<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: sadly]]></title>
    <link>http://securityratty.com/tag/sadly</link>
    <description></description>
    <pubDate>Mon, 08 Sep 2008 08:29:57 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Monthly Blog Round-Up November 2008]]></title>
      <link>http://securityratty.com/article/1bdd878eaa6b7f3beec3fe92db4f4c7c</link>
      <guid>http://securityratty.com/article/1bdd878eaa6b7f3beec3fe92db4f4c7c</guid>
      <description><![CDATA[As we all know, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see today . These monthly round-ups is an attempt to remind...]]></description>
      <content:encoded><![CDATA[<p>As we all know, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>. These <a href="http://chuvakin.blogspot.com/search/label/Monthly">monthly round-ups</a> is an attempt to remind people of useful content from the past month! If you are “too busy to read the blogs” (!), at least read <a href="http://chuvakin.blogspot.com/search/label/Monthly">these</a>.</p>  <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">&quot;Security Warrior&quot; blog</a> </strong>round-up of top 5 popular posts/topics.</p>  <ol>   <li>Amazingly, this month by far the #1 post is my “'<a href="http://chuvakin.blogspot.com/2008/11/blogging-from-deepsec-2008-in-vienna.html">Blogging from DeepSec 2008 in Vienna</a>.” DeepSec was indeed an awesome conference.</li>    <li>Last month, I said that “SIEM bashing reached a new high.” OMFG. What should I say <a href="http://chuvakin.blogspot.com/2008/06/11-signs-that-your-siem-is-dog-or-you.html">now</a>? I dunno. In any case, “<a href="http://chuvakin.blogspot.com/2008/06/11-signs-that-your-siem-is-dog-or-you.html">11 Signs That Your SIEM Is A Dog or &quot;Raffy, You Killed SIM!&quot;</a> is on the top list. BTW, “<a href="http://www.matasano.com/log/661/pro-forma-06-punditry-results/">On Open Source in SIEM and Log Management</a>” is also again on the top list, to much of my amazement.</li>    <li>Again and again, <a href="http://chuvakin.blogspot.com/search/label/PCI">PCI compliance</a> is obviously still all the rage: <a href="http://chuvakin.blogspot.com/2008/02/must-do-logging-for-pci.html">MUST-DO Logging for PCI?</a> post was again propelled to a place in my monthly Top5 list. </li>    <li>Get a firewall AND a fire extinguisher, now, will ya? Is it too much to ask? :-) The post “<a href="http://pcianswers.com/2008/11/03/e-commerce-startups-deal-with-pci-compliance/">On Small Companies and PCI Compliance</a>” is on the Top list.</li>    <li>Shockingly, <a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">AGAINx2</a> :-) this month, the &quot;<a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Top 11 Reasons to Secure and Protect Your Logs</a>&quot; came up as on the Top list.&#160; BTW, see <a href="http://chuvakin.blogspot.com/search/label/poll">my other logging polls</a> and my other “top 11” lists. </li> </ol>  <p><a href="http://chuvakin.blogspot.com/search/label/Monthly">See you</a> in December. Also see my annual “Top Posts” (<a href="http://chuvakin.blogspot.com/2008/01/annual-blog-round-up-2007.html">2007</a>)</p>  <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2008/11/monthly-blog-round-up-october-2008.html">Monthly Blog Round-Up - October 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - September 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - August 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/08/monthly-blog-round-up-july-2008.html">Monthly Blog Round-Up - July 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/07/monthly-blog-round-up-june-2008.html">Monthly Blog Round-Up - June 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/06/monthly-blog-round-up-may-2008.html">Monthly Blog Round-Up - May 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/05/monthly-blog-round-up-april-2008.html">Monthly Blog Round-Up - April 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a> </li>    <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a> </li> </ul>  <p>&#160; </p>  <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:7192e29b-e335-4630-8b0b-dc37806d54ee" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati Tags: <a href="http://technorati.com/tags/blog" rel="tag">blog</a>,<a href="http://technorati.com/tags/security" rel="tag">security</a>,<a href="http://technorati.com/tags/loggings" rel="tag">loggings</a>,<a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=CToyO"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=CToyO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=q2gTO"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=q2gTO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=uBDPO"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=uBDPO" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/473057574" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 13:24:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <category domain="http://securityratty.com/tag/top list">top list</category>
      <category domain="http://securityratty.com/tag/annual top posts">annual top posts</category>
      <category domain="http://securityratty.com/tag/monthly round-ups">monthly round-ups</category>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/473057574/monthly-blog-round-up-november-2008.html">Monthly Blog Round-Up November 2008</source>
    </item>
    <item>
      <title><![CDATA[Another link spammer]]></title>
      <link>http://securityratty.com/article/4dd72baf5933c49893c38cadde935c82</link>
      <guid>http://securityratty.com/article/4dd72baf5933c49893c38cadde935c82</guid>
      <description><![CDATA[Yet another link spammer is cluttering up my in-box. Youd think that after exposing this one , and this one , and this one , theyd know better
The latest set of miscreants operates under the brand...]]></description>
      <content:encoded><![CDATA[<p>Yet another link spammer is cluttering up my in-box. You&#8217;d think that after exposing <a href="http://www.lightbluetouchpaper.org/2007/01/07/human-rights-and-biophysics-strange-similarities/">this one</a>, and <a href="http://www.lightbluetouchpaper.org/2007/08/30/the-interns-of-privila/">this one</a>, and <a href="http://www.lightbluetouchpaper.org/2007/12/20/fatal-wine-waiters/">this one</a>, they&#8217;d know better.</p>
<p>The latest set of miscreants operates under the brand &#8220;<a href="http://www.goodeyeforlinks.com" rel="nofollow">goodeyeforlinks.com</a>&#8221; and claim to &#8220;use white hat SEO techniques in order to get high quality, do-follow links to your website&#8221;. They also claim to be &#8220;professional&#8221; which in this case must mean you pay for their services, since sending out bulk unsolicited email is anything but professional.</p>
<p>Nevertheless, although their long term aim may indeed be to make money from legitimate, albeit foolish, businesses seeking a higher profile, the sites they have been promoting so far are anything but legitimate. In fact they&#8217;ve been fake sites covered with Google adverts (so-called &#8220;<a href="http://www.sabahan.com/2006/06/26/how-mfa-made-for-adsense-sites-make-money/">Made for AdSense</a>&#8221; (MFA) sites).</p>
<p>They started by asking me to link to &#8220;<a href="http://www.entovation.net" rel="nofollow">entovation.net</a>&#8221; which they claim is &#8220;page rank 3&#8243;. In fact it is page rank 3 (!) and a blatant copy of <a href="http://www.acentesolutions.com/">http://www.acentesolutions.com</a> which appears entirely genuine (albeit only page rank 1). They have also been promoting &#8220;<a href="http://www.poland-translation-services.com" rel="nofollow">poland-translation-services.com</a>&#8220;, which claims to be a site offering &#8220;A large team of 2,500 translators specializing in each sector, located in over 30 countries&#8221; &#8230;</p>
<p>However, this site is clearly fake as well. I haven&#8217;t tracked down where it all comes from, but much of <a href="http://poland-translation-services.com/Translate-a-Document.html" rel="nofollow">this page</a> comes from <a href="http://www.intowords.com.ar/espanol/traducciones/traducciones-de-espanol-ingles.html">this Argentinian page</a>, the text of which has been pushed through <a href="http://www.google.com/language_tools?hl=en">Google&#8217;s Spanish to English translation tools</a>&#8230;  which sadly (for example) renders </p>
<blockquote><p>
Comentarios: Se considera foja al equivalente a 500 palabras. Si el documento a traducir es menor a una foja, se lo considerará como una foja.
</p></blockquote>
