<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: reuters]]></title>
    <link>http://securityratty.com/tag/reuters</link>
    <description></description>
    <pubDate>Tue, 03 Jun 2008 07:28:32 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Blue Box #81: iSkoot vulnerability, OFCOM legislation, VoIP security news and more]]></title>
      <link>http://securityratty.com/article/40c512ffa3724f6d4a41f0c63caad84d</link>
      <guid>http://securityratty.com/article/40c512ffa3724f6d4a41f0c63caad84d</guid>
      <description><![CDATA[Synopsis: Blue Box #81: iSkoot vulnerability, OFCOM legislation, VoIP security news and more
Welcome to Blue Box: The VoIP Security Podcast #81, a 42-minute podcast from Dan York and Jonathan Zar...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #81: iSkoot vulnerability, OFCOM legislation, VoIP security news and more</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #81, a 42-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-081-2008-05-21.mp3">Download the show here</a> (MP3, 19MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on May 21, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-081-2008-05-21.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-081-2008-05-21.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>
<li>Programming notes:
	<ul>
	<li>Note about the hiatus</li>
	</ul>
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/26/are-your-skype-username-and-password-completely-exposed-if-you-use-iskoot/">Are your Skype username and password completely exposed if you use iSkoot?</a></li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/28/chronology-of-the-blogosphere-and-iskoot-weekend-response-to-the-iskoot-security-issue/">Chronology</a></li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/28/iskoot-disclosure-of-skype-credentials-resolved-new-version-by-wednesday/">iSkoot disclosure of Skype credentials resolved &#8211; new version by Wednesday</a></li>
<li><a href="http://www.ofcom.org.uk/media/news/2007/12/nr_22071205">Ofcom confirms VoIP providers must provide access to 999 and 112</a> &#8211; and Hannes Tschofenig points to <a href="http://www.emergency-services-coordination.info/esw4.html">4th Emergency Services Coordination Workshop</a> and <a href="http://www.tschofenig.priv.at/twiki/pub/EmergencyServices/EswAgenda2008/BT-ES_SDO_April_08.ppt">presentation about the UK</a></li>
<li>MarketingVOX: <a href="http://www.marketingvox.com/british-proposal-may-force-isps-to-fork-over-online-activity-emails-voip-calls-038702/">British Proposal May Force ISPs to Fork Over Online Activity, Emails, <span class="caps">VOIP </span>Calls</a> pointing to Reuters article: <a href="http://www.reuters.com/article/lifestyleMolt/idUSL2076461020080520">Britain mulls plan to store all email and calls</a></li>

<p><li>Enterprise VoIP Planet: <a href="http://www.voipplanet.com/solutions/article.php/3747161">VoIP Security: <span class="caps">SIP</span>-Versatile but Vulnerable</a></li><br />
		<li><span class="caps">IT </span>Business Edge: <a href="http://www.itbusinessedge.com/blogs/cip/?p=343">Pay Attention to VoIP Security Before The Storm</a></li></p>

<p><li>NetworkWorld: <a href="http://www.pcworld.com/businesscenter/article/145272/guide_to_voip_security.html">Business Guide to VoIP Security</a></li><br />
<li>Pocket-lint: <a href="http://www.pocket-lint.co.uk/news/news.phtml/14768/15792/Fraudsters-targeting-internet-phone-services.phtml">Fraudsters targeting VoIP Users</a> based on <a href="http://www.voip-news.co.uk/2008/05/21/newport-networks-highlights-voip-security/">report out of Newport Networks</a> (reported in VoIP News) &#8211; also covered at Fierce VoIP: <a href="http://www.fiercevoip.com/story/newport-networks-riles-voip-security-fears/2008-05-18">Newport Networks riles up VoIP Security Fears</a> and Computeractive: <a href="http://www.computeractive.co.uk/personal-computer-world/news/2216851/phreak-voip">Phreak-out over VoIP</a> and <a href="http://www.thetechherald.com/article.php/200821/1017/Newport-Networks-raises-VoIP-identity-theft-concerns">TechHerald article</a></li><br />
<li>Network World: <a href="http://www.networkworld.com/newsletters/converg/2008/042808converge1.html">Security and management considerations when deploying <span class="caps">OCS</span></a></li><br />
<li>LXer: <a href="http://lxer.com/module/newswire/view/102328/">Secure Calling Initiative Reaches Second Milestone</a> pointing to <a href="http://www.gnutelephony.org/index.php/Secure_Call">Secure Calling Initiative</a></li><br />
	<br />
	<li>[H]Enthusiast: <a href="http://www.hardocp.com/news.html?news=MzI0NjMsLCxoZW50aHVzaWFzdCwsLDE">Mobile Phones, VoIP Not Secure, Experts Warn</a>=</li><br />
	<br />
	<li>VoIP News: <a href="http://www.voip-news.com/feature/essential-guide-voip-privacy-042308/">The Essential Guide to VoIP Privacy</a></li><br />
	<br />
	<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/18/information-week-interviews-securelogix-about-voip-security/">Information Week interviews SecureLogix about VoIP security</a></li><br />
<li>eWeek: <a href="http://www.eweek.com/c/a/Knowledge-Center/VoIP-Security-through-Responsible-Software-Development/">VoIP Security through Responsible Software Development</a></li><br />
<li><a href="http://techdirt.com/articles/20080429/095514977.shtml">Microsoft gives back door keys to Vista to police</a></li><br />
<li>Comment (blog) from <a href="http://www.blueboxpodcast.com/2008/03/blue-box-77-sky.html#comment-108655562">Martyn Davies</a></li><br />
		<li>Comment (email) from Detlef</li><br />
		<li>Comment (email) from Dan McGinn-Combs</li><br />
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>41:43 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>
]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 17:16:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip users based">voip users based</category>
      <category domain="http://securityratty.com/tag/enterprise voip planet">enterprise voip planet</category>
      <category domain="http://securityratty.com/tag/voip calls">voip calls</category>
      <category domain="http://securityratty.com/tag/voip privacy">voip privacy</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/voip news">voip news</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <source url="http://www.blueboxpodcast.com/2008/08/blue-box-81-isk.html">Blue Box #81: iSkoot vulnerability, OFCOM legislation, VoIP security news and more</source>
    </item>
    <item>
      <title><![CDATA[Blue Box #81: iSkoot vulnerability, OFCOM legislation, VoIP security news and more]]></title>
      <link>http://securityratty.com/article/133c80b2a9536649a83e82483659eb92</link>
      <guid>http://securityratty.com/article/133c80b2a9536649a83e82483659eb92</guid>
      <description><![CDATA[Synopsis: Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more
Welcome to Blue Box: The VoIP Security Podcast #80, a...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #80: VoIPShield vulnerabilities, what is ethical disclosure?, SIP trunking, VoIP security news, new nomadism, and much more...</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #80, a 44-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a rel="enclosure" href="http://media.libsyn.com/media/lodestar/BBP-081-2008-05-21.mp3">Download the show here</a> (MP3, 19MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

