<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: public-key]]></title>
    <link>http://securityratty.com/tag/public-key</link>
    <description></description>
    <pubDate>Mon, 01 Sep 2008 01:15:41 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[FAQ: Is your county posting your Social Security number online?]]></title>
      <link>http://securityratty.com/article/b908d17bbb107bca3a45c5bab64b3086</link>
      <guid>http://securityratty.com/article/b908d17bbb107bca3a45c5bab64b3086</guid>
      <description><![CDATA[County and state Web sites may harbor Social Security numbers and other personal data in broadly accessible public records. Here's what you should...]]></description>
      <content:encoded><![CDATA[County and state Web sites may harbor Social Security numbers and other personal data in broadly accessible public records. Here's what you should know.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:d0dd9a35cd2608e4f6335e3b30fc6f3c:5qzalZ0Z6OhI1%2BBYIXtkSGn9Hkxkbz403lJYWtQ2qjt6%2BwSqQWvd7O7C97lQf%2BfWCcvxWldFWxhiGv9iJDYnRLVAlEhYGqLYSsUvcZ6SZVs%3D'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:ad85aeb6b8ba02c54ff4984adabcc8a7:miAydBhVIU%2B%2F5Fcfb5dljSU0FXnhcnmz3ZItb80hBMSURysBXj%2FX210vjI1dmlZgHVk%2BAzGIaale9mAwSTZD8%2BHzubzatca8C0tGlAs%2BTyg%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:750070f286298d730e4280ff7ee8cf7d:uWW5i7kDsYQdDSoE0MyO8QCJrWe%2FbXYoZ119LXK8DlyNfaWiYjq58V1eVDfKns0He9Hpst9PBEPXEZapEdPXyRDN%2B%2Bi3KK6fkEg5WjgZ2Vw%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v2:cc721c56aeb97a089720dd496074ac56:GR%2FImFfoVRWGXmjiosz1ApKmtX4wK0g6tPm53PSGxMmGJIH8OXzAqhdmirRF6c6O5r98LhY58JpkEsKcPAJeREOJZPv2JR2AhVdGTs%2FPYOw%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=a815cf9261dd5e28ab3b4bd6bf71d6b2" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=a815cf9261dd5e28ab3b4bd6bf71d6b2" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/harbor social security">harbor social security</category>
      <category domain="http://securityratty.com/tag/personal data">personal data</category>
      <category domain="http://securityratty.com/tag/web sites">web sites</category>
      <category domain="http://securityratty.com/tag/county">county</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=a815cf9261dd5e28ab3b4bd6bf71d6b2">FAQ: Is your county posting your Social Security number online?</source>
    </item>
    <item>
      <title><![CDATA[Cablevision Activates Major Areas of Its Wi-Fi Network]]></title>
      <link>http://securityratty.com/article/40a07e9654a39fb5503761a8d723e3f9</link>
      <guid>http://securityratty.com/article/40a07e9654a39fb5503761a8d723e3f9</guid>
      <description><![CDATA[New York area cable operator Cablevision flips switch for high-traffic areas of Long Island: They're announcing Thursday that they've turned on the initial phases of their network in Nassau and...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/muni_icon.jpg" align="right" border="0" hspace="5" /><strong>New York area cable operator Cablevision flips switch for high-traffic areas of Long Island:</strong> They're announcing Thursday that they've turned on the initial phases of their network in Nassau and Suffolk counties, as well as at commuter rail platforms and station parking lots throughout Long Island. The service offers 1.5 Mbps in each direction, the company claims. Detailed site maps for their previous much smaller activated areas are up at <a href="http://www.optimumwifi.com/"><strong>their Wi-Fi information site</strong></a>, and I expect to see these updated soon.</p>

<p>Cablevision will ultimately spend about $300m in building a Wi-Fi network exclusively for its customers; 2.4m of these customers qualify to use the service at no cost. There's no pay as you go option, no monthly subscription; you're either a subscriber of theirs, or not. It's a fascinating strategy, because they're leveraging all these dollars as a tool to crack its competitors in the market. With increasing competition from telephone companies that are offering television service, cable companies need to compete on voice, data, and video, as well as well as on mobile offerings. When the network is built, Cablevision can conceivably offer Wi-Fi telephony service, too.</p>

<p>I'm dying to know what the reduced churn rate and increase in subscriptions will be in six months. Given that hotspot access costs $10 to $30 per month depending on the network, Cablevision is delivering something of value. It's great honey for new subscribers and glue to keep current subscribers.</p>

