<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: suppose]]></title>
    <link>http://securityratty.com/tag/suppose</link>
    <description></description>
    <pubDate>Thu, 10 Jul 2008 20:00:20 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Its hard work protecting your personal data.]]></title>
      <link>http://securityratty.com/article/4692e1a5bcc675a8e1bff9e77387066d</link>
      <guid>http://securityratty.com/article/4692e1a5bcc675a8e1bff9e77387066d</guid>
      <description><![CDATA[Did you fill out the Opt Out form? Did you make a copy? Do you know if they honored it? Can you hold them responsible if they lose or sell your data? Its not just about them selling a product and you...]]></description>
      <content:encoded><![CDATA[<div > Did you fill out the Opt Out form?<br/>Did you make a copy? Do you know if they honored it?<br/>Can you hold them responsible if they &#8220;lose&#8221; or sell your data?<br/>Its not just about them selling a product and you buying it anymore.<br/>Its about how much profit they can glean from that purchase. You dont even have to buy anything! They still get to use your data and not pay you for it. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/0EED012F-115D-4894-82AF-E07D270FEB80/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/97e18058-e484-47cb-9860-19c1c78ec1c5/0EED012F-115D-4894-82AF-E07D270FEB80/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.internetevolution.com/author.asp?doc_id=164855&#038;f_src=ieupdate" href="http://www.internetevolution.com/author.asp?doc_id=164855&#038;f_src=ieupdate" style="font-size: 11px;">www.internetevolution.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.internetevolution.com/author.asp?doc_id=164855&#038;f_src=ieupdate --><DIV><SPAN class="gray header biggest"><A href="http://www.internetevolution.com/author.asp?section_id=561&#038;doc_id=164855&#038;">Don&#8217;t Tap My Phone, Don&#8217;t Tap My Internet</A></SPAN></DIV></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.internetevolution.com/author.asp?doc_id=164855&#038;f_src=ieupdate --><P><br />
Let&#8217;s make this really simple: You have a phone, and I want to tap it without your knowledge to find out what your buying habits are and sell the information to advertisers. That&#8217;s not legal, period.<br />
</P></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.internetevolution.com/author.asp?doc_id=164855&#038;f_src=ieupdate --><P><br />
Suppose you say, &#8220;OK, you can tap my phone.&#8221; You &#8220;opt in.&#8221;  Does that make it legal?<br />
</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/0EED012F-115D-4894-82AF-E07D270FEB80/blog/" title="blog or email this clip"><img src="http://content7.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_011008030555"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=011008030555&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=011008030555&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=011008030555&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_011008030555" /></a></P>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 11:05:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tap">tap</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/phone">phone</category>
      <category domain="http://securityratty.com/tag/opt">opt</category>
      <category domain="http://securityratty.com/tag/legal">legal</category>
      <category domain="http://securityratty.com/tag/habits">habits</category>
      <category domain="http://securityratty.com/tag/anymore">anymore</category>
      <category domain="http://securityratty.com/tag/advertisers">advertisers</category>
      <category domain="http://securityratty.com/tag/form">form</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=634">Its hard work protecting your personal data.</source>
    </item>
    <item>
      <title><![CDATA[Root of Trust ?]]></title>
      <link>http://securityratty.com/article/a65dcd69a47316de0df44497406963f0</link>
      <guid>http://securityratty.com/article/a65dcd69a47316de0df44497406963f0</guid>
      <description><![CDATA[Ive given some talks this year about the Internets insecure infrastructure stressing that fundamental protocols such as BGP and DNS cannot really be trusted at the moment. Although they work just fine...]]></description>
      <content:encoded><![CDATA[<p>I&#8217;ve given <a href="http://www.cl.cam.ac.uk/~rnc1/talks/080211-mailserver.pdf">some</a> <a href="http://www.cl.cam.ac.uk/~rnc1/talks/080915-ISPsecurity.pdf">talks</a> this year about the Internet&#8217;s insecure infrastructure &#8212; stressing that fundamental protocols such as <a href="http://www.bgp4.as/">BGP</a> and <a href="http://oreilly.com/catalog/9780596100575/">DNS</a> cannot really be trusted at the moment. Although they work just fine most of the time, they are susceptible to attacks which can mean, for example, that you visit the wrong website, or your email is intercepted.</p>
<p>Steps are now being taken, <a href="http://voices.washingtonpost.com/securityfix/2008/08/dns_security_mandatory_for_all.html">rather faster</a> since Dan Kaminsky came up with a <a href="http://www.doxpara.com/?p=1185">really effective DNS poisoning attack</a>, to secure DNS by using <a href="http://www.dnssec.net/">DNSSEC</a>.</p>
<p>The basic idea of DNSSEC is that when you get an answer from the DNS it will be signed by someone you trust. At some point the &#8220;trust anchor&#8221; for the system will be &#8220;.&#8221; the DNS root, but for the moment there&#8217;s <a href="http://www.unbound.net/documentation/howto_anchor.html">just a handful of &#8220;trust anchors&#8221; one level down</a> from that. One such anchor is the &#8220;.se&#8221; country code domain for Sweden. Additionally, Brazil (.br), Puerto Rico (.pr), and Bulgaria (.bg) have signed their zones, but that&#8217;s about it for today.</p>
<p>So, wishing to get some experience with the <a href="http://www.sparknotes.com/lit/bravenew/">brave new world</a> of DNSSEC, I decided that Sweden was <a href="http://www.cartoonbank.com/item/25468">the &#8220;in&#8221; place to be</a>, and to purchase &#8220;cloudba.se&#8221; and roll out my first DNSSEC signed domain.</p>
<p>The purchase wasn&#8217;t as easy as it might have been &#8212; when you buy a domain, Sweden <a href="http://www.iis.se/docs/general_conditions.pdf">insists</a> that people provide their <a href="http://www.papersplease.org/id.html">identity numbers</a> (albeit they have absolutely no way of checking if you&#8217;re telling the truth) &#8212; or if a company they want a VAT or registration number (which are checkable, albeit I suspect they didn&#8217;t bother). I also found that they don&#8217;t like spaces in the VAT number &#8212; which held things up for a while!</p>
<p>However, eventually they sent me a PGP signed email to tell me I was now the proud owner of &#8220;cloudba.se&#8221;.  Unfortunately, this email wasn&#8217;t in RFC3156 PGP/MIME format (or any other format that my usually <a href="http://en.wikipedia.org/wiki/Turnpike_(software)">pretty capable email client</a> understood).</p>
<p>The email was signed with key 0xF440EE9B which was reassuring because the <a href="http://www.iis.se/">.se registry</a> gives the fingerprint for this key on their website <a href="https://domainmanager.iis.se/start/customerservice">here</a>. Rather less reassuringly footnote (*) next to the fingerprint says &#8220;<em>.SE signature for outgoing e-mail. (**) June 1 through August 31.</em>&#8221; (the (**) is for a second level of footnote, which is absent &#8212; and of course it is now September).</p>
<p>They also enable you to fetch the key through a link on <a href="http://www.iis.se/support">this page</a> to their &#8220;PGP nyckel-ID&#8221; at <a href="http://subkeys.pgp.net:11371/pks/lookup?op=get&#038;search=0xFCEC5128F440EE9B">http://subkeys.pgp.net</a>.</p>
<p>Unfortunately, fetching the key shows that the signature on the email is invalid.</p>
<p>Since the email seems to have originated in the Windows world, but was signed on a Linux box (giving it a mixture of 0D 0A and 0A line endings), then pushed through a three year old copy of <a href="http://search.cpan.org/dist/MIME-tools/">MIME-tools</a> I suppose the failure isn&#8217;t too surprising. But strictly the invalid signature means that I shouldn&#8217;t trust the email&#8217;s contents at all &#8212; because the contents have definitely been tampered with since the signature was applied.</p>
<p>Since the point of the email was to get me to login for the first time to the registry website and set my password to control the domain, this is a little <a href="http://www.cartoonbank.com/item/32907">unfortunate</a>.</p>
<p>Even if the signature had been correct, then should I trust the PGP key?</p>
<p>Well it is pointed to from the registry website which is a Good Thing. However, they do themselves no favours by referencing a version on <a href="http://www.rossde.com/PGP/pgp_keyserv.html">the public key servers</a>. I checked who had signed the key (which is an <a href="http://www.pgpi.org/doc/pgpintro/#p20">alternative way of trusting its provenance</a> &#8212; since the email had arrived to a non-DNSSEC secured domain). Turned out there was no-one I knew, and of 4 individual signatures, 2 were from expired keys. The other signature was the IIS root key &#8212; which sounds promising. That has 8 signatures, once again not people I know &#8212; but only 1 from a non-expired key, so perhaps I can get to know some of the other 7?</p>
<p>Of course, anyone can sign a key on a public key server, so perhaps it makes sense for .se to suggest that people fetch a key with as many signatures as possible &#8212; there&#8217;s more chance of it being signed by someone they know. Anyway, I have now added my own signature, using an email address at my nice shiny new domain. However, it is possible that I may not have increased the level of trust <img src='http://www.lightbluetouchpaper.org/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
<p><img src="http://www.lightbluetouchpaper.org/wp-content/uploads/2008/09/signers.png" alt="" title="Signers of the .se PGP key" class="aligncenter size-full wp-image-381"></p>
]]></content:encoded>
      <pubDate>Mon, 29 Sep 2008 14:33:27 +0000</pubDate>
      <category domain="http://securityratty.com/tag/key">key</category>
      <category domain="http://securityratty.com/tag/public key servers">public key servers</category>
      <category domain="http://securityratty.com/tag/trust">trust</category>
      <category domain="http://securityratty.com/tag/iis root key">iis root key</category>
      <category domain="http://securityratty.com/tag/key 0xf440ee9b">key 0xf440ee9b</category>
      <category domain="http://securityratty.com/tag/pgp">pgp</category>
      <category domain="http://securityratty.com/tag/pgp nyckel-id">pgp nyckel-id</category>
      <category domain="http://securityratty.com/tag/public key server">public key server</category>
      <category domain="http://securityratty.com/tag/pgp key">pgp key</category>
      <source url="http://www.lightbluetouchpaper.org/2008/09/29/root-of-trust/">Root of Trust ?</source>
    </item>
    <item>
      <title><![CDATA[Wee-Fi: Wi-Fi Robot Attack; Silicon Valley Plan Proceeds]]></title>
      <link>http://securityratty.com/article/a73229a533aa9f53897566105f7e6501</link>
      <guid>http://securityratty.com/article/a73229a533aa9f53897566105f7e6501</guid>
      <description><![CDATA[The Spykee is a $300 Wi-Fi Skype robot: Lots of strange coolness here. I don't know how I missed hearing about this before, but apparently an actual customer got his hands on the thing and recorded a...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><strong><a href="http://www.robotsrule.com/html/spykee.php">The Spykee is a $300 Wi-Fi Skype robot:</a></strong> Lots of strange coolness here. I don't know how I missed hearing about this before, but apparently an actual customer got his hands on the thing and recorded a video. It's cute. You can access its video through control software or a remote Skype video connection. It's got a speaker and microphone, and can be used for VoIP calls. The control software allows it to move around, play sound effects, and produce music. Like the computer in Superman III (or a Roomba), it craves power, and knows to return to its charger.</p>

