<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: shannon]]></title>
    <link>http://securityratty.com/tag/shannon</link>
    <description></description>
    <pubDate>Sun, 25 Feb 2007 21:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Phreaknic 12 (2008) Hacker Con]]></title>
      <link>http://securityratty.com/article/4f1c46cc8d2c53438d8656355e1bfa74</link>
      <guid>http://securityratty.com/article/4f1c46cc8d2c53438d8656355e1bfa74</guid>
      <description><![CDATA[New Video: Phreaknic 12 (2008) Hacker Con

This is a quick and dirty video documentary of the things that when on around the talks and event at Phreaknic 12 (2008). Don't watch if you get sick at...]]></description>
      <content:encoded><![CDATA[New Video: <a href="http://www.irongeek.com/i.php?page=videos/phreaknic-12-hacker-con">Phreaknic 12 (2008) Hacker Con</FONT></B></a>
<p></p>
<p>This is a quick and dirty video documentary of the things that when on around the talks and event at <a href="http://www.phreaknic.info">Phreaknic 12 </a>(2008). Don't watch if you get sick at shaky cam movies like Blair Witch or Cloverfield. A rough timeline of the content in the video is as follows: </p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Intro and leaving Louisville with Brian. Morgellon talks about hacking the <a href="http://dailyduino.com/">Arduino</a> micro controller platform.&nbsp;Sorteal talks about the LiVes Open Source video editor. AT&amp;T Batman building by night. Mojo-JoJo soldering some stuff for the shooting range. The patron gods of hackerdom. Registration. Con swag overview. Morgellon&nbsp; gets his discreet logic on. AK-47 building with HandGrip and Buttstock. Froggy talks up Notacon, which I plan to go to next year. Skydog explains the Jware chair toss event, and then we compete. Rootwars hacker wargames. I ask <a href="http://dualcoremusic.com/nerdcore/">Int80 about using his nerdcore</a> music in some of my videos. NotLarry explains rootwars. Some iPhone hacking with <a href="http://leebaird.com/Me/Hacking.html">Lee Baird</a> and John Skinner. I do a little <a href="http://www.irongeek.com/i.php?page=security/bluecasing1">Bluecaseing/Warnibbling </a>with the Bluetooth on my Nokia n810. John, Lee, Brian and I go to the German restaurant. I blind DOSman with the light from my camera and check out what folks are doing with the <a href="http://dailyduino.com/">Arduinos</a> Droops brought for folks to play with. I check back in on R00tW4rz. I blind Droops. I talk Ettercap filters with <a href="http://www.rmccurdy.com/">operat0r</a>. USB door key fun with the <a href="http://dailyduino.com/">Arduino</a>. More breadboard fun. Nokia n810 + Ettercap Filter + Lemon-part = win. <a href="http://dualcoremusic.com/nerdcore/">Int80</a> gets down with his own bad self, and the rest of Phreaknic. I find an energy drink with protein. Folks play with the hardware keyloggers I brought, and we have some epic fail with the IBM Model M + USB adapter + Mac OS 10.5. <a href="http://www.winnschwartau.com/">Winn Schwartau</a> joins in on the keylogger fun. <a href="http://www.packetsniffers.org/">DOSman and Zack</a> use a directional antenna from the 9th floor to search downtown Nashville for WiFi access points. Zoom in on Al. John and Lee eat jerky. <a href="http://www.hak5.org/">Daren and Shannon from Hak5</a> blind me this time. :) Then they do a quick interview. I interview <a href="http://www.digome.com/">TRiP</a> about the legalities of wardriving, sniffing and leaving your access point open so you have plausible deniability of copyright infringement (most likely it won't hold water in court if you are a computer geek). I give Hak5 Daren beef jerky. <a href="http://www.offensive-security.com/">Ziplock</a> had more con badges than God. I meet up with Iridium. I talk with Nightcarnage about the audio/video setup at Phreaknic. As I predicted, the <a href="http://www.shmoo.com/~gdead/Site/Home.html">Potters</a> won the WiFi Race. I say why this was the best Phreaknic ever. Using green lasers on crack dealers. Techno in the dark, the Aiptek action HD does not do well in low light. Nicodemius shows off his Minority Report like multi-touch table. Hula hoop contest. I check back in with Jeff Cotton and his USB keyed door. I strap on my gear to leave the con. Brian and I do a wrap up of our thoughts on Phreaknic 2008.</p>
<p><a href="http://feedads.googleadservices.com/~a/fu-jGbBXkZllK6znlRDBB8Bbjxo/a"><img src="http://feedads.googleadservices.com/~a/fu-jGbBXkZllK6znlRDBB8Bbjxo/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/H4w0W-ygK2s" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 02:59:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/con">con</category>
