<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: recipient]]></title>
    <link>http://securityratty.com/tag/recipient</link>
    <description></description>
    <pubDate>Fri, 13 Jun 2008 09:10:18 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Identity-Based Encryption]]></title>
      <link>http://securityratty.com/article/253a9af205184254981184c27db4e40d</link>
      <guid>http://securityratty.com/article/253a9af205184254981184c27db4e40d</guid>
      <description><![CDATA[Public-key cryptography offers very strong protection for electronic communications. Much of its strength comes from the use of paired keys, which are separate (but mathematically related) codes that...]]></description>
      <content:encoded><![CDATA[Public-key cryptography offers very strong protection for electronic communications. Much of its strength comes from the use of paired keys, which are separate (but mathematically related) codes that encrypt and decrypt a message; one key is public and one is known only to the recipient.]]></content:encoded>
      <pubDate>Sun, 16 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/public-key cryptography offers">public-key cryptography offers</category>
      <category domain="http://securityratty.com/tag/public">public</category>
      <category domain="http://securityratty.com/tag/key">key</category>
      <category domain="http://securityratty.com/tag/electronic communications">electronic communications</category>
      <category domain="http://securityratty.com/tag/strong protection">strong protection</category>
      <category domain="http://securityratty.com/tag/encrypt">encrypt</category>
      <category domain="http://securityratty.com/tag/recipient">recipient</category>
      <category domain="http://securityratty.com/tag/codes">codes</category>
      <category domain="http://securityratty.com/tag/message">message</category>
      <source url="http://www.networkworld.com/news/2008/111708-identity-based.html?fsrc=rss-security">Identity-Based Encryption</source>
    </item>
    <item>
      <title><![CDATA[Targeted E-Mail Attacks: The Bull's-Eye Is on You]]></title>
      <link>http://securityratty.com/article/797d1b424985ec7645636e0a12e99d2e</link>
      <guid>http://securityratty.com/article/797d1b424985ec7645636e0a12e99d2e</guid>
      <description><![CDATA[Far more dangerous than a normal e-mail attack, targeted attacks choose a particular person as the prospective victim and tailor their message to that recipient. Since their creators craft the...]]></description>
      <content:encoded><![CDATA[Far more dangerous than a normal e-mail attack, targeted at­­tacks choose a particular person as the prospective victim and tailor their message to that recipient. Since their creators craft the messages carefully (with few spelling and grammatical errors, for example), these attacks lack tell-tale indicators and thus stand a far greater chance of snaring a victim.]]></content:encoded>
      <pubDate>Wed, 12 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/prospective victim">prospective victim</category>
      <category domain="http://securityratty.com/tag/normal e-mail attack">normal e-mail attack</category>
      <category domain="http://securityratty.com/tag/victim">victim</category>
      <category domain="http://securityratty.com/tag/creators craft">creators craft</category>
      <category domain="http://securityratty.com/tag/attacks choose">attacks choose</category>
      <category domain="http://securityratty.com/tag/grammatical errors">grammatical errors</category>
      <category domain="http://securityratty.com/tag/stand">stand</category>
      <category domain="http://securityratty.com/tag/messages">messages</category>
      <category domain="http://securityratty.com/tag/recipient">recipient</category>
      <source url="http://www.networkworld.com/news/2008/111308-targeted-e-mail-attacks-the-bulls-eye.html?fsrc=rss-security">Targeted E-Mail Attacks: The Bull's-Eye Is on You</source>
    </item>
    <item>
      <title><![CDATA[Pseudo Email Marketing Tools Empowering Spammers]]></title>
      <link>http://securityratty.com/article/7568db3beb1fe59141f6ec74902d2ae7</link>
      <guid>http://securityratty.com/article/7568db3beb1fe59141f6ec74902d2ae7</guid>
      <description><![CDATA[Largely ignoring its real life applicability, a vendor of &quot;email marketing&quot; tools continues the development of a DIY spamming tools, whose features greatly evolved throughout the last couple of years....]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SQj-qLXa7XI/AAAAAAAACZs/eVrvlQbC73Y/s1600-h/marketing_spamming_6.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SQj-qLXa7XI/AAAAAAAACZs/ByNNe5khEhY/s200-R/marketing_spamming_6.gif" /></a>Largely ignoring its real life applicability, a vendor of "email marketing" tools continues the development of a DIY spamming tools, whose features greatly evolved throughout the last couple of years. Originally released in 2004, the vendor appears to have been actively improving the real-time metrics of the campaigns, next to building interactivity into the spamming process through the WYSIWYG editor.<br />
<br />
For better or worse, despite that these applications are empowering spammers and lowering down the entry barriers into spamming, the tools have gotten <a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">largely replaced</a> by the <a href="http://ddanchev.blogspot.com/2008/10/inside-managed-spam-service.html">increasing number</a> of <a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">managed spamming services</a>, whose quality assurance features of bypassing spam filters act as a main differentiation factor. Here are some of this tool's features :<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SQj3AWUp3WI/AAAAAAAACZE/IJaKNStG3tY/s1600-h/marketing_spamming_1.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="151" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SQj3AWUp3WI/AAAAAAAACZE/A906A5o9i1I/s200-R/marketing_spamming_1.gif" width="200" /></a><i>"- High speed distribution - 200,000 letters per hour.</i><br />
<i>- Contains an embedded SMTP server that allows you to send letters directly to the recipient's mailbox without using your provider's SMTP server.</i><br />
<i>-&nbsp; If you are accessing the Internet via modem, and distribution using the SMTP server, you do not fit - also allowed to send mail through any number of remote SMTP servers (relay), or via SMTP server provider.</i><br />
<i>- Support for SMTP authentication.</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SQj_l02fWvI/AAAAAAAACZ8/V9kNzRzibCQ/s1600-h/marketing_spamming_2.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SQj_l02fWvI/AAAAAAAACZ8/_uP9YfEEhEk/s200-R/marketing_spamming_2.gif" /></a><i>- Supports up to 500 concurrent streams to send to each mailing.</i><br />
<i>- Automatic caching DNS requests to speed up distribution and reducing the load on the DNS server.</i><br />
<i>- Ability to run multiple independent shots at the same time.</i><br />
<i>- Ability to suspend delivery and continue later with a point.</i><br />
