<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: takes]]></title>
    <link>http://securityratty.com/tag/takes</link>
    <description></description>
    <pubDate>Sun, 16 Nov 2008 21:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Stolen Credit Cards account for 59% of online criminal activity]]></title>
      <link>http://securityratty.com/article/cffc479a20281b84d90e501e93ee3e5d</link>
      <guid>http://securityratty.com/article/cffc479a20281b84d90e501e93ee3e5d</guid>
      <description><![CDATA[Please dont become a statistic in this area. Be careful online, make sure the site is safe and make sure your computer security products are up to date and functioning properly


clipped from...]]></description>
      <content:encoded><![CDATA[<div > Please dont become a statistic in this area.<br/>Be careful online, make sure the site is safe and make sure your computer security products are up to date and functioning properly. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/99552E1B-B318-4802-8F6C-B1B550619662/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/42ad7146-dd54-4e9b-a0e8-3ef6189e7b41/99552E1B-B318-4802-8F6C-B1B550619662/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.crime-research.org/news/24.11.2008/3666/" href="http://www.crime-research.org/news/24.11.2008/3666/" style="font-size: 11px;">www.crime-research.org</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.crime-research.org/news/24.11.2008/3666/ -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Symantec takes cybercrime snapshot with &#8216;Underground Economy&#8217; report
</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.crime-research.org/news/24.11.2008/3666/ --><DIV><br />
The “Underground Economy” report contains a snapshot of online criminal activity observed from July 2007 to June 2008 by a Symantec team monitoring activities in Internet Relay Chat (IRC) and Web-based forums where stolen goods are advertised. Symantec estimates the total value of the goods advertised on what it calls &#8220;underground servers&#8221; was about $276 million, with credit-card information accounting for 59% of the total.</DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/99552E1B-B318-4802-8F6C-B1B550619662/blog/" title="blog or email this clip"><img src="http://content6.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_281108040924"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=281108040924&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=281108040924&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=281108040924&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_281108040924" /></a></P>]]></content:encoded>
      <pubDate>Fri, 28 Nov 2008 13:09:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/online criminal activity">online criminal activity</category>
      <category domain="http://securityratty.com/tag/underground economy report">underground economy report</category>
      <category domain="http://securityratty.com/tag/symantec">symantec</category>
      <category domain="http://securityratty.com/tag/symantec team">symantec team</category>
      <category domain="http://securityratty.com/tag/computer security products">computer security products</category>
      <category domain="http://securityratty.com/tag/calls underground servers">calls underground servers</category>
      <category domain="http://securityratty.com/tag/internet relay chat">internet relay chat</category>
      <category domain="http://securityratty.com/tag/credit-card information">credit-card information</category>
      <category domain="http://securityratty.com/tag/total">total</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=663">Stolen Credit Cards account for 59% of online criminal activity</source>
    </item>
    <item>
      <title><![CDATA[Forensic genomics]]></title>
      <link>http://securityratty.com/article/db4fa79fc51e6d9290abb3a8fd263e3f</link>
      <guid>http://securityratty.com/article/db4fa79fc51e6d9290abb3a8fd263e3f</guid>
