<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: routine]]></title>
    <link>http://securityratty.com/tag/routine</link>
    <description></description>
    <pubDate>Thu, 12 Jun 2008 06:41:30 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Whos got your Laptop?]]></title>
      <link>http://securityratty.com/article/fdcc1cfa283eb2fc50672e381d8a9ccb</link>
      <guid>http://securityratty.com/article/fdcc1cfa283eb2fc50672e381d8a9ccb</guid>
      <description><![CDATA[Id like a receipt for you taking my lappie please. Sure


clipped from arstechnica.com

New bill would tighten rules for DHS border laptop searches



Sanchezs bill would bring more routine to the...]]></description>
      <content:encoded><![CDATA[<div > I&#8217;d like a receipt for you taking my lappie please.<br/>Sure.  </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/91B77627-B32E-4307-85A2-4EB1E258E7FB/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/4837b138-9344-4f86-ab32-b0f1976973fb/91B77627-B32E-4307-85A2-4EB1E258E7FB/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://arstechnica.com/news.ars/post/20080916-new-bill-wants-tighter-rules-for-laptop-border-searches.html" href="http://arstechnica.com/news.ars/post/20080916-new-bill-wants-tighter-rules-for-laptop-border-searches.html" style="font-size: 11px;">arstechnica.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://arstechnica.com/news.ars/post/20080916-new-bill-wants-tighter-rules-for-laptop-border-searches.html -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">
<A href="http://arstechnica.com/news.ars/post/20080916-new-bill-wants-tighter-rules-for-laptop-border-searches.html">New bill would tighten rules for DHS border laptop searches</A></div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://arstechnica.com/news.ars/post/20080916-new-bill-wants-tighter-rules-for-laptop-border-searches.html --><P><br />
Sanchez&#8217;s bill would bring more routine to the search process. The bill requires the government to draft additional rules regarding information security, the number of days a device can be retained, receipts that must be issued when devices are taken, ways to report abuses, and it requires the completion of both a privacy impact study and a civil liberties impact study. Travelers would also have the explicit right to watch as the search is conducted.<br />
</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/91B77627-B32E-4307-85A2-4EB1E258E7FB/blog/" title="blog or email this clip"><img src="http://content8.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_170908040517"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=170908040517&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=170908040517&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=170908040517&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_170908040517" /></a></P>]]></content:encoded>
      <pubDate>Wed, 17 Sep 2008 12:05:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/bill requires">bill requires</category>
      <category domain="http://securityratty.com/tag/bill">bill</category>
      <category domain="http://securityratty.com/tag/rules">rules</category>
      <category domain="http://securityratty.com/tag/draft additional rules">draft additional rules</category>
      <category domain="http://securityratty.com/tag/dhs border laptop">dhs border laptop</category>
      <category domain="http://securityratty.com/tag/sanchezs bill">sanchezs bill</category>
      <category domain="http://securityratty.com/tag/requires">requires</category>
      <category domain="http://securityratty.com/tag/privacy impact study">privacy impact study</category>
      <category domain="http://securityratty.com/tag/report abuses">report abuses</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=615">Whos got your Laptop?</source>
    </item>
    <item>
      <title><![CDATA[Automatic Email Harvesting 2.0]]></title>
      <link>http://securityratty.com/article/215d1f3ffdea93e64224f10dcdb310d4</link>
      <guid>http://securityratty.com/article/215d1f3ffdea93e64224f10dcdb310d4</guid>
      <description><![CDATA[Just when you think that email harvesting matured into user names harvesting in a true Web 2.0 style with the recently uncovered harvested IM screen names , and Youtube user lists for spammers,...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SLPj-Z2aPhI/AAAAAAAACHM/KxPZ6rpqjZs/s1600-h/email_harvesting_20.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SLPj-Z2aPhI/AAAAAAAACHM/To_TE0L7esg/s200-R/email_harvesting_20.jpg" /></a>Just <a href="http://ddanchev.blogspot.com/2006/09/email-spam-harvesting-statistics.html">when you</a> think that <a href="http://ddanchev.blogspot.com/2007/01/inside-email-harvesters-configuration.html">email harvesting</a> matured into user names harvesting in a true Web 2.0 style with the recently uncovered harvested <a href="http://ddanchev.blogspot.com/2007/10/thousands-of-im-screen-names-in-wild.html">IM screen names</a>, and <a href="http://ddanchev.blogspot.com/2008/05/harvesting-youtube-usernames-for.html">Youtube user lists</a> for spammers, phishers and malware authors to take advantage of, someone has filled in the gap that's been around as long as email harvesting has been a daily routine for spammers - dealing with text obfuscations which still remain highly popular online, once it became evident that spammers are in fact crawling for default mailto lines. This email harvesting module can be run a separate script, or get integrated as a module within any botnet, is capable of harvesting the following text obfuscations often used in order to prevent spamming crawlers : <br />
<br />
<b>mail@gmail.com <br />
mail[at]gmail.com <br />
mail[at]gmail[dot]com <br />
mail [space]gmail [space]com <br />
mail(@)gmail.com <br />
mail(a)gmail.com<br />
mail AT gmail DOT com</b><br />
<br />
The overall availability and easy of obtaining a huge percentage of valid email addresses within an organizaton, is not just resulting in the increasing <a href="http://ddanchev.blogspot.com/2008/05/segmenting-and-localizing-spam.html">segmentation and localization of spam, phishing and malware campaigns</a>, it's increasing the profit margins for the spamming providers which is now not just <a href="http://ddanchev.blogspot.com/2007/04/shots-from-malicious-wild-west-sample.html">offering verified to be 100% valid email addresses</a>, but also, can providing the foundations for spear phishing and targeted attacks.<br />
<br />
<a href="http://ddanchev.blogspot.com/2008/07/dissecting-managed-spamming-service.html">Quality assurance in spaming</a> is still in its introduction phrase, with customers starting to put the emphasis on the number of emails that actually made it through the spam filters, than the number of emails sent as <a href="http://ddanchev.blogspot.com/2007/10/managed-spamming-appliances-future-of.html">a benchmark for increasing the probability of bypassing anti spam filters</a>. Taking into consideration the big picture, sniffing for email addresses streaming out of malware infected hosts, and stealing huge email databases by exploiting vulnerable online communities, seems to be the tactics of choice for the majority of individuals whose responsibility is to continuously provide fresh and valid email addresses.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2rXjAK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2rXjAK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nGHWgK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nGHWgK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BC4Y6k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BC4Y6k" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=N6ZPDk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=N6ZPDk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Pklg3K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Pklg3K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=TfpIxK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=TfpIxK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=iTLEzk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=iTLEzk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/375213353" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 04:01:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/email addresses">email addresses</category>
      <category domain="http://securityratty.com/tag/valid email addresses">valid email addresses</category>
      <category domain="http://securityratty.com/tag/spam filters">spam filters</category>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/huge email databases">huge email databases</category>
      <category domain="http://securityratty.com/tag/anti spam filters">anti spam filters</category>
      <category domain="http://securityratty.com/tag/mail spacegmail spacecom">mail spacegmail spacecom</category>
      <category domain="http://securityratty.com/tag/mail">mail</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/375213353/automatic-email-harvesting-20.html">Automatic Email Harvesting 2.0</source>
    </item>
    <item>
      <title><![CDATA[Get Involved Now In Cloud Computing Discussions]]></title>
      <link>http://securityratty.com/article/a06cd0de4e69f284cadf864ed07e11a2</link>
      <guid>http://securityratty.com/article/a06cd0de4e69f284cadf864ed07e11a2</guid>
      <description><![CDATA[This week Amazons Simple Storage Service (S3) suffered a major outage that affected several websites that rely on the service. This is actually the second major outage for Amazon S3 this year. As a...]]></description>
      <content:encoded><![CDATA[<p><img border="0" title="Stephanie Balaouras" alt="Stephanie Balaouras" src="http://www.forrester.com/role_based/images/author/imported/forresterDotCom/Analyst_Photos/Silhouette/Color/Stephanie-Balaouras.gif" style="margin: 0px 5px 5px 0px; float: left;" /></p>
<p class="MsoNormal" style="margin: 0pt;"><span face="Times New Roman">This week Amazon’s Simple Storage Service (S3) suffered a major outage that affected several websites that rely on the service. This is actually the second major outage for Amazon S3 this year. As a result of these and other reported outages, some companies will come to question whether they should pursue these new cloud-based services in the future. I agree with </span><a href="http://www.roughtype.com/archives/2008/02/amazons_s3_util.php"><span face="Times New Roman">Nick Carr</span></a><span face="Times New Roman">, whether you’re a startup looking to rely on the cloud almost exclusively for computing power and storage capacity or you’re a brick and mortar company who may want to use SaaS services for CRM or an </span><a href="http://www.forrester.com/go?docid=42947"><span face="Times New Roman">online backup service</span></a><span face="Times New Roman">, these outages should not scare companies away from cloud-based services. Outages are inevitable; no one, not the most sophisticated internal IT shops on Wall Street, or the largest service providers can offer 100% availability all the time. </span><a href="http://status.aws.amazon.com/"><span face="Times New Roman">Amazon threw everything it had to fix the problem</span></a><span face="Times New Roman"> and was able to address the outage in several hours. How well would you be able to execute on your disaster recovery plan if you had a major outage?</span></p>

