: <a href="http://www.realtime-websecurity.com/ESMWSv3.asp">The Essentials Series:<br />Messaging and Web Security<br />Volume <span class="caps">III</span></a></li><br />
		<li>Global Knowledge: <a href="http://images.globalknowledge.com/wwwimages/seminars/voipsec/player.html">On-Demand Webinar on VoIP Security</a> (hat tip to <a href="http://tfl09.blogspot.com/2008/06/voip-security-web-seminar.html">Thomas Lee</a> )</li><br />
		<li>SearchSecurity: <a href="http://searchsecurity.techtarget.com.au/articles/24883-The-threats-to-telcos-and-how-they-can-repel-them">The threats to telcos and how they can repel them</a></li><br />
		<li>TMCnet: <a href="http://www.tmcnet.com/news/2008/06/02/3476832.htm">Balancing Issues in World of Telepresence</a></li><br />
		<li>Network World: <a href="http://www.networkworld.com/buyersguides/guide.php?cat=898361">VoIP Security Buying Guide</a></li></p>

<p><li><a href="http://www.fiercewireless.com/press-releases/nortel-and-securelogix-team-deliver-voice-security-and-management-solutions-worldwide">Nortel and SecureLogix Team to Deliver Voice Security and Management Solutions to Worldwide Enterprise Market</a> (see also <a href="http://www.fiercevoip.com/story/nortel-adds-voip-security-thru-securelogix/2008-06-02?utm_medium=rss&#38;utm_source=rss&#38;cmp-id=OTC-RSS-FV0">this analysis</a> )</li><br />
		<li><a href="http://www.earthtimes.org/articles/show/sipera-partner-network-arms-resellers-with-comprehensive-uc-and-voip-security,428703.shtml">Sipera Partner Network Arms Resellers With Comprehensive UC and VoIP Security</a></li><br />
		<li><a href="http://www.webitpr.com/release_detail.asp?ReleaseID=8791">VIVOphone Deploys Paradial RealTunnel® to Solve <span class="caps">NAT </span>Traversal Challenges for VoIP Services</a></li><br />
		<li><a href="http://www.networkworld.com/newsletters/converg/2008/061608converge1.html">Audiocodes joins the ranks of <span class="caps">SBC</span> vendors</a></li><br />
<li>SearchSecurity: <a href="http://searchnetworking.techtarget.com.au/articles/24906-Securing-the-new-network">Securing the new network</a> (interesting because it shows the layers of a defense in depth)</li><br />
<li>The Hindu Business News: <a href="http://www.thehindubusinessline.com/ew/2008/06/16/stories/2008061650050201.htm">Serious about Security</a></li><br />
<li>Shows:<br />
<ul><br />
	<li><a href="http://www.iptelephonyuniversity.com/home.html">IP Telephony University</a> &#8211; June 23-24, Alexandria, VA</li><br />
		<li><a href="http://voipsa.org/pipermail/voipsec_voipsa.org/2008-June/002675.html">IPTComm 2008</a> &#8211; July 1-2, Heidelberg, Germany</li><br />
		<li><a href="http://www.thelasthope.org/index.php">The Last H.O.P.E.</a> &#8211; July 18-20, New York</li><br />
		<li><a href="http://www.speechtek.com/">SpeechTek</a> &#8211; August 18-20, New York</li><br />
	</ul><br />
<li><a href="http://article.gmane.org/gmane.comp.voip.security.voipsa/2562">Call for papers for Hack-in-the-box Malaysia</a> ends June 30th</li><br />
	<br />
	<li><a href="http://www.room362.com/archives/192-ShmooCon-2008-Videos-Hit-the-Shelves.html">SchmooCon 2008 videos available &#8211; several dealing with VoIP</a></li></p>

