<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: thai]]></title>
    <link>http://securityratty.com/tag/thai</link>
    <description></description>
    <pubDate>Thu, 12 Jun 2008 12:29:10 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Modelling The Global Financial Meltdown]]></title>
      <link>http://securityratty.com/article/15c8ebf58fa47d569eb7cdbc4039c683</link>
      <guid>http://securityratty.com/article/15c8ebf58fa47d569eb7cdbc4039c683</guid>
      <description><![CDATA[Yesterday I received a call from Penny Grosman , Senior Editor, Wall Street &amp; Technology . Penny was interested in my opinion, Will risk management applications be the next killer app for CEP on Wall...]]></description>
      <content:encoded><![CDATA[<p>Yesterday I received a call from <a href="http://www.wallstreetandtech.com/penny-crosman/" target="_blank">Penny Grosman</a>, Senior Editor, <a href="http://www.wallstreetandtech.com/" target="_blank">Wall Street &amp; Technology</a>.   Penny was interested in my opinion, &#8220;Will risk management applications be the next killer app for CEP&#8221; on Wall Street.    I enjoyed talking with Penny.  She caught up with me leaving a tailor&#8217;s shop in Chiang Mai, so I hope she did not mind hearing my stories of buying unique Northern Thai cotton fabric and designing my own casual shirts in the economic turndown.</p>
<p>We read many stories on the net where folks claim that the current financial crisis could have been avoided with more or better use of technology.     This is expected, as software companies and IT professionals will often try to piggy-backtheir business development strategy on the &#8220;crisis of the day&#8221; to sell more goods and services.    Honestly, in this current situation, the main technology that we needed was simple, accurate financial models.</p>
<p>For example, in the chart above, the US economy was doing quite well with US federal funds rates low.   Housing prices in the US were skyrocketing and there was a concern about inflation.    There was an understandable concern the sustainability of that economy.</p>
<p style="text-align: center;"><img class="aligncenter" style="vertical-align: bottom;" src="http://www.thewrittenblog.com/main_1/images/97kcpv16xjh0uvsi8k7kdhaw.gif" alt="" width="277" height="415" /></p>
<p>So, in perhaps one the most ill-advised Federal Reserve actions of many decades, the folks at the helm of the Fed decided to raise their lending rates around 500 percent over a two year period.</p>
<p>As we all know, primarily because of the action by the Fed, the world faces perhaps the worst economic disaster in modern times, while the US Executive Branch and the Congress fight over how to spend $700 Billion taxpayer dollars to inject liquidity into the markets to try to head off a global financial disaster.</p>
<p>It is amazing to me that the US Federal Government, or their advisors, does not have simple financial models with cause-and-effect analysis such as:</p>
<ul>
<li>Homeowners with adjustable rate mortuages will not be able to make payments;and</li>
<li>Housing prices will fall dramatically; then</li>
<li>Homeowners will default on loans where the collateral is much less than the asset value, and</li>
<li>Banks will suffer great losses, and</li>
<li>Lending will come to a halt, then</li>
<li>Banks will collapse, then</li>
<li>Wall Street will exit the markets in panic</li>
<li>&#8230; and more trouble&#8230;.. !!</li>
</ul>
<p>There are and continue to be a lot of discussion and opinions about how risk management needs improvement. and I agree.   We will also read folks talk about how technology can be used to help solve this problem, including CEP/EP and related software (see also <!-- This wrapper class appears only on Page and Single Post pages. --><a title="Capital Market CEP Fantasy Land" rel="bookmark" href="../2008/06/23/capital-market-cep-fantasy-land/">Capital Market CEP Fantasy Land</a>). However, as much I would be pleased to see more CEP/EP applications and use cases, I do not believe that event processing technology is really very useful to solve the core problem of the current financial crisis.</p>
<p>The core problem is, seemingly, that our &#8220;financial experts&#8221; do not even have simple models that will illustrate what will or could happen when you raise the fed lending rates 500 percent in two years in an economy pregnant with adjustable rate mortgages.</p>
<p>To me, this does not appear to be rocket science.  The negligence by the US Federal Reserve and their advisors is astonishing.</p>
]]></content:encoded>
      <pubDate>Thu, 02 Oct 2008 02:33:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/simple financial models">simple financial models</category>
      <category domain="http://securityratty.com/tag/financial models">financial models</category>
      <category domain="http://securityratty.com/tag/current financial crisis">current financial crisis</category>
      <category domain="http://securityratty.com/tag/crisis">crisis</category>
      <category domain="http://securityratty.com/tag/simple">simple</category>
      <category domain="http://securityratty.com/tag/technology">technology</category>
      <category domain="http://securityratty.com/tag/wall street">wall street</category>
      <category domain="http://securityratty.com/tag/main technology">main technology</category>
      <category domain="http://securityratty.com/tag/folks">folks</category>
      <source url="http://www.thecepblog.com/2008/10/02/modelling-the-global-financial-meltdown/">Modelling The Global Financial Meltdown</source>
    </item>
    <item>
      <title><![CDATA[A New Security Breach in Google Docs Revealed]]></title>
      <link>http://securityratty.com/article/caf2790afa2996d6a38ac70d10ec784a</link>
      <guid>http://securityratty.com/article/caf2790afa2996d6a38ac70d10ec784a</guid>
      <description><![CDATA[I am a big fan of Google and, over time, I have started to enjoy the freedom from my desktop with Google Docs . For example, when I keep track of business expenses I have found it easier to update a...]]></description>
      <content:encoded><![CDATA[<p>I am a big fan of Google and, over time, I have started to enjoy the freedom from my desktop with <a href="http://docs.google.com/">Google Docs</a>.  For example, when I keep track of business expenses I have found it easier to update a Google Spreadsheet versus depending on Microsoft Excel on my laptop because I can update from anywhere in the world and share with my bookkeeper too.     So, I&#8217;ve been using Google Docs more lately.</p>
