<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: sounds]]></title>
    <link>http://securityratty.com/tag/sounds</link>
    <description></description>
    <pubDate>Mon, 11 Aug 2008 05:49:01 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Zango And The Batman Online Videogame]]></title>
      <link>http://securityratty.com/article/df88ab063f04def43d02f931dfa23c42</link>
      <guid>http://securityratty.com/article/df88ab063f04def43d02f931dfa23c42</guid>
      <description><![CDATA[This is Newsarama, a site (mostly) geared around comics and other related media





Click to Enlarge

You'll notice Batman, over on the right there. Let's take a closer look





Free Online Batman...]]></description>
      <content:encoded><![CDATA[
        This is Newsarama, a site (mostly) geared around comics and other related media:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/batzang1.html" onclick="window.open('http://blog.spywareguide.com/images/batzang1.html','popup','width=839,height=492,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/batzang1-thumb-339x198.jpg" alt="batzang1.jpg" class="mt-image-none" style="" height="198" width="339" /></a></span><br /> </div><div><div align="center">Click to Enlarge<br /></div><br />You'll notice Batman, over on the right there. Let's take a closer look:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="batzang2.gif" src="http://blog.spywareguide.com/images/batzang2.gif" class="mt-image-none" style="" height="266" width="316" /></span></div><br /></div><div><br />"Free Online Batman Game"? Well, that's curious because I follow comics pretty closely and I'd be the first to know if an "Online Batman Game" had been in the works (this advert has been doing the rounds on <a href="http://forums.superherohype.com/showthread.php?p=15406107">numerous</a> <a href="http://dcboards.warnerbros.com/web/message.jspa?messageID=2004718393#2004718393">comic-related</a> <a href="http://www.comicforum.de/showpost.php?s=543cba941aeb245f8174ec4943be2adc&amp;p=2733165&amp;postcount=29">websites</a>. Visit the URL in the ad - Batmangame.info - and you'll see this...<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/batzang3.html" onclick="window.open('http://blog.spywareguide.com/images/batzang3.html','popup','width=725,height=666,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/batzang3-thumb-325x298.gif" alt="batzang3.gif" class="mt-image-none" style="" height="298" width="325" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br />There it is again - "Online Batman Game". Furthermore, the text goes on to say:<br /><i><br />"Batman Online lets you do anything and every little thing you'd like in a Batman game. From leveling up your character to destroying villans, it has it all. Download and play this amazing game now, all for free! I'm sure you'll be playing for hours on end, it's that much fun.<br /><br />&nbsp;&nbsp;&nbsp; Level Up Your Character<br />&nbsp;<br />&nbsp;&nbsp; Explore a Huge Vast World<br />&nbsp;<br />&nbsp;&nbsp; Play Online With Your Friends<br />&nbsp;<br />&nbsp;&nbsp; Hundreds of Quests To Finish<br />&nbsp;<br />&nbsp;&nbsp; Perfect Battle System<br /><br />So start your Batman adventure today! Download the&nbsp; full game below and fight them all!"</i><br /><br />Note that they specifically call it "Batman Online". It specifically sounds like a text blurb you'd expect to see with a <a href="http://en.wikipedia.org/wiki/Massively_multiplayer_online_role-playing_game">MMORPG</a>. However, something isn't quite right here.<br /><br /><b>1)</b> The only DC licensed MMORPG anybody knows of is <a href="http://en.wikipedia.org/wiki/DC_Universe_%28video_game%29">this</a>, and it isn't due out until 2009. It's not Batman-centric, either.<br /><br /><b>2)</b> The screenshots are lifted from the <a href="http://en.wikipedia.org/wiki/Batman_Begins_%28video_game%29">Batman Begins videogame</a>, which came out in 2005. If you were offering a "Batman Online Game", wouldn't you use screenshots from that instead of an unrelated title?<br /><br /><b>3)</b> Absolutely no licensing, copyright or legal mumbo-jumbo on the page anywhere. DC and Warner Bros don't roll like that.<br /><br /><b>4)</b> The website - Batmangame(dot)info - is <a href="http://whois.domaintools.com/batmangame.info">registered anonymously</a>. Not exactly something you see everyday for websites related to licensed DC franchises such as Batman videogames.<br /><br /><b>5)</b> "To download and play the Batman Online Game you must download and install Zango as well. It is free, very easy to install and will give you access to the full game."<br /><br />Shall we continue?<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/batzang4.html" onclick="window.open('http://blog.spywareguide.com/images/batzang4.html','popup','width=757,height=638,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/batzang4-thumb-357x300.gif" alt="batzang4.gif" class="mt-image-none" style="" height="300" width="357" /></a></span><br />Click to Enlarge<br /></div><br />A Zango installer prompt, complete with picture of Batman at the top. If you say "No" to the install, you end up on Google.com. What happens if you click "Start"? Well, you'll get the <a href="http://blog.spywareguide.com/images/batzang5.gif">usual collection</a> of <a href="http://blog.spywareguide.com/images/batzang6.gif">Zango installer screens</a> including one that rather humorously has a guy in a superhero costume.