<p><li>No comments this week.<br />
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>47:09 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=lWcQZE"><img src="http://feeds.feedburner.com/~a/BlueBox?i=lWcQZE" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=pYLEpK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=pYLEpK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=rcmyeK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=rcmyeK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=FcteyK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=FcteyK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=g4KpjK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=g4KpjK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=XvHGuk"><img src="http://feeds.feedburner.com/~f/BlueBox?i=XvHGuk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=WQc3oK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=WQc3oK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/376657116" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 15:53:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip security">voip security</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security tools">voip security tools</category>
      <category domain="http://securityratty.com/tag/voip steganography">voip steganography</category>
      <category domain="http://securityratty.com/tag/voip services">voip services</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/skype security vulnerabilities">skype security vulnerabilities</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/376657116/blue-box-82-ast.html">Blue Box #82: Asterisk &amp; Skype security vulnerabilities, new VoIP security tools, VoIP steganography, VoIP security news and much, much more...</source>
    </item>
    <item>
      <title><![CDATA[12 Sly Web Tricks That Put You in Control]]></title>
      <link>http://securityratty.com/article/3ca42354edb274e3324c681fb243deb4</link>
      <guid>http://securityratty.com/article/3ca42354edb274e3324c681fb243deb4</guid>
      <description><![CDATA[So it's Friday afternoon, the weekend is just around the corner, and you're up to no good. Rather than waste your time turning monitors upside down around the office, why not update your tech arsenal?...]]></description>
      <content:encoded><![CDATA[So it's Friday afternoon, the weekend is just around the corner, and you're up to no good. Rather than waste your time turning monitors upside down around the office, why not update your tech arsenal? If you have a computer or cell phone on hand, you're more than ready to beef up your weapons and spy kit with these 12 sly tricks. We'll teach you why and how (and with what) to do them, and tell you how well you can expect them to work. And you will forget where you heard this information...]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monitors upside">monitors upside</category>
      <category domain="http://securityratty.com/tag/sly tricks">sly tricks</category>
      <category domain="http://securityratty.com/tag/tech arsenal">tech arsenal</category>
      <category domain="http://securityratty.com/tag/friday afternoon">friday afternoon</category>
      <category domain="http://securityratty.com/tag/cell phone">cell phone</category>
      <category domain="http://securityratty.com/tag/spy kit">spy kit</category>
      <category domain="http://securityratty.com/tag/weekend">weekend</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/beef">beef</category>
      <source url="http://www.networkworld.com/news/2008/082708-12-sly-web-tricks-that.html?fsrc=rss-security">12 Sly Web Tricks That Put You in Control</source>
    </item>
    <item>
      <title><![CDATA[Open Letter to Verizon Wireless]]></title>
      <link>http://securityratty.com/article/33861048df9fa12f13bd8d46690d0a5b</link>
      <guid>http://securityratty.com/article/33861048df9fa12f13bd8d46690d0a5b</guid>
      <description><![CDATA[After receiving no support from agents at the Verizon Wireless store or by agents on the phone, I decided to write them and make it an open letter. Its no secret that Verizon has a great network, but...]]></description>