<p class="MsoNormal" style="margin: 0pt;"><span face="Times New Roman"><br /></span></p>

<p class="MsoNormal" style="margin: 0pt;"></p>













<p class="MsoNormal" style="margin: 0pt;"><span face="Times New Roman">Instead of avoiding cloud-based services, organizations need to be savvier about security and resiliency of the service provider. In fact, your organization may already be in pursuit of these services. Online backup is becoming a viable alternate to premise-based solutions for PC backup as well as remote office backup. Next will be a number of services related to information management such as </span><a href="/t/app/Local%20Settings/Temporary%20Internet%20Files/OLKF5/The%20Forrester%20Wave:%20Message%20Archiving%20Hosted%20Services,%20Q1%202008"><span face="Times New Roman">online archiving</span></a><span face="Times New Roman"> and online records management and more online storage offerings to support low cost storage. Further down the road, there will also be hosted, multi-tenancy Exchange solutions. Get involved in these discussions. Don’t take it for granted that the potential service provider has hardened data centers that meet Tier III or Tier IV classifications (these classifications describe data center site infrastructure and topology, Tier IV is the highest rating), that your data is replicated to another data center, that your data is encrypted in flight and at rest and that the service provider has strong security measures in place so that administrators can support the infrastructure but not access or even see your organization’s information.<span style="text-decoration: underline;">&nbsp;</span></span><a href="http://www.forrester.com/go?docid=43849"><span face="Times New Roman">Organizations should have consistent processes before, during and after the contracts have been signed. </span></a><span face="Times New Roman"><br /></span></p>

<p class="MsoNormal" style="margin: 0pt;"><span face="Times New Roman"><br /></span></p>

<p class="MsoNormal" style="margin: 0pt;"><span face="Times New Roman">And, when you ask about SLAs regarding resiliency, keep in mind that there will be some downtime for routine maintenance and that some unplanned downtime is inevitable. Consider a service provider that might boast about 99.9% availability (8 hours/year outage for 24x7). What is the difference between the following?</span></p>

<p class="MsoNormal" style="margin: 0pt;"></p>





<p class="MsoNormal" style="margin: 0pt 0pt 0pt 90pt; text-indent: -18pt;"><span style="font-family: Symbol;">·<span style="font-family: &quot;Times New Roman&quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;">&nbsp;</span></span><span face="Times New Roman">8 AM to 4 PM on the last Friday of the quarter </span></p>

<p class="MsoNormal" style="margin: 0pt 0pt 0pt 90pt; text-indent: -18pt;"><span style="font-family: Symbol;">·<span style="font-family: &quot;Times New Roman&quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;">&nbsp;</span></span><span face="Times New Roman">Biweekly outages of 30 min at 4 AM local time</span></p>

<p class="MsoNormal" style="margin: 0pt;"></p>





<p class="MsoNormal" style="margin: 0pt;"><span face="Times New Roman">Timing and duration are more important than total downtime/outage.</span></p>

<p class="MsoNormal" style="margin: 0pt;"><span face="Times New Roman"><br /></span></p>