<p>Today, however, I discovered a huge security breach in Google Docs.  While I was in my account working on a spreadsheet I suddenly found my Google Doc account listing many documents that did not belong to me.  I clicked on one of the documents and the results are in the image below, where my Google Doc session appears to have &#8220;crossed over&#8221; with another users.</p>
<p><img style="width: 474px; height: 443px;" src="http://www.thecepblog.com/imgs/google.docs.security.breach.jpg" alt="" /></p>
<p>I decided to do a bit more exploring and take a few more screenshots, because I don&#8217;t yet know how to reproduct this security breach.  The image below show a Google document (fifth from the top) which is not owned by me, &#8220;owned by me&#8221;. However, when I click on this mysterious &#8220;owned by me&#8221; document, it is owned by another user.  Here is another screenshot below; you can click on the image for the full-screen version.</p>
<p><a href="http://www.thecepblog.com/imgs/google.docs.security.breach2.jpg"><img style="width: 474px; height: 443px;" src="http://www.thecepblog.com/imgs/google.docs.security.breach2.jpg" alt="" /></a></p>
<p>Again, here is another example of the same security violation with two documents. As above, you can click on the image for a full-screen version.</p>
<p><a href="http://www.thecepblog.com/imgs/google.docs.security.breach4.jpg"><img style="width: 473px; height: 442px;" src="http://www.thecepblog.com/imgs/google.docs.security.breach4.jpg" alt="" /></a></p>
<p>I contacted the owner of the Google Docs account which I had suddenly and mysteriously &#8220;crossed sessions&#8221; with today.   I asked him if he was in Thailand (since a few of the documents were in Thai) and he said yes, however he say he did not have any Thai language documents in his account.    However, as you can see from the screenshot, the Google Docs menu shows this person as &#8220;the owner&#8221; of a Thai language document.  He also mentioned that, today, he saw &#8220;wierd documents&#8221; in his account that did not belong to him (or &#8220;normally&#8221; shared with him).</p>
<p>Unfortunately, I was having problems with the Internet connection in my hotel room so I could not continue to investigate the breach.  When I logged back in a few hours later, everything was back to normal.  So far, all is &#8220;normal&#8221; and I have not been able to repeat this breach.</p>
<p>I suspect the Google Docs flaw comes from a JavaScript error in how Google manages user sessions.  The bottom line is that the security breach is real and dangerous.  Your Google Docs, and I suspect other Google applications that use the same session management code, are vulnerable.  There may be an underlying XSS vulnerability as well.</p>
<p>Note: Reposted from my original post on the <a href="http://blog.isc2.org/isc2_blog/2008/09/serious-securit.html" target="_blank">ISC2 blog</a>.</p>
]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 07:59:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/google docs">google docs</category>
      <category domain="http://securityratty.com/tag/google docs menu">google docs menu</category>
      <category domain="http://securityratty.com/tag/google docs flaw">google docs flaw</category>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/google docs account">google docs account</category>
      <category domain="http://securityratty.com/tag/security breach">security breach</category>
      <category domain="http://securityratty.com/tag/breach">breach</category>
      <category domain="http://securityratty.com/tag/account">account</category>
      <category domain="http://securityratty.com/tag/thai language documents">thai language documents</category>
      <source url="http://www.thecepblog.com/2008/09/15/a-new-security-breach-in-google-docs-revealed/">A New Security Breach in Google Docs Revealed</source>
    </item>
    <item>
      <title><![CDATA[Modelling Shoplifting]]></title>
      <link>http://securityratty.com/article/3943f3c70f24e801812a87cf0b0b61f8</link>
      <guid>http://securityratty.com/article/3943f3c70f24e801812a87cf0b0b61f8</guid>
      <description><![CDATA[The other day I was thinking that I should write about specific situation models and by coincident Marc Adler pens CEP and Shoplifting . In Marcs post, Marc begins to model shoplifting as if...]]></description>
      <content:encoded><![CDATA[<p>The other day I was thinking that I should write about specific situation models and by coincident Marc Adler pens <a href="http://magmasystems.blogspot.com/2008/09/cep-and-shoplifting.html" target="_blank">CEP and Shoplifting</a>.  In Marc&#8217;s post, Marc begins to model shoplifting as if shoplifting is &#8220;market data,&#8221; with Level 1 to Level 4 shoplifting &#8220;quotes&#8221; - the natural approach for a brilliant guy from Citi.   In reality, this model does not work very well, and I&#8217;ll touch on a few reasons why today.</p>
<p>Marc&#8217;s initial shoplifting model in his post is based on John <span id="SPELLING_ERROR_3" class="blsp-spelling-error">Colapinto&#8217;s concepts of matching a pattern of customer movements in the store with their estimated patterns of shoplifting behavioral patterns.    Marc&#8217;s asks how Coral8 might address this.   We are not ready to seek a vendor solution.  We do not yet have a workable detection model.</span></p>
<p><span class="blsp-spelling-error">As indicated above, I don&#8217;t think the example situation cited by John and Marc is a viable model for automated processing.    Tracking the behavior of customer&#8217;s movements, by machine, would require some very sophisticated image processing technology that would be too expensive compared to any possible loss at most retails stores.    This type of behavioral pattern recognition. in retail stores, is performed by people (security personnel), not machines, observing people.  </span></p>
<p><span class="blsp-spelling-error">To develop a machine pattern recognition application to detect retail shoplifting we need to build detection models that are economically feasible.  If we are going to use a model of shoplifting pattern recognition versus anomaly detection, we need to define the objects we must track.   </span></p>
