<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: telecom]]></title>
    <link>http://securityratty.com/tag/telecom</link>
    <description></description>
    <pubDate>Thu, 10 Jul 2008 10:18:03 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Blue Box #84: New Cisco, Avaya, Nortel VoIP security vulnerabilities from VoIPShield, Skype in China, UCSniff and other new tools, news and more]]></title>
      <link>http://securityratty.com/article/5ad9e83dc3458677a18e9f3f40c0fb21</link>
      <guid>http://securityratty.com/article/5ad9e83dc3458677a18e9f3f40c0fb21</guid>
      <description><![CDATA[Synopsis: Blue Box #84: New Cisco, Avaya, Nortel VoIP security vulnerabilities from VoIPShield, Skype in China, UCSniff and other new tools, news and more
Welcome to Blue Box: The VoIP Security...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Synopsis:</strong>&nbsp; Blue Box #84: New Cisco, Avaya, Nortel VoIP security vulnerabilities
from VoIPShield, Skype in China, UCSniff and other new tools, news and
more

</p><hr /><p>Welcome to <strong>Blue Box: The VoIP Security Podcast</strong> #84, a 30-minute podcast&nbsp; from Dan York and Jonathan Zar covering VoIP security news, comments and opinions.&nbsp; &nbsp; </p>

<p><a href="http://media.libsyn.com/media/lodestar/BBP-084-2008-10-10.mp3" rel="enclosure">Download the show here</a> (MP3, MB) or <a href="http://feeds.feedburner.com/BlueBox">subscribe to the RSS feed</a> to download the show automatically.&nbsp; </p>

 

<p>You may also listen to this podcast right now:</p> 

<p><object width="200" height="20" type="application/x-shockwave-flash" data="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-084-2008-10-10.mp3"><param name="movie" value="http://www.blueboxpodcast.com/dewplayer.swf?son=http://media.libsyn.com/media/lodestar/BBP-084-2008-10-10.mp3&amp;bgcolor=#FFFFFF" /></object> </p> 

<p><strong>Show Content:</strong></p> 
 


	<ul> <li>00:20 - Intro to the show, contact information and how to provide comments.&nbsp; Welcome to all the new listeners - and to all those listeners who have been here for so long!</li>
<li>Programming notes:
	<ul>
	<li>Three-year anniversary of Blue Box coming up on October 24th - any thoughts you'd like to share with us? (Please send them to us by October 23rd.)</li>
		
	</ul>
</li>

<li><a href="http://www.marketwatch.com/news/story/voipshield-uncovers-new-security-vulnerabilities/story.aspx?guid=%7B956C0D98-121F-4E95-BC14-3B5F448AF25A%7D&amp;dist=hppr">VoIPShield announces new vulnerabilities</a> and <a id="r9se" href="http://www.voipshield.com/research.php" title="http://www.voipshield.com/research.php">http://www.voipshield.com/research.php</a></li>

<li><span style="font-family: Arial;"><a href="http://www.theregister.co.uk/2008/09/30/voip_eavesdropping_tool">http://www.theregister.co.uk/2008/09/30/voip_eavesdropping_tool</a><span style="font-size: 0.8em;">/</span></span></li>

<li><span style="font-family: Arial;"><span style="font-size: 0.8em;">&quot;Sipera Develops VoIP Spy Program - to Prove a Point&quot; - <a title="http://www.voipplanet.com/trends/article.php/3776136" href="http://www.voipplanet.com/trends/article.php/3776136" id="gfhu">http://www.voipplanet.com/trends/article.php/3776136</a></span></span></li>

<li><span style="font-family: Arial;"><span style="font-size: 0.8em;"><a href="http://www.marketwatch.com/news/story/securelogix-announces-free-availability-voip/story.aspx?guid=%7BF1947C89-8177-4FA2-A40E-8D6E021BF558%7D&amp;dist=hppr">SecureLogix Announces Free Availability of VoIP Security Tools</a></span></span></li>

<li>NY Times: Surveillance of Skype Messages Found in China - <a title="http://www.nytimes.com/2008/10/02/technology/internet/02skype.html?_r=2&amp;partner=rssnyt&amp;pagewanted=print" href="http://www.nytimes.com/2008/10/02/technology/internet/02skype.html?_r=2&amp;partner=rssnyt&amp;pagewanted=print" id="dnb2">http://www.nytimes.com/2008/10/02/technology/internet/02skype.html?_r=2&amp;partner=rssnyt&amp;pagewanted=print</a> </li>

<li><a title="http://securitywatch.eweek.com/privacy/skypechina_breach_is_anyone_really_surprised.html" href="http://securitywatch.eweek.com/privacy/skypechina_breach_is_anyone_really_surprised.html" id="i8rz">http://securitywatch.eweek.com/privacy/skypechina_breach_is_anyone_really_surprised.html</a> </li>