<p><img src="http://wifinetnews.com//images/2008/spykee_1.jpg" alt="spykee_1.jpg" border="0" width="200" height="200" /></p>

<p>The name reveals some of its creepy appeal: Spykee = Spy Camera. I suppose the nanny you're trying to make sure isn't shaking your baby might be freaked out when it suddenly starts emitting Star Wars music, or such like. Made by Meccano under the Erector brand, its control software is Mac and Windows compatible. </p>

<p>I, for one, welcome our new Spykee overlords--on 15-Oct-2008 when it starts to ship generally.</p>

<p><strong><a href="http://news.yahoo.com/s/ibd/20080924/bs_ibd_ibd/20080924tech01">Silicon Valley project finally gets underway:</a></strong> It's a still a pilot, small, with no promised outcome. And after all this time, a switch of partners, and new parameters, they've still mounted just 20 of 28 access points.</p>]]></content:encoded>
      <pubDate>Wed, 24 Sep 2008 17:13:28 +0000</pubDate>
      <category domain="http://securityratty.com/tag/control software">control software</category>
      <category domain="http://securityratty.com/tag/spykee">spykee</category>
      <category domain="http://securityratty.com/tag/spykee overlords">spykee overlords</category>
      <category domain="http://securityratty.com/tag/suddenly starts">suddenly starts</category>
      <category domain="http://securityratty.com/tag/wi-fi skype robot">wi-fi skype robot</category>
      <category domain="http://securityratty.com/tag/silicon valley project">silicon valley project</category>
      <category domain="http://securityratty.com/tag/star wars music">star wars music</category>
      <category domain="http://securityratty.com/tag/play sound effects">play sound effects</category>
      <category domain="http://securityratty.com/tag/starts">starts</category>
      <source url="http://wifinetnews.com/archives/008460.html">Wee-Fi: Wi-Fi Robot Attack; Silicon Valley Plan Proceeds</source>
    </item>
    <item>
      <title><![CDATA[What to watch for - the Rest of the Fortune 500 Gets Their Software Security]]></title>
      <link>http://securityratty.com/article/d0a9a1ce70c7eb39399e6f52665bcf05</link>
      <guid>http://securityratty.com/article/d0a9a1ce70c7eb39399e6f52665bcf05</guid>
      <description><![CDATA[The financial industry drives a lot of what happens in security. They have had a lot of money, and lots of people try to steal from them their customers. They did drive some good stuff, but only from...]]></description>
      <content:encoded><![CDATA[<p>The financial industry drives a lot of what happens in security. They <strike>have</strike> had a lot of money, and lots of people try to steal from <strike>them</strike> their customers. They did drive some good stuff, but only from one vertical&#39;s perspective. I have advocated for awhile that software security look to other verticals to understand their security needs. Now that we&#39;re watching these behemoth financial firms vanish before our eyes, we will see the needs of insurance, manufacturing, healthcare and other verticals take on more precedence. If you want some ideas on what is important, start <a href="http://duckdown.blogspot.com/">here</a>. FWIW, here are some key themes that i think will emerge.</p><br />
<div><span style="FONT-WEIGHT: bold">Standard Support</span></div>
<div><a href="http://xmlnetworking.blogspot.com/">Mark O&#39;Neill</a> posted this comment to an earlier <a href="http://1raindrop.typepad.com/1_raindrop/2008/09/software-security-may-live-in-interesting-times.html">blog</a> and it bears repeating</div><br />
<blockquote class="webkit-indent-blockquote" style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; MARGIN: 0px 0px 0px 40px; BORDER-TOP-STYLE: none; PADDING-TOP: 0px; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-BOTTOM-STYLE: none">
<p><span style="COLOR: #333333; LINE-HEIGHT: 19px">Take a difference I&#39;ve noticed between financial services and government. I have encountered situations where a financial services customer may say &quot;what if we just forget about using all those standards and make all these messages simpler&quot;, as they have optimization hard-wired as a goal. A government customer is (in my experience) more likely to focus on standards support for interoperability, and also to support directives that certain standards are used (e.g. XACML, let&#39;s say).</span></p></blockquote>
<blockquote class="webkit-indent-blockquote" style="PADDING-RIGHT: 0px; PADDING-LEFT: 0px; PADDING-BOTTOM: 0px; MARGIN: 0px 0px 0px 40px; BORDER-TOP-STYLE: none; PADDING-TOP: 0px; BORDER-RIGHT-STYLE: none; BORDER-LEFT-STYLE: none; BORDER-BOTTOM-STYLE: none">
<p><span style="COLOR: #333333; LINE-HEIGHT: 19px"><br /></span><span style="COLOR: #333333; LINE-HEIGHT: 19px">If the vendor was to build their product based solely on either customers needs, they would assume, as you say, that &quot;the client just doesn&#39;t get it&quot;. It would be either &quot;These government people are crazy, the people back at the bank told us those standards were not important&quot;, or else &quot;these financial services people are crazy, we show them all the complex support for standards we have and they do not seem to care at all, they just want us to strip all that out&quot;.</span><br /><span style="COLOR: #333333; LINE-HEIGHT: 19px">In that case, the trick would be to build something down the middle, with the standards support and the optimization. But, just focusing on one sector is bad.</span></p></blockquote><br />
<div>The financial people have been optimizing for so long and they had so much money they didn&#39;t need to worry about standards, they were the standard. But you don&#39;t need standards for standards&#39; sake, you need...</div><br />
<div><span style="FONT-WEIGHT: bold">Interoperability</span></div>
<div>The financial people didn&#39;t worry about this, the pot of gold was so big people would pay to play and build their own adapters. Architects at other companies need to figure out how to cost effectively knit things together and get authN, authZ, and audit too.</div><br />
<div><span style="FONT-WEIGHT: bold">Fuzzy Edges</span></div>
<div>Take something hideous like the FIX protocol. Everyone knows its broken but they just built stuff all around in terms of accountability and other controls. they could do this because there was a living breathing audit log of transactions - a hard edge. So the financial industry drove lots of poor plumbing and compensated with hard edges. It worked well enough I suppose, but as any protocol plumber knows, you need to fix the pipes eventually. Especially if you want to...</div><br />
<div><span style="FONT-WEIGHT: bold">Scale</span></div>
<div>Need to scale across domains, locations, geographies. Its not one little closed trading floor loop. Its wheels within wheels. You might say its <span style="FONT-STYLE: italic">federated</span> autonomous nodes.&#160;</div><br />
<div>its not just technical run time scale. Its people scale. You can&#39;t assume that your tool is supported by several security people per project. The tools have to scale for one security person and a hundred developer type ratios. Better automation, better reporting, faster integration. Raise the floor one inch, but raise the <span style="FONT-STYLE: italic">whole</span> floor.</div>