      <description><![CDATA[I recently presented a paper on Forensic genomics: kin privacy, driftnets and other open questions (co-authored with Lucia Bianchi, Pietro Liò and Douwe Korff ) at WPES 2008 , the Workshop for...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.cl.cam.ac.uk/~fms27/">I</a> recently presented a paper on <a href="http://www.cl.cam.ac.uk/~fms27/papers/2008-StajanoBiaLioKor-genomics.pdf"><em>Forensic genomics: kin privacy, driftnets and other open questions</em></a> (co-authored with Lucia Bianchi, <a href="http://www.cl.cam.ac.uk/~pl219/">Pietro Liò</a> and <a href="http://www.londonmet.ac.uk/research-units/hrsj/staff/douwe-korff.cfm">Douwe Korff</a>) at <a href="http://dais.cs.uiuc.edu/wpes08/">WPES 2008</a>, the Workshop for Privacy in the Electronic Society of <a href="http://www.sigsac.org/ccs/CCS2008/">ACM CCS</a>, the ACM Computer and Communication Security</a> conference. Pietro and I also gave a <a href="http://talks.cam.ac.uk/talk/index/13300">related talk</a> here at the Computer Laboratory in Cambridge.</p>
<p>While <a href="http://en.wikipedia.org/wiki/Genetics">genetics</a> is concerned with the observation of specific sections of DNA, genomics is about studying the entire <a href="http://en.wikipedia.org/wiki/Genome">genome </a> of an organism, something that has only become practically possible in recent years. In forensic genetics, which is the technology behind the large national DNA databases being built in several countries including notably UK and USA (<a href="http://www.nature.com/embor/journal/v7/n1s/pdf/7400727.pdf">Wallace&#8217;s outstanding article</a> lucidly exposes many significant issues), investigators compare scene-of-crime samples with database samples by checking if they match, but only on a very small number of specific locations in the genome (e.g. 13 locations according to the <a href="http://en.wikipedia.org/wiki/Codis">CODIS</a> rules). In our paper we explore what might change when forensic analysis moves from genetics to genomics over the next few decades. This is a problem that can only be meaningfully approached from a multi-disciplinary viewpoint and indeed our combined backgrounds cover computer security, bioinformatics and law.</p>
<p><img src="http://upload.wikimedia.org/wikipedia/commons/7/7a/Codis_profile.jpg" alt="CODIS markers" /><em><br />
(Image from <a href="http://en.wikipedia.org/wiki/Image:Codis_profile.jpg">Wikimedia commons</a>, in turn from <a href="http://www.cstl.nist.gov/div831/strbase/fbicore.htm">NIST</a>.)</em></p>
<p>Sequencing the first human genome (2003) cost 2.7 billion dollars and took 13 years. The US&#8217;s National Human Genome Research Institute has <a href="http://www.medicalnewstoday.com/articles/118963.php">offered over 20 M$ worth of grants</a> towards the goal of <a href="http://www.genome.gov/27527584">driving the cost of whole-genome sequencing down to a thousand dollars</a>. This will enable <a href="http://en.wikipedia.org/wiki/Personal_genomics">personalized genomic medicine</a> (e.g. predicting genetic risk of contracting specific diseases) but will also open up a number of ethical and privacy-related problems. Eugenetic abortions, genomic pre-screening as precondition for healthcare (or even just dating&#8230;), (mis)use of genomic data for purposes other than that for which it was collected and so forth. In various jurisdictions there exists legislation (such as the recent <a href="http://www.govtrack.us/congress/billtext.xpd?bill=h110-493&amp;show-changes=0&amp;page-command=print">GINA</a> in the US) that attempts to protect citizens from some of the possible abuses; but how strongly is it enforced? And is it enough? In the forensic context, is the DNA analysis procedure as infallible as we are led to believe? There are many subtleties associated with the interpretation of statistical results; when even professional statisticians disagree, how are the poor jurors expected to reach a fair verdict? Another subtle issue is kin privacy: if the scene-of-crime sample, compared with everyone in the database, partially matches Alice, this may be used as a hint to investigate all her relatives, who aren&#8217;t even in the database; indeed, some 1980s murders were recently solved in this way. &#8220;This raises compelling policy questions about the balance between collective security and individual privacy&#8221; [<a href="http://www.sciencemag.org/cgi/content/full/sci;312/5778/1315">Bieber, Brenner, Lazer, 2006</a>]. Should a democracy allow such a &#8220;driftnet&#8221; approach of suspecting and investigating all the innocents in order to catch the guilty?</p>
<p>This is a paper of questions rather than one of solutions. We believe an informed public debate is needed <em>before</em> the expected transition from genetics to genomics takes place. We want to stimulate discussion and therefore we invite you to read the paper, make up your mind and support what you believe are the right answers.</p>
]]></content:encoded>