<p class="MsoNormal" style="margin: 0pt;"></p>





<p class="MsoNormal" style="margin: 0pt;"><span face="Times New Roman">Get involved in these discussions but be careful not to come off as the obstacle or as the doomsayer. Quite the opposite, you want to be seen as the enabler. Help the organization understand some of the potential risks but then help the organization define its resiliency requirements, security requirements, and risk tolerance. When the organization knows this, it can more confidently go out and select the right service provider, negotiate the appropriate SLAs and be prepared ahead of time with contingency plans for any potential service outages.</span></p>]]></content:encoded>
      <pubDate>Thu, 24 Jul 2008 06:55:19 +0000</pubDate>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/online backup service">online backup service</category>
      <category domain="http://securityratty.com/tag/online">online</category>
      <category domain="http://securityratty.com/tag/potential service provider">potential service provider</category>
      <category domain="http://securityratty.com/tag/service provider">service provider</category>
      <category domain="http://securityratty.com/tag/online storage offerings">online storage offerings</category>
      <category domain="http://securityratty.com/tag/online records management">online records management</category>
      <category domain="http://securityratty.com/tag/online backup">online backup</category>
      <category domain="http://securityratty.com/tag/potential service outages">potential service outages</category>
      <source url="http://blogs.forrester.com/srm/2008/07/get-involved-no.html">Get Involved Now In Cloud Computing Discussions</source>
    </item>
    <item>
      <title><![CDATA[When your hotel does funerals]]></title>
      <link>http://securityratty.com/article/7a31420cf206dd2cfc4b681fe0a369fc</link>
      <guid>http://securityratty.com/article/7a31420cf206dd2cfc4b681fe0a369fc</guid>
      <description><![CDATA[So another week, another travel nightmare. This week I am in the DC area for a few days, than flying over to Ohio and then back home. Staying in the DC/Northern Va area I made hotel reservations...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>So another week, another travel nightmare.&nbsp; This week I am in the DC area for a few days, than flying over to Ohio and then back home.&nbsp; Staying in the DC/Northern Va area I made hotel reservations through our corporate Expedia account (which is now called Egencia BTW). Though it is fine for airline reservations, I regret it every time I make a hotel reservation on Expedia.&nbsp; This time I reserved a room at the <a href="http://www.google.com/aclk?sa=L&amp;ai=B953Ve6WGSLmnCIHceNvFuMMG-O_QGNDqiswB_LTwvwfgpxIIABABGAEoAjgBUOK2vZn8_____wFgyaaZjeykgBDIAQHIAtiqsgHZA9i4qLGuQL7D&amp;sig=AGiWqtw77p9SVu7mO_lOJ0ulJrBj4rf-rg&amp;q=http://www.virginiansuites.com/%3Fsrc%3Dppc_google_brand">Virginian Suites</a>. I had never heard of it, but it was only $158, which is really cheap for around here.&nbsp; It had 3 stars and sounded good, so I booked it.</p>

<p>I arrived tonight and as I pulled up I have to say that I thought I made a good choice. It is a converted apartment building and every room is actually a studio type of apartment. It has free parking and is located near where I have meetings in Arlington. I gave my name at the desk and they had my reservation, looking good!&nbsp; I was given keys to room 707 and headed on up.&nbsp; I got to room 707 and tried to open the door.&nbsp; No luck, the keys didn???t work. After a moment or two of trying to make the keys work, the door opens and the guy who is staying in the room wants to know what I am doing trying to get in. Well I was reminded of an old Robert Schimmel comedy routine and ran away from there as fast as I could.&nbsp; </p>

<p>I went back down to the desk and told them what happened.&nbsp; The woman at the desk apologized, she meant to write room 700, not 707.&nbsp; While I am waiting for her to correct this and issue new keys, I am looking at the schedule of events at the hotel today.&nbsp; That is when I notice that one of the main events of the day was a someone???s funeral!&nbsp; Thats right, it seems the hotel is used for funerals in the area.&nbsp; That just freaked me out.&nbsp; Now I am getting Six Feet Under deja vu here.&nbsp; I don???t know, call me squeamish, but I just don???t feel good about staying at a hotel that doubles as a funeral home. To top it off, the Internet access here sucks. It is so slow that I am watching the paint dry.&nbsp; Maybe I should go down and catch a funeral or two while I wait for a page to load.&nbsp; In any event, I think this will be the last time I stay here.&nbsp; I just can???t wait for what the rest of this week brings!</p></div>
]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 19:41:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hotel">hotel</category>
      <category domain="http://securityratty.com/tag/hotel reservations">hotel reservations</category>
      <category domain="http://securityratty.com/tag/hotel reservation">hotel reservation</category>
      <category domain="http://securityratty.com/tag/home">home</category>
      <category domain="http://securityratty.com/tag/funeral home">funeral home</category>
      <category domain="http://securityratty.com/tag/week brings">week brings</category>
      <category domain="http://securityratty.com/tag/funeral">funeral</category>
      <category domain="http://securityratty.com/tag/keys">keys</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/07/when-your-hotel.html">When your hotel does funerals</source>
    </item>
    <item>
      <title><![CDATA[When your hotel does funerals]]></title>
      <link>http://securityratty.com/article/cb3246b5c2e5a9f8d7ce414decd6efd3</link>
      <guid>http://securityratty.com/article/cb3246b5c2e5a9f8d7ce414decd6efd3</guid>
      <description><![CDATA[So another week, another travel nightmare. This week I am in the DC area for a few days, than flying over to Ohio and then back home. Staying in the DC/Northern Va area I made hotel reservations...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>So another week, another travel nightmare.&nbsp; This week I am in the DC area for a few days, than flying over to Ohio and then back home.&nbsp; Staying in the DC/Northern Va area I made hotel reservations through our corporate Expedia account (which is now called Egencia BTW). Though it is fine for airline reservations, I regret it every time I make a hotel reservation on Expedia.&nbsp; This time I reserved a room at the <a href="http://www.google.com/aclk?sa=L&amp;ai=B953Ve6WGSLmnCIHceNvFuMMG-O_QGNDqiswB_LTwvwfgpxIIABABGAEoAjgBUOK2vZn8_____wFgyaaZjeykgBDIAQHIAtiqsgHZA9i4qLGuQL7D&amp;sig=AGiWqtw77p9SVu7mO_lOJ0ulJrBj4rf-rg&amp;q=http://www.virginiansuites.com/%3Fsrc%3Dppc_google_brand">Virginian Suites</a>. I had never heard of it, but it was only $158, which is really cheap for around here.&nbsp; It had 3 stars and sounded good, so I booked it.</p>

<p>I arrived tonight and as I pulled up I have to say that I thought I made a good choice. It is a converted apartment building and every room is actually a studio type of apartment. It has free parking and is located near where I have meetings in Arlington. I gave my name at the desk and they had my reservation, looking good!&nbsp; I was given keys to room 707 and headed on up.&nbsp; I got to room 707 and tried to open the door.&nbsp; No luck, the keys didn’t work. After a moment or two of trying to make the keys work, the door opens and the guy who is staying in the room wants to know what I am doing trying to get in. Well I was reminded of an old Robert Schimmel comedy routine and ran away from there as fast as I could.&nbsp; </p>