      <content:encoded><![CDATA[<P><FONT size=2><FONT face=Verdana>After receiving no support from agents at the Verizon Wireless store or by agents on the phone, I decided to write them and make it an open letter.<SPAN>&nbsp; </SPAN>It&#8217;s no secret that Verizon has a great network, but it&#8217;s also no secret that their phone selection stinks.<SPAN>&nbsp; </SPAN>I don&#8217;t want to leave them and am hoping that whatever little bad press I can cause will encourage them to resolve the issue.<SPAN>&nbsp; </SPAN>If not, I&#8217;m tapping out.<SPAN>&nbsp; </SPAN>For 3 years I have hated my phone and loved their network.<SPAN>&nbsp; </SPAN>I&#8217;m ready to feel mediocre about both.<SPAN>&nbsp; </SPAN>Here it goes: </FONT></FONT>
<P><FONT size=2><FONT face=Verdana>I am currently without a phone and would appreciate a speedy reply. </FONT></FONT>
<P><FONT size=2><FONT face=Verdana>I have been a Verizon Wireless customer for over 5 years and my monthly bill easily averages over $200 during that time frame.<SPAN>&nbsp; </SPAN>While I love your network, I have been completely unsatisfied by your selection of phones.<SPAN>&nbsp; </SPAN>It is a stretch to say that my last phone worked&#8212;it had a feature called a battery that allowed me to switch from the car charger to my office charger without dying.<SPAN>&nbsp; </SPAN>And I waited&#8212;under duress&#8212;until I was allowed to purchase a new phone with the discount. </FONT></FONT>
<P><FONT size=2><FONT face=Verdana>My current phone has a wonderful battery life, but this is the 4th time the charger has snapped off in the phone.<SPAN>&nbsp; </SPAN>The phone is fine, but I keep paying $30 for new chargers.<SPAN>&nbsp; </SPAN>I refuse to purchase another or wait until February when I will be eligible for a new phone.<SPAN>&nbsp; </SPAN>You sold a phone with a design flaw, and I&#8217;m not even asking for a refund or a free phone.<SPAN>&nbsp; </SPAN>Just allow me to take a chance on a new one at the 2 year contract renewal rate.<SPAN>&nbsp; </SPAN></FONT></FONT>
<P><FONT size=2><FONT face=Verdana><SPAN></SPAN></FONT></FONT><FONT size=2><FONT face=Verdana>If not, I will gladly pay the early termination fee and leave Verizon.<SPAN>&nbsp; </SPAN>On general principle, I will spend more money canceling my account with you than I would likely receive as a discount on a new phone.<SPAN>&nbsp; </SPAN>As a customer, I consider it unacceptable that you sell inferior phones and leave me with no recourse. </FONT></FONT>
<P><FONT size=2><FONT face=Verdana>The first time I waited haplessly to become eligible for a new phone.<SPAN>&nbsp; </SPAN>I will not suffer a second time.<SPAN>&nbsp; </SPAN>If you don&#8217;t like the fact that you will end up losing money by allowing me to purchase a new phone early, I suggest you take it up your vendors who supply you with awful products.<SPAN>&nbsp; </SPAN>I can promise you that we will both lose more money if you don&#8217;t. </FONT></FONT>
<P><FONT size=2><FONT face=Verdana>Sincerely, </FONT></FONT>
<P><FONT face=Verdana size=2>Eric Marvets</FONT></P><img src ="http://marvets.com/blog/aggbug/12205.aspx" width = "1" height = "1" />]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 11:43:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/phone workedit">phone workedit</category>
      <category domain="http://securityratty.com/tag/free phone">free phone</category>
      <category domain="http://securityratty.com/tag/current phone">current phone</category>
      <category domain="http://securityratty.com/tag/verizon">verizon</category>
      <category domain="http://securityratty.com/tag/phone selection stinks">phone selection stinks</category>
      <category domain="http://securityratty.com/tag/verizon wireless store">verizon wireless store</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/verizon wireless customer">verizon wireless customer</category>
      <source url="http://marvets.com/blog/archive/2008/08/25/12205.aspx">Open Letter to Verizon Wireless</source>
    </item>
    <item>
      <title><![CDATA[Kids with Cell Phones in Emergencies]]></title>
      <link>http://securityratty.com/article/cfaf0428c49f446db4722e74309138c9</link>
      <guid>http://securityratty.com/article/cfaf0428c49f446db4722e74309138c9</guid>
      <description><![CDATA[In the middle of a sensationalist article about risks to children and how giving them cell phones can help, there's at least one person who gets it. Since the 1999 Columbine High School shootings and...]]></description>
      <content:encoded><![CDATA[<p>In the middle of a <a href="http://www.cnn.com/2008/TECH/ptech/08/11/cellphones.kids/index.html">sensationalist article</a> about risks to children and how giving them cell phones can help, there's at least one person who gets it.</p>