<p>The company is claiming that with this latest activation, they have the largest Wi-Fi network for consumers in the U.S. They're likely correct. The only other public access network of scale that's being used by large numbers is in Minneapolis, and based on what I know about both networks, Cablevision probably deserves bragging rights. The network in Taipei, Taiwan, is likely still larger, but I haven't heard any usage number in nearly two years; at that point, subscription rates were 10 percent of what had been projected.</p>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 17:01:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wi-fi network">wi-fi network</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/wi-fi network exclusively">wi-fi network exclusively</category>
      <category domain="http://securityratty.com/tag/cablevision">cablevision</category>
      <category domain="http://securityratty.com/tag/public access network">public access network</category>
      <category domain="http://securityratty.com/tag/service offers">service offers</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/hotspot access costs">hotspot access costs</category>
      <category domain="http://securityratty.com/tag/television service">television service</category>
      <source url="http://wifinetnews.com/archives/008429.html">Cablevision Activates Major Areas of Its Wi-Fi Network</source>
    </item>
    <item>
      <title><![CDATA[Real Artists Ship]]></title>
      <link>http://securityratty.com/article/da6631c856e43a023c66515e59fbce16</link>
      <guid>http://securityratty.com/article/da6631c856e43a023c66515e59fbce16</guid>
      <description><![CDATA[For a number of reasons I follow emerging economies, the biggies being China and India. The BRIC countries (Brazil, Russia, India, and China) generally get lumped in together as the &quot;next big thing&quot;,...]]></description>
      <content:encoded><![CDATA[<p>For a number of reasons I follow emerging economies, the biggies being China and India. The BRIC countries (Brazil, Russia, India, and China) generally get lumped in together as the &quot;next big thing&quot;, but they are at very, very different stages of development and more importantly are taking different paths. You can easily think of software security as an emerging discipline - despite a lot of talk and papers about Saltzer and Schroeder, we really don&#39;t have this stuff figured out.&#160;</p><br /><div>So China is following a well worn path similar to South Korea, Japan, and the early US. India is taking a totally different and unproven path towards growth. Tata Motors has been innovative in building the cheapest car - the Tata Nano which is a $2500 car, and<a href="http://1raindrop.typepad.com/1_raindrop/2008/01/to-those-about.html"> engineering triumph</a>, driven by a mantra that an engineer would stand behind &quot;do we really need that?&quot;</div><br /><div>Now the progress to executing on this is <a href="http://www.nytimes.com/2008/09/03/world/asia/03tata.html?_r=1&amp;ref=world&amp;oref=slogin">held back</a> by India&#39;s dysfunctional environment:</div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-style: italic; line-height: normal; ">In a tale rich with incongruities, the Communist-run government of West Bengal State invited the&#160;<a href="http://topics.nytimes.com/top/news/business/companies/tata_group/index.html?inline=nyt-org" style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; text-decoration: none; color: #006683; " title="More articles about the Tata Group.">Tata Group</a>, a symbol of Indian capitalism, to set up its plant in an area called Singur. It acquired 1,000 acres from farmers on the company’s behalf.</span><br /><span style="font-family: Verdana; font-style: italic; line-height: normal; ">As the project advanced, some farmers who had sold their land demanded it back. The main state-level opposition party, the Trinamool Congress, led protests demanding that the land be returned. Most people sympathetic to Tata accused the opposition of inducing the farmers to protest, while Tata’s critics said the farmers had legitimate grievances.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-style: italic; line-height: normal;"><br /></span><span style="font-family: Verdana; font-style: italic; line-height: normal; ">The issue simmered for months. But in recent days, protesters began surrounding the plant, blocking roads and preventing Tata workers from reaching the plant. “The existing environment of obstruction, intimidation and confrontation has begun to impact the ability of the company to convince several of its experienced managers to relocate and work in the plant,” Tata said in a statement on Tuesday.</span><br /><span style="font-family: Verdana; font-style: italic; line-height: normal; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-style: italic; line-height: normal; ">The halt to the plant has caused many Indian business people to warn of a chilling effect on investment in the country. It is also unclear how Tata will be able to keep the Nano’s cost so low, since part of the affordable price reflects the company’s savings on the land in Singur.</span></p></blockquote><p><span style="font-family: Verdana; font-style: italic; line-height: normal;"><br /><div><span style="font-style: normal; "><a href="http://voxeu.org/index.php?q=node/1585">Arvind Subramanian</a>&#160;compares China and India&#39;s trajectories:</span><br /></div><div><span style="font-style: normal;"><br /></span></div></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-style: italic; line-height: normal; ">There is a fundamental asymmetry between state and markets. It is easier to create markets than it is to create state capacity or to prevent its deterioration. Creating markets is a lot about letting go, establishing a reasonable policy framework, and allowing the natural hustling instinct to take over. In other words, hustling is the natural state. Building state capacity, on the other hand, is quite different. It involves overcoming collective action problems, mediating conflict, creating accountability mechanisms where outputs are multiple and fuzzy and links between inputs and outputs murky, and contending with the deep imprints of history. In Weber’s memorable words, building public institutions is like the “slow boring of hard boards”.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; font-style: italic; line-height: normal;"><br /></span><span style="font-family: Verdana; font-style: italic; line-height: normal; ">In that light, China’s task of improving its private sector seems easier to accomplish than India’s task of arresting institutional decline. So, while China and India can probably both count on more years of high growth, the odds still favour China pulling off that feat than India. That, and not just the meagre medal tally, should be what India mulls over after the Beijing Olympics.</span></p></blockquote><div><span style="font-family: Verdana; font-style: italic; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; line-height: normal; ">The Economist </span><a href="http://www.economist.com/blogs/freeexchange/2008/09/the_passion_of_the_tata.cfm">summarizes</a><span style="font-family: Verdana; line-height: normal; ">:</span></div><div><span style="font-family: Verdana; line-height: normal;"><br /></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Verdana; line-height: normal; ">It&#39;s easier to liberalise a functional state than it is to functionalise a dysfunctional one, of any ideological stripe.</span></p></blockquote><p><span style="font-family: Verdana; line-height: normal;"><br /></span></p><div><span style="font-family: Verdana; line-height: normal;">What does all this have to do with ostensibly the topic at hand - Information Security? Well Tata Motors had the innovation but they didn&#39;t have the deployment model, at least not yet. More to the point, a lot of software security gets driven by infosec groups but real change is only coming when its driven by the development group. Why? Development groups are functional, they ship code.&#160;A lot of the success in software security is predicated by who you choose to partner with, it is more effective and easier to add security into a functional development group that ships code.</span></div><div><span style="font-family: Verdana; line-height: normal;"><br /></span></div><div><span style="font-family: Verdana; line-height: normal;"><br /></span></div>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 07:23:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tata">tata</category>
      <category domain="http://securityratty.com/tag/tata workers">tata workers</category>
      <category domain="http://securityratty.com/tag/tata motors">tata motors</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/india">india</category>
      <category domain="http://securityratty.com/tag/india mulls">india mulls</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/functional development">functional development</category>
      <category domain="http://securityratty.com/tag/software security">software security</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/real-artists-ship.html">Real Artists Ship</source>
    </item>
    <item>
      <title><![CDATA[Zango And The Batman Online Videogame]]></title>
      <link>http://securityratty.com/article/df88ab063f04def43d02f931dfa23c42</link>
      <guid>http://securityratty.com/article/df88ab063f04def43d02f931dfa23c42</guid>
      <description><![CDATA[This is Newsarama, a site (mostly) geared around comics and other related media