<i>- All modes distribution - TO, CC, BCC and PersonalCopy. In the latter case, the program generates a personal letter to each recipient.</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SQj_VDIUypI/AAAAAAAACZ0/-Zr9CYINTlY/s1600-h/marketing_spamming_3.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SQj_VDIUypI/AAAAAAAACZ0/aJp3Ub3Uwfo/s200-R/marketing_spamming_3.gif" /></a><i>- Ability to specify the size of BCC package regimes TO, CC, and BCC.</i><br />
<i>- Ability to specify the TO: field for mailing regimes and CS BCC.</i><br />
<i>- Full emulation signature letters Outlook Express to increase cross-your-mails through spam filters.</i><br />
<i>- Support for distribution via a proxy server.</i><br />
<i>- Automatically detect the bad (non-existent) and not by E-Mail addresses directly in the process of distribution based on a flexible, user SMTP rules. Thanks SMTP rules achieved a very precise definition of bad addresses virtually no false positives.</i><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SQj3jFAM6tI/AAAAAAAACZc/Rf_WZkjuJ84/s1600-h/marketing_spamming_7.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SQj3jFAM6tI/AAAAAAAACZc/kujVnisjcjY/s200-R/marketing_spamming_7.gif" /></a><i>- Ability to create lists of addresses, depending on the specific responses of remote servers for SMTP commands.</i><br />
<i>- Organize automatically subscribe / unsubscribe to the mailing addresses.</i><br />
<i>- Perform any processing of existing lists.</i><br />
<i>- Develop a letter to the powerful WYSIWYG Html editor.</i><br />
<br />
<i>- Automatically apply to each recipient by name, as well as paste in a letter to a specific, personalized information through powerful Mail Merge templates.</i><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SQj3vx0a3PI/AAAAAAAACZk/dlmHlT-5hyw/s1600-h/marketing_spamming_8.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SQj3vx0a3PI/AAAAAAAACZk/fRcQsC-6XlY/s200-R/marketing_spamming_8.gif" /></a><i>- Set the calendar to automatically launch shots at the right time.</i><br />
<i>- Quickly send out mail.</i>"<br />
<br />
With managed spam services' on-demand, risk forwarding and completely outsourced processes, they're not only going to replace such DIY tools, but also, <a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">position them as a dynamically</a> evolving <a href="http://ddanchev.blogspot.com/2008/10/managed-fast-flux-provider-part-two.html">cybercrime platforms</a>.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=CqO0M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=CqO0M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HbgzM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HbgzM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KVshm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KVshm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wJpMm"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wJpMm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ON79M"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ON79M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nKPXM"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nKPXM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hPU3m"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hPU3m" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/436383197" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 16:28:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bad addresses">bad addresses</category>
      <category domain="http://securityratty.com/tag/addresses">addresses</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/smtp server">smtp server</category>
      <category domain="http://securityratty.com/tag/smtp server provider">smtp server provider</category>
      <category domain="http://securityratty.com/tag/e-mail addresses directly">e-mail addresses directly</category>
      <category domain="http://securityratty.com/tag/distribution">distribution</category>
      <category domain="http://securityratty.com/tag/modes distribution">modes distribution</category>
      <category domain="http://securityratty.com/tag/speed distribution">speed distribution</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/436383197/pseudo-email-marketing-tools-empowering.html">Pseudo Email Marketing Tools Empowering Spammers</source>
    </item>
    <item>
      <title><![CDATA[Assets Good Until Reached For]]></title>
      <link>http://securityratty.com/article/b4259e9d1ccfa754480b062e7acb4e32</link>
      <guid>http://securityratty.com/article/b4259e9d1ccfa754480b062e7acb4e32</guid>
      <description><![CDATA[A few months back Minyanville wondered whether this subprime mess would end up as a cancer or a car crash. Guess we know the answer now. The question is - should we be at all surprised? Some smart...]]></description>
      <content:encoded><![CDATA[<p><span style="white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;">A few months back </span></span><a href="http://www.minyanville.com/articles/football-bears-bulls-Credit-equities-fannie/index/a/18769"><span style="font-size: 12px; "><span style="font-family: Arial;">Minyanville</span></span></a><span style="white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;"> wondered whether this subprime mess would end up as a cancer or a car crash. Guess we know the answer now. The question is - should we be at all surprised?

Some smart folks have been warning for a long time. Warren Buffett famously called derivatives financial weapons of mass destruction.</span></span></p><div><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;"><br /></span></span></div><div><span style="white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;">Charlie Munger, as he is wont to do, went a bit further (from 2004):</span></span></div><div><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;"><br /></span></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #222222; line-height: 20px; font-size: 12px; "><span style="font-family: Arial;">I think a good litmus test of the mental and moral quality at any large institution [with significant derivatives exposure] would be to ask them, &quot;Do you really understand your derivatives book?&quot; Anyone who says yes is either crazy or lying.</span></span></p></blockquote><div><span style="white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;">
</span></span><div><span style="white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;">They have many other statements in the same direction, based on their own experience from buying companies that used deriviatives where they were unable to to unwind the books and figure out who owed who. At the last Berkshire Hathaway annual meeting someone asked Charlie Munger what we could learn from past blow ups about the present crisis</span></span></div><div><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;"><br /></span></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 20px; font-size: 12px; "><span style="font-family: Arial;">It was a particularly foolish mess. We talked about an idiot in the credit delivery grocery business, Webvan. Internet based delivery service for groceries -- that was smarter than what happened in mortgage business. I wish we had those Webvan people back.</span></span></p></blockquote><div><div><span style="white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;">
What can we learn from all this?
