<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: saturday]]></title>
    <link>http://securityratty.com/tag/saturday</link>
    <description></description>
    <pubDate>Tue, 12 Aug 2008 08:13:02 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[T-Mobile lost disk containing data on 17 million customers]]></title>
      <link>http://securityratty.com/article/e2839ad43fefaa9d25e12189d038269d</link>
      <guid>http://securityratty.com/article/e2839ad43fefaa9d25e12189d038269d</guid>
      <description><![CDATA[Deutsche Telekom's German mobile phone subsidiary T-Mobile lost a disk containing personal information about 17 million of its customers in early 2006, the company said...]]></description>
      <content:encoded><![CDATA[Deutsche Telekom's German mobile phone subsidiary T-Mobile lost a disk containing personal information about 17 million of its customers in early 2006, the company said Saturday.<p><A href="http://ad.doubleclick.net/jump/idg.us.nwf.rss/wirelessmobile;sz=468x60;ord=30283?">
<IMG src="http://ad.doubleclick.net/ad/idg.us.nwf.rss/wirelessmobile;sz=468x60;ord=30283?" border="0" width="468" height="60"></A>
</p>]]></content:encoded>
      <pubDate>Sun, 05 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/million">million</category>
      <category domain="http://securityratty.com/tag/disk">disk</category>
      <category domain="http://securityratty.com/tag/deutsche telekom">deutsche telekom</category>
      <category domain="http://securityratty.com/tag/customers">customers</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/saturday">saturday</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <source url="http://www.networkworld.com/news/2008/100608-t-mobile-lost-disk-containing-data.html?fsrc=rss-security">T-Mobile lost disk containing data on 17 million customers</source>
    </item>
    <item>
      <title><![CDATA[Sao Paulo, here I come]]></title>
      <link>http://securityratty.com/article/2e34b18734b7a577eee71ba74340c1c6</link>
      <guid>http://securityratty.com/article/2e34b18734b7a577eee71ba74340c1c6</guid>
      <description><![CDATA[I have a new TechEd destination this year: Brazil. Itll be my first time to speak at our event there; indeed, even my first time to travel to South America. Im looking forward to it
The event runs...]]></description>
      <content:encoded><![CDATA[<p>I have a new <a target="_blank" href="http://www.teched.com.br/Palestrantes.aspx">TechEd destination</a> this year: Brazil. It’ll be my first time to speak at our event there; indeed, even my first time to travel to South America. I’m looking forward to it.</p>  <p>The event runs during <a target="_blank" href="http://www.teched.com.br/Default.aspx">14-16 October 2008</a>. I’m delivering the same four presentations I gave at TechEd US (and have used at most other TechEds around the world, too):</p>  <ul>   <li>Do these ten things now or else get 0wn3d!</li>    <li>Virtualization and security: what does it mean for me?</li>    <li>Privacy: the why, the what, and the how</li>    <li>21st century networking: throw away your medieval gateways</li> </ul>  <p>That’s gonna be a crazy week, because I’ll have been in Hong Kong for TechEd there the week prior. I get home from Hong Kong on Saturday, spend the night in Seattle, then on Sunday fly down to Sao Paulo! Oh well, I still love my job :)</p>  <p>If you’re headed to TechEd Brazil, be sure to introduce yourself to me after one of my talks. See you soon!</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3130019" width="1" height="1">]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 13:31:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hong kong">hong kong</category>
      <category domain="http://securityratty.com/tag/sao paulo">sao paulo</category>
      <category domain="http://securityratty.com/tag/event">event</category>
      <category domain="http://securityratty.com/tag/event runs">event runs</category>
      <category domain="http://securityratty.com/tag/south america">south america</category>
      <category domain="http://securityratty.com/tag/21st century">21st century</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/brazil">brazil</category>
      <category domain="http://securityratty.com/tag/medieval gateways">medieval gateways</category>
      <source url="http://blogs.technet.com/steriley/archive/2008/09/29/sao-paulo-here-i-come.aspx">Sao Paulo, here I come</source>
    </item>
    <item>
      <title><![CDATA[New Sniffer Can Attack VoIP Users]]></title>
      <link>http://securityratty.com/article/90d400b0b5671bf907af9923f902dd15</link>
      <guid>http://securityratty.com/article/90d400b0b5671bf907af9923f902dd15</guid>
      <description><![CDATA[Next-generation VoIP sniffer was released on Saturday at Toorcon in San Diego by Jason Ostrom of VoIP Hopper. The tool, that might be used for attacks, should help raise awareness of the type of...]]></description>
      <content:encoded><![CDATA[Next-generation VoIP sniffer was released on Saturday at Toorcon in San Diego by Jason Ostrom of VoIP Hopper. The tool, that might be used for attacks, should help raise awareness of the type of vulnerabilities businesses face as they adopt unified communications (UC) technology.