<p><strong>NOTE: </strong><em>This show was originally recorded on April 21, 2008. </em></p> 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-081-2008-05-21.mp3" type="application/x-shockwave-flash"><param value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-081-2008-05-21.mp3&amp;bgcolor=#FFFFFF" name="movie" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 

<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>
<li>Programming notes:
	<ul>
	<li>Note about the hiatus</li>
	</ul>
<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/26/are-your-skype-username-and-password-completely-exposed-if-you-use-iskoot/">Are your Skype username and password completely exposed if you use iSkoot?</a></li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/28/chronology-of-the-blogosphere-and-iskoot-weekend-response-to-the-iskoot-security-issue/">Chronology</a></li>
		<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/28/iskoot-disclosure-of-skype-credentials-resolved-new-version-by-wednesday/">iSkoot disclosure of Skype credentials resolved &#8211; new version by Wednesday</a></li>
<li><a href="http://www.ofcom.org.uk/media/news/2007/12/nr_22071205">Ofcom confirms VoIP providers must provide access to 999 and 112</a> &#8211; and Hannes Tschofenig points to <a href="http://www.emergency-services-coordination.info/esw4.html">4th Emergency Services Coordination Workshop</a> and <a href="http://www.tschofenig.priv.at/twiki/pub/EmergencyServices/EswAgenda2008/BT-ES_SDO_April_08.ppt">presentation about the UK</a></li>
<li>MarketingVOX: <a href="http://www.marketingvox.com/british-proposal-may-force-isps-to-fork-over-online-activity-emails-voip-calls-038702/">British Proposal May Force ISPs to Fork Over Online Activity, Emails, <span class="caps">VOIP </span>Calls</a> pointing to Reuters article: <a href="http://www.reuters.com/article/lifestyleMolt/idUSL2076461020080520">Britain mulls plan to store all email and calls</a></li>

<p><li>Enterprise VoIP Planet: <a href="http://www.voipplanet.com/solutions/article.php/3747161">VoIP Security: <span class="caps">SIP</span>-Versatile but Vulnerable</a></li><br />
		<li><span class="caps">IT </span>Business Edge: <a href="http://www.itbusinessedge.com/blogs/cip/?p=343">Pay Attention to VoIP Security Before The Storm</a></li></p>