<br /></span></span></div><div><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;">Well Dan Geer launched a revolution with his </span></span><a href="http://catless.ncl.ac.uk/risks/20.06.html"><span style="font-size: 12px; "><span style="font-family: Arial;">famous speech</span></span></a><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;"> about risk management. He got the big picture part right on the security industry evolving into more risk management practices, however the examples we assumed that were right at the time, the financial industry are proving wrong. For one thing you can&#39;t manage a risk if you don&#39;t know the assets (back to Charlie Munger, emphasis added):</span></span></div><div><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;"><br /></span></span></div></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 20px; "><span style="color: #333333; line-height: 20px; font-size: 12px; "><span style="font-family: Arial;">It is crazy to allow things to get too big to fail, run with knavery. As an industry, there is a crazy culture of greed and overreaching and overconfidence trading algorithms. It is demented to allow derivative trading such that clearance risks are embedded in system. Assets are all “good until reached for” on balance sheets. We had $400m of that at general re, </span></span><span style="font-weight: bold; font-size: 12px; "><span style="font-family: Arial;">“good until reached for”</span></span><span style="color: #333333; line-height: 20px; font-size: 12px; "><span style="font-family: Arial;">. In drug business you must prove it is good. It is a crazy culture, and to some extent an evil culture. Accounting people really failed us. Accounting standards ought to be dealt with like engineering standards.</span></span></span></p></blockquote><div><div><div><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;"><br /></span></span></div><div><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;">So, yes it is about risk management, but if you build too many abstractions on top of your assets through derivative accounting and such you may find you don&#39;t have any assets when you need them. Don&#39;t fall in love with your abstractions, </span></span><a href="http://1raindrop.typepad.com/1_raindrop/2008/04/security-rules.html"><span style="font-size: 12px; "><span style="font-family: Arial;">manage your assets</span></span></a><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;">.</span></span></div><div><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;"><br /></span></span></div><div><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;">There are some clear lessons for us in Information Security, err I mean Information Risk Management.</span></span></div><div><span style="font-size: 12px; white-space: pre-wrap; "><span style="white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;">
</span></span><span style="font-style: italic; font-size: 12px; "><span style="font-family: Arial;">Margin of safety</span></span><span style="white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;">
Its our job to manage risk, but this doesn&#39;t mean that we have to build layers and layer of abstraction on top of it. It also means that we help to design, build, deploy, and operate systems with margins of safety. Understanding the failure modes and accounting for this in design. Developers (because they are supposed to) and architects (because they haven&#39;t been properly trained) focus on functional requirements, building features, but on security not so much. There are many ways to improve security in a system and they are all inadequate by themselves, but we can help find </span></span></span><a href="http://1raindrop.typepad.com/1_raindrop/2007/06/cost_effective_.html"><span style="font-size: 12px; "><span style="font-family: Arial;">cost effective improvements</span></span></a><span style="white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;">. </span></span></div><div><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;"><br /></span></span></div><div><span style="font-size: 12px; white-space: pre-wrap; "><span style="font-style: italic; font-size: 12px; "><span style="font-family: Arial;">Don&#39;t fall in love with abstractions</span></span><span style="white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;">
</span></span></span></div><div><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;">If you have a 100,000 dekstops or 100,000 servers it hard to manage. You will need to automate and to do that you need to abstract, but you should also realize that its a drawing on a whiteboard not reality. You need </span></span><a href="http://1raindrop.typepad.com/1_raindrop/2005/12/the_road_to_ass.html"><span style="font-size: 12px; "><span style="font-family: Arial;">abstraction assurance</span></span></a><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;">.&#160;</span></span></div><div><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;"><br /></span></span></div><div><a href="https://financialcryptography.com/"><span style="font-size: 12px; "><span style="font-family: Arial;">Ian Grigg</span></span></a><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;"> </span></span><a href="http://1raindrop.typepad.com/1_raindrop/2008/09/if-a-tree-falls-in-someone-elses-silo.html#comments"><span style="font-size: 12px; "><span style="font-family: Arial;">commented</span></span></a><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;"> on an earlier post</span></span></div><div><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;"><br /></span></span></div></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 12px; "><span style="font-family: Arial;">There are distinct parallels between phishing / retail payments, and the bigger investment mess. In both cases, banks would argue these are core business. In both cases, they have applied risk-based security models, and accepted some loss. In both cases, they have the ability to apply substantial experience to the monitoring, allocating and absorbing risks and losses.</span></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 12px; "><span style="font-family: Arial;"><br /></span></span><span style="color: #333333; line-height: 19px; font-size: 12px; "><span style="font-family: Arial;">In both cases, they watched and did nothing as the risks started from low, and migrated upwards. Are we at the point where regulation has killed the ability of banks to apply their (arguable) one core skill, to whit, risk-based analysis? Are banks that far out of banking that they no longer have it?</span></span></p></blockquote><div><div><div><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;"><br /></span></span></div><div><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;">So you have to remember that top down and bottom up need to be combined.</span></span></div><div><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;"><br /></span></span></div><div><span style="font-size: 12px; line-height: 14px; white-space: pre-wrap; "><span style="font-style: italic; font-size: 12px; "><span style="font-family: Arial;">Design for failure</span></span></span></div><div><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;">Dan Geer has also told the story that he sat in a large bank&#39;s risk management training, and the trainer said &quot;you may wonder why this works so well. it works because there is zero ambiguity over who owns what risk.&quot; Dan&#39;s thought was - &quot;in my field we have nothing but ambiguity.