<p><span class="blsp-spelling-error">In the most simple model, we have merchandise-objects.   Stores normally (physically) track merchandise-objects only at the exit/entry points of the store using some electromagnetic proximity detection technology.   In this model, the detection configuration is a combination of simple alerting with humans watching the store (&#8221;minding the store&#8221;).    This is not complex event processing.</span></p>
<p><span class="blsp-spelling-error">However, if we added another object to our model, the customer-object, then we start to get more &#8220;complex,&#8221; but we have not defined &#8220;complexity&#8221; yet because we have not defined the object properties, the possible states of the objects, and the relationships between the objects that are the basis for estimated situations.</span></p>
<p><span class="blsp-spelling-error">Hence, model building is constrained by available resources, simple economics and risk (cost-benefit).  If we are detecting shoplifting in Walmart the cost-benefit model for implementing an automated shoplifting detection system would be different than at a top diamond store on 5th Avenue in NYC.   Protecting loss at a weapons-grade uranium respository follows a different model than protecting loss at a handicraft shop, naturally.</span></p>
<p><span class="blsp-spelling-error">Like Marc, I find models to automatically detect shoplifting interesting, so permit me to close with a general discussion of shoplifting in the context of our <a href="http://www.thecepblog.com/what-is-complex-event-processing/" target="_blank">CEP/EP reference model</a>.</span></p>
<p><span class="blsp-spelling-error"><span class="blsp-spelling-error">One approach would be do determine what objects will be represented in our model.   For example, if we are going to track merchandise, we need to model the &#8221;merchandise-object&#8221;.  If we are going to track people, we need to define the properties of this &#8220;person object.&#8221;  If we are going to represent the store layout, we need to define all these objects (store-object, table-object, shelf-object, entry-object and so forth).  The model can get &#8220;complex&#8221; quite quickly.  </span></span></p>
<blockquote><p><span class="blsp-spelling-error"><span class="blsp-spelling-error">Editorial Note:  <em>An object-oriented approach greatly assists complex model building because we can benefit from OO properties such as encapsulation and polymorphism.  For example, we can define a basic &#8220;person object class&#8221; and then create superclasses of this object for &#8220;customer-object&#8221;, &#8220;manager-object&#8221;, &#8220;or criminal-object.&#8221;</em></span></span></p></blockquote>
<p><span class="blsp-spelling-error"><span class="blsp-spelling-error">Generally speaking, each object we define will require a state-model, for example, in Marc&#8217;s example of a customer moving around the store, we would need to model the possible states (customer at the entrance, at table 1, at table 2, at shelf 1, in the bathroom, at the cashier, etc.)  Indeed Marc, this is complex event processing if we have modelled multiple objects and defined object-object relationships that indicate situations of interest.   For example, customer-object at table2 where merchandise-object has the property of  &#8221;very expensive, high risk&#8221; and then customer-object changes state to &#8220;in bathroom&#8221;.  Of course, we need more key indicators, but you get the idea.</span></span></p>
<p><span class="blsp-spelling-error"><span class="blsp-spelling-error">Right now, I am typing from the <a href="http://www.taste4heaven.com">Taste from Heaven Vegetarian Restaurant</a> in Chiang Mai and my battery is running low.  The owner of this excellent restaurant also runs the <a href="http://www.elephantnaturefoundation.org/" target="_blank">Elephant Nature Park</a>, a non-profit organization advocating and acting on behalf of the rights of the mighty elephants in Thailand.  Would be great if we could also automatically detect the situation of &#8220;elephant abuse&#8221; by poachers and other crimes against nature.   Time to get back to my delicious mushroom salad, Northeastern Thai style.</span></span></p>
<p><span class="blsp-spelling-error"><span class="blsp-spelling-error">As always, thanks for reading, time for me to get back to eating!</span></span></p>
<p> </p>
]]></content:encoded>
      <pubDate>Sun, 07 Sep 2008 03:30:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/store">store</category>
      <category domain="http://securityratty.com/tag/store-object">store-object</category>
      <category domain="http://securityratty.com/tag/complex">complex</category>
      <category domain="http://securityratty.com/tag/model canget complex">model canget complex</category>
      <category domain="http://securityratty.com/tag/model">model</category>
      <category domain="http://securityratty.com/tag/simple">simple</category>
      <category domain="http://securityratty.com/tag/simple economics">simple economics</category>
      <category domain="http://securityratty.com/tag/simple model">simple model</category>
      <category domain="http://securityratty.com/tag/object">object</category>
      <source url="http://www.thecepblog.com/2008/09/07/modelling-shoplifting/">Modelling Shoplifting</source>
    </item>
    <item>
      <title><![CDATA[Business In Thailand - Part 1: The Challenge]]></title>
      <link>http://securityratty.com/article/9f1f804e00135ef904eb97970171c32e</link>
      <guid>http://securityratty.com/article/9f1f804e00135ef904eb97970171c32e</guid>
      <description><![CDATA[Recently someone asked about business in Thailand.Here is my first post on this challenging topic
First of all, as background information, I learned the Thai alphabet(script with 44 consonants and 32...]]></description>
      <content:encoded><![CDATA[<p>Recently someone asked about business in Thailand.  Here is my first post on this challenging topic:</p>