<p>I went back down to the desk and told them what happened.&nbsp; The woman at the desk apologized, she meant to write room 700, not 707.&nbsp; While I am waiting for her to correct this and issue new keys, I am looking at the schedule of events at the hotel today.&nbsp; That is when I notice that one of the main events of the day was a someone’s funeral!&nbsp; Thats right, it seems the hotel is used for funerals in the area.&nbsp; That just freaked me out.&nbsp; Now I am getting Six Feet Under deja vu here.&nbsp; I don’t know, call me squeamish, but I just don’t feel good about staying at a hotel that doubles as a funeral home. To top it off, the Internet access here sucks. It is so slow that I am watching the paint dry.&nbsp; Maybe I should go down and catch a funeral or two while I wait for a page to load.&nbsp; In any event, I think this will be the last time I stay here.&nbsp; I just can’t wait for what the rest of this week brings!</p></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=bAF3vT"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=bAF3vT" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=TtFnXJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=TtFnXJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=FF9XkJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=FF9XkJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=CgaObJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=CgaObJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=kuNdRJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=kuNdRJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=KCgbwj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=KCgbwj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=BQjQzj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=BQjQzj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/343165828" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 22 Jul 2008 18:45:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hotel">hotel</category>
      <category domain="http://securityratty.com/tag/hotel reservations">hotel reservations</category>
      <category domain="http://securityratty.com/tag/hotel reservation">hotel reservation</category>
      <category domain="http://securityratty.com/tag/home">home</category>
      <category domain="http://securityratty.com/tag/funeral home">funeral home</category>
      <category domain="http://securityratty.com/tag/funeral">funeral</category>
      <category domain="http://securityratty.com/tag/week brings">week brings</category>
      <category domain="http://securityratty.com/tag/keys">keys</category>
      <category domain="http://securityratty.com/tag/week">week</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/343165828/when-your-hotel.html">When your hotel does funerals</source>
    </item>
    <item>
      <title><![CDATA[Visualized Storm fireworks for your 4th of July]]></title>
      <link>http://securityratty.com/article/cd69cdbb404159575b86657784e007bb</link>
      <guid>http://securityratty.com/article/cd69cdbb404159575b86657784e007bb</guid>
      <description><![CDATA[As expected, the Storm botnet maestros have queued up some pwnage for your 4th of July
See the SANS diary for all the details
Upon receipt of my first fireworks.exe sample this evening, I went through...]]></description>
      <content:encoded><![CDATA[As expected, the Storm botnet maestros have queued up some pwnage for your 4th of July. <br />See the SANS <a href="http://isc.sans.org/diary.html?storyid=4669" target="_blank">diary</a> for all the details.<br />Upon receipt of my first fireworks.exe sample this evening, I went through the standard routine and ran it through the analysis mill. Like the ISC said, not much new here, but if you'd like the nitty-gritty, I've put the analysis report <a href="http://holisticinfosec.org/analysis/storm/fireworks/fireworks_storm.txt" target="_blank">here</a>, the peers config list <a href="http://holisticinfosec.org/analysis/storm/fireworks/peers.txt" target="_blank">here</a>, and the pcap <a href="http://holisticinfosec.org/analysis/storm/fireworks/fireworks.pcap" target="_blank">here</a>.<br />However, what I was really inspired to do this evening was visualize the pcap with Raffael Marty's AfterGlow. His new <a href="http://www.amazon.com/Applied-Security-Visualization-Raffael-Marty/dp/0321510100" target="_blank">book</a>, Applied Security Visualization, is coming out next month, so we can turn old Storm news into a celebration of the 4th and the pending release of Applied Security Visualization. By the way, Raffael's visualization workshop slides from the 20th Annual <a href="http://www.first.org/" target="_blank">FIRST</a> Conference in Vancouver, B.C. last week are <a href="http://www.secviz.org/content/applied-security-visualization-first-2008-talk" target="_blank">here</a>, and mine regarding Malcode Analysis for Incident Handlers are <a href="http://holisticinfosec.org/publications/McRee_MATFIH_FIRST_final.pdf" target="_blank">here</a>.<br />So, a little AfterGlow magic,<br /><span style="font-style:italic;">tcpdump -vttttnnelr /home/rmcree/pcap/fireworks.pcap | ./tcpdump2csv.pl "sip dip ttl" | perl ../graph/afterglow.pl -c /home/rmcree/afterglow/src/perl/graph/color.properties -p 2 | neato -Tgif -o fireworks.gif</span>, and the results look just like the fireworks we hoped they would. <br />Happy 4th of July everyone! <br />Except you Storm a$$hat$. ;-)<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://holisticinfosec.org/analysis/storm/fireworks/fireworks.gif" target="_blan"><img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px;" src="http://holisticinfosec.org/analysis/storm/fireworks/fireworks.gif" border="0" alt="" /></a><br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/07/visualized-storm-fireworks-for-your-4th.html&title=Visualized%20Storm%20fireworks%20for%20your%204th%20of%20July " title="Visualized Storm fireworks for your 4th of July ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/07/visualized-storm-fireworks-for-your-4th.html" title="Visualized Storm fireworks for your 4th of July ">digg</a>]]></content:encoded>
      <pubDate>Thu, 03 Jul 2008 16:54:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/4th">4th</category>
      <category domain="http://securityratty.com/tag/fireworks">fireworks</category>
      <category domain="http://securityratty.com/tag/july">july</category>
      <category domain="http://securityratty.com/tag/security visualization">security visualization</category>
      <category domain="http://securityratty.com/tag/happy 4th">happy 4th</category>
      <category domain="http://securityratty.com/tag/peers config list">peers config list</category>
      <category domain="http://securityratty.com/tag/afterglow">afterglow</category>
      <category domain="http://securityratty.com/tag/visualization workshop slides">visualization workshop slides</category>
      <category domain="http://securityratty.com/tag/raffael marty">raffael marty</category>
      <source url="http://holisticinfosec.blogspot.com/2008/07/visualized-storm-fireworks-for-your-4th.html">Visualized Storm fireworks for your 4th of July</source>
    </item>
    <item>
      <title><![CDATA[Tweet!]]></title>
      <link>http://securityratty.com/article/ea05cb277df3256f86f6a03dd1c4d597</link>
      <guid>http://securityratty.com/article/ea05cb277df3256f86f6a03dd1c4d597</guid>
      <description><![CDATA[The other day an office mate asked, &quot;Do you twitter?&quot; Sorting through the various snarky remarks that immediately popped to mind, I replied that I didn't think anyone would find my routine bits all...]]></description>
      <content:encoded><![CDATA[<p>The other day an office mate asked, &quot;Do you twitter?&quot; Sorting through the various snarky remarks that immediately popped to mind, I replied that I didn't think anyone would find my routine bits all that interesting. He suggested otherwise: that it would be a convenient place to record quick ideas. So I am <a href="http://twitter.com/steveriley" target="_blank">now indeed twittering</a>. Check out the link on the right of this blog. For those using an RSS/ATOM aggravator, you'll want <a title="http://twitter.com/statuses/user_timeline/15237105.rss" href="http://twitter.com/statuses/user_timeline/15237105.rss">http://twitter.com/statuses/user_timeline/15237105.rss</a>.</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3079175" width="1" height="1">]]></content:encoded>
      <pubDate>Fri, 27 Jun 2008 01:52:18 +0000</pubDate>
      <category domain="http://securityratty.com/tag/record quick ideas">record quick ideas</category>
      <category domain="http://securityratty.com/tag/snarky remarks">snarky remarks</category>
      <category domain="http://securityratty.com/tag/routine bits">routine bits</category>
      <category domain="http://securityratty.com/tag/twitter">twitter</category>
      <category domain="http://securityratty.com/tag/rssatom aggravator">rssatom aggravator</category>
      <category domain="http://securityratty.com/tag/link">link</category>
      <category domain="http://securityratty.com/tag/comstatusesuser">comstatusesuser</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/convenient">convenient</category>
      <source url="http://blogs.technet.com/steriley/archive/2008/06/26/tweet.aspx">Tweet!</source>
    </item>
    <item>
      <title><![CDATA[Civilians Ask Whats With All the Privacy Act Kerfluffle?]]></title>
      <link>http://securityratty.com/article/d5daa36201f5ba38464b919d3abcc3dc</link>
      <guid>http://securityratty.com/article/d5daa36201f5ba38464b919d3abcc3dc</guid>
      <description><![CDATA[And by kerfluffle, I mean these articles
GAOPrivacy Report
Technology Liberation Front
Center for Democracy and Technology
And how about an analysis of the Privacy Act from DOJ for background reasons...]]></description>
      <content:encoded><![CDATA[<p>And by &#8220;kerfluffle&#8221;, I mean these articles:</p>
<ul>
<li><a href="http://www.gao.gov/new.items/d08536.pdf" target="_blank">GAO Privacy Report</a></li>