<br /><br /></div><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="batzang7.gif" src="http://blog.spywareguide.com/images/batzang7.gif" class="mt-image-none" style="" height="333" width="419" /></span></div><div><br />Once everything is installed, you're taken to another page and from here things just get plain confusing. Remember, up to this point you've been promised an "Online Batman Game", the description of which is clearly intended to evoke images of a MMORPG. However....<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/batveng.html" onclick="window.open('http://blog.spywareguide.com/images/batveng.html','popup','width=841,height=623,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/batveng-thumb-341x252.jpg" alt="batveng.jpg" class="mt-image-none" style="" height="252" width="341" /></a></span><br />Click to Enlarge<br /></div><br />All of a sudden, you're being told you're downloading "Batman: Vengeance" on a cheap-looking splash page and shown what looks like an unofficially ripped <a href="http://www.youtube.com/watch?v=D1WqzbNB8tM&amp;eurl=http://www.batmangame.info/setup.exe">Batman: Vengeance trailer</a> on Youtube.<br /><br />In case you're unaware, Batman: Vengeance is a videogame <a href="http://en.wikipedia.org/wiki/Batman_Vengeance">first launched way back in 2001</a> for consoles (followed shortly after by a PC version). What does this have to do with an "Online Batman Game"? Well, nothing, actually. Aside from the fact you were presented with one thing and are now handed another, things get even stranger when you see the download location:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/batzang00.html" onclick="window.open('http://blog.spywareguide.com/images/batzang00.html','popup','width=542,height=281,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/batzang00-thumb-342x177.gif" alt="batzang00.gif" class="mt-image-none" style="" height="177" width="342" /></a></span><br /></div></div><div><div align="center">Click to Enlarge<br /></div><br />Have you ever heard of an officially licensed game being offered via Rapidshare downloads? It's possible, I guess, but it seems a little odd. However, the <i>real</i> oddness is reserved for the "Online Batman game" itself.<br /><br />Remember, we've been promised "Hundreds of quests", "A huge vast world", the ability to "level up your character" and (of course) the "play online with your friends" promise of greatness.<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/batinstall.html" onclick="window.open('http://blog.spywareguide.com/images/batinstall.html','popup','width=811,height=549,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/batinstall-thumb-311x210.gif" alt="batinstall.gif" class="mt-image-none" style="" height="210" width="311" /></a></span><br />Click to Enlarge<br /></div><br />Imagine your dismay, then, when you've installed Zango, downloaded the game from Rapidshare using up around 140MB of bandwidth, installed it and....<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="batdemo.gif" src="http://blog.spywareguide.com/images/batdemo.gif" class="mt-image-none" style="" height="288" width="451" /></span></div><br />Oh dear.<br /><br />Not only are you given a totally different game than what was advertised, you're given a DEMO VERSION of that game with <a href="http://blog.spywareguide.com/images/menu.gif">four short sample levels</a> present, no online functionality and quite a few less quests than the "hundreds" advertised.<br /><br />Hilariously, you can download a 100% legit copy of this demo <a href="http://www.fileplanet.com/110885/110000/fileinfo/Batman-Vengeance-Demo">here at Fileplanet</a>, sans Adware. Setting aside the issue of whether this file is actually sitting on Rapidshare with either Ubisoft or DC / Warner Bros permission (and if it IS okay to be there, I'm pretty sure it's NOT okay to falsely advertise it as some kind of MMORPG) there are some questions that need to be raised here.<br /><br />When this guy approached them with his website, did nobody stop to think that this game did not actually match up with the "Online Batman" game it was touted as? Didn't someone at Zango Quality Control actually download the game and see the big "This is a demo" wording as soon as it starts up? Or question why the <a href="http://blog.spywareguide.com/images/begins1.gif">screenshots</a> on the website don't look like the graphics for <a href="http://blog.spywareguide.com/images/batveng1.gif">Batman: Vengeance</a> in the slightest?<br /><br />However you look at it, this is a scam, pure and simple. Whoever came up with the idea of an "Online Batman Game" is lying through their teeth. Of course, because their website is registered anonymously we have no idea who the culprit is, unless of course Zango want to deposit them on the steps of Gotham City and let me dispense some Batman-style justice to their posterior.<br /><br />However, based on the way these things tend to go - God forbid anyone ever offer up the identity of someone happily scamming the public at large, even when that person is dragging the name of the company associated with them through the mud by their antics - I think I might be waiting some time for the Bat Signal...<br /></div>
        