&quot; Turns out the second part was right, we have nothing but ambiguity over who owns what risk; unfortunately the financial people have much more ambiguity than they thought! So we do have a lesson here after all, and it this - when the thing you thought was true isn&#39;t, the failure mode is very ugly. </span></span><a href="http://1raindrop.typepad.com/1_raindrop/2006/01/design_for_fail.html"><span style="font-size: 12px; "><span style="font-family: Arial;">Design for failure - a</span></span></a><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;">dd layers of protection. </span></span><span style="font-size: 12px; "><span style="font-family: Arial;"><br /></span></span></div><div><span style="white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;"><br /></span></span></div><div><span style="font-size: 12px; white-space: pre-wrap; "><span style="font-style: italic; font-size: 12px; "><span style="font-family: Arial;">Keep it simple.</span></span></span></div><div><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;">They have some smart engineers at Google to be sure, but even they had </span></span><a href="http://www.identityblog.com/?p=1011"><span style="font-size: 12px; "><span style="font-family: Arial;">incredibly basic errors in their SSO</span></span></a><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;">. I have seen other obvious fails like people signing WS-Security messages, and the recipient checks for a signature but not if they trust the signer! There are so many ways to shoot yourself in the foot in a loosely coupled systems, and we have so many abstractions layered on top of each other, part of the mantra of protecting assets has to be keeping it simple.</span></span></div><div><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;"><br /></span></span></div><div><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;">So that is my list, to do all these things it requires that Infosec get in the game, understand the use cases, understand the business value (it should be abundantly clear that you can&#39;t simply rely on &quot;business people&quot; to be &quot;business experts&quot;), and that you not lose sight of the asset amidst all the abstraction. Finally, the systems we build security on are very primitive, a firewall and SSL are fine, a seatbelt was fine in 1935 and its still fine today, but there are lots of other safety controls in cars. ABS, airbags, traction control, they all protect the assets far better than in 1935, that&#39;s what we need to build.</span></span></div><div><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;"><br /></span></span></div><div><span style="line-height: 14px; white-space: pre-wrap; font-size: 12px; "><span style="font-family: Arial;">Anyone can make bad assumptions (assume you know who owns what risk) and its easy to make bad abstractions (the firewall protects the information system), but when you combine bad assumptions with bad abstractions you&#39;ll get assets that are good until reached for sooner or later</span></span></div></div></div>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 05:41:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/information risk management">information risk management</category>
      <category domain="http://securityratty.com/tag/risk management practices">risk management practices</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/assets">assets</category>
      <category domain="http://securityratty.com/tag/industry">industry</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/business people">business people</category>
      <category domain="http://securityratty.com/tag/security industry">security industry</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/assets-good-until-reached-for.html">Assets Good Until Reached For</source>
    </item>
    <item>
      <title><![CDATA[Scammers Avoid Spam Detection By Using Redirection In Adobe Flash Files And ImageShack.com Free Hosting]]></title>
      <link>http://securityratty.com/article/3ca3b30ea3e958da67db13cc2c0f1325</link>
      <guid>http://securityratty.com/article/3ca3b30ea3e958da67db13cc2c0f1325</guid>
      <description><![CDATA[Anti-spam service MessageLabs reports a new way found by scammers to bypass anti-spam filters. This time scammers are utilizing Adobe Flash files and free websites hosting services. Spam messages with...]]></description>
      <content:encoded><![CDATA[Anti-spam service MessageLabs reports a new way found by scammers to bypass anti-spam filters. This time scammers are utilizing Adobe Flash files and free websites hosting services.
Spam messages with harmless-looking content contain links to Flash-based files on free image hosting services like ImageShack.com. The commands embedded in flash files redirect the recipient to sites that [...]]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 15:59:04 +0000</pubDate>
      <category domain="http://securityratty.com/tag/files">files</category>
      <category domain="http://securityratty.com/tag/adobe flash files">adobe flash files</category>
      <category domain="http://securityratty.com/tag/flash files redirect">flash files redirect</category>
      <category domain="http://securityratty.com/tag/scammers">scammers</category>
      <category domain="http://securityratty.com/tag/bypass anti-spam filters">bypass anti-spam filters</category>
      <category domain="http://securityratty.com/tag/time scammers">time scammers</category>
      <category domain="http://securityratty.com/tag/imageshack">imageshack</category>
      <category domain="http://securityratty.com/tag/free websites">free websites</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <source url="http://cyberinsecure.com/scammers-avoid-spam-detection-by-using-redirection-in-adobe-flash-and-imageshack-hosting/">Scammers Avoid Spam Detection By Using Redirection In Adobe Flash Files And ImageShack.com Free Hosting</source>
    </item>
    <item>
      <title><![CDATA[Don't put your foot in it, Mr. President]]></title>
      <link>http://securityratty.com/article/d826a8c8ac69bcbf21bb4cc5b4cdf815</link>
      <guid>http://securityratty.com/article/d826a8c8ac69bcbf21bb4cc5b4cdf815</guid>
      <description><![CDATA[Watching the beginning of the Olympics, I was surprised to see the way President Bush was sitting

The First Lady was on one side of him (thankfully) and a Chinese looking gentleman was on the other...]]></description>
      <content:encoded><![CDATA[<a href="http://1.bp.blogspot.com/_1UFxC-OgSnA/SKXxuGNxEzI/AAAAAAAAAF4/KfNUNDfyARI/s1600-h/george-w-bush.jpg"><img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_1UFxC-OgSnA/SKXxuGNxEzI/AAAAAAAAAF4/KfNUNDfyARI/s320/george-w-bush.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5234855916132700978" /></a><br />Watching the beginning of the Olympics, I was surprised to see the way President Bush was sitting.<br /><span id="fullpost"><br />The First Lady was on one side of him (thankfully) and a Chinese looking gentleman was on the other side.  The President had his right foot resting on his left knee, thereby exposing his shoe sole.  That is a huge "no no" in Asia and the Middle East. <br /></span><br />As I said, thankfully the First Lady, Laura Bush was the recipient of the President's sole-waving but it made me wonder if he changed legs at a later stage and "flashed" the Chinese official.  I figure it was a high ranking official or else he would hardly be sat next to the President of the United States.<br /><br />What has this to do with security?  It is one of the topics we teach to our budding bodyguards during our intensive Executive Protection course in the United States and abroad.  You could have a very successful business meeting or trip, either overseas or at home, but ruin it by insulting (albeit unintentionally)a foreign guest.  It is very important for those wroking around forein nationals to be aware of their customs and traditions.  <br /><br />This is not that difficult these days with all of the materials available.  One of the best books I have found is; "Kiss, Bow or Shake Hands".  This book and others like it, will advise the reader on the correct course of action to take when dealing with people from a host of different countries.  Not that I expect the President to read the book, afterall, he must have Protocol officers to keep an eye on him.  My question is, were they brought to China? <br /><br />For the rest of us who are not lucky enough to have our own Protocol officers to keep us out of trouble, we'll just have to read the book.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 16:57:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/president">president</category>