<li><a href="http://techliberation.com/2008/06/20/gao-issues-report-on-privacy/" target="_blank">Technology Liberation Front</a></li>
<li><a href="http://www.cdt.org/publications/policyposts/2008/10" target="_blank">Center for Democracy and Technology</a></li>
<li>And how about an <a href="http://www.usdoj.gov/oip/04_7_1.html" target="_blank">analysis of the Privacy Act </a>from DOJ for background reasons?</li>
</ul>
<p>Well, let&#8217;s talk about how privacy and the Government works with Uncle Rybolov (please hold the references to Old Weird Uncle Harold until we&#8217;re through with today&#8217;s lesson please).</p>
<p>We have a law, the Privacy Act of 1974.  Think about it, what significant privacy-wrenching activities happened just a couple of years prior?  Can we say &#8220;<a href="http://en.wikipedia.org/wiki/Watergate_scandal" target="_blank">Watergate Scandal</a>&#8220;?  Can we say &#8220;<a href="http://en.wikipedia.org/wiki/Church_Committee" target="_blank">Church Committee</a>&#8220;?  Suffice it to say, the early 1970s was an era filled with privacy issues and is where most of our privacy policy and law comes from.  Remember this for later:  this was the 1970&#8217;s!</p>
<p>Each of the various sections of the Privacy Act deals with a particular data type.  For instance, Title 13 refers to data collected by the Census Bureau when they&#8217;ll go count everybody in 2010.</p>
<p>The Privacy Act talks about the stuff that everybody in the Government needs to know about:  how you&#8217;re going to jail if you disclose this information to a third party.  For those of you who have ever been in the military or had to fill out a government form that required your social security number, the light in the back of your head should be going off right now because they all have the warnings about disclosure.</p>
<p style="text-align: center;"><em><img src="http://farm3.static.flickr.com/2095/2054565713_1d20d5f90a.jpg?v=0" alt="Huts and Chairs Need Privacy Too" width="376" height="500" /></em></p>
<p style="text-align: center;"><em>Remember to respect the privacy of the beach huts and chairs photo by </em><a href="http://www.flickr.com/photos/joeshlabotnik/" target="_blank"><em>Joe Shlabotnik</em></a></p>
<p>When it comes to IT security, the Privacy Act works like this:</p>
<ul>
<li>You realize a need to collect PII on individuals.</li>
<li>You do a privacy impact assessment to determine if you can legally collect this data and what the implications of collecting the data are.</li>
<li>You build rules about what you can do normally with the data once you have collected it.  This is called the &#8220;routine use&#8221;.</li>
<li>You write a report on how, why, and about whom you&#8217;re collecting this information.  This is known as the &#8220;System of Record Notice&#8221;.</li>
<li>You file this report with the Federal Register to notify the public.</li>
<li>This IT system becomes the authoritative source of that information.</li>
</ul>
<p>IE, no secret dossiers on the public.  We&#8217;ll suspend our disbelief in FISA for a minute, this conversation is about non-intelligence data collection.</p>
<p>Now the problem with all this is that if you stop and think about it, I was 1 year old when the Privacy Act was signed.  Our technology for information sharing has gone above and beyond that.  We can exchange data much much much more quickly than the Privacy Act originally intended.  As a result, we have PII everywhere.  Most of the PII is needed to provide services to the citizens, except that it&#8217;s a royal PITA to protect it all, and that&#8217;s the lesson of the past 2 years in Government data breaches.</p>
<p>Problems with the Privacy Act:</p>
<ul>
<li>The SORN is hard to read and is not easy to find.</li>
<li>Privacy Act data given to contractors or &#8220;business partners&#8221; (aka, state and local government or NGOs) does not have the same amount of oversight as it does in the Government.</li>
<li>Data given to the Government by a third-party is not susceptible to the Privacy Act because the Government did not collect it.  Wow, lots of room for abuse&#8211;waterboarding-esque abuse.</li>
<li>Privacy Act procedures were written for mainframes.  Mainframes have been replaced with clusters of servers.  It&#8217;s easy to add a new server to this setup.  Yes, this <strong>is</strong> a feature.</li>
<li>If you build a new system with the same data types and routine uses as an already existing SORN, you can &#8220;piggyback&#8221; on that existing SORN.</li>
<li>It&#8217;s very easy to use the data in a way that isn&#8217;t on your &#8220;routine use&#8221; statement, thus breaking the entire privacy system.</li>
</ul>
<p>Obviously, at this point, you should have gotten the hint that maybe we need to revise the Privacy Act.  I think GAO and OMB would agree with you here.</p>
<p>So, what alternatives do we have to the existing system?</p>
<ul>
<li>Make blanket data types and do a PIA and SORN on them regardless of where that data lies.</li>
<li>Bend the Paperwork Reduction act and OMB guidance so that we don&#8217;t collect as much information.</li>
<li>Make the Privacy Act more specific on what should be in SORN, PIA, and routine use statements.</li>
</ul>
<p>To be honest, it seems like most of this is already in place, it just needs to get tuned a little bit so we&#8217;re doing the right things.  Once again, the scale of the Government&#8217;s IT infrastructure is keeping us from doing the right thing:    there isn&#8217;t enough time in the day to do PIAs on a per-server basis or to keep track of every little bit of data.  You have to automate our privacy efforts in some fashion.</p>
<p>And this is why, dear readers, I think the Government needs DLP solutions more than the private sector does.  Too bad the DLP vendors are stuck on credit cards and social security numbers.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/424&amp;title=Civilians+Ask+%26%238220%3BWhat%26%238217%3Bs+With+All+the+Privacy+Act+Kerfluffle%3F%26%238221%3B" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Del.icio.us" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/424&amp;title=Civilians+Ask+%26%238220%3BWhat%26%238217%3Bs+With+All+the+Privacy+Act+Kerfluffle%3F%26%238221%3B" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to digg" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/424&amp;title=Civilians+Ask+%26%238220%3BWhat%26%238217%3Bs+With+All+the+Privacy+Act+Kerfluffle%3F%26%238221%3B" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to reddit" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=Civilians+Ask+%26%238220%3BWhat%26%238217%3Bs+With+All+the+Privacy+Act+Kerfluffle%3F%26%238221%3B&amp;url=http://www.guerilla-ciso.com/archives/424&amp;version=0.7" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Feed Me Links" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/424" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Technorati" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/424&amp;t=Civilians+Ask+%26%238220%3BWhat%26%238217%3Bs+With+All+the+Privacy+Act+Kerfluffle%3F%26%238221%3B" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Yahoo My Web" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/424&amp;title=Civilians+Ask+%26%238220%3BWhat%26%238217%3Bs+With+All+the+Privacy+Act+Kerfluffle%3F%26%238221%3B" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Stumble Upon" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/424&amp;title=Civilians+Ask+%26%238220%3BWhat%26%238217%3Bs+With+All+the+Privacy+Act+Kerfluffle%3F%26%238221%3B" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Google Bookmarks" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/424" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Squidoo" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/424" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Bloglines" alt="Add 'Civilians Ask &#8220;What&#8217;s With All the Privacy Act Kerfluffle?&#8221;' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=iZflJI"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=iZflJI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=SHBmQi"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=SHBmQi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/320829287" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 26 Jun 2008 17:51:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/privacy act">privacy act</category>
      <category domain="http://securityratty.com/tag/privacy act procedures">privacy act procedures</category>
      <category domain="http://securityratty.com/tag/privacy act deals">privacy act deals</category>
      <category domain="http://securityratty.com/tag/privacy act data">privacy act data</category>
      <category domain="http://securityratty.com/tag/privacy">privacy</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data lies">data lies</category>
      <category domain="http://securityratty.com/tag/privacy act talks">privacy act talks</category>
      <category domain="http://securityratty.com/tag/privacy policy">privacy policy</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/320829287/424">Civilians Ask Whats With All the Privacy Act Kerfluffle?</source>
    </item>
    <item>
      <title><![CDATA[LifeLock and Identity Theft]]></title>
      <link>http://securityratty.com/article/7a242b55dda570936ede0e9a19e4374c</link>
      <guid>http://securityratty.com/article/7a242b55dda570936ede0e9a19e4374c</guid>
      <description><![CDATA[LifeLock, one of the companies that offers identity-theft protection in the United States, has been taking quite a beating recently. They're being sued by credit bureaus, competitors and lawyers in...]]></description>
      <content:encoded><![CDATA[<p>LifeLock, one of the companies that offers identity-theft protection in the United States, has been taking quite a beating recently. They're being sued by credit bureaus, competitors and lawyers in several states that are launching class action lawsuits. And the stories in the media ... it's like a piranha feeding frenzy.</p>