Click to Enlarge

You'll notice Batman, over on the right there. Let's take a closer look





Free Online Batman...]]></description>
      <content:encoded><![CDATA[
        This is Newsarama, a site (mostly) geared around comics and other related media:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/batzang1.html" onclick="window.open('http://blog.spywareguide.com/images/batzang1.html','popup','width=839,height=492,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/batzang1-thumb-339x198.jpg" alt="batzang1.jpg" class="mt-image-none" style="" height="198" width="339" /></a></span><br /> </div><div><div align="center">Click to Enlarge<br /></div><br />You'll notice Batman, over on the right there. Let's take a closer look:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="batzang2.gif" src="http://blog.spywareguide.com/images/batzang2.gif" class="mt-image-none" style="" height="266" width="316" /></span></div><br /></div><div><br />"Free Online Batman Game"? Well, that's curious because I follow comics pretty closely and I'd be the first to know if an "Online Batman Game" had been in the works (this advert has been doing the rounds on <a href="http://forums.superherohype.com/showthread.php?p=15406107">numerous</a> <a href="http://dcboards.warnerbros.com/web/message.jspa?messageID=2004718393#2004718393">comic-related</a> <a href="http://www.comicforum.de/showpost.php?s=543cba941aeb245f8174ec4943be2adc&amp;p=2733165&amp;postcount=29">websites</a>. Visit the URL in the ad - Batmangame.info - and you'll see this...<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/batzang3.html" onclick="window.open('http://blog.spywareguide.com/images/batzang3.html','popup','width=725,height=666,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/batzang3-thumb-325x298.gif" alt="batzang3.gif" class="mt-image-none" style="" height="298" width="325" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br />There it is again - "Online Batman Game". Furthermore, the text goes on to say:<br /><i><br />"Batman Online lets you do anything and every little thing you'd like in a Batman game. From leveling up your character to destroying villans, it has it all. Download and play this amazing game now, all for free! I'm sure you'll be playing for hours on end, it's that much fun.<br /><br />&nbsp;&nbsp;&nbsp; Level Up Your Character<br />&nbsp;<br />&nbsp;&nbsp; Explore a Huge Vast World<br />&nbsp;<br />&nbsp;&nbsp; Play Online With Your Friends<br />&nbsp;<br />&nbsp;&nbsp; Hundreds of Quests To Finish<br />&nbsp;<br />&nbsp;&nbsp; Perfect Battle System<br /><br />So start your Batman adventure today! Download the&nbsp; full game below and fight them all!"</i><br /><br />Note that they specifically call it "Batman Online". It specifically sounds like a text blurb you'd expect to see with a <a href="http://en.wikipedia.org/wiki/Massively_multiplayer_online_role-playing_game">MMORPG</a>. However, something isn't quite right here.<br /><br /><b>1)</b> The only DC licensed MMORPG anybody knows of is <a href="http://en.wikipedia.org/wiki/DC_Universe_%28video_game%29">this</a>, and it isn't due out until 2009. It's not Batman-centric, either.<br /><br /><b>2)</b> The screenshots are lifted from the <a href="http://en.wikipedia.org/wiki/Batman_Begins_%28video_game%29">Batman Begins videogame</a>, which came out in 2005. If you were offering a "Batman Online Game", wouldn't you use screenshots from that instead of an unrelated title?<br /><br /><b>3)</b> Absolutely no licensing, copyright or legal mumbo-jumbo on the page anywhere. DC and Warner Bros don't roll like that.<br /><br /><b>4)</b> The website - Batmangame(dot)info - is <a href="http://whois.domaintools.com/batmangame.info">registered anonymously</a>. Not exactly something you see everyday for websites related to licensed DC franchises such as Batman videogames.<br /><br /><b>5)</b> "To download and play the Batman Online Game you must download and install Zango as well. It is free, very easy to install and will give you access to the full game."<br /><br />Shall we continue?<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/batzang4.html" onclick="window.open('http://blog.spywareguide.com/images/batzang4.html','popup','width=757,height=638,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/batzang4-thumb-357x300.gif" alt="batzang4.gif" class="mt-image-none" style="" height="300" width="357" /></a></span><br />Click to Enlarge<br /></div><br />A Zango installer prompt, complete with picture of Batman at the top. If you say "No" to the install, you end up on Google.com. What happens if you click "Start"? Well, you'll get the <a href="http://blog.spywareguide.com/images/batzang5.gif">usual collection</a> of <a href="http://blog.spywareguide.com/images/batzang6.gif">Zango installer screens</a> including one that rather humorously has a guy in a superhero costume.