<li><a title="http://www.informationweek.com/news/telecom/voip/showArticle.jhtml?articleID=210605439" href="http://www.informationweek.com/news/telecom/voip/showArticle.jhtml?articleID=210605439" id="ugx5">http://www.informationweek.com/news/telecom/voip/showArticle.jhtml?articleID=210605439</a> </li>

<li>Skype CEO's blog post about the issue: <a title="http://share.skype.com/sites/en/2008/10/answers_to_some_commonly_asked.html" href="http://share.skype.com/sites/en/2008/10/answers_to_some_commonly_asked.html" id="mucu">http://share.skype.com/sites/en/2008/10/answers_to_some_commonly_asked.html</a></li>

<li><span style="font-family: Arial;"><a title="http://www.itbusinessedge.com/blogs/top/?p=398" href="http://www.itbusinessedge.com/blogs/top/?p=398">http://www.itbusinessedge.com/blogs/top/?p=398</a></span></li>

<li><span style="font-family: Arial;"><a title="http://www.voip-news.com/feature/google-phone-europe-growth-092408/" href="http://www.voip-news.com/feature/google-phone-europe-growth-092408/">http://www.voip-news.com/feature/google-phone-europe-growth-092408/</a></span></li>

<li><span style="font-family: Arial;"><a title="http://www.itnewsafrica.com/?p=1269" href="http://www.itnewsafrica.com/?p=1269">http://www.itnewsafrica.com/?p=1269</a></span></li>

<li><span style="font-family: Arial;"><a title="http://news.cnet.com/8301-1009_3-10052393-83.html" href="http://news.cnet.com/8301-1009_3-10052393-83.html">http://news.cnet.com/8301-1009_3-10052393-83.html</a></span></li>

<li><span style="font-family: Arial;"><a title="http://www.broadbandreports.com/shownews/VoIP-Vulnerabilities-Being-Exposed-Today-98039" href="http://www.broadbandreports.com/shownews/VoIP-Vulnerabilities-Being-Exposed-Today-98039">http://www.broadbandreports.com/shownews/VoIP-Vulnerabilities-Being-Exposed-Today-98039</a></span></li>

<li><span style="font-family: Arial;"><a title="http://www.itbusinessedge.com/blogs/top/?p=402" href="http://www.itbusinessedge.com/blogs/top/?p=402">http://www.itbusinessedge.com/blogs/top/?p=402</a></span></li>

<li><span style="font-family: Arial;"><a id="tvjh" href="http://voipsa.org/blog/2008/10/07/5th-emergency-services-workshop-to-be-held-oct-21-23-in-vienna/" title="http://voipsa.org/blog/2008/10/07/5th-emergency-services-workshop-to-be-held-oct-21-23-in-vienna/">http://voipsa.org/blog/2008/10/07/5th-emergency-services-workshop-to-be-held-oct-21-23-in-vienna/</a></span></li>

<li><span style="font-family: Arial;"><a title="http://eon.businesswire.com/news/eon/20080924005342/en" href="http://eon.businesswire.com/news/eon/20080924005342/en">http://eon.businesswire.com/news/eon/20080924005342/en</a></span></li>

<li><span style="font-family: Arial;"><a title="http://www.crn.com/security/210602442" href="http://www.crn.com/security/210602442">http://www.crn.com/security/210602442</a></span></li>

<li><span style="font-family: Arial;"><a title="http://it.tmcnet.com/topics/it/articles/41236-infoblox-unveils-dns-firewall-address-dns-vulnerability-concerns.htm" href="http://it.tmcnet.com/topics/it/articles/41236-infoblox-unveils-dns-firewall-address-dns-vulnerability-concerns.htm">http://it.tmcnet.com/topics/it/articles/41236-infoblox-unveils-dns-firewall-address-dns-vulnerability-concerns.htm</a></span></li>

<li><span style="font-family: Arial;"><a title="http://www.newswire.ca/en/releases/archive/September2008/29/c9005.html" href="http://www.newswire.ca/en/releases/archive/September2008/29/c9005.html">http://www.newswire.ca/en/releases/archive/September2008/29/c9005.html</a></span></li>

<li>No comments this week.<br />
</li>

<li>Review of the last week's traffic on the <a href="http://www.voipsa.org/VOIPSEC/">VOIPSEC </a>public mailing list<br />
</li>

<li>Wrap-up of the show<br />
</li>

<li>30:26 - End of show&nbsp; </li></ul> <p><em>NOTE: Long-time listeners will note that the show notes above are in a less descriptive form than usual. After almost three years of using one wiki for preparing for our shows, Jonathan and I switched to using a new system and are still working out some of the details that will speed the input into show notes. </em></p>