      <pubDate>Thu, 27 Nov 2008 12:58:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/genomics">genomics</category>
      <category domain="http://securityratty.com/tag/forensic genomics">forensic genomics</category>
      <category domain="http://securityratty.com/tag/privacy">privacy</category>
      <category domain="http://securityratty.com/tag/individual privacy">individual privacy</category>
      <category domain="http://securityratty.com/tag/dna">dna</category>
      <category domain="http://securityratty.com/tag/national dna databases">national dna databases</category>
      <category domain="http://securityratty.com/tag/genome">genome</category>
      <category domain="http://securityratty.com/tag/whole-genome">whole-genome</category>
      <category domain="http://securityratty.com/tag/kin privacy">kin privacy</category>
      <source url="http://www.lightbluetouchpaper.org/2008/11/27/forensic-genomics/">Forensic genomics</source>
    </item>
    <item>
      <title><![CDATA[Zermatt is now Geneva Framework]]></title>
      <link>http://securityratty.com/article/ffdbf806596ce2b9eecd4ab50a7394dc</link>
      <guid>http://securityratty.com/article/ffdbf806596ce2b9eecd4ab50a7394dc</guid>
      <description><![CDATA[For those who didn't attend PDC, the Zermatt identity framework has been re-code-named Geneva Framework so that it fits in with the Geneva family of products
Geneva Framework : a .NET class library...]]></description>
      <content:encoded><![CDATA[<p>For those who didn&#39;t attend PDC, the <a href="http://www.pluralsight.com/community/blogs/keith/archive/2008/07/09/introducing-microsoft-code-name-zermatt.aspx">Zermatt identity framework</a> has been re-code-named Geneva Framework so that it fits in with the <a href="http://www.microsoft.com/geneva" target="_blank">Geneva family of products</a>:</p>
<p><a href="http://blogs.msdn.com/card/archive/2008/11/04/microsoft-geneva-framework.aspx" target="_blank">Geneva Framework</a>: a .NET class library called Microsoft.IdentityModel (basically it&#39;s an updated Zermatt)</p>
<p><a href="http://blogs.msdn.com/card/archive/2008/11/04/geneva-server-beta.aspx" target="_blank">Geneva Server</a>: This is essentially ADFS v2, built on top of the Geneva Framework</p>
<p><a href="http://blogs.msdn.com/card/archive/2008/11/18/the-cardspace-geneva-selection-experience.aspx" target="_blank">Geneva CardSpace</a>: This is CardSpace v2.</p>
<p>This link takes you to the &quot;Geneva&quot; landing page at Microsoft, where you&#39;ll find links to all of the bits, as well as the whitepaper v2. The new version of the whitepaper was co-authored by myself and a PM on the Geneva Framework team, Sesha Mani, who added a bunch of new details based on the PDC version of the framework.</p><div style="clear:both;"></div><img src="http://www.pluralsight.com/community/aggbug.aspx?PostID=55244" width="1" height="1">]]></content:encoded>
      <pubDate>Wed, 26 Nov 2008 11:41:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/geneva">geneva</category>
      <category domain="http://securityratty.com/tag/geneva framework">geneva framework</category>
      <category domain="http://securityratty.com/tag/zermatt">zermatt</category>
      <category domain="http://securityratty.com/tag/framework">framework</category>
      <category domain="http://securityratty.com/tag/geneva family">geneva family</category>
      <category domain="http://securityratty.com/tag/zermatt identity framework">zermatt identity framework</category>
      <category domain="http://securityratty.com/tag/geneva cardspace">geneva cardspace</category>
      <category domain="http://securityratty.com/tag/cardspace">cardspace</category>
      <category domain="http://securityratty.com/tag/geneva framework team">geneva framework team</category>
      <source url="http://www.pluralsight.com/community/blogs/keith/archive/2008/11/26/zermatt-is-now-geneva-framework.aspx">Zermatt is now Geneva Framework</source>
    </item>
    <item>
      <title><![CDATA[Localizing Cybercrime - Cultural Diversity on Demand Part Two]]></title>
      <link>http://securityratty.com/article/6fa5c311a11504a21120c6a907e03041</link>
      <guid>http://securityratty.com/article/6fa5c311a11504a21120c6a907e03041</guid>