<div>&#160;</div>
<div><strong>Smaller Overall Security Budget</strong></div>
<div>I saved the best for last. When the financial people wanted software security, they kept spending on network security and they added dollars to support software security tools and processes. The rest of the F500 can&#39;t or wont be able to, this means that for the software security vendors, they will need to <strong>take market share</strong>. Its not just competing against each other, its making the business case for software security over other types of security that have <a href="http://1raindrop.typepad.com/1_raindrop/2008/08/golf-driven-security.html">ossified technically</a> but still command a rosy price, like *cough* network firewalls.</div>
<div>&#160;</div>
<div>Side note, I know three financial firms that did excellent work in software security. really dug and invested time and money to make sure they are world class in that space. Strangely enough with all these firms melting down, the three I am thinking of that took a conservative approach, addressing software security in a root and branch mode,have not been named as a target for the next meltdown. Coincidence? We report, you decide.</div>]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 11:06:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/software security">software security</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/government customer">government customer</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/government people">government people</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/financial people">financial people</category>
      <category domain="http://securityratty.com/tag/software security vendors">software security vendors</category>
      <category domain="http://securityratty.com/tag/financial services people">financial services people</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/09/what-to-watch-for---the-rest-of-the-fortune-500-gets-their-software-security.html">What to watch for - the Rest of the Fortune 500 Gets Their Software Security</source>
    </item>
    <item>
      <title><![CDATA[UPDATES GALORE! or, THE PRONOUN WE MEANS YOU AND ME!]]></title>
      <link>http://securityratty.com/article/6ebd2507c3c7a5fbc11f6123a9af9559</link>
      <guid>http://securityratty.com/article/6ebd2507c3c7a5fbc11f6123a9af9559</guid>
      <description><![CDATA[So much traveling, so little blogging. Sorry everyone. Ive gotta say first that I really enjoyed meeting readers and friends of the blog this past two weeks
Today, allow me to update you on FAIR and...]]></description>
      <content:encoded><![CDATA[<p>So much traveling, so little blogging.  Sorry everyone.  I&#8217;ve gotta say first that I really enjoyed meeting readers and friends of the blog this past two weeks.</p>
<p>Today, allow me to update you on FAIR and the movement towards a formal, open standard.  There&#8217;s a couple of cool things going on in our little risk-world.</p>
<p>First, The Open Group Security Forum continues to move towards a formal adoption of FAIR.</p>
<p><strong>WHAT DO YOU MEAN &#8220;WE&#8221; - YOU GOT A STANDARDS BODY IN YOUR POCKET OR SOMETHING?</strong></p>
<p>Our meeting in Chicago a few weeks ago was great, but also slightly disturbing for me. I got pronoun-confusion syndrome.   I&#8217;m used to using the &#8220;we&#8221; pronoun to refer to RMI, or Jack and myself as we vet the models.  So without even thinking I would said &#8220;we have been looking at how loss occurs, and may want to change the model some&#8221; and The Open Group Members freaked out (rightfully so).  Adrian Seccombe gently reminded me that the &#8220;we&#8221; was now the Security Forum, and that &#8220;we&#8221; didn&#8217;t go changing things at will without vetting against each other.  Man I love this stuff.  I get to run our thoughts and ideas past some great folks now - you know, those smart people who tend to have really complex problems and are trying hard to solve them.<br />
<span style="color: #000080;"><strong><br />
Formal Adoption:  Soon, Very Soon Now</strong></span></p>
<p>Formal Adoption basically means we&#8217;ve made this document, everyone is close to saying that they generally like it, and once that finally happens then &#8220;bam&#8221;, we&#8217;re ready to move onward and upward with better things (see Cookbooks, below).  We&#8217;ve got a couple of changes to the current document that have been requested that aren&#8217;t a big deal.  For example, one request is that we make some statement about general applicability of FAIR to risk domains outside of the IT realm.   But once additions like that and others are done, this long process should be complete.</p>
<p><span style="color: #000080;"><strong>New Document Moving Towards Public Release:</strong></span></p>
<p>We&#8217;ve got a basic document that should be public in the next few weeks on <em><strong>&#8220;What Makes a Good Risk Assessment Methodology&#8221;</strong></em> - written by yours truly and Jack.  It&#8217;s a very high-level document, and serves two purposes:</p>
<ul>
<li>For novices it helps parse out what is important in any undertaking to understand corporate risk (the repeated discussions on the ISO 27001 mailing list make me think it would be a place ripe for such a document).</li>
<li>For those who &#8220;know&#8221; risk, it helps to re-establish some fundamental principles like the use of scales (ratio, please), the implications of dealing in probabilities, what attributes like consistency and defensibility mean, how &#8220;risk&#8221; should be reported to the business (something you know, meaningful) and so on.</li>
</ul>
<p>When this doc is deemed ready for public consumption I&#8217;ll be sure to post on this blog here.</p>
<p><strong>COOKBOOKS, EUROPEAN AGENCIES, AND, IRON CHEF &#8220;RISK&#8221; - WHOSE CUISINE WILL REIGN SUPREME?</strong></p>
<p>One interesting thing that came up in the Chicago meeting was that <strong><a href="http://www.enisa.europa.eu/">ENISA</a></strong> (The European Network and Information Security Agency) developed a very nice document that reviewed something like 18 different risk assessment methodologies against their Criteria for Goodness.  FAIR was one of the ones they reviewed, and we (the royal &#8220;we&#8221; used there to include all us FAIR-Folk) did awfully well.  Things of interest:</p>
<ol>
<li>They based their work on the current introduction paper which is not at all a step-by-step guide towards an organizational risk assessment (what ENISA really wanted) and we did pretty well.  Well enough that if we had developed a paper along the lines of NIST 800-30 or OCTAVE for the use of FAIR in a formal process, we could have done <em><strong>really, really</strong></em> well.  Like won-the-bake-off kind of well.</li>
