<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: salary]]></title>
    <link>http://securityratty.com/tag/salary</link>
    <description></description>
    <pubDate>Mon, 09 Jun 2008 22:31:39 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Wakeup Call for Risk Management]]></title>
      <link>http://securityratty.com/article/5c961827ce1d8ef57419fb5d2d847236</link>
      <guid>http://securityratty.com/article/5c961827ce1d8ef57419fb5d2d847236</guid>
      <description><![CDATA[Blogger: Dan Blum
With the crisis in financial markets still unfolding, it is important to draw what lessons we can from the experience. Since the roots of the crisis lie in a monumental failure of...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Dan Blum</p>

<p>With the crisis in financial markets still unfolding, it is important to draw what lessons we can from the experience. Since the roots of the crisis lie in a monumental failure of risk management, it’s important to understand more about what happened, and then draw some parallels to our business risk management and&nbsp; IT risk management situations.</p>

<p>The risk management failure in the housing market and on Wall Street had multiple interdependent dimensions:</p>

<ul><li><strong>Mortgage lenders abandoned long standing prudent loan practices</strong>. They made too many loans that buyers might not be able to repay. Exotic instruments like ARMs, option ARMs, and interest only loans proliferated. In many cases, all pretense of lending standards were abandoned, so-called “liar loans” approved.</li>

<li><strong>Capital was grossly over-leveraged</strong>. Mortgage lenders and other financial services packaged loans into securities, which they sold to raise capital to support more lending. Real capital reserve requirements to back loans were reduced. Of course, if borrowers could not repay loans, all or parts of the derivative securities would become worthless.</li>

<li><strong>Risk was aggregated at Fannie Mae, Freddie Mac, and mortgage loan insurance companies</strong>. These companies bought or insured some mortgage loans, providing something of a backstop should loans fail. Government sponsored enterprises (GSEs) Fannie and Freddie in turn became over-leveraged and securities that they sold were in turn repackaged in the murky brew of mortgage-backed securities called collateralized debt obligations (CDOs) and other exotic instruments returning generous yields. </li>

<li><strong>Non-Caveat Emptor.</strong> Institutional wealth funds and financial services firms who should have known better bought securities that had been deliberately structured to obfuscate risk. They bought securities they didn’t understand with buried tranches of toxic subprime loans..</li></ul>

<p>It was a great Ponzi scheme – one that kept working as long as housing prices were going up; the recipients of subprime loans could always flip that house to the next buyer. Everyone made money. As Chuck Prince of Citigroup famously put it during <a href="http://search.ft.com/ftArticle?sortBy=gadatearticle&amp;queryText=chuck+prince+dancing&amp;y=0&amp;aje=true&amp;x=0&amp;id=070710000610&amp;ct=0&amp;page=6&amp;nclick_check=1">a July, 2007 interview</a>: “So long as the music is playing, you’ve got to keep dancing. We’re still dancing.” But one month later, the music stopped. Since then, Citigroup and other financial institutions have taken massive writeoffs with more to come. Wall Street titans like Bear Sterns, Lehman Brothers, Merrill Lynch, and AIG have fallen or been bought out.</p>

<p>What can we learn from this risk management debacle?</p>

<p>As business risk managers and investors, we should ask questions like these:</p>

<ul><li><strong>Does the executive incentive structure of the company encourage managers to dance around risk?</strong> Many Wall Street firms paid senior managers 5 times their salary in bonuses tied to annual growth alone.</li>

<li><strong>Is the company over-leveraged?</strong> Is it borrowing too much money and betting it on ventures with uncertain outcomes?</li>

<li><strong>Are financial models used for risk management realistic?</strong> Earlier, I described the mortgage market of the past few years as a Ponzi scheme, where risk management models must have assumed prices would keep rising. Unlike the dotcom boom whose demise many predicted, very few in the industry foresaw the sharp declines to come in housing prices and sales volumes. Historically, the U.S. housing market has been a steadily rising one, but on the other hand the 2000s saw unprecedented rates of price increases. In reality, what goes up must come down. </li>

<li><strong>Has your company’s risk council ever performed worst case scenario analysis and built adequate reserves?</strong> In the days before economics emerged as a would-be “hard” deterministic science, business leaders may have been more cautious, more aware of and more accepting of uncertainty. Events like the Great Tulip Bubble came once in decades or centuries – not every few years. Note that legendary investor George Soros has proposed a Theory of Reflexivity that, if true, helps explain the recent extremes of boom and bust cycles. This theory holds that market participants model market behaviors based on self-interest, and for a time, their manipulations change the reality of the market – until gravitational forces bring it back to earth. Has the music of ephemeral success played to the backbeat of deterministic-sounding economic models gone to your heads and infected your risk management models? </li>

<li><strong>Are cost cutting efforts pursued blindly?</strong> Outsourcing and other forays into treacherous global waters may be giving away the crown jewels. Smart companies cut costs, but they do it in smart ways. Smart companies think like intelligence agencies as they parcel out work to different partners with varying levels of dependability, and they check on those partners.</li></ul>

<p>Risk management failures can also occur at the more technical level of IT security. As IT risk managers, we might ask questions like these:</p>

<ul><li><strong>Are the accounting and financial systems your IT department supports under adequate control?</strong> As Fred Cohen wrote in <a href="http://www.burtongroup.com/Client/Research/Document.aspx?cid=750">one of our documents</a>: “Many companies use computers to manage financial systems, and despite the Sarbanes-Oxley Act (SOX) claims about accounts being properly kept, there are many attacks on financial systems that remain. For example, most of the largest financial systems in the world running on common financial databases do not use <a href="http://en.wikipedia.org/wiki/Double-entry_bookkeeping">double-entry bookkeeping</a> and are thus susceptible to all manner of frauds by insiders.” We find it troubling that a prudent control dating back to the 12th century is going out of style in the name of convenience and cost cutting. Kind of like credit checking became anachronistic during the housing bubble, eh?</li>

<li><strong>Is the “separation” in your “separation of duty” (SoD) for real?</strong> Sure the SOX auditors are looking for SoD, and maybe you have different administrators with different accounts maintaining different systems or functions. But when they say Western civilization may be but one weak password from collapse they’re not lying. Look what happened to Sarah Palin’s email account! Weak and straggly SoD is a problem across all critical IT systems where deperimiterization and server consolidation may be bringing down protective barriers, identity management is weak, and strong process controls (e.g., where two people must sign on, one perform a critical operation such as backbone router reconfiguration, and the second observe) abandoned in the name of expediency. </li>