<p><li>NetworkWorld: <a href="http://www.pcworld.com/businesscenter/article/145272/guide_to_voip_security.html">Business Guide to VoIP Security</a></li><br />
<li>Pocket-lint: <a href="http://www.pocket-lint.co.uk/news/news.phtml/14768/15792/Fraudsters-targeting-internet-phone-services.phtml">Fraudsters targeting VoIP Users</a> based on <a href="http://www.voip-news.co.uk/2008/05/21/newport-networks-highlights-voip-security/">report out of Newport Networks</a> (reported in VoIP News) &#8211; also covered at Fierce VoIP: <a href="http://www.fiercevoip.com/story/newport-networks-riles-voip-security-fears/2008-05-18">Newport Networks riles up VoIP Security Fears</a> and Computeractive: <a href="http://www.computeractive.co.uk/personal-computer-world/news/2216851/phreak-voip">Phreak-out over VoIP</a> and <a href="http://www.thetechherald.com/article.php/200821/1017/Newport-Networks-raises-VoIP-identity-theft-concerns">TechHerald article</a></li><br />
<li>Network World: <a href="http://www.networkworld.com/newsletters/converg/2008/042808converge1.html">Security and management considerations when deploying <span class="caps">OCS</span></a></li><br />
<li>LXer: <a href="http://lxer.com/module/newswire/view/102328/">Secure Calling Initiative Reaches Second Milestone</a> pointing to <a href="http://www.gnutelephony.org/index.php/Secure_Call">Secure Calling Initiative</a></li><br />
	<br />
	<li>[H]Enthusiast: <a href="http://www.hardocp.com/news.html?news=MzI0NjMsLCxoZW50aHVzaWFzdCwsLDE">Mobile Phones, VoIP Not Secure, Experts Warn</a>=</li><br />
	<br />
	<li>VoIP News: <a href="http://www.voip-news.com/feature/essential-guide-voip-privacy-042308/">The Essential Guide to VoIP Privacy</a></li><br />
	<br />
	<li>Voice of <span class="caps">VOIPSA</span>: <a href="http://voipsa.org/blog/2008/04/18/information-week-interviews-securelogix-about-voip-security/">Information Week interviews SecureLogix about VoIP security</a></li><br />
<li>eWeek: <a href="http://www.eweek.com/c/a/Knowledge-Center/VoIP-Security-through-Responsible-Software-Development/">VoIP Security through Responsible Software Development</a></li><br />
<li><a href="http://techdirt.com/articles/20080429/095514977.shtml">Microsoft gives back door keys to Vista to police</a></li><br />
<li>Comment (blog) from <a href="http://www.blueboxpodcast.com/2008/03/blue-box-77-sky.html#comment-108655562">Martyn Davies</a></li><br />
		<li>Comment (email) from Detlef</li><br />
		<li>Comment (email) from Dan McGinn-Combs</li><br />
<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list&nbsp; </li><br />
<li>Wrap-up of the show </li><br />
<li>41:43 - End of show&nbsp; </li></ul> <p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=labVEA"><img src="http://feeds.feedburner.com/~a/BlueBox?i=labVEA" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=PJqInK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=PJqInK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=DKnQRK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=DKnQRK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=0ojlsK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=0ojlsK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=zQkKxK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=zQkKxK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=j1XWBk"><img src="http://feeds.feedburner.com/~f/BlueBox?i=j1XWBk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=t89cyK"><img src="http://feeds.feedburner.com/~f/BlueBox?i=t89cyK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/375722849" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 16:16:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/voip security news">voip security news</category>
      <category domain="http://securityratty.com/tag/voip users based">voip users based</category>
      <category domain="http://securityratty.com/tag/enterprise voip planet">enterprise voip planet</category>
      <category domain="http://securityratty.com/tag/voip calls">voip calls</category>
      <category domain="http://securityratty.com/tag/voip privacy">voip privacy</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/voip news">voip news</category>
      <category domain="http://securityratty.com/tag/voip security podcast">voip security podcast</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/375722849/blue-box-81-isk.html">Blue Box #81: iSkoot vulnerability, OFCOM legislation, VoIP security news and more</source>
    </item>
    <item>
      <title><![CDATA[FaceTime wins lawsuit against Thomson Reuters over IM code]]></title>
      <link>http://securityratty.com/article/ac0a5d55111401fcc38a631572924217</link>
      <guid>http://securityratty.com/article/ac0a5d55111401fcc38a631572924217</guid>
      <description><![CDATA[FaceTime won a legal battle that ordered Thomson Reuters to stop using its code for archiving instant messages, but Thomson Reuters said it is using a different application that will enable its...]]></description>
      <content:encoded><![CDATA[FaceTime won a legal battle that ordered Thomson Reuters to stop using its code for archiving instant messages, but Thomson Reuters said it is using a different application that will enable its customers to continue using the IM service without interruption.
<p><a href="http://feeds.computerworld.com/~a/Computerworld/Security/News?a=mkHHdR"><img src="http://feeds.computerworld.com/~a/Computerworld/Security/News?i=mkHHdR" border="0"></img></a></p><img src="http://feeds.computerworld.com/~r/Computerworld/Security/News/~4/351944949" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 31 Jul 2008 09:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/thomson reuters">thomson reuters</category>
      <category domain="http://securityratty.com/tag/facetime">facetime</category>
      <category domain="http://securityratty.com/tag/legal battle">legal battle</category>
      <category domain="http://securityratty.com/tag/code">code</category>
      <category domain="http://securityratty.com/tag/instant messages">instant messages</category>
      <category domain="http://securityratty.com/tag/enable">enable</category>
      <category domain="http://securityratty.com/tag/stop">stop</category>
      <category domain="http://securityratty.com/tag/application">application</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <source url="http://feeds.computerworld.com/~r/Computerworld/Security/News/~3/351944949/article.do">FaceTime wins lawsuit against Thomson Reuters over IM code</source>
    </item>
    <item>
      <title><![CDATA[Can The Gov Be Trusted With Your Personal Data?]]></title>
      <link>http://securityratty.com/article/f09583068525ca2d56abe689ff8ea4e0</link>
      <guid>http://securityratty.com/article/f09583068525ca2d56abe689ff8ea4e0</guid>
      <description><![CDATA[Survey says(insert buzzer noise
Faith in the (UK) govs ability to securely manage personal data is out the window
From Reuters
The inquiries followed Britains biggest data loss scandal, when two discs...]]></description>
      <content:encoded><![CDATA[<p>Survey says&#8230;(insert buzzer noise)</p>
<p>Faith in the (UK) gov&#8217;s ability to securely manage personal data is out the window. </p>
<p>From Reuters:</p>
<blockquote><p>The inquiries followed Britain’s biggest data loss scandal, when two discs containing child benefit records, including names, addresses and bank details, of some 25 million people, went missing after being put in the post by a junior employee.</p>
<p>The reports concluded that it wasn’t individuals who were to blame - some 30 were officials played some role in events leading to the loss of the discs - but institutional and systematic failures at Britain’s tax authority.</p>
<p>But the HMRC is not alone in such security breaches. A separate report into a stolen laptop containing the details of 600,000 potential recruits revealed similar failings at the Ministry of Defence. In all, four MoD computers had been stolen since 2004 and the report said the MoD was probably in breach of several principles set out in the Data Protection Act.</p></blockquote>