<p>Comments, suggestions and feedback are welcome either as replies to this post&nbsp; or via e-mail to <a href="mailto:blueboxpodcast@gmail.com">blueboxpodcast@gmail.com</a>.&nbsp; Audio comments sent as attached MP3 files are definitely welcome and will be played in future shows.&nbsp; You may also call the listener comment line at either +1-415-830-5439 or via SIP to '<a href="sip:bluebox@voipuser.org">bluebox@voipuser.org</a>' to leave a comment there.&nbsp; </p> <p>Thank you for listening and please do let us know what you think of the show. </p></div>

<p><a href="http://feeds.feedburner.com/~a/BlueBox?a=vzRu3i"><img src="http://feeds.feedburner.com/~a/BlueBox?i=vzRu3i" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BlueBox?a=MSaWM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=MSaWM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=Uy3HM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=Uy3HM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=yGFHM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=yGFHM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=eCUOM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=eCUOM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=ZOgKm"><img src="http://feeds.feedburner.com/~f/BlueBox?i=ZOgKm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BlueBox?a=5vEnM"><img src="http://feeds.feedburner.com/~f/BlueBox?i=5vEnM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BlueBox/~4/426417749" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 20 Oct 2008 04:32:28 +0000</pubDate>
      <category domain="http://securityratty.com/tag/skype">skype</category>
      <category domain="http://securityratty.com/tag/blue box">blue box</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/voipshield">voipshield</category>
      <category domain="http://securityratty.com/tag/comments">comments</category>
      <category domain="http://securityratty.com/tag/audio comments">audio comments</category>
      <category domain="http://securityratty.com/tag/podcast">podcast</category>
      <category domain="http://securityratty.com/tag/skype messages">skype messages</category>
      <source url="http://feeds.feedburner.com/~r/BlueBox/~3/426417749/blue-box-84-new.html">Blue Box #84: New Cisco, Avaya, Nortel VoIP security vulnerabilities from VoIPShield, Skype in China, UCSniff and other new tools, news and more</source>
    </item>
    <item>
      <title><![CDATA[EFF, ACLU slam carrier immunity law]]></title>
      <link>http://securityratty.com/article/644527098fb8a2b3f5fb0e535ccabda4</link>
      <guid>http://securityratty.com/article/644527098fb8a2b3f5fb0e535ccabda4</guid>
      <description><![CDATA[A U.S. law that allows telecom carriers to be granted immunity in some suits alleging illegal government surveillance is unconstitutional, two civil-rights groups argued late...]]></description>
      <content:encoded><![CDATA[A U.S. law that allows telecom carriers to be granted immunity in some suits alleging illegal government surveillance is unconstitutional, two civil-rights groups argued late Thursday.]]></content:encoded>
      <pubDate>Thu, 16 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/illegal government surveillance">illegal government surveillance</category>
      <category domain="http://securityratty.com/tag/law">law</category>
      <category domain="http://securityratty.com/tag/immunity">immunity</category>
      <category domain="http://securityratty.com/tag/telecom carriers">telecom carriers</category>
      <category domain="http://securityratty.com/tag/suits">suits</category>
      <category domain="http://securityratty.com/tag/thursday">thursday</category>
      <category domain="http://securityratty.com/tag/civil-rights">civil-rights</category>
      <source url="http://www.networkworld.com/news/2008/101708-eff-aclu-slam-carrier-immunity.html?fsrc=rss-security">EFF, ACLU slam carrier immunity law</source>
    </item>
    <item>
      <title><![CDATA[Complex Event Processing An Emerging Paradigm in Business Intelligence, Security and Monitoring and Control]]></title>
      <link>http://securityratty.com/article/85dd8ffe0f10a11626880b7de9e30386</link>
      <guid>http://securityratty.com/article/85dd8ffe0f10a11626880b7de9e30386</guid>
      <description><![CDATA[The following quote is from Complex Event Processing An Emerging Paradigm in Business Intelligence, Security and Monitoring and Control by Evo Eftimov, iSec Consulting Ltd
Complex Event Processing...]]></description>
      <content:encoded><![CDATA[<p>The following quote is from <a href="http://www.top-consultant.com/articles/CEP.pdf" target="_blank">Complex Event Processing – An Emerging Paradigm in Business Intelligence, Security and Monitoring and Control</a> by Evo Eftimov, <a href="http://www.isecc.com" target="_blank">iSec Consulting Ltd</a></p>
<blockquote><p>&#8220;Complex Event Processing (CEP) is a technology which has been used for many years in the Aerospace and Defence Industry for Situational Awareness and Data Fusion modules in Command, Control, Communications, Computing and Intelligence Systems (aka C4I).</p>
<p>Currently CEP is being rediscovered as a foundation for new class of extremely effective Business Intelligence, Security and System/Network/SCADA Monitoring solutions in industries like Financial Services, Telecommunications, Oil and Gas, Manufacturing, Logistics etc. The increasing connectivity and processing power of the modern IT and Telecom technologies lead to increasing speed and volume of the dataflow available to the organisations. By using CEP solutions companies can gain competitive advantage by achieving real-time situational awareness and tapping the information value that is hidden within the streams of real-time event data that are coming from a variety of sources such as enterprise applications, financial transactions, sensor networks and supply chains.&#8221;</p></blockquote>
<p style="text-align: left;">Unfortunately, the author does not cite references in the paper.</p>
