<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: round-up]]></title>
    <link>http://securityratty.com/tag/round-up</link>
    <description></description>
    <pubDate>Mon, 10 Mar 2008 05:32:03 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Fake IE 7 Update Spam Installs Malware]]></title>
      <link>http://securityratty.com/article/4a83e9491aa7f732cbdd0af9b8dec6fa</link>
      <guid>http://securityratty.com/article/4a83e9491aa7f732cbdd0af9b8dec6fa</guid>
      <description><![CDATA[Another round of fake authority email has been launched, this time it is a bogus Internet Explorer 7 (IE7) update spam. Here is a current version of the email (it will probably change a bit soon):...]]></description>
      <content:encoded><![CDATA[Another round of fake &#8220;authority&#8221; email has been launched, this time it is a bogus Internet Explorer 7 (IE7) update spam. Here is a current version of the email (it will probably change a bit soon):
From: admin@microsoft.com
Subject: Internet Explorer 7
Message: You are receiving this e-mail because you subscribed to MSN Featured Offers. Microsoft respects your [...]]]></content:encoded>
      <pubDate>Mon, 11 Aug 2008 06:00:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/internet explorer">internet explorer</category>
      <category domain="http://securityratty.com/tag/bogus internet explorer">bogus internet explorer</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/fake authority email">fake authority email</category>
      <category domain="http://securityratty.com/tag/microsoft respects">microsoft respects</category>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/current version">current version</category>
      <category domain="http://securityratty.com/tag/bit">bit</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <source url="http://cyberinsecure.com/fake-ie-7-update-spam-installs-malware/">Fake IE 7 Update Spam Installs Malware</source>
    </item>
    <item>
      <title><![CDATA[SQL Attacks Still Inject Websites Including Government Sites In US, UK]]></title>
      <link>http://securityratty.com/article/c5429a8c759a9a3a9659af78716ec7bc</link>
      <guid>http://securityratty.com/article/c5429a8c759a9a3a9659af78716ec7bc</guid>
      <description><![CDATA[A new round of SQL injection attacks (most likely by Asprox) has infected millions of web pages belonging to businesses and government agencies, including those that belong to the National Institutes...]]></description>
      <content:encoded><![CDATA[A new round of SQL injection attacks (most likely by Asprox) has infected millions of web pages belonging to businesses and government agencies, including those that belong to the National Institutes of Health and Education Department in the US and the UK Trade &#38; Investment. It seems that a lot of domains involved are still [...]]]></content:encoded>
      <pubDate>Fri, 08 Aug 2008 06:43:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sql injection attacks">sql injection attacks</category>
      <category domain="http://securityratty.com/tag/government agencies">government agencies</category>
      <category domain="http://securityratty.com/tag/national institutes">national institutes</category>
      <category domain="http://securityratty.com/tag/web pages">web pages</category>
      <category domain="http://securityratty.com/tag/education department">education department</category>
      <category domain="http://securityratty.com/tag/asprox">asprox</category>
      <category domain="http://securityratty.com/tag/lot">lot</category>
      <category domain="http://securityratty.com/tag/businesses">businesses</category>
      <category domain="http://securityratty.com/tag/round">round</category>
      <source url="http://cyberinsecure.com/sql-attacks-still-inject-websites-including-government-sites-in-us-uk/">SQL Attacks Still Inject Websites Including Government Sites In US, UK</source>
    </item>
    <item>
      <title><![CDATA[FBI warns of new Storm Worm attacks]]></title>
      <link>http://securityratty.com/article/194f5fb83e037653d07ec3faf97667b2</link>
      <guid>http://securityratty.com/article/194f5fb83e037653d07ec3faf97667b2</guid>
      <description><![CDATA[A rash of complaints prompted the FBI to issue a warning of a new round of spam e-mails bombarding the Internet to spread the malicious Storm...]]></description>
      <content:encoded><![CDATA[A rash of complaints prompted the FBI to issue a warning of a new round of spam e-mails bombarding the Internet to spread the malicious Storm Worm.]]></content:encoded>
      <pubDate>Tue, 29 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malicious storm worm">malicious storm worm</category>
      <category domain="http://securityratty.com/tag/fbi">fbi</category>
      <category domain="http://securityratty.com/tag/spam e-mails">spam e-mails</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/complaints">complaints</category>
      <category domain="http://securityratty.com/tag/rash">rash</category>
      <category domain="http://securityratty.com/tag/round">round</category>
      <category domain="http://securityratty.com/tag/issue">issue</category>
      <category domain="http://securityratty.com/tag/spread">spread</category>
      <source url="http://www.networkworld.com/news/2008/073008-fbi-warns-of-new-storm.html?fsrc=rss-security">FBI warns of new Storm Worm attacks</source>
    </item>
    <item>
      <title><![CDATA[Security Briefing: June 24th]]></title>
      <link>http://securityratty.com/article/7c51b13e19619dcf4c3d6327c107b355</link>
      <guid>http://securityratty.com/article/7c51b13e19619dcf4c3d6327c107b355</guid>
      <description><![CDATA[Another day, another coffee
Click here to subscribe to Liquidmatrix Security Digest
And now, the news
Former SEMO Employee Found with Data Files of Personal Information of Students | KFVS 12
Ruby...]]></description>