<p>Well, where do you stand? Do you trust your respective government not to punt on data security? </p>
<p>Read on.</p>
<p><a href="http://blogs.reuters.com/uknews/2008/06/25/can-the-government-be-trusted-with-your-personal-data/">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=770kXb"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=770kXb" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=pFZPzI"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=pFZPzI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=hm8i3i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=hm8i3i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=pnvfai"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=pnvfai" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=en11wi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=en11wi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=EkCewi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=EkCewi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/320499028" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 26 Jun 2008 08:44:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/loss">loss</category>
      <category domain="http://securityratty.com/tag/data loss scandal">data loss scandal</category>
      <category domain="http://securityratty.com/tag/britains">britains</category>
      <category domain="http://securityratty.com/tag/britains tax authority">britains tax authority</category>
      <category domain="http://securityratty.com/tag/data protection act">data protection act</category>
      <category domain="http://securityratty.com/tag/details">details</category>
      <category domain="http://securityratty.com/tag/child benefit records">child benefit records</category>
      <category domain="http://securityratty.com/tag/mod computers">mod computers</category>
      <category domain="http://securityratty.com/tag/bank details">bank details</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/320499028/">Can The Gov Be Trusted With Your Personal Data?</source>
    </item>
    <item>
      <title><![CDATA[Security Briefing: June 12th]]></title>
      <link>http://securityratty.com/article/b2893d182cde9224ef787f6e8fd1b0ef</link>
      <guid>http://securityratty.com/article/b2893d182cde9224ef787f6e8fd1b0ef</guid>
      <description><![CDATA[Well, imagine that. I received this email at 9:31 am yesterday from the marketing folks at Infosecurity Canada
Sorry DaveI will make arrangements for a badge to be ready for pick up at...]]></description>
      <content:encoded><![CDATA[<p><center><img src='http://www.liquidmatrix.org/blog/wp-content/uploads/2007/09/newspapera.jpg' alt='newspapera.jpg' /></center></p>
<p>Well, imagine that. I received this email at 9:31 am yesterday from the marketing folks at Infosecurity Canada.</p>
<blockquote><p>Sorry Dave&#8230;I will make arrangements for a badge to be ready for pick up at pre-registration.</p></blockquote>
<p>Um, yeah see I was on the other side of the city. At least Myrcurial is on the ground. Maybe he&#8217;ll grace us with an update.</p>
<p>Click here to <a href="http://feeds.feedburner.com/Liquidmatrix">subscribe to Liquidmatrix Security Digest!</a>. </p>
<p>And now, the news&#8230;</p>
<ol>
<li><a href="http://www.guardian.co.uk/technology/2008/jun/12/hitechcrime.law">Banks slip through virus loophole</a> | The Guardian UK</li>
<li><a href="http://computerworld.com/action/article.do?command=viewArticleBasic&#038;taxonomyName=cybercrime_and_hacking&amp;articleId=9097018&#038;taxonomyId=82&amp;intsrc=kc_top">Danish filter catches Romanian child-porn sites</a> | Computer World</li>
<li><a href="http://www.intelligencer.ca/ArticleDisplay.aspx?e=1069804&amp;auth=BY+W.+BRICE+MCVICAR%2C+THE+INTELLIGENCER">City officials confident information is secure</a> (<i>This is funny. They&#8217;re claiming 15 char password is secure. Sigh</i>)| Belleville Intelligencer</li>
<li><a href="http://www.sophos.com/pressoffice/news/articles/2008/06/bentley-imprisoned.html">Sophos assists Computer Crime Unit in bringing botnet master to justice</a> | Sophos Press</li>
<li><a href="http://www.upi.com/Top_News/2008/06/11/US_warns_on_Olympics_computer_security/UPI-89951213195000/">U.S. warns on Olympics computer security</a> | UPI</li>
<li><a href="http://www.reuters.com/article/internetNews/idUSN1138948520080612">Lawmakers accuse China of hacking computers</a> | Reuters</li>
<li><a href="http://ap.google.com/article/ALeqM5gJxb1IN1QhieBsB9jEUqW611sBCgD918I31O0">China denies hacking into US computers</a> | Associated Press</li>
<li><a href="http://www.customer-strategy.co.uk/csnews/index.cfm?ccs=584&amp;cs=3598">Customer fears grow after mass hacking of retail website</a> | Customer Strategy</li>
<li><a href="http://www.usatoday.com/news/health/2008-06-11-online-medical-records_N.htm">Online medical records offer convenience, may limit privacy</a> | USA Today</li>
</ol>
<p> Tags: <a href="http://technorati.com/tag/News" rel="tag">News</a>, <a href="http://technorati.com/tag/Daily+Links" rel="tag"> Daily Links</a>, <a href="http://technorati.com/tag/Security+Blog" rel="tag"> Security Blog</a>, <a href="http://technorati.com/tag/Information+Security" rel="tag"> Information Security</a>, <a href="http://technorati.com/tag/Security+News" rel="tag"> Security News</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=OIJJnl"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=OIJJnl" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=uZuatI"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=uZuatI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=BzURVi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=BzURVi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=woRJki"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=woRJki" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=TEz8ji"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=TEz8ji" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=vg3MLi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=vg3MLi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/310450703" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 12 Jun 2008 10:52:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security news">security news</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <category domain="http://securityratty.com/tag/lawmakers accuse china">lawmakers accuse china</category>
      <category domain="http://securityratty.com/tag/sophos press">sophos press</category>
      <category domain="http://securityratty.com/tag/press">press</category>
      <category domain="http://securityratty.com/tag/olympics computer security">olympics computer security</category>
      <category domain="http://securityratty.com/tag/customer fears">customer fears</category>
      <category domain="http://securityratty.com/tag/secure">secure</category>
      <category domain="http://securityratty.com/tag/retail website">retail website</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/310450703/">Security Briefing: June 12th</source>
    </item>
    <item>
      <title><![CDATA[T-Mobile, AT&T, Starbucks Make Nice about Wi-Fi]]></title>
      <link>http://securityratty.com/article/60919a9cb82e31cad0f852bf9779cf61</link>
      <guid>http://securityratty.com/article/60919a9cb82e31cad0f852bf9779cf61</guid>
      <description><![CDATA[Starbucks informed me that it, AT&amp;T, and T-Mobile have signed a memorandum of understanding about the free Wi-Fi kerfuffle: T-Mobile filed a lawsuit a few days ago against Starbucks stating it wasn't...]]></description>
      <content:encoded><![CDATA[<p><strong>Starbucks informed me that it, AT&T, and T-Mobile have signed a memorandum of understanding about the free Wi-Fi kerfuffle:</strong> T-Mobile filed a lawsuit a few days ago against Starbucks stating it wasn't involved in discussions about its network carrying free loyalty-awarded Wi-Fi via AT&T's authentication system. Now the three companies are apparently making nice. </p>