]]></content:encoded>
      <pubDate>Sun, 21 Sep 2008 01:59:21 +0000</pubDate>
      <category domain="http://securityratty.com/tag/complex event">complex event</category>
      <category domain="http://securityratty.com/tag/cep solutions companies">cep solutions companies</category>
      <category domain="http://securityratty.com/tag/cep">cep</category>
      <category domain="http://securityratty.com/tag/situational awareness">situational awareness</category>
      <category domain="http://securityratty.com/tag/real-time situational awareness">real-time situational awareness</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/solutions">solutions</category>
      <category domain="http://securityratty.com/tag/control">control</category>
      <category domain="http://securityratty.com/tag/business intelligence">business intelligence</category>
      <source url="http://www.thecepblog.com/2008/09/21/complex-event-processing-%e2%80%93-an-emerging-paradigm-in-business-intelligence-security-and-monitoring-and-control/">Complex Event Processing An Emerging Paradigm in Business Intelligence, Security and Monitoring and Control</source>
    </item>
    <item>
      <title><![CDATA[Schneier Interview in Telecom Asia ]]></title>
      <link>http://securityratty.com/article/678f5e8b17c449b243ba17ffc22ce983</link>
      <guid>http://securityratty.com/article/678f5e8b17c449b243ba17ffc22ce983</guid>
      <description><![CDATA[I was interviewed for Telecom...]]></description>
      <content:encoded><![CDATA[<p>I was <a href="http://www.telecomasia.net/article.php?id_article=10230">interviewed</a> for <i>Telecom Asia</i>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=QBNpL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=QBNpL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=A3HAL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=A3HAL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 19 Sep 2008 09:55:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/telecom asia">telecom asia</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/schneier_interv_4.html">Schneier Interview in Telecom Asia </source>
    </item>
    <item>
      <title><![CDATA[S&P Downgrades TIBCO to Sell On Financial Services Exposure]]></title>
      <link>http://securityratty.com/article/401726b89f56c470f7b2b4c0e8f2d4f1</link>
      <guid>http://securityratty.com/article/401726b89f56c470f7b2b4c0e8f2d4f1</guid>
      <description><![CDATA[Standard &amp; Poors analyst Zaineb Bokhari cut her rating on TIBCO Software (TIBX) to Sell from Hold. Bokhari referenced TIBCOs relatively high exposure to financial services and telecom companies and...]]></description>
      <content:encoded><![CDATA[<p>Standard &amp; Poor’s analyst Zaineb Bokhari  cut her rating on TIBCO Software <a href="http://online.barrons.com/quotes/main.html?symbol=tibx">(TIBX)</a> to Sell from Hold.  Bokhari referenced TIBCO’s relatively high exposure to financial services and telecom companies and dependence on large deals.  Bokhari noted that TIBCO will report Aug 2008 quarter results on September 25.  She estimates revenue of $154 million and an operating EPS of 6 cents.  For the November 2008 fiscal year, she cut his sales forecast to $650 million from $663 million, with EPS dropping 2 cents to 34 cents. For FY ‘09,  Bokhari drops another penny to 44 cents.  Bokhari cuts her target price on TIBCO stock to $6.50, from $8.</p>
]]></content:encoded>
      <pubDate>Thu, 18 Sep 2008 14:15:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tibco">tibco</category>
      <category domain="http://securityratty.com/tag/bokhari">bokhari</category>
      <category domain="http://securityratty.com/tag/bokhari drops">bokhari drops</category>
      <category domain="http://securityratty.com/tag/bokhari cuts">bokhari cuts</category>
      <category domain="http://securityratty.com/tag/tibco software">tibco software</category>
      <category domain="http://securityratty.com/tag/financial services">financial services</category>
      <category domain="http://securityratty.com/tag/cents">cents</category>
      <category domain="http://securityratty.com/tag/bokhari noted">bokhari noted</category>
      <category domain="http://securityratty.com/tag/million">million</category>
      <source url="http://www.thecepblog.com/2008/09/18/sp-downgrades-tibco-to-sell-on-financial-services-exposure/">S&amp;P Downgrades TIBCO to Sell On Financial Services Exposure</source>
    </item>
    <item>
      <title><![CDATA[In-Flight VoIP Ban: Against FCC Rules? Highly Desirable?]]></title>
      <link>http://securityratty.com/article/04edfe3e5a28bd63c48bc3f4ded28db4</link>
      <guid>http://securityratty.com/article/04edfe3e5a28bd63c48bc3f4ded28db4</guid>
      <description><![CDATA[Think-tank wonders whether banning in-flight VoIP constitutes a violation of FCC rules about blocking services: The Progress and Freedom Foundation's Barbara Espin uses the ban on in-flight VoIP by...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/plane.jpg" align="right" border="0" hspace="5" /><a href="http://blog.pff.org/archives/2008/09/does_disclosure.html"><strong>Think-tank wonders whether banning in-flight VoIP constitutes a violation of FCC rules about blocking services:</strong></a> The Progress and Freedom Foundation's Barbara Espin uses the ban on in-flight VoIP by American Airlines (facilitated by provider Aircell) to make a broader argument about what she calls the FCC's "ad hoc approach to broadband network management issues." It's clever. American discloses that calling isn't allowed, and VoIP isn't even technically within the FAA or FCC's purview, as far as I can determine. The FAA could choose to regulate it as a safety issue. PFF generally tilts anti-regulation, and has as what it calls its "supporters" a broad area of multiple system cable operators and telecom firms, including Comcast, which was singled out and fined by the FCC for its undisclosed network disruption of P2P connections.</p>