      <category domain="http://securityratty.com/tag/phreaknic">phreaknic</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/con swag overview">con swag overview</category>
      <category domain="http://securityratty.com/tag/source video editor">source video editor</category>
      <category domain="http://securityratty.com/tag/talks">talks</category>
      <category domain="http://securityratty.com/tag/sorteal talks">sorteal talks</category>
      <category domain="http://securityratty.com/tag/hacker con">hacker con</category>
      <category domain="http://securityratty.com/tag/lee eat jerky">lee eat jerky</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/H4w0W-ygK2s/i.php">Phreaknic 12 (2008) Hacker Con</source>
    </item>
    <item>
      <title><![CDATA[Phreaknic 12 (2008) Hacker Con]]></title>
      <link>http://securityratty.com/article/91dad2a3ec5ac9d4f78bd2d1a2bb18c2</link>
      <guid>http://securityratty.com/article/91dad2a3ec5ac9d4f78bd2d1a2bb18c2</guid>
      <description><![CDATA[New Video: Phreaknic 12 (2008) Hacker Con

This is a quick and dirty video documentary of the things that when on around the talks and event at Phreaknic 12 (2008). Don't watch if you get sick at...]]></description>
      <content:encoded><![CDATA[New Video: <a href="http://www.irongeek.com/i.php?page=videos/phreaknic-12-hacker-con">Phreaknic 12 (2008) Hacker Con</FONT></B></a>
<p></p>
<p>This is a quick and dirty video documentary of the things that when on around the talks and event at <a href="http://www.phreaknic.info">Phreaknic 12 </a>(2008). Don't watch if you get sick at shaky cam movies like Blair Witch or Cloverfield. A rough timeline of the content in the video is as follows: </p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Intro and leaving Louisville with Brian. Morgellon talks about hacking the <a href="http://dailyduino.com/">Arduino</a> micro controller platform.&nbsp;Sorteal talks about the LiVes Open Source video editor. AT&amp;T Batman building by night. Mojo-JoJo soldering some stuff for the shooting range. The patron gods of hackerdom. Registration. Con swag overview. Morgellon&nbsp; gets his discreet logic on. AK-47 building with HandGrip and Buttstock. Froggy talks up Notacon, which I plan to go to next year. Skydog explains the Jware chair toss event, and then we compete. Rootwars hacker wargames. I ask <a href="http://dualcoremusic.com/nerdcore/">Int80 about using his nerdcore</a> music in some of my videos. NotLarry explains rootwars. Some iPhone hacking with <a href="http://leebaird.com/Me/Hacking.html">Lee Baird</a> and John Skinner. I do a little <a href="http://www.irongeek.com/i.php?page=security/bluecasing1">Bluecaseing/Warnibbling </a>with the Bluetooth on my Nokia n810. John, Lee, Brian and I go to the German restaurant. I blind DOSman with the light from my camera and check out what folks are doing with the <a href="http://dailyduino.com/">Arduinos</a> Droops brought for folks to play with. I check back in on R00tW4rz. I blind Droops. I talk Ettercap filters with <a href="http://www.rmccurdy.com/">operat0r</a>. USB door key fun with the <a href="http://dailyduino.com/">Arduino</a>. More breadboard fun. Nokia n810 + Ettercap Filter + Lemon-part = win. <a href="http://dualcoremusic.com/nerdcore/">Int80</a> gets down with his own bad self, and the rest of Phreaknic. I find an energy drink with protein. Folks play with the hardware keyloggers I brought, and we have some epic fail with the IBM Model M + USB adapter + Mac OS 10.5. <a href="http://www.winnschwartau.com/">Winn Schwartau</a> joins in on the keylogger fun. <a href="http://www.packetsniffers.org/">DOSman and Zack</a> use a directional antenna from the 9th floor to search downtown Nashville for WiFi access points. Zoom in on Al. John and Lee eat jerky. <a href="http://www.hak5.org/">Daren and Shannon from Hak5</a> blind me this time. :) Then they do a quick interview. I interview <a href="http://www.digome.com/">TRiP</a> about the legalities of wardriving, sniffing and leaving your access point open so you have plausible deniability of copyright infringement (most likely it won't hold water in court if you are a computer geek). I give Hak5 Daren beef jerky. <a href="http://www.offensive-security.com/">Ziplock</a> had more con badges than God. I meet up with Iridium. I talk with Nightcarnage about the audio/video setup at Phreaknic. As I predicted, the <a href="http://www.shmoo.com/~gdead/Site/Home.html">Potters</a> won the WiFi Race. I say why this was the best Phreaknic ever. Using green lasers on crack dealers. Techno in the dark, the Aiptek action HD does not do well in low light. Nicodemius shows off his Minority Report like multi-touch table. Hula hoop contest. I check back in with Jeff Cotton and his USB keyed door. I strap on my gear to leave the con. Brian and I do a wrap up of our thoughts on Phreaknic 2008.</p>]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 02:59:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/con">con</category>