<p>The statement from Starbucks reads: "T-Mobile, AT&T and Starbucks have entered into a memorandum of understanding to resolve their disputes and are committed to providing a high quality WiFi experience for customers, including Starbucks Rewards Customers, at Starbucks locations nationwide."</p>

<p>My interpretation is Starbucks said, oops, our bad, and they're figuring out the dollars and cents. Sometimes companies move too rapidly. T-Mobile is a quasi-jilted suitor, although they get something out of AT&T transition, too, so they're not likely to cut any slack.</p>

<p>Reuters <a href="http://news.yahoo.com/s/nm/20080611/bs_nm/starbucks_tmobile_deal_dc"><strong>confirms</strong></a> that AT&T confirms the statement. I separately confirmed with T-Mobile that the statement is accurate as well.</p>]]></content:encoded>
      <pubDate>Wed, 11 Jun 2008 06:07:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/starbucks">starbucks</category>
      <category domain="http://securityratty.com/tag/starbucks reads">starbucks reads</category>
      <category domain="http://securityratty.com/tag/t-mobile">t-mobile</category>
      <category domain="http://securityratty.com/tag/starbucks rewards customers">starbucks rewards customers</category>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/starbucks locations nationwide">starbucks locations nationwide</category>
      <category domain="http://securityratty.com/tag/att">att</category>
      <category domain="http://securityratty.com/tag/att confirms">att confirms</category>
      <category domain="http://securityratty.com/tag/t-mobile filed">t-mobile filed</category>
      <source url="http://wifinetnews.com/archives/008351.html">T-Mobile, AT&amp;T, Starbucks Make Nice about Wi-Fi</source>
    </item>
    <item>
      <title><![CDATA[T-Mobile Sues Starbucks over Premature Free Wi-Fi]]></title>
      <link>http://securityratty.com/article/9af62b0022762210a4e7cd7866ac74ff</link>
      <guid>http://securityratty.com/article/9af62b0022762210a4e7cd7866ac74ff</guid>
      <description><![CDATA[T-Mobile filed a complaint in New York's Supreme Court over the Starbucks Card Rewards free Wi-Fi launched this week: T-Mobile spokesperson Peter Dobrow said this evening that his firm was surprised...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com//images/2008/coffee_stain.jpg" align="right" hspace="5" height="100" width="150" border="0" /><strong>T-Mobile filed a complaint in New York's Supreme Court over the Starbucks Card Rewards free Wi-Fi launched this week:</strong> T-Mobile spokesperson Peter Dobrow said this evening that his firm was surprised when the free Wi-Fi was launched in every market, because T-Mobile wasn't party to that deal. "Starbucks launched this promotion without involving T-Mobile," he said. Dobrow said that T-Mobile continues to operate 95 percent of the Starbucks locations in the U.S. under contract as AT&T transitions into its role as the new operator.</p>