<p>into </p>
<blockquote><p>
Comments: foja is considered the equivalent of 500 words. If the document is translated to a lesser foja, we will consider as a foja.
</p></blockquote>
<p>which makes the 2500 translators look more than a little bit <a href="http://www.cartoonbank.com/item/124224">foolish</a>!</p>
<p>The fake websites are hosted by <a href="http://www.euroaccess.nl/">EuroAccess Enterprises Ltd.</a> in The Netherlands (which is also where the email spam has been sent from). I&#8217;m not alone in receiving this type of email, further examples can be found <a href="http://archives.neohapsis.com/archives/openbsd/2008-09/1548.html">here</a>, and <a href="http://www.projecthoneypot.org/ip_89.248.172.66">here</a>, and <a href="http://dansdata.blogsome.com/2008/10/16/i-do-like-a-good-link-spam-in-the-morning/">here</a>, and <a href="http://avvoblog.com/2008/11/10/linkbrokers-gone-wild/">here</a>, and <a href="http://www.nabble.com/Link-exchange-with-page-rank-4--Hotel-site-td19973368.html">here</a>, and <a href="http://www.allvoices.com/contributed-news/1522559">here</a>, and even <a href="http://blogpintura.wordpress.com/#comment-5">here (in Spanish)</a>.</p>
<p>EuroAccess have a fine ticketing system for abuse complaints&#8230; so I&#8217;m able to keep track of what they&#8217;re doing about my emails drawing their attention to the fraudsters they are hosting. I am therefore fully aware that they&#8217;ve so far marked my missives as &#8220;Priority: Low&#8221;, and nothing else is recorded to have been done&#8230; However, the tickets are still &#8220;Status: Open&#8221;, so perhaps a little publicity will encourage them to reassess their prioritisation.</p>
]]></content:encoded>
      <pubDate>Sun, 23 Nov 2008 16:45:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/argentinian page">argentinian page</category>
      <category domain="http://securityratty.com/tag/page">page</category>
      <category domain="http://securityratty.com/tag/foja">foja</category>
      <category domain="http://securityratty.com/tag/lesser foja">lesser foja</category>
      <category domain="http://securityratty.com/tag/page rank">page rank</category>
      <category domain="http://securityratty.com/tag/considera foja">considera foja</category>
      <category domain="http://securityratty.com/tag/link spammer">link spammer</category>
      <category domain="http://securityratty.com/tag/link">link</category>
      <category domain="http://securityratty.com/tag/fake">fake</category>
      <source url="http://www.lightbluetouchpaper.org/2008/11/23/another-link-spammer/">Another link spammer</source>
    </item>
    <item>
      <title><![CDATA[Vulnerabilities quickly mitigated by security-conscious vendors]]></title>
      <link>http://securityratty.com/article/7953938c09c36aba1397daeec84ac8ab</link>
      <guid>http://securityratty.com/article/7953938c09c36aba1397daeec84ac8ab</guid>
      <description><![CDATA[As you are likely aware, I spend a fair bit of time heckling those I believe deserving due to their shortcomings with regard to protecting online consumers
I do, however, continue to seek...]]></description>
      <content:encoded><![CDATA[As you are likely aware, I spend a fair bit of time heckling those I believe deserving due to their shortcomings with regard to protecting online consumers.<br />I do, however, continue to seek opportunities to shed positive light as well, and recent responses from a number of vendor/developers warrant an opportunity to do just that.<br />In the last 30 days, I've discovered vulnerabilities in products from four different vendors, and <a href="http://holisticinfosec.org/content/category/6/23/45/" target="_blank">advised</a> them all immediately upon discovery. Usually, that's where the story ends, as sadly, my repeated requests for action are often ignored. The last 30 days have proven to be entirely different, with swift responses and action from ALL vendors to whom I reported vulnerabilities. In all cases I received replies within 24 hours or less, and patches/fixes/updates were typically released within 24-72 additional hours. These are exemplary responses, and reflect why I choose to conduct vulnerability research. I believe we, as web application professionals (both developers and security practitioners), are beholden to the greater public and must endeavor to protect the online safety of the Internet consumer. <br />To each of these vendors/developers I'd like to issue a hearty "well done" and issue public kudos for their diligence and security consciousness, on behalf of consumers and website operators.<br />To Lukas of <a href="http://planetluc.com/en/" target="_blank">PlanetLuc</a>, Jasper and Eric of <a href="http://infrae.com/products/silva" target="_blank">Infrae/Silva</a>, Alexander of <a href="http://www.compactcms.nl/" target="_blank">CompactCMS</a>, and Peter from <a href="http://activecampaign.com/" target="_blank">ActiveCampaign</a> may I say that your efforts are greatly appreciated. Where too few choose to do the right thing, your responses leave us with the perception of caring and integrity.<br />Thank you.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/11/vulnerabilities-quickly-mitigated-by.html&title=Vulnerabilities%20quickly%20mitigated%20by%20security-conscious%20vendors " title="Vulnerabilities quickly mitigated by security-conscious vendors ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/11/vulnerabilities-quickly-mitigated-by.html" title="Vulnerabilities quickly mitigated by security-conscious vendors ">digg</a> | <a href="http://slashdot.org/submit.pl?url=http://holisticinfosec.blogspot.com/2008/11/vulnerabilities-quickly-mitigated-by.html">Submit to Slashdot</a>]]></content:encoded>
      <pubDate>Tue, 11 Nov 2008 17:10:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/responses">responses</category>
      <category domain="http://securityratty.com/tag/swift responses">swift responses</category>
      <category domain="http://securityratty.com/tag/exemplary responses">exemplary responses</category>
      <category domain="http://securityratty.com/tag/issue public kudos">issue public kudos</category>
      <category domain="http://securityratty.com/tag/public">public</category>
      <category domain="http://securityratty.com/tag/issue">issue</category>
      <category domain="http://securityratty.com/tag/vendors">vendors</category>
      <category domain="http://securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://securityratty.com/tag/web application professionals">web application professionals</category>
      <source url="http://holisticinfosec.blogspot.com/2008/11/vulnerabilities-quickly-mitigated-by.html">Vulnerabilities quickly mitigated by security-conscious vendors</source>
    </item>
    <item>
      <title><![CDATA[Monthly Blog Round-Up October 2008]]></title>
      <link>http://securityratty.com/article/425e8bb2014656857a1c215075620790</link>
      <guid>http://securityratty.com/article/425e8bb2014656857a1c215075620790</guid>
      <description><![CDATA[As we all know, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see today . These monthly round-ups is an attempt to remind...]]></description>
      <content:encoded><![CDATA[<p>As we all know, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>. These <a href="http://chuvakin.blogspot.com/search/label/Monthly">monthly round-ups</a> is an attempt to remind people of useful content from the past month!</p>  <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">&quot;Security Warrior&quot; blog</a> </strong>round-up of top 5 popular posts and topics.</p>  <ol>   <li>OF COURSE, the news of my “transition” is the item #1, by far. “<a href="http://chuvakin.blogspot.com/2008/10/change.html">Change!!!</a>” and “<a href="http://www.qualys.com/solutions/pci_compliance/">Qualys</a>” posts rule the list.</li>    <li>Last month I posted a bunch of my presentations on logs, security, etc on the blog.&#160; “<a href="http://www.slideshare.net/anton_chuvakin/logs-for-incident-response-and-forensics-key-issues-for-govcertnl-2008-presentation-620704">Presentation from GOVCERT.NL 2008: Log Forensics</a>” takes one of the tops spots; and so do “<a href="http://www.slideshare.net/anton_chuvakin/application-logging-good-bad-ugly-beautiful-presentation">Presentation on Application Logging, Done Wrong or Very Wrong</a>” and “<a href="http://www.slideshare.net/anton_chuvakin/logs-vs-insiders-presentation">Presentation on Optimizing Your Logging for Insider Attack Tracking</a>.”&#160; BTW, all the presentations are <a href="http://chuvakin.blogspot.com/search/label/presentation">here</a>.