      <category domain="http://securityratty.com/tag/phreaknic">phreaknic</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/con swag overview">con swag overview</category>
      <category domain="http://securityratty.com/tag/source video editor">source video editor</category>
      <category domain="http://securityratty.com/tag/talks">talks</category>
      <category domain="http://securityratty.com/tag/sorteal talks">sorteal talks</category>
      <category domain="http://securityratty.com/tag/hacker con">hacker con</category>
      <category domain="http://securityratty.com/tag/lee eat jerky">lee eat jerky</category>
      <source url="http://www.irongeek.com/i.php?page=videos/phreaknic-12-hacker-con">Phreaknic 12 (2008) Hacker Con</source>
    </item>
    <item>
      <title><![CDATA[Phreaknic 12 (2008) Hacker Con]]></title>
      <link>http://securityratty.com/article/215684d0c6bd7ef7ac4756e6b556cf79</link>
      <guid>http://securityratty.com/article/215684d0c6bd7ef7ac4756e6b556cf79</guid>
      <description><![CDATA[New Video: Phreaknic 12 (2008) Hacker Con

This is a quick and dirty video documentary of the things that when on around the talks and event at Phreaknic 12 (2008). Don't watch if you get sick at...]]></description>
      <content:encoded><![CDATA[New Video: <a href="http://www.irongeek.com/i.php?page=videos/phreaknic-12-hacker-con">Phreaknic 12 (2008) Hacker Con</FONT></B></a>
<p></p>
<p>This is a quick and dirty video documentary of the things that when on around the talks and event at <a href="http://www.phreaknic.info">Phreaknic 12 </a>(2008). Don't watch if you get sick at shaky cam movies like Blair Witch or Cloverfield. A rough timeline of the content in the video is as follows: </p>
<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Intro and leaving Louisville with Brian. Morgellon talks about hacking the <a href="http://dailyduino.com/">Arduino</a> micro controller platform.&nbsp;Sorteal talks about the LiVes Open Source video editor. AT&amp;T Batman building by night. Mojo-JoJo soldering some stuff for the shooting range. The patron gods of hackerdom. Registration. Con swag overview. Morgellon&nbsp; gets his discreet logic on. AK-47 building with HandGrip and Buttstock. Froggy talks up Notacon, which I plan to go to next year. Skydog explains the Jware chair toss event, and then we compete. Rootwars hacker wargames. I ask <a href="http://dualcoremusic.com/nerdcore/">Int80 about using his nerdcore</a> music in some of my videos. NotLarry explains rootwars. Some iPhone hacking with <a href="http://leebaird.com/Me/Hacking.html">Lee Baird</a> and John Skinner. I do a little <a href="http://www.irongeek.com/i.php?page=security/bluecasing1">Bluecaseing/Warnibbling </a>with the Bluetooth on my Nokia n810. John, Lee, Brian and I go to the German restaurant. I blind DOSman with the light from my camera and check out what folks are doing with the <a href="http://dailyduino.com/">Arduinos</a> Droops brought for folks to play with. I check back in on R00tW4rz. I blind Droops. I talk Ettercap filters with <a href="http://www.rmccurdy.com/">operat0r</a>. USB door key fun with the <a href="http://dailyduino.com/">Arduino</a>. More breadboard fun. Nokia n810 + Ettercap Filter + Lemon-part = win. <a href="http://dualcoremusic.com/nerdcore/">Int80</a> gets down with his own bad self, and the rest of Phreaknic. I find an energy drink with protein. Folks play with the hardware keyloggers I brought, and we have some epic fail with the IBM Model M + USB adapter + Mac OS 10.5. <a href="http://www.winnschwartau.com/">Winn Schwartau</a> joins in on the keylogger fun. <a href="http://www.packetsniffers.org/">DOSman and Zack</a> use a directional antenna from the 9th floor to search downtown Nashville for WiFi access points. Zoom in on Al. John and Lee eat jerky. <a href="http://www.hak5.org/">Daren and Shannon from Hak5</a> blind me this time. :) Then they do a quick interview. I interview <a href="http://www.digome.com/">TRiP</a> about the legalities of wardriving, sniffing and leaving your access point open so you have plausible deniability of copyright infringement (most likely it won't hold water in court if you are a