      <category domain="http://securityratty.com/tag/president bush">president bush</category>
      <category domain="http://securityratty.com/tag/chinese official">chinese official</category>
      <category domain="http://securityratty.com/tag/official">official</category>
      <category domain="http://securityratty.com/tag/protocol officers">protocol officers</category>
      <category domain="http://securityratty.com/tag/chinese">chinese</category>
      <category domain="http://securityratty.com/tag/intensive executive protection">intensive executive protection</category>
      <category domain="http://securityratty.com/tag/book">book</category>
      <category domain="http://securityratty.com/tag/shoe sole">shoe sole</category>
      <source url="http://www.thebulletproofblog.com/2008/08/dont-put-your-foot-in-it-mr-president.html">Don't put your foot in it, Mr. President</source>
    </item>
    <item>
      <title><![CDATA[Mailing error at the University of Maryland exposes student information]]></title>
      <link>http://securityratty.com/article/a51262d40f98a67474833c65ff29621e</link>
      <guid>http://securityratty.com/article/a51262d40f98a67474833c65ff29621e</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/17/08

Organization
University of Maryland

Contractor/Consultant/Branch
Department of Transportation Services

Victims
All students registered for...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/umd.jpg" width="88" align="right" height="83"><font size="2"><b>Date Reported: </b><br>7/17/08<br><br><b>Organization: </b><br><a href="http://www.umd.edu/">University of Maryland</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.transportation.umd.edu/index.html">Department of Transportation Services</a> <br><br><span style="font-weight: bold;">Victims:</span><br>All students registered for Fall 2008 classes<br><br><span style="font-weight: bold;">Number Affected:</span><br>23,727<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, addresses, and Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>On July 1st, 2008, the University of Maryland Department of Transportation Services mailed an </font><font size="2">on-campus parking </font><font size="2">brochure to all students </font><font size="2">registered for Fall 2008 classes</font><font size="2"> as of June 15, 2008.&nbsp; Recipient Social Security numbers were inadvertently exposed on the mailing labels.<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.transportation.umd.edu/parkingmailer/">University of Maryland</a> <br><a href="http://www.wjla.com/news/stories/0708/536794.html">ABC Channel 7 News</a> <br><a href="http://www.wtop.com/?sid=1442585&amp;nid=25">WTOP FM 103.5 News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>University of Maryland<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>On July 1st, 2008, the University of Maryland’s Department of Transportation Services sent all students registered at the time, by U.S. mail, a brochure with on-campus parking information.<br><br>On July 8, 2008, the University discovered that the labels on that mailing included the addressees’ Social Security numbers.<br><span style="font-style: italic;">[Evan] Sheesh, a fraudster doesn't even have to tamper with the mail if the Social Security number is on the label.</span><br><br>The error was discovered on the morning of July 8 when calls were made to the University.<br><br>This parking mailer was sent to all individuals registered for Fall 2008 classes at the University of Maryland as of June 15, 2008.<br><br>The mailing list numbered 23,727 individuals.<br><br>In our annual effort to provide parking and transportation information to the University community, the names and addresses of all registered students was requested internally at the Department of Transportation Services for the purpose of creating mailing labels for a brochure.<br><br>This information was generated by a computer query and included names, addresses and what was believed to be University identification numbers (UIDs).<br><span style="font-style: italic;">[Evan] When writing and executing database queries, isn't it a good idea to check the results and see if the information displayed is the information you were looking for?&nbsp; I wonder if UIDs are also nine digits long like Social Security numbers are.</span><br><br>Our normal process is to remove the University ID numbers prior to mailing.<br><span style="font-style: italic;">[Evan] Is it safe to assume that "normal process" was not followed in this instance?&nbsp; If so, then why not?&nbsp; There is no mention in the school's response.</span><br><br>It was not apparent to departmental staff that these numbers not only still existed within the file, but were Social Security numbers, and not University ID numbers.<br><span style="font-style: italic;">[Evan] Not apparent?&nbsp; They were on the labels!</span><br><br>The numbers were not identified as Social Security numbers and did not show the normal spacing between digits.<br><span style="font-style: italic;">[Evan] So it would be xxxxxxxxx instead of xxx-xx-xxxx.&nbsp; What percentage of people would recognize the first set of nine digits as a SSN?</span><br><br>This mailer was sent using third class, bulk mail delivery and may not have been delivered to you yet.<br><br>Currently, there is no evidence that anyone's Social Security number has been misused.<br><br>The University apologizes and deeply regrets this unfortunate mistake.<br><br>We are initiating immediate action to ensure that this error does not recur.<br><span style="font-style: italic;">[Evan] Like what?&nbsp; Maybe train people to review their query results and follow "normal process"?</span><br><br>The University of Maryland values the critical importance of your personal information.<br><br>We strongly recommend that you take appropriate precautions to mask, black out or destroy this document after use.<br><br>In unfortunate situations like this, it is possible that dishonest people may contact you asking for personal information in the guise of offering assistance from the University.<br><span style="font-style: italic;">[Evan] Equally unfortunate is the fact that there are a lot of dishonest people.</span><br><br>Please note that the University WILL NOT contact you by phone, e-mail or in any other way requesting personal information regarding this incident.<br><br>Please do not release any personal information in response to contacts claiming to be from the University.<br><br>In response to this incident, the University, and specifically the Department of Transportation Services, has moved to severely restrict access to sensitive student and faculty/staff information; we believe the fewer individuals who have access to this data will only increase our ability to protect sensitive information.<br><br>If individuals feel that they would like to take extra steps beyond the fraud alert, the University has arranged with Equifax to make available, at no cost to them, a 12-month service that includes credit monitoring, customer care, fraud expense reimbursement insurance and access to their credit report.<br><br>If you have not received this mailer and are unsure if you are included in the affected group, please call toll-free 1(877) 935-2428, Monday - Friday, 8:30 a.m. - 5 p.m. EST.<br><br><span style="font-weight: bold;">You may contact us in one of the following ways:</span><br>By telephone: Toll-free 1(877) 935-2428, Monday-Friday, 8:30 a.m. - 5 p.m. EST<br>Via e-mail: parkingmailer@umd.edu<br>Mailing address: Regents Drive Garage, Building #202, College Park, MD 20742<br><br><span style="font-weight: bold;">Commentary:</span><br>The lack of attention to detail coupled with lack of control leads to an increase of risk of confidential information disclosure.&nbsp; Not all that uncommon. <br><br><b>Past Breaches:</b><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/18/umd.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Fri, 18 Jul 2008 05:18:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/university">university</category>