<br /><br /></div><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="batzang7.gif" src="http://blog.spywareguide.com/images/batzang7.gif" class="mt-image-none" style="" height="333" width="419" /></span></div><div><br />Once everything is installed, you're taken to another page and from here things just get plain confusing. Remember, up to this point you've been promised an "Online Batman Game", the description of which is clearly intended to evoke images of a MMORPG. However....<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/batveng.html" onclick="window.open('http://blog.spywareguide.com/images/batveng.html','popup','width=841,height=623,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/batveng-thumb-341x252.jpg" alt="batveng.jpg" class="mt-image-none" style="" height="252" width="341" /></a></span><br />Click to Enlarge<br /></div><br />All of a sudden, you're being told you're downloading "Batman: Vengeance" on a cheap-looking splash page and shown what looks like an unofficially ripped <a href="http://www.youtube.com/watch?v=D1WqzbNB8tM&amp;eurl=http://www.batmangame.info/setup.exe">Batman: Vengeance trailer</a> on Youtube.<br /><br />In case you're unaware, Batman: Vengeance is a videogame <a href="http://en.wikipedia.org/wiki/Batman_Vengeance">first launched way back in 2001</a> for consoles (followed shortly after by a PC version). What does this have to do with an "Online Batman Game"? Well, nothing, actually. Aside from the fact you were presented with one thing and are now handed another, things get even stranger when you see the download location:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/batzang00.html" onclick="window.open('http://blog.spywareguide.com/images/batzang00.html','popup','width=542,height=281,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/batzang00-thumb-342x177.gif" alt="batzang00.gif" class="mt-image-none" style="" height="177" width="342" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br />Have you ever heard of an officially licensed game being offered via Rapidshare downloads? It's possible, I guess, but it seems a little odd. However, the <i>real</i> oddness is reserved for the "Online Batman game" itself.<br /><br />Remember, we've been promised "Hundreds of quests", "A huge vast world", the ability to "level up your character" and (of course) the "play online with your friends" promise of greatness.<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/batinstall.html" onclick="window.open('http://blog.spywareguide.com/images/batinstall.html','popup','width=811,height=549,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/batinstall-thumb-311x210.gif" alt="batinstall.gif" class="mt-image-none" style="" height="210" width="311" /></a></span><br />Click to Enlarge<br /></div><br />Imagine your dismay, then, when you've installed Zango, downloaded the game from Rapidshare using up around 140MB of bandwidth, installed it and....<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="batdemo.gif" src="http://blog.spywareguide.com/images/batdemo.gif" class="mt-image-none" style="" height="288" width="451" /></span></div><br />Oh dear.<br /><br />Not only are you given a totally different game than what was advertised, you're given a DEMO VERSION of that game with <a href="http://blog.spywareguide.com/images/menu.gif">four short sample levels</a> present, no online functionality and quite a few less quests than the "hundreds" advertised.<br /><br />Hilariously, you can download a 100% legit copy of this demo <a href="http://www.fileplanet.com/110885/110000/fileinfo/Batman-Vengeance-Demo">here at Fileplanet</a>, sans Adware. Setting aside the issue of whether this file is actually sitting on Rapidshare with either Ubisoft or DC / Warner Bros permission (and if it IS okay to be there, I'm pretty sure it's NOT okay to falsely advertise it as some kind of MMORPG) there are some questions that need to be raised here.<br /><br />When this guy approached them with his website, did nobody stop to think that this game did not actually match up with the "Online Batman" game it was touted as? Didn't someone at Zango Quality Control actually download the game and see the big "This is a demo" wording as soon as it starts up? Or question why the <a href="http://blog.spywareguide.com/images/begins1.gif">screenshots</a> on the website don't look like the graphics for <a href="http://blog.spywareguide.com/images/batveng1.gif">Batman: Vengeance</a> in the slightest?<br /><br />However you look at it, this is a scam, pure and simple. Whoever came up with the idea of an "Online Batman Game" is lying through their teeth. Of course, because their website is registered anonymously we have no idea who the culprit is, unless of course Zango want to deposit them on the steps of Gotham City and let me dispense some Batman-style justice to their posterior.<br /><br />However, based on the way these things tend to go - God forbid anyone ever offer up the identity of someone happily scamming the public at large, even when that person is dragging the name of the company associated with them through the mud by their antics - I think I might be waiting some time for the Bat Signal...<br /></div>
        