<li><strong>Are risks being aggregated to unacceptable levels in centralized control systems?</strong> There are many ways that risks aggregate within enterprise IT infrastructures as we pursue automation and cost cutting. Network risks aggregate when centralized domain name system control is implemented. Application risks aggregate when common infrastructure is shared among applications. And enterprises aggregate platform risks when they use low-assurance endpoints, authentication, and directory systems with single sign-on to access large numbers of resources and don’t separate high consequence systems. </li>

<li><strong>Non-caveat emptor:</strong> Has IT security really done the worst case consequence analysis, attack graphs, and vulnerability analysis to know when putting more eggs in a supposedly stronger basket aggregates risks to an unacceptable level? Or are you depending only on vendor claims about some black box appliance equivalent of a risk-obfuscated CDO security? Caveat emptor (buyer beware) again! (The good news is we’ll keep talking about promoting vendor and product rating systems so you don’t have to do all the detailed product analysis yourself, but that’s another post.)</li></ul>

<p>There are many parallels between the monumental risk management failure in the financial markets, and the probable weaknesses in our day to day business risk management and IT risk management. Abandonment of prudent practices for profit; excessive leverage and centralization; ill-constructed risk analysis models; risk obfuscation; and a failure of caveat emptor seem to be common problems. Please take this as a wakeup call to sharpen up the risk management thinking, process, and execution.</p></div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/397240912" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 19 Sep 2008 06:11:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/risk management debacle">risk management debacle</category>
      <category domain="http://securityratty.com/tag/risk management failure">risk management failure</category>
      <category domain="http://securityratty.com/tag/failure">failure</category>
      <category domain="http://securityratty.com/tag/risk management realistic">risk management realistic</category>
      <category domain="http://securityratty.com/tag/business risk management">business risk management</category>
      <category domain="http://securityratty.com/tag/risk management models">risk management models</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk management situations">risk management situations</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/397240912/wakeup-call-for.html">Wakeup Call for Risk Management</source>
    </item>
    <item>
      <title><![CDATA[Links List 9.5.08]]></title>
      <link>http://securityratty.com/article/a76e7e02c1b33be171e4bf894b4cceda</link>
      <guid>http://securityratty.com/article/a76e7e02c1b33be171e4bf894b4cceda</guid>
      <description><![CDATA[Sanjay Kumar is singing like a canary from federal prison. Just when you thought it was over, the CA accounting scandal is back and even more juicy. Ex-CEO Kumar is about a year into his 12-year...]]></description>
      <content:encoded><![CDATA[<p>Sanjay Kumar is <a href="http://online.wsj.com/article/SB122049724868198047.html?mod=djemTECH" target="_blank">singing like a canary</a> from federal prison. Just when you thought it was over, the CA accounting scandal is back and even more juicy. Ex-CEO Kumar is about a year into his <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2006/11/sanjay_kumar_ge.html" target="_blank">12-year prison term</a> but still busy pointing the finger at everyone else who he says knew about the company’s fraudulent accounting practices that lead to $2.2 billion in misstated revenue. From a former Salomon Brothers vice chairman to a former US senator to company founder <a href="http://blogs.computerworld.com/sanjay_kumar_hero_or_villain" target="_blank">Charles Wang</a>, it looks like open season on CA board directors.
<p>Ten days before <a href="http://www.vmworld.com/conferences/2008" target="_blank">VMworld</a> and VMware still can’t get good press. First their CEO, Diane Greene, gets ousted, then a high-profile <a href="http://toutvirtual.com/blogs/2008/09/02/vmware-really-hurting-or-just-really-bad-timing-for-a-simple-mistake/" target="_blank">licensing bug</a> is found and now the Director of R&amp;D, <a href="http://blogs.eweek.com/first_read/content/virtualization/vmware_rd_chief_resignation_is_bad_timing.html" target="_blank">Richard Sarwal</a>, leaves his $1.25 million salary after just 7 months. (Note to self: get into R&amp;D) It will be interesting to take the pulse of the VMware community at the show and in person. And in the meantime, Microsoft Hyper-V comes out of the gate with customers already <a href="http://www.nwwsubscribe.com/news/2008/082608-how-hyper-v-helped-my-it.html" target="_blank">touting its benefits</a>.
<p><a href="http://blog.sciencelogic.com/wp-content/uploads/2008/09/borg-jean-luc.jpg"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="243" alt="borg_jean-luc" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/borg-jean-luc-thumb.jpg" width="244" border="0"></a> </p>
<p>The hypervisor is the “new” operating system. If you didn’t think that before, take a look at Red Hat’s purchase of Qumranet for $107 million. With Qumranet, Red Hat gets KVM, described by <a href="http://www.infoworld.com/article/08/09/04/Red_Hat_buys_Qumranet_to_extend_virtualization_reach_1.html?source=NLC-DAILY&amp;cgd=2008-09-04" target="_blank">CTO Brian Stevens</a> as an extension to the Linux kernel that allows it to be used as a bare-metal hypervisor, running directly on the underlying hardware and hosting guest operating systems. But according to <a href="http://www.brianmadden.com/blog/BrianMadden/Red-Hat-buys-Qumranet-for-107M-What-does-this-mean-for-KVM-and-SolidICE" target="_blank">Brian Madden,</a> the “press” around the purchase is all focusing on the not-so-interesting part. Along with KVM, the SolidICE product includes Spice, a remote display protocol for VDI. </p>
<blockquote><p>I wonder if this will be like Symantec buying Altiris or Microsoft buying Softricity, where the portion that we care about sort of loses focus as The Borg concentrates on the parts of the acquired technology that are more relevant to them?</p>
</blockquote>
<p>(I’m a sucker for quotes that reference The Borg)
<p>Network World publishes “<a href="http://www.networkworld.com/news/2008/090208-open-to-watch.html?page=1">10 open source companies to watch</a>”. On the list, Qumranet!
<p>Also on the list: Kickfire, Marketcetera, Vyatta, Sonatype, Untangle, XAware, SnapLogic, Acquia and Openmoko. What’s best about the list: <a href="http://news.cnet.com/8301-13505_3-10030356-16.html?part=rss&amp;subj=news&amp;tag=2547-1_3-0-20" target="_blank">Matt Asay</a> gives it a thumbs up. </p>
]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 14:52:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/brian">brian</category>