According to Jason, the tool, UCSniff, has two settings. One is a [...]]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 06:50:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/jason ostrom">jason ostrom</category>
      <category domain="http://securityratty.com/tag/jason">jason</category>
      <category domain="http://securityratty.com/tag/next-generation voip sniffer">next-generation voip sniffer</category>
      <category domain="http://securityratty.com/tag/tool">tool</category>
      <category domain="http://securityratty.com/tag/voip hopper">voip hopper</category>
      <category domain="http://securityratty.com/tag/raise awareness">raise awareness</category>
      <category domain="http://securityratty.com/tag/vulnerabilities businesses">vulnerabilities businesses</category>
      <category domain="http://securityratty.com/tag/san diego">san diego</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <source url="http://cyberinsecure.com/new-sniffer-can-attack-voip-users/">New Sniffer Can Attack VoIP Users</source>
    </item>
    <item>
      <title><![CDATA[Inc 500/5000 Conference Summary]]></title>
      <link>http://securityratty.com/article/9368d02fff1906cea272fe55093a6965</link>
      <guid>http://securityratty.com/article/9368d02fff1906cea272fe55093a6965</guid>
      <description><![CDATA[It didnt really sink in until after the final black-tie awards ceremony finished last Saturday night that I had a chance to comprehend how starting a company that achieves this list is a once in a...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 5px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/slinc5002.jpg" border="0" alt="slinc5002" width="240" height="181" align="left" /> It didn’t really sink in until after the final black-tie awards ceremony finished last Saturday night that I had a chance to comprehend how starting a company that achieves <a href="http://www.inc.com/inc5000/">this list</a> is a once in a lifetime experience.</p>
<p>When I walked up on stage and accepted the <a href="http://www.inc.com/inc5000/2008/company-profile.html?id=200803500" target="_blank">Inc 500 award</a>, it hit me square in the face that this is a rare accomplishment, and even more difficult for a product company that started without the benefit of VC funding.</p>
<p><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/slinc5003.jpg" border="0" alt="slinc5003" width="240" height="181" /><br />
<em>Dave with wife, Anne, at the awards ceremony</em><br />
Over <a href="http://blog.inc.com/inc5000/" target="_blank">the 2 day period</a>, I heard from some <a href="http://secure.lenos.com/lenos/inc/Inc500WashingtonDC/speakers.asp" target="_blank">great speakers with entrepreneurial passion</a>, many who never had accomplished making the list. It is so <a href="http://www.prospectmx.com/inc-500-conference-and-awards" target="_blank">highly competitive and just plain hard</a> to do.</p>
<p>I loved <a href="http://blog.sciencelogic.com/good-to-great-built-to-last-whats-next-for-creating-great-companies/09/2008" target="_blank">hearing</a> some of the <a href="http://www.business-opportunities.biz/2008/09/24/inside-small-biz-guru-michael-gerbers-dreaming-room/" target="_blank">speeches during the conference</a> and getting to know other <a href="http://www.johnwinsor.com/my_weblog/2008/09/inc-500.html" target="_blank">entrepreneurs that attended</a> the conference talk about how they created their niche and ultimately built a successful company from a good idea.</p>
<p>Because I enjoyed hearing some of what I like to call &#8220;golden nuggets of wisdom&#8221; so much, I thought in my conference wrap-up I would pass on a few to our blog readers:</p>
<p><strong></strong></p>
<p><strong><a href="http://www.tompeters.com/" target="_blank">Tom Peters – Author In Search of Excellence and The New World of WOW</a></strong></p>
<p>“Only 7% of our great nation works for Fortune 500 companies. Small businesses and the <a href="http://www.jonlowder.com/2008/09/why-i-havent-be.html" target="_blank">entrepreneurs are the jet fuel</a> that makes our country fly.”</p>