<p>There are also a lot of errors and misconceptions. With its aggressive advertising campaign and a CEO who publishes his Social Security number and dares people to steal his identity -- Todd Davis, 457-55-5462 -- <a href="http://www.lifelock.com">LifeLock</a> is a company that's easy to hate. But the company's story has some interesting security lessons, and it's worth understanding in some detail.</p>

<p>In December 2003, as part of the <a href="http://www.ftc.gov/opa/2004/06/factaidt.shtm">Fair and Accurate Credit Transactions Act</a>, or <a href=" http://www.treasury.gov/offices/domestic-finance/financial-institution/cip/pdf/fact-act.pdf">Facta</a>, credit bureaus were forced to allow you to put a <a href="http://www.consumersunion.org/creditmatters/creditmattersfactsheets/001626.html">fraud alert</a> on their credit reports, requiring lenders to verify your identity before issuing a credit card in your name. This alert is temporary, and expires after 90 days.  Several companies have sprung up -- LifeLock, Debix, LoudSiren, TrustedID -- that automatically renew these alerts and effectively make them permanent.</p>

<p>This service pisses off the credit bureaus and their financial customers. The reason lenders don't routinely verify your identity before issuing you credit is that it takes time, costs money and is one more hurdle between you and another credit card. (Buy, buy, buy -- it's the American way.) So in the eyes of credit bureaus, LifeLock's customers are inferior goods; selling their data isn't as valuable. LifeLock also opts its customers out of pre-approved credit card offers, further making them less valuable in the eyes of  credit bureaus.</p>

<p>And, so began a smear campaign on the part of the credit bureaus. You can read their points of view in <a href="http://www.nytimes.com/2008/05/24/business/yourmoney/24money.html?8dpc">this <cite>New York Times</cite> article</a>, written by a reporter who didn't do much more than regurgitate their talking points. And the class action lawsuits have piled on, accusing LifeLock of deceptive business practices, fraudulent advertising and so on.  The biggest smear is that LifeLock didn't even protect Todd Davis, and that his identity was allegedly stolen.</p>

