<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: pretty]]></title>
    <link>http://securityratty.com/tag/pretty</link>
    <description></description>
    <pubDate>Thu, 14 Aug 2008 16:01:06 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[ASCII Art Spam]]></title>
      <link>http://securityratty.com/article/49c86c75eefe5a4e5a516c983562397c</link>
      <guid>http://securityratty.com/article/49c86c75eefe5a4e5a516c983562397c</guid>
      <description><![CDATA[I recently had a chat with Stephen Shankland over at CNET regarding the weird and wacky world of ASCII Art Spam . It's been around for some time now, and every now and again there's a little surge...]]></description>
      <content:encoded><![CDATA[
        I recently had a chat with Stephen Shankland over at CNET regarding the weird and wacky world of <a href="http://news.cnet.com/8301-1023_3-10025917-93.html">ASCII Art Spam</a>. It's been around for some time now, and every now and again there's a little surge (currently most of it seems to be coming out of Korea &amp; China) before dying down again.<br /><br />Of course, it has an element of visual appeal to it in some cases:<br /><br /><div class="flickr-frame">	<a href="http://www.flickr.com/photos/petecooper/2759424270/" title="photo sharing"><img src="http://farm4.static.flickr.com/3109/2759424270_7a76511520.jpg" class="flickr-photo" alt="" /></a><br />	<font class="flickr-caption"><a href="http://www.flickr.com/photos/petecooper/2759424270/">A bowl of  spammy noodles</a>, originally uploaded by <a href="http://www.flickr.com/people/petecooper/">pragmatic_pete</a>.</font><br /><br />They're pretty cool noodles, however you look at it. The biggest problem (for the spammers, anyway) continues to be the fact that, for the most part, the spam is largely unintelligble.<br /><br /><div class="flickr-frame">	<a href="http://www.flickr.com/photos/schoschie/351948223/" title="photo sharing"><img src="http://farm1.static.flickr.com/159/351948223_7ba810f520.jpg" class="flickr-photo" alt="" /></a><br />	<font class="flickr-caption"><a href="http://www.flickr.com/photos/schoschie/351948223/">ASCII Art Spam</a>, originally uploaded by <a href="http://www.flickr.com/people/schoschie/">schoschie</a>.<br /><br />.....wha? Sexy....grrmfs? Girls? Gorillas? Who knows. The problem with mangled text also extends (somewhat more crucially) to the URLs they happen to be pimping:<br /><br /></font><div class="flickr-frame">	<a href="http://www.flickr.com/photos/22381191@N02/2697722316/" title="photo sharing"><img src="http://farm4.static.flickr.com/3277/2697722316_f70bc0d65e.jpg" class="flickr-photo" alt="" /></a><br />	<font class="flickr-caption"><a href="http://www.flickr.com/photos/22381191@N02/2697722316/">Spam</a>, originally uploaded by <a href="http://www.flickr.com/people/22381191@N02/">cablejimmy</a>.<br /><br />They're not doing too badly there until they reach the web address, at which point it might as well say<br /><br />www. absolutelynoideawhatthatsays .com<br /><br />Of course, the last thing I'm suggesting is that I long for the day when the spammers get it <i>right</i>, but at least they can provide us with some cheap laughs regarding how hopeless their spam is in the meantime.<br /></font></div></div></div><br /> 
        
    ]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 04:35:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ascii art spam">ascii art spam</category>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/pretty cool noodles">pretty cool noodles</category>
      <category domain="http://securityratty.com/tag/spammy noodles">spammy noodles</category>
      <category domain="http://securityratty.com/tag/web address">web address</category>
      <category domain="http://securityratty.com/tag/visual appeal">visual appeal</category>
      <category domain="http://securityratty.com/tag/pragmatic pete">pragmatic pete</category>
      <category domain="http://securityratty.com/tag/cheap laughs">cheap laughs</category>
      <category domain="http://securityratty.com/tag/spammers">spammers</category>
      <source url="http://blog.spywareguide.com/2008/08/ascii-art-spam.html">ASCII Art Spam</source>
    </item>
    <item>
      <title><![CDATA[Myspace Cracker Steals Firefox Passwords]]></title>
      <link>http://securityratty.com/article/1a4072a96ea8dd94eda6fa2169ef914f</link>
      <guid>http://securityratty.com/article/1a4072a96ea8dd94eda6fa2169ef914f</guid>
      <description><![CDATA[A &quot;Myspace Cracking tool&quot; has recently come to light, though if you're considering attempting to crack some Myspace accounts with this