<p>“Brand is shorthand for a collection of experiences, memories of what it will be like the next time a customer deals with you. With the <a href="http://www.debbieweil.com/blog/tom-peters/" target="_blank">advent of blogs and consumer activism</a>, Brand is impossible to fake; it is like the temperature in the room… it is there… it exists.”</p>
<p><strong><a href="http://www.carrots.com/" target="_blank">Chester Elton – SVP Carrot Culture Group</a></strong></p>
<p>“At the casino – they train the heck out of the Valet! Why do they spend 3 months on Valet training? Because he is the first and the last person to greet and interact with a visitor during their trip! Who is your company Valet?”</p>
<p><strong><a href="http://www.ideo.com/search/cluster/paul-bennett/" target="_blank">Paul Bennett – Chief Creative officer IDEO</a> – speaking on &#8212; Creating a culture of optimism:</strong></p>
<p>“You need to ditch B-B and B-C Need to become P-P Person to Person.”</p>
<p>“You don’t buy loyalty… you earn it… this is an interesting challenge, but small allows us to behave like human beings… Going off script and doing something human is a great place to start.”</p>
<p>“Stop obsessing about ROI and start obsessing about ROC! Return on Customer/Consumer is much more powerful than ROI!!!!”</p>
<p>“Happy people, unabashedly doing, happy things, makes for happy companies, which create happy businesses which enable happy cultures… IN WHICH THRIVE”</p>
<p><strong><a href="http://carlson.umn.edu/Page5365.aspx" target="_blank">Marilyn Carlson Nelson – Chairman and CEO Carlson Companies</a> – A family owned $40 Billion empire including TGI Fridays, Radisson Hotels…</strong></p>
<p>“My leadership was tested terribly - after 9/11 the travel industry was particularly harmed. It was an extraordinary time for Carlson. “</p>
<p>“Put tactics around these strategic initiatives”</p>
<ul>
<li>Whomever you serve, serve with caring</li>
<li>Whenever you dream – dream with your all</li>
<li>Wherever you go, go as a leader</li>
<li>And never, never give up</li>
<li>Whatever you do – do it with integrity</li>
</ul>
<p>“That builds trust, trust builds relationships and relationships build results.”</p>
<p>=============================================</p>
<p>Actually, I took about 40 pages of notes throughout the two days… So I can’t say that this will be my last summary post on the Inc 500/5000 conference, but I can say that the conference did leave a strong impression about how I can help shape the future of ScienceLogic in an even more positive way.</p>
]]></content:encoded>
      <pubDate>Fri, 26 Sep 2008 14:00:44 +0000</pubDate>
      <category domain="http://securityratty.com/tag/conference">conference</category>
      <category domain="http://securityratty.com/tag/happy companies">happy companies</category>
      <category domain="http://securityratty.com/tag/happy">happy</category>
      <category domain="http://securityratty.com/tag/successful company">successful company</category>
      <category domain="http://securityratty.com/tag/happy businesses">happy businesses</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/product company">product company</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/ceo carlson companies">ceo carlson companies</category>
      <source url="http://blog.sciencelogic.com/inc-5005000-conference-summary/09/2008">Inc 500/5000 Conference Summary</source>
    </item>
    <item>
      <title><![CDATA[Too Many Events, Too Little Time]]></title>
      <link>http://securityratty.com/article/50b43f8b0380bf4469fd976197e64cf6</link>
      <guid>http://securityratty.com/article/50b43f8b0380bf4469fd976197e64cf6</guid>
      <description><![CDATA[ScienceLogicians will be scattering around the nation next week to cover 5 shows. Where well be

Interop NY
East Coast version of this major networking show. ScienceLogic is the official provider for...]]></description>