      <content:encoded><![CDATA[<p><center><img src='http://www.liquidmatrix.org/blog/wp-content/uploads/2007/09/newspapera.jpg' alt='newspapera.jpg' /></center></p>
<p>Another day, another coffee.</p>
<p>Click here to <a href="http://feeds.feedburner.com/Liquidmatrix">subscribe to Liquidmatrix Security Digest!</a>. </p>
<p>And now, the news&#8230;</p>
<ol>
<li><a href="http://www.kfvs12.com/Global/story.asp?S=8541051&amp;nav=menu51_2_3_2">Former SEMO Employee Found with Data Files of Personal Information of Students</a> | KFVS 12</li>
<li><a href="http://www.theregister.co.uk/2008/06/23/group_patches_ruby/">Ruby flaws send security researchers into shock</a> | The Register</li>
<li><a href="http://www.earthtimes.org/articles/show/whitehat-secures-7-million-round-of-funding,442587.shtml">WhiteHat Secures $7 Million Round of Funding</a> | Earth Times</li>
<li><a href="http://www.vnunet.com/vnunet/news/2219781/uk-firm-software-licensing">UK firm offers web-based software audit</a> | vnunet</li>
<li><a href="http://www.smallbusinesscomputing.com/news/article.php/3754681">Educating Employees Reduces Security Breaches</a> | Small Business Computing</li>
<li><a href="http://blog.washingtonpost.com/securityfix/2008/06/new_trojan_leverages_unpatched.html">New Trojan Leverages Unpatched Mac Flaw</a> | Washington Post</li>
<li><a href="http://www.thestar.com/Canada/Columnist/article/447810">Secrecy an effective legal tool</a> The Star</li>
</ol>
<p> Tags: <a href="http://technorati.com/tag/News" rel="tag">News</a>, <a href="http://technorati.com/tag/Daily+Links" rel="tag"> Daily Links</a>, <a href="http://technorati.com/tag/Security+Blog" rel="tag"> Security Blog</a>, <a href="http://technorati.com/tag/Information+Security" rel="tag"> Information Security</a>, <a href="http://technorati.com/tag/Security+News" rel="tag"> Security News</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=RjuqTv"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=RjuqTv" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=Cf5AzI"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=Cf5AzI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=4pQVYi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=4pQVYi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=gTqkHi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=gTqkHi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=S9Dcti"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=S9Dcti" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=0zMsYi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=0zMsYi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/318806879" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 24 Jun 2008 07:00:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security news">security news</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <category domain="http://securityratty.com/tag/effective legal tool">effective legal tool</category>
      <category domain="http://securityratty.com/tag/washington post">washington post</category>
      <category domain="http://securityratty.com/tag/firm offers">firm offers</category>
      <category domain="http://securityratty.com/tag/whitehat secures">whitehat secures</category>
      <category domain="http://securityratty.com/tag/software audit">software audit</category>
      <category domain="http://securityratty.com/tag/security blog">security blog</category>
      <category domain="http://securityratty.com/tag/mac flaw">mac flaw</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/318806879/">Security Briefing: June 24th</source>
    </item>
    <item>
      <title><![CDATA[Another Round Of Fake Breaking News Spam Installs Malware]]></title>
      <link>http://securityratty.com/article/c318c181e646b9a98b063bbbce99de6d</link>
      <guid>http://securityratty.com/article/c318c181e646b9a98b063bbbce99de6d</guid>
      <description><![CDATA[Nuwar spammers have recently moved from real news of natural disasters and current affairs to creating their own fictional events in an attempt to infect users computers. This new high volume spam...]]></description>
      <content:encoded><![CDATA[Nuwar spammers have recently moved from real news of natural disasters and current affairs to creating their own fictional events in an attempt to infect users computers. This new high volume spam campaign is using some attention drawing subjects to lure people into clicking on the links.
The spam message has a list of newsworthy subjects [...]]]></content:encoded>
      <pubDate>Sat, 21 Jun 2008 18:43:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/volume spam campaign">volume spam campaign</category>
      <category domain="http://securityratty.com/tag/infect users computers">infect users computers</category>
      <category domain="http://securityratty.com/tag/subjects">subjects</category>
      <category domain="http://securityratty.com/tag/newsworthy subjects">newsworthy subjects</category>
      <category domain="http://securityratty.com/tag/recently moved">recently moved</category>
      <category domain="http://securityratty.com/tag/natural disasters">natural disasters</category>
      <category domain="http://securityratty.com/tag/real news">real news</category>
      <category domain="http://securityratty.com/tag/fictional events">fictional events</category>
      <category domain="http://securityratty.com/tag/spam message">spam message</category>
      <source url="http://cyberinsecure.com/another-round-of-fake-breaking-news-spam-installs-malware/">Another Round Of Fake Breaking News Spam Installs Malware</source>
    </item>
    <item>
      <title><![CDATA[Spring ISD mobile devices stolen along with personal student information]]></title>
      <link>http://securityratty.com/article/f51f56449615943eec1d39d3cb6103f3</link>
      <guid>http://securityratty.com/article/f51f56449615943eec1d39d3cb6103f3</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
5/16/08