<p>The lawsuit, which I've read, says that T-Mobile never agreed to nor was compensated for providing free service in stores. A link to AT&T's network in all markets except San Antonio, Tex., and Bakersfield, Calif., is handled on the backend entirely by T-Mobile. The suit notes, "If AT&T or Starbucks wanted to offer 'free' Wi-Fi in non-transitioned stores for Starbucks customers, as they are now doing, they should have--and, indeed, were contractually required to--negotiate such an arrangement with T-Mobile."</p>

<p>The crux is that while T-Mobile did agree to provide free roaming to AT&T subscribers, as defined in a bilateral roaming agreement the two firms signed, T-Mobile states the agreement doesn't allow other parties to roam for free. (That's most likely why we haven't seen AT&T's roaming partners, like Boingo and iPass, appear in the login menu, too.)</p>

<p>Representatives of Starbucks immediately available on a Friday night. A <strong><a href="http://www.reuters.com/article/internetNews/idUSN0631262620080607">Reuters report quotes</a></strong> a Starbucks spokesperson who doesn't comment directly on the suit.</p>

<p>An AT&T spokesperson said via email that the company doesn't comment on other companies' lawsuits. AT&T is not a party to the suit, although it is mentioned throughout.</p>

<p>The lawsuit provides quite a bit of previously private detail about the transition agreement. T-Mobile says that the transition contract signed by all three parties, T-Mobile still had responsibility for and ownership of a market until all equipment in all stores in a defined market belong to AT&T. The agreement also called for exclusive roaming only for each party's existing subscribers in markets that were converted or still under T-Mobile's control until 4-Jan-2009.</p>

<p>T-Mobile states in the suit that they didn't learn of the planned launch of the free Wi-Fi service until 30-May-2008. </p>

<p>T-Mobile wants money, release from current obligations, and other damages. I expect that things have gone quite far for them to file a suit.</p>