<li>FAIR is actually not at all incongruous to many of the risk assessment methodologies offered, and in fact compliments many of them by letting those methodologies develop real, structured probabilities.  Think OCTAVE, where they basically say &#8220;math is (probabilities are) hard, so if you want to do them for reals, good luck!  But here&#8217;s a nonsensical way to do things if you want to believe in <span style="color: #ff00ff;"><em>magic-fairy risk</em></span>&#8220;.  FAIR fits right in there by stomping on the magic-fairy risk with the jack-boots of rationality.  FAIR similarly helps other risk standards that might lack structured probability development.</li>
</ol>
<p>So The Open Group Security Forum decided that though we could create a new document and totally p0wn any future ENISA bake-off, there wasn&#8217;t much demand for the development of that documentation by the membership  - a point which was made quite apparent at the beginning of the discussion when one large European company CISO asked &#8220;What&#8217;s ENISA?&#8221;  Relevancy is everything, I suppose.</p>
<p>But that second item up there - the one about helping rather than competing with other &#8220;risk assessment methodologies&#8221; - really struck a chord.  So &#8220;we&#8221; (The Security Forum) are going to develop some &#8220;Cookbooks&#8221; that basically are high-level documents that say &#8220;If you want to use FAIR with (OCTAVE/COSO/CoBIT/Whatever) here&#8217;s how it fits, makes it better, and improves your life.  I&#8217;m pretty excited about these, and our first document looks like it&#8217;s going to be COSO integration.</p>
<p><strong>THE OPEN GROUP SECURITY FORUM - THEY&#8217;RE A TRUSTING BUNCH (WITH QUALIFICATION, OF COURSE)<br />
</strong></p>
<p>Finally, many people have asked me &#8220;Why work with The Open Group?&#8221;  There are many reasons, to be sure, but I will give you one example.  Members of the Security Forum there are not only great at vetting the model and getting consensus on risk and risk factors - but they&#8217;re quick to start applying.  So in Chicago, I thought I&#8217;d be talking about FAIR and the standard and fighting groupthink.  Nope.  Not at all.  In fact, the forum members spent more time suddenly discussing use of FAIR in a new Trust Model they&#8217;re developing.  So all of the sudden, I&#8217;m part of a new and exciting project to develop a Trust Model - how cool is that?  While formal adoption of the Trust Model will be necessarily long and deliberate - the collaboration and development is happening much faster than I can keep up with.  But if you all will allow me, it will help me get my head around it all by blogging about it later this week.  So be prepared to read about me dealing in &#8220;Trust&#8221; a little bit.</p>
]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 11:24:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk assessment methodologies">risk assessment methodologies</category>
      <category domain="http://securityratty.com/tag/security forum">security forum</category>
      <category domain="http://securityratty.com/tag/forum">forum</category>
      <category domain="http://securityratty.com/tag/magic-fairy risk">magic-fairy risk</category>
      <category domain="http://securityratty.com/tag/risk standards">risk standards</category>
      <category domain="http://securityratty.com/tag/fair">fair</category>
      <category domain="http://securityratty.com/tag/risk-world">risk-world</category>
      <category domain="http://securityratty.com/tag/fair similarly helps">fair similarly helps</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=381">UPDATES GALORE! or, THE PRONOUN WE MEANS YOU AND ME!</source>
    </item>
    <item>
      <title><![CDATA[Listening to the evidence]]></title>
      <link>http://securityratty.com/article/cb3684b9bd257e429791aaa34c5339e3</link>
      <guid>http://securityratty.com/article/cb3684b9bd257e429791aaa34c5339e3</guid>
      <description><![CDATA[Last week the House of Commons Culture, Media and Sport Select Committee published a report of their inquiry into Harmful content on the Internet and in video games . They make a number of...]]></description>
      <content:encoded><![CDATA[<p>Last week the <a href="http://www.parliament.uk/parliamentary_committees/culture__media_and_sport.cfm">House of Commons Culture, Media and Sport Select Committee</a> published a report of their inquiry into &#8220;<a href="http://www.publications.parliament.uk/pa/cm200708/cmselect/cmcumeds/353/353.pdf">Harmful content on the Internet and in video games</a>&#8220;. They make a number of recommendations including a self-regulatory body to set rules for Internet companies to force them to protect users; that sites should provide a &#8220;watershed&#8221; so that grown-up material cannot be viewed before 9pm; that YouTube should screen material for forbidden content; that &#8220;<a href="http://www.spiked-online.com/index.php?/site/article/4633/">suicide websites</a>&#8221; should be blocked; that ISPs should be forced to block child sexual abuse image websites whatever the cost, and that blocking of bad content was generally desirable.</p>
<p>You will discern a certain amount of enthusiasm for blocking, and for a &#8220;<a href="http://www.yes-minister.com/polterms.htm#Politicians">something must be done</a>&#8221; approach. However, in coming to their conclusions, they do not, in my view, seem to have listened too hard to the evidence, or sought out expertise elsewhere in the world&#8230;<br />
<span id="more-351"></span><br />
Google/YouTube told them that 10 hours of video was posted every minute, and the amount is increasing. In the oral evidence session an MP helpfully suggested: &#8220;That video content is tagged. You do not need to look at every single minute of video content. Surely you could have people who would look at the video content which is tagged with labels which suggest it could be inappropriate.&#8221; Of course &#8220;<a href="http://lostria.blogspot.com/2008/01/fertility-slaps.html">happy_slapping.wmv</a>&#8221; or &#8220;<a href="http://www.phrases.org.uk/meanings/bunny-boiler.html">fluffy_bunnies.avi</a>&#8221; must always contain exactly what it says on the tin (<a href="http://en.wikipedia.org/wiki/Not%21">not!</a>) but unaccountably Google said it was a &#8220;fair suggestion&#8221;, so perhaps my cynicism is misplaced.</p>
<p>However, back to blocking.</p>
<p>I submitted <a href="http://www.cl.cam.ac.uk/~rnc1/080129-cms.pdf">some evidence of my own</a>, which the committee summarised, reasonably accurately:</p>
<blockquote><p>Dr Richard Clayton, a researcher in the Security Group of the Computer Laboratory at Cambridge University and author of several academic papers on methods for blocking access to Internet content, pointed out that there was no single blocking method which was both inexpensive and discerning enough to block access to only one part of a large website (such as FaceBook). In his view, the fatal flaw of all network-level blocking schemes was the ease with which they could be overcome, either by encrypting content or by the use of proxy services hosted outside the UK.</p></blockquote>
<p>The committee&#8217;s conclusion, having read this was:</p>