Organization
Spring Independent School District (&quot;Spring ISD

Contractor/Consultant/Branch
None

Victims
Students

Number Affected
8,000

Types...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/springisd.jpg" align="right" height="90" width="194"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>5/16/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.springisd.org/default.aspx?name=homepage">Spring Independent School District ("Spring ISD")</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Students<br><br><span style="font-weight: bold;">Number Affected:</span><br>~8,000<br><br><span style="font-weight: bold;">Types of Data:</span><br>"personal information, including name, social security number or state-assigned identification number, gender, name of school, grade and birthday"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"Spring ISD has been informing the parents of about 8,000 students of an incident that occurred in the evening on Wednesday, May 14 that involves the students’ personal information. The Spring ISD testing coordinator’s car was broken into while she was making a stop at a business on her way home from work that evening and a Spring ISD laptop computer and an external flash drive were stolen."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.springisd.org/default.aspx?name=may08.laptop">Spring ISD News</a> <br><a href="http://www.chron.com/disp/story.mpl/metropolitan/5786308.html">Houston Chronicle</a> <br><a href="http://abclocal.go.com/ktrk/story?section=news/local&amp;id=6146241">ABC Channel 13 News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Spring ISD<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Spring ISD has been informing the parents of about 8,000 students of an incident that occurred in the evening on Wednesday, May 14 that involves the students’ personal information.<br><br>The Spring ISD testing coordinator’s car was broken into while she was making a stop at a business on her way home from work that evening and a Spring ISD laptop computer and an external flash drive were stolen.<br><span style="font-style: italic;">[Evan] The fact that the district allows personal student information to be stored on mobile devices is very troubling.&nbsp; There is no mention of encryption, so I will assume that there was none.&nbsp; This is very careless.</span><br><br>The coordinator's computer bag was stolen from her vehicle between 5:30 and 7 p.m. Wednesday when she stopped to run an errand near Mason Road and Beltway 8, on her way home from work<br><br>The coordinator had the laptop, Curry said, because the job responsibilities often require her to work nights and weekends.<br><span style="font-style: italic;">[Evan] Fine.&nbsp; This is the reason why many organizations use laptops.&nbsp; The problem is the lack of control and security.&nbsp; If an organization decides to employ laptops, then the organization MUST ensure that they are adequately protected.</span><br style="font-style: italic;"><br>The flash drive contains the Texas Assessment of Knowledge and Skills (TAKS) results of third and fifth graders who have taken the first round of reading and math tests, eighth graders who have taken the first round of math tests and 11th and 12th graders who have taken the exit level retest.<br><br>In addition, the drive contains the students’ personal information, including name, social security number or state-assigned identification number, gender, name of school, grade and birthday.<br><span style="font-style: italic;">[Evan] Why in the *&amp;^$ does a testing coordinator have Social Security numbers on a laptop and/or flash drive?!&nbsp; A Social Security number should have no correlation to testing scores.</span><br style="font-style: italic;"><br>This also applies to students who are in those testing groups but were absent when the testing took place. <br><br>Personal phone calls were made to the parents of these students on Thursday, letters were sent home with students and the letters are being mailed to homes also in an effort to help parents quickly take steps to protect their children from identity theft.<br><br>"The district immediately contacted federal agencies to make them aware of the theft, and we are checking to see whether there is any thing else we can do on behalf of the individual students. In the meantime, we urge parents to use the information we have provided," said Regina Curry, assistant superintendent for communications and community relations. <br><br>The theft is being investigated by the Harris County Sheriff’s Department and every effort is being made to recover the equipment.<br><br>The district has reported the incident to the Texas Education Agency Test Security Task Force and will comply with whatever action they require. <br><br>"This incident is highly regrettable and the district is looking at potential security precautions to protect the students’ personal information in the future," Curry said.<br><span style="font-style: italic;">[Evan] I'm sure that the district regrets the incident, but careless acts have consequences and this should have been known beforehand.