</li>    <li>Shockingly, <a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">AGAIN</a> this month, the &quot;<a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Top 11 Reasons to Secure and Protect Your Logs</a>&quot; came up as #1 most popular post (maybe driven by <a href="http://chuvakin.blogspot.com/2008/08/poll-9-how-much-log-security-do-you.html">my poll</a>).&#160; BTW, see <a href="http://chuvakin.blogspot.com/search/label/poll">my other logging polls</a> and my other “top 11” lists.</li>    <li>SIEM bashing reached a new high (eh…“low”? :-)), now that Richard is <a href="http://taosecurity.blogspot.com/2008/10/security-event-correlation-looking-back_4144.html">helping too</a>;&#160; my “<a href="http://chuvakin.blogspot.com/2008/06/11-signs-that-your-siem-is-dog-or-you.html">11 Signs That Your SIEM Is A Dog or &quot;Raffy, You Killed SIM!&quot;</a> is on the top list. It is both humorous and sadly true (and <a href="http://www.networkworld.com/cgi-bin/mailto/x.cgi?pagetosend=/export/home/httpd/htdocs/reviews/2008/063008-test-siem.html&amp;pagename=/reviews/2008/063008-test-siem.html&amp;pageurl=http://www.networkworld.com/reviews/2008/063008-test-siem.html&amp;site=security">backed up by other sources</a> and <a href="http://taosecurity.blogspot.com/2008/10/security-event-correlation-looking-back_4144.html">here</a>.)</li>    <li>Somewhat predictably, PCI compliance is obviously still all the rage: <a href="http://chuvakin.blogspot.com/2008/02/must-do-logging-for-pci.html">MUST-DO Logging for PCI?</a> post was again propelled to a place in my monthly Top5 list.</li> </ol>  <p><a href="http://chuvakin.blogspot.com/search/label/Monthly">See you</a> in November.</p>  <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - September 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - August 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/08/monthly-blog-round-up-july-2008.html">Monthly Blog Round-Up - July 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/07/monthly-blog-round-up-june-2008.html">Monthly Blog Round-Up - June 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/06/monthly-blog-round-up-may-2008.html">Monthly Blog Round-Up - May 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/05/monthly-blog-round-up-april-2008.html">Monthly Blog Round-Up - April 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a> </li>    <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a> </li> </ul>  <p>&#160; <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:7192e29b-e335-4630-8b0b-dc37806d54ee" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati Tags: <a href="http://technorati.com/tags/blog" rel="tag">blog</a>,<a href="http://technorati.com/tags/security" rel="tag">security</a>,<a href="http://technorati.com/tags/loggings" rel="tag">loggings</a>,<a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div></p>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=bZriN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=bZriN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=8jskN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=8jskN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=haLRN"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=haLRN" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/448986147" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 10 Nov 2008 13:35:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/monthly round-ups">monthly round-ups</category>
      <category domain="http://securityratty.com/tag/monthly top5 list">monthly top5 list</category>
      <category domain="http://securityratty.com/tag/posts">posts</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/448986147/monthly-blog-round-up-october-2008.html">Monthly Blog Round-Up October 2008</source>
    </item>
    <item>
      <title><![CDATA[The Bot Monsters are right outside your door!]]></title>
      <link>http://securityratty.com/article/976622d0fcfc683b71677e19ae6cf4fe</link>
      <guid>http://securityratty.com/article/976622d0fcfc683b71677e19ae6cf4fe</guid>
      <description><![CDATA[GO Chicken Heart! Sorry, a flashback to my days as a kid. Yes, I was a kid! Make sure your Firewall is properly configured to thwart attacks or you may be getting a trick instead of a treat this...]]></description>
      <content:encoded><![CDATA[<div > GO Chicken Heart!<br/>Sorry, a flashback to my days as a kid. Yes, I was a kid!<br/>Make sure your Firewall is properly configured to thwart attacks or you may be getting a trick instead of a treat this Halloween. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/D9A864F7-C94A-4F4A-8311-CF830E388C95/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/b5bdb15a-4555-4cc9-bb0b-53d081ab73eb/D9A864F7-C94A-4F4A-8311-CF830E388C95/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.pcworld.com/article/152965/article?tk=nl_spxhow" href="http://www.pcworld.com/article/152965/article?tk=nl_spxhow" style="font-size: 11px;">www.pcworld.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.pcworld.com/article/152965/article?tk=nl_spxhow -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Don&#8217;t Be Dragooned Into the Botnet Army</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.pcworld.com/article/152965/article?tk=nl_spxhow --><H2>A favorite multipurpose weapon of online thieves is growing larger and more powerful, according to those who combat the threat.</H2></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.pcworld.com/article/152965/article?tk=nl_spxhow --><P>The malware armies are growing, with a sharp rise in the number of computers <A href="http://www.pcworld.com/businesscenter/article/137797/attack_of_the_killer_bots.html">corralled into botnets</A>&#8211;far-flung networks of infected PCs that digital crooks use to steal financial account data, relay spam, and launch crippling Internet attacks. Now that popular Web sites can invisibly and unwillingly spread malicious software, the days of staying safe just by being careful where you surf are sadly long gone. But you can take steps to protect yourself and your PC from these threats.</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/D9A864F7-C94A-4F4A-8311-CF830E388C95/blog/" title="blog or email this clip"><img src="http://content9.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_301008034857"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=301008034857&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=301008034857&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=301008034857&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_301008034857" /></a></P>]]></content:encoded>
      <pubDate>Thu, 30 Oct 2008 12:48:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/popular web sites">popular web sites</category>
      <category domain="http://securityratty.com/tag/favorite multipurpose weapon">favorite multipurpose weapon</category>
      <category domain="http://securityratty.com/tag/botnets far-flung networks">botnets far-flung networks</category>
      <category domain="http://securityratty.com/tag/financial account data">financial account data</category>
      <category domain="http://securityratty.com/tag/thwart attacks">thwart attacks</category>
      <category domain="http://securityratty.com/tag/internet attacks">internet attacks</category>
      <category domain="http://securityratty.com/tag/malware armies">malware armies</category>
      <category domain="http://securityratty.com/tag/online thieves">online thieves</category>
      <category domain="http://securityratty.com/tag/botnet army">botnet army</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=649">The Bot Monsters are right outside your door!</source>
    </item>
    <item>
      <title><![CDATA[The Seven Habits of Highly Ineffective Terrorists]]></title>
      <link>http://securityratty.com/article/9ded3dd1627a4f9a60f16de4625687eb</link>
      <guid>http://securityratty.com/article/9ded3dd1627a4f9a60f16de4625687eb</guid>
      <description><![CDATA[Most counterterrorism policies fail, not because of tactical problems, but because of a fundamental misunderstanding of what motivates terrorists in the first place. If we're ever going to defeat...]]></description>
      <content:encoded><![CDATA[<p>Most counterterrorism policies fail, not because of tactical problems, but because of a fundamental misunderstanding of what motivates terrorists in the first place. If we're ever going to defeat terrorism, we need to understand what drives people to become terrorists in the first place. </p>