<p><a href="http://www.nytimes.com/2008/09/14/business/14essay.html?_r=2&ei=5070&emc=eta1&oref=slogin&oref=slogin"><strong>Espin references Joe Sharkey's excellent column on in-flight calling in Sunday's New York Times:</strong></a> Sharkey, a veteran travel writer, who survived a mid-air collision over the Brazilian Amazon a few years ago, looks at varying attitudes about calls made during flights. He quotes Aircell's Jack Blumenstein saying what I've telling folks for months: Aircell has a lot of techniques to block VoIP calls already, and "as we identify new ways that people are trying to do voice calls on the airplane, we just kind of zero in and knock those off." Many geeks have assumed Aircell is a bunch of unsavvy folks who wouldn't be able to figure out how to disrupt their clever workarounds for making VoIP. (I keep noting that introducing jitter for suspicious data connections wouldn't disrupt legitimate applications, but would destroy VoIP call quality.)</p>]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 05:50:22 +0000</pubDate>
      <category domain="http://securityratty.com/tag/voip">voip</category>
      <category domain="http://securityratty.com/tag/in-flight voip constitutes">in-flight voip constitutes</category>
      <category domain="http://securityratty.com/tag/in-flight">in-flight</category>
      <category domain="http://securityratty.com/tag/in-flight voip">in-flight voip</category>
      <category domain="http://securityratty.com/tag/block voip calls">block voip calls</category>
      <category domain="http://securityratty.com/tag/fcc rules">fcc rules</category>
      <category domain="http://securityratty.com/tag/fcc">fcc</category>
      <category domain="http://securityratty.com/tag/voice calls">voice calls</category>
      <category domain="http://securityratty.com/tag/calls">calls</category>
      <source url="http://wifinetnews.com/archives/008444.html">In-Flight VoIP Ban: Against FCC Rules? Highly Desirable?</source>
    </item>
    <item>
      <title><![CDATA[How carriers batten down the hatches for hurricanes]]></title>
      <link>http://securityratty.com/article/5a6dad089e49c0e4a38a4daca3b27eac</link>
      <guid>http://securityratty.com/article/5a6dad089e49c0e4a38a4daca3b27eac</guid>
      <description><![CDATA[Picture what would happen if the multitude of hardhat-wearing network technicians you see in a typical Verizon commercial got swept up in a &quot;Wizard of Oz&quot;-style twister. In other words, think about...]]></description>
      <content:encoded><![CDATA[Picture what would happen if the multitude of hardhat-wearing network technicians you see in a typical Verizon commercial got swept up in a "Wizard of Oz"-style twister. In other words, think about how spread out telecom carrier infrastructure is and about how many different bases telcos have to cover to protect it all during natural disasters. ]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/typical verizon commercial">typical verizon commercial</category>
      <category domain="http://securityratty.com/tag/telecom carrier infrastructure">telecom carrier infrastructure</category>
      <category domain="http://securityratty.com/tag/natural disasters">natural disasters</category>
      <category domain="http://securityratty.com/tag/-style twister">-style twister</category>
      <category domain="http://securityratty.com/tag/bases telcos">bases telcos</category>
      <category domain="http://securityratty.com/tag/network technicians">network technicians</category>
      <category domain="http://securityratty.com/tag/wizard">wizard</category>
      <category domain="http://securityratty.com/tag/swept">swept</category>
      <category domain="http://securityratty.com/tag/protect">protect</category>
      <source url="http://www.networkworld.com/news/2008/090408-hurricane.html?fsrc=rss-security">How carriers batten down the hatches for hurricanes</source>
    </item>
    <item>
      <title><![CDATA[Summarizing Zero Day's Posts for July]]></title>
      <link>http://securityratty.com/article/8dcef74e51c669037abd743dd3beb89d</link>
      <guid>http://securityratty.com/article/8dcef74e51c669037abd743dd3beb89d</guid>
      <description><![CDATA[Different audience provokes different approach for communicating a particular event. In case you aren't reading ZDNet's Zero Day , where I blog next to Ryan Naraine and Nathan McFeters - join us
...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="text-align: center; clear: both;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/SJyNk-jjwHI/AAAAAAAACBM/TzBiD3_WOw0/s1600-h/zero_day.png" imageanchor="1" style="border: 0pt none ; background-color: transparent; clear: left; margin-bottom: 1em; float: left; margin-right: 1em;"><img src="http://1.bp.blogspot.com/_wICHhTiQmrA/SJyNk-jjwHI/AAAAAAAACBM/CewQ6GCj8yE/s200-R/zero_day.png" style="border: 0pt none ;" /></a>Different audience provokes different approach for communicating a particular event. In case you aren't reading <a href="http://blogs.zdnet.com/security">ZDNet's Zero Day</a>, where I blog next to Ryan Naraine and Nathan McFeters - join us.<br />
<br />
Also, consider subscribing yourself to <a href="http://updates.zdnet.com/tags/dancho+danchev.html?t=0&amp;s=0&amp;o=1&amp;mode=rss">my personal RSS feed</a>, or Zero Day's main feed <a href="http://feeds.feedburner.com/zdnet/security">in order to read all the posts</a>. Here's a quick summary of my posts for last month :<br />
<br />
<b>01.</b> <a href="http://blogs.zdnet.com/security/?p=1378">Blizzard introducing two-factor authentication for WoW gamers</a><br />
<b>02.</b> <a href="http://blogs.zdnet.com/security/?p=1394">Sony PlayStation's site SQL injected, redirecting to rogue security software</a><br />
<b>03.</b> <a href="http://blogs.zdnet.com/security/?p=1408">300 Lithuanian sites hacked by Russian hackers</a><br />
<b>04.</b> <a href="http://blogs.zdnet.com/security/?p=1412">Antivirus vendor introducing virtual keyboard for secure Ebanking</a><br />
<b>05.</b> <a href="http://blogs.zdnet.com/security/?p=1418">Gmail, Yahoo and Hotmail's CAPTCHA broken by spammers</a><br />