      <category domain="http://securityratty.com/tag/maryland">maryland</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/university identification">university identification</category>
      <category domain="http://securityratty.com/tag/university community">university community</category>
      <category domain="http://securityratty.com/tag/social security">social security</category>
      <category domain="http://securityratty.com/tag/addressees social security">addressees social security</category>
      <category domain="http://securityratty.com/tag/recipient social security">recipient social security</category>
      <source url="http://breachblog.com/2008/07/18/umd.aspx">Mailing error at the University of Maryland exposes student information</source>
    </item>
    <item>
      <title><![CDATA[Money Mule Recruiters use ASProx's Fast Fluxing Services]]></title>
      <link>http://securityratty.com/article/56322fa6d09fc3127cbaf772115cd182</link>
      <guid>http://securityratty.com/article/56322fa6d09fc3127cbaf772115cd182</guid>
      <description><![CDATA[Just consider this scheme for a second. A well known money mule recruitment site Cash Transfers is maintaining a fast-flux infrastructure on behalf of the Asprox botnet, that is also providing hosting...]]></description>
      <content:encoded><![CDATA[<a href="http://bp3.blogger.com/_wICHhTiQmrA/SIB2JwZOw4I/AAAAAAAAB7c/c7TMX064n4w/s1600-h/cash_transfers_money_mule_recruitment.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp3.blogger.com/_wICHhTiQmrA/SIB2JwZOw4I/AAAAAAAAB7c/CaeHtWn_06M/s200-R/cash_transfers_money_mule_recruitment.png" style="border: 0pt none ;" /></a>Just consider this scheme for a second. A well known <a href="http://www.docep.wa.gov.au/ConsumerProtection/scamnet/Scams/Cash-Transfers_Inc.html">money mule recruitment site Cash Transfers</a> is maintaining a fast-flux infrastructure on behalf of the Asprox botnet, that is also providing hosting services for several hundred domains used on the last wave of SQL injection attacks. Ironically, <a href="http://www.banksafeonline.org.uk/moneymule_explained.html">the money mule recruitment site</a> is sharing IPs with many of them. Who are these money launderers (<b>cashtransfers.tk</b>; <b>cashtransfers.eu; type53.eu</b>; <b>sid57.tk</b>; <b>catdbw.mobi</b>; <b>cdrpoex.com </b>etc.&nbsp; ) anyway?<br />
<br />
<div style="text-align: left;">"<i>Cash-Transfers Inc. is an online-to-offline international money transfer service. We offer a secure, fast, and inexpensive means of sending money from the UK to offline recipients worldwide. Recipients do not require a bank account or Internet connection to receive funds. We have teamed with select local disbursement partners to provide a convenient, secure, and cost-effective means of sending money to family, friends and business partners abroad. The basic requirements to send money/transfer money are:</i></div><i><br />
1) Senders must have Internet access and a bank account or credit/debit card to transfer money. However, recipients do not require either a bank account or Internet connection.<br />
<br />
2) Money sent through Cash-Transfers Inc. is available for pick up at the distribution partner instantly, or, in most countries, money can be delivered to the recipient in a matter of hours.<br />
<br />
3) Our local agents will call your recipient (during local business hours) to provide additional details, including: forms of identification required, hours of operation, and other locations. The sender will also receive an email confirmation with transaction details and tracking information.</i>"<br />
<br />
<div class="separator" style="text-align: left; clear: both;"><a href="http://bp0.blogger.com/_wICHhTiQmrA/SIB3agOgfJI/AAAAAAAAB7k/qtHLcMs6sVs/s1600-h/cash_transfers_asprox_SQL_injection.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://bp0.blogger.com/_wICHhTiQmrA/SIB3agOgfJI/AAAAAAAAB7k/y-aSv2_Sztk/s200-R/cash_transfers_asprox_SQL_injection.JPG" style="border: 0pt none ;" /></a></div>The fast-flux infrastructure they're currently using is also providing services to domains that are currently used, or have been used in previous SQL injection attacks. Some info on the current DNS servers used in the fast-flux :<br />
<br />
<b>ns10.cashtransfers.tk<br />
ns11.cashtransfers.tk<br />
ns1.cashtransfers.tk<br />
ns12.cashtransfers.tk<br />
ns2.cashtransfers.tk<br />
ns13.cashtransfers.tk<br />
ns3.cashtransfers.tk<br />
ns14.cashtransfers.tk<br />
ns4.cashtransfers.tk<br />
ns15.cashtransfers.tk<br />
ns5.cashtransfers.tk<br />
ns16.cashtransfers.tk<br />
ns6.cashtransfers.tk<br />
ns17.cashtransfers.tk<br />
ns7.cashtransfers.tk<br />
ns8.cashtransfers.tk</b><br />
<br />
With the distributed and dynamic hosting infrastructure courtesy of the malware infected user, scammers, spammers, phishers and malware authors are only starting to experiment with the potential abuses of such an underground ecosystem build on the foundations of compromises hosts.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br />
<b> </b><a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">Managed Fast Flux Provider</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-flux-spam-and-scams-increasing.html">Fast Flux Spam and Scams Increasing</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-fluxing-yet-another-pharmacy-scam.html">Fast Fluxing Yet Another Pharmacy Spam</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast Fluxed SQL Injected Domains</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</a><br />
<a href="http://blogs.zdnet.com/security/?p=1122">Fast-Fluxing SQL injection attacks executed from the Asprox botnet</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=aMnYfJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=aMnYfJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=wo8AkJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=wo8AkJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=22rmej"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=22rmej" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=ec2OKj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=ec2OKj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LfbMJJ"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LfbMJJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2LYf9J"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2LYf9J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2LO3zj"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2LO3zj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/338919917" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 18 Jul 2008 02:23:49 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fast">fast</category>
      <category domain="http://securityratty.com/tag/fast flux networks">fast flux networks</category>
      <category domain="http://securityratty.com/tag/money">money</category>