<p>Conventional wisdom holds that terrorism is inherently political, and that people become terrorists for political reasons. This is the "strategic" model of terrorism, and it's basically an economic model. It posits that people resort to terrorism when they believe -- rightly or wrongly -- that terrorism is worth it; that is, when they believe the political gains of terrorism minus the political costs are greater than if they engaged in some other, more peaceful form of protest. It's assumed, for example, that people join Hamas to achieve a Palestinian state; that people join the PKK to attain a Kurdish national homeland; and that people join al-Qaida to, among other things, get the United States out of the Persian Gulf. </p>

<p>If you believe this model, the way to fight terrorism is to change that equation, and that's what most experts advocate. Governments tend to minimize the political gains of terrorism through a no-concessions policy; the international community tends to recommend reducing the political grievances of terrorists via appeasement, in hopes of getting them to renounce violence. Both advocate policies to provide effective nonviolent alternatives, like free elections. </p>

<p>Historically, none of these solutions has worked with any regularity. Max Abrahms, a predoctoral fellow at Stanford University's Center for International Security and Cooperation, has studied dozens of terrorist groups from all over the world. He argues that the model is wrong. In a <a href="http://maxabrahms.com/pdfs/DC_250-1846.pdf">paper</a> published this year in International Security that -- sadly -- doesn't have the title "Seven Habits of Highly Ineffective Terrorists," he discusses, well, seven habits of highly ineffective terrorists. These seven tendencies are seen in terrorist organizations all over the world, and they directly contradict the theory that terrorists are political maximizers: </p>

<p>Terrorists, he writes, (1) attack civilians, a policy that has a lousy track record of convincing those civilians to give the terrorists what they want; (2) treat terrorism as a first resort, not a last resort, failing to embrace nonviolent alternatives like elections; (3) don't compromise with their target country, even when those compromises are in their best interest politically; (4) have protean political platforms, which regularly, and sometimes radically, change; (5) often engage in anonymous attacks, which precludes the target countries making political concessions to them; (6) regularly attack other terrorist groups with the same political platform; and (7) resist disbanding, even when they consistently fail to achieve their political objectives or when their stated political objectives have been achieved. </p>

<p>Abrahms has an alternative model to explain all this: People turn to terrorism for social solidarity. He theorizes that people join terrorist organizations worldwide in order to be part of a community, much like the reason inner-city youths join gangs in the United States. </p>

<p>The evidence supports this. Individual terrorists often have no prior involvement with a group's political agenda, and often join multiple terrorist groups with incompatible platforms. Individuals who join terrorist groups are frequently not oppressed in any way, and often can't describe the political goals of their organizations. People who join terrorist groups most often have friends or relatives who are members of the group, and the great majority of terrorist are socially isolated: unmarried young men or widowed women who weren't working prior to joining. These things are true for members of terrorist groups as diverse as the IRA and al-Qaida. </p>

<p>For example, several of the 9/11 hijackers planned to fight in Chechnya, but they didn't have the right paperwork so they attacked America instead. The mujahedeen had no idea whom they would attack after the Soviets withdrew from Afghanistan, so they sat around until they came up with a new enemy: America. Pakistani terrorists regularly defect to another terrorist group with a totally different political platform. Many new al-Qaida members say, unconvincingly, that they decided to become a jihadist after reading an extreme, anti-American blog, or after converting to Islam, sometimes just a few weeks before. These people know little about politics or Islam, and they frankly don't even seem to care much about learning more. The blogs they turn to don't have a lot of substance in these areas, even though more informative blogs do exist. </p>

<p>All of this explains the seven habits. It's not that they're ineffective; it's that they have a different goal. They might not be effective politically, but they are effective socially: They all help preserve the group's existence and cohesion. </p>

<p>This kind of analysis isn't just theoretical; it has practical implications for counterterrorism. Not only can we now better understand who is likely to become a terrorist, we can engage in strategies specifically designed to weaken the social bonds within terrorist organizations. Driving a wedge between group members -- commuting prison sentences in exchange for actionable intelligence, planting more double agents within terrorist groups -- will go a long way to weakening the social bonds within those groups. </p>

<p>We also need to pay more attention to the socially marginalized than to the politically downtrodden, like unassimilated communities in Western countries. We need to support vibrant, benign communities and organizations as alternative ways for potential terrorists to get the social cohesion they need. And finally, we need to minimize collateral damage in our counterterrorism operations, as well as clamping down on bigotry and hate crimes, which just creates more dislocation and social isolation, and the inevitable calls for revenge.</p>

<p>This essay <a href="http://www.wired.com/print/politics/security/commentary/securitymatters/2008/10/securitymatters_1002">previously appeared</a> on Wired.com.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=QW5fM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=QW5fM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=YCnjM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=YCnjM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 01:48:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ineffective">ineffective</category>
      <category domain="http://securityratty.com/tag/highly ineffective terrorists">highly ineffective terrorists</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/people join">people join</category>
      <category domain="http://securityratty.com/tag/people join hamas">people join hamas</category>
      <category domain="http://securityratty.com/tag/people join al-qaida">people join al-qaida</category>
      <category domain="http://securityratty.com/tag/terrorist organizations">terrorist organizations</category>
      <category domain="http://securityratty.com/tag/organizations">organizations</category>
      <category domain="http://securityratty.com/tag/al-qaida">al-qaida</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/the_seven_habit.html">The Seven Habits of Highly Ineffective Terrorists</source>
    </item>
    <item>
      <title><![CDATA[Security Matters: The Seven Habits of Highly Ineffective Terrorists]]></title>
      <link>http://securityratty.com/article/d7f6e34d46350bc3546ccbac96bdd613</link>
      <guid>http://securityratty.com/article/d7f6e34d46350bc3546ccbac96bdd613</guid>
      <description><![CDATA[Most counterterrorism policies fail, not because of tactical problems, but because of a fundamental misunderstanding of what motivates terrorists in the first place. If we're ever going to defeat...]]></description>
      <content:encoded><![CDATA[<p>
Most counterterrorism policies fail, not because of tactical problems, but because of a fundamental misunderstanding of what motivates terrorists in the first place. If we're ever going to defeat terrorism, we need to understand what drives people to become terrorists in the first place.
</p>