      <category domain="http://securityratty.com/tag/cto brian stevens">cto brian stevens</category>
      <category domain="http://securityratty.com/tag/purchase">purchase</category>
      <category domain="http://securityratty.com/tag/red hats purchase">red hats purchase</category>
      <category domain="http://securityratty.com/tag/hypervisor">hypervisor</category>
      <category domain="http://securityratty.com/tag/million">million</category>
      <category domain="http://securityratty.com/tag/million salary">million salary</category>
      <category domain="http://securityratty.com/tag/bare-metal hypervisor">bare-metal hypervisor</category>
      <source url="http://blog.sciencelogic.com/links-list-9508/09/2008">Links List 9.5.08</source>
    </item>
    <item>
      <title><![CDATA[Who's Behind the Georgia Cyber Attacks?]]></title>
      <link>http://securityratty.com/article/5b529a9f3815b10331813e58bacf8129</link>
      <guid>http://securityratty.com/article/5b529a9f3815b10331813e58bacf8129</guid>
      <description><![CDATA[Of course the Klingons did it, or you were naive enough to even think for a second that Russians were behind it at the first place? Of the things I hate most, it's lowering down the quality of the...]]></description>
      <content:encoded><![CDATA[<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SKQoGBB38zI/AAAAAAAACCU/WYu9dc61zMQ/s1600-h/georgia_ddos8.JPG" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img height="51" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SKQoGBB38zI/AAAAAAAACCU/1TazKONjKVw/s200-R/georgia_ddos8.JPG" style="border: 0pt none ;" width="200" /></a>Of course the Klingons did it, or you were naive enough to even think for a second that Russians were behind it at the first place? Of the things I hate&nbsp; most, it's lowering down the quality of the discussion I hate the most. Even if you're excluding all the factual evidence (<a href="http://blogs.zdnet.com/security/?p=1670">Coordinated Russia vs Georgia cyber attack in progress</a>), common sense must prevail.<br />
<br />
Sometimes, the degree of incompetence can in fact be pretty entertaining, and greatly explains why certain countries are lacking behind others with years in their inability to understand the rules of information warfare, or the basic premise of unrestricted warfare, that there are no rules on how to achieve your objectives.<br />
<br />
So who's behind the Georgia cyber attacks, encompassing of plain simple ping floods, web site defacements, to sustained DDoS attacks, which no matter the fact that Geogia has switched hosting location to the U.S remain ongoing? It's <a href="http://computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=cybercrime_and_hacking&amp;articleId=9112443&amp;taxonomyId=82&amp;intsrc=kc_top">Russia's self-mobilizing cyber militia, the product of a collectivist society</a> having the capacity to wage cyber wars and literally dictating the rhythm in this space. What is militia anyway : <br />
<br />
<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SKQqNt95RjI/AAAAAAAACCc/hxG1PZAcltY/s1600-h/information_warfare.1.gif" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://2.bp.blogspot.com/_wICHhTiQmrA/SKQqNt95RjI/AAAAAAAACCc/B0-V902UtRA/s200-R/information_warfare.1.gif" style="border: 0pt none ;" /></a>"<i>civilians trained as soldiers but not part of the regular army; the entire body of physically fit civilians eligible by law for military service; a military force composed of ordinary citizens to provide defense, emergency law enforcement, or paramilitary service, in times of emergency; without being paid a regular salary or committed to a fixed term of service; an army of trained civilians, which may be an official reserve army, called upon in time of need; the national police force of a country; the entire able-bodied population of a state; or a private force, not under government control; An army or paramilitary group comprised of citizens to serve in times of emergency</i>"<br />
<br />
Next to the "blame the Russian Business Network for the lack of large scale implementation of DNSSEC" mentality, certain news articles also try to wrongly imply that <a href="http://arstechnica.com/news.ars/post/20080813-georgian-attacks-might-not-be-russians-after-all.html%20">there's no Russian connection in these attacks</a>, and that the attacks are not "state-sponsored", making it look like that there should be a considerable amount of investment made into these attacks, and that the Russian government has the final word on whether or not its DDoS capabilities empowered citizens should launch any attacks or not. In reality, the only thing the Russian government was asking itself during these attacks was "why didn't they start the attacks earlier?!".<br />
<br />
Thankfully, there are some visionary folks out there understanding the situation. Last year, I asked the following question - <a href="http://www.imedialearn.com/imediapoll/poll.php?code=f1156c39d3c972139c62bc91c17e2c53">What is the most realistic scenario on what exactly happened in the recent DDoS attacks aimed at Estonia, from your point of view?</a> and some of the possible answers still fully apply in this situation :<br />
<br />
- It was a Russian government-sponsored hacktivism, or shall we say a government-tolerated one<br />
<br />
- Too much media hype over a sustained ICMP flood, given the publicly obtained statistics of the network traffic<br />
<br />
- Certain individuals of the collectivist Russian society, botnet masters for instance, were automatically recruited based on a nationalism sentiments so that they basically forwarded some of their bandwidth to key web servers<br />
<br />
- In order to generate more noise, DIY DoS tools were distributed to the masses so that no one would ever know who's really behind the attacks<br />
<br />
- Don't know who did it, but I can assure you my kid was playing !synflood at that time<br />
<br />
- Offended by the not so well coordinated removal of the Soviet statue, Russian oligarchs felt the need to send back a signal but naturally lacking any DDoS capabilities, basically outsourced the DDoS attacks<br />
<br />
- A foreign intelligence agency twisting the reality and engineering cyber warfare tensions did it, while taking advantage of the momentum and the overall public perception that noone else but the affected Russia could be behind the attacks<br />
<br />
- I hate scenario building, reminds me of my academic years, however, yours are pretty good which doesn't necessarily mean I actually care who did it, and pssst - it's not cyberwar, as in cyberwar you have two parties with virtual engagement points, in this case it was bandwidth domination by whoever did it over the other. A virtual shock and awe<br />
<br />
- I stopped following the news story by the time every reporter dubbed it the first cyber war, and started following it again when the word hacktivism started gaining popularity. So, hacktivists did it to virtually state their political preferences <br />
<br />