<p>First of all, as background information, I learned the Thai alphabet (script with 44 consonants and 32 vowels) nearly 20 years ago, so I have have a pretty decent foundation for the Thai language compared to most foreigners visting or working in Thailand.   I can read (slowly) and speak better than 99.99+ percent of all foreigners in Thailand.  For this reason, I thought it was &#8221;the right thing to do&#8221; to redirect my career to a &#8220;new challenge&#8221; in the business climate of Thailand as I continue to improve my foreign language skills.   I wanted to help Thailand progress in IT and IT security, so where else would I go but where I have second language skills?</p>
<p>This was no small decision as you can imagine.  Your career and life changes quite dramatically when you give up a long established consulting practice in the US and dive into business in a foreign land, seeking a new challenge.  I can frankly tell you thatit is more difficult to do business in Thailand (as a foreigner) than I expected, for a number of reasons.  Here is my first off-topic post on this topic.</p>
<p>First of all, it is not legal for foreigners to directly own land in Thailand.  Foreigners can &#8221;own&#8221; land using a variety of legal loopholes, proxy owners and shell companies; but all of this is risky and not advised.  Many foreigners lose a lot of money coming to Thailand and attempting to buy land via various &#8220;structures&#8221;.  Some get lucky, but the entire process of foreigners buying and selling land is quite risky and not recommended.</p>
<p>Foreigners can legally own condominiums, under certain conditions, but this &#8220;foreign market&#8221; results in inflated prices for condos in Thailand that are traded in an &#8220;artificial market place&#8221; designed for foreigners.   Condos in Bangkok and major resort areas that are up-to-par with condos in the US can easily cost more than condos in major cities in the US.  Hence, the cost of living in Thailand is not as economical as some might believe when you visit Thailand as a tourist.</p>
<p>Second, business in Thailand can best be described as protectionism with discrimination where the government has placed many barriers to entry to foreigners working and competing in Thailand.     Every foreigner must have a work permit and these work permits are expensive and time consuming to maintain.   If you own a business you must pay high professional service fees for &#8220;auditors&#8221; to perform annual and semiannual audits regardless of how much income you have (including zero).   Firms in Thailand charge thousands of dollars for these &#8221;audits&#8221;.      </p>
<p>Third, if you operate a business in Thailand, you must have a place of business (you cannot legally work from your condo you bought at high prices!), so you are forced, by law, to lease office space.   Foreigners from the US, for example, must be paid a minimum of 50,000 Thai Baht per month, so the government will take 10 percent of that each month as their share of tax withholdings.  Startups with no income simply pay income taxes against their personal savings to comply with the law.  Therefore, to start a company and maintain the business in Thailand, you are required to pay significant startup, monthly, semi-annual and annual fees, permits, tax, leases, visas, etc. </p>
<p>Forth, generating incoming revenue in Thailand can be quite difficult in a climate of both protectionism and discrimination.   In Thailand, it is easy when you are spending money.  This is the &#8221;Land of Smiles&#8221; that tourists see and experience.   However, when you are legally permitted to work in Thailand and trying to generate in-country income, you cannot help but notice the protectionism and discrimination against foreigners working and living here.  Many foreigners working in Thailand just &#8220;give up&#8221; because the barriers to business success are quite high.</p>
<p>Fifth, on top of the challenges of protectionism/discrimination regarding foreigners and foreign investments, which I have only just scratched the surface here, is the overall global business slowdown combined with a climate of political instability which I am sure you have seen in the news.  Thailand has seen 18 coups since 1932.   Currently, <a href="http://www.independent.co.uk/news/world/asia/state-of-emergency-declared-in-thailand-916866.html" target="_blank">Thailand is under a State-of-Emergency </a> which negatively impacts business even more.  Sound challenging? </p>
<p>Most people who live and work in Thailand have the opinion that it is far better to enjoy being a tourist here. Working in Thailand is very difficult for many reasons.   Being a tourist in Thailand is completely different than working here.  When you are a tourist, foreign currently flows from you into Thailand, so life in Thailand as a tourist is fun and friendly, hence the &#8220;Land of Smiles&#8221; you have heard about or experienced.     However, when you are working in Thailand and trying to generate income from Thailand versus bringing in foreign currency, you don&#8217;t see the &#8220;Land of Smiles&#8221; quite the same anymore.</p>
<p>Without getting into too many details in this post, I can simply say that a foreigner doing business in Thailand experiences both protectionism and discrimination.  I came to Thailand hoping to contribute my experience to help the Kingdom.  However, sometimes it feels like foreigners are only welcome if you are working for free, giving seminars for free, and bringing in lots of foreign currency here.</p>
<p>In a future post on business in Thailand I will dive into some details on a number of topics that might be of interest to readers who will never have a chance to come and work here.   </p>
]]></content:encoded>
      <pubDate>Fri, 05 Sep 2008 10:16:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/thailand">thailand</category>
      <category domain="http://securityratty.com/tag/visit thailand">visit thailand</category>
      <category domain="http://securityratty.com/tag/thailand progressin">thailand progressin</category>
      <category domain="http://securityratty.com/tag/thailand chargethousands">thailand chargethousands</category>
      <category domain="http://securityratty.com/tag/lifein thailand">lifein thailand</category>
      <category domain="http://securityratty.com/tag/foreigners">foreigners</category>
      <category domain="http://securityratty.com/tag/foreigners canown">foreigners canown</category>
      <category domain="http://securityratty.com/tag/businessin thailand">businessin thailand</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <source url="http://www.thecepblog.com/2008/09/05/business-in-thailand-part-1-the-challenge/">Business In Thailand - Part 1: The Challenge</source>