      <description><![CDATA[It's where you advertise your services, and how you position yourself that speak for your intentions, of course, &quot;between the lines&quot;. There's a common misunderstanding that in order for a malware...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SSv52TmaA2I/AAAAAAAACec/W3ErlbR-fSo/s1600-h/translation_service_cybercrime.JPG" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/SSv52TmaA2I/AAAAAAAACec/W3ErlbR-fSo/s200/translation_service_cybercrime.JPG" /></a> It's where you advertise your services, and how you position yourself that speak for your intentions, of course, "between the lines". There's a common misunderstanding that in order for a malware campaigner or scammer to launch a localized attack speaking the native language of their potential victims, they need to speak the local language. This misconception is largely based on the fact that a huge number of people remain unaware on how core strategic business practices have been in operation across the cybercrime underground for the last couple of years.<br />
<br />
<a href="http://ddanchev.blogspot.com/2008/02/localizing-cybercrime-cultural.html">Outsourcing the localization process</a> (translation services for spam/phishing/malware campaigns) has been happening for a while, courtsy of DIY servics ensuring complete anonymity of their customers. Interestingly, the translators may in fact be unaware that the advertising channels the service is using is directly attracting everyone from the bottom to the top of the cybercriminal food chain as a customer. Sometimes, it's services like this that open a new market segment covering an untapped opportunity, with this particular service already pointing out that it's charging cheaper than their competitors.<br />
<br />
"<i>We offer our services in translation. We are only competent translators profile higher education. Service is working with all types of texts. Languages available at this time of Russian, English, German. Average translation of the text takes up to 10 hours (usually much faster) through the full automation of the order and payment. <b>Just want to note that we do not keep any logs on IP and does not require registration</b>. In addition you can remove your order from the database after his execution. In addition to running more than 1000 translations already, we can use all the lessons learned to be more effective in our services. Prices vary depending on the complexity of the topic covered.</i><br />
<br />
<i><b>Prices and deadlines:  </b><br />
* Standard - the deadline is not more than 24 hours. Prices depend on the direction and guidance from the 'Order'.&nbsp;</i><br />
<i>* Term - work on your translation begins precedence. The price of the 50% more than the standard translation. Prices also depend on the direction and guidance from the 'Order'. <br />
<br />
The cost of the transfer depends on the amount of work. The workload is measured in symbols. In calculating the characters are shown letters and numbers. Punctuation do not count. Minimum order 100 characters.</i>"<br />
<br />
I'm particularly curious how is a contractor(translator) going to react to a situation when a large scale malware campaign speaking several different languages tell a fake story that the contractor might have recently translated for them. With the employer positioning itself as a fully legitimate company, whereas its customers requesting localized version of texts for the spam/phishing/malware campaigns are the "usual suspects", the contractors would continue allowing cybercriminals the opportunity to build more authenticity within their campaigns.<br />
<br />
<b>Related posts:</b><br />
<a href="http://ddanchev.blogspot.com/2008/01/e-crime-and-socioeconomic-factors.html">E-crime and Socioeconomic Factors</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/mpack-and-icepack-localized-to-chinese.html">MPack and IcePack Localized to Chinese</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/icepack-exploitation-kit-localized-to.html">The Icepack Exploitation Kit Localized to French</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/firepack-exploitation-kit-localized-to.html">The FirePack Exploitation Kit Localized to Chinese</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/localizing-open-source-malware.html">Localizing Open Source Malware</a><br />
<a href="http://ddanchev.blogspot.com/2008/04/localized-fake-security-software.html">Localized Fake Security Software</a><br />