Departamental cyber warfare would never reach the flexibity state of people's information warfare where everyone is a cyber warrior given he's empowered with access to the right tools at a particular moment in time.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2007/10/peoples-information-warfare-concept.html">People's Information Warfare Concept</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/combating-unrestricted-warfare.html">Combating Unrestricted Warfare</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/cyber-storm-ii-cyber-exercise.html">The Cyber Storm II Cyber Exercise</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/chinese-hacktivists-waging-peoples.html">Chinese Hacktivists Waging People's Information Warfare Against CNN</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/ddos-attack-against-cnncom.html">The DDoS Attacks Against CNN.com</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/chinas-cyber-espionage-ambitions.html">China's Cyber Espionage Ambitions</a><br />
<a href="http://ddanchev.blogspot.com/2006/07/north-koreas-cyber-warfare-unit-121.html">North Korea's Cyber Warfare Unit 121</a><br />
<div><a href="http://ddanchev.blogspot.com/2006/09/chinese-hackers-attacking-us.html">Chinese Hackers Attacking U.S Department of Defense Networks</a></div><div><a href="http://ddanchev.blogspot.com/2007/11/electronic-jihad-v30-what-cyber-jihad.html">Electronic Jihad v3.0 - What Cyber Jihad Isn't</a></div><div><a href="http://ddanchev.blogspot.com/2007/11/electronic-jihads-targets-list.html">Electronic Jihad's Targets List</a></div><div><a href="http://ddanchev.blogspot.com/2007/11/teaching-cyber-jihadists-how-to-hack.html">Teaching Cyber Jihadists How to Hack</a></div><div><a href="http://ddanchev.blogspot.com/2007/10/empowering-script-kiddies.html">Empowering the Script Kiddies</a></div><div><a href="http://ddanchev.blogspot.com/2007/04/osint-through-botnets.html">OSINT Through Botnets</a></div><div><a href="http://ddanchev.blogspot.com/2007/05/corporate-espionage-through-botnets.html">Corporate Espionage Through Botnets</a></div><div><a href="http://ddanchev.blogspot.com/2008/02/malware-infected-hosts-as-stepping.html">Malware Infected Hosts as Stepping Stones</a></div><div><a href="http://ddanchev.blogspot.com/2006/07/hacktivism-tensions-israel-vs.html">Hacktivism Tensions - Israel vs Palestine Cyberwars</a></div><div><a href="http://ddanchev.blogspot.com/2006/05/current-emerging-and-future-state-of.html">The Current, Emerging, and Future State of Hacktivism</a></div><div><a href="http://ddanchev.blogspot.com/2006/09/internet-psyops-psychological.html">Internet PSYOPS - Psychological Operations</a></div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Tcck1K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Tcck1K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=X9Eb0K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=X9Eb0K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=sJIFNk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=sJIFNk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=dY7m7k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=dY7m7k" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=rRiYlK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=rRiYlK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=XCeTAK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=XCeTAK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IYEN6k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IYEN6k" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/364867192" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 06:16:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/georgia cyber attacks">georgia cyber attacks</category>
      <category domain="http://securityratty.com/tag/warfare">warfare</category>
      <category domain="http://securityratty.com/tag/departamental cyber warfare">departamental cyber warfare</category>
      <category domain="http://securityratty.com/tag/cyber warfare tensions">cyber warfare tensions</category>
      <category domain="http://securityratty.com/tag/information warfare concept">information warfare concept</category>
      <category domain="http://securityratty.com/tag/information warfare">information warfare</category>
      <category domain="http://securityratty.com/tag/russian">russian</category>
      <category domain="http://securityratty.com/tag/russian oligarchs">russian oligarchs</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/364867192/whos-behind-georgia-cyber-attacks.html">Who's Behind the Georgia Cyber Attacks?</source>
    </item>
    <item>
      <title><![CDATA[Digital Cash in Iraq]]></title>
      <link>http://securityratty.com/article/84493590b736c33ff0c22bfa1fc5590a</link>
      <guid>http://securityratty.com/article/84493590b736c33ff0c22bfa1fc5590a</guid>
      <description><![CDATA[Smart cards have still never quite taken off across the US, and at this point its fair to wonder if they will or if they will be eclipsed by phones or some such, but smart cards sure are big outside...]]></description>
      <content:encoded><![CDATA[<p>Smart cards have still never quite taken off across the US, and at this point its fair to wonder if they will or if they will be eclipsed by phones or some such, but smart cards sure are big outside the US. One of the most interesting applications is of course digital cash and transaction processing. <a href="http://www.aplitec.co.za/">Net1 UEPS</a>&#160;(ticker: <a href="http://finance.google.com/finance?q=ueps">UEPS</a>) out of South Africa appears to be the leader here having built a $1.2B business out of this model. there are lots of regions in the world where people are underbanked or unbanked altogether and where its dangerous to have too much cash. I blogged about this earlier on <a href="http://1raindrop.typepad.com/1_raindrop/2007/08/beer-shotguns-a.html">Beer, Shotguns and Digital Cash</a>.&#160;</p><br /><div>Now <a href="http://biz.yahoo.com/iw/080804/0421781.html">Net1 UEPS is in Iraq as well</a>:</div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: arial; line-height: normal; ">The first UEPS transaction was performed on Sunday, August 3, 2008, in Baghdad, Iraq, during the official launch of the UEPS smart card technology with the two state banks namely, Rafidain Bank and Rasheed Bank.</span></p></blockquote><div><span style="font-family: arial; line-height: normal;"><br /></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: arial; line-height: normal; ">The official launch, attended by invitees from Rafidain Bank, Rasheed Bank, the Iraqi Government, War Victim Ministry and Martyrdom Ministry, demonstrated smart card registration, biometric enrolment and issuing of UEPS cards, offline loading of wage payments and government grants to the UEPS cards and dispensing of cash.</span><br /><span style="font-family: arial; line-height: normal; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: arial; line-height: normal; ">The pilot project involving 100,000 beneficiaries is now ready for implementation across selected bank branches and will enable the distribution and payment of government grants to war victims and martyrdom beneficiaries, as well as salary and wage distribution and payment to employees of the two state banks.