      <content:encoded><![CDATA[<p>ScienceLogicians will be scattering around the nation next week to cover 5 shows. Where we&#8217;ll be:</p>
<p><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="107" alt="interopny" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/interopny1.gif" width="214" border="0" /> </p>
<p><a href="http://www.interop.com/" target="_blank">Interop NY</a></p>
<ul>
<li>East Coast version of this major networking show. ScienceLogic is the official provider for network monitoring and help desk for <a href="http://www.interop.com/newyork/event-highlights/interopnet/sponsors.php">InteropNet</a>, the world&#8217;s largest temporary network. See us in action in the NOC. Stop by the booth, #1045, to chat, pick up your own deck of <a href="http://www.sciencelogic.com/carddeck.htm" target="_blank">EM7 cards</a>, or fill out a <a href="http://www.sciencelogic.com/pressrelease_20071114.htm" target="_blank">survey</a> for a free t-shirt. </li>
<li>When: Conference runs from Mon 9/15 &#8211; Friday 9/19. Expo days are Wed 9/17 &#8211; Thurs 9/18. </li>
<li>Where: The Javits Center, NYC. </li>
</ul>
<p>&#160;</p>
<p>&#160;<img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="101" alt="vmware" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/vmware.png" width="296" border="0" /> </p>
<p><a href="http://www.vmworld.com/conferences/2008" target="_blank">VMworld 2008</a></p>
<ul>
<li>The largest virtualization show put on by VMware, the leader in the space. VMworld is only a couple of years old but growing like gangbusters. This year&#8217;s show should be an interesting one in light of all the turmoil surrounding VMware and Microsoft&#8217;s putsch, oops I meant push, into the space with Hyper-V. </li>
<li>When: Mon 9/15 is Partner Day. Conference runs from Tues 9/16 &#8211; Thurs 9/18 </li>
<li>Where: The Venetian Hotel, Las Vegas. </li>
</ul>
<p>&#160;</p>
<p><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="57" alt="clip_image002" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/clip-image0021.jpg" width="305" border="0" /></p>
<p><a href="http://www.hsvsummit.com/na/2008/" target="_blank">Hosting Transformation Summit</a></p>
<ul>
<li>Executive-level hosting/service provider show run by The 451 Group (and Tier 1). The analysts at The 451 Group and Tier 1 discuss state of the industry and trends. </li>
<li>When: Mon 9/15 &#8211; Wed 9/17 </li>
<li>Where: The Mirage, Las Vegas </li>
</ul>
<p>&#160;</p>
<p><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="61" alt="clip_image002[5]" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/clip-image0025.jpg" width="304" border="0" /></p>
<p><a href="http://www.icesummit.com/na/2008/" target="_blank">ICE Summit</a></p>
<ul>
<li>Also run by The 451 Group, the ICE (Infrastructure Computing for the Enterprise) Summit will focus on &#8220;virtualization in context&#8221;. This overlaps the last day of VMworld (personally making my life a little harder). </li>
<li>When: Thurs 9/18 </li>
<li>Where: The Mirage, Las Vegas </li>
</ul>
<p>&#160;</p>
<p><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="85" alt="in500inc5000" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/in500inc5000.png" width="294" border="0" /> </p>
<p>Inc 500 / Inc 5000 <a href="http://secure.lenos.com/lenos/inc/Inc500WashingtonDC/" target="_blank">Conference &amp; Awards Ceremony</a></p>
<ul>
<li>Since we made it on the list (<a href="http://blog.sciencelogic.com/sciencelogic-makes-it-onto-the-inc-500-list-of-fastest-growing-private-companies-in-us/08/2008" target="_blank">#350</a>!), we thought we should show the flag at the Inc 500 conference, culminating in an awards gala on Saturday night. </li>
<li>When: Thurs 9/18 &#8211; Sat 9/20 </li>
<li>Where: Gaylord National Resort &amp; Convention Center at the National Harbor (DC) </li>
</ul>
<p>Stay tuned for live blogging and video from the various events with always lively commentary from the ScienceLogicians.</p>
]]></content:encoded>