    ]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 07:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/batman">batman</category>
      <category domain="http://securityratty.com/tag/batman online">batman online</category>
      <category domain="http://securityratty.com/tag/batman game">batman game</category>
      <category domain="http://securityratty.com/tag/online batman game">online batman game</category>
      <category domain="http://securityratty.com/tag/batman online game">batman online game</category>
      <category domain="http://securityratty.com/tag/batman adventure">batman adventure</category>
      <category domain="http://securityratty.com/tag/batman begins videogame">batman begins videogame</category>
      <category domain="http://securityratty.com/tag/batman-centric">batman-centric</category>
      <category domain="http://securityratty.com/tag/batman-style justice">batman-style justice</category>
      <source url="http://blog.spywareguide.com/2008/09/zango-and-the-batman-online-vi.html">Zango And The Batman Online Videogame</source>
    </item>
    <item>
      <title><![CDATA[Leave Your Webcam On 24/7? Might Want To Reconsider...]]></title>
      <link>http://securityratty.com/article/4d1de8afa43b141ff7ed90cd99cc3cb3</link>
      <guid>http://securityratty.com/article/4d1de8afa43b141ff7ed90cd99cc3cb3</guid>
      <description><![CDATA[It's nothing new that many hackers use programs that allow them to &quot;spy&quot; on their victims once they've compromised the PC (as long as they have a webcam switched on, of course). Similarly, hacking...]]></description>
      <content:encoded><![CDATA[
        It's nothing new that many hackers use programs that allow them to "spy" on their victims once they've compromised the PC (as long as they have a webcam switched on, of course). Similarly, hacking culture has always had a fascination for memes, <a href="http://blog.spywareguide.com/2008/05/memehacks_1.html">incorporating them</a> into part of the design of their latest DDoS tools.<br /><br />However, the strange obsession with <a href="http://en.wikipedia.org/wiki/Shock_sites">shock memes</a> has now spilled into a "fun" game currently doing the rounds on various hacking sites and forums.<br /><br />What this involves is hackers compromising a PC, ensuring the victim has a webcam switched on then opening up shock meme websites at the most inopportune moment, recording the moment of impact with the webcam feed. Or, as one guy put it:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="spinny1.jpg" src="http://blog.spywareguide.com/images/spinny1.jpg" class="mt-image-none" style="" height="86" width="451" /></span></div><br /><br />If you don't know what Meatspin is, you can probably count yourself lucky. If you still want to know, click <a href="http://answers.yahoo.com/question/index?qid=20060710001351AAMxYqY">here</a> (for an <i>explanation</i>. Not Meatspin itself, though the explanation might be classed NSFW anyway).<br /><br />Here's a real life example of one such incident, taken from a message board:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/spinny2.html" onclick="window.open('http://blog.spywareguide.com/images/spinny2.html','popup','width=929,height=192,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/spinny2-thumb-329x67.gif" alt="spinny2.gif" class="mt-image-none" style="" height="67" width="329" /></a></span><br />Click to Enlarge<br /></div><br />Typically, the shock meme website is opened up at full blast, which startles the victim (most sites of this nature loop a piece of music in the background while the, er, action takes place on screen). The bigger the shock, the better. Here's one guy who sounds like he shot about six feet in the air when the meme site fired up in his browser:<br /><br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/spinny3.html" onclick="window.open('http://blog.spywareguide.com/images/spinny3.html','popup','width=636,height=108,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/spinny3-thumb-336x57.jpg" alt="spinny3.jpg" class="mt-image-none" style="" height="57" width="336" /></a></span><br />Click to Enlarge<br /></div><br />This might all sound like fun and games - <i>sort of</i> - but note that the above individual did try to grab the victims credit card details. <br /><br />Generally, the attacker doesn't interact with the victim (because they want friends, relatives or others to think the victim actually brought the site up themselves) but here's a little trash talk anyway:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="spinny4.jpg" src="http://blog.spywareguide.com/images/spinny4.jpg" class="mt-image-none" style="" height="188" width="245" /></span></div><br /><br />At this point, the attacker may or may not grab a screenshot for posterity. I've seen quite a few galleries on sites comprised of people looking shocked at Tubgirl, or being spun round baby right round by Meatspin, and there's no doubt countless others out there floating around. Of course, not everybody is shocked (or indeed impressed) by a shockmeme site popping up on their computer. As an example of that, take this guy:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="spinny5.jpg" src="http://blog.spywareguide.com/images/spinny5.jpg" class="mt-image-none" style="" height="342" width="334" /></span></div><br /><br />Full credit to anyone that counters a shockmeme site appearing on their desktop by picking their nose for five minutes. At any rate, the golden rule with this is that the hackers only bother doing this when a webcam is present and left switched on. If there's no webcam, there's no point trying to elicit a response (because for all they know they're popping open 2 Girls and 1 Cup to an empty server room).<br /><br />Webcams can be a fun tool, but remember to switch them off every now and again or they could come back to haunt you. Of course, depending on the shock meme site deployed (and who happens to be in the room with you at the time), that could be the least of your worries...<br /><div><br /></div><div><br /></div>
        