    ]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 07:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/batman">batman</category>
      <category domain="http://securityratty.com/tag/batman online">batman online</category>
      <category domain="http://securityratty.com/tag/batman game">batman game</category>
      <category domain="http://securityratty.com/tag/online batman game">online batman game</category>
      <category domain="http://securityratty.com/tag/batman online game">batman online game</category>
      <category domain="http://securityratty.com/tag/batman adventure">batman adventure</category>
      <category domain="http://securityratty.com/tag/batman begins videogame">batman begins videogame</category>
      <category domain="http://securityratty.com/tag/batman-centric">batman-centric</category>
      <category domain="http://securityratty.com/tag/batman-style justice">batman-style justice</category>
      <source url="http://blog.spywareguide.com/2008/09/zango-and-the-batman-online-vi.html">Zango And The Batman Online Videogame</source>
    </item>
    <item>
      <title><![CDATA[Copycat Web Malware Exploitation Kits are Faddish]]></title>
      <link>http://securityratty.com/article/ba56aabae03bad418cbbf5ae497d3769</link>
      <guid>http://securityratty.com/article/ba56aabae03bad418cbbf5ae497d3769</guid>
      <description><![CDATA[For the cheap cybercriminals not wanting to invest a couple of thousand dollars into purchasing a cutting edge web malware exploitation kit -- a pirated copy of which they would ironically obtained...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SL1mWgfY_TI/AAAAAAAACJU/u4h7TuozLDI/s1600-h/copycat_web_malware_exploitation_kit.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SL1mWgfY_TI/AAAAAAAACJU/H8HQ-QzSBfg/s200-R/copycat_web_malware_exploitation_kit.gif" /></a>For the cheap cybercriminals not wanting to invest a couple of thousand dollars into purchasing a cutting edge web malware exploitation kit -- a pirated copy of which they would ironically obtained several moths later -- with all the related and royalty free updates coming with it, there are always the copycat malware kits like this one offered for $100.<br />
<br />
Taking into consideration the proprietary nature of some of the kits, the business model of malware kits was mostly relying on their exclusive nature next to the number, and diversity of the exploits included in order to improve the infection rate. This simplistic assumption on behalf of the coders totally <a href="http://blogs.zdnet.com/security/?p=1598">ignored the possibility of their kits leaking to the general public</a>, or copies of the kits ending up as a bargain in particular underground deal where the once highly exclusive kit was offered as a bonus.<br />
<br />
"Me too" web malware kits were a faddish way to enjoy the popularity of web malware kits like MPack and Icepack and try to cash in on that popularity by coming up average kits lacking any significant differentiation factors in the process. But just like the original and proprietary kits, whose authors didn't envision the long term growth strategy of integrating different services into their propositions or the kits themselves, the authors of copycat malware kits didn't bother considering the lack of long-term growth strategy for their releases. Branding in respect to releasing a Firepack malware kit to compete with Icepack which was originally released to compete with Mpack, has failed to achieve the desired results as well.<br />
<br />
And with malware kits now a commodity, and underground vendors excelling in a particular practice with the long term objective to vertically integrate in their area of expertise -- think spammers offering localization of messages into different languages and segmented email databases from a specific country -- would we witness the emergence of <a href="http://ddanchev.blogspot.com/2008/08/76service-cybercrime-as-service-going.html">managed cybercrime services</a> charging a premium for providing fresh dumps of credit card numbers, PayPal, Ebay accounts or whatever the buyer is requesting?<br />
<br />
That may well be the case in the long term.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/08/web-based-botnet-command-and-control.html">Web Based Botnet Command and Control Kit 2.0</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/diy-botnet-kit-promising-eternal.html">DIY Botnet Kit Promising Eternal Updates</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/pinch-vulnerable-to-remotely.html">Pinch Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">The Zeus Crimeware Kit Vulnerable to Remotely Exploitable Flaw</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/small-pack-web-malware-exploitation-kit.html">The Small Pack Web Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/crimeware-in-middle-zeus.html">Crimeware in the Middle - Zeus</a><br />
<a href="http://ddanchev.blogspot.com/2006/11/nuclear-grabber-toolkit.html">The Nuclear Grabber Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/rbns-phishing-activities.html">The Apophis Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">The FirePack Exploitation Kit Localized to Chinese</a><span style="font-weight: bold;"><br />
</span><a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">MPack and IcePack Localized to Chinese</a><br />
<span style="font-weight: bold;"><span style="font-weight: bold;"></span></span><a href="http://ddanchev.blogspot.com/2008/05/icepack-exploitation-kit-localized-to.html">The Icepack Exploitation Kit Localized to French</a> <br />
<a href="http://ddanchev.blogspot.com/2008/04/firepack-exploitation-kit-part-two.html">The FirePack Exploitation Kit - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/firepack-web-malware-exploitation-kit.html">The FirePack Web Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2007/05/webattacker-in-action.html">The WebAttacker in Action</a><br />
<a href="http://ddanchev.blogspot.com/2007/08/nuclear-malware-kit.html">Nuclear Malware Kit</a><br />
<a href="http://ddanchev.blogspot.com/2008/01/random-js-malware-exploitation-kit.html">The Random JS Malware Exploitation Kit</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/metaphisher-malware-kit-spotted-in-wild.html">Metaphisher Malware Kit Spotted in the Wild</a><br />
<a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample_7672.html">The Black Sun Bot</a><br />
<a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample_20.html">The Cyber Bot</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/google-hacking-for-mpacks-zunkers-and.html">Google Hacking for MPacks, Zunkers and WebAttackers</a><br />
<a href="http://ddanchev.blogspot.com/2007/07/icepack-malware-kit-in-action.html">The IcePack Malware Kit in Action</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jUilFL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jUilFL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LiAKxL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LiAKxL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=GnpH1l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=GnpH1l" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=bjjwel"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=bjjwel" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NAlZrL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NAlZrL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ybk3ML"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ybk3ML" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=0j6X0l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=0j6X0l" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/382290326" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 03:18:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware kits">malware kits</category>
      <category domain="http://securityratty.com/tag/web malware kits">web malware kits</category>
      <category domain="http://securityratty.com/tag/kits">kits</category>
      <category domain="http://securityratty.com/tag/copycat malware kits">copycat malware kits</category>
      <category domain="http://securityratty.com/tag/proprietary kits">proprietary kits</category>
      <category domain="http://securityratty.com/tag/term">term</category>
      <category domain="http://securityratty.com/tag/long-term growth strategy">long-term growth strategy</category>
      <category domain="http://securityratty.com/tag/icepack">icepack</category>
      <category domain="http://securityratty.com/tag/icepack exploitation kit">icepack exploitation kit</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/382290326/copycat-web-malware-exploitation-kits.html">Copycat Web Malware Exploitation Kits are Faddish</source>
    </item>
    <item>
      <title><![CDATA[Sucking Data off of Cell Phones]]></title>
      <link>http://securityratty.com/article/4cbc1761652d9271a9311931f47b85b5</link>
      <guid>http://securityratty.com/article/4cbc1761652d9271a9311931f47b85b5</guid>
      <description><![CDATA[Don't give someone your phone unless you trust them: There is a new electronic capture device that has been developed primarily for law enforcement, surveillance, and intelligence operations that is...]]></description>
      <content:encoded><![CDATA[<p>Don't <a href="http://news.cnet.com/8301-1009_3-10028589-83.html?tag=newsEditorsPicksArea.0">give someone your phone</a> unless you trust them:</p>