<p>"We hope to come to an amicable solution, and sometimes you do have to file a complaint in order to make that happen," T-Mobile's Dobrow said. "It's easy to give something away for free if it's not yours."<br />
</p>]]></content:encoded>
      <pubDate>Fri, 06 Jun 2008 15:18:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/free wi-fi">free wi-fi</category>
      <category domain="http://securityratty.com/tag/free">free</category>
      <category domain="http://securityratty.com/tag/t-mobile">t-mobile</category>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/starbucks">starbucks</category>
      <category domain="http://securityratty.com/tag/t-mobile filed">t-mobile filed</category>
      <category domain="http://securityratty.com/tag/t-mobile continues">t-mobile continues</category>
      <category domain="http://securityratty.com/tag/provide free">provide free</category>
      <category domain="http://securityratty.com/tag/subscribers">subscribers</category>
      <source url="http://wifinetnews.com/archives/008345.html">T-Mobile Sues Starbucks over Premature Free Wi-Fi</source>
    </item>
    <item>
      <title><![CDATA[Securiy Briefing: June 6th]]></title>
      <link>http://securityratty.com/article/dd0c564dca2422cfc43519ef1455de5f</link>
      <guid>http://securityratty.com/article/dd0c564dca2422cfc43519ef1455de5f</guid>
      <description><![CDATA[Working form the home office this morning. The best kind of commute. Now, back to my research
Click here to subscribe to Liquidmatrix Security Digest
And now, the news
Google to allow third party code...]]></description>
      <content:encoded><![CDATA[<p><center><img src='http://www.liquidmatrix.org/blog/wp-content/uploads/2007/09/newspapera.jpg' alt='newspapera.jpg' /></center></p>
<p>Working form the home office this morning. The best kind of commute. Now, back to my research.</p>
<p>Click here to <a href="http://feeds.feedburner.com/Liquidmatrix">subscribe to Liquidmatrix Security Digest!</a></p>
<p>And now, the news&#8230;</p>
<ol>
<li><a href="http://www.builderau.com.au/blogs/codemonkeybusiness/viewblogpost.htm?p=339270985">Google to allow third party code in Gmail?</a> | Builder AU</li>
<li><a href="http://blogs.zdnet.com/security/?p=1248">Skype patches security policy bypassing vulnerability</a> | ZDNet</li>
<li><a href="http://www.vnunet.com/vnunet/news/2218454/experts-warn-security-dodging">Experts warn of security-dodging Trojans</a> | vnunet</li>
<li><a href="http://www.theregister.co.uk/2008/06/06/june_patch_tuesday/">Microsoft Patch Tuesday promises seven fixes</a> | The Register</li>
<li><a href="http://www.networkworld.com/news/2008/060508-security-burning-questions.html">6 burning questions about network security</a> | Network World</li>
<li><a href="http://compliancehome.com/news/SOX/12897.html">ArcSight and VeriSign Enterprise Security Services Launch Global Business Relationship</a> | Compliance Home</li>
<li><a href="http://www.reuters.com/article/domesticNews/idUSL0563953020080605">EU gives mixed response to new U.S. travel laws</a> | Reuters</li>
<li><a href="http://www.australianit.news.com.au/story/0,25197,23819648-15306,00.html">Conroy launches service to warn of e-crimes</a> | Australian IT</li>
<li><a href="http://weblog.infoworld.com/securityadviser/archives/2008/06/are_you_a_compu.html">Are you a computer security professional?</a> | InfoWorld</li>
</ol>
<p> Tags: <a href="http://technorati.com/tag/News" rel="tag">News</a>, <a href="http://technorati.com/tag/Daily+Links" rel="tag"> Daily Links</a>, <a href="http://technorati.com/tag/Security+Blog" rel="tag"> Security Blog</a>, <a href="http://technorati.com/tag/Information+Security" rel="tag"> Information Security</a>, <a href="http://technorati.com/tag/Security+News" rel="tag"> Security News</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=y1msOh"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=y1msOh" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=it2bZI"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=it2bZI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=Bidn3i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=Bidn3i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=10CdWi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=10CdWi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=7wEQFi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=7wEQFi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=9RsSyi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=9RsSyi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/306082823" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 06 Jun 2008 08:56:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security news">security news</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <category domain="http://securityratty.com/tag/experts warn">experts warn</category>
      <category domain="http://securityratty.com/tag/computer security professional">computer security professional</category>
      <category domain="http://securityratty.com/tag/conroy launches service">conroy launches service</category>
      <category domain="http://securityratty.com/tag/warn">warn</category>
      <category domain="http://securityratty.com/tag/network security">network security</category>
      <category domain="http://securityratty.com/tag/travel laws">travel laws</category>
      <category domain="http://securityratty.com/tag/mixed response">mixed response</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/306082823/">Securiy Briefing: June 6th</source>
    </item>
    <item>
      <title><![CDATA[Picture of Camera Thieves Uploaded by Eye-Fi]]></title>
      <link>http://securityratty.com/article/4060220ba0cb57ff32255f9f96098ccb</link>
      <guid>http://securityratty.com/article/4060220ba0cb57ff32255f9f96098ccb</guid>
      <description><![CDATA[This story is a bit cute, but it's true: Alison DeLauzon, Reuters reports, had her camera stolen when left an equipment bag in a restaurant in Florida. The folks who allegedly took the bag also took...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.reuters.com/article/marketsNews/idINN0534545220080605?rpc=44"><strong>This story is a bit cute, but it's true:</strong></a> Alison DeLauzon, Reuters reports, had her camera stolen when left an equipment bag in a restaurant in Florida. The folks who allegedly took the bag also took pictures of themselves, which isn't unusual. But DeLauzon had an Eye-Fi wireless Secure Digital (SD) card in her camera, received as a gift. The thieves apparently wandered by an open access point with the same SSID as one that DeLauzon had configured for use, and pictures of her baby and the thieves were uploaded to her picture-sharing account. Nifty.</p>

<p>This is reminiscent of <a href="http://db.tidbits.com/article/9608"><strong>another recent story</strong></a> in which an Apple Store employee was able to use Mac OS X 10.5 Leopard's Back to My Mac remote access software to connect to a laptop that was stolen from her apartment to grab images and screenshots of the two men alleged to have taken the laptop and other gear.</p>]]></content:encoded>
      <pubDate>Thu, 05 Jun 2008 11:09:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/thieves">thieves</category>
      <category domain="http://securityratty.com/tag/delauzon">delauzon</category>
      <category domain="http://securityratty.com/tag/camera">camera</category>
      <category domain="http://securityratty.com/tag/alison delauzon">alison delauzon</category>
      <category domain="http://securityratty.com/tag/recent story">recent story</category>
      <category domain="http://securityratty.com/tag/story">story</category>
      <category domain="http://securityratty.com/tag/apple store employee">apple store employee</category>
      <category domain="http://securityratty.com/tag/equipment bag">equipment bag</category>
      <category domain="http://securityratty.com/tag/bag">bag</category>
      <source url="http://wifinetnews.com/archives/008343.html">Picture of Camera Thieves Uploaded by Eye-Fi</source>
    </item>
    <item>
      <title><![CDATA[Personal information stolen from State Street mystery vendor]]></title>
      <link>http://securityratty.com/article/e36f5feb727edb6b2a9058889b8adb2b</link>
      <guid>http://securityratty.com/article/e36f5feb727edb6b2a9058889b8adb2b</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
5/29/08