<blockquote><p>At a time of rapid technological change, it is difficult to judge whether blocking access to Internet content at network level by Internet service providers is likely to become ineffective in the near future. However, this is not a reason for not doing so while it is still effective for the overwhelming majority of users.</p></blockquote>
<p>which I suppose logically means that the committee thinks that blocking should now be discarded as a policy option &#8212; but somehow I think that isn&#8217;t their intended meaning.</p>
<p>The Committee should perhaps have a look at <a href="http://www.acma.gov.au/webwr/_assets/main/lib310554/isp-level_internet_content_filtering_trial-report.pdf">this Australian report</a>, which found that ISP level content filtering (and in Australia the politicians want to use ISP level filtering to provide a child-friendly Internet) did work (up to a point) at Tier 3 (the smallest) ISPs. The <a href="http://en.wikiquote.org/wiki/Evelyn_Waugh#Scoop_.281938.29">up-to-a-point</a> is that unlike previous tests the systems didn&#8217;t completely wreck the browsing experience by slowing it down. However, the systems blocked only 85-98% of illegal material and similar percentages of material suitable for adults but not for younger children. Interestingly some products were better at different categories.</p>
<p>Getting that many sites wrong is really quite significant, so it&#8217;s difficult to see this as a ringing endorsement for blocking the web. Additionally, the Australian report found that the blocking was useless on &#8220;non-web&#8221; protocols (such as peer-to-peer) and their report specifically didn&#8217;t consider cost, or ease of circumvention &#8212; so it&#8217;s not just UK politicians not wanting to consider evidence on that topic!</p>
<p>Finally, I should note that the Culture Media and Sport Committee has also ignored some rather more recent academic work. The MPs have put into their report that they were horrified to discover that child sexual abuse images took 24 hours to remove in the UK. What (should they ever learn of it) will they make of the recent discovery by <a href="http://people.seas.harvard.edu/~tmoore/">Tyler Moore</a> and myself that shows that if the website is hosted abroad then <a href="http://www.lightbluetouchpaper.org/2008/06/11/slow-removal-of-child-sexual-abuse-image-websites/">a month is more to be expected</a>?</p>
]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 20:24:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/content">content</category>
      <category domain="http://securityratty.com/tag/isp level content">isp level content</category>
      <category domain="http://securityratty.com/tag/video games">video games</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/bad content">bad content</category>
      <category domain="http://securityratty.com/tag/video content">video content</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/evidence">evidence</category>
      <category domain="http://securityratty.com/tag/child-friendly internet">child-friendly internet</category>
      <source url="http://www.lightbluetouchpaper.org/2008/08/08/listening-to-the-evidence/">Listening to the evidence</source>
    </item>
    <item>
      <title><![CDATA[VCsChoosing How to Invest]]></title>
      <link>http://securityratty.com/article/c4d8ac0dd426afdf9ac1d38d36dad4e8</link>
      <guid>http://securityratty.com/article/c4d8ac0dd426afdf9ac1d38d36dad4e8</guid>
      <description><![CDATA[Don Dodge has a series going on about VCs and why startups fail, and he says VCs say no to startups 99% of the time, yet still choose failing companies 33% of the time or so. Interestingly he compares...]]></description>
      <content:encoded><![CDATA[<p>Don Dodge has a series going on about VCs and why startups fail, and he says VC&#8217;s say no to startups 99% of the time, yet still choose failing companies 33% of the time or so. Interestingly he <a rel="nofollow" target="_blank" href="http://dondodge.typepad.com/the_next_big_thing/2008/08/why-vcs-say-no-99-of-the-time.html">compares </a>the selection process to the way investors choose their stocks &#8211;</p>
<blockquote><p>I would guess that every one of you reading this blog have a stock portfolio with 5 to 10 individual stocks or mutual funds. There are more than 5,000 publicly listed companies to choose from, and another 5,000 mutual funds. But, out of 10,000 possible companies you chose 10 to invest in. Why? Why did you reject the other 9,990 companies? Obviously there are more than 10 good companies to invest in. Other investors chose to invest their money in the other 9,990 companies&#8230;why not you?</p></blockquote>
<p>I suppose the difference must be that many investors aren&#8217;t actively involved in their investments (maybe entrepreneurs are more so, since they have to know a certain investment space quite well)&#8230;</p>
<p>It sounds to me a lot like the editorial selection process for book manuscripts, articles, and so forth &#8212; editors receive a ton of submissions and they have to be choosy. Sometimes they don&#8217;t pick winners; sometimes they pick losers. More importantly, each has a personal style, opinions, preferences, and they are trying to appeal to a certain audience. It&#8217;s interesting to think that VCs are similar but makes sense&#8211;the end question of &#8220;What will be successful&#8221; really depends on the consumer base and industry, and VCs are just people who probably know and prefer to interact with a certain type of consumer base or audience.</p>]]></content:encoded>
      <pubDate>Mon, 04 Aug 2008 06:23:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/investors chose">investors chose</category>
      <category domain="http://securityratty.com/tag/chose">chose</category>
      <category domain="http://securityratty.com/tag/investors">investors</category>
      <category domain="http://securityratty.com/tag/editorial selection process">editorial selection process</category>
      <category domain="http://securityratty.com/tag/investors choose">investors choose</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/selection process">selection process</category>
      <category domain="http://securityratty.com/tag/choose">choose</category>
      <category domain="http://securityratty.com/tag/mutual funds">mutual funds</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/355545351/">VCsChoosing How to Invest</source>
    </item>
    <item>
      <title><![CDATA[Anti-Terrorism Stupidity at Yankee Stadium]]></title>
      <link>http://securityratty.com/article/dfb361bbe6338d8abaf924431ba80dfb</link>
      <guid>http://securityratty.com/article/dfb361bbe6338d8abaf924431ba80dfb</guid>
      <description><![CDATA[They's at Yankee Stadium: The team contends that sunscreen has long been on the list of stadium contraband, but there is no mention of it on the Yankee Web site
Four weeks ago, Stadium officials...]]></description>
      <content:encoded><![CDATA[<p>They's <a href="http://www.nypost.com/seven/07222008/news/regionalnews/sunblockheads__at_the_stadium_120930.htm"confiscating sunscreen</a> at Yankee Stadium:</p>