<blockquote>Since the 1999 Columbine High School shootings and the 9/11 terrorist attacks, many parents feel better having a way to contact their children. But hundreds of students on cell phones during an emergency can cause problems for responders.

<p>"There's a huge difference between feeling safer and being safer," says Kenneth Trump, president of National School Safety and Security Services.</p>

<p>According to Trump, students' cell phone use during emergencies can do three things: increase the spread of rumors about the situation, expedite parental traffic at a scene that needs to be controlled and accelerate the overload of cell-phone systems in the area.</p>

<p>Tom Hautton, an attorney for the National School Board Association, said that cell phones in schools also can lead to classroom distractions, text-message cheating and inappropriate photographs and videos being spread around campus.</blockquote></p>

<p>We are just naturally inclined to make irrational security decisions when it comes to our children.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=U1TUKK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=U1TUKK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=6SGplK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=6SGplK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 08:20:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cell phones">cell phones</category>
      <category domain="http://securityratty.com/tag/irrational security decisions">irrational security decisions</category>
      <category domain="http://securityratty.com/tag/trump">trump</category>
      <category domain="http://securityratty.com/tag/expedite parental traffic">expedite parental traffic</category>
      <category domain="http://securityratty.com/tag/kenneth trump">kenneth trump</category>
      <category domain="http://securityratty.com/tag/national school safety">national school safety</category>
      <category domain="http://securityratty.com/tag/huge difference">huge difference</category>
      <category domain="http://securityratty.com/tag/cell phone">cell phone</category>
      <category domain="http://securityratty.com/tag/terrorist attacks">terrorist attacks</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/kids_with_cell.html">Kids with Cell Phones in Emergencies</source>
    </item>
    <item>
      <title><![CDATA[Wee-Fi: Meraki Modifies, Drops Standard; Tempe's Phoenix?; Remote Wake, Wi-Fi Need Not Apply]]></title>
      <link>http://securityratty.com/article/a930349b033e6f56c6098e0b152daddf</link>
      <guid>http://securityratty.com/article/a930349b033e6f56c6098e0b152daddf</guid>
      <description><![CDATA[Meraki reworks product line, drops new sales of community flavor: The cheap mesh router company has mutated slightly once again. The partly-Google-backed firm founded by MIT RoofNet &quot;graduates&quot; built...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://meraki.com/"><strong>Meraki reworks product line, drops new sales of community flavor:</strong></a> The cheap mesh router company has mutated slightly once again. The partly-Google-backed firm founded by MIT RoofNet "graduates" built the company on the notion that they could sell $50 routers that could mesh with each other, and use a robust central management system they developed. Over time, the $50 price didn't hold up for commercial networks of scale. Last October, the <a href="http://wifinetnews.com/archives/007973.html"><strong>company mishandled a change</strong></a> in its business model when they abruptly announced a $100 increase in price for newly purchased nodes under their Meraki Pro level for any network that wanted to control whether or not ads appeared, have user accounts, and charge for service. (They eventually <a href="http://wifinetnews.com/archives/007979.html"><strong>recovered, apologized, and reworked</strong></a> some of the transition details.) <img src="http://wifinetnews.com//images/2008/meraki_indoor.jpg" alt="meraki_indoor.jpg" border="0" width="175" height="111" align="right" />The company continued to offer a $50 indoor and $100 outdoor Standard level nodes for networks that required ads and had other limits. As of a few days ago, Standard is dead, and the Meraki mini has been upgraded to the <a href="http://meraki.com/products_services/hardware/indoor/"><strong>Meraki Indoor</strong></a> ($150). The Indoor has signal strength LEDs on the side for better help in placing units, an internal antenna, and better resilience against power fluctuations. The company <a href="http://meraki.com/support/faq/"><strong>explains its move</strong></a> in eliminating Standard by noting that most customers moved to Pro. It's not precisely the end of idealism (nor did that happen last October), as Meraki is still one of the major commercial mesh vendors, and their products are still vastly easier and a fraction of the cost of higher-end competitors.<br clear="all"></p>

<p><a href="http://www.eastvalleytribune.com/story/123037"><strong>New life for dead Tempe network?</strong></a> Another firm has expressed interest in buying the pennies on the dollar assets that remain of the former Kite Networks installation in Tempe from the firm that financed the venture as long as they can negotiate a new, more favorable deal with the city for mounting and removal rights. CTC, Inc., which the East Valley Tribune reports runs networks in the Kansas City, Mo., area, thinks there's an opportunity. The article notes that reception problems were due in part to the prevalence of stucco in Tempe, common in the southwest. Stucco walls layer plaster or other materials on a wire mesh for strength that turns a house into a bit of an accidental <a href="http://en.wikipedia.org/wiki/Faraday_cage"><strong>Faraday cage</strong></a>, partially shielding the home from electromagnetic radiation. (Could I go so far to say that Tempe's network could be a phoenix? Ouch.)</p>

<p><a href="http://www.usatoday.com/tech/products/2008-08-14-intel-wake-up-pcs_N.htm"><strong>Wake up, you darn computer:</strong></a> Intel's new Remote Wake motherboards won't work with Wi-Fi, it's important to note. The feature, announced today, will let an incoming VoIP call (the articles all say "phone call over the Internet") to wake a computer, as long as the call comes from a particular source. Of course, the standard SIP protocol for VoIP doesn't have the kind of security and integrity that would allow this; Intel has to overcome the problem with network address translation that renders most computer unreachable from outside the local network without a separate service like GoToMyPC or LogMeIn; and it will only work for computers connected via Ethernet to a local network, because Wi-Fi is off when a computer sleeps, while Ethernet can remain lightly active. I don't have the protocol details yet, but there's long been a <a href="http://en.wikipedia.org/wiki/Wake-on-LAN"><strong>Wake on LAN protocol</strong></a> that required support in a router, operating system, and Ethernet card; Intel may be leveraging this.</p>]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 06:32:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/meraki">meraki</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/network address translation">network address translation</category>
      <category domain="http://securityratty.com/tag/dead tempe network">dead tempe network</category>
      <category domain="http://securityratty.com/tag/dead">dead</category>
      <category domain="http://securityratty.com/tag/tempe">tempe</category>
      <category domain="http://securityratty.com/tag/standard">standard</category>
      <category domain="http://securityratty.com/tag/meraki indoor">meraki indoor</category>
      <category domain="http://securityratty.com/tag/meraki mini">meraki mini</category>
      <source url="http://wifinetnews.com/archives/008420.html">Wee-Fi: Meraki Modifies, Drops Standard; Tempe's Phoenix?; Remote Wake, Wi-Fi Need Not Apply</source>
    </item>
  </channel>
</rss>