Organization
State Street Corporation

Stock Symbol
NYSE: STT

Contractor/Consultant/Branch
Unnamed vendor hired &quot;to provide legal support...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/statestreet.jpg" align="right" height="74" width="175"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>5/29/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.statestreet.com/default.html">State Street Corporation</a> <br><br><span style="font-weight: bold;">Stock Symbol:</span><br>NYSE: STT<br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>Unnamed vendor hired "to provide legal support services"<br><br><span style="font-weight: bold;">Victims:</span><br>"employees and some customers of the former Investors Financial Services Corp. (“IBT”)"<br><br><span style="font-weight: bold;">Number Affected:</span><br>"more than 45,000"<br><br><span style="font-weight: bold;">Types of Data:</span><br>Names, addresses, dates of birth, and, in some cases, Social Security numbers.<br><br><span style="font-weight: bold;">Breach Description:</span><br>"State Street Corp. (STT) sent notices to employees and some customers of the former Investors Financial Services Corp. that computer equipment containing personal data was stolen from a vendor's facility."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://pr.statestreet.com/us/en/20080529_1.html">State Street Corporation News Release</a> <br><a href="http://www.boston.com/business/personalfinance/articles/2008/05/30/state_street_data_stolen_from_vendor/">The Boston Globe</a> <br><a href="http://money.cnn.com/news/newsfeeds/articles/djf500/200805290840DOWJONESDJONLINE000656_FORTUNE5.htm">Dow Jones Newswires via CNNMoney</a> <br><a href="http://www.bizjournals.com/boston/stories/2008/05/26/daily25.html">Boston Business Journal</a> <br><a href="http://www.cnbc.com/id/24875931">Reuters via CNBC</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>State Street Corporation<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>State Street Corp. said yesterday that a disk drive containing personal details from 5,500 employees and 40,000 customer accounts was stolen<br><br>BOSTON, MAY 29, 2008 – State Street Corporation (NYSE: STT) today began sending precautionary notifications to employees and some customers of the former Investors Financial Services Corp. (“IBT”) that computer equipment containing certain personal data was stolen from a vendor’s facility.<br><span style="font-style: italic;">[Evan] So this vendor relationship is probably governed by a vendor/third-party security policy and supporting documentation and processes, right?</span><br><br>IBT had engaged the vendor for legal support services.<br><br>the compromised information was among a batch of data sent to the analysis firm, which she declined to identify except to say it was in the United States. (A spokeswoman for State Street of Boston)<br><span style="font-style: italic;">[Evan] Why decline to identify?&nbsp; If I were someone affected by this (thank God I am not), do you think that I should have the right to know?&nbsp; After all, am I not the owner of my personal information?</span><br><br>At the time of the transfer, the data were encrypted, making it much more difficult to misuse. But the firm had unencrypted the information for its work and stored it on the hard drive that was then stolen<br><span style="font-style: italic;">[Evan] This is why data-at-rest encryption is as (or more) important that data-in-transit encryption.&nbsp; Both applications have their place in many information protection strategies.</span><br><br>Lost details included individuals' names, addresses, dates of birth, and, in some cases, Social Security numbers.<br><br>There is no evidence to date to suggest that the data has been misused or that legacy State Street customers or employees are impacted.<br><br>The theft was reported to federal authorities<br><br>the theft occurred in December and was reported to State Street in January<br><br>State Street didn't disclose the breach publicly or to individuals until yesterday because it took months to determine who was affected<br><span style="font-style: italic;">[Evan] Yeah, like more than four months!&nbsp; Let's say that only one FTE was assigned to determining what data was on the stolen computer equipment.&nbsp; One FTE x 40 hours x 17 weeks (est.) = 680 hours.</span><br><br>As a precaution, State Street is notifying legacy IBT employees and certain legacy IBT customers whose personal data was on the stolen computer equipment.<br><span style="font-style: italic;">[Evan] I don't like the word "precaution" used in notification that is a "reaction".</span><br><br>This notification process is expected to be completed shortly.<br><br>State Street has developed a dedicated section of its website with more details for the legacy IBT customers and employees who will receive these precautionary notifications. This information can be found at <a href="http://www.statestreet.com/notification">www.statestreet.com/notification</a> and includes detail about a number of credit monitoring services being made available by State Street at no cost for two years.<br><br>State Street said this was the first case of data theft in its history.<br>[Evan] State Street was <a href="http://www.statestreet.com/company/company_information/fact_sheet.html">founded in 1792</a>, and this is the first case of data theft?&nbsp; If so, that's amazing!<br><br><span style="font-weight: bold;">Contact Information:</span><br>Customers: <br>Please contact your usual customer representative. <br>Media:<br>Please contact publicrelations@statestreet.com. <br>Employees:<br>Please contact GHR Customer Service at +1 617 985 8040.<br><br><span style="font-weight: bold;">Commentary:</span><br>Make sure that your information security program takes into account the information that is shared with vendors, partners, and other third-party providers.&nbsp; There are numerous approaches that can be employed and customized to an individual business or organization.&nbsp; Most effective information security programs govern the security of confidential information shared with third-parties through policy, contractual language, standards, and periodic assessments for compliance.&nbsp; If possible, get information security personnel involved very early on in the establishment of the relationship. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/03/statestreet.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Tue, 03 Jun 2008 07:28:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/street">street</category>
      <category domain="http://securityratty.com/tag/legacy ibt customers">legacy ibt customers</category>
      <category domain="http://securityratty.com/tag/ibt">ibt</category>
      <category domain="http://securityratty.com/tag/street corp">street corp</category>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <category domain="http://securityratty.com/tag/information protection strategies">information protection strategies</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <source url="http://breachblog.com/2008/06/03/statestreet.aspx">Personal information stolen from State Street mystery vendor</source>
    </item>
  </channel>
</rss>