<blockquote>The team contends that sunscreen has long been on the list of stadium contraband, but there is no mention of it on the Yankee Web site. 

<p>Four weeks ago, Stadium officials decided that sunscreen of all sizes and varieties would not be permitted, a security supervisor told The Post before last night's game. </p>

<p>"There have been a lot of complaints," he said. "We tell them to apply once and then throw it out." </p>

<p>For fans who bring babies or young children to cheer on the home team, the guard had suggested they "beg" to take the sunblock in. </p>

<p>Seeing the giant bag full of confiscated sunscreen Saturday, one steaming Yankee fan asked whether he could take one of the tubes and apply it before heading into the park. </p>

<p>"Absolutely not," the guard told him. "What if you get a rash? You might sue the Yankees."</blockquote></p>

<p>Next, I suppose, is <a href="http://www.schneier.com/blog/archives/2008/06/liquid_ban_gone.html">confiscating liquids at pools</a>.  </p>

<p>We've collectively lost our minds.</p>

<p>This story has a happy ending, though.  A day after <i>The New York Post</i> published this story, Yankee Stadium <a href="http://www.salon.com/sports/daily/?last_story=/sports/daily/feature/2008/07/23/sunblock/">reversed</a> its ban.  Now, if only the Post had that same affect on airport security.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=EgeecJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=EgeecJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=TjuhOJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=TjuhOJ" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 24 Jul 2008 02:50:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/yankee stadium">yankee stadium</category>
      <category domain="http://securityratty.com/tag/post">post</category>
      <category domain="http://securityratty.com/tag/york post">york post</category>
      <category domain="http://securityratty.com/tag/yankee web site">yankee web site</category>
      <category domain="http://securityratty.com/tag/giant bag">giant bag</category>
      <category domain="http://securityratty.com/tag/yankee fan">yankee fan</category>
      <category domain="http://securityratty.com/tag/collectively lost">collectively lost</category>
      <category domain="http://securityratty.com/tag/guard">guard</category>
      <category domain="http://securityratty.com/tag/airport security">airport security</category>
      <source url="http://www.schneier.com/blog/archives/2008/07/antiterrorism_s.html">Anti-Terrorism Stupidity at Yankee Stadium</source>
    </item>
    <item>
      <title><![CDATA[Indiana State University professor's laptop is stolen]]></title>
      <link>http://securityratty.com/article/ac01a165449e657f832374db2c405cad</link>
      <guid>http://securityratty.com/article/ac01a165449e657f832374db2c405cad</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/15/08