<p>It wasn't. Someone in Texas used Davis's SSN to get a $500 advance against his paycheck. It worked because the loan operation didn't check with any of the credit bureaus before approving the loan -- perfectly reasonable for an amount this small. The payday-loan operation called Davis to collect, and LifeLock cleared up the problem. His credit report remains spotless.</p>

<p>The Experian credit bureau's <a href="http://www.networkworld.com/news/2008/022108-credit-reporting-firm-sues-lifelock.html">lawsuit</a> basically claims that fraud alerts are only for people who have been victims of identity theft. This seems spurious; the text of the law states that anyone "who asserts a good faith suspicion that the consumer has been or is about to become a victim of fraud or related crime" can request a fraud alert. It seems to me that includes anybody who has ever received one of those notices about their financial details being lost or stolen, which is everybody.</p>

<p>As to deceptive business practices and fraudulent advertising -- those just seem like class action lawyers piling on. LifeLock's aggressive fear-based marketing doesn't seem any worse than a lot of other similar advertising campaigns. My guess is that the <a href="http://www.insidetech.com/news/2148-id-protection-ads-come-back-to-bite-lifelock-pitchman">class action lawsuits</a> won't go anywhere.</p>

<p>In reality, forcing lenders to verify identity before issuing credit is <a href="http://www.schneier.com/crypto-gram-0504.html#2">exactly the sort of thing we need to do</a> to fight identity theft. Basically, there are two ways to deal with identity theft: Make personal information harder to steal, and make stolen personal information harder to use. We all know the former doesn't work, so that leaves the latter.  If Congress wanted to solve the problem for real, one of the things it would do is make fraud alerts permanent for everybody. But the credit industry's lobbyists would never allow that.</p>

<p>LifeLock does a bunch of other clever things. They monitor the national address database, and alert you if your address changes. They look for your credit and debit card numbers on hacker and criminal websites and such, and assist you in getting a new number if they see it. They have a million-dollar service guarantee -- for complicated legal reasons, they can't call it insurance -- to help you recover if your identity is ever stolen.</p>

<p>But even with all of this, I am not a LifeLock customer. At $120 a year, it's just not worth it. You wouldn't know it from the press attention, but dealing with identity theft has become easier and more routine. Sure, it's a pervasive problem. The Federal Trade Commission <a href="http://www.ftc.gov/opa/2007/11/idtheft.shtm">reported</a> that 8.3 million Americans were identity-theft victims in 2005. But that includes things like someone stealing your credit card and using it, something that rarely costs you any money and that LifeLock doesn't protect against. New account fraud is much less common, affecting 1.8 million Americans per year, or 0.8 percent of the adult population. The FTC hasn't published detailed numbers for 2006 or 2007, but the rate <a href="http://www.consumer.gov/sentinel/pubs/top10fraud2007.pdf">seems</a> to be <a href="http://www.privacyrights.org/ar/idtheftsurveys.htm#Jav2007">declining</a>. </p>

<p>New card fraud is also not very damaging. The median amount of fraud the thief commits is $1,350, but you're not liable for that. Some spectacularly horrible identity-theft stories notwithstanding, the financial industry is pretty good at quickly cleaning up the mess. The victim's median out-of-pocket cost for new account fraud is only $40, plus ten hours of grief to clean up the problem. Even assuming your time is worth $100 an hour, LifeLock isn't worth more than $8 a year.</p>

<p>And it's hard to get any data on how effective LifeLock really is. They've been in business three years and have about a million customers, but most of them have joined up in the last year. They've paid out on their service guarantee 113 times, but a lot of those were for things that happened before their customers became customers. (It was easier to pay than argue, I assume.) But they don't know how often the fraud alerts actually catch an identity thief in the act. My guess is that it's less than the 0.8 percent fraud rate above.</p>

<p>LifeLock's business model is based more on the fear of identity theft than the actual risk.</p>

<p>It's pretty ironic of the credit bureaus to attack LifeLock on its marketing practices, since they know all about profiting from the fear of identity theft. Facta also forced the credit bureaus to give Americans a <a href="http://www.annualcreditreport.com/">free credit report</a> once a year upon request. Through <a href="http://blog.washingtonpost.com/securityfix/2005/09/beware_free_credit_report_scam_1.html">deceptive</a> <a href="http://www.msnbc.msn.com/id/7803368/">marketing</a> <a href="http://ezinearticles.com/?The-Free-Credit-Report-Scam&id=321877">techniques</a>, they've turned this requirement into a multimillion-dollar business.</p>

<p>Get LifeLock if you want, or one of its competitors if you prefer. But remember that you can <a href="http://www.nytimes.com/2008/05/24/business/yourmoney/24moneyside.html">do most</a> of what these companies do <a href="http://www.savingadvice.com/blog/2008/06/04/102143_never-pay-someone-to-protect-your-identity.html">yourself</a>. You can put a fraud alert on your own account, but you have to remember to renew it every three months. You can also put a credit freeze on your account, which is more work for the average consumer but more effective if you're a privacy wonk -- and the rules differ by state. And maybe someday Congress will do the right thing and put LifeLock out of business by forcing lenders to verify identity every time they issue credit in someone's name.</p>

<p>This essay <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/06/securitymatters_0612">originally appeared</a> in Wired.com.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=nECM2I"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=nECM2I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=1G9U3I"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=1G9U3I" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 17 Jun 2008 02:51:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/identity theft">identity theft</category>
      <category domain="http://securityratty.com/tag/credit reports">credit reports</category>
      <category domain="http://securityratty.com/tag/credit">credit</category>
      <category domain="http://securityratty.com/tag/identity">identity</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <category domain="http://securityratty.com/tag/fraud alerts permanent">fraud alerts permanent</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <category domain="http://securityratty.com/tag/credit industry">credit industry</category>
      <category domain="http://securityratty.com/tag/experian credit bureau">experian credit bureau</category>
      <source url="http://www.schneier.com/blog/archives/2008/06/lifelock_and_id.html">LifeLock and Identity Theft</source>
    </item>
    <item>
      <title><![CDATA[University of Florida student information online for years]]></title>
      <link>http://securityratty.com/article/70535b81354ea161a0135979f7d38509</link>
      <guid>http://securityratty.com/article/70535b81354ea161a0135979f7d38509</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
6/11/08

Organization
University of Florida

Contractor/Consultant/Branch
Office for Academic Support and Institutional Services