    ]]></content:encoded>
      <pubDate>Mon, 01 Sep 2008 11:46:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/shockmeme site">shockmeme site</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/meme site fired">meme site fired</category>
      <category domain="http://securityratty.com/tag/shock">shock</category>
      <category domain="http://securityratty.com/tag/shock meme websites">shock meme websites</category>
      <category domain="http://securityratty.com/tag/webcam">webcam</category>
      <category domain="http://securityratty.com/tag/shock meme site">shock meme site</category>
      <category domain="http://securityratty.com/tag/shock meme website">shock meme website</category>
      <category domain="http://securityratty.com/tag/webcam feed">webcam feed</category>
      <source url="http://blog.spywareguide.com/2008/09/leave-your-webcam-on-247-might.html">Leave Your Webcam On 24/7? Might Want To Reconsider...</source>
    </item>
    <item>
      <title><![CDATA[Erase Your Hard Drives Before Selling Them]]></title>
      <link>http://securityratty.com/article/1863838def4b467b54e51c1ef762ffdf</link>
      <guid>http://securityratty.com/article/1863838def4b467b54e51c1ef762ffdf</guid>
      <description><![CDATA[Sounds like a no-brainer, but its a lesson that some large companies still have to learn
IT manager Andrew Chapman purchased a used drive on eBay, for just 77 British pounds, only to find that it...]]></description>
      <content:encoded><![CDATA[<p>Sounds like a no-brainer, but it&#8217;s a lesson that some large companies still have to learn.</p>
<p><span style="font-size:x-small;">IT manager Andrew Chapman purchased a used drive on eBay, for just 77 British pounds, only to find that it contained the financial history and information for several million people, customers of the </span><span style="font-size:x-small;">Royal Bank of Scotland (RBS) and its subsidiary, Natwest. Luckily for them, Chapman had their best interests at heart and reported the problem, rather than selling or using the information.</span></p>
<p>According to Evan at the Breach Blog:</p>
<blockquote><p><span style="font-size:x-small;"><span style="font-style:italic;"> The University of Glamorgan conducted research about hard drives bought on eBay that contained sensitive information and </span><a rel="nofollow" style="font-style:italic;" target="_blank" href="http://breachblog.com/2007/09/13/university-of-glamorgan-discovers-data-on-discarded-drives.aspx">published</a><span style="font-style:italic;"> their findings in September 2007. If people don&#8217;t think that criminals are buying hard drives on eBay, searching for sensitive information (personal information, health information, corporate secrets, intellectual property, etc.), then they are deluded</span></span></p></blockquote>
<p>Click here to read the<a rel="nofollow" target="_blank" href="http://breachblog.com/2008/08/27/ebay.aspx"> full article.</a></p>]]></content:encoded>
      <pubDate>Wed, 27 Aug 2008 06:48:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/health information">health information</category>
      <category domain="http://securityratty.com/tag/sensitive information">sensitive information</category>
      <category domain="http://securityratty.com/tag/chapman">chapman</category>
      <category domain="http://securityratty.com/tag/manager andrew chapman">manager andrew chapman</category>
      <category domain="http://securityratty.com/tag/hard">hard</category>
      <category domain="http://securityratty.com/tag/ebay">ebay</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/376404913/">Erase Your Hard Drives Before Selling Them</source>
    </item>
    <item>
      <title><![CDATA[New Releases at Defcon]]></title>
      <link>http://securityratty.com/article/6b70bb54d788a022a4d23f955e0fc8cc</link>
      <guid>http://securityratty.com/article/6b70bb54d788a022a4d23f955e0fc8cc</guid>
      <description><![CDATA[One of my funny moments at Black Rock City last year was meeting a random guy early one morning on deep playa, chatting and finding out we both were involved in IT security. Hed been at the defcon...]]></description>
      <content:encoded><![CDATA[<p>One of my funny moments at Black Rock City last year was meeting a random guy early one morning on deep playa, chatting and finding out we both were involved in IT security. He&#8217;d been at the defcon conference just before Burning Man, we talked for just a minute about industry publications and the hacker contests, before getting distracted with shinier things. I&#8217;m not going this year but everyone I know is buzzing about BM this year:)</p>
<p>I was just reminded of this randomly just by reading this list of new tools released at the Defcon this year. Sounds like a busy conference, with a lot of hackers who love what they do. Good stuff.</p>
<blockquote><p>It has become more like a global fair than what most people think of conferences; even the badge is highly unique. I say this because there are so many things to do at DEFCON, other than going to talks, that you could spend your whole weekend looking at the &#8220;World&#8217;s Largest Boar!&#8221; so to speak. One of the CTF (Capture the Flag) contest winners this year actually exclaimed that he only made it to 2 talks in 12 years! I am also one of those individuals who barely get a chance to go to talks and now that the speaker pool is so diverse it&#8217;s hard to find all of the &#8220;stuff&#8221; they release.</p></blockquote>