<b>06.</b> <a href="http://blogs.zdnet.com/security/?p=1440">Storm Worm's Independence Day campaign</a><br />
<b>07.</b> <a href="http://blogs.zdnet.com/security/?p=1445">Approximately 800 vulnerabilities discovered in antivirus products</a><br />
<b>08.</b> <a href="http://blogs.zdnet.com/security/?p=1448">$1 Million prize offered for cracking an encryption algorithm</a><br />
<b>09.</b> <a href="http://blogs.zdnet.com/security/?p=1453">U.K's most spammed person receives 44,000 spam emails daily</a><br />
<b>10.</b> <a href="http://blogs.zdnet.com/security/?p=1462">Storm Worm says the U.S have invaded Iran</a><br />
<b>11.</b> <a href="http://blogs.zdnet.com/security/?p=1473">Gmail, PayPal and Ebay embrace DomainKeys to fight phishing emails</a><br />
<b>12.</b> <a href="http://blogs.zdnet.com/security/?p=1476">Verizon, Telecom Italia, and Brasil Telecom top the botnet charts in Q2 of 2008</a><br />
<b>13.</b> <a href="http://blogs.zdnet.com/security/?p=1487">XSS worm at Justin.tv infects 2,525 profiles</a><br />
<b>14.</b> <a href="http://blogs.zdnet.com/security/?p=1492">Remote code execution through Intel CPU bugs</a><br />
<b>15.</b> <a href="http://blogs.zdnet.com/security/?p=1502">Ringleader of cybercrime group to be offered a job as cybercrime fighter</a><br />
<b>16.</b> <a href="http://blogs.zdnet.com/security/?p=1514">Spam coming from free email providers increasing</a><br />
<b>17.</b> <a href="http://blogs.zdnet.com/security/?p=1516">Kaspersky's Malaysian site hacked by Turkish hacker</a><br />
<b>18.</b> <a href="http://blogs.zdnet.com/security/?p=1533">Georgia President's web site under DDoS attack from Russian hackers</a><br />
<b>19.</b> <a href="http://blogs.zdnet.com/security/?p=1536">75% of online banking sites found vulnerable to security design flaws</a><br />
<b>20.</b> <a href="http://blogs.zdnet.com/security/?p=1538">McAfee debunks recent vulnerabilities in AV software research, n.runs restates its position</a><br />
<b>21.</b> <a href="http://blogs.zdnet.com/security/?p=1555">Click fraud in 2nd quarter of 2008 more sophisticated, botnets to blame</a><br />
<b>22.</b> <a href="http://blogs.zdnet.com/security/?p=1562">How OpenDNS, PowerDNS and MaraDNS remained unaffected by the DNS cache poisoning vulnerability</a><br />
<b>23.</b> <a href="http://blogs.zdnet.com/security/?p=1590">DNS cache poisoning attacks exploited in the wild</a><br />
<b>24.</b> <a href="http://blogs.zdnet.com/security/?p=1598">The Neosploit cybercrime group abandons its web malware exploitation kit</a><br />
<b>25.</b> <a href="http://blogs.zdnet.com/security/?p=1603">OS fingerprinting Apple's iPhone 2.0 software - a "trivial joke"</a><br />
<b>26.</b> <a href="http://blogs.zdnet.com/security/?p=1608">HD Moore pwned with his own DNS exploit, vulnerable AT&amp;T DNS servers to blame</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=2aIHIK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=2aIHIK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gWQX0K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gWQX0K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=yKKS6k"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=yKKS6k" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=HJ2jlk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=HJ2jlk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=1CE30K"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=1CE30K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=6ODqHK"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=6ODqHK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fiaybk"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fiaybk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/359698181" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 08 Aug 2008 10:35:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/day">day</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/rogue security software">rogue security software</category>
      <category domain="http://securityratty.com/tag/spam emails daily">spam emails daily</category>
      <category domain="http://securityratty.com/tag/cybercrime">cybercrime</category>
      <category domain="http://securityratty.com/tag/cybercrime fighter">cybercrime fighter</category>
      <category domain="http://securityratty.com/tag/independence day campaign">independence day campaign</category>
      <category domain="http://securityratty.com/tag/emails">emails</category>
      <category domain="http://securityratty.com/tag/posts">posts</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/359698181/summarizing-zero-days-posts-for-july.html">Summarizing Zero Day's Posts for July</source>
    </item>
    <item>
      <title><![CDATA[Long Island Proposal Snags Again, on Poles]]></title>
      <link>http://securityratty.com/article/479733758aebc5a0eefa89ed8a473de2</link>
      <guid>http://securityratty.com/article/479733758aebc5a0eefa89ed8a473de2</guid>
      <description><![CDATA[Long Island proposal still mired: The plan to put Wi-Fi up across two Long Island counties has seemed doomed to me from the start. The company that won the bid was untested, and its other...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/muni_icon.jpg" align="right" border="0" hspace="5" /><a href="http://www.newsday.com/news/local/ny-liwifi0728,0,7393890.story?track=rss"><strong>Long Island proposal still mired:</strong></a> The plan to put Wi-Fi up across two Long Island counties has seemed doomed to me from the start. The company that won the bid was untested, and its other in-deployment or in-proposal networks are off the table. Expertise aside, it needs tens of millions to build such a network, and financing for company-funded metro-scale projects is not available. The counties involved have pledged no purchases of services. And, perhaps the final stroke, the local utility says that E-Path doesn't meet the test of being a telecom and paying less than $10 per year for pole placement, but instead must pay the all-comer rate of $50 per year.</p>