      <category domain="http://securityratty.com/tag/fast-flux">fast-flux</category>
      <category domain="http://securityratty.com/tag/cashtransfers">cashtransfers</category>
      <category domain="http://securityratty.com/tag/fast flux provider">fast flux provider</category>
      <category domain="http://securityratty.com/tag/fast flux spam">fast flux spam</category>
      <category domain="http://securityratty.com/tag/transfer money">transfer money</category>
      <category domain="http://securityratty.com/tag/fast-flux infrastructure">fast-flux infrastructure</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/338919917/money-mule-recruiters-use-asproxs-fast.html">Money Mule Recruiters use ASProx's Fast Fluxing Services</source>
    </item>
    <item>
      <title><![CDATA[Errant email exposed Department of Consumer Affairs personal information]]></title>
      <link>http://securityratty.com/article/ca6f5be22b8296dc3dbda7041339d863</link>
      <guid>http://securityratty.com/article/ca6f5be22b8296dc3dbda7041339d863</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
6/23/08

Organization
State of California

Contractor/Consultant/Branch
Department of Consumer Affairs

Victims
employees, contractors and board members...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/caldca.jpg" width="169" align="right" height="65"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>6/23/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.ca.gov/">State of California</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.dca.ca.gov/">Department of Consumer Affairs</a><br><br><span style="font-weight: bold;">Victims:</span><br>"employees, contractors and board members"<br><br><span style="font-weight: bold;">Number Affected:</span><br>5,000<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, Social Security numbers, salaries and job titles<br><br><span style="font-weight: bold;">Breach Description:</span><br>"The state Department of Consumer Affairs (DCA) has sent letters to 5,000 employees, contractors and board members warning them of a security breach that has compromised their names and social security numbers. "<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.capitolweekly.net/article.php?_adctlid=v%7Cjq2q43wvsl855o%7Cx7o1tt8kp1c3g5&amp;issueId=x79xdv8us2oeyp&amp;xid=x7csom3a3og08k">Capitol Weekly</a> <br><a href="http://www.centralvalleybusinesstimes.com/stories/001/?ID=9111">Central Valley Business Times</a> <br><a href="http://www.pogowasright.org/article.php?story=20080624114400847">Props to PogoWasRight</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Malcolm Maclachlan, Capitol Weekly<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>The state Department of Consumer Affairs (DCA) has sent letters to 5,000 employees, contractors and board members warning them of a security breach that has compromised their names and social security numbers.<br><br>About 2,800 of the people on the list are current, full-time employees of the DCA.<br><br>The document also included some former employees and numerous contractors, such as people who proctor state job examinations.<br><br>The rest of the names were employees and board members of the 56 professional boards and bureaus administered by the DCA, such as the Bureau of Automotive Repair and the Medical Board.<br><br>The breach occurred on June 5 or 6 when a Microsoft Word document was improperly transmitted electronically outside of the department, said DCA spokesman Russ Heimerich.<br><br>The document also contained the salaries and titles of everyone on the list, but Heimerich noted that this was public information.<br><br>"The thing that is troubling to us is that information was coupled with their social security numbers," Heimerich said.<br><span style="font-style: italic;">[Evan] Troubling to you?&nbsp; It's probably hard for the victims to have much sympathy.</span><br><br>The main danger with giving away a social security number is that it can be used to set up new credit cards, loans or purchases in someone's name.<br><br>However, a thief would generally need other information that was not included and could be harder to get, such as addresses, phone numbers and driver's license numbers.<br><span style="font-style: italic;">[Evan] Addresses and phone numbers are usually pretty easy to obtain and I would think are much easier to get than Social Security numbers.&nbsp; Unless of course, somebody emails them to you.</span><br><br>The DCA is the main state agency charged with protecting consumers in California.<br><span style="font-style: italic;">[Evan] Ironic.</span><br><br>From 2003 to 2007, it also housed the office charged with educating consumers and businesses about identity theft and fraud.<br><span style="font-style: italic;">[Evan] More Ironic</span><br><br>One agency whose employees were not on the list is the California Office of Privacy Protection (OPP).<br><br>Heimerich said the incident is still being investigated, and that he could not disclose who had received the document.<br><br>He said that so far there is no evidence that any information has been used. It was not even clear the recipient had opened the document.<br><br>"We know that it left the building and that it wound up somewhere it shouldn't have wound up," Heimerich. "We're looking into how that happened."<br><br>“We kind of know where it was sent,” Mr. Heimerich says<br><span style="font-style: italic;">[Evan] Sounds obvious, but did anyone check "Sent Items"?&nbsp; Yeah, probably.&nbsp; Seriously though, does the California DCA not log email sends and receives?&nbsp; It's hard to believe that the sender does not recall to whom they sent the email and there is no evidence of where it was sent.</span><br><br>The breach was discovered on Monday, June 9<br><span style="font-style: italic;">[Evan] It took 3 or 4 days for the DCA to discover the breach.</span><br><br>People's whose names were on the list were sent an email the next day and an official letter a week later.<br><span style="font-style: italic;">[Evan] Excellent quick notification.&nbsp; The earlier that a breach is detected and communicated to the data owner, the better.</span><br><br>Heimerich said the DCA will pay for a year of free credit reports and provide fraud insurance of up to $25,000 for everyone on the list.<br><span style="font-style: italic;">[Evan] One year of protection does not adequately protect information that has a lifespan that far exceeds that one year.&nbsp; Most bad guys (or gals) know that the "standard" organization response to a breach includes one year of free credit monitoring/protection, so many of them wait a year to use the information.&nbsp; It is also important to point out that just because a person monitors their credit, does not mean that their identity isn't being used elsewhere.&nbsp; It's a scary thought, but it's a broken system.</span><br><br>He said the DCA had not yet determined how much these protections were going to cost. <br><span style="font-style: italic;">[Evan] You can estimate the cost yourself.</span><br><br><span style="font-weight: bold;">Commentary:</span><br>I like how Microsoft Outlook helps me when I am typing an email address in the "To:" field of my email.&nbsp; It saves me some keystrokes and a few precious seconds.&nbsp; Sometimes I am in such a hurry that I don't even notice that Outlook put in the wrong email address.&nbsp; I type my email, click send and away I go onto another task.&nbsp; A couple of days later, I get a call from a customer asking where their information is.&nbsp; I state that I sent it to them a couple of days ago, but they claim to have never gotten my email.&nbsp; I look through my sent items, and HOLY #*@^!&nbsp; I just sent some confidential (sensitive and potentially damaging) information to a competitor instead of my customer.<br><br>Sound conceivable?&nbsp; Have you ever sent an embarrassing email to the wrong person?&nbsp; It is very easy to do if your not paying attention.<br><br>There are a number of controls us information security guys can put in place to reduce the risk of this happening.&nbsp; One of the best is information security training and awareness (kind of an administrative control). <br><br><span style="font-weight: bold;">Past Breaches:</span><br><span style="font-weight: bold;">State of California:</span><br>March, 2008 - <a href="http://breachblog.com/2008/03/31/caldoc.aspx">San Quentin visitor and volunteer information lost</a> </font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/24/caldca.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Tue, 24 Jun 2008 13:51:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/volunteer information lost">volunteer information lost</category>