<a href="http://ddanchev.blogspot.com/2008/03/localized-bankers-malware-campaign.html">A Localized Bankers Malware Campaign</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/lonely-polinas-secret.html">Lonely Polina's Secret</a> (Localized malware campaign)<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=jtrxN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=jtrxN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=MlKUN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=MlKUN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=x6kTn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=x6kTn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=NtZ5n"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=NtZ5n" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=11AEN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=11AEN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=KL4TN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=KL4TN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=BB2Un"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=BB2Un" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/465119206" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 05:55:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/translation">translation</category>
      <category domain="http://securityratty.com/tag/standard translation">standard translation</category>
      <category domain="http://securityratty.com/tag/average translation">average translation</category>
      <category domain="http://securityratty.com/tag/translation services">translation services</category>
      <category domain="http://securityratty.com/tag/malware campaign">malware campaign</category>
      <category domain="http://securityratty.com/tag/bankers malware campaign">bankers malware campaign</category>
      <category domain="http://securityratty.com/tag/prices">prices</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/prices vary">prices vary</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/465119206/localizing-cybercrime-cultural.html">Localizing Cybercrime - Cultural Diversity on Demand Part Two</source>
    </item>
    <item>
      <title><![CDATA[Symantec takes cybercrime snapshot with 'Underground Economy' report]]></title>
      <link>http://securityratty.com/article/1372806ad60aee438b9a56d4c8eebbfb</link>
      <guid>http://securityratty.com/article/1372806ad60aee438b9a56d4c8eebbfb</guid>
      <description><![CDATA[The criminal market online for buying and selling stolen credit cards, pirated software and information about financial accounts is thriving, according to a Symantec report published...]]></description>
      <content:encoded><![CDATA[The criminal market online for buying and selling stolen credit cards, pirated software and information about financial accounts is thriving, according to a Symantec report published Monday.]]></content:encoded>
      <pubDate>Sun, 23 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/criminal market online">criminal market online</category>
      <category domain="http://securityratty.com/tag/credit cards">credit cards</category>
      <category domain="http://securityratty.com/tag/financial accounts">financial accounts</category>
      <category domain="http://securityratty.com/tag/symantec report">symantec report</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/monday">monday</category>
      <source url="http://www.networkworld.com/news/2008/112408-symantec-underground-economy-report.html?fsrc=rss-security">Symantec takes cybercrime snapshot with 'Underground Economy' report</source>
    </item>
    <item>
      <title><![CDATA[Opinion: Obama's Blackberry Is No Security Threat]]></title>
      <link>http://securityratty.com/article/e87ac9b85b1440c70317a2e3c99bc69a</link>
      <guid>http://securityratty.com/article/e87ac9b85b1440c70317a2e3c99bc69a</guid>
      <description><![CDATA[A lot of the stories about President-Elect Barack Obama possibly having to relinquish his BlackBerry when he takes office Jan. 20 are, for a variety of reasons, just plain dumb
Presented By
Expedition...]]></description>
      <content:encoded><![CDATA[A lot of the stories about President-Elect Barack Obama possibly having to relinquish his BlackBerry when he takes office Jan. 20 are, for a variety of reasons, just plain dumb.<br style="clear: both;"/>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:ec05a75c51a0c57bf749dc34de320338:9saJDFUNixvCt9W%2FnAURKdwA2cqnMddIgJicBm8aa7XRGqSr3d0tP4bmhbLQU11krWw1pJd5zPcU'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:ee597d2c1bb98b27efdcaefe8ebb3f75:EF6STR8ij2QRJ8xF4MBcoSPj2lJwQex7OGQm3R4yzLgsLbUdOaDqd300xLdPMY8UCWy9otIBA7UvIQ%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:d51c69caef3a79fa989b3a7574d817cb:uzyMPJwsArJb1adLPnID9o%2BjzBNZTeavL38C94JxNqfi1Cu7ClBDRM2SRcEXd0Rorv8gufvurWb2Vw%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