</span><br style="font-style: italic;"><br>Anyone with information about the theft is urged to call the Harris County Sheriff's Office Burglary and Theft Division at 713-967-5770 or the Spring ISD Police Department at 832-764-4911.<br><br><span style="font-weight: bold;">Commentary:</span><br>I try to be politically correct in many of my comments although sometimes I push the boundaries.&nbsp; I can't think of a word right now that adequately expresses my thoughts.&nbsp; Where was common sense?&nbsp; It could be argued that many breaches we read about entail a certain amount of dumbness, but this one definitely strikes a chord.&nbsp; <br><br>Who in their right mind would allow highly-confidential personal information to be carried around on mobile devices?&nbsp; Without encryption?&nbsp; When it isn't necessary?&nbsp; It puzzles me.<br><br>I feel like I should say more, but my high blood pressure has gone high enough for the day.&nbsp; I should rest. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/05/18/springisd.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Sun, 18 May 2008 19:01:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/students personal information">students personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/isd">isd</category>
      <category domain="http://securityratty.com/tag/students">students</category>
      <category domain="http://securityratty.com/tag/individual students">individual students</category>
      <category domain="http://securityratty.com/tag/isd laptop computer">isd laptop computer</category>
      <category domain="http://securityratty.com/tag/external flash drive">external flash drive</category>
      <category domain="http://securityratty.com/tag/drive">drive</category>
      <source url="http://breachblog.com/2008/05/18/springisd.aspx">Spring ISD mobile devices stolen along with personal student information</source>
    </item>
    <item>
      <title><![CDATA[Second edition]]></title>
      <link>http://securityratty.com/article/3ccb50d30ce934d02ac085d7ca13bcd3</link>
      <guid>http://securityratty.com/article/3ccb50d30ce934d02ac085d7ca13bcd3</guid>
      <description><![CDATA[The second edition of my book Security Engineering came out three weeks ago. Wiley have now got round to sending me the final electronic version of the book, plus permission to put half a dozen of the...]]></description>
      <content:encoded><![CDATA[<p>The second edition of my book &#8220;Security Engineering&#8221; came out three weeks ago. Wiley have now got round to sending me the final electronic version of the book, plus permission to put half a dozen of the chapters online. They&#8217;re now available for download <a href="http://www.cl.cam.ac.uk/~rja14/book.html">here</a>.</p>
<p>The chapters I&#8217;ve put online cover security psychology, banking systems, physical protection, APIs, search, social networking, elections and terrorism. That&#8217;s just a sample of how our field has grown outwards in the seven years since the first edition.</p>
<p>Enjoy!</p>
<p>Ross</p>
]]></content:encoded>
      <pubDate>Sun, 27 Apr 2008 13:10:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/edition">edition</category>
      <category domain="http://securityratty.com/tag/chapters">chapters</category>
      <category domain="http://securityratty.com/tag/chapters online">chapters online</category>
      <category domain="http://securityratty.com/tag/book security">book security</category>
      <category domain="http://securityratty.com/tag/book">book</category>
      <category domain="http://securityratty.com/tag/final electronic version">final electronic version</category>
      <category domain="http://securityratty.com/tag/weeks ago">weeks ago</category>
      <category domain="http://securityratty.com/tag/physical protection">physical protection</category>
      <category domain="http://securityratty.com/tag/grown outwards">grown outwards</category>
      <source url="http://www.lightbluetouchpaper.org/2008/04/27/second-edition/">Second edition</source>
    </item>
    <item>
      <title><![CDATA[BART Wi-Fi Access Moves Closer in Bay Area]]></title>
      <link>http://securityratty.com/article/d73122c3bc0c1f93eec67b59922f15e3</link>
      <guid>http://securityratty.com/article/d73122c3bc0c1f93eec67b59922f15e3</guid>
      <description><![CDATA[WiFi Rail may sign contract with Bay Area Rapid Transit soon: That's typical marketing fare from many companies, to pre-announce deals, but a BART official confirmed the state of negotiations in this...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/train.jpg" align="right" hspace="5" height="80" width="80" border="0" /><strong><a href="http://www.sacbee.com/103/story/847624.html">WiFi Rail may sign contract with Bay Area Rapid Transit soon:</a></strong> That's typical marketing fare from many companies, to pre-announce deals, but a BART official confirmed the state of negotiations in this Sacramento Bee article. I had a long talk with the WiFi Rail folks a few months ago, and they sent me some fascinating video of a live four-way video chat with three participants communicating from moving trains.</p>