<blockquote>There is a new electronic capture device that has been developed primarily for law enforcement, surveillance, and intelligence operations that is also available to the public. It is called the Cellular Seizure Investigation Stick, or CSI Stick as a clever acronym. It is manufactured by a company called Paraben, and is a self-contained module about the size of a BIC lighter. It plugs directly into most Motorola and Samsung cell phones to capture all data that they contain. More phones will be added to the list, including many from Nokia, RIM, LG and others, in the next generation, to be released shortly.</blockquote>

<p>Another <a href="http://www.physorg.com/news139460365.html">news article</a>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=FDP4FL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=FDP4FL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=WZ1UtL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=WZ1UtL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 02:03:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/phones">phones</category>
      <category domain="http://securityratty.com/tag/capture">capture</category>
      <category domain="http://securityratty.com/tag/electronic capture device">electronic capture device</category>
      <category domain="http://securityratty.com/tag/samsung cell phones">samsung cell phones</category>
      <category domain="http://securityratty.com/tag/news article">news article</category>
      <category domain="http://securityratty.com/tag/law enforcement">law enforcement</category>
      <category domain="http://securityratty.com/tag/intelligence operations">intelligence operations</category>
      <category domain="http://securityratty.com/tag/csi stick">csi stick</category>
      <category domain="http://securityratty.com/tag/clever acronym">clever acronym</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/sucking_data_of.html">Sucking Data off of Cell Phones</source>
    </item>
    <item>
      <title><![CDATA[Education and the willingness of parents ot insure their childs online safety is paramount]]></title>
      <link>http://securityratty.com/article/62f8d39bb7a731e55237495c7b654a1f</link>
      <guid>http://securityratty.com/article/62f8d39bb7a731e55237495c7b654a1f</guid>
      <description><![CDATA[I agree with alot of both the Point and Counterpoint articles by Alan and Mary. The Counterpoint article is at this link. http://www.internetevolution.com/author.asp?doc id=162622&amp;f src=ieupdate