<p>This is a critical distinction. Telecoms are covered under the Telecom Act of 1996 that requires non-discriminatory access to utility poles to avoid incumbent local exchange carriers (ILECs) and utilities from being gatekeepers that prevent competitive service from emerging. There are a series of tests in the law and local qualifications, too, that allow a firm to be a registered telecom. An FCC decision last year ruled that companies that mix telecom and unregulated information services on the same wires aren't disqualified from getting the Telecom Act deal, however. </p>

<p>But E-Path seems to meet none of the criteria except their desire to pay $10 instead of $50 per year per pole. Utility poles have held up many other municipal networks. We're not hearing more about them these days because such networks are now being built on a smaller scale for different purposes, where the number of nodes and their placement is rather different than networks built with the intent of providing indoor coverage.</p>

<p>Cablevision, by the way, qualifies as a telecom, this article states, which helps them in placing nodes for their planned $300m network across their coverage territory. They can also mount nodes in-line with their cable lines, using power from their cable plant on the lines already.</p>

<p>E-Path appears to have a variety of communication problems as well. The article notes, "Tortoretti said his Washington, D.C., attorneys disagree with LIPA's interpretation. But the attorney Tortoretti said represents E-Path, Charles Rohe, said he couldn't speak about the company or the dispute."</p>

<p>Later, E-Path's "chief executive said he hopes the county will help with his LIPA dispute." But an aide to the Suffolk County executive said, "That's not really our issue. That's out of our control."</p>