<p>Their technical description of what they're doing makes a lot of sense, and if they can pull off their trial work in a production environment, they will have a set of patents and products that will likely be the model for deploying subway and train Wi-Fi in urban areas around the world. Yes, that's a big claim; but they have a unique and interesting solution.</p>

<p>The company told the Bee that they would start on heavily traveled underground routes first, with service available within 4 months of a contract. WiFi Rail relies on leaky coax, which is wiring that runs in the tunnel already, and they've overlaid Wi-Fi signals on in a way that simulates a very long antenna.</p>

<p>The Bee reports that they've raised $1.5m in financing so far with another round of $15m to $20m to close later this year. With a BART contract in hand, I can't imagine they'll have any difficulty getting funds. Captive audiences are worth the big bucks.</p>]]></content:encoded>
      <pubDate>Wed, 09 Apr 2008 02:39:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wifi rail">wifi rail</category>
      <category domain="http://securityratty.com/tag/wifi rail relies">wifi rail relies</category>
      <category domain="http://securityratty.com/tag/bee">bee</category>
      <category domain="http://securityratty.com/tag/sacramento bee article">sacramento bee article</category>
      <category domain="http://securityratty.com/tag/contract">contract</category>
      <category domain="http://securityratty.com/tag/sign contract">sign contract</category>
      <category domain="http://securityratty.com/tag/wifi rail folks">wifi rail folks</category>
      <category domain="http://securityratty.com/tag/overlaid wi-fi signals">overlaid wi-fi signals</category>
      <category domain="http://securityratty.com/tag/months ago">months ago</category>
      <source url="http://wifinetnews.com/archives/008265.html">BART Wi-Fi Access Moves Closer in Bay Area</source>
    </item>
    <item>
      <title><![CDATA[On Hannaford Brothers Breach and PCI]]></title>
      <link>http://securityratty.com/article/36e935406309e8e4b2c780f2055e9c97</link>
      <guid>http://securityratty.com/article/36e935406309e8e4b2c780f2055e9c97</guid>
      <description><![CDATA[So, is Hannaford Brothers breach a PCI failure? Rich Mogul discuss this here by pointing at this piece in the breach FAQ