computer geek). I give Hak5 Daren beef jerky. <a href="http://www.offensive-security.com/">Ziplock</a> had more con badges than God. I meet up with Iridium. I talk with Nightcarnage about the audio/video setup at Phreaknic. As I predicted, the <a href="http://www.shmoo.com/~gdead/Site/Home.html">Potters</a> won the WiFi Race. I say why this was the best Phreaknic ever. Using green lasers on crack dealers. Techno in the dark, the Aiptek action HD does not do well in low light. Nicodemius shows off his Minority Report like multi-touch table. Hula hoop contest. I check back in with Jeff Cotton and his USB keyed door. I strap on my gear to leave the con. Brian and I do a wrap up of our thoughts on Phreaknic 2008.</p>
<p><a href="http://feedads.googleadservices.com/~a/fu-jGbBXkZllK6znlRDBB8Bbjxo/a"><img src="http://feedads.googleadservices.com/~a/fu-jGbBXkZllK6znlRDBB8Bbjxo/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/f9ViIhlukDU" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 02:59:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/con">con</category>
      <category domain="http://securityratty.com/tag/phreaknic">phreaknic</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/con swag overview">con swag overview</category>
      <category domain="http://securityratty.com/tag/source video editor">source video editor</category>
      <category domain="http://securityratty.com/tag/talks">talks</category>
      <category domain="http://securityratty.com/tag/sorteal talks">sorteal talks</category>
      <category domain="http://securityratty.com/tag/hacker con">hacker con</category>
      <category domain="http://securityratty.com/tag/lee eat jerky">lee eat jerky</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/f9ViIhlukDU/i.php">Phreaknic 12 (2008) Hacker Con</source>
    </item>
    <item>
      <title><![CDATA[Hardware Keyloggers use detection and mitigation Phreaknic Presentation slides posted]]></title>
      <link>http://securityratty.com/article/a4ffb7265555883a6ec1791fa2e0813f</link>
      <guid>http://securityratty.com/article/a4ffb7265555883a6ec1791fa2e0813f</guid>
      <description><![CDATA[Phreaknic was a great time this year, as always. I've posted the slides from my hardware key loggers presentation at the above link. I'd like to thank the following people
Sky Dog and crew for making...]]></description>
      <content:encoded><![CDATA[<a href="http://www.phreaknic.info">Phreaknic</a> was a great time this year, as always. I've posted the slides from my hardware key loggers presentation at the above link. <br/>I'd like to thank the following people: 
<p>Sky Dog and crew for making it happen.<br/><a href="http://dailyduino.com/">Droops/Morgellon</a> for their presentation on <a href="http://dailyduino.com/">Arduino</a>, time for some hardware hacking. <br/>Sorteal for showing me the LiVes Open Source video editor.<br/>Marie for the dance and conversation.<br/><a href="http://www.digome.com/">TRiP</a> for an excellent talk on the legalities of wardriving.<br/>HandGrip/Buttstock for the Open Source AK-47 talk.<br/>All the folks who let me interview them.<br/>DOSman and Zack form being DOSman and Zack.<br/><a href="http://leebaird.com/Me/Hacking.html">Lee Baird</a> and John Skinner for comparing mobile hacking notes with me (Yippy <a href="http://leebaird.com/Me/Hacking.html">hacking with the iPhone / iPwn</a>).<br/><a href="http://www.offensive-security.com/">Ziplock</a> for the encouragement. <br/><a href="http://dualcoremusic.com/nerdcore/">Int 80</a> for the <a href="http://dualcoremusic.com/nerdcore/">Nercore</a> entertainment. <br/>Scott Moulton for the talk "At Least TEN things you didn't know about your hard drive!" Go check out his <a href="http://www.myharddrivedied.com/presentations.html">forensics and hard drive recovery videos</a>. <br/><a href="http://hackerpimps.com/">Nathan Hamiel/Shawn Moyer</a> for "Satan is on my Friends List: Attacking Social Networks", looks like I need to get into some CSRF. <br/><a href="http://www.hak5.org/">Darren, Shannon and Mubix of Hak5 </a>for the interview.<br/><a href="http://www.rmccurdy.com/">operat0r</a> for the Ettercap ideas.<br/>Brian for driving me down.</p>
<p>And everyone else I'm forgetting. It was a great weekend.</p>
<p><a href="http://feedads.googleadservices.com/~a/RAlOYBqvOeWovKvsjMCQ5RgneeA/a"><img src="http://feedads.googleadservices.com/~a/RAlOYBqvOeWovKvsjMCQ5RgneeA/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/yXBkWYheSAg" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 26 Oct 2008 13:26:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/source ak-47 talk">source ak-47 talk</category>