then you might want to think again, on account of it not...]]></description>
      <content:encoded><![CDATA[
        A "Myspace Cracking tool" has recently come to light, though if you're considering attempting to crack some Myspace accounts with this:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="mscrkff1.jpg" src="http://blog.spywareguide.com/images/mscrkff1.jpg" class="mt-image-none" style="" height="87" width="67" /></span></div><br /> <div><br />....then you might want to think again, on account of it not being quite what it seems. This "cracking tool" is only after one persons details: yours. Run it, and you'll see the following (somewhat bizarre) message, which should be your first clue that all is not quite right here:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="mscrkff2.jpg" src="http://blog.spywareguide.com/images/mscrkff2.jpg" class="mt-image-none" style="" height="125" width="229" /><br />
  <br />
  <br />
</span></div>
At this point, your CD tray may well pop open - perhaps in tribute to the Trojans of old that did pretty much the same thing. At any rate, you're certainly not cracking any Myspace accounts, and after a faint grinding from your PC you're left to sit and stare at your desktop, wondering what went wrong. Here's a clue - have a poke around inside the EXE, and some lines of code will likely start to give the game away:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="mscrkff3.jpg" src="http://blog.spywareguide.com/images/mscrkff3.jpg" class="mt-image-none" style="" height="44" width="308" /></span></div><br /><br />..."Firefox password grabber"? Oh dear.<br /><br />The observant end-user will notice a .txt file appears on their C Drive, and itcontains all the stored passwords saved via Firefox on their computer:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/mscrkff51.html" onclick="window.open('http://blog.spywareguide.com/images/mscrkff51.html','popup','width=563,height=282,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/mscrkff5-thumb-363x181.jpg" alt="mscrkff5.jpg" class="mt-image-none" style="" height="181" width="363" /></a></span><br /><br />Click to Enlarge<br /></div><br />As you can see, the bad guys here seem to be exploiting a well known password recovery tool for nefarious purposes - in this case, <a href="http://www.security-hacks.com/2007/05/01/firepassword-decrypt-firefox-password-manager">Firepassword</a>. You're probably wondering what happens with the stored login details at this point - well, do some more digging in the code and you'll see this:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/stolen.html" onclick="window.open('http://blog.spywareguide.com/images/stolen.html','popup','width=574,height=377,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/stolen-thumb-374x245.jpg" alt="stolen.jpg" class="mt-image-none" style="" height="245" width="374" /></a></span><br /><br />Click to Enlarge<br /></div><br />The stolen Firefox passwords are sent to an FTP drop set up by the hacker, and every login you had stored in Firefox at that point is immediately at risk. Of course, if you're foolish enough to play around with hacking tools then there's a good chance you're going to get burned sooner or later...<br /><br />We detect this as <a href="http://www.spywareguide.com/spydet_32576_foxpass.html">FoxPass</a>.<br /></div><div><br /></div>
        