Organization
Indiana State University

Contractor/Consultant/Branch
None

Victims
students who took economics classes from 1997 through the...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/indianastate.jpg" width="137" align="right" height="48"><font size="2"><b>Date Reported: </b><br>7/15/08<br><br><b>Organization: </b><br><a href="http://www.indstate.edu/home.htm">Indiana State University</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>"students who took economics classes from 1997 through the spring semester 2008"<br><br><span style="font-weight: bold;">Number Affected:</span><br>"more than 2,500"<br><br><span style="font-weight: bold;">Types of Data:</span><br>"names, grades, e-mail addresses and student identification numbers"*<br><br><font size="1">*Until 2003, student identification numbers were the equivalent of each student’s Social Security number.</font><br><br><span style="font-weight: bold;">Breach Description:</span><br>"A password-protected laptop computer containing personal information for current and former Indiana State University students was stolen during the weekend, the university reported Tuesday."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www1.indstate.edu/laptopsecurity/">Indiana State University</a> <br><a href="http://www.wthitv.com/Global/story.asp?S=8684098&amp;nav=menu593_1">Associated Press via WTHI Channel 10 News</a> <br><a href="%20http://www.chicagotribune.com/news/chi-ap-in-isu-stolenlaptop,0,1255776.story">Associated Press via Chicago Tribune</a><br><br><span style="font-weight: bold;">Report Credit:</span><br>Indiana State University<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>A password-protected laptop computer containing personal information for current and former Indiana State University students was stolen during the weekend, the university reported Tuesday.<br><span style="font-style: italic;">[Evan] What do you suppose the purpose of the "password-protected" mention is?&nbsp; I hope it is not meant to reassure anyone that the information is safe.&nbsp; For those of you that do not know, password-protection is easily bypassed and in the opinion of many information security professionals (this one included), does NOT provide adequate protection for confidential information.</span><br><br>While there is no evidence to suggest that password security was breached, the university is taking the precaution of notifying all affected students for whom it has current contact information.<br><span style="font-style: italic;">[Evan] If someone were to breach the "password security", what evidence would the school see?&nbsp; None.&nbsp; There would be no evidence (except locally on the laptop) if the local password store had been compromised.&nbsp; The school no longer has possession of the laptop, so the school would have no evidence.</span><br><br>The laptop contained data for students who took economics classes from 1997 through the spring semester 2008, estimated at more than 2,500 individuals.<br><br>If you took an economics class during this time period, but did not receive a letter, please call the Registrar’s Office to verify that you were on the list, and to update your address so that we may send you a letter.<br><span style="font-style: italic;">[Evan] Contact information for the Registrar's Office, click </span><a style="font-style: italic;" href="http://www1.indstate.edu/registrar/">here</a><span style="font-style: italic;">.</span><br><br>The information includes names, grades, e-mail addresses and student identification numbers.<br><br>Beginning in 2003, use of social security numbers as student ID numbers was discontinued in favor of university-specific identification numbers.<br><span style="font-style: italic;">[Evan] A sound security decision by the university would have been to follow up with a project to identify and remove Social Security numbers already held as student IDs.&nbsp; Maybe it was, but the information on this laptop was missed.</span><br><br>The theft occurred Saturday while the professor was traveling in southern Indiana<br><br>the professor was traveling with his family and briefly left the computer unattended<br><span style="font-style: italic;">[Evan] A laptop can grow legs in a flash.&nbsp; A person doesn't need to leave a laptop unattended for very long for it to disappear.</span><br><br>The incident occurred on July 12, 2008 and was reported to university officials on July 14, 2008.<br><br>The incident was reported immediately to the appropriate law enforcement agency and early Monday to university officials.<br><br>The extent of the information contained on the computer was not determined until Monday night.<br><br>Faculty and staff are being reminded that university policy prohibits the storage of private, sensitive data on portable computers.<br><span style="font-style: italic;">[Evan] Excellent policy provision.&nbsp; Policy does little if it is not communicated, enforced, audited against, and improved.&nbsp; Where was the failure in the breach?&nbsp; Was the policy not communicated to this professor, and thus he/she was not aware?</span><br><br>In addition, laptops provided to faculty are equipped with several security measures including encryption and a bio-metric fingerprint reader to prevent access by anyone other than the assigned user.<br><span style="font-style: italic;">[Evan] An excellent standard (or procedure).</span><br><br>Approximately 500 ISU faculty members have laptop computers.<br><br>The university is reviewing its procedures to ensure compliance with existing policies, said Interim President C. Jack Maynard, the university’s provost and vice president for academic affairs<br><br><span style="font-weight: bold;">From the FAQs:</span><br><br>Q: What can someone do with a stolen SSN?<br>A: "With just a SSN there is little anyone can do in the way of setting up a false identity or securing credit. Generally an identity thief would need more information and documentation to set up false credit.<br><span style="font-style: italic;">[Evan] A SSN needs to be held in strict confidentiality in today's financial, employment, health, and other systems.&nbsp; It is often used for identification and authentication.&nbsp; Once an identity thief has a SSN, the owner of that SSN is now a prime target because the thief has the most confidential piece of information (ingredient) in the identity theft recipe.&nbsp; The rest of the information is typically easier to come by, i.e. name, address, employer, etc.&nbsp; It is true that an SSN alone is not enough information to commit identity theft, but it is an EXCELLENT start.</span><br><br><span style="font-weight: bold;">Commentary:</span><br>We can assume that the school knows the risks involved in storing confidential information on a poorly protected laptop.&nbsp; Otherwise, they probably wouldn't have policy and procedure against it.&nbsp; The school's statements that are meant to minimize the risk, seemingly without fact, are disappointing. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/17/indianastate.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Thu, 17 Jul 2008 05:29:35 +0000</pubDate>
      <category domain="http://securityratty.com/tag/university">university</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/information includes names">information includes names</category>
      <category domain="http://securityratty.com/tag/university students">university students</category>
      <category domain="http://securityratty.com/tag/confidential information">confidential information</category>
      <category domain="http://securityratty.com/tag/laptop">laptop</category>
      <category domain="http://securityratty.com/tag/evan contact information">evan contact information</category>
      <category domain="http://securityratty.com/tag/university policy prohibits">university policy prohibits</category>
      <source url="http://breachblog.com/2008/07/17/indianastate.aspx">Indiana State University professor's laptop is stolen</source>
    </item>
    <item>
      <title><![CDATA[Employee fraud hits Baptist Health in Arkansas]]></title>
      <link>http://securityratty.com/article/4227f770b7017f7d953c43516b49d951</link>
      <guid>http://securityratty.com/article/4227f770b7017f7d953c43516b49d951</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
7/2/08