<p>
Conventional wisdom holds that terrorism is inherently political, and that people become terrorists for political reasons. This is the "strategic" model of terrorism, and it's basically an economic model. It posits that people resort to terrorism when they believe -- rightly or wrongly -- that terrorism is worth it; that is, when they believe the political gains of terrorism minus the political costs are greater than if they engaged in some other, more peaceful form of protest. It's assumed, for example, that people join Hamas to achieve a Palestinian state; that people join the PKK to attain a Kurdish national homeland; and that people join al-Qaida to, among other things, get the United States out of the Persian Gulf.
</p>

<p>
If you believe this model, the way to fight terrorism is to change that equation, and that's what most experts advocate. Governments tend to minimize the political gains of terrorism through a no-concessions policy; the international community tends to recommend reducing the political grievances of terrorists via appeasement, in hopes of getting them to renounce violence. Both advocate policies to provide effective nonviolent alternatives, like free elections.
</p>

<p>
Historically, none of these solutions has worked with any regularity. Max Abrahms, a predoctoral fellow at Stanford University's Center for International Security and Cooperation, has studied dozens of terrorist groups from all over the world. He argues that the model is wrong. In a <a href="http://maxabrahms.com/pdfs/DC_250-1846.pdf">paper</a> (.pdf) published this year in <cite>International Security</cite> that -- sadly -- doesn't have the title "Seven Habits of Highly Ineffective Terrorists," he discusses, well, seven habits of highly ineffective terrorists. These seven tendencies are seen in terrorist organizations all over the world, and they directly contradict the theory that terrorists are political maximizers:
</p>

<p>
Terrorists, he writes, (1) attack civilians, a policy that has a lousy track record of convincing those civilians to give the terrorists what they want; (2) treat terrorism as a first resort, not a last resort, failing to embrace nonviolent alternatives like elections; (3) don't compromise with their target country, even when those compromises are in their best interest politically; (4) have protean political platforms, which regularly, and sometimes radically, change; (5) often engage in anonymous attacks, which precludes the target countries making political concessions to them; (6) regularly attack other terrorist groups with the same political platform; and (7) resist disbanding, even when they consistently fail to achieve their political objectives or when their stated political objectives have been achieved.
</p>


<p>
Abrahms has an alternative model to explain all this:  People turn to terrorism for social solidarity. He theorizes that people join terrorist organizations worldwide in order to be part of a community, much like the reason inner-city youths join gangs in the United States.
</p>

<p>
The evidence supports this. Individual terrorists often have no prior involvement with a group's political agenda, and often join multiple terrorist groups with incompatible platforms. Individuals who join terrorist groups are frequently not oppressed in any way, and often can't describe the political goals of their organizations. People who join terrorist groups most often have friends or relatives who are members of the group, and the great majority of terrorist are socially isolated: unmarried young men or widowed women who weren't working prior to joining. These things are true for members of terrorist groups as diverse as the IRA and al-Qaida.
</p>