      <pubDate>Thu, 11 Sep 2008 11:00:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/conference">conference</category>
      <category domain="http://securityratty.com/tag/conference runs">conference runs</category>
      <category domain="http://securityratty.com/tag/las vegas">las vegas</category>
      <category domain="http://securityratty.com/tag/summit">summit</category>
      <category domain="http://securityratty.com/tag/transformation summit">transformation summit</category>
      <category domain="http://securityratty.com/tag/thurs">thurs</category>
      <category domain="http://securityratty.com/tag/ice summit">ice summit</category>
      <category domain="http://securityratty.com/tag/ice">ice</category>
      <category domain="http://securityratty.com/tag/day">day</category>
      <source url="http://blog.sciencelogic.com/too-many-events-too-little-time/09/2008">Too Many Events, Too Little Time</source>
    </item>
    <item>
      <title><![CDATA[Over 400 Calls Made Using Hacked Federal Emergency Management Agency PBX Network]]></title>
      <link>http://securityratty.com/article/c9de99e2785196a9f0d97e85d7507137</link>
      <guid>http://securityratty.com/article/c9de99e2785196a9f0d97e85d7507137</guid>
      <description><![CDATA[A hacker broke into a Homeland Security Department telephone system over the weekend and racked up about $12,000 in calls to the Middle East and Asia. The hacker made more than 400 calls on a Federal...]]></description>
      <content:encoded><![CDATA[A hacker broke into a Homeland Security Department telephone system over the weekend and racked up about $12,000 in calls to the Middle East and Asia. The hacker made more than 400 calls on a Federal Emergency Management Agency (FEMA) voicemail system in Emmitsburg, Md., on Saturday and Sunday, according to FEMA spokesman Tom Olshanski.
The [...]]]></content:encoded>
      <pubDate>Thu, 21 Aug 2008 12:25:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/calls">calls</category>
      <category domain="http://securityratty.com/tag/middle east">middle east</category>
      <category domain="http://securityratty.com/tag/hacker">hacker</category>
      <category domain="http://securityratty.com/tag/voicemail system">voicemail system</category>
      <category domain="http://securityratty.com/tag/sunday">sunday</category>
      <category domain="http://securityratty.com/tag/weekend">weekend</category>
      <category domain="http://securityratty.com/tag/fema">fema</category>
      <category domain="http://securityratty.com/tag/saturday">saturday</category>
      <category domain="http://securityratty.com/tag/asia">asia</category>
      <source url="http://cyberinsecure.com/over-400-calls-made-using-hacked-federal-emergency-management-agency-pbx-network/">Over 400 Calls Made Using Hacked Federal Emergency Management Agency PBX Network</source>
    </item>
    <item>
      <title><![CDATA[MBTA Hacking Injunction Lifted]]></title>
      <link>http://securityratty.com/article/68d65816825f3a808d946a2980aee0f8</link>
      <guid>http://securityratty.com/article/68d65816825f3a808d946a2980aee0f8</guid>
      <description><![CDATA[Earlier today, the US District Court dealt a victory to the MBTA hackers and the EFF, lifting the injunction issued on August 9th to prevent the three MIT students from presenting their findings at...]]></description>
      <content:encoded><![CDATA[<p>Earlier today, the US District Court <a href="http://www.eff.org/press/archives/2008/08/19">dealt a victory</a> to the MBTA hackers and the EFF, lifting the injunction issued on August 9th to prevent the three MIT students from presenting their findings at <a href="http://defcon.org/">DEFCON 16</a>.  In summary:</p>
<blockquote><p>The lawsuit claimed that the students&#8217; planned presentation would violate the Computer Fraud and Abuse Act (CFAA) by enabling others to defraud the MBTA of transit fares. A different federal judge, meeting in a special Saturday session, ordered the trio not to disclose for ten days any information that could be used by others to get free subway rides.</p>