    ]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 14:49:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/firefox">firefox</category>
      <category domain="http://securityratty.com/tag/firefox passwords">firefox passwords</category>
      <category domain="http://securityratty.com/tag/myspace">myspace</category>
      <category domain="http://securityratty.com/tag/tool">tool</category>
      <category domain="http://securityratty.com/tag/myspace accounts">myspace accounts</category>
      <category domain="http://securityratty.com/tag/firefox password grabber">firefox password grabber</category>
      <category domain="http://securityratty.com/tag/password recovery tool">password recovery tool</category>
      <category domain="http://securityratty.com/tag/ftp drop set">ftp drop set</category>
      <category domain="http://securityratty.com/tag/login details">login details</category>
      <source url="http://blog.spywareguide.com/2008/08/myspace-cracker-steals-firefox.html">Myspace Cracker Steals Firefox Passwords</source>
    </item>
    <item>
      <title><![CDATA[Software Security Market]]></title>
      <link>http://securityratty.com/article/0adbf216425dc6d24bde35c8640002aa</link>
      <guid>http://securityratty.com/article/0adbf216425dc6d24bde35c8640002aa</guid>
      <description><![CDATA[Information Security budgets are pretty crufty , they are an accumulation of decisions but the analysis that led to these decisions is rarely revisited, it just snowballs. So the normal Information...]]></description>
      <content:encoded><![CDATA[<p>Information Security budgets are pretty <a href="http://en.wikipedia.org/wiki/Cruft">crufty</a>, they are an accumulation of decisions but the analysis that led to these decisions is rarely revisited, it just snowballs. So the normal Information Security budget is just a legacy artifact of when the network was the greatest vulnerability. <a href="http://www.cigital.com/~gem/">Gary McGraw&#160;</a><a href="http://www.informit.com/articles/article.aspx?p=1237978">took a pass</a> at reviewing the numbers in software security, breaking down software security sectors like tools and services (note to Gary - I think <a href="http://www.aspectsecurity.com/">Aspect</a> does more than just training!). This is great work by Gary to get these numbers to see the real changes occuring in software security. Here were his findings on software security tools:</p><div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: &#39;Lucida Grande&#39;; line-height: 19px; ">One of the most important developments in the software security market can be seen in the tools space which, combined, almost doubled to $150-180 million. Top of list are two major acquisitions that closed in 2007: Watchfire&#39;s purchase by IBM (somewhere in the range of $120-150 million on 2006 revenue of $26 million) and SPI Dynamics&#39;s purchase by HP (for around $100 million on 2006 revenue of $21.2 million).</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: &#39;Lucida Grande&#39;; line-height: 19px;">...</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: &#39;Lucida Grande&#39;; line-height: 19px; ">The black box space was flat in 2007, with IBM/Watchfire checking in at $24.1 million and HP/SPI Dynamics earning $22.3 million. Smaller companies in the space, including Cenzic, Codenomicon, WhiteHat and the like had combined revenues around $12.5 million (a growth of 25%, though Cenzic grew 16% and WhiteHat 52%). Most of the growth &quot;hiccup&quot; in the black box market can be attributed to the serious challenges posed by any acquisition. So far 2008 looks to be back on track from a growth perspective in the black box testing space. The global reach that IBM and HP offer are already making a big difference.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: &#39;Lucida Grande&#39;; line-height: 19px;"><br /></span><span style="font-family: &#39;Lucida Grande&#39;; line-height: 19px; ">On a more positive note, static analysis tools for code review grew at a healthy clip in 2007 into a $91.9 million dollar market. Fortify was up 83% to $29.2 million. Klocwork grew over 60% to $26 million. Coverity grew over 50% to $27.2 million. Ounce Labs tripled their revenue to $9.5 million.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><br /></blockquote><div><br /><div>These are very nice growth numbers, what company doesn&#39;t want 83% growth? However, the total picture is not so good. Gary&#39;s estimate shows the software security space coming in at $150 Million total, yet we see a company like Checkpoint that won the network security war in 1995 with earnings of around $900 Million! One single network security vendor is 6 times bigger than the entire software security space?!? Complete UTTER Madness!</div><br /><div>This is the stupefying, stultifying effects of budget cruft, where the decisions made in <a href="http://1raindrop.typepad.com/1_raindrop/2007/10/network-securit.html">The People&#39;s Republic of Information Security</a> have no bearing on reality of threats or even a business case.</div><br /><div>Let&#39;s look at networks. Obviously Cisco is the biggest, they earned $39.5 Billion last year. Pretty stellar. So spending $900 Million (Checkpoint) to defined $39.5 Billion seems like a pretty good deal.</div><br /><div>Except, let&#39;s compare software security spending - last year Microsoft earned $60 Billion, SAP $16 billion, and Oracle $22 Billion. So that is about $98 Billion and you are going to &quot;defend&quot; that with allocating $150 Million worth of software security tools?</div><br />

</div><table border="1">
<tbody><tr>
<td>
</td>
<td><span style="background-color: #d0d0d0; font-family: &#39;Trebuchet MS&#39;; ">
Network
</span></td>
<td><span style="background-color: #d0d0d0; font-family: &#39;Trebuchet MS&#39;; ">
Software
</span></td>
</tr>
<tr>
<td>
Asset Value
</td>
<td>
$39.5 billion
</td>
<td>
$98 billion
</td>
</tr>
<tr>
<td>
Security Investment
</td>
<td>
$900 Million
</td>
<td>
$150 Million
</td>
</tr>
<tr>
<td>
Security Investment <br />&#160;as a percentage of asset value
</td>
<td>
2.28%
</td>
<td>
0.15%
</td></tr></tbody></table>