<p>
For example, several of the 9/11 hijackers planned to fight in Chechnya, but they didn't have the right paperwork so they attacked America instead. The mujahedeen had no idea whom they would attack after the Soviets withdrew from Afghanistan, so they sat around until they came up with a new enemy: America. Pakistani terrorists regularly defect to another terrorist group with a totally different political platform. Many new al-Qaida members say, unconvincingly, that they decided to become a jihadist after reading an extreme, anti-American blog, or after converting to Islam, sometimes just a few weeks before. These people know little about politics or Islam, and they frankly don't even seem to care much about learning more. The blogs they turn to don't have a lot of substance in these areas, even though more informative blogs do exist.
</p><p>
All of this explains the seven habits. It's not that they're ineffective; it's that they have a different goal. They might not be effective politically, but they are effective socially: They all help preserve the group's existence and cohesion.
</p><p>
This kind of analysis isn't just theoretical; it has practical implications for counterterrorism. Not only can we now better understand who is likely to become a terrorist, we can engage in strategies specifically designed to weaken the social bonds within terrorist organizations. Driving a wedge between group members -- commuting prison sentences in exchange for actionable intelligence, planting more double agents within terrorist groups -- will go a long way to weakening the social bonds within those groups.
</p><p>
We also need to pay more attention to the socially marginalized than to the politically downtrodden, like unassimilated communities in Western countries. We need to support vibrant, benign communities and organizations as alternative ways for potential terrorists to get the social cohesion they need. And finally, we need to minimize collateral damage in our counterterrorism operations, as well as clamping down on bigotry and hate crimes, which just creates more dislocation and social isolation, and the inevitable calls for revenge.
</p>
<p>
---
</p>
<p><cite>Bruce Schneier is Chief Security Technology Officer of BT, and author of </cite>Beyond Fear: Thinking Sensibly About Security in an Uncertain World<cite>.</cite>
</p><br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=16939d16056d6d01accd415177a76dbb" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=16939d16056d6d01accd415177a76dbb" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=igbdM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=igbdM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=CO91m"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=CO91m" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=rBiKm"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=rBiKm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=qO8rM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=qO8rM" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=0b0DM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=0b0DM" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=nYn4m"><img src="http://feeds.wired.com/~f/wired/politics/security?i=nYn4m" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=EcnRm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=EcnRm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=UhYOM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=UhYOM" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/408903389" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/408903390" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ineffective">ineffective</category>
      <category domain="http://securityratty.com/tag/highly ineffective terrorists">highly ineffective terrorists</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/people join">people join</category>
      <category domain="http://securityratty.com/tag/people join hamas">people join hamas</category>
      <category domain="http://securityratty.com/tag/people join al-qaida">people join al-qaida</category>
      <category domain="http://securityratty.com/tag/terrorist organizations">terrorist organizations</category>
      <category domain="http://securityratty.com/tag/organizations">organizations</category>
      <category domain="http://securityratty.com/tag/al-qaida">al-qaida</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/408903390/securitymatters_1002">Security Matters: The Seven Habits of Highly Ineffective Terrorists</source>
    </item>
    <item>
      <title><![CDATA[Monthly Blog Round-Up - September 2008]]></title>
      <link>http://securityratty.com/article/7bcc00d7fa1280bf6a276c7c821e4445</link>
      <guid>http://securityratty.com/article/7bcc00d7fa1280bf6a276c7c821e4445</guid>
      <description><![CDATA[As we all know, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see today . These monthly round-ups is an attempt to remind...]]></description>
      <content:encoded><![CDATA[<p>As we all know, blogs are a bit &quot;stateless&quot; and a lot of good content gets lost since many people, sadly, only pay attention to what they see <em>today</em>. These <a href="http://chuvakin.blogspot.com/search/label/Monthly">monthly round-ups</a> is an attempt to remind people of useful content from the past month!</p>  <p>So, here is my next <strong>monthly <a href="chuvakin.blogspot.com/">&quot;Security Warrior&quot; blog</a> </strong>round-up of top 5 popular posts and topics.</p>  <ol>   <li>Shockingly, <a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">AGAIN</a> this month, the &quot;<a href="http://chuvakin.blogspot.com/2007/10/top-11-reasons-to-secure-and-protect.html">Top 11 Reasons to Secure and Protect Your Logs</a>&quot; came up as #1 most popular post (maybe driven by <a href="http://chuvakin.blogspot.com/2008/08/poll-9-how-much-log-security-do-you.html">my poll</a>).&#160; BTW, see <a href="http://chuvakin.blogspot.com/search/label/poll">my other logging polls</a>. </li>    <li><a href="http://chuvakin.blogspot.com/search/label/ROI">Security ROI</a> - and its parent topic &quot;security metrics&quot;/&quot;measuring security&quot; - is definitely an ongoing <strong>HOT</strong> debate. Indeed, the old post <a href="http://chuvakin.blogspot.com/2007/07/security-roi-pile-up.html">&quot;</a><a href="http://chuvakin.blogspot.com/2007/07/security-roi-pile-up.html">Security ROI Pile-Up!</a><a href="http://chuvakin.blogspot.com/2007/07/security-roi-pile-up.html">&quot;</a> takes the #2 spot this month, possibly propelled by a more recent post &quot;<a href="http://chuvakin.blogspot.com/2008/09/second-roi-war.html">Second ROI War</a>.&quot;</li>    <li>Some say that &quot;short blog posts rule&quot;, but, in reality, good, fun content is the best. Here is an example:&#160; &quot;<a href="http://chuvakin.blogspot.com/2008/09/dumb-luck-is-strategy.html">Dumb Luck IS a Strategy!</a>&quot; post makes the top list. In it, I try to explore why people still ignore security concerns even if stare people in the face...</li>    <li>Discussion on what you can do to soften the impact of &quot;getting 0wned&quot; ( &quot;<a href="http://chuvakin.blogspot.com/2008/09/what-can-you-do.html">What CAN You Do?</a>&quot;) made the top list. Good!</li>    <li>As before, my post &quot;<a href="http://chuvakin.blogspot.com/2008/06/11-signs-that-your-siem-is-dog-or-you.html">11 Signs That Your SIEM Is A Dog or &quot;Raffy, You Killed SIM!&quot;</a>&quot;. It is both humorous and sadly true (and <a href="http://www.networkworld.com/cgi-bin/mailto/x.cgi?pagetosend=/export/home/httpd/htdocs/reviews/2008/063008-test-siem.html&amp;pagename=/reviews/2008/063008-test-siem.html&amp;pageurl=http://www.networkworld.com/reviews/2008/063008-test-siem.html&amp;site=security">backed up by other sources</a>) </li>    <li>Still burning hot is a post with my irreverent comments on a Terry Childs saga. Namely, &quot;<a href="http://chuvakin.blogspot.com/2008/07/on-doomsaying-terry-childs-case.html">On Doomsaying (Terry Childs case)</a>&quot;, &quot;<a href="http://chuvakin.blogspot.com/2008/07/on-doomsaying-terry-childs-case.html">So ... Am I? Maybe I Am!</a>&quot; and &quot;<a href="http://chuvakin.blogspot.com/2008/07/admins-good-guys-or-am-not-idiot.html">Admins , Good Guys or &quot;I am NOT an Idiot!&quot;</a>&quot; </li> </ol>  <p><a href="http://chuvakin.blogspot.com/search/label/Monthly">See you</a> in October.</p>  <p><strong>Possibly related posts / past monthly popular blog round-ups:</strong></p>  <ul>   <li><a href="http://chuvakin.blogspot.com/2008/09/monthly-blog-round-up-august-2008.html">Monthly Blog Round-Up - August 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/08/monthly-blog-round-up-july-2008.html">Monthly Blog Round-Up - July 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/07/monthly-blog-round-up-june-2008.html">Monthly Blog Round-Up - June 2008</a> </li>    <li><a href="http://chuvakin.blogspot.com/2008/06/monthly-blog-round-up-may-2008.html">Monthly Blog Round-Up - May 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/05/monthly-blog-round-up-april-2008.html">Monthly Blog Round-Up - April 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/04/monthly-blog-round-up-march-2008.html">Monthly Blog Round-Up - March 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/03/monthly-blog-round-up-february-2008.html">Monthly Blog Round-Up - February 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/02/monthly-blog-round-up-january-2008.html">Monthly Blog Round-Up - January 2008</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2008/01/monthly-blog-round-up-december-2007.html">Monthly Blog Round-Up - December 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-november-2007.html">Monthly Blog Round-Up - November 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/11/monthly-blog-round-up-october-2007.html">Monthly Blog Round-Up - October 2007</a>&#160;&#160; </li>    <li><a href="http://chuvakin.blogspot.com/2007/10/monthly-blog-round-up-september-2007.html">Monthly Blog Round-Up - September 2007</a> </li>    <li><a href="http://chuvakin.blogspot.com/2007/08/monthly-blog-round-up-august-2007.html">Monthly Blog Round-Up - August 2007</a> </li> </ul>  <p>&#160;</p>  <p></p>  <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:7192e29b-e335-4630-8b0b-dc37806d54ee" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati Tags: <a href="http://technorati.com/tags/blog" rel="tag">blog</a>,<a href="http://technorati.com/tags/security" rel="tag">security</a>,<a href="http://technorati.com/tags/loggings" rel="tag">loggings</a>,<a href="http://technorati.com/tags/monthly" rel="tag">monthly</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=IIM1M"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=IIM1M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=bxJsM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=bxJsM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=fBKoM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=fBKoM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/408700309" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 12:19:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/monthly blog round-up">monthly blog round-up</category>
      <category domain="http://securityratty.com/tag/blog">blog</category>
      <category domain="http://securityratty.com/tag/blog round-up">blog round-up</category>
      <category domain="http://securityratty.com/tag/monthly">monthly</category>
      <category domain="http://securityratty.com/tag/security roi pile-up">security roi pile-up</category>
      <category domain="http://securityratty.com/tag/security roi">security roi</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/ignore security concerns">ignore security concerns</category>
      <category domain="http://securityratty.com/tag/security metrics">security metrics</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/408700309/monthly-blog-round-up-september-2008.html">Monthly Blog Round-Up - September 2008</source>
    </item>
    <item>
      <title><![CDATA[A Diverse Portfolio of Fake Security Software - Part Seven]]></title>
      <link>http://securityratty.com/article/51d3037b3c70ac0a110b0606415c4194</link>
      <guid>http://securityratty.com/article/51d3037b3c70ac0a110b0606415c4194</guid>
      <description><![CDATA[In case you haven't heard - Microsoft and the Washington state are suing a U.S based -- naturally -- &quot;scareware&quot; vendor Branch Software