</span><br /><span style="font-family: arial; line-height: normal; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: arial; line-height: normal; ">Brenda Stewart, Net1 Senior Vice President Sales and Marketing, said, &quot;From the entire team at Net1, we congratulate the Iraqi consortium on this historic achievement and look forward to the successful implementation of the various projects already identified for implementation, as well as the projects currently in business development. Net1 is proud that the development of its core technology, from which it creates end-user products that satisfy the requirements of its customers, can change the way business is conducted leading to the improvement of people&#39;s lives. We share the belief of our Iraqi partners that our technology can play a fundamental role in the upliftment of the economy. The success of any technology should be measured, not only by the profits it generates for its inventors, suppliers and users, but also by the difference that it makes to the lives of people,&quot; Stewart concluded.</span></p></blockquote><div><span style="font-family: arial; line-height: normal;"><p>I think there are lessons to be learned here wrt data and message level security. Net1 UEPS is a good example a of system carrying valuable assets across hostile terrain, web security architecture can learn a lot from this model.</p><p>P.S. If you are a <a href="http://en.wikipedia.org/wiki/Joel_Greenblatt">Joel Greenblatt</a> geek - UEPS is a <a href="http://www.magicformulainvesting.com/">magic formula stock</a>&#160;(meaning they make cash and are priced cheaply) last time I checked.</p><p></p></span></div>]]></content:encoded>
      <pubDate>Mon, 11 Aug 2008 08:53:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ueps cards">ueps cards</category>
      <category domain="http://securityratty.com/tag/ueps">ueps</category>
      <category domain="http://securityratty.com/tag/digital cash">digital cash</category>
      <category domain="http://securityratty.com/tag/cash">cash</category>
      <category domain="http://securityratty.com/tag/net1 ueps">net1 ueps</category>
      <category domain="http://securityratty.com/tag/bank">bank</category>
      <category domain="http://securityratty.com/tag/net1">net1</category>
      <category domain="http://securityratty.com/tag/rafidain bank">rafidain bank</category>
      <category domain="http://securityratty.com/tag/ueps transaction">ueps transaction</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/digital-cash-in-iraq.html">Digital Cash in Iraq</source>
    </item>
    <item>
      <title><![CDATA[Top 10 Signs Your Network Admin has Gone Rogue]]></title>
      <link>http://securityratty.com/article/c8be0329b2d0d092450eeafe3c99a9a7</link>
      <guid>http://securityratty.com/article/c8be0329b2d0d092450eeafe3c99a9a7</guid>
      <description><![CDATA[Terry Childs captivated much of the IT world over the past week and a half with his lock-down of San Franciscos IT system. Instead of watching a bunch of police chasing a white Bronco, this time the...]]></description>
      <content:encoded><![CDATA[<p>Terry Childs captivated much of the IT world over the past week and a half with his lock-down of <a href="http://www.eweek.com/c/a/Security/SF-Mayor-Breaks-Up-IT-Standoff/" target="_blank">San Francisco’s</a> IT system. Instead of watching a bunch of police chasing a white Bronco, this time the coverage amounted to many many articles, blog posts, comments, and long email chains. It seemed I would read one thing and the very next one would contradict or shed more light on some aspect of the case.</p>
<p>Depending on who you talk to, he is:</p>
<p>a) a hero</p>
<p>b) a disgruntled worker</p>
<p>c) in need of a serious work/life adjustment</p>
<p>d) in need of <a href="http://www.examiner.com/a-1502156~Alleged_SF_computer_saboteur_s_bail_request_denied.html" target="_blank" class="broken_link">$5 million</a> and/or a better lawyer</p>
<p>e) all of the above</p>
<p>Surprisingly <a href="http://www.infoworld.com/article/08/07/18/30FE-sf-network-lockout_1.html" target="_blank">strong opinions</a>, regardless of what you choose.</p>
<p>We chose to lighten things up a bit and, as we always try to do, figure out how to help our customers be proactive. So here it is, the Top 10 Signs Your Network Admin has Gone Rogue:</p>
<p>10) David Letterman has a Top 10 list called &#8220;Top 10 Signs Your Network Admin Has Gone Rogue&#8221;</p>
<p>9) Your Admin is the only one with the network device log-ins and refuses to share them with anyone else.</p>
<p>&#8216;8) His presentations about network configuration include the words “Magic” and “Burn after reading”.</p>
<p>7) Instead of email, he forces everyone to use the Suggestion box placed outside of his door…and then places a very obvious nanny-cam hidden in a teddy bear right next to it.</p>
<p>6) He begins to grow out his sideburns and every question directed to him in meetings results in the same response, “Do you feel lucky today, punk?”</p>
<p>5) He has the mayor on speed-dial.</p>
<p>4) He starts wearing very big shoes to the office and accosts random people in the hallways asking if they think they could fill them.</p>
<p>3) He refuses to write router and switch configs to flash citing network security concerns.</p>
<p>2) He calls you and asks for a $5 million salary advance; caller id flashes “Department of Corrections”.</p>
<p>And #1: You’re the City of San Francisco</p>
<p>Enjoy your lock-down free weekend!</p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Top+10+Signs+Your+Network+Admin+has+Gone+Rogue&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Ftop-10-signs-your-network-admin-has-gone-rogue%2F07%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Fri, 25 Jul 2008 14:00:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network admin">network admin</category>
      <category domain="http://securityratty.com/tag/admin">admin</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <category domain="http://securityratty.com/tag/lock-down">lock-down</category>
      <category domain="http://securityratty.com/tag/signs">signs</category>
      <category domain="http://securityratty.com/tag/lock-down free weekend">lock-down free weekend</category>
      <category domain="http://securityratty.com/tag/rogue">rogue</category>
      <category domain="http://securityratty.com/tag/network configuration include">network configuration include</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <source url="http://blog.sciencelogic.com/top-10-signs-your-network-admin-has-gone-rogue/07/2008">Top 10 Signs Your Network Admin has Gone Rogue</source>
    </item>
    <item>
      <title><![CDATA[Backup tape is stolen from Bristol-Myers Squibb]]></title>
      <link>http://securityratty.com/article/911478f22f756b8e8513c59d7f720d18</link>
      <guid>http://securityratty.com/article/911478f22f756b8e8513c59d7f720d18</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/17/08