<p>&#8220;The judge today correctly found that it was unlikely that the CFAA would apply to security researchers giving an academic talk,&#8221; said EFF Staff Attorney Marcia Hofmann. &#8220;A presentation at a security conference is not some sort of computer intrusion. It&#8217;s protected speech and vital to the free flow of information about computer security vulnerabilities. Silencing researchers does not improve security &#8212; the vulnerability was there before the students discovered it and would remain in place regardless of whether the students publicly discussed it or not.&#8221;</p></blockquote>
<p>This sets a good precedent for future cases, and perhaps next time a similar situation arises, a judge will not be so quick to issue a gag order.  It&#8217;s not a happy ending yet though, as the <a href="http://www.eff.org/files/filenode/MBTA_v_Anderson/mbta-v-anderson-complaint.pdf">original lawsuit</a> is still in effect.</p>
<p>As Chris Wysopal <a href="http://www.veracode.com/blog/2008/08/sorry-charliecard-your-security-model-is-broken/">pointed out last week</a>, the MBTA&#8217;s ire is misdirected.  Rather than suing the vendor who sold them the defective system, they sued and attempted to silence the students who discovered the weakness.  This is 2008, not 1988 &#8212; did they honestly think a gag order would prevent the information from reaching the general public?   The DEFCON presentation was already available on the <a href="http://en.wikipedia.org/wiki/Series_of_tubes">Intertubes</a> prior to the injunction being issued, and the MBTA attorneys included a copy of the confidential whitepaper with their filing, thereby making it public.  </p>
<p>I guess you wouldn&#8217;t expect that a transit authority would have paid any attention to the<a href="http://www.schneier.com/blog/archives/2005/07/cisco_harasses.html">Ciscogate fiasco</a> from a few years ago. <a href="http://cryptome.org/lynn-cisco-jpg.htm">That presentation</a> never got out either, did it?  All that taxpayer money the MBTA spent on ridiculous lawsuits and restraining orders could have been put toward fixing the security flaws.  What a concept.</p>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 01:49:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mbta">mbta</category>
      <category domain="http://securityratty.com/tag/students">students</category>
      <category domain="http://securityratty.com/tag/students publicly">students publicly</category>
      <category domain="http://securityratty.com/tag/defcon presentation">defcon presentation</category>
      <category domain="http://securityratty.com/tag/defcon">defcon</category>
      <category domain="http://securityratty.com/tag/mbta hackers">mbta hackers</category>
      <category domain="http://securityratty.com/tag/presentation">presentation</category>
      <category domain="http://securityratty.com/tag/mit students">mit students</category>
      <category domain="http://securityratty.com/tag/judge">judge</category>
      <source url="http://www.veracode.com/blog/2008/08/mbta-hacking-injunction-lifted/">MBTA Hacking Injunction Lifted</source>
    </item>
    <item>
      <title><![CDATA[Consumer Reports Responds]]></title>
      <link>http://securityratty.com/article/6c99136056552315f93619486db85f54</link>
      <guid>http://securityratty.com/article/6c99136056552315f93619486db85f54</guid>
      <description><![CDATA[Consumer Reports has sent a response to my recent column Security Software Reviews Done Wrong , which criticized their recent story on computer security and review of security products. This statement...]]></description>
      <content:encoded><![CDATA[Consumer Reports has sent a response to my recent column <A href="http://www.eweek.com/c/a/Security/The-Wrong-Way-To-Review-Security-Software/">Security Software Reviews Done Wrong</A>, which criticized their recent story on computer security and review of security products.