    </item>
    <item>
      <title><![CDATA[Business In Thailand - Part 1: The Challenge]]></title>
      <link>http://securityratty.com/article/ea0ac16a8a09729fec092a6a2c0a7e21</link>
      <guid>http://securityratty.com/article/ea0ac16a8a09729fec092a6a2c0a7e21</guid>
      <description><![CDATA[Recently someone asked about business in Thailand.Here is my first post on this topic
First of all, I learned the Thai alphabet nearly 20 years ago, so I have have a pretty good foundation for the...]]></description>
      <content:encoded><![CDATA[<p>Recently someone asked about business in Thailand.  Here is my first post on this topic:</p>
<p>First of all, I learned the Thai alphabet nearly 20 years ago, so I have have a pretty good foundation for the Thai language.   I can read (slowly) and speak better than 99.99+ percent of all foreigners in Thailand; so, I thought it was time to redirect my career to a &#8220;new challenge&#8221; in the business climate of Thailand.   </p>
<p>This was no small decision.  Your career changes dramatically when you give up a successful consulting practice in the US and dive into business in a foreign land for a new challenge.  I can frankly tell you that often the challenge is sometimes overwhelming.    It is quite difficult as a foreigner to do business in Thailand.</p>
<p>First of all, it is not legal for foreigners to own land in Thailand.  Foreigners can &#8221;own&#8221; land using a variety of legal loopholes, proxy owners and shell companies; but all of this is risky and not advised.  Foreigners lose a lot of money coming to Thailand and attempting to buy land.  Some get lucky, but the entire process of foreigners buying and selling land is quite risky.</p>
<p>Foreigners can own condos, under certain conditions, but this results in  inflated prices for condos in Thailand that are traded in an artificial market place.   Condos that are up-to-par with condos in the US can easily cost more than condos in major cities in the US.  Hence, the cost of living is not as cheap as some might believe.</p>
<p>Business can best be described as &#8220;protectism&#8221; where the government has placed many barriers to entry to foreigners working in Thailand.     Every foreigner must have a work permit and these work permits are expensive and time consuming to maintain.   If you own a business you must pay high professional service fees for auditors to perform annual and semiannual audits even if your business has no income yet.   Firms in Thailand charge thousands of dollars for these &#8221;audits&#8221;.      </p>
<p>In addition, if you operate a business, you must have a place of business, so you are forced to lease office space.   Foreigners from the US must be paid a minimum of 50,000 Thai Baht per month, so the government will take 10 percent of that each month as their share of tax withholdings.   Therefore, to start a company, you will pay a lot of money in startup fees, permits, tax, leases, visas, etc.  The entire system is designed to secure money from you, even if you do not have a penny of incoming revenue.</p>
<p>Of course, generating incoming revenue can be quite difficult in a climate of protectionism.   In Thailand, it is easy when you are spending money.  When you are trying to generate income from Thailand, as a foreigner the challenge can seem overwhelming at times.   Many foreigners here give up because the barriers to business here are very high.</p>
<p>On top of all these challenges, which I have not described in detail, is the overall global business slowdown combined with a climate of political instability, which I am sure you have seen in the news.  </p>
<p>Most people I know say it is better to be a tourist here.   Being a tourist is completely different.  Money flows from you, so life in Thailand is fun and friendly, complimentary to the &#8220;Land of Smiles&#8221; you have heard about.     However, when you are working to have money flow the other direction, flow to you versus away from you, you don&#8217;t see the &#8220;Land of Smiles&#8221; as tourists experience.</p>
<p>Without getting into too many details, I can simply say that a foreigner doing business in Thailand experiences protectionism and, to a certain degree, discrimination, and sometimes I wonder if coming here for a &#8220;business challenge&#8221; was a good idea.    I was seeking a &#8220;new challenge&#8221; and I got more than I bargained for!</p>
<p>In a future post on business in Thailand I will discuss issues regarding how little value is placed in intellectual property in Thailand and how this adversely impacts professional services.    I will also touch on how this lack of regard for intellectual property impacts a consulting practice.   Also, I will touch on some cultural differences in how Thais appear to view teamwork, which is very different than in the US.</p>
<p> </p>
]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 10:16:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/challenge">challenge</category>
      <category domain="http://securityratty.com/tag/business">business</category>
      <category domain="http://securityratty.com/tag/thailand">thailand</category>
      <category domain="http://securityratty.com/tag/business challenge">business challenge</category>
      <category domain="http://securityratty.com/tag/global business slowdown">global business slowdown</category>
      <category domain="http://securityratty.com/tag/thailand chargethousands">thailand chargethousands</category>
      <category domain="http://securityratty.com/tag/foreigners">foreigners</category>
      <category domain="http://securityratty.com/tag/money">money</category>
      <category domain="http://securityratty.com/tag/money flows">money flows</category>
      <source url="http://www.thecepblog.com/2008/09/04/business-in-thailand-part-1-the-challenge/">Business In Thailand - Part 1: The Challenge</source>
    </item>
    <item>
      <title><![CDATA[Technology Tales from Thailand: KBank Fraud Management]]></title>
      <link>http://securityratty.com/article/5f893d1cf14b7adbe58a329292652735</link>
      <guid>http://securityratty.com/article/5f893d1cf14b7adbe58a329292652735</guid>
      <description><![CDATA[In The Magical ATM Card and SMS Message in Thailand we talked about booking flights and securely paying using a SMS PayCode and ATM transfer, avoiding the possibility of on-line credit card fraud; and...]]></description>