Organization
Bristol-Myers Squibb Co. (&quot;BMS

Contractor/Consultant/Branch
Unknown

Victims
Current and former employees and some dependants
...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/bms.jpg" width="198" align="right" height="160"><font size="2"><b>Date Reported: </b><br>7/17/08<br><br><b>Organization: </b><br><a href="http://www.bms.com/landing/data/index.html">Bristol-Myers Squibb Co. ("BMS")</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>Unknown<br><br><span style="font-weight: bold;">Victims:</span><br>Current and former employees and some dependants<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown*<br><br><font size="1">*Bristol-Myers Squibb had "about 42,000 employees as of Dec. 31, the last date for which work force figures were available in regulatory filings.", Source: <a href="http://money.cnn.com/news/newsfeeds/articles/djf500/200807171514DOWJONESDJONLINE000844_FORTUNE5.htm">CNN Money</a></font> <br><br><span style="font-weight: bold;">Types of Data:</span><br>"name, address, date of birth, Social Security number, marital status, gender, salary, hire date, termination date, retirement date, and, in some instances bank account information"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"On June 4, 2008, Bristol-Myers Squibb Company ("BMS") learned that a back-up data tape containing BMS-related data was stolen while it was being transported for storage.&nbsp; Through subsequent forensic work, it was determined that the data tape included personal information of current and former BMS employees"<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.pharmalot.com/wp-content/uploads/2008/07/bms_letter.pdf">Pharmalot (copy of notification letter)</a> <br><a href="http://www.pharmalot.com/2008/07/bristol-myers-security-breach-hits-untold-thousands/">Pharmalot</a> <br><a href="http://money.cnn.com/news/newsfeeds/articles/djf500/200807171514DOWJONESDJONLINE000844_FORTUNE5.htm">CNNMoney</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Ed Silverman, Pharmalot<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>The drugmaker sent letters over the past week saying a data tape containing reams of personal information was stolen several weeks ago<br><br>On June 4, 2008, Bristol-Myers Squibb Company ("BMS") learned that a back-up data tape containing BMS-related data was stolen while it was being transported for storage. <br><span style="font-style: italic;">[Evan] This statement prompted me to list the contractor as "unknown" instead of "none".&nbsp; I presume that the data tape was being transported by a third-party vendor when it was stolen.&nbsp; I am looking for more information on this.</span><br><br>Through subsequent forensic work, it was determined that the data tape included personal information of current and former BMS employees, such as name, address, date of birth, Social Security number, marital status, gender, salary, hire date, termination date, retirement date, and, in some instances, bank account information.<br><span style="font-style: italic;">[Evan] Ugh, this looks like very sensitive HR and benefits data.</span><br><br>The names, addresses, and Social Security numbers of some employee dependents also were included on the tape.<br><br>an untold number of current and former employees - and their dependents - could be affected<br><br>BMS has initiated an investigation of this incident.<br><br>To date, BMS has no reason to believe that any of your personal information has been inappropriately accessed from the data tape by an unauthorized party, or that any identity theft, fraud or misuse of your personal information has occurred.<br><span style="font-style: italic;">[Evan] I agree with most of this statement except for the "misuse" part.&nbsp; There may be no evidence of misuse post stolen tape, but there may be an argument for misuse by BMS themselves.&nbsp; BMS is the data custodian in this scenario, not the data owner.&nbsp; If a data custodian does not care for the owner's information in a manner that is expected or communicated, does it constitute misuse?</span><br><br>In addition, there is no evidence that the data tape or the information contained on it was the target of the theft.<br><span style="font-style: italic;">[Evan] I am interested in knowing more about who was transporting the tape and whether or not other items were taken.</span><br><br>As a precaution, to help you detect any possible misuse of your data, BMS has arranged for you to enroll in credit monitoring for one full year, at no cost to you.<br><span style="font-style: italic;">[Evan] There is that "misuse" mention again.&nbsp; One year of free credit monitoring does nothing to protect a victim against fraud that occurs after one year, supposing the victim does not renew at his/her own expense.&nbsp; I wonder how many people renew on average.</span><br><br>If you have any questions, you may call the dedicated Privacy Help Line at 1-877-214-0689.&nbsp; Our representatives will be available to assist you Monday through Friday, between 8 a.m. and 5 p.m. ET.<br><br>the drugmaker is issuing this statement: "Bristol-Myers Squibb regrets that this incident occurred and is committed to providing appropriate assistance for affected individuals who had their personal information on the stolen data tape. We are committed to protecting the privacy and security of employee and dependent information. Maintaining the trust and confidence of our employees is paramount to Bristol-Myers Squibb."<br><br>Protecting the privacy and security of your information is extremely important to us.<br><br>In this regard, BMS wishes to reiterate that it does not have any evidence indicating that your personal information has been misused.<br><span style="font-style: italic;">[Evan] Another "misuse" mention.</span><br><br>the company is taking appropriate remedial steps, including enhancing security protocols regarding the handling of personal information and our back-up data tapes.<br><span style="font-style: italic;">[Evan] Like what? Encryption maybe?</span><br><br>On behalf of BMS, I apologize for any inconvenience or concern that this matter may cause for you.<br><br><span style="font-weight: bold;">Commentary:</span><br>I couldn't find any mention about encryption or whether or not police were called.&nbsp; You would think that a large, well-repected company like Bristol-Myers Squibb encrypts confidential data on tape, right? <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/18/bms.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Fri, 18 Jul 2008 07:26:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tape">tape</category>
      <category domain="http://securityratty.com/tag/back-up data tape">back-up data tape</category>
      <category domain="http://securityratty.com/tag/data tape">data tape</category>
      <category domain="http://securityratty.com/tag/owner">owner</category>
      <category domain="http://securityratty.com/tag/data owner">data owner</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/bristol-myers squibb">bristol-myers squibb</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <source url="http://breachblog.com/2008/07/18/bms.aspx">Backup tape is stolen from Bristol-Myers Squibb</source>
    </item>
    <item>
      <title><![CDATA[Waukesha County job applicant data exposed in mailing]]></title>
      <link>http://securityratty.com/article/6efea251f53508bced1039830009ef31</link>
      <guid>http://securityratty.com/article/6efea251f53508bced1039830009ef31</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/13/08