      <category domain="http://securityratty.com/tag/talk">talk</category>
      <category domain="http://securityratty.com/tag/zack form">zack form</category>
      <category domain="http://securityratty.com/tag/zack">zack</category>
      <category domain="http://securityratty.com/tag/nathan hamielshawn moyer">nathan hamielshawn moyer</category>
      <category domain="http://securityratty.com/tag/excellent talk">excellent talk</category>
      <category domain="http://securityratty.com/tag/source video editor">source video editor</category>
      <category domain="http://securityratty.com/tag/slides">slides</category>
      <category domain="http://securityratty.com/tag/ettercap ideas">ettercap ideas</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/yXBkWYheSAg/keyloggers.pptx">Hardware Keyloggers use detection and mitigation Phreaknic Presentation slides posted</source>
    </item>
    <item>
      <title><![CDATA[Hardware Keyloggers use detection and mitigation Phreaknic Presentation slides posted]]></title>
      <link>http://securityratty.com/article/e9f6c48276a2b3f0f66121e4f7c467f1</link>
      <guid>http://securityratty.com/article/e9f6c48276a2b3f0f66121e4f7c467f1</guid>
      <description><![CDATA[Phreaknic was a great time this year, as always. I've posted the slides from my hardware key loggers presentation at the above link. I'd like to thank the following people
Sky Dog and crew for making...]]></description>
      <content:encoded><![CDATA[<a href="http://www.phreaknic.info">Phreaknic</a> was a great time this year, as always. I've posted the slides from my hardware key loggers presentation at the above link. <br/>I'd like to thank the following people: 
<p>Sky Dog and crew for making it happen.<br/><a href="http://dailyduino.com/">Droops/Morgellon</a> for their presentation on <a href="http://dailyduino.com/">Arduino</a>, time for some hardware hacking. <br/>Sorteal for showing me the LiVes Open Source video editor.<br/>Marie for the dance and conversation.<br/><a href="http://www.digome.com/">TRiP</a> for an excellent talk on the legalities of wardriving.<br/>HandGrip/Buttstock for the Open Source AK-47 talk.<br/>All the folks who let me interview them.<br/>DOSman and Zack form being DOSman and Zack.<br/><a href="http://leebaird.com/Me/Hacking.html">Lee Baird</a> and John Skinner for comparing mobile hacking notes with me (Yippy <a href="http://leebaird.com/Me/Hacking.html">hacking with the iPhone / iPwn</a>).<br/><a href="http://www.offensive-security.com/">Ziplock</a> for the encouragement. <br/><a href="http://dualcoremusic.com/nerdcore/">Int 80</a> for the <a href="http://dualcoremusic.com/nerdcore/">Nercore</a> entertainment. <br/>Scott Moulton for the talk "At Least TEN things you didn't know about your hard drive!" Go check out his <a href="http://www.myharddrivedied.com/presentations.html">forensics and hard drive recovery videos</a>. <br/><a href="http://hackerpimps.com/">Nathan Hamiel/Shawn Moyer</a> for "Satan is on my Friends List: Attacking Social Networks", looks like I need to get into some CSRF. <br/><a href="http://www.hak5.org/">Darren, Shannon and Mubix of Hak5 </a>for the interview.<br/><a href="http://www.rmccurdy.com/">operat0r</a> for the Ettercap ideas.<br/>Brian for driving me down.</p>
<p>And everyone else I'm forgetting. It was a great weekend.</p>]]></content:encoded>
      <pubDate>Sun, 26 Oct 2008 13:26:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/source ak-47 talk">source ak-47 talk</category>
      <category domain="http://securityratty.com/tag/talk">talk</category>
      <category domain="http://securityratty.com/tag/zack form">zack form</category>
      <category domain="http://securityratty.com/tag/zack">zack</category>
      <category domain="http://securityratty.com/tag/nathan hamielshawn moyer">nathan hamielshawn moyer</category>
      <category domain="http://securityratty.com/tag/excellent talk">excellent talk</category>
      <category domain="http://securityratty.com/tag/source video editor">source video editor</category>
      <category domain="http://securityratty.com/tag/slides">slides</category>
      <category domain="http://securityratty.com/tag/ettercap ideas">ettercap ideas</category>
      <source url="http://www.irongeek.com/security/keyloggers.pptx">Hardware Keyloggers use detection and mitigation Phreaknic Presentation slides posted</source>
    </item>
    <item>
      <title><![CDATA[WellPoint customer information exposed for a year]]></title>
      <link>http://securityratty.com/article/b6ed464e6a6644fda5d62ce2d87cb4d9</link>