<br /><div>This table greatly disturbs me. From a prioritization standpoint The People&#39;s Republic of Information Security is misaligned by orders of magnitude. Next time you read about a data breach, or see an auditor&#39;s report with thousands of findings you won&#39;t have to wonder how it happened. It happened because Information Security doesn&#39;t have its eye on the ball.</div><br /><div>Consider that software security tools could grow 50% a year for five years and still be half of where Checkpoint is today!</div><br />I see the outcomes of backwards looking, crufty decisions by Information Security every day - one or two software security sherpas heading out to work with thousands of developers, meanwhile the network security people sit around and read the newspaper and go home every day at 5.</div><br /><div>The optimistic way of looking at all this data is that there is major room for growth for software security, if you take Checkpoint as a target, then the software security space should evolve to around 2% of the software space meaning that it should evolve into a $2 billion space <span style="font-style: italic;">around fifteen times larger</span> than it is today. Unprotected assets will either be protected or will cease to be assets, VCs get your check books ready.</div>]]></content:encoded>
      <pubDate>Mon, 25 Aug 2008 09:18:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/software security market">software security market</category>
      <category domain="http://securityratty.com/tag/software security sectors">software security sectors</category>
      <category domain="http://securityratty.com/tag/space">space</category>
      <category domain="http://securityratty.com/tag/tools space">tools space</category>
      <category domain="http://securityratty.com/tag/compare software security">compare software security</category>
      <category domain="http://securityratty.com/tag/software security sherpas">software security sherpas</category>
      <category domain="http://securityratty.com/tag/software security space">software security space</category>
      <category domain="http://securityratty.com/tag/software security">software security</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/software-security-market.html">Software Security Market</source>
    </item>
    <item>
      <title><![CDATA[Went on Vacation - Missed PCI DSS 1.2 :-)]]></title>
      <link>http://securityratty.com/article/669ffcd0a9fc29935f567f47acbda31a</link>
      <guid>http://securityratty.com/article/669ffcd0a9fc29935f567f47acbda31a</guid>
      <description><![CDATA[OMG, I go on vacation for 3 days (pretty much offline) - and I miss pre-release of PCI DSS 1.2
How unfair is that

In any case, I am baaaaaack
About me:...]]></description>
      <content:encoded><![CDATA[OMG, I go on vacation for 3 days (pretty much offline) - and I miss <a href="http://www.pcisecuritystandards.org/pdfs/pci_dss_summary_of_changes_v1-2.pdf">pre-release of PCI DSS 1.2.</a><br />How unfair is that? :-)<br /><br />In any case, I am baaaaaack!<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=bqDeOK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=bqDeOK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=A38ibK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=A38ibK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=JFATMK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=JFATMK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/371058820" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 21 Aug 2008 04:52:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/miss pre-release">miss pre-release</category>
      <category domain="http://securityratty.com/tag/vacation">vacation</category>
      <category domain="http://securityratty.com/tag/baaaaaack">baaaaaack</category>
      <category domain="http://securityratty.com/tag/org">org</category>
      <category domain="http://securityratty.com/tag/omg">omg</category>
      <category domain="http://securityratty.com/tag/days">days</category>
      <category domain="http://securityratty.com/tag/pretty">pretty</category>
      <category domain="http://securityratty.com/tag/offline">offline</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/371058820/went-on-vacation-missed-pci-dss-12.html">Went on Vacation - Missed PCI DSS 1.2 :-)</source>
    </item>
    <item>
      <title><![CDATA[Adi Shamir's Cube Attacks]]></title>
      <link>http://securityratty.com/article/8345c0860bf136893d6341873c7b5ffd</link>
      <guid>http://securityratty.com/article/8345c0860bf136893d6341873c7b5ffd</guid>
      <description><![CDATA[At this moment, Adi Shamir is giving an invited talk at the Crypto 2008 conference about a new type of cryptanalytic attack called &quot;cube attacks.&quot; He claims very broad applicability to block ciphers,...]]></description>
      <content:encoded><![CDATA[<p>At this moment, Adi Shamir is giving an invited talk at the <a href="http://www.iacr.org/conferences/crypto2008/">Crypto 2008</a> conference about a new type of cryptanalytic attack called "cube attacks."  He claims very broad applicability to block ciphers, stream ciphers, hash functions, etc.</p>

<p>My personal joke -- at least I hope it's a joke -- is that he's going to break every <a href="http://csrc.nist.gov/groups/ST/hash/index.html">NIST hash submission</a> without ever seeing any of them.</p>

<p>More later.   (I'm sorry, but I missed the name of his student/co-author for this work.)</p>