Organization
Baptist Health

Baptist Health is the largest not-for-profit healthcare organization in Arkansas

Contractor/Consultant/Branch
None...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/baptisthealth.jpg" width="120" align="right" height="274"><font size="2"><b>Date Reported: </b><br>7/2/08<br><br><b>Organization: </b><br><a href="http://www.baptist-health.org/">Baptist Health*</a><br><br><font size="1">*Baptist Health is the largest not-for-profit healthcare organization in Arkansas</font><br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br>None<br><br><span style="font-weight: bold;">Victims:</span><br>Patients<br><br><span style="font-weight: bold;">Number Affected:</span><br>~1,800<br><br><span style="font-weight: bold;">Types of Data:</span><br>"name, address, date of birth, Social Security number, and reason for coming to Baptist Health"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"LITTLE ROCK (AP) - A North Little Rock woman has been arrested for using financial information from patients at Baptist Health to illegally obtain Wal-Mart gift cards for her own use. The hospital has notified about 1,800 patrons of the ID theft."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.wxvt.com/Global/story.asp?S=8609129&amp;nav=menu1344_2">Associated Press via WXVT Channel 15 News</a> <br><a href="http://arkansasmatters.com/content/fulltext/news/?cid=80211">KARK Channel 4 News</a> <br><a href="http://www.nwanews.com/adg/News/230290/">Arkansas Democrat-Gazette</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Toby Manthey, Arkansas Democrat-Gazette<br><br><span style="font-weight: bold;">Response:</span><br>From the online sources cited above:<br><br>Baptist Health has sent letters warning about 1,800 patients that the hospital system’s records may have been breached<br><span style="font-style: italic;">[Evan] Uh, "may have been breached"?!</span><br><br>The notification came after the arrest of a Baptist Health employee at a Wal-Mart store on 25 counts of financial identity fraud.<br><span style="font-style: italic;">[Evan] Wouldn't life be grand if we could trust our employees?&nbsp; Maybe, I suppose.</span><br><br>The letters, mailed last week, follow the firing of the woman in early June<br><br>North Little Rock police say Tamara Hill, 30, of that city worked at Baptist Health Medical Center-North Little Rock in the emergency department.<br><br>Hill, an admissions clerk, was arrested May 30 at the Wal-Mart<br><br>Ebony Flowers, 25, also of North Little Rock, was arrested at the store the same day on three counts of identity fraud<br><br>Flowers was listed in a police report as a janitor for the North Little Rock School District<br><span style="font-style: italic;">[Evan] Key word is "was".</span><br><br>Baptist Health recorded more than 950,000 patient visits systemwide in 2007, a number that includes repeat visits.<br><br>Mark Lowman, spokesman for the Little Rock-based Baptist Health system, confirmed that the system fired the employee after notification of the arrest.<br><br>Police reports say the women used a victim’s personal information to obtain temporary Wal-Mart "account authorization numbers" - credit cards, essentially - used to buy Wal-Mart gift cards.<br><br>The victim reported to police that he had not authorized the transactions<br><br>the same victim confirmed he was a Baptist Health patient<br><br>He expressed appreciation of the handling of the case by the system and by the North Little Rock police. <br><br>Among the items found during a search connected with the arrest of Hill was personal information for 24 other people, including "screen shots" - printouts showing the exact appearance of the images on a computer screen - that showed victims’ personal information.<br><span style="font-style: italic;">[Evan] This seems like confirmation that "may have been breached" is not all that accurate.</span><br><br>Also found were four Wal-Mart gift cards and $ 1,490 in cash<br><br>Police found a small bag of marijuana on Flowers, according to the reports. In a search connected with her arrest, they also discovered a. 25-caliber magazine with six bullets, as well as a receipt for four of the gift cards and information on three-identity theft victims.<br><span style="font-style: italic;">[Evan] A thug.</span><br><br>The U. S. Secret Service is helping with the investigation. <br><br>"Due to a breach of our information systems security policies, there is a possibility that some personal information, such as your name, address, date of birth, Social Security number, and reason for coming to Baptist Health, was accessed by an unauthorized person."<br><span style="font-style: italic;">[Evan] This is from the letter to the victims.</span><br><br>No information in the patient’s "medical records" and no information about the patient’s diagnosis or prognosis was accessed<br><br>while no "medical record" information was accessed, the letter mentioned the patient’s "reason for coming" to the system possibly was accessed<br><br>Lowman said a reason stated by a patient using the system isn’t considered medical information because the reason is a layman’s explanation, not one from a medical professional.<br><span style="font-style: italic;">[Evan] This is Mark Lowman, spokesman for the Little Rock-based Baptist Health system</span><br><br>He said the breach wouldn’t violate the Health Insurance Portability and Accountability Act, or HIPAA. <br><br>But Pam Dixon, executive director of the San Diego-based World Privacy Forum, a privacy advocacy group, thinks all the information mentioned in the letter falls under HIPAA.<br><br>"It doesn’t matter that [it’s not ] a prognosis or diagnosis," she said. <br><span style="font-style: italic;">[Evan] Splitting hairs.&nbsp; The bottom line is that confidential personal information was stolen and there are victims.&nbsp; Whether or not it is a HIPAA violation seems somewhat irrelevant.</span><br><br>Dixon found the system’s letter lacking in several respects, such as clarifying the exact meaning of a "reason for coming to Baptist Health." The letter also should have mentioned when and for how long the breach occurred, she said.<br><br>"Almost all breach letters have that," Dixon added.<br><span style="font-style: italic;">[Evan] Almost all breach letters have what?&nbsp; A mention about for how long the breach occurred?&nbsp; I must be reading some of the wrong breach letters because it seems to me that this information is 50/50 at best.&nbsp; Also missing is the "we have no reason to believe that the information will be misused", but this one doesn't fit does it?</span><br><br>Dixon said Baptist Health should have offered in the letter to set up free credit monitoring for victims.<br><span style="font-style: italic;">[Evan] Why?&nbsp; One year (or two) of credit monitoring is almost useless.&nbsp; Credit monitoring alerts a victim after fraud has already occurred and one year (or two) of monitoring is too limited for information that has a much longer lifespan.&nbsp; I guess credit monitoring would be better than nothing, but not by much.</span><br><br>Lowman said the health system continually conducts audits to know which staff members are accessing what information, and whether or not the access is appropriate.<br><span style="font-style: italic;">[Evan] Good!</span><br><br>"We’re always looking to provide better audits and better oversight of private, confidential and protected information," Lowman said.<br><span style="font-style: italic;">[Evan] And Good!</span><br><br><span style="font-weight: bold;">Commentary:</span><br>Preventing and detecting employee fraud has always been a challenge.&nbsp; This doesn't mean we give up though.&nbsp; We have some tools at our disposal such as employee background checks, role-based access control, segregation of duties, and job rotation to name a few.<br><br>I don't think that these two crooks are anything more than common criminals.&nbsp; The fact of the matter is that identity theft and fraud are very easy crimes to commit and require very little skill. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown<br></font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/07/10/baptisthealth.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Thu, 10 Jul 2008 20:00:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/confidential personal information">confidential personal information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/baptist health system">baptist health system</category>
      <category domain="http://securityratty.com/tag/health system">health system</category>
      <category domain="http://securityratty.com/tag/fraud">fraud</category>
      <category domain="http://securityratty.com/tag/victims personal information">victims personal information</category>
      <category domain="http://securityratty.com/tag/employee fraud">employee fraud</category>
      <category domain="http://securityratty.com/tag/baptist health">baptist health</category>
      <category domain="http://securityratty.com/tag/employee">employee</category>
      <source url="http://breachblog.com/2008/07/10/baptisthealth.aspx">Employee fraud hits Baptist Health in Arkansas</source>
    </item>
  </channel>
</rss>