  <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:42f0cd0844493e4e350b139fc5b4aac4:MXMK2lz0WWHJX0PP4CSpEs7sIpFYH2zP5xNyh3ZAJhafvgGgWMApfnlvI1ecgN6drJ%2B6%2B12av%2F4TCA%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>
<hr />
<div style="font-size:xx-small;color:gray;padding-bottom:.5em">Presented By:</div>
<div><a href="http://www.pheedo.com/feeds/ht.php?t=c&amp;i=f38edf875ae6f3723280e92fea392c4c&amp;p=1">Expedition Week Continues Tonight</a></div>
<table border="0" cellpadding="0" cellspacing="0">
<tr><td valign="top"><embed src="http://services.brightcove.com/services/viewer/federated_f8/1902560944" bgcolor="#FFFFFF" flashVars="playerId=1902560944&viewerSecureGatewayURL=https://console.brightcove.com/services/amfgateway&servicesURL=http://services.brightcove.com/services&cdnURL=http://admin.brightcove.com&domain=embed&autoStart=false&" base="http://admin.brightcove.com" name="flashObj" width="300" height="250" seamlesstabbing="false" type="application/x-shockwave-flash" swLiveConnect="true" pluginspage="http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash"></embed><br />
<br /><img src="http://images.pheedo.com/g/ngc/natgeologo_80x60.jpg"><br />
<font size="2" face="helvetica" >Seven nights of one great discovery after another continues tonight at 9P e/p only on National Geographic Channel.  From the ancient pyramids to the ocean depths, from lost cities to outer space, travel with the latest generation of intrepid explorers as they make one great discovery after another.  Expedition Week, only on National Geographic Channel.</font><br />
<a href="http://www.pheedo.com/click.phdo?a=v3%3Ac1abad0b6daa4d28e9a527be56ca4e2f%3As2rmGnBOH62ZTX7YSZtUtsuGGEa8BJPlu%2FnPAP5iBIxxx5lnUHVgxgWtXjRC%2BL9X6noRAJMryZFAD1poPIhkf6cQxJS8bBfGwQlOn880Zw7JEF%2BMyg8FaI55gEz%2FwsMAIsKOYGloldTlO7L2E7%2FRMBd5jFHoF%2BTSxltqVyVuyH%2BRkxk%3D" target="_blank">www.natgeotv.com/expedition</font><br />
</a></td></tr>
<tr><td>&nbsp;</td></tr>
</table>
<div style="font-size:xx-small; padding-top: 1em;"><span style="border-top: 1px solid">
<br style="display:none"/>
<a href="http://www.pheedo.com/">Ads by Pheedo</a>
</span><img alt="" style="border: 0; height: 1px; width: 1px;" border="0" height="1" width="1" src="http://www.pheedo.com/feeds/ht.php?t=v&amp;i=f38edf875ae6f3723280e92fea392c4c&amp;p=1"/>
<br/>
</div>
]]></content:encoded>
      <pubDate>Thu, 20 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/national geographic channel">national geographic channel</category>
      <category domain="http://securityratty.com/tag/takes office jan">takes office jan</category>
      <category domain="http://securityratty.com/tag/plain dumb">plain dumb</category>
      <category domain="http://securityratty.com/tag/continues tonight">continues tonight</category>
      <category domain="http://securityratty.com/tag/blackberry">blackberry</category>
      <category domain="http://securityratty.com/tag/intrepid explorers">intrepid explorers</category>
      <category domain="http://securityratty.com/tag/expedition week">expedition week</category>
      <category domain="http://securityratty.com/tag/discovery">discovery</category>
      <category domain="http://securityratty.com/tag/ancient pyramids">ancient pyramids</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=f38edf875ae6f3723280e92fea392c4c">Opinion: Obama's Blackberry Is No Security Threat</source>
    </item>
    <item>
      <title><![CDATA[CISSPs Lend me your ears]]></title>
      <link>http://securityratty.com/article/2f51be6dbed18127b772146d8ca86adc</link>
      <guid>http://securityratty.com/article/2f51be6dbed18127b772146d8ca86adc</guid>
      <description><![CDATA[Art of Information Security endorses Dan Houser for(ISC)²Board of Directors
The CISSP isundoubtablyone of the most, if not the most, important professional certifications in Information Security....]]></description>
      <content:encoded><![CDATA[<p><strong>Art of Information Security endorses Dan Houser for (ISC)² Board of Directors</strong></p>
<p>The CISSP is undoubtably one of the most, if not the most, important professional certifications in Information Security. Many organizations and practitioners rely on it as evidence of a solid foundation and track record in Information Security. But the CISSP is only one of the many ways that the (ISC)² attempts to fulfill its mission of developing the Information Security profession.</p>