<p>EDITED TO ADD (8/19):  Okay, he thinks that AES is immune to this attack -- the degree of the algebraic polynomial is too high -- and all the blog ciphers we use have a higher degree.  But, in general, anything that can be described with a low-degree polynomial equation is vulnerable: that's pretty much every LFSR scheme.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=zUgXJK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=zUgXJK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=tBQAsK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=tBQAsK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 09:15:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/degree">degree</category>
      <category domain="http://securityratty.com/tag/low-degree polynomial equation">low-degree polynomial equation</category>
      <category domain="http://securityratty.com/tag/cube attacks">cube attacks</category>
      <category domain="http://securityratty.com/tag/adi shamir">adi shamir</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <category domain="http://securityratty.com/tag/joke">joke</category>
      <category domain="http://securityratty.com/tag/cryptanalytic attack">cryptanalytic attack</category>
      <category domain="http://securityratty.com/tag/personal joke">personal joke</category>
      <category domain="http://securityratty.com/tag/nist hash submission">nist hash submission</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/adi_shamirs_cub.html">Adi Shamir's Cube Attacks</source>
    </item>
    <item>
      <title><![CDATA[Wee-Fi: Houston-Fi, ASCII WPA Passphrases, Green Wi-Fi]]></title>
      <link>http://securityratty.com/article/7f30d96346f66d41619e4abd9bae8e7d</link>
      <guid>http://securityratty.com/article/7f30d96346f66d41619e4abd9bae8e7d</guid>
      <description><![CDATA[Houston flips switch on free downtown Wi-Fi: Dwight Silverman of the Houston Chronicle accidentally discovers the soft launch of the network funded by EarthLink's $5m default fee. (The fee was paid...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://blogs.chron.com/techblog/archives/2008/08/it_lives_city_of_houston_turns_on_free_downto.html"><strong>Houston flips switch on free downtown Wi-Fi:</strong></a> Dwight Silverman of the Houston Chronicle accidentally discovers the soft launch of the network funded by EarthLink's $5m default fee. (The fee was paid when they missed a milestone, and the firm later walked away.) The downtown area now has a limited pilot project that's free; the real effort in Houston is supposed to be at 10 housing projects and in parks where service would be used to bridge the digital divide and improve the quality of life. How, exactly, is part of what's being tested.</p>

<p><a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/08/18/MNH312BTS1.DTL&hw=wi+fi&sn=004&sc=589"><strong>That's ASCII, not hex:</strong></a> An article on wardriving raises security hackles by repeating some slightly overheated statements about Wi-Fi security. The article opens with a 63-character ASCII WPA passphrase, which is later described as "hex." (ASCII passphrases in WPA can be up to 63 "printable" characters - ASCII 32 to 127 - while a hex version of a 256-bit TKIP or AES password is 64 hexadecimal digits long.) The article tries to conflate Wi-Fi attacks that led to the largest set of breaches in retail credit-card systems and wardriving, a hobbyist activity that's never been looked on very favorably by law enforcement. The sense of ennui of wardriving pioneers is pretty clear; when Wi-Fi is everywhere and generally secured, it's far less interesting. The wardriver in the article convinced the reporter that a maximum-length WPA passphrase stored on a USB drive for automatic use was the best way to go. But, really, 20 characters containing letters and punctuation and no words found in a dictionary along with changing your network's SSID (network name) provides all the security you'll ever need for a home or small business. (If you need more, deploy WPA/WPA2 Personal.)</p>