This statement is from Jeff Fox, Technology Editor, Consumer Reports:
<blockquote><i>At Consumer Reports, we have always believed that scientific testing is the best way to evaluate products. We also use a statistically-valid survey methodology to measure consumer experiences. In preparing our September security reports, we employed both methods as we have for many decades. Some additional notes on this column:

<ul>
	<li>The story was not, as you state, "filled with data sourced to eMarketer." That service provided just two pieces of data, namely the current number of Internet- and broadband-using U.S. Households</li>
	<li>Using a separate credit card for online transactions avoids having to cancel your main card should fraud occur.</li>
	<li>We test software against modified versions of actual malware because such threats are what security software will often be called upon to recognize on the job.</li>
</ul>

Finally, a note about your claim that Consumer Reports was invited to respond. Your e-mail to us requesting a comment was time-stamped on the same Saturday evening as your column is labeled as having posted. That left fewer than six hours to respond, on a weekend. It would have been helpful to have had more time.</i></blockquote>

It's true, as I said in the column, that I didn't give them much time to respond. I hope I can make up for that some by putting this response out now and including it in the column itself.<img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/jvhoWp-SQns" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 12:12:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/consumer reports">consumer reports</category>
      <category domain="http://securityratty.com/tag/column">column</category>
      <category domain="http://securityratty.com/tag/measure consumer experiences">measure consumer experiences</category>
      <category domain="http://securityratty.com/tag/products">products</category>
      <category domain="http://securityratty.com/tag/online transactions avoids">online transactions avoids</category>
      <category domain="http://securityratty.com/tag/recent story">recent story</category>
      <category domain="http://securityratty.com/tag/story">story</category>
      <category domain="http://securityratty.com/tag/september security reports">september security reports</category>
      <category domain="http://securityratty.com/tag/security products">security products</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/jvhoWp-SQns/consumer_reports_responds.html">Consumer Reports Responds</source>
    </item>
    <item>
      <title><![CDATA[The Continuing Cheapening of the Word "Terrorism"]]></title>
      <link>http://securityratty.com/article/2077783c6168471edf6cbb56a4eacb02</link>
      <guid>http://securityratty.com/article/2077783c6168471edf6cbb56a4eacb02</guid>
      <description><![CDATA[Illegally diverting water is terrorism: South Australian Premier Mike Rann says the diversion of water from the Paroo River in Queensland is an act of terrorism during a water crisis
Anonymously...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.abc.net.au/news/stories/2008/08/15/2336850.htm">Illegally diverting water</a> is terrorism:</p>

<blockquote>South Australian Premier Mike Rann says the diversion of water from the Paroo River in Queensland is an act of terrorism during a water crisis.</blockquote>

<p><a href="http://www.wsls.com/sls/news/local/new_river_valley/article/giles_county_teens_face_terrorism_related_charges/15587/">Anonymously threatening people with messages on playing cards</a>, like the Joker in <i>The Dark Knight</i>, is terrorism:</p>

<blockquote>Giles County deputies arrest two county teenagers they say made terroristic threats to people on playing cards.