      <guid>http://securityratty.com/article/b6ed464e6a6644fda5d62ce2d87cb4d9</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
4/8/08

Organization
WellPoint, Inc

Contractor/Consultant/Branch
An unnamed data management vendor

Victims
Customers

Number Affected
128,000

Types of...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/wellpoint.jpg" align="right" height="52" width="133"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>4/8/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.wellpoint.com/default.asp">WellPoint, Inc.</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>An unnamed data management vendor<br><br><span style="font-weight: bold;">Victims:</span><br>Customers<br><br><span style="font-weight: bold;">Number Affected:</span><br>~128,000<br><br><span style="font-weight: bold;">Types of Data:</span><br>"may have included Social Security numbers and pharmacy or medical data"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"Personal information that may have included Social Security numbers and pharmacy or medical data for about 128,000 WellPoint Inc. customers in several states was exposed online over the past year, the health insurer said Tuesday."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.businessweek.com/ap/financialnews/D8VTUVB80.htm">BusinessWeek</a> <br><a href="http://www.courier-journal.com/apps/pbcs.dll/article?AID=/20080409/BUSINESS/804090795/1003">The Courier-Journal</a> <br><a href="http://www.rttnews.com/sp/breakingnews.asp?item=88">RTT News</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Associated Press via Tom Murphy at BusinessWeek<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Personal information that may have included Social Security numbers and pharmacy or medical data for 128,000 WellPoint customers in several states was exposed online over the past year, the Indianapolis health insurer said yesterday.<br><span style="font-style: italic;">[Evan] Exposed for over a year and nobody (at WellPoint or the vendor anyway) noticed until recently?&nbsp; WellPoint is a large company with millions of confidential records and conflicting business issues, but is this any excuse?</span><br><br>WellPoint, which has had other data security issues in the past, recently learned about the problem, fixed it and is notifying customers, spokeswoman Shannon Troughton said.<br><br>The nation's largest health insurer by membership is offering free credit-monitoring services for those customers, but has received no reports of identity theft or credit fraud.<br><span style="font-style: italic;">[Evan] Uh.&nbsp; There's the short-sighted, limited effectiveness credit-monitoring again.&nbsp; Credit monitoring can limit the damage done by fraudsters, but only after some damage has already been done.</span><br><br>The latest security lapse stems from two servers maintained by an outside vendor that Troughton declined to identify.<br><br>The vendor specializes in data management.<br><span style="font-style: italic;">[Evan] Not very well.&nbsp; Part of data management is data security or vice versa.</span><br><br>WellPoint had learned early last year that a server was improperly secured, and that information on about 1,350 customers may have been exposed online and was vulnerable to Internet search engines. The insurer fixed that breach quickly, Troughton said.<br><br>But the company recently learned that a second server had problems which exposed information for more than 128,000 customers to Internet access for about a year. That data had some code protection and couldn't be found by people using search engines.<br><br>That problem has been corrected, Troughton said, and the company is working with experts to improve its security.<br><span style="font-style: italic;">[Evan] Yeah.&nbsp; I hope the experts are really experts.&nbsp; This really calls for some.</span><br><br>It is still using the same vendor.<br><span style="font-style: italic;">[Evan] Really?</span><br><br>"We're constantly working to fortify and bolster our security," she said.<br><br><span style="font-weight: bold;">Commentary:</span><br>I just wrote the WellCare breach, and now we have the WellPoint breach.&nbsp; Both are health care companies and both involved unsecured online information.&nbsp; Weird.<br><br>Anyway.&nbsp; This is definitely a preventable exposure of personal information that should have been identified much earlier.&nbsp; Due to this and other facts surrounding previous breaches, I think there is cause for serious concern. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>March, 2007 - <a href="http://www.nytimes.com/2007/03/14/business/14insure.html">Medical Data on Empire Blue Cross Members May Be Lost</a> <br>February, 2007 - <a href="http://www.securityfocus.com/brief/440">Healthcare groups bleed patient data</a></font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/04/09/wellpoint.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Wed, 09 Apr 2008 10:23:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data management vendor">data management vendor</category>