      <content:encoded><![CDATA[<p>In <a title="The Magical ATM Card and SMS Message in Thailand" rel="bookmark" href="http://www.thecepblog.com/2008/08/03/the-magical-atm-card-and-sms-message-in-thailand/"><span style="color: #105cb6;">The Magical ATM Card and SMS Message in Thailand</span></a> we talked about booking flights and securely paying using a SMS PayCode and ATM transfer, avoiding the possibility of on-line credit card fraud; and in <a title="Keyloggers: Why Banks Need Two-Factor Authentication" rel="bookmark" href="http://www.thecepblog.com/2008/01/14/keyloggers-why-banks-need-two-factor-authentication/"><span style="color: #105cb6;">Keyloggers: Why Banks Need Two-Factor Authentication</span></a> I described how <a href="http://www.kasikornbank.com/portal/site/KBank/?" target="_blank">KBank</a> uses SMS-based one-time-passwords (OTP) to authenticate transactions.   </p>
<p>In addition to the above services, KBank offers a service that permits users to receive an SMS message that details any change in account balance and/or point-of-sale (POS) transaction with your debit card.   I really like this service and the feeling of security knowing when, where and by how much my balance changes or my debit card is used in a transaction.    The KBank POS SMS notification is so fast that when I present my card to a merchant I normally receive an SMS message detailing the transaction before the merchant returns for my signature.  (There is an unfortunate lag in the balance change notification that can run minutes to hours behind real-time, but the POS VISA debit card notification is real-time).</p>
<p>As the story goes,  I should have been using my KBank card and account a few weeks ago and not my US-based VISA debit dard.  Why?</p>
<p>My US-based VISA debit card was cloned sometime on or before August 8th.   I am really careful with this card, so I was surprised the magnetic strip was cloned at a POS merchant.   The fraudster made 7 fraudulent transactions beginning on August 8th for a total of around $2500 USD, mostly on August 11th, before I discovered the fraudulent transactions viewing my account on-line.</p>
<p>This would not have happened with KBank SMS-based transaction notification services.</p>
<p>The first transaction with my cloned VISA debit card was less than $50 USD (I assume the fraudster was &#8220;testing the water&#8221;).   If I was using my KBank card, I would have received an immediate SMS message detailing a POS transaction in Bangkok when I was physically far away from Bangkok in Chiang Mai.   I could have immediately called the bank (or logged in) and blocked the debit card, limiting potential losses to the bank or the merchant to one fraudulent transaction, not seven.</p>
<p>In addition, KBank offers what they call a Web-Shopping VISA card, where you can go into your on-line account (verified by SMS OTP as mentioned) and request a VISA debit card number (with expiration date, CCV etc).   You set the limit from 0 to 500,000 THB (Thai Baht) per day; and you can login to your account and change this anytime (authenticating your transaction with another SMS-based OTP). You can also block or cancel this number anytime and apply for another one.</p>
<p>I am amazed that in Thailand I receive much better anti-fraud prevention and detection services than with banks in the US.   I know of no bank or brokerage in the US that offers the same quality of service and security as KBank in Thailand.  </p>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 03:16:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/visa debit card">visa debit card</category>
      <category domain="http://securityratty.com/tag/debit card">debit card</category>
      <category domain="http://securityratty.com/tag/card">card</category>
      <category domain="http://securityratty.com/tag/visa card">visa card</category>
      <category domain="http://securityratty.com/tag/kbank">kbank</category>
      <category domain="http://securityratty.com/tag/kbank card">kbank card</category>
      <category domain="http://securityratty.com/tag/transaction">transaction</category>
      <category domain="http://securityratty.com/tag/transaction notification services">transaction notification services</category>
      <category domain="http://securityratty.com/tag/fraudulent transaction">fraudulent transaction</category>
      <source url="http://www.thecepblog.com/2008/08/20/technology-tales-from-thailand/">Technology Tales from Thailand: KBank Fraud Management</source>
    </item>
    <item>
      <title><![CDATA[The Fallacy of Self-Fulfilling CEP Use Case Studies]]></title>
      <link>http://securityratty.com/article/47aaa0956d45ca036911731d192fc4e3</link>
      <guid>http://securityratty.com/article/47aaa0956d45ca036911731d192fc4e3</guid>
      <description><![CDATA[I am back at the glaring computer screenafter a day in Lamphun , Northern Thailand, hanging out will my friends who are preparing for a Bonsai tree competition.I spent the dayeating Thai and Chinese...]]></description>
      <content:encoded><![CDATA[<p>I am back at the glaring computer screen after a day in <a href="http://en.wikipedia.org/wiki/Lamphun" target="_blank">Lamphun</a>, Northern Thailand, hanging out will my friends who are preparing for a Bonsai tree competition.  I spent the day eating Thai and Chinese food and relaxing in a lounge chair under imported blue palm trees with the sound of exotic birds making background music to keep me entertained.</p>
<p>Back to CEP and EPTS, there are folks who appear to believe they may define &#8220;CEP&#8221; by the current use cases from self-described CEP vendors. Frankly speaking, I am puzzled by the bottom-up approach.</p>
<p>The bottom-up approach is a bit like saying &#8220;We have a lot of prototype rockets being built, so let&#8217;s define the future of space travel based on the prototypes!&#8221;</p>
<p>It really makes little sense, at least to me, to attempt to define CEP based on what the current generation products (self-described CEP products) are capable of doing.   </p>
<p>From my persective, it would be more beneficial to customers to define the types of complex events (and situations) businesses need to detect in real-time and match the technologies and solution architectures to detect those events, in real-time, with high confidence.</p>