<p>Read the <a rel="nofollow" target="_blank" href="http://www.room362.com/archives/217-DEFCON-16-The-Tools-not-the-Toools.html">list and full article</a> here</p>]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 09:04:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/defcon">defcon</category>
      <category domain="http://securityratty.com/tag/defcon conference">defcon conference</category>
      <category domain="http://securityratty.com/tag/talks">talks</category>
      <category domain="http://securityratty.com/tag/black rock city">black rock city</category>
      <category domain="http://securityratty.com/tag/busy conference">busy conference</category>
      <category domain="http://securityratty.com/tag/industry publications">industry publications</category>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/funny moments">funny moments</category>
      <category domain="http://securityratty.com/tag/random guy">random guy</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/369359734/">New Releases at Defcon</source>
    </item>
    <item>
      <title><![CDATA[Will Passwords Become Obsolete?]]></title>
      <link>http://securityratty.com/article/f7dd714962f1e8f812f0f43645c379ba</link>
      <guid>http://securityratty.com/article/f7dd714962f1e8f812f0f43645c379ba</guid>
      <description><![CDATA[I cant keep track of how many different passwords I have, although I know its not nearly enough I tend to be lazy like most people and re-use the same passwords for many different accounts
But heres a...]]></description>
      <content:encoded><![CDATA[<p>I can&#8217;t keep track of how many different passwords I have, although I know it&#8217;s not nearly enough &#8212; I tend to be lazy like most people and re-use the same passwords for many different accounts.<br />
But here&#8217;s a new idea &#8212; what if passwords for online accounts were replaced entirely by cryptographic keys that sat on our desktops like icons, and functioned in the background, so we wouldn&#8217;t need to remember a string of letters or numbers?</p>
<p>An interesting <a rel="nofollow" target="_blank" href="http://www.novainfosecportal.com/2008/08/14/bye-bye-passwords-maybe/">blog post </a>this morning discusses the obstacles and implications of this kind of technology, in part quoting a recent New York Times article &#8212; </p>
<blockquote><p>
In short, we need a log-on system that relies on cryptography, not mnemonics. As users, we would replace passwords with so-called information cards, icons on our screen that we select with a click to log on to a Web site. The click starts a handshake between machines that relies on hard-to-crack cryptographic code.</p></blockquote>
<p>An obstacle to this kind of system are the current initiatives toward Open ID and single-sign on services, strategies that are backed by large industry players such as the Equifax, Google, Novell, Microsoft, Oracle, etc. In the open ID system, you would log in to a session on the web with one password, which would be accepted by any application/account supporting the open ID infrastructure. </p>
<p>To me Open ID sounds like a step backwards, toward less security&#8230;<br />
then again, I would think that encrypting everything could also make your system run significantly slower, and that it wouldn&#8217;t prevent all the risks either&#8230;</p>]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 09:46:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/passwords">passwords</category>
      <category domain="http://securityratty.com/tag/log-on system">log-on system</category>
      <category domain="http://securityratty.com/tag/log">log</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/replace passwords">replace passwords</category>
      <category domain="http://securityratty.com/tag/web site">web site</category>
      <category domain="http://securityratty.com/tag/click starts">click starts</category>
      <category domain="http://securityratty.com/tag/york times article">york times article</category>
      <category domain="http://securityratty.com/tag/online accounts">online accounts</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/366003641/">Will Passwords Become Obsolete?</source>
    </item>
    <item>
      <title><![CDATA[UK Police Seize War on Terror Board Game]]></title>
      <link>http://securityratty.com/article/3f568c502112697df18ef85b916ccd1c</link>
      <guid>http://securityratty.com/article/3f568c502112697df18ef85b916ccd1c</guid>
      <description><![CDATA[They said -- and it's almost to stupid to believe -- that: the balaclava &quot;could be used to conceal someone's identity or could be used in the course of a criminal act
Don't they realize that...]]></description>
      <content:encoded><![CDATA[<p>They <a href="http://www.cambridge-news.co.uk/cn%5Fnews%5Fhome/DisplayArticle.asp?ID=338658">said</a> -- and it's almost to stupid to believe -- that:</p>