<p>Board membership is a role of governance, guidance, and passion. Let&#8217;s briefly explore how Dan&#8217;s track record and past contributions demonstrate his qualification for this post, and possibly your vote.</p>
<p><strong>Passion</strong></p>
<p>Dan is someone who has a passion for promoting and developing the talent needed to continue to grow and mature our profession. Anyone who has seen Dan speak at conferences, local chapter meetings, or in one of his classes knows how passionate Dan is! But anyone who takes the time to approach him knows that he is no ideologue or zealot; Dan is always interested in improving his own understanding, and then sharing that knowledge with others.</p>
<p>Dan has a long track record as a contributor - as a &#8220;giver&#8221; - to the profession. In addition to teaching over a dozen CISSP review courses, he has also served on multiple (ISC)² committees, is one of the authors of the ISSAP Body of Knowledge (cryptography), and has published primary research on professional certifications. He is also the founder of the monthly Columbus, Ohio Information Security MBA (Masters of Beer Appreciation) meeting - a professional roundtable that attracts practitioners from across the state.</p>
<p><strong>Governance and Guidance <br />
</strong></p>
<p>In addition to past experience serving on (ISC)² committees, which I assume led to the current board&#8217;s nomination, Dan has served on numerous Boards of Directors including local and regional community organizations, ISSA chapters,and several Toastmasters clubs. </p>
<p><strong>Personal Experiences</strong></p>
<p>I have known Dan for almost three yeas. Dan and I have collaborated on a number or projects, including a half-day Cryptographic Controls Seminar and a full-day Identity Management Architecture class. It is my feeling that when you collaborate, work closely, and travel with someone, you really get to know them. You get to do more than hear about their College Sweethearts (which, for Dan, is Rebecca, his wife of 21 years), but you also get to understand their ethics, how they really conduct themselves, how they deal with stress, etc.</p>
<p>Given the entire picture, the understanding that I have of Dan Houser, I can think of no one better suited to representing, guiding and developing the (ISC)². I have voted for Dan, and I hope that you will consider doing the same.</p>
<p>Here is the voting link for (ISC)²: <a href="https://webportal.isc2.org/custom/votenow.aspx%20" onclick="javascript:pageTracker._trackPageview('/outbound/article/https://webportal.isc2.org/custom/votenow.aspx%20');" target="_blank">https://webportal.isc2.org/custom/votenow.aspx</a></p>
<p>Cheers, Erik</p>
<p></p>
<p><a href="http://artofinfosec.com/105/cissps-lend-me-your-ears/" >CISSPs&#8230; Lend me your ears&#8230;</a></p>
<img src="http://feeds.feedburner.com/~r/artofinfosec/~4/456765137" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 01:15:31 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dan">dan</category>
      <category domain="http://securityratty.com/tag/dan houser">dan houser</category>
      <category domain="http://securityratty.com/tag/dan foralmostthree yeas">dan foralmostthree yeas</category>
      <category domain="http://securityratty.com/tag/dans track record">dans track record</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/track record">track record</category>
      <category domain="http://securityratty.com/tag/information security profession">information security profession</category>
      <category domain="http://securityratty.com/tag/isc">isc</category>
      <category domain="http://securityratty.com/tag/profession">profession</category>
      <source url="http://feeds.feedburner.com/~r/artofinfosec/~3/456765137/">CISSPs Lend me your ears</source>
    </item>
    <item>
      <title><![CDATA[It's all about getting the job done, unfortunately]]></title>
      <link>http://securityratty.com/article/6028d5bb121d67465c28c3635c2c899d</link>
      <guid>http://securityratty.com/article/6028d5bb121d67465c28c3635c2c899d</guid>
      <description><![CDATA[Managers expect users to meet certain performance levels. Users, being human, do whatever it takes to meet management's expectations. So why, when we don't provide an alternative, do we bemoan...]]></description>
      <content:encoded><![CDATA[Managers expect users to meet certain performance levels.  Users, being human, do whatever it takes to meet management's expectations.  So why, when we don't provide an alternative, do we bemoan continued bad behavior.]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 10:09:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/managers expect users">managers expect users</category>