Organization
Waukesha County, Wisconsin

Contractor/Consultant/Branch
Crivello Carlson, S.C

Victims
Job applicants from the year 2006

Number...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/waukesha.jpg" width="149" align="right" height="200"><font size="2"><b>Date Reported: </b><br>7/13/08<br><br><b>Organization: </b><br><a href="http://www.waukeshacounty.gov/">Waukesha County, Wisconsin</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://www.milwlaw.com/index.aspx">Crivello Carlson, S.C.</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Job applicants from the year 2006<br><br><span style="font-weight: bold;">Number Affected:</span><br>"more than 130"<br><br><span style="font-weight: bold;">Types of Data:</span><br>Job applications including, names, addresses, job and education history, salary, and Social Security numbers<br><br><span style="font-weight: bold;">Breach Description:</span><br>"More than 130 people who applied for a job with Waukesha County in 2006 had their Social Security numbers, employment and salary information, addresses and phone numbers and other personal information released to one of the women who applied for the job. "<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.jsonline.com/story/index.aspx?id=772046">Milwaukee Journal Sentinel</a> <br><a href="http://www.newrichmond-news.com/articles/index.cfm?id=87905&amp;section=Wisconsin%20News&amp;property_id=19">New Richmond News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Raquel Rutledge, Milwaukee Journal Sentinel<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Taunya Thomas was horrified when she got a call from a stranger who knew almost everything about her.<br><br>The woman on the phone told Thomas she knew her Social Security number, where she lived and worked, how much money she made and where she went to high school and college. She rattled them off, not missing a single digit or fact.<br><br>She promised she wasn't going to use the information.<br><span style="font-style: italic;">[Evan] Yeah.&nbsp; The government body that exposed the information made the promise that "your Social Security number will remain confidential".&nbsp; So much for promises</span>.<br><br>She was calling, she said, because she wanted Thomas and others to know where she had gotten it.<br><br>She hadn't stolen it. <br><br>Waukesha County sent it to her in the mail, along with the same personal information for more than 130 other people who had all applied for a job with the county in 2006.<br><span style="font-style: italic;">[Evan] What's with Wisconsin and mailing confidential information (in error)?&nbsp; This is the third mailing error reported on The Breach Blog coming out of Wisconsin this year.</span><br><br>The woman on the phone, Bernadine Matthews, too had applied for the position as an economic support specialist.<br><br><img src="http://images.quickblogcast.com/95781-88451/matthews.jpg" width="324" border="0"><br><font size="1">This is Matthews displayed holding the applications.&nbsp; Source: Milwaukee Journal Sentinel</font><br><br>When she didn't get it, she filed a complaint with the Equal Employment Opportunity Commission.<br><br>As part of the complaint and the investigation, the EEOC requested copies of all the applications.<br><br>The law firm representing the county, Crivello Carlson, sent the applications to Matthews.<br><span style="font-style: italic;">[Evan] Really?&nbsp; Any second thoughts about the fact that this may put innocent people at risk?</span><br><br>Waukesha County tried to reclaim the documents sent to Matthews, threatening to get a search warrant and send a lawyer to her house, Matthews said.<br><br>When Matthews refused, they insisted she bring the documents to the law firm so they could white-out the private information in the applications.<br><br>Again, Matthews refused.<br><span style="font-style: italic;">[Evan] At what point does Matthews cross a line.&nbsp; The confidential information on those job applications does NOT belong to her.&nbsp; In my opinion, she has no right to maintain possession of the information.&nbsp; For Matthews to knowingly maintain information that does not belong to her almost seems criminal to me.</span><br><br>The applications would be critical to her discrimination suit, she thought.<br><span style="font-style: italic;">[Evan] So risk the disclosure of senstive information belonging to 130 people for your own benefit?&nbsp; If not criminal, it is certainly selfish.</span><br><br>She quickly hired an attorney, copied the documents and sent a set back to the county. She keeps her copies in an oversize safe-deposit box at her bank, she said.<br><span style="font-style: italic;">[Evan] Who authorized her to make copies?&nbsp; The data owners (victims) certainly did not.</span><br><br>"I'm not going to be like the county," Matthews said. "I'm going to protect the privacy of the information in this box. Obviously they didn't give a darn about the applicants' privacy."<br><br>The Waukesha County employment application specifically states it will protect Social Security numbers.<br><br>"Your Social Security Number will remain confidential and will not be copied or released but is required for applicant tracking purposes," the application reads.<br><br><a href="http://www.milwlaw.com/ourpeople/profile.aspx?id=285&amp;name=Raymond%20J.%20Pollen">Ray Pollen</a>, an attorney with Crivello Carlson, at first said it was no mistake that Matthews received the uncensored applications.<br><span style="font-style: italic;">[Evan] So Mr. Pollen sent the information on purpose.&nbsp; Did he stop to think that there might be a problem here?&nbsp; Did it occur to anyone that they should redact the most sensitive information such as Social Security numbers, or names?</span><br><br>He said it was required under federal law that all parties in an EEOC discrimination complaint receive copies of information requested by the agency investigating. He couldn't point to the specific provision.<br><span style="font-style: italic;">[Evan] Does a specific provision exist?&nbsp; I cannot think of a single purpose that a Social Security number would serve in this case.</span><br><br>Several days later, Pollen said the EEOC had no such requirement.<br><br>"The EEOC is silent on the issue," he said.<br><br>Instead it's the state's Equal Rights Division that requires all parties be copied on information requested by the division but even that provision doesn't mandate that attachments - such as the applications - be included. And, Matthew's case was not filed with the state.<br><br>"We followed the state's protocol," Pollen said.<br><br>P.I. asked: So anyone who applies for a job with Waukesha County could have their private information disclosed to a non-governmental third-party?<br>&nbsp;<br>Pollen answered: "We responded to a federal agency's request for information. . . . In my opinion there was no violation of any law or procedure."<br><span style="font-style: italic;">[Evan] Let's give Mr. Pollen the benefit of the doubt.&nbsp; Let's say that there was no violation of any law or procedure here.&nbsp; There certainly seems to be a violation of trust, a violation of good judgment, and a violation of privacy.&nbsp; The "if the law don't state it, then I must be able to do it" mentality is one of the reasons we have so many laws.&nbsp; Maybe if we used a little more common sense.</span><br><br>Taunya Thomas called the release of her information to a stranger shocking. She said at a minimum the county should have notified her that her information had been compromised.<br><br>"I'm devastated that it's that easy for my information to be disclosed," she said. "For someone to call me and tell me where I worked, where I went to school, recite my Social Security number verbatim to me, that's scary."<br><br><span style="font-weight: bold;">Commentary:</span><br>This is a very frustrating breach to read about.&nbsp; It is frustrating when someone knowingly discloses confidential information and then tries to justify it.&nbsp; Equally frustrating is when a person that has no right to the information refuses to part with it.&nbsp; In the middle of all of this are 130 innocent people.<br><br>I do not claim to know half as much about the law as Mr. Pollen does.&nbsp; His actions may be well within his legal rights for all I know. <br><br><b>Past Breaches:</b><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/15/waukesha.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Tue, 15 Jul 2008 04:07:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/job">job</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/county">county</category>
      <category domain="http://securityratty.com/tag/waukesha county">waukesha county</category>
      <category domain="http://securityratty.com/tag/senstive information">senstive information</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <category domain="http://securityratty.com/tag/sensitive information">sensitive information</category>
      <category domain="http://securityratty.com/tag/salary information">salary information</category>
      <source url="http://breachblog.com/2008/07/15/waukesha.aspx">Waukesha County job applicant data exposed in mailing</source>
    </item>
    <item>
      <title><![CDATA[Survey: One In Three IT Staff Snoops]]></title>
      <link>http://securityratty.com/article/877ce0234491c5a2dd7ddf70a70e6051</link>
      <guid>http://securityratty.com/article/877ce0234491c5a2dd7ddf70a70e6051</guid>