Is it safe to continue shopping in your stores? We have continually devoted...]]></description>
      <content:encoded><![CDATA[So, is <a href="http://securosis.com/2008/03/18/picking-apart-the-hannaford-breach-what-might-have-happened/" onclick="javascript:urchinTracker('/outbound/apnews.myway.com/article/20080317/D8VFDD180.html');">Hannaford Brothers</a><a href="http://securosis.com/2008/03/18/picking-apart-the-hannaford-breach-what-might-have-happened/"> breach</a> a PCI failure? Rich Mogul discuss this <a href="http://securosis.com/2008/03/18/picking-apart-the-hannaford-breach-what-might-have-happened/">here</a> by pointing at this piece in the <a href="http://www.hannaford.com/Contents/News_Events/News/QA.shtml">breach FAQ</a>:<br /><br />"Is it safe to continue shopping in your stores?<blockquote>We have continually devoted significant round-the-clock resources to ensure Hannaford has comprehensive data security systems in place. For example, <span style="font-style: italic;">our security measures meet industry compliance standards</span> and many go above and beyond what is required by industry standards."<br /><br />Are they alluding to PCI <a href="http://www.hannaford.com/Contents/News_Events/News/QA.shtml">here</a>? I think so ... So, is this a PCI failure? Or this is simply a reflection of the fact that you CAN be 0wned, no matter how many compliance hurdles you overcame....?<br /></blockquote><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=jZDkkNF"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=jZDkkNF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=CuHfl2F"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=CuHfl2F" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/253898229" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 18 Mar 2008 11:58:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/hannaford brothers breach">hannaford brothers breach</category>
      <category domain="http://securityratty.com/tag/pci failure">pci failure</category>
      <category domain="http://securityratty.com/tag/significant round-the-clock resources">significant round-the-clock resources</category>
      <category domain="http://securityratty.com/tag/rich mogul discuss">rich mogul discuss</category>
      <category domain="http://securityratty.com/tag/industry compliance standards">industry compliance standards</category>
      <category domain="http://securityratty.com/tag/security measures">security measures</category>
      <category domain="http://securityratty.com/tag/industry standards">industry standards</category>
      <category domain="http://securityratty.com/tag/ensure hannaford">ensure hannaford</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/253898229/on-hannaford-brothers-breach-and-pci.html">On Hannaford Brothers Breach and PCI</source>
    </item>
    <item>
      <title><![CDATA[Dave Cowan of Bessemer says mid-market is the new battleground for security]]></title>
      <link>http://securityratty.com/article/9d29a834d792f015007ef9b5ff352e0c</link>
      <guid>http://securityratty.com/article/9d29a834d792f015007ef9b5ff352e0c</guid>
      <description><![CDATA[Brad Feld turned me on to this interview of Dave Cowan of Bessemer Ventures on Red Herring TV. Dave and Brad have co-invested in several deals, Postini being one of them. Dave speaks about his recent...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p> <a href="http://www.feld.com/" target="_blank">Brad Feld</a> turned me on to this interview of Dave Cowan of Bessemer Ventures on Red Herring TV.&nbsp; Dave and Brad have co-invested in several deals, Postini being one of them.&nbsp; Dave speaks about his recent involvement in a 100+ million dollar round in Perimeter Securtity, the MSSP aimed at mid-market and SMBs.&nbsp; Dave and Bessemer have invested in many security companies over they years and he has a well honed view into the space.&nbsp; His comments are that security is saturated at the top of the pyramid, meaning the Fortune 2000 and large government accounts.&nbsp; He thinks the real opportunity is at the mid-market.&nbsp; Not surprising given his recent Perimeter investment.</p>

<p>From my perspective though, I have to agree.&nbsp; I think the mid-market is a much more dynamic marketplace for security.&nbsp; You know what they say about the Fortune 500? There are only 500 of them.&nbsp; Anyway, here is the interview, but be advised the security talk is only for about the first half of the show.&nbsp; The rest is on VC stuff.</p>

<div class="wlWriterSmartContent" id="scid:5737277B-5D6D-4f48-ABFC-DD9C333F4C5D:547231bf-21d8-4a76-9f5c-0d662c91730e" style="PADDING-RIGHT: 0px; DISPLAY: inline; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; MARGIN: 0px; PADDING-TOP: 0px"><div><embed name="flashObj" pluginspage="http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash" src="http://services.brightcove.com/services/viewer/federated_f8/1263947866" width="486" height="412" type="application/x-shockwave-flash" bgcolor="#FFFFFF" flashvars="videoId=1388771269&amp;playerId=1263947866&amp;viewerSecureGatewayURL=https://services.brightcove.com/services/amfgateway&amp;servicesURL=http://services.brightcove.com/services&amp;cdnURL=http://admin.brightcove.com&amp;domain=embed&amp;autoStart=false&amp;" base="http://admin.brightcove.com" seamlesstabbing="false" swliveconnect="true"></embed></div></div></div>
]]></content:encoded>
      <pubDate>Mon, 10 Mar 2008 05:32:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/dave">dave</category>
      <category domain="http://securityratty.com/tag/dave cowan">dave cowan</category>
      <category domain="http://securityratty.com/tag/mid-market">mid-market</category>
      <category domain="http://securityratty.com/tag/bessemer">bessemer</category>
      <category domain="http://securityratty.com/tag/security companies">security companies</category>
      <category domain="http://securityratty.com/tag/dave speaks">dave speaks</category>
      <category domain="http://securityratty.com/tag/security talk">security talk</category>
      <category domain="http://securityratty.com/tag/brad">brad</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/03/dave-cowan-of-b.html">Dave Cowan of Bessemer says mid-market is the new battleground for security</source>
    </item>
  </channel>
</rss>