<blockquote>the balaclava "could be used to conceal someone's identity or could be used in the course of a criminal act".</blockquote>

<p>Don't they realize that balaclavas are <a href="http://www.google.com/search?hl=en&client=opera&rls=en&hs=OZD&q=balaclava+sale+UK&btnG=Search">for sale</a> everywhere in the UK?  Or that scarves, hoods, handkerchiefs, and dark glasses could also be used to conceal someone's identity?</p>

<p>The game sounds like it could be fun, though:</p>

<blockquote>Each player starts as an empire filled with good intentions and a determination to liberate the world from terrorists and from each other.

<p>Then the reality of world politics kicks and terrorist states emerge.</p>

<p>Andrew said: "The terrorists can win and quite often do and it's global anarchy. It sums up the randomness of geo-politics pretty well."</p>

<p>In their cardboard version of realpolitik George Bush's "Axis of Evil" is reduced to a spinner in the middle of the board, which determines which player is designated a terrorist state.</p>

<p>That person then has to wear a balaclava (included in the box set) with the word "Evil" stitched on to it.</blockquote></p>

<p>Buy yours <a href="http://www.waronterrortheboardgame.com/">here</a>; I first <a href="http://www.schneier.com/blog/archives/2006/12/war_on_terror_t.html">blogged about it</a> in 2006.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=gzxk4K"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=gzxk4K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=fQtAMK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=fQtAMK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 02:50:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/world">world</category>
      <category domain="http://securityratty.com/tag/world politics kicks">world politics kicks</category>
      <category domain="http://securityratty.com/tag/realpolitik george bush">realpolitik george bush</category>
      <category domain="http://securityratty.com/tag/player starts">player starts</category>
      <category domain="http://securityratty.com/tag/player">player</category>
      <category domain="http://securityratty.com/tag/geo-politics pretty">geo-politics pretty</category>
      <category domain="http://securityratty.com/tag/conceal">conceal</category>
      <category domain="http://securityratty.com/tag/game sounds">game sounds</category>
      <category domain="http://securityratty.com/tag/cardboard version">cardboard version</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/uk_police_seize.html">UK Police Seize War on Terror Board Game</source>
    </item>
    <item>
      <title><![CDATA[Fog of the Future: Cloud Computings on the Horizon]]></title>
      <link>http://securityratty.com/article/b0444080036cffd2f313acaf1bcf9b99</link>
      <guid>http://securityratty.com/article/b0444080036cffd2f313acaf1bcf9b99</guid>
      <description><![CDATA[If you trust the media and are looking to the future, you might be thinking a good deal about Cloud Computing according to ComputerWorld, this could be the next big movement
Ive heard the buzzwords...]]></description>
      <content:encoded><![CDATA[<p>If you trust the media and are looking to the future, you might be thinking a good deal about <a rel="nofollow" target="_blank" href="http://blogs.computerworld.com/forecast_calls_for_clouds_are_we_ready">Cloud Computing</a> &#8212; according to ComputerWorld, this could be the next big movement.</p>
<p>I&#8217;ve heard the buzzwords but wasn&#8217;t exactly sure what they meant&#8211;luckily, when there&#8217;s media hype, there are definitions, too. According to <a rel="nofollow" target="_blank" href="http://www.thestandard.com/news/2008/08/04/quicker-path-clouds">this article</a>, cloud computing is exemplified by Software as a Service &#8212; outsourced, hosted platforms and software that perform services for companies. </p>
<p>Another <a rel="nofollow" target="_blank" href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&#038;articleId=9111689">article </a>puts it slightly differently:</p>
<blockquote><p>OK, let us look at what form of computing in being provided via the cloud. In this model, all IT applications and facilities (i.e. compute, storage and network) are provided as a service rather than dedicated infrastructure. This is intended to allow any user, independent of client platform, to access IT services without knowledge or concern of their location or form. Sound familiar &#8212; it&#8217;s a service-oriented architecture (SOA)!</p>
<p>In addition, cloud computing incorporates almost every computing manifestation within the IT world: distributed, grid, utility, on-demand, open-source, Web services, P2P, Web 2.0 and, last but not least, software as a service.</p>
<p>It also accommodates thin, thick and mobile clients and allows integration of corporate, commercial and service provider cloud-accessed resources. As an example, in this model, storage is a service resource that is accessed via the cloud, not a dedicated user resource.</p></blockquote>
<p>Honestly I read that last one first and found the definition a bit dense. It sounds like a summation of everything that makes up our Internet infrastructure already, so how is that different than the Internet itself? Well, cloud computing isn&#8217;t about what service or devices are being supported &#8212; it&#8217;s more about how it&#8217;s being provided&#8211; it is a location-independent style of computing. The first article calls it &#8220;platform as a service.&#8221;</p>
<p>Have you heard better definitions of what cloud computing is and does? Share them in the comments below. Thanks!</p>]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 08:56:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/service provider">service provider</category>
      <category domain="http://securityratty.com/tag/service resource">service resource</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/perform services">perform services</category>
      <category domain="http://securityratty.com/tag/web services">web services</category>
      <category domain="http://securityratty.com/tag/internet infrastructure">internet infrastructure</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/365101308/">Fog of the Future: Cloud Computings on the Horizon</source>
    </item>
    <item>
      <title><![CDATA[Trust No One?]]></title>
      <link>http://securityratty.com/article/cbe272a22113c011f34b6644f8b4ea09</link>
      <guid>http://securityratty.com/article/cbe272a22113c011f34b6644f8b4ea09</guid>
      <description><![CDATA[Sorry to go all X-Files on you, but I received an EMail earlier today that really drives home how paranoid we probably all are about Phishing nowadays