Victims
Students
...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/uflorida.jpg" align="right" height="165" width="165"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>6/11/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.ufl.edu/">University of Florida</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://web.oasis.ufl.edu/">Office for Academic Support and Institutional Services</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Students <br><br><span style="font-weight: bold;">Number Affected:</span><br>"more than 11,300"<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names, addresses and Social Security numbers"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"GAINESVILLE, Fla. - University of Florida officials today mailed letters of notification to more than 11,300 current and former students regarding a privacy breach that resulted in names, addresses and Social Security numbers being posted online that may have been accessible to the public."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://privacy.ufl.edu/CLASBreach/">University of Florida</a> <br><a href="http://www.miamiherald.com/top_stories/story/565567.html">Miami Herald</a> <br><a href="http://insideuf.ufl.edu/2008/06/10/clas-breach/">Inside UF</a> <br><a href="http://www.upi.com/Top_News/2008/06/11/Security_breached_at_Florida_university/UPI-38151213211913/">United Press International</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>University of Florida<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>GAINESVILLE, Fla. - University of Florida officials today mailed letters of notification to more than 11,300 current and former students regarding a privacy breach that resulted in names, addresses and Social Security numbers being posted online that may have been accessible to the public.<br><span style="font-style: italic;">[Evan] Not "may have been".&nbsp; The information was accessible to the public and was not even protected by a password.</span><br><br>The student information was actively used from 2003 through 2005 and remained posted until it was recently discovered during a routine audit of UF systems.<br><span style="font-style: italic;">[Evan] If I am reading this right, this means that some of the personal information was available publicly for ~5 years!</span><br><br>School officials emphasized that the site would not have been easy to find and they do not believe it was accessed by anyone outside the school.<br><span style="font-style: italic;">[Evan] There is no security through obscurity.</span><br><br>"The risk of someone outside actually finding this information and using it inappropriately is very low," - Steve Orlando, UF Spokesman<br><span style="font-style: italic;">[Evan] I wonder how Mr. Orlando came to the conclusion that the risk of disclosure and misuse is "very low".&nbsp; As I understand, the server was publicly accessible, presumably via the internet.&nbsp; If so, was the site indexed by search engines like Google, Yahoo, and Microsoft?&nbsp; It is much easier to find information through a search index because folder structure is much less relevant.&nbsp; The fact that this information was available for 3-5 years adds to the risk too.&nbsp; I only know what I read and based on this and experience, I wouldn't classify this as a "very low" risk situation.&nbsp; Either way, the risk was increased due to poor information security practice and was not necessary. </span><br><br>"We've done computer forensics, and we don't have any evidence that anybody accessed this information," he added.<br><span style="font-style: italic;">[Evan] This indicates poor logging and monitoring which are both essential detective controls (in most situations).&nbsp; Information security personnel (or admins) should be empowered to reconstruct events.</span><br><br>"But because we can't say that with absolute certainty, we're going through with the notification out of an abundance of caution," Orlando said.<br><span style="font-style: italic;">[Evan] I am NOT a fan of the "abundance of caution" claims that seem more popular in breach notifications lately.&nbsp; Organizations would be best advised to use an "abundance of caution" in the prevention and early detection of breaches by applying sound information security principles.</span><br><br>Since 2005, the site has been "dormant but accessible," said university spokesman Steve Orlando. "It was just sitting there."<br><br>The information has been removed and is no longer available online or elsewhere in the UF systems.<br><br>The breach occurred when former student employees of the Office for Academic Support and Institutional Service, or OASIS, program created online records of students participating in the program.<br><br>The student employees posted the information online so that they could work with it from remote locations, but they did not install security measures to keep others from accessing it as well<br><span style="font-style: italic;">[Evan] I have so many questions and arguments.&nbsp; Were the students aware of the risks?&nbsp; If not, then there is probably an information security training and awareness problem.&nbsp; Why was it necessary to include Social Security numbers in the records?&nbsp; Why were the seemingly untrained students allowed to post the information without being stopped or detected?&nbsp; I have many more questions, but I am starting to confuse myself now.</span><br><br>The university sent letters of notification to about 11,300 students whose information is believed to have been potentially compromised.<br><span style="font-style: italic;">[Evan] Here's my take on the word "compromised".&nbsp; If an organization cannot provide reasonable assurance that the information has not been subject to unauthorized disclosure, modification, or destruction, then the information has been "compromised".&nbsp; </span><br><br>University officials were unable to find contact information for about 570, so they are asking students who were enrolled in CLAS from 2003 to 2005 and did not receive a letter but who believe their information may have been compromised to call UF’s Privacy Office Hotline at 866-876-HIPA and provide the requested information.<br><br>Anyone who thinks he or she may be one of the 570 people who were not notified is urged to go to <a href="http://privacy.ufl.edu">privacy.ufl.edu</a> and read the information posted there before calling the privacy hotline.<br><br>"This would certainly appear to be the largest privacy breach we've had," Orlando said.<br><br>We're in the process of strengthening some of those policies regarding what information can be posted and what security measures should be in place<br><span style="font-style: italic;">[Evan] Good start.</span><br><br><span style="font-weight: bold;">Victim Reaction:</span><br>"Why would it be necessary to use a Social Security number instead of something else?" asked Reixach, pointing out that students were given ID numbers. "It's just silly".<br><br>"It's negligence on their part, especially if anyone has been affected with identity theft,"<br><br>Johann Arias, a spring CLAS graduate, had not heard about the breach Wednesday and said UF should be doing more to notify those affected.<br><br>"They always make information very prominent when you have a hold or owe them money," Arias said.<br><br><span style="font-weight: bold;">Commentary:</span><br>This is a case where poorly trained students are granted access or obtained access to confidential information and posted the information to an unsecured location which went undetected for years.&nbsp; Bad all around.&nbsp; <br><br><span style="font-weight: bold;">Past Breaches:</span><br>May, 2008 - <a href="http://breachblog.com/2008/05/22/uflorida.aspx">University of Florida doctor loses job over breach</a> <br>November, 2007 - <a href="http://breachblog.com/2007/11/28/uf.aspx">University of Florida student info online</a> </font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/06/12/uflorida.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Thu, 12 Jun 2008 06:41:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information online">information online</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <category domain="http://securityratty.com/tag/information security personnel">information security personnel</category>
      <category domain="http://securityratty.com/tag/student information">student information</category>
      <category domain="http://securityratty.com/tag/security measures">security measures</category>
      <category domain="http://securityratty.com/tag/install security measures">install security measures</category>
      <source url="http://breachblog.com/2008/06/12/uflorida.aspx">University of Florida student information online for years</source>
    </item>
  </channel>
</rss>