      <category domain="http://securityratty.com/tag/vendor">vendor</category>
      <category domain="http://securityratty.com/tag/data management">data management</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/medical data">medical data</category>
      <category domain="http://securityratty.com/tag/patient data">patient data</category>
      <category domain="http://securityratty.com/tag/data security">data security</category>
      <category domain="http://securityratty.com/tag/data security issues">data security issues</category>
      <category domain="http://securityratty.com/tag/wellpoint">wellpoint</category>
      <source url="http://breachblog.com/2008/04/09/wellpoint.aspx">WellPoint customer information exposed for a year</source>
    </item>
    <item>
      <title><![CDATA[Speaking of Security Podcast #89]]></title>
      <link>http://securityratty.com/article/6f05c34ab6acbfd91d6879df0497df2e</link>
      <guid>http://securityratty.com/article/6f05c34ab6acbfd91d6879df0497df2e</guid>
      <description><![CDATA[Click here to listen/download (09:40

Speaking of Security Blogger Shannon Kellogg talks with Matt Buckley about the state of information security from a Washington, D.C. point of...]]></description>
      <content:encoded><![CDATA[<a href="http://rsa.edgeboss.net/download/rsa/2008/blogpodcasts/080114_securitypodcast.mp3" target="_blank">Click here to listen/download</a> (09:40).<br><br>Speaking of Security Blogger <a href="http://www.rsa.com/blog/blog.aspx?author=kellogg">Shannon Kellogg</a> talks with Matt Buckley about the state of information security from a Washington, D.C. point of view. <br><br>]]></content:encoded>
      <pubDate>Sun, 13 Jan 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/matt buckley">matt buckley</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/click">click</category>
      <category domain="http://securityratty.com/tag/listendownload">listendownload</category>
      <category domain="http://securityratty.com/tag/view">view</category>
      <category domain="http://securityratty.com/tag/washington">washington</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1254">Speaking of Security Podcast #89</source>
    </item>
    <item>
      <title><![CDATA[Speaking of Security Podcast #69]]></title>
      <link>http://securityratty.com/article/7fc41e8385c9aa0098b0a186f3402ff7</link>
      <guid>http://securityratty.com/article/7fc41e8385c9aa0098b0a186f3402ff7</guid>
      <description><![CDATA[Click here to listen/download (10:55
Speaking of Security Blogger, Shannon Kellogg , interviews Hord Tipton, former CIO of the U.S. Department of Interior . Hord shares a bit about how he led the...]]></description>
      <content:encoded><![CDATA[<p><a href="https://www.rsa.com/blog/podcasts/070723_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (10:55).</p>

<p>Speaking of Security Blogger, <a href="http://www.rsa.com/blog/index.asp?author=kellogg">Shannon Kellogg</a>, interviews Hord Tipton, former <a href="http://www.doi.gov/ocio/security/index.html" target="_blank">CIO of the U.S. Department of Interior</a>. Hord shares a bit about how he led the reorganization and development the Department's IT infrastructure across eight major bureaus and how his focus moved more and more toward information security initiatives.</p>

 

]]></content:encoded>
      <pubDate>Mon, 23 Jul 2007 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/interviews hord tipton">interviews hord tipton</category>
      <category domain="http://securityratty.com/tag/information security initiatives">information security initiatives</category>
      <category domain="http://securityratty.com/tag/department">department</category>
      <category domain="http://securityratty.com/tag/focus moved">focus moved</category>
      <category domain="http://securityratty.com/tag/security blogger">security blogger</category>
      <category domain="http://securityratty.com/tag/major bureaus">major bureaus</category>
      <category domain="http://securityratty.com/tag/hord shares">hord shares</category>
      <category domain="http://securityratty.com/tag/shannon kellogg">shannon kellogg</category>