<p>A lot of this &#8220;top down thinking&#8221; has been already done.</p>
<p>IT businesses need to detect operational threats and problems, and be able to pinpoint, with very high accuracy, where the problem is in a complex network, for example.  This problem remains mostly unsolved with a very low signal-to-noise ratio.</p>
<p>Also, most businesses would like to detect fraud and other criminal activity on their network before the activities adversely impacts their business.   This problem remains unsolved for most companies.</p>
<p>Scientific researchers seek models of weather, epidemiology, and so much more; and they need event processing solutions to obtain situational knowledge into current events and predict future ones.  We know how difficult predicting the weather can be!</p>
<p>Folks on the ground need to model urban traffic as events and design better event-driven traffic models and solutions.</p>
<p>The list of important event processing challenges we face go on and on.  </p>
<p>While I see some merit in the bottom-up approach, it is better for users to define what are practical &#8220;complex event&#8221; related problems and then look for the solutions, vs. define the solution and then look for the problem.</p>
<p>From a strategic perspective,  self-fulfilling CEP use case studies are interesting, but they hould not limit the vision, definition, and future of processing complex events; and be careful of use case <a href="http://en.wikipedia.org/wiki/List_of_fallacies" target="_blank">fallacies</a>.</p>
]]></content:encoded>
      <pubDate>Wed, 06 Aug 2008 11:30:13 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cep">cep</category>
      <category domain="http://securityratty.com/tag/cep products">cep products</category>
      <category domain="http://securityratty.com/tag/believethey maydefine cep">believethey maydefine cep</category>
      <category domain="http://securityratty.com/tag/detect">detect</category>
      <category domain="http://securityratty.com/tag/liketo detect fraud">liketo detect fraud</category>
      <category domain="http://securityratty.com/tag/cep vendors">cep vendors</category>
      <category domain="http://securityratty.com/tag/current generation products">current generation products</category>
      <category domain="http://securityratty.com/tag/complex events">complex events</category>
      <category domain="http://securityratty.com/tag/define">define</category>
      <source url="http://www.thecepblog.com/2008/08/06/the-fallacy-of-self-fulfilling-cep-use-case-studies/">The Fallacy of Self-Fulfilling CEP Use Case Studies</source>
    </item>
    <item>
      <title><![CDATA[The Magical ATM Card and SMS Message in Thailand]]></title>
      <link>http://securityratty.com/article/1ba59a13d2493ca9d5042d5c2f7ceb4e</link>
      <guid>http://securityratty.com/article/1ba59a13d2493ca9d5042d5c2f7ceb4e</guid>
      <description><![CDATA[It was not too long ago that I penned Keyloggers: Why Banks Need Two-Factor Authentication . In that post, I briefly mentioned how a number of banks in Thailand use inexpensive SMS-based two-factor...]]></description>
      <content:encoded><![CDATA[<p>It was not too long ago that I penned <a href="http://www.thecepblog.com/2008/01/14/keyloggers-why-banks-need-two-factor-authentication/">Keyloggers: Why Banks Need Two-Factor Authentication</a>. In that post, I briefly mentioned how a number of banks in Thailand use inexpensive SMS-based two-factor authentication (2FA) with one-time password (OTP) to authenticate transactions.</p>
<p>One of my favorite banks in Thailand is <a href="http://www.kasikornbank.com/portal/site/KBank/?" target="_blank">K-Bank</a>. With K-Bank I can simply walk up to an ATM machine and pay a mobile phone bill, purchase mutual funds, buy insurance, or transact an ever-growing list of services payable at the modern and sleek K-Bank ATM.</p>
<p>For example, tomorrow I fly to Chiang Mai in Northern Thailand and found K-Bank&#8217;s service amazingly better than in the US. For example, I booked my flight as usual (over the phone, but could have used the Internet) and told the reservation agent I was going to pay by ATM. He simply gave me a PayCode and told me I had three hours to go to the ATM and enter the PayCode to perfect my reservation.  I also got the PayCode via SMS.  This gave me the time I needed to make sure I had <a href="http://www.r24.org/whatsonchiangmai.com/chiangmai/fernparadise/pictures/" target="_blank">booked the perfect boutique hotel</a> in Chiang Mai, the <strong><a href="http://www.r24.org/whatsonchiangmai.com/chiangmai/fernparadise/review/" target="_blank">Fern Paradise</a>.</strong></p>
<p>Then, I went out into the beautiful Thai weather and completely my airplane reservation at the ATM machine; which also printed out a receipt with my flight details and reservation number.</p>
<p>It sometimes amazes me how much further advanced some services are in Thailand compared to the US. To me, it feels more secure not to use an on-line payment center or give out my credit card details over the phone. I can simply book a ticket, take a PayCode, and complete the transaction at a nice modern, shiny, K-Bank ATM machine.</p>
<p>Who knows, maybe soon I can select the perfect window seat at the ATM and the receipt will act as my boarding pass!</p>
]]></content:encoded>
      <pubDate>Sun, 03 Aug 2008 09:30:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/atm">atm</category>
      <category domain="http://securityratty.com/tag/k-bank atm machine">k-bank atm machine</category>
      <category domain="http://securityratty.com/tag/sleek k-bank atm">sleek k-bank atm</category>
      <category domain="http://securityratty.com/tag/k-bank">k-bank</category>
      <category domain="http://securityratty.com/tag/thailand">thailand</category>
      <category domain="http://securityratty.com/tag/atm machine">atm machine</category>
      <category domain="http://securityratty.com/tag/banks">banks</category>
      <category domain="http://securityratty.com/tag/perfect window seat">perfect window seat</category>
      <category domain="http://securityratty.com/tag/perfect">perfect</category>
      <source url="http://www.thecepblog.com/2008/08/03/the-magical-atm-card-and-sms-message-in-thailand/">The Magical ATM Card and SMS Message in Thailand</source>
    </item>
    <item>