<p><a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/08/16/BUA712BH1O.DTL&hw=wi+fi&sn=001&sc=1000"><strong>Green Wi-Fi's Senegal efforts hit snags:</strong></a> The folks at Green Wi-Fi are well motivated, and they're running up against all forms of security theater and bureaucracy both here and in Senegal, where they have an active project. The San Francisco Chronicle notes the group's effort to build solar-powered, self-sustaining Internet access via mesh networked nodes. Getting devices out of the country, clearing customs in Senegal, and hooking up their solar system all hit problems they're working through. As with the One Laptop Per Child program, I see a "build it and they will come" mentality in <a href="http://www.green-wifi.org/"><strong>Green Wi-Fi's mission statement</strong></a>: the notion that providing computing power and Internet access will result in good things, rather than an effort to figure out what good things need to be achieved, and whether computers and the Internet will assist. </p>]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 06:26:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/wi-fi attacks">wi-fi attacks</category>
      <category domain="http://securityratty.com/tag/houston">houston</category>
      <category domain="http://securityratty.com/tag/wi-fi security">wi-fi security</category>
      <category domain="http://securityratty.com/tag/free downtown wi-fi">free downtown wi-fi</category>
      <category domain="http://securityratty.com/tag/free">free</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/ascii">ascii</category>
      <category domain="http://securityratty.com/tag/security theater">security theater</category>
      <source url="http://wifinetnews.com/archives/008423.html">Wee-Fi: Houston-Fi, ASCII WPA Passphrases, Green Wi-Fi</source>
    </item>
    <item>
      <title><![CDATA[CNN, MSNBC Spammers Downgrading Their EMails]]></title>
      <link>http://securityratty.com/article/b412b7768a969bd9f0f16c8b816bcbeb</link>
      <guid>http://securityratty.com/article/b412b7768a969bd9f0f16c8b816bcbeb</guid>
      <description><![CDATA[This is pretty interesting. After a week or two of seeing CNN spam , then MSNBC spam (both of which allude to &quot;breaking news stories&quot; in order to get peoples attention), it seems the people behind...]]></description>
      <content:encoded><![CDATA[
        This is pretty interesting. After a week or two of seeing <a href="http://blog.spywareguide.com/2008/08/cnn-custom-alerts.html">CNN spam</a>, then <a href="http://blog.spywareguide.com/2008/08/a-change-of-plan-for-your-spam.html">MSNBC spam</a> (both of which allude to "breaking news stories" in order to get peoples attention), it seems the people behind those attacks are now sending out plain emails (with none of the allusions to being from major news networks) that simply say "BREAKING news" in the title field:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="breakingnews.jpg" src="http://blog.spywareguide.com/images/breakingnews.jpg" class="mt-image-none" style="" height="90" width="418" /></span></div><br />If you visit the link in the email, you'll see this:<br /><div><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/breakingnews2.html" onclick="window.open('http://blog.spywareguide.com/images/breakingnews2.html','popup','width=599,height=556,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/breakingnews2-thumb-399x370.jpg" alt="breakingnews2.jpg" class="mt-image-none" style="" height="370" width="399" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br />I don't believe I've seen the length, rating and viewcount under the video before so that's likely a new tactic they've employed. Looks like they need to hire a spellchecker though...<br /></div>
        
    ]]></content:encoded>
      <pubDate>Sun, 17 Aug 2008 12:00:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/news stories">news stories</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <category domain="http://securityratty.com/tag/major news networks">major news networks</category>
      <category domain="http://securityratty.com/tag/plain emails">plain emails</category>
      <category domain="http://securityratty.com/tag/title field">title field</category>
      <category domain="http://securityratty.com/tag/msnbc spam">msnbc spam</category>
      <category domain="http://securityratty.com/tag/cnn spam">cnn spam</category>
      <category domain="http://securityratty.com/tag/peoples attention">peoples attention</category>
      <category domain="http://securityratty.com/tag/spellchecker">spellchecker</category>
      <source url="http://blog.spywareguide.com/2008/08/cnn-msnbc-spammers-downgrading.html">CNN, MSNBC Spammers Downgrading Their EMails</source>
    </item>
    <item>
      <title><![CDATA[Lost.....and Found]]></title>
      <link>http://securityratty.com/article/1315aa8a559dddd4479c65bf88b0f2fc</link>
      <guid>http://securityratty.com/article/1315aa8a559dddd4479c65bf88b0f2fc</guid>
      <description><![CDATA[The practice of affiliates signing up with Zango then hiding pirated movies behind their installer prompt ([ 1 ], [ 2 ]) takes another twist, as we go hunting for TV episodes instead of movies and...]]></description>
      <content:encoded><![CDATA[
        The practice of affiliates signing up with Zango then hiding pirated movies behind their installer prompt ([<a href="http://blog.spywareguide.com/2008/08/a-dark-knight-for-zango.html">1</a>], [<a href="http://blog.spywareguide.com/2008/08/another-site-hiding-pirate-mov.html">2</a>]) takes another twist, as we go hunting for TV episodes instead of movies and find....<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/zan1.html" onclick="window.open('http://blog.spywareguide.com/images/zan1.html','popup','width=982,height=581,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/zan1-thumb-382x226.gif" alt="zan1.gif" class="mt-image-none" style="" height="226" width="382" /></a></span><br /> </div><div><div align="center">Click to Enlarge<br /></div><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/zan2.html" onclick="window.open('http://blog.spywareguide.com/images/zan2.html','popup','width=949,height=570,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/zan2-thumb-349x209.gif" alt="zan2.gif" class="mt-image-none" style="" height="209" width="349" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/zan3.html" onclick="window.open('http://blog.spywareguide.com/images/zan3.html','popup','width=948,height=584,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/zan3-thumb-348x214.gif" alt="zan3.gif" class="mt-image-none" style="" height="214" width="348" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/zan4.html" onclick="window.open('http://blog.spywareguide.com/images/zan4.html','popup','width=841,height=584,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/zan4-thumb-341x236.gif" alt="zan4.gif" class="mt-image-none" style="" height="236" width="341" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br />......TV shows (apparently ripped and streamed from Chinese Youtube-style websites), hidden behind Zango installer prompts. Obviously, this is something of a mini industry we have here but I'm faintly alarmed that so many of these affiliates are happily churning out these kinds of sites. I'm also pretty sure Zango doesn't want people seeing what effectively says "Free ripped off movies online sponsored by Zango" on their installer prompts, either.<br /><br />As a side note, it's not just Zango affiliates doing this - here's another example, this time for something called "Cpalead.com" that wants you to fill in a survey in return for seeing "free" episodes of Lost:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/cpal1.html" onclick="window.open('http://blog.spywareguide.com/images/cpal1.html','popup','width=836,height=603,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/cpal1-thumb-336x242.gif" alt="cpal1.gif" class="mt-image-none" style="" height="242" width="336" /></a></span><br />Click to Enlarge<br /></div><br />In case you were wondering, my monitor isn't broken, they just grey out the page when the popup appears. The Lost episodes appear to be ripped by end-users and uploaded to Megavideo.com.<br /><br />The sites above are<br /><br />lost-stream(dot)com<br />ietv(dot)co.uk/category/watch-lost-online<br />watchprisonbreakonlinefree(dot)com<br />watch-lost-online(dot)info<br />www.heroesstreaming(dot)com<br /><br />I guess I ended up with a trilogy after all.<br /></div><div><br /></div>
        