Entitled &quot;Chris Boyd, would you be able to spot...]]></description>
      <content:encoded><![CDATA[
        Sorry to go all X-Files on you, but I received an EMail earlier today that really drives home how paranoid we probably all are about Phishing nowadays.<br /><br />Entitled "Chris Boyd, would you be able to spot a fake email?", it was apparently from Paypal:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="fakeornot1.jpg" src="http://blog.spywareguide.com/images/fakeornot1.jpg" class="mt-image-none" style="" height="468" width="437" /></span><br /> <div><br /><i>"Protect yourself from phishing: Paypal is working with Gmail and Yahoo! to block fake Paypal emails from your inbox. Learn how".</i><br /><br />As it turns out, the email <i>was</i> legitimate - but as soon as I hear someone asking me "Can you spot a fake Email", my brain is sadly conditioned to assume the mail asking me that question is <i>fake too</i>.<br /><br />Kind of depressing, isn't it? At any rate, it's interesting how certain words / phrases in mails will automatically set alarm bells ringing. If I'd received <a href="http://anti-virus-rants.blogspot.com/2008/08/is-sympatico-training-their-users-to-be.html">this email</a>, I'd have deleted it as soon as I saw the phrase "Your download to win contest has arrived".<br /><br /><i>Download to Win Contest</i>?? That sounds so very, very wrong, doesn't it?<br /></div>
        
    ]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 10:46:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake email">fake email</category>
      <category domain="http://securityratty.com/tag/fake">fake</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/set alarm bells">set alarm bells</category>
      <category domain="http://securityratty.com/tag/paypal">paypal</category>
      <category domain="http://securityratty.com/tag/win">win</category>
      <category domain="http://securityratty.com/tag/chris boyd">chris boyd</category>
      <category domain="http://securityratty.com/tag/spot">spot</category>
      <category domain="http://securityratty.com/tag/download">download</category>
      <source url="http://blog.spywareguide.com/2008/08/trust-no-one.html">Trust No One?</source>
    </item>
    <item>
      <title><![CDATA[Twelve billion dollars!]]></title>
      <link>http://securityratty.com/article/a29d689a1e0dae9d7152dedb093cf36b</link>
      <guid>http://securityratty.com/article/a29d689a1e0dae9d7152dedb093cf36b</guid>
      <description><![CDATA[Sounds like a Dr. Evil sound bite :). In fact this could be the potential impact of the 41 million cards stolen - according to security company Jefferson Wells . The amount is a result of simple...]]></description>
      <content:encoded><![CDATA[Sounds like a Dr. Evil sound bite :). In fact this could be the <a href="http://www.networkworld.com/news/2008/080708-tjx-data-breach-ignore-cost.html">potential impact</a> of the 41 million cards stolen - according to security company <a href="http://www.jeffersonwells.com/">Jefferson Wells</a>. The amount is a result of simple multiplication - 41 million x $300 for each card lost. On the higher end, no doubt.<br /><br />While I don't think the real cost is anywhere close to that (even by an order of magnitude), it is still a large number. Even at street price of $2 per card, someone must be making 41 million x $2 = $82M!<br /><br />More scary to imagine, is where this stolen data is going, what kind of money they are making and what illegal stuff is being done with it.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BitArmor1?a=k6HlgK"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=k6HlgK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=04MlBk"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=04MlBk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=mge6hK"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=mge6hK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BitArmor1/~4/363980306" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 10:37:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/million">million</category>
      <category domain="http://securityratty.com/tag/million cards">million cards</category>
      <category domain="http://securityratty.com/tag/security company jefferson">security company jefferson</category>
      <category domain="http://securityratty.com/tag/card lost">card lost</category>
      <category domain="http://securityratty.com/tag/card">card</category>
      <category domain="http://securityratty.com/tag/street price">street price</category>
      <category domain="http://securityratty.com/tag/simple multiplication">simple multiplication</category>
      <category domain="http://securityratty.com/tag/illegal stuff">illegal stuff</category>
      <category domain="http://securityratty.com/tag/evil sound">evil sound</category>
      <source url="http://feeds.feedburner.com/~r/BitArmor1/~3/363980306/twelve-billion-dollars.html">Twelve billion dollars!</source>
    </item>
    <item>
      <title><![CDATA[Wee-Fi: iPhone Penetration, Hotspots Undercounted, Warballoon, Cincy Bus-Fi]]></title>
      <link>http://securityratty.com/article/e40f33339b59735e12dc94589ccb5479</link>
      <guid>http://securityratty.com/article/e40f33339b59735e12dc94589ccb5479</guid>
      <description><![CDATA[iPhone sleeper cell: Security researchers demonstrated the use of an iPhone with an external battery pack as a method of sniffing networks from a mailroom, to find information that a business might...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/lock.jpg" align="right" border="0" hspace="5" /><a href="http://www.tgdaily.com/content/view/38814/108/"><strong>iPhone sleeper cell:</strong></a> Security researchers demonstrated the use of an iPhone with an external battery pack as a method of sniffing networks from a mailroom, to find information that a business might not feel that it has to secure in the heart of its operations. Errata Security performed distant penetration testing for a client in this way, and found most of their wireless networks unprotected. This is sort of absurd, and I'll be curious what Errata posts on their own site about this project--the scope sounds wrong in the reporting on their talk--because every firm of any scale has some kind of encryption on their internal networks. If they don't, you have concerns at a much higher level than penetration testing. </p>