      <description><![CDATA[Only one in three? I would hazard that is being conservative
From MSNBC
One in three information technology professionals abuses administrative passwords to access confidential data such as colleagues...]]></description>
      <content:encoded><![CDATA[<p>Only one in three? I would hazard that is being conservative. </p>
<p>From MSNBC:</p>
<blockquote><p>One in three information technology professionals abuses administrative passwords to access confidential data such as colleagues&#8217; salary details, personal e-mails or board-meeting minutes, according to a survey.</p>
<p>U.S. information security company Cyber-Ark surveyed 300 senior IT professionals, and found that one-third admitted to secretly snooping, while 47 percent said they had accessed information that was not relevant to their role.</p></blockquote>
<p>Ah, there it is. One-third admitted to it. OK, that is more what I would expect. Now for the other two thirds get the electric cattle prod and some thumb screws and I&#8217;m sure they&#8217;ll start singing. </p>
<p>hyuk.</p>
<p><a href="http://www.msnbc.msn.com/id/25263009/">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=MzaUqx"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=MzaUqx" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=M6Py4I"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=M6Py4I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=T0ieHi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=T0ieHi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=jy14qi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=jy14qi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=iycrOi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=iycrOi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=F1qAvi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=F1qAvi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/316180251" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 20 Jun 2008 08:29:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/electric cattle prod">electric cattle prod</category>
      <category domain="http://securityratty.com/tag/colleagues salary details">colleagues salary details</category>
      <category domain="http://securityratty.com/tag/access confidential data">access confidential data</category>
      <category domain="http://securityratty.com/tag/article link">article link</category>
      <category domain="http://securityratty.com/tag/survey">survey</category>
      <category domain="http://securityratty.com/tag/one-third">one-third</category>
      <category domain="http://securityratty.com/tag/personal e-mails">personal e-mails</category>
      <category domain="http://securityratty.com/tag/thumb screws">thumb screws</category>
      <category domain="http://securityratty.com/tag/msnbc">msnbc</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/316180251/">Survey: One In Three IT Staff Snoops</source>
    </item>
    <item>
      <title><![CDATA[IT Workers Would Take a Pay Cut to Telecommute?]]></title>
      <link>http://securityratty.com/article/304b2edbe7265be11a18989464d6f140</link>
      <guid>http://securityratty.com/article/304b2edbe7265be11a18989464d6f140</guid>
      <description><![CDATA[According to a recent study , a good percentage of IT Workers would be happy to telecommute, even if it meant a pay cut of up to10
Nearly 40% of U.S. information technology workers would accept a...]]></description>
      <content:encoded><![CDATA[<p>According to a <a rel="nofollow" target="_blank" href="http://www.informationweek.com/news/management/trends/showArticle.jhtml?articleID=208403187">recent study</a>, a good percentage of IT Workers would be happy to telecommute, even if it meant a pay cut of up to10%:</p>
<blockquote><p><span id="articleBody"> Nearly 40% of U.S. <a rel="nofollow" target="_blank" href="http://www.techweb.com/encyclopedia/defineterm.jhtml?term=information%20technology&amp;x=&amp;y=">information technology</a> workers would accept a reduced salary to have the ability to telecommute, a Dice Holding survey revealed Tuesday.</span></p>
<p><span id="articleBody">In a poll of more than 1,500 IT workers, 37% of respondents said they would be willing to take &#8220;slightly less&#8221; pay to telecommute full time. The survey defined &#8220;slightly less&#8221; as up to a 10% reduction in salary.</span></p></blockquote>
<p>The article does mention that workers can save some costs at the gas pump &#8212; but there are a lot more savings from telecommuting too. Workers who commute have to pay not just for gas or bus fees, but also for parking, the cost of lunch from eating out often, and the time they spend in the commute. In the end, the amount that workers might save by telecommuting might make up for the potential pay cut.</p>
<p>Of course, there are other costs to working remotely &#8212; getting a good business phone line and Internet connection, setting up a home office that you can stand to sit in all day and the costs of coffee for renting a table at your local coffee shop. But those are certainly worthwhile for the convenience and flexibility of working remotely.</p>]]></content:encoded>
      <pubDate>Wed, 11 Jun 2008 07:33:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/workers">workers</category>
      <category domain="http://securityratty.com/tag/information technology workers">information technology workers</category>
      <category domain="http://securityratty.com/tag/telecommute">telecommute</category>
      <category domain="http://securityratty.com/tag/coffee">coffee</category>
      <category domain="http://securityratty.com/tag/local coffee shop">local coffee shop</category>
      <category domain="http://securityratty.com/tag/cut">cut</category>
      <category domain="http://securityratty.com/tag/business phone line">business phone line</category>
      <category domain="http://securityratty.com/tag/gas">gas</category>
      <category domain="http://securityratty.com/tag/gas pump">gas pump</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/309846263/">IT Workers Would Take a Pay Cut to Telecommute?</source>
    </item>
    <item>
      <title><![CDATA[Unencrypted AT&T Laptop with Employee Data Stolen]]></title>
      <link>http://securityratty.com/article/eaa97436e1a4c560ea3ec764a92ce9b4</link>
      <guid>http://securityratty.com/article/eaa97436e1a4c560ea3ec764a92ce9b4</guid>
      <description><![CDATA[Um, whoops
From Consumer Affairs
A laptop containing personal information on AT&amp;T employees and management was stolen from an employees vehicle last month, the company said
The laptop, which had no...]]></description>
      <content:encoded><![CDATA[<p>Um, whoops. </p>
<p>From Consumer Affairs:</p>
<blockquote><p>A laptop containing personal information on AT&#038;T employees and management was stolen from an employee&#8217;s vehicle last month, the company said.</p>
<p>The laptop, which had no encryption or security protection beyond a password lock, contained names, Social Security numbers, and salary information for an undisclosed number of workers.</p>
<p>Employees were notified of the theft on May 22, seven days after the theft, according to privacy watchdog PogoWasRight.org, which first reported the story. In a letter to employees, AT&#038;T said that, &#8220;The measures and precautions we put in place to protect the security of company-owned property and our employees&#8217; personal information were not followed.&#8221;</p>
<p>AT&#038;T said that the responsible employee &#8220;has been disciplined.&#8221;</p></blockquote>
<p>Disciplined you say?</p>
<p><center><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2008/06/dungeon.jpg" alt="Dungeon" title="dungeon" width="400" height="300"  /></center></p>
<p>Muawhaha!</p>
<p><a href="http://www.consumeraffairs.com/news04/2008/06/att_laptop.html">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=SDfQUP"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=SDfQUP" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=Lhjt8I"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=Lhjt8I" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=58VL6i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=58VL6i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=KryrLi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=KryrLi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=hPULYi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=hPULYi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=MWGLKi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=MWGLKi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/308480894" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 09 Jun 2008 22:31:39 +0000</pubDate>
      <category domain="http://securityratty.com/tag/employees personal information">employees personal information</category>
      <category domain="http://securityratty.com/tag/employees vehicle">employees vehicle</category>
      <category domain="http://securityratty.com/tag/employees">employees</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/att employees">att employees</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security protection">security protection</category>
      <category domain="http://securityratty.com/tag/laptop">laptop</category>
      <category domain="http://securityratty.com/tag/att">att</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/308480894/">Unencrypted AT&amp;T Laptop with Employee Data Stolen</source>
    </item>
  </channel>
</rss>