    ]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 10:20:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/zango installer prompts">zango installer prompts</category>
      <category domain="http://securityratty.com/tag/installer prompts">installer prompts</category>
      <category domain="http://securityratty.com/tag/lost">lost</category>
      <category domain="http://securityratty.com/tag/zango">zango</category>
      <category domain="http://securityratty.com/tag/tv episodes">tv episodes</category>
      <category domain="http://securityratty.com/tag/episodes">episodes</category>
      <category domain="http://securityratty.com/tag/enlarge">enlarge</category>
      <category domain="http://securityratty.com/tag/click">click</category>
      <category domain="http://securityratty.com/tag/dot">dot</category>
      <source url="http://blog.spywareguide.com/2008/08/lostand-found.html">Lost.....and Found</source>
    </item>
    <item>
      <title><![CDATA[UK Police Seize War on Terror Board Game]]></title>
      <link>http://securityratty.com/article/3f568c502112697df18ef85b916ccd1c</link>
      <guid>http://securityratty.com/article/3f568c502112697df18ef85b916ccd1c</guid>
      <description><![CDATA[They said -- and it's almost to stupid to believe -- that: the balaclava &quot;could be used to conceal someone's identity or could be used in the course of a criminal act
Don't they realize that...]]></description>
      <content:encoded><![CDATA[<p>They <a href="http://www.cambridge-news.co.uk/cn%5Fnews%5Fhome/DisplayArticle.asp?ID=338658">said</a> -- and it's almost to stupid to believe -- that:</p>

<blockquote>the balaclava "could be used to conceal someone's identity or could be used in the course of a criminal act".</blockquote>

<p>Don't they realize that balaclavas are <a href="http://www.google.com/search?hl=en&client=opera&rls=en&hs=OZD&q=balaclava+sale+UK&btnG=Search">for sale</a> everywhere in the UK?  Or that scarves, hoods, handkerchiefs, and dark glasses could also be used to conceal someone's identity?</p>

<p>The game sounds like it could be fun, though:</p>

<blockquote>Each player starts as an empire filled with good intentions and a determination to liberate the world from terrorists and from each other.