      <category domain="http://securityratty.com/tag/wrong email address">wrong email address</category>
      <category domain="http://securityratty.com/tag/email address">email address</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/adequately protect information">adequately protect information</category>
      <category domain="http://securityratty.com/tag/credit cards">credit cards</category>
      <category domain="http://securityratty.com/tag/credit">credit</category>
      <source url="http://breachblog.com/2008/06/24/caldca.aspx">Errant email exposed Department of Consumer Affairs personal information</source>
    </item>
    <item>
      <title><![CDATA[Severance and personal details of GlaxoSmithKline employees exposed]]></title>
      <link>http://securityratty.com/article/58e91758aa8878262c367e27cb3e449c</link>
      <guid>http://securityratty.com/article/58e91758aa8878262c367e27cb3e449c</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
6/10/08

Organization
GlaxoSmithKline

Contractor/Consultant/Branch
None

Victims
Employees

Number Affected
more than 500

Types of Data
names, dates of...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/gsk.jpg" align="right" height="51" width="154"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>6/10/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.gsk.com/">GlaxoSmithKline</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Employees<br><br><span style="font-weight: bold;">Number Affected:</span><br>"more than 500"<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names, dates of birth, addresses, pensions, National Insurance numbers and, in some cases, redundancy payouts"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"GLAXO workers fear they will fall victim to fraudsters after their personal details were sent to all staff at the Ulverston site."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.nwemail.co.uk/news/barrow/1.121420">North West Evening Mail</a> <br><a href="http://www.fleetwoodtoday.co.uk/latest-north-west-news/Apology-over-emails.4174723.jp">Fleetwood Weekly News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>North West Evening Mail <br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>GLAXO workers fear they will fall victim to fraudsters after their personal details were sent to all staff at the Ulverston site.<br><br>The emails contained information such as names, dates of birth, addresses, pensions, National Insurance numbers and, in some cases, redundancy payouts, of more than 500 employees.<br><span style="font-style: italic;">[Evan] Have you ever received or sent an email to an entire group of people on accident?&nbsp; It is embarrassing.&nbsp; Add to fact that 500+ of your co-workers were just put at risk of identity theft, and now how do you feel.&nbsp; Chances are greater if you use mail client programs that automatically guess the recipient after only typing a few letters.&nbsp; I wonder if this email was sent by a person or programmatically.</span><br><br>A reliable source, who wishes to remain anonymous, says GSK staff from across south and west Cumbria are up in arms.<br><br>They fear the information has been sent out to all 110,000 employees in the UK and US.<br><span style="font-style: italic;">[Evan] Glaxo officials claim that this was not the case.</span><br><br>And some feel they could become victims of identity theft by cash-strapped workers facing redundancy.<br><br>The mails sent out all with attachments on the intranet<br><br>When they were opened up they gave details of all 540 or so workers. It had such details as their names, address, position and if they had put in for redundancy what figures they could expect.<br><span style="font-style: italic;">[Evan] Wow!&nbsp; The redunancy (or severance) payout information adds a twist to this breach.&nbsp; Not only can the personal information be used for identity theft, but a person getting a larger payout can be targeted specifically.&nbsp; Bad.</span><br style="font-style: italic;"><br>For instance one of the bosses is getting £200,000 redundancy and then a £40,000 a year pension.<br><span style="font-style: italic;">[Evan] That's a helluva payout.&nbsp; That's almost $400,000 and $80,000 US.</span><br><br>A few days after this happened a letter saying sorry was sent out to all employees.<br><span style="font-style: italic;">[Evan] "Sorry" reminds me of what my children say to me when they do something they shouldn't have done.&nbsp; </span><br><br>GSK has apologised to staff, saying it regrets the incident and has made steps to make sure the breach is never repeated.<br><span style="font-style: italic;">[Evan] How will GSK ensure that this breach is never repeated?</span><br><br>The firm claims only Ulverston workers had access to the information.<br><br>Ulverston site director Richard Pamenter say in the letter to Glaxo employees, obtained by The Evening Mail:<br><br>"I wanted to make sure you were made aware that information has been inadvertently released on both the GSK e-mail and intranet systems, which if used inappropriately, could permit access to certain personal information for staff.<br><br>"If any of these documents are used inappropriately, this could allow access to information on individuals’ date of birth, job grade, National Insurance number and home address.<br><br>"Additionally, for some staff, information on pensions, quotes and redundancy payments could be accessed. We have removed the information source from the intranet and are currently progressing the removal of documents and relevant attachments from the company email.<br><br>"We very much regret this incident has occurred and I would like to apologise unreservedly for any embarrassment or inconvenience caused."<br><br><span style="font-weight: bold;">Commentary:</span><br>This breach was not widely covered in the press and the information we know is very limited.&nbsp; I'm going to presume that this breach was the result of an employee mistake. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/13/glaxo.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Fri, 13 Jun 2008 09:10:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/details">details</category>
      <category domain="http://securityratty.com/tag/employees">employees</category>
      <category domain="http://securityratty.com/tag/personal details">personal details</category>
      <category domain="http://securityratty.com/tag/staff">staff</category>
      <category domain="http://securityratty.com/tag/fear">fear</category>
      <category domain="http://securityratty.com/tag/glaxo workers fear">glaxo workers fear</category>
      <category domain="http://securityratty.com/tag/gsk staff">gsk staff</category>
      <source url="http://breachblog.com/2008/06/13/gsk.aspx">Severance and personal details of GlaxoSmithKline employees exposed</source>
    </item>
  </channel>
</rss>