We won't tolerate the use of alarmist warnings or deceptive...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/SOKKvX_5seI/AAAAAAAACMw/V5DqP_zsvuk/s1600-h/lawsuit_got_one.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="161" src="http://3.bp.blogspot.com/_wICHhTiQmrA/SOKKvX_5seI/AAAAAAAACMw/FVk3TrvBJIo/s200-R/lawsuit_got_one.gif" width="200" /></a>In case you haven't heard - <a href="http://voices.washingtonpost.com/securityfix/2008/09/microsoft_washington_state_tar.html">Microsoft and the Washington state</a> are suing a U.S based -- naturally -- "scareware" vendor Branch Software :<br />
<br />
"<i>We won't tolerate the use of alarmist warnings or deceptive 'free scans' to  trick consumers into buying software to fix a problem that doesn't even exist,"  Washington <b style="font-weight: normal;">Attorney General Rob McKenna</b> said. <b>"We've repeatedly  proven that Internet companies that prey on consumers' anxieties are within our  reach.</b></i><b>"</b><br />
<br />
Sadly, Branch Software is the tip of the iceberg on the top of the affiliates participating in different affiliation based programs, which similar to <a href="http://ddanchev.blogspot.com/2008/03/cybersquatting-security-vendors-for.html">IBSOFTWARE CYPRUS</a> and <a href="http://ddanchev.blogspot.com/2008/04/cybersquatting-symantecs-norton.html">Interactivebrands</a>, which I've been tracking down for a while, are the aggregators of scareware<b><span style="font-weight: normal;"> that popped up on the radars due to their extensive portfolios. These three companies offering software bundles or plain simple fake software, are somewhere in between the food chain of this ecosystem, with the real vendors paying out the commissions on a per installation basis slowly starting to issue invitation codes that they've distributed only across invite-only forums/sections of particular forums.</span></b><br />
<br />
Behind these brands is everyone that is participating in the franchise and is putting personal efforts into monetizing the high payout rates that the fake security software vendor is paying for successful installation. These high payout rates -- with the financing naturally coming straight from other criminal activities online -- are in fact so high, that I can easily say that the last two quarters we've witnesses the largest increase of such domains ever, and they're only heating up since the typosquatting possibilities are countless and they seem to know that as well.<br />
<br />
It's important to point out that their business model of acquiring traffic is outsourced to all the affiliates that do the blackhat SEO, SQL injections, web sessions hijacking of malware infected hosts in order to monetize, so basically, you have an affiliates network whose actions are directly driving the growth into all these areas. Throwing money into the underground marketplace as a "financial injection", is proving itself as a growth factor, and incentive for innovation on behalf of all the participants.<br />
<br />
Here are some of the most recent fake security software domains, a "deja vu" moment with a known RBN domain from a "previous life" that is also parked at one of the servers, and evidence that typosquatting for fraudulent purposes is still pretty active with a dozen of Norton Antivirus related domains, some of which have already started issuing "fake security notices" by brandjacking the vendor for traffic acquisition purposes.<br />
<br />
<b>Antivirus-Alert .com </b>(203.117.111.47) where<b> pepato .org</b> a domain that was used in the <a href="http://ddanchev.blogspot.com/2008/03/wiredcom-and-historycom-getting-rbn-ed.html">Wired.com and History.com IFRAME injections</a>, which back in March was also hosted at Hostfresh (58.65.238.59).<br />
<br />
<b>softload2008name .com</b> (78.157.143.250)<br />
<b>softload2008nm .com<br />
softload2008n .com<br />
softload2008jq .com</b><br />
<br />
<b>microantivir-2009 .com</b> (91.208.0.223)<br />
<b>scanner.microantivir-2009 .com<br />
microantivir2009 .com<br />
microantivirus-2009 .com<br />
microantivirus2009 .com</b><br />
<br />
<b>ms-scan .com</b> (91.208.0.228)<br />
<b>msscanner .com</b><br />
<b>ms-scanner .com</b><br />
<br />
<b>Personalantispy .com</b> (93.190.139.197)<br />
<b>freepcsecure .com<br />
quickinstallpack .com<br />
quickdownloadpro .com<br />
advancedcleaner .com<br />
performanceoptimizer .com<br />
internetanonymizer .com</b><br />
<br />
<b>ieprogramming .com</b> (92.62.101.83)<br />
<b>uptodatepage .com<br />
fileliveupdate .com<br />
qwertypages .com<br />
sharedupdates .com<br />
ierenewals .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://4.bp.blogspot.com/_wICHhTiQmrA/SOKZEpXlfhI/AAAAAAAACM4/eJI5I5BgGoQ/s1600-h/norton_alert.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/SOKZEpXlfhI/AAAAAAAACM4/Rpjz8LY4LEQ/s200-R/norton_alert.png" /></a><b>norton-antivirus-alert .com<br />
norton-anti-virus-2007 .com <br />
norton-antivirus-2007 .com <br />
norton-antivirus2007 .com <br />
nortonantivirus2007 .com <br />
norton-antivirus-2008 .com <br />
nortonantivirus2008 .com <br />
nortonantivirus2008freedownload .com <br />
norton-antivirus-2009 .com <br />
nortonantivirus2009 .com <br />
norton-antivirus-2010 .com <br />
nortonantivirus2010 .com <br />
nortonantivirus360 .com <br />
nortonantivirus8 .com <br />
nortonantivirusa .com <br />
nortonantivirusactivation .com <br />
norton-antivirus-alert .com <br />
nortonantivirusalerts .com <br />
norton--anti-virus .com <br />
norton-anti-virus .com <br />
norton-antivirus .com <br />
nortonanti-virus .com <br />
nortonantivirus.com <br />
nortonantiviruscom .com <br />
nortonantiviruscorporate .com <br />
nortonantiviruscorporateedition .com <br />
nortonantiviruscoupon .com <br />
nortonantivirusdefinition .com <br />
nortonantivirusdefinitions .com <br />
nortonantivirusdirect .com</b><br />
<br />
Fake Antivirus Inc. is not going away as long as the affiliate based model remains active. If the real vendors were greedy enough not to share the revenues with others, they would have been the one popping up on the radar, compared to the situation where it's the affiliate network's participations greed that's increasing their visibility online.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security_24.html">A Diverse Portfolio of Fake Security Software - Part Six</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Five</a> <br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_25.html">A  Diverse Portfolio of Fake Security Software - Part Four</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security_20.html">A  Diverse Portfolio of Fake Security Software - Part Three</a><b> </b><br />
<a href="http://ddanchev.blogspot.com/2008/08/diverse-portfolio-of-fake-security.html">A  Diverse Portfolio of Fake Security Software - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/diverse-portfolio-of-fake-security.html">Diverse  Portfolio of Fake Security Software</a> <br />
<a href="http://ddanchev.blogspot.com/2008/04/cybersquatting-symantecs-norton.html">Cybersquatting Symantec's Norton AntiVirus</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/cybersquatting-security-vendors-for.html">Cybersquatting Security Vendors for Fraudulent Purposes</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/fake-porn-sites-serving-malware-part.html">Fake  Porn Sites Serving Malware - Part Three</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/fake-porn-sites-serving-malware-part.html">Fake  Porn Sites Serving Malware - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/fake-porn-sites-serving-malware.html">Fake  Porn Sites Serving Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/09/estdomains-and-intercage-vs-cybercrime.html">EstDomains  and Intercage VS Cybercrime</a><br />
<a href="http://ddanchev.blogspot.com/2008/08/fake-security-software-domains-serving.html">Fake  Security Software Domains Serving Exploits</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/localized-fake-security-software.html">Localized  Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/got-your-xpshield-up-and-running.html">Got  Your XPShield Up and Running?</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/fake-pestpatrol-security-software.html">Fake  PestPatrol Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/rbns-fake-security-software.html">RBN's  Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/lazy-summer-days-at-ukrtelegroup-ltds.html">Lazy  Summer Days at UkrTeleGroup Ltd</a><br />
<a href="http://ddanchev.blogspot.com/2008/02/geolocating-malicious-isps.html">Geolocating  Malicious ISPs</a><br />
<a href="http://ddanchev.blogspot.com/2008/06/malicious-isps-you-rarely-see-in-any.html">The  Malicious ISPs You Rarely See in Any Report</a><b> </b><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=88nnL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=88nnL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=F8uQL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=F8uQL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=T1xil"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=T1xil" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=eAF4l"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=eAF4l" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rdg2L"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rdg2L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=nXveL"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=nXveL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=moMol"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=moMol" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/407645950" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 12:35:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/fake security software">fake security software</category>
      <category domain="http://securityratty.com/tag/vendor branch software">vendor branch software</category>
      <category domain="http://securityratty.com/tag/vendor">vendor</category>
      <category domain="http://securityratty.com/tag/diverse portfolio">diverse portfolio</category>
      <category domain="http://securityratty.com/tag/fake porn sites">fake porn sites</category>
      <category domain="http://securityratty.com/tag/software bundles">software bundles</category>
      <category domain="http://securityratty.com/tag/branch software">branch software</category>
      <category domain="http://securityratty.com/tag/norton antivirus">norton antivirus</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/407645950/diverse-portfolio-of-fake-security_30.html">A Diverse Portfolio of Fake Security Software - Part Seven</source>
    </item>
    <item>
      <title><![CDATA[If a tree falls in someone else's silo...]]></title>
      <link>http://securityratty.com/article/16a8e8bbe75a3994d655d2737adf90ce</link>
      <guid>http://securityratty.com/article/16a8e8bbe75a3994d655d2737adf90ce</guid>
      <description><![CDATA[Must read post by Iang