...]]></description>
      <content:encoded><![CDATA[<div > I agree with alot of both the Point and Counterpoint articles by Alan and Mary.<br/>The Counterpoint article is at this link.<br/><a href="http://www.internetevolution.com/author.asp?doc_id=162622&amp;f_src=ieupdate" rel="nofollow" target="_blank">http://www.internetevolution.com/author.asp?doc_id=162622&amp;f_src=ieupdate</a><br/> </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/B42C1E85-7ED5-44B2-8D4B-724E807F2ABE/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/ee0189c8-87a3-495d-9556-11ffce26cd81/B42C1E85-7ED5-44B2-8D4B-724E807F2ABE/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.internetevolution.com/author.asp?section_id=526&#038;doc_id=162659" href="http://www.internetevolution.com/author.asp?section_id=526&#038;doc_id=162659" style="font-size: 11px;">www.internetevolution.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.internetevolution.com/author.asp?section_id=526&#038;doc_id=162659 --><DIV><SPAN class="gray header biggest"><A href="http://www.internetevolution.com/author.asp?section_id=526&#038;doc_id=162659&#038;"><I>Point</I>: The Fantasy of a &#8216;Childproof&#8217; Internet</A></SPAN></DIV></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.internetevolution.com/author.asp?section_id=526&#038;doc_id=162659 --><DIV><br />
One problem is that content filtering software simply isn&#8217;t good enough.?Yes, software blocks many child porn sites, but it also allows some sites to get through.?Also, child porn sites are typically very good at evading filters.?Just as importantly, the software mandated for schools and public libraries doesn&#8217;t just ban child porn, it bans thousands of sites.?Does the software company investigate the thousands of sites it blocks??Does it know whether a child engaged in illicit activity on a Website is 16, 18, or 21 years old?</DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/B42C1E85-7ED5-44B2-8D4B-724E807F2ABE/blog/" title="blog or email this clip"><img src="http://content7.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_020908115811"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=020908115811&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=020908115811&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=020908115811&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_020908115811" /></a></P>]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 19:58:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/child porn sites">child porn sites</category>
      <category domain="http://securityratty.com/tag/child">child</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/software blocks">software blocks</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/software simply">software simply</category>
      <category domain="http://securityratty.com/tag/ban child porn">ban child porn</category>
      <category domain="http://securityratty.com/tag/blocks">blocks</category>
      <category domain="http://securityratty.com/tag/software company">software company</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=601">Education and the willingness of parents ot insure their childs online safety is paramount</source>
    </item>
    <item>
      <title><![CDATA[DC Young IT Scene Growing]]></title>
      <link>http://securityratty.com/article/cfe7523038453c0b939b3153f29dbc01</link>
      <guid>http://securityratty.com/article/cfe7523038453c0b939b3153f29dbc01</guid>
      <description><![CDATA[The late 90s IT boom represented everything great about the American dream. If you had a brilliant idea, knew how to put it into production and had some idea on how to market said idea, you could make...]]></description>
      <content:encoded><![CDATA[<p>The late 90’s IT boom represented everything great about the American dream.&nbsp; If you had a brilliant idea, knew how to put it into production and had some idea on how to market said idea, you could make it and many were indeed making it big in Silicon Valley.
<p>This chance to “get rich quick” prompted many talented young entrepreneurs and IT specialists to move to the Valley, and in turn helped <a href="http://www.somewhatfrank.com/2008/07/web-20-startups.html" target="_blank">establish the area</a> as a hip young center for the most talented people in the field.&nbsp;
<p>The Beltway, (a.k.a. Washington, DC area) has always been known as a home for those wanting to enter into public service, or at least a career in grand gestures, however with the rapid growth of government-based IT needs, and the <a href="http://www.istrategylabs.com/giving-you-50000-for-office-space-and-lot-of-other-fun-things/" target="_blank">success of many IT companies</a> in the area, it is slowly <a href="http://eastcoastblogging.com/2008/07/28/crossmine-dcs-directory-of-technology-ventures/" target="_blank">transforming into an IT hub of its own</a>.&nbsp;
<p>[Note: Dave and Julia disagree with my perspective on the slow growth of DC as a tech hub. In their opinions, it always has been with many great IT companies founded and run out of the DC area, including AOL, UUnet, and The Motley Fool, to name a few. The area was properly positioned as the “Silicon Valley of the East” in the 90’s and was able to successfully cultivate a large and prominent IT culture. BUT it’s interesting that Silicon Valley dominates in terms of popular perception, as I believe and so do many friends I’ve discussed this with.]
<p>But perhaps that is changing. Dave wrote an earlier post about the <a href="http://blog.sciencelogic.com/whats-up-with-the-washington-posts-biz-section-coverage-of-local-business/05/2008" target="_blank">lack of local tech coverage in the Washington Post</a>. Recently, however, we’re seeing more relevant articles in the paper that highlight the growing DC young IT scene. Case in point, this <a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/08/10/AR2008081002026.html?wpisrc=newsletter" target="_blank">article</a> about LaunchBox, a DC tech incubator that will hopefully only serve to grow and enrich the community with more <a href="http://technosailor.com/2008/07/25/andrew-feinberg-to-join-technosailorcom/" target="_blank">talented young IT professionals and big thinkers</a>.&nbsp;
<p>The question that remains is <a href="http://blog.sciencelogic.com/a-new-generation-of-tech-in-dc/07/2008" target="_blank">how the culture</a> in this <a href="http://www.gottabemobile.com/Mobile+Tech+And+Social+Tools+Upset+Some+Congress+Folk.aspx" target="_blank">very traditional area</a> will change with this growth.&nbsp; </p>
]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 14:45:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/valley">valley</category>
      <category domain="http://securityratty.com/tag/silicon valley">silicon valley</category>
      <category domain="http://securityratty.com/tag/slow growth">slow growth</category>
      <category domain="http://securityratty.com/tag/growth">growth</category>
      <category domain="http://securityratty.com/tag/washington post">washington post</category>
      <category domain="http://securityratty.com/tag/brilliant idea">brilliant idea</category>
      <category domain="http://securityratty.com/tag/washington">washington</category>
      <category domain="http://securityratty.com/tag/idea">idea</category>
      <category domain="http://securityratty.com/tag/hub">hub</category>
      <source url="http://blog.sciencelogic.com/dc-young-it-scene-growing/09/2008">DC Young IT Scene Growing</source>
    </item>
    <item>
      <title><![CDATA[File Sharing Program Exposes Prince William County Public School Private Records]]></title>
      <link>http://securityratty.com/article/debd02bcf35f1ed85371deca5a8817ef</link>
      <guid>http://securityratty.com/article/debd02bcf35f1ed85371deca5a8817ef</guid>
      <description><![CDATA[Prince William County Public Schools (PWCS) recently learned that certain personal information relating to a small group of students, staff, and volunteers was inadvertently exposed to the public...]]></description>
      <content:encoded><![CDATA[Prince William County Public Schools (PWCS) recently learned that certain personal information relating to a small group of students, staff, and volunteers was inadvertently exposed to the public through the Internet for a period of approximately five weeks this summer. It was determined that a school-based employee, while working on school business from home on [...]]]></content:encoded>
      <pubDate>Mon, 01 Sep 2008 18:13:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/public">public</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/school business">school business</category>
      <category domain="http://securityratty.com/tag/volunteers">volunteers</category>
      <category domain="http://securityratty.com/tag/pwcs">pwcs</category>
      <category domain="http://securityratty.com/tag/employee">employee</category>
      <category domain="http://securityratty.com/tag/students">students</category>
      <category domain="http://securityratty.com/tag/home">home</category>
      <category domain="http://securityratty.com/tag/approximately">approximately</category>
      <source url="http://cyberinsecure.com/file-sharing-program-exposes-prince-william-county-public-school-private-records/">File Sharing Program Exposes Prince William County Public School Private Records</source>
    </item>
    <item>
      <title><![CDATA[My LA Times Op Ed on Photo ID Checks at Airport]]></title>
      <link>http://securityratty.com/article/a6c4e0b6a9a71f79c2c06446ffd85b8a</link>
      <guid>http://securityratty.com/article/a6c4e0b6a9a71f79c2c06446ffd85b8a</guid>
      <description><![CDATA[Opinion
The TSA's useless photo ID rules
No-fly lists and photo IDs are supposed to help protect the flying public from terrorists. Except that they don't work
By Bruce Schneier
August 28, 2008
The...]]></description>
      <content:encoded><![CDATA[<p>Opinion</p>