<p>Correspondent Craig Plunkett, quoted near the end, points out that if the counties were to change their minds and want to buy services on the network, the proposal would have to be rebid (appears as the sound-alike "rebuild" by accident in the online article at this moment).</p>]]></content:encoded>
      <pubDate>Mon, 28 Jul 2008 07:07:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/telecom act">telecom act</category>
      <category domain="http://securityratty.com/tag/telecom act deal">telecom act deal</category>
      <category domain="http://securityratty.com/tag/telecom">telecom</category>
      <category domain="http://securityratty.com/tag/proposal">proposal</category>
      <category domain="http://securityratty.com/tag/island proposal">island proposal</category>
      <category domain="http://securityratty.com/tag/e-path">e-path</category>
      <category domain="http://securityratty.com/tag/networks">networks</category>
      <category domain="http://securityratty.com/tag/represents e-path">represents e-path</category>
      <category domain="http://securityratty.com/tag/municipal networks">municipal networks</category>
      <source url="http://wifinetnews.com/archives/008403.html">Long Island Proposal Snags Again, on Poles</source>
    </item>
    <item>
      <title><![CDATA[Help EFF Continue the Fight Against Warrantless Wiretapping!]]></title>
      <link>http://securityratty.com/article/cb31e91ff88905f8510b8445973f2788</link>
      <guid>http://securityratty.com/article/cb31e91ff88905f8510b8445973f2788</guid>
      <description><![CDATA[Got this in a email this morning, makes me sad, maybe you can help,,, I feel as if my concerns are not being given adequate attention with my elected officials. Especially the ones I voted into...]]></description>
      <content:encoded><![CDATA[<pre>Got this in a email this morning, makes me sad, maybe you can help,,,
I feel as if my concerns are not being given adequate
attention with my elected officials.
Especially the ones I voted into office.

Dear Friend of Freedom,

In a move that I can only describe as cowardice, Congress
just passed legislation meant to immunize telephone
companies for their illegal, disloyal, and irresponsible
behavior. EFF has been fighting against telecom immunity,
and we need your help to bring the fight to the next level:

<a class="moz-txt-link-freetext" href="http://secure.eff.org/wiretapping">http://secure.eff.org/wiretapping</a>

Two and a half years ago, EFF sued AT&amp;T on behalf of its
customers, seeking to hold the telecom giant responsible
for its craven complicity in the White House&#8217;s illegal
warrantless wiretapping program.

Since then, the phone companies and their allies in
Washington have spent tens of millions of dollars lobbying
Congress to grant them retroactive immunity. They ran
ridiculous fear-mongering attack ads against any politician
who dared to oppose them. President Bush threatened to veto
any bill that allowed EFF&#8217;s lawsuit to continue.

Yesterday, Congress completely capitulated to the
President&#8217;s threats and voted to let the telecoms off the
hook. If the telecoms are not held accountable, the
administration will remain unchecked in its warrantless
wiretapping of innocent Americans. This must stop!

We need your help to take the fight to the next level.
We&#8217;re going to challenge Congress&#8217;s unconstitutional grant
of immunity in our case against AT&amp;T. We&#8217;re going to fight
for a congressional repeal of immunity in the next
Congress. And we&#8217;re going to file a new lawsuit against the
government, challenging its warrantless surveillance
practices, past, present and future.

Now, more than ever, we need your support!

<a class="moz-txt-link-freetext" href="http://secure.eff.org/wiretapping">http://secure.eff.org/wiretapping</a>

The fight for civil liberties would never have come this
far without your help. We can&#8217;t give up now. Help EFF
today!

Sincerely,
Shari

&#8211;
*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*
Shari Steele
Executive Director
Electronic Frontier Foundation
454 Shotwell Street
San Francisco CA 94110
<a class="moz-txt-link-freetext" href="http://www.eff.org/">http://www.eff.org/</a>

Membership &amp; donation queries:
<a class="moz-txt-link-abbreviated" href="mailto:membership@eff.org">membership@eff.org</a>

All other queries:
<a class="moz-txt-link-abbreviated" href="mailto:information@eff.org">information@eff.org</a></pre>
]]></content:encoded>
      <pubDate>Thu, 10 Jul 2008 10:18:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/eff">eff</category>
      <category domain="http://securityratty.com/tag/eff sued att">eff sued att</category>
      <category domain="http://securityratty.com/tag/fight">fight</category>
      <category domain="http://securityratty.com/tag/warrantless">warrantless</category>
      <category domain="http://securityratty.com/tag/immunity">immunity</category>
      <category domain="http://securityratty.com/tag/retroactive immunity">retroactive immunity</category>
      <category domain="http://securityratty.com/tag/congress">congress</category>
      <category domain="http://securityratty.com/tag/congress completely">congress completely</category>
      <category domain="http://securityratty.com/tag/att">att</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=499">Help EFF Continue the Fight Against Warrantless Wiretapping!</source>
    </item>
  </channel>
</rss>