<p>Then the reality of world politics kicks and terrorist states emerge.</p>

<p>Andrew said: "The terrorists can win and quite often do and it's global anarchy. It sums up the randomness of geo-politics pretty well."</p>

<p>In their cardboard version of realpolitik George Bush's "Axis of Evil" is reduced to a spinner in the middle of the board, which determines which player is designated a terrorist state.</p>

<p>That person then has to wear a balaclava (included in the box set) with the word "Evil" stitched on to it.</blockquote></p>

<p>Buy yours <a href="http://www.waronterrortheboardgame.com/">here</a>; I first <a href="http://www.schneier.com/blog/archives/2006/12/war_on_terror_t.html">blogged about it</a> in 2006.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=gzxk4K"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=gzxk4K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=fQtAMK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=fQtAMK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 02:50:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/world">world</category>
      <category domain="http://securityratty.com/tag/world politics kicks">world politics kicks</category>
      <category domain="http://securityratty.com/tag/realpolitik george bush">realpolitik george bush</category>
      <category domain="http://securityratty.com/tag/player starts">player starts</category>
      <category domain="http://securityratty.com/tag/player">player</category>
      <category domain="http://securityratty.com/tag/geo-politics pretty">geo-politics pretty</category>
      <category domain="http://securityratty.com/tag/conceal">conceal</category>
      <category domain="http://securityratty.com/tag/game sounds">game sounds</category>
      <category domain="http://securityratty.com/tag/cardboard version">cardboard version</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/uk_police_seize.html">UK Police Seize War on Terror Board Game</source>
    </item>
    <item>
      <title><![CDATA[No Trademark for Cloud Computing]]></title>
      <link>http://securityratty.com/article/4b9f7e842fb8a79ceb2a5ea157dab13c</link>
      <guid>http://securityratty.com/article/4b9f7e842fb8a79ceb2a5ea157dab13c</guid>
      <description><![CDATA[Just a couple of weeks ago, it was reported that Dell was in the final stages of being granted a trademark on Cloud Computing shocking and amusing pretty much everyone except for possibly Dell...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="157" alt="clouds-jwn6" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/clouds-jwn6.jpg" width="240" align="left" border="0" /> Just a couple of weeks ago, it was reported that Dell was in the final stages of being granted a trademark on &#8220;Cloud Computing&#8221; &#8211; <a href="http://languagelog.ldc.upenn.edu/nll/?p=434#more-434" target="_blank">shocking and amusing</a> pretty much everyone except for possibly Dell employees. But apparently the US Patent and Trademark Office paid attention to the flurry of negative responses and has since <a href="http://samj.net/2008/08/dells-notice-of-allowance-for-cloud.html" target="_blank">cancelled their &#8220;Notice of Allowance&#8221;</a> for the trademark. </p>
<p>I&#8217;d like to give everyone the benefit of the doubt here; perhaps Dell was using it in a much narrower sense. Perhaps the term has really only been used more commonly since the time Dell first applied for the trademark back in March 2007 and now. BUT&#8230;</p>
<p>- Dell&#8217;s definition is quite broad and certainly not Dell-specific. <a href="http://www.eweek.com/c/a/IT-Infrastructure/Dell-Attempts-to-Trademark-Cloud-Computing/" target="_blank">&#8220;The design of computer hardware for use in datacenters and mega-scale computing environments for others; customization of computer hardware for use in data centers and mega-scale computing environments for others; design and development of networks for use in data centers and mega-scale computing environments for others.&#8221;</a> Strike One.</p>
<p>- And according to the Wall Street Journal&#8217;s research, &#8220;<a href="http://blogs.wsj.com/biztech/2008/08/06/dells-tech-jargon-trademark/" target="_blank">cloud computing&#8221; has been in regular use since 2001</a>. Strike Two.</p>
<p>So now the &#8220;case&#8221; has been returned to examination and hopefully the PTO will follow up on everyone else&#8217;s research on this and decide that yes, cloud computing is one of those broad, ubiquitous terms that should NOT be trademarked by a single company. </p>
]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 16:01:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/trademark">trademark</category>
      <category domain="http://securityratty.com/tag/dell">dell</category>
      <category domain="http://securityratty.com/tag/time dell">time dell</category>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/dell-specific">dell-specific</category>
      <category domain="http://securityratty.com/tag/possibly dell employees">possibly dell employees</category>
      <category domain="http://securityratty.com/tag/trademark office">trademark office</category>
      <category domain="http://securityratty.com/tag/computer hardware">computer hardware</category>
      <category domain="http://securityratty.com/tag/data centers">data centers</category>
      <source url="http://blog.sciencelogic.com/no-trademark-for-cloud-computing/08/2008">No Trademark for Cloud Computing</source>
    </item>
  </channel>
</rss>