<p><a href="http://www.latimes.com/news/opinion/la-oe-schneier28-2008aug28,0,3099808.story">The TSA's useless photo ID rules</a></p>

<p>No-fly lists and photo IDs are supposed to help protect the flying public from terrorists. Except that they don't work.</p>

<p>By Bruce Schneier </p>

<p>August 28, 2008</p>

<p>The TSA is tightening its photo ID rules at airport security. Previously, people with expired IDs or who claimed to have lost their IDs were subjected to secondary screening. Then the Transportation Security Administration realized that meant someone on the government's no-fly list -- the list that is supposed to keep our planes safe from terrorists -- could just fly with no ID. </p>

<p>Now, people without ID must also answer personal questions from their credit history to ascertain their identity. The TSA will keep records of who those ID-less people are, too, in case they're trying to probe the system.</p>

<p>This may seem like an improvement, except that the photo ID requirement is a joke. Anyone on the no-fly list can easily fly whenever he wants. Even worse, the whole concept of matching passenger names against a list of bad guys has negligible security value.</p>

<p>How to fly, even if you are on the no-fly list: Buy a ticket in some innocent person's name. At home, before your flight, check in online and print out your boarding pass. Then, save that web page as a PDF and use Adobe Acrobat to change the name on the boarding pass to your own. Print it again. At the airport, use the fake boarding pass and your valid ID to get through security. At the gate, use the real boarding pass in the fake name to board your flight.</p>

<p>The problem is that it is unverified passenger names that get checked against the no-fly list. At security checkpoints, the TSA just matches IDs to whatever is printed on the boarding passes. The airline checks boarding passes against tickets when people board the plane. But because no one checks ticketed names against IDs, the security breaks down.</p>

<p>This vulnerability isn't new. It isn't even subtle. I first wrote about it in 2006. I asked Kip Hawley, who runs the TSA, about it in 2007. Today, any terrorist smart enough to Google "print your own boarding pass" can bypass the no-fly list.</p>

<p>This gaping security hole would bother me more if the very idea of a no-fly list weren't so ineffective. The system is based on the faulty notion that the feds have this master list of terrorists, and all we have to do is keep the people on the list off the planes. </p>

<p>That's just not true. The no-fly list -- a list of people so dangerous they are not allowed to fly yet so innocent we can't arrest them -- and the less dangerous "watch list" contain a combined 1 million names representing the identities and aliases of an estimated 400,000 people. There aren't that many terrorists out there; if there were, we would be feeling their effects. </p>

<p>Almost all of the people stopped by the no-fly list are false positives. It catches innocents such as Ted Kennedy, whose name is similar to someone's on the list, and Islam Yusuf (formerly Cat Stevens), who was on the list but no one knew why.</p>

<p>The no-fly list is a Kafkaesque nightmare for the thousands of innocent Americans who are harassed and detained every time they fly. Put on the list by unidentified government officials, they can't get off. They can't challenge the TSA about their status or prove their innocence. (The U.S. 9th Circuit Court of Appeals decided this month that no-fly passengers can sue the FBI, but that strategy hasn't been tried yet.) </p>

<p>But even if these lists were complete and accurate, they wouldn't work. Timothy McVeigh, the Unabomber, the D.C. snipers, the London subway bombers and most of the 9/11 terrorists weren't on any list before they committed their terrorist acts. And if a terrorist wants to know if he's on a list, the TSA has approved a convenient, $100 service that allows him to figure it out: the Clear program, which issues IDs to "trusted travelers" to speed them through security lines. Just apply for a Clear card; if you get one, you're not on the list.</p>

<p>In the end, the photo ID requirement is based on the myth that we can somehow correlate identity with intent. We can't. And instead of wasting money trying, we would be far safer as a nation if we invested in intelligence, investigation and emergency response -- security measures that aren't based on a guess about a terrorist target or tactic.</p>

<p>That's the TSA: Not doing the right things. Not even doing right the things it does.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=0Nd83L"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=0Nd83L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=Uz4JRL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=Uz4JRL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 01 Sep 2008 01:15:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/no-fly list">no-fly list</category>
      <category domain="http://securityratty.com/tag/airport">airport</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security hole">security hole</category>
      <category domain="http://securityratty.com/tag/transportation security administration">transportation security administration</category>
      <category domain="http://securityratty.com/tag/photo">photo</category>
      <category domain="http://securityratty.com/tag/ids">ids</category>
      <category domain="http://securityratty.com/tag/matches ids">matches ids</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/my_la_times_op.html">My LA Times Op Ed on Photo ID Checks at Airport</source>
    </item>
  </channel>
</rss>