In the case of phishing, it is relatively clear. The developers believe the PKI book. The PKI people believe in the efficacy of digital signatures to prove stuff. The...]]></description>
      <content:encoded><![CDATA[<p>&#160;Must read <a href="https://financialcryptography.com/mt/archives/001093.html">post</a> by Iang:</p><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #666666; font-family: georgia; line-height: 19px; ">In the case of phishing, it is relatively clear. The developers believe the PKI book. The PKI people believe in the efficacy of digital signatures to prove stuff. The cryptographers believe in the perfection of mathematics, and the security world believes in the completeness of their own learning. They are all wrong, but only at the large level of generalisations, not at the detailed level of particular claims. Any one of the claims,&#160;<em>in isolation</em>&#160;can be shown to be true. But, generalising these brittle claims to be solid building blocks is a completely different question. Few of the claims are strong enough to partake in a general model without severe support; the general model of secure browsing is the best evidence of how it is secure in name only.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #666666; font-family: georgia; line-height: 19px;"><br /></span><span style="color: #666666; font-family: georgia; line-height: 19px; ">How then is it built? By accident or by design, a series of claims meet together in a holy ring of righteous architecture. Each of the proponents claim loudly that their part is strong, but the ring has no strength. Eventually, one of the claims in the links is broken. For phishing, the browsers never did have the potential to show authenticity; not only did they not have the security strength to do it (c.f., Skype v.&#160;<a href="http://en.wikipedia.org/wiki/Cross-site_request_forgery" style="color: #003366; font-weight: normal; text-decoration: underline; ">CSRF</a>), they didn&#39;t even do it in practice (recall the lost padlock?), and their recent efforts to show authenticity (c.f. colour debate) reveal how far they are from understanding even the goal, let alone the implementation. Once that link was broken, and money was made, all the others revealed their weaknesses, as crooks systematically worked to breach the lot.</span><br /><span style="color: #666666; font-family: georgia; line-height: 19px; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #666666; font-family: georgia; line-height: 19px; ">If we look at the wider financial collapse, now underscored by the nationalisation of the worlds biggest financiers of mortgages ($ 5.3 trillion.... or is it $ 5.4 ?), we see the same pattern. The bankers believed in their product. The originators believed in their origination, the securitizers believed in their free market and accurate price, and the holders believed in the assets. The CDO, the subprime, the other 100 special names, each was a contract. Each was clear in and of itself. But, when placed end-to-end, in a line, with a bunch of other agreements, the claims that were good in isolation were not strong enough to participate in the super-claim made of the overall edifice.</span><br /><span style="color: #666666; font-family: georgia; line-height: 19px; ">The financial system was built like a bridge; each piece rested on the previous one. And then, the clever architects bent the bridge around ... and around again, until the first piece met the last. The elegant keystone of finance was to finally lift up the first one to rest on the last.</span><br /><span style="color: #666666; font-family: georgia; line-height: 19px; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #666666; font-family: georgia; line-height: 19px; ">Thus, the banks themselves invested their capital in their own product.</span></p></blockquote><p><span style="color: #666666; font-family: georgia; line-height: 19px;"><br /></span></p><div><span style="color: #666666; font-family: georgia; line-height: 19px;"><span style="color: #000000; font-family: &#39;Trebuchet MS&#39;; line-height: 15px; ">Maybe computer security failures won&#39;t ever result in $6 trillion worth of failures, but every day we bet more and more of our economy on networked computer systems. And those architectures are built on the precise mindsets that Iang portrays.</span><br /></span></div><br /><div>Banks are apt to comply with their auditor&#39;s request to run scans their resources, but what they do not do is build systems with architectural integrity. Why do you log in with a username and password? Why are the <a href="http://1raindrop.typepad.com/1_raindrop/2008/09/your-companies-biggest-security-hole---what-is-the-bgp-style-vuln-lurking-in-software-security.html">messaging systems not locked down</a>? Where are the strong identity tokens and claims? Do banks know that they are <a href="http://1raindrop.typepad.com/1_raindrop/2008/08/mainframe-mindset.html">not on a mainframe any more</a>?&#160;</div><br /><div>Sadly, they don&#39;t - they build a web silo and then they hook it up the legacy silo and put a wide open messaging system in between. There is no end to end security design, just silos. The banks build distributed systems, they operate distributed systems, but they don&#39;t design distributed systems.</div><br /><div>It is too bad, its never been a core competency of banks to design systems, but it never mattered before because IBM just drew up the plan and the banks followed it. Now everyone has their own plan, but the security architecture reflects an auditor&#39;s checklist and manager&#39;s <a href="http://1raindrop.typepad.com/1_raindrop/2008/08/golf-driven-security.html">golf games</a> not risk management decisions or security architecture.</div><br /><div>If a tree falls in someone else&#39;s silo, your system doesn&#39;t hear until their silo knocks yours over...</div>]]></content:encoded>
      <pubDate>Mon, 08 Sep 2008 08:29:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/silo">silo</category>
      <category domain="http://securityratty.com/tag/design">design</category>
      <category domain="http://securityratty.com/tag/design systems">design systems</category>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/brittle claims">brittle claims</category>
      <category domain="http://securityratty.com/tag/claims">claims</category>
      <category domain="http://securityratty.com/tag/computer systems">computer systems</category>
      <category domain="http://securityratty.com/tag/legacy silo">legacy silo</category>
      <category domain="http://securityratty.com/tag/banks">banks</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/if-a-tree-falls-in-someone-elses-silo.html">If a tree falls in someone else's silo...</source>
    </item>
  </channel>
</rss>