<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://www.pcworld.com/article/149620/2008/08/.html?tk=rss_news"><strong>Four chains, four Wi-Fi pay policies:</strong></a> CIO magazine looks at Borders, McDonald's, Panera, and Starbucks, and how they're offering Wi-Fi. I'd like to suggest you read this article, but the author writes, "Right now, according to <a href="http://www.hotspot-locations.com/"><strong>Hotspot Locations</strong></a>, there are more than 33,000 WLAN hotspots worldwide, and more than 10,000 in the United States alone." I don't know who "Hotspot Locations" is, and I need to disclose that I have a financial interest in what must be their competitor, JiWire, but any hotspot finder that calls them "WLAN Hotspots" and reports 11,712 in the U.S. and 33,106 worldwide just isn't working very hard. JiWire <a href="http://www.jiwire.com/search-hotspot-locations.htm"><strong>lists over 230,000 hotspots worldwide</strong></a>, and notes over 60,000 in the U.S., while <a href="http://boingo.com/what-is-boingo.php?btn_learn_more="><strong>Boingo</strong></a> and <a href="https://www.ipassconnect.com/main"><strong>iPass</strong></a> each resell access to over 100,000 hotspots worldwide.<br />
 <br />
<a href="http://www.networkworld.com/news/2008/081008-covert-operation-floats-network-sniffing.html?hpg1=bn"><strong>Up, up, and away in my beautiful, my beautiful warballoon:</strong></a> Defcon hackers deployed a balloon with Wi-Fi receivers on it 150 feet in the air to scan for network vulnerabilities in Las Vegas last week. They found 1/3rd of networks had no encryption--although I always wonder if they're using passive scanning where 802.1X allows a limited connection for authentication and appears "open" in some ways, or if they were actively scanning, in which case 802.1X networks would be unavailable.</p>

<p><a href="http://news.cincinnati.com/apps/pbcs.dll/article?AID=/20080809/NEWS01/808090335"><strong>Cincinnati Metro service has Wi-Fi on 20 buses:</strong></a> The free service supplied by AT&T in an ads-for-access deal with the authority was placed after a couple years of testing on a relatively long commuter run. The authority spends $15,000 per bus to setup a connection, which seems rather pricey. Other authorities are paying in the low thousands, from what I've seen, so I'm not sure what their particular case is.</p>]]></content:encoded>
      <pubDate>Mon, 11 Aug 2008 05:49:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wlan hotspots worldwide">wlan hotspots worldwide</category>
      <category domain="http://securityratty.com/tag/wlan hotspots">wlan hotspots</category>
      <category domain="http://securityratty.com/tag/hotspots worldwide">hotspots worldwide</category>
      <category domain="http://securityratty.com/tag/worldwide">worldwide</category>
      <category domain="http://securityratty.com/tag/iphone">iphone</category>
      <category domain="http://securityratty.com/tag/wireless networks">wireless networks</category>
      <category domain="http://securityratty.com/tag/networks">networks</category>
      <category domain="http://securityratty.com/tag/penetration">penetration</category>
      <category domain="http://securityratty.com/tag/internal networks">internal networks</category>
      <source url="http://wifinetnews.com/archives/008416.html">Wee-Fi: iPhone Penetration, Hotspots Undercounted, Warballoon, Cincy Bus-Fi</source>
    </item>
  </channel>
</rss>