      <category domain="http://securityratty.com/tag/led">led</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1210">Speaking of Security Podcast #69</source>
    </item>
    <item>
      <title><![CDATA[Speaking of Security Podcast #62]]></title>
      <link>http://securityratty.com/article/682836a4b0faf883392537daa5f5fd04</link>
      <guid>http://securityratty.com/article/682836a4b0faf883392537daa5f5fd04</guid>
      <description><![CDATA[Click here to listen/download (10:21
Paul Joyal checks in with our man in Washington, blogger Shannon Kellogg , about the doings on the hill as well. EMC encourages all amateur movie-makers to enter...]]></description>
      <content:encoded><![CDATA[<p><a href="https://www.rsa.com/blog/podcasts/070514_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (10:21).</p><p>Paul Joyal checks in with our man in Washington, blogger <a href="http://www.rsa.com/blog/index.asp?author=kellogg">Shannon Kellogg</a>, about the doings on the hill as well. EMC encourages all amateur movie-makers to enter You-Tube-like shorts for <a href="http://www.emc.com/iva" target="_blank">Inforati Video Awards</a> (IVA) contest. The best entries in three categories will earn prizes (not to mention fame and bragging rights) for their creators, with the winners announced at <a href="http://www.emcworld2007.com/" target="_blank">EMC World</a> in Orlando May 21-24.</p>]]></content:encoded>
      <pubDate>Sun, 13 May 2007 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/paul joyal checks">paul joyal checks</category>
      <category domain="http://securityratty.com/tag/blogger shannon kellogg">blogger shannon kellogg</category>
      <category domain="http://securityratty.com/tag/enter you-tube-like shorts">enter you-tube-like shorts</category>
      <category domain="http://securityratty.com/tag/inforati video awards">inforati video awards</category>
      <category domain="http://securityratty.com/tag/emc world">emc world</category>
      <category domain="http://securityratty.com/tag/emc encourages">emc encourages</category>
      <category domain="http://securityratty.com/tag/amateur movie-makers">amateur movie-makers</category>
      <category domain="http://securityratty.com/tag/mention fame">mention fame</category>
      <category domain="http://securityratty.com/tag/orlando">orlando</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1187">Speaking of Security Podcast #62</source>
    </item>
    <item>
      <title><![CDATA[Speaking of Security Podcast #51]]></title>
      <link>http://securityratty.com/article/263552d0a735deb83bb4f344ad394487</link>
      <guid>http://securityratty.com/article/263552d0a735deb83bb4f344ad394487</guid>
      <description><![CDATA[Click here to listen/download (10:36

Recently at the industry-wide RSA Conference in San Francisco, Speaking of Security blogger, Shannon Kellogg , sat down with Ron Teixeira, Executive Director of...]]></description>
      <content:encoded><![CDATA[<p><a href="https://www.rsa.com/blog/podcasts/070226_SecurityPodcast.mp3" target="_blank">Click here to listen/download</a> (10:36).<br><br>Recently at the industry-wide <a href="http://www.rsaconference.com/2007/US/" target="_blank">RSA Conference</a> in San Francisco, Speaking of Security blogger, <a href="http://www.rsa.com/blog/index.asp?author=kellogg">Shannon Kellogg</a>, sat down with Ron Teixeira, Executive Director of the <a href="http://staysafeonline.org/practices/index.html" target="_blank">National Cyber Security Alliance</a>, to discuss that organization&#8217;s national information security awareness programs. We invite our listeners to learn more about this important initiative.<br></p>]]></content:encoded>
      <pubDate>Sun, 25 Feb 2007 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/industry-wide rsa conference">industry-wide rsa conference</category>
      <category domain="http://securityratty.com/tag/shannon kellogg">shannon kellogg</category>
      <category domain="http://securityratty.com/tag/security blogger">security blogger</category>
      <category domain="http://securityratty.com/tag/executive director">executive director</category>
      <category domain="http://securityratty.com/tag/san francisco">san francisco</category>
      <category domain="http://securityratty.com/tag/ron teixeira">ron teixeira</category>
      <category domain="http://securityratty.com/tag/discuss">discuss</category>
      <category domain="http://securityratty.com/tag/invite">invite</category>
      <category domain="http://securityratty.com/tag/recently">recently</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1171">Speaking of Security Podcast #51</source>
    </item>
  </channel>
</rss>