      <title><![CDATA[Wee-Fi: Car-Fi, Boston Ferry-Fi, Thai-Fi]]></title>
      <link>http://securityratty.com/article/2c859bc4acfb354040b0928482e21bd1</link>
      <guid>http://securityratty.com/article/2c859bc4acfb354040b0928482e21bd1</guid>
      <description><![CDATA[Chrysler offers automotive Internet access as 2009 model option: All its newest cars and trucks will, for an undisclosed price, act as cellular relays over Wi-Fi. The news was leaked and details...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://latimesblogs.latimes.com/technology/2008/06/chrysler-to-tur.html?cid=120125120#comments"><strong>Chrysler offers automotive Internet access as 2009 model option:</strong></a> All its newest cars and trucks will, for an undisclosed price, act as cellular relays over Wi-Fi. The news was leaked and details should be available tomorrow. The LA Times writer notes that while only passengers should use the Internet while the car is in motion, there's no way to prevent the driver from surfing. Except common sense. Yeah, that'll work. (The writer has confused his megas and kilos; the likely EVDO Rev. A service that will power this system runs at 600 Kbps to 1.4 Mbps downstream and 350 to 550 Kbps upstream, according to the cell operators.)</p>

<p><a href="http://www.metrobostonnews.com/us/article/2008/06/25/03/0515-66/index.xml"><strong>Boston ferries gain Wi-Fi:</strong></a> The MTBA has put Internet access on its 11 commuter boats that serve 4,500 daily riders. Ridership is way up this year.</p>

<p><a href="http://afp.google.com/article/ALeqM5g_cp1eD_monzp7gY9odfRlPpw0cw"><strong>Bangkok builds slow Wi-Fi network, free for first year:</strong></a> The details are a bit sketchy, but the government has built a 15,000-hotspot network that offer 64 Kbps connections, and will be free (with an access card) for the first year. The government is handing out 500,000 such cards at shopping malls before this week's launch.</p>]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 09:43:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/kbps upstream">kbps upstream</category>
      <category domain="http://securityratty.com/tag/kbps">kbps</category>
      <category domain="http://securityratty.com/tag/times writer notes">times writer notes</category>
      <category domain="http://securityratty.com/tag/writer">writer</category>
      <category domain="http://securityratty.com/tag/kbps connections">kbps connections</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <category domain="http://securityratty.com/tag/internet access">internet access</category>
      <category domain="http://securityratty.com/tag/000-hotspot network">000-hotspot network</category>
      <category domain="http://securityratty.com/tag/evdo rev">evdo rev</category>
      <source url="http://wifinetnews.com/archives/008378.html">Wee-Fi: Car-Fi, Boston Ferry-Fi, Thai-Fi</source>
    </item>
    <item>
      <title><![CDATA[ICT Cmte: Thailands Cyber Law Compliance Seminar]]></title>
      <link>http://securityratty.com/article/be79095431b01548cc9cc3f74c01bc94</link>
      <guid>http://securityratty.com/article/be79095431b01548cc9cc3f74c01bc94</guid>
      <description><![CDATA[ICT Cmte: Thailands Cyber Law Compliance Seminar
American Chamber of Commerce in Thailand
Date &amp; Time: 17-Jun-2008
Details : This month You are invited to attend a Computer Crime Act Compliance...]]></description>
      <content:encoded><![CDATA[<div class='snap_preview'><br /><p><a href="http://www.amchamthailand.com/ACCT/asp/EventDetail.asp?EventID=2539&amp;SponsorId=0" target="_blank">ICT Cmte: Thailand&#8217;s Cyber Law Compliance Seminar</a></p>
<p><a href="http://www.amchamthailand.com/" target="_blank">American Chamber of Commerce in Thailand</a></p>
<p>Date &amp; Time: 17-Jun-2008</p>
<p><a href="http://www.amchamthailand.com/ACCT/asp/EventDetail.asp?EventID=2539&amp;SponsorId=0" target="_blank">Details</a>: This month You are invited to attend a Computer Crime Act Compliance Seminar. Find out what the Thai “Cyber Law” requires, when it will start to be enforced and how you can comply. If your business or hotel offers Internet access to customers, employees or end users, this will be a practical session for you to gain a better understanding of the <a href="http://multimedia.prachatai.com/doc/2007/Computer_Crimes_Act_B.E._2550_Eng.pdf" target="_blank">Thai Computer Crime Act</a>.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/eventprocessing.wordpress.com/252/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/eventprocessing.wordpress.com/252/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/eventprocessing.wordpress.com/252/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/eventprocessing.wordpress.com/252/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/eventprocessing.wordpress.com/252/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/eventprocessing.wordpress.com/252/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/eventprocessing.wordpress.com/252/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/eventprocessing.wordpress.com/252/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/eventprocessing.wordpress.com/252/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/eventprocessing.wordpress.com/252/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/eventprocessing.wordpress.com/252/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/eventprocessing.wordpress.com/252/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thecepblog.com&blog=1100533&post=252&subd=eventprocessing&ref=&feed=1" /></div>]]></content:encoded>
      <pubDate>Thu, 12 Jun 2008 12:29:10 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ict cmte">ict cmte</category>
      <category domain="http://securityratty.com/tag/american chamber">american chamber</category>
      <category domain="http://securityratty.com/tag/practical session">practical session</category>
      <category domain="http://securityratty.com/tag/thailand">thailand</category>
      <category domain="http://securityratty.com/tag/employees">employees</category>
      <category domain="http://securityratty.com/tag/month">month</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/comply">comply</category>
      <source url="http://thecepblog.com/2008/06/12/ict-cmte-thailands-cyber-law-compliance-seminar/">ICT Cmte: Thailands Cyber Law Compliance Seminar</source>
    </item>
  </channel>
</rss>