<p>Investigators say 18-year olds Brian Stafford and Justin Dirico left eight threatening playing cards at the Pearisburg Wal-Mart on Saturday, August 9th.  The cards read "9 people will die" and "9 people will suffer" with the date 8-15-08.</p>

<p>A ninth card was found on a car at the Dairy Queen on Sunday, August 10th.</blockquote></p>

<p>I've written about <a href="http://www.schneier.com/blog/archives/2008/04/terroristic_thr.html">this sort</a> <a href="http://www.schneier.com/blog/archives/2008/07/random_stupidit.html">of thing</a> before.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=sKBDWK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=sKBDWK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=7O7XFK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=7O7XFK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 02:09:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/terrorism">terrorism</category>
      <category domain="http://securityratty.com/tag/water">water</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/water crisis">water crisis</category>
      <category domain="http://securityratty.com/tag/cards">cards</category>
      <category domain="http://securityratty.com/tag/giles county deputies">giles county deputies</category>
      <category domain="http://securityratty.com/tag/august 10th">august 10th</category>
      <category domain="http://securityratty.com/tag/county teenagers">county teenagers</category>
      <category domain="http://securityratty.com/tag/terroristic threats">terroristic threats</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/the_continuing_1.html">The Continuing Cheapening of the Word "Terrorism"</source>
    </item>
    <item>
      <title><![CDATA[Review: Eye-Fi Explore Hits the Mark]]></title>
      <link>http://securityratty.com/article/33c4299be29dce33f9010e5f6b251d93</link>
      <guid>http://securityratty.com/article/33c4299be29dce33f9010e5f6b251d93</guid>
      <description><![CDATA[After spending two weeks with the $130 Eye-Fi Explore Wi-Fi memory card, I'm a fan: The Eye-Fi Explore was introduced in July by the eponymous firm to support geotagging - embedding latitude and...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.eye.fi/products/explore/"><strong>After spending two weeks with the $130 Eye-Fi Explore Wi-Fi memory card, I'm a fan:</strong></a> The Eye-Fi Explore was introduced in July by the eponymous firm to support geotagging - embedding latitude and longitude into photo metadata - and easier uploading of images. The Eye-Fi Explore is a Secure Digital (SD) card with 2 GB of storage, a tiny computer, and a Wi-Fi radio. The Explore uses Skyhook Wireless's Wi-Fi positioning data combined with Wayport's network of 10,000 hotspots, mostly McDonald's, along with revised firmware and software that dramatically improves the experience of uploading photos.</p>

<p>The company shuffled its products into three versions several weeks ago: Eye-Fi Home ($80), which uploads only to a specific computer over a local network; Eye-Fi Share ($100), a rebranded version identical to its first offering last year, which can upload to photo-sharing services or a computer or both; and the Explore. (You can purchase <a href="http://www.amazon.com/gp/redirect.html?ie=UTF8&location=http%3A%2F%2Fwww.amazon.com%2FEye-Fi-Explore-Wireless-Digital-EYE-FI-2EX%2Fdp%2FB001ACXHXE&tag=searchbyisbn&linkCode=ur2&camp=1789&creative=9325">the Eye-Fi Explore from Amazon.com</a><img src="http://www.assoc-amazon.com/e/ir?t=searchbyisbn&amp;l=ur2&amp;o=1" width="1" height="1" border="0" alt="" style="border:none !important; margin:0px !important;" />, as well as the other models.)</p>

<p><img src="http://wifinetnews.com//images/2008/eye-fi_cards_sharer_sm.jpg" alt="eye-fi_cards_sharer_sm.jpg" border="0" width="169" height="250" align="right" />I <a href="http://seattletimes.nwsource.com/html/businesstechnology/2008101745_ptgeotag09.html"><strong>reviewed the Explore as a geotagging system</strong></a> for The Seattle Times this last Saturday; I'd <a href="http://seattletimes.nwsource.com/html/businesstechnology/2004005462_pteyefi10.html"><strong>reviewed the original Eye-Fi</strong></a> (now Eye-Fi Share) for them last year as well. You can read that review for my take on geotagging, or skip to the bottom of this review, as well.</p>

<p>The hardware is apparently the same or nearly so, and it works just as well as it did last year. The biggest improvements, however, are a few workflow tweaks that make it far easier to manage and track uploads of pictures without draining your camera's batteries down to zero.<br />
<br clear="all"></p>]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 08:13:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/eye-fi explore">eye-fi explore</category>
      <category domain="http://securityratty.com/tag/explore">explore</category>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/specific computer">specific computer</category>
      <category domain="http://securityratty.com/tag/eye-fi share">eye-fi share</category>
      <category domain="http://securityratty.com/tag/review">review</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/weeks ago">weeks ago</category>
      <category domain="http://securityratty.com/tag/wi-fi radio">wi-fi radio</category>
      <source url="http://wifinetnews.com/archives/008418.html">Review: Eye-Fi Explore Hits the Mark</source>
    </item>
  </channel>
</rss>