      <category domain="http://securityratty.com/tag/bad behavior">bad behavior</category>
      <category domain="http://securityratty.com/tag/performance levels">performance levels</category>
      <category domain="http://securityratty.com/tag/human">human</category>
      <category domain="http://securityratty.com/tag/expectations">expectations</category>
      <category domain="http://securityratty.com/tag/provide">provide</category>
      <category domain="http://securityratty.com/tag/takes">takes</category>
      <category domain="http://securityratty.com/tag/alternative">alternative</category>
      <source url="http://networking.ittoolbox.com/r/rss.asp?url=http://it.toolbox.com/blogs/adventuresinsecurity/its-all-about-getting-the-job-done-unfortunately-28349">It's all about getting the job done, unfortunately</source>
    </item>
    <item>
      <title><![CDATA[Attacks On Banks]]></title>
      <link>http://securityratty.com/article/788a3c9a82e042e1d445b41303e5e129</link>
      <guid>http://securityratty.com/article/788a3c9a82e042e1d445b41303e5e129</guid>
      <description><![CDATA[This article provides an overview of the methods currently used by cyber criminals to attack financial institutions and banks in particular. It reviews general trends and takes how malicious...]]></description>
      <content:encoded><![CDATA[This article provides an overview of the methods currently used by cyber criminals to attack financial institutions and banks in particular. It reviews general trends and takes how malicious programs ...]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 03:15:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attack financial institutions">attack financial institutions</category>
      <category domain="http://securityratty.com/tag/malicious programs">malicious programs</category>
      <category domain="http://securityratty.com/tag/banks">banks</category>
      <category domain="http://securityratty.com/tag/cyber criminals">cyber criminals</category>
      <category domain="http://securityratty.com/tag/reviews">reviews</category>
      <category domain="http://securityratty.com/tag/overview">overview</category>
      <category domain="http://securityratty.com/tag/trends">trends</category>
      <category domain="http://securityratty.com/tag/takes">takes</category>
      <category domain="http://securityratty.com/tag/article">article</category>
      <source url="http://www.net-security.org/article.php?id=1189">Attacks On Banks</source>
    </item>
    <item>
      <title><![CDATA[Events per Second the difference between a target and an assurance]]></title>
      <link>http://securityratty.com/article/f9815504814bde06b74afe918ec8d827</link>
      <guid>http://securityratty.com/article/f9815504814bde06b74afe918ec8d827</guid>
      <description><![CDATA[Weve been getting a good few questions recently about how many Events Per Second a SIEM product support. Well, that depends on a few factors
The transport processing Syslog events takes up a heck of a...]]></description>
      <content:encoded><![CDATA[<p>We&rsquo;ve been getting a good few questions recently about how many Events
  Per Second a SIEM product support. Well, that depends on a few factors:</p>

<ul>
  <li><strong>The transport</strong> &ndash; processing Syslog events takes up
    a heck of a lot less processing power than collecting from a Windows box.
    Same with collecting data over an ODBC connection.</li>
</ul>]]></content:encoded>
      <pubDate>Sun, 16 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/events">events</category>
      <category domain="http://securityratty.com/tag/syslog events takes">syslog events takes</category>
      <category domain="http://securityratty.com/tag/siem product support">siem product support</category>
      <category domain="http://securityratty.com/tag/windows box">windows box</category>
      <category domain="http://securityratty.com/tag/questions recently">questions recently</category>
      <category domain="http://securityratty.com/tag/odbc connection">odbc connection</category>
      <category domain="http://securityratty.com/tag/lot">lot</category>
      <category domain="http://securityratty.com/tag/transport">transport</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1390">Events per Second the difference between a target and an assurance</source>
    </item>
  </channel>
</rss>
