<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: tragedy]]></title>
    <link>http://securityratty.com/tag/tragedy</link>
    <description></description>
    <pubDate>Sat, 12 Jan 2008 03:27:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Lessons from Mumbai]]></title>
      <link>http://securityratty.com/article/ca74a145bde98eb6902487f29715eaa3</link>
      <guid>http://securityratty.com/article/ca74a145bde98eb6902487f29715eaa3</guid>
      <description><![CDATA[I'm still reading about the Mumbai terrorist attacks, and I expect it'll be a long time before we get a lot of the details. What we know is horrific, and my sympathy goes out to the survivors of the...]]></description>
      <content:encoded><![CDATA[<p>I'm still reading about the Mumbai terrorist attacks, and I expect it'll be a long time before we get a lot of the details.  What we know is horrific, and my sympathy goes out to the survivors of the dead (and the injured, who often seem to get ignored as people focus on death tolls).  Without discounting the awfulness of the events, I have some initial observations:</p>

<ul><li>Low-tech is very effective.  <a href="http://www.schneier.com/essay-087.html">Movie-plot threats</a> -- terrorists with crop dusters, terrorists with biological agents, terrorists targeting our water supplies -- might be what people worry about, but a bunch of trained (we don't really know yet what sort of training they had, but it's clear that they <a href="http://www.news.com.au/couriermail/story/0,23739,24726093-954,00.html">had some</a>) men with guns and grenades is all they needed.

<p><li>At the same time, the attacks were surprisingly ineffective.  I can't find exact numbers, but it seems there were about 18 terrorists.  The latest toll is 195 dead, 235 wounded.  That's 11 dead, 13 wounded, per terrorist.  As horrible as the reality is, that's much less than you might have thought if you imagined the movie in your head.  Reality is <a href="http://www.pebbleandavalanche.com/weblog/2008/11/30/blog-20081130T1857">different</a> from the movies.</p>

<p><li>Even so, terrorism is rare.  If a bunch of men with guns and grenades is all they really need, then why isn't this sort of terrorism more common?  Why not in the U.S., where it's easy to get hold of weapons?  It's because terrorism is very, very rare.</p>

<p><li>Specific countermeasures don't help against these attacks.  None of the high-priced countermeasures that defend against specific tactics and specific targets made, or would have made, any difference: photo ID checks, confiscating liquids at airports, fingerprinting foreigners at the border, bag screening on public transportation, anything.  Even<a href="http://www.upi.com/Top_News/2008/11/29/Executive_says_Taj_hotel_warned_of_attack/UPI-97361228007685/">metal detectors and threat warnings</a> didn't do any good:</p>

<blockquote>"If I look at what we had, which all of us complained about, it could not have stopped what took place," he told CNN. "It's ironic that we did have such a warning, and we did have some measures."

<p>He said people were told to park away from the entrance and had to go through a metal detector. But he said the attackers came through a back entrance.</p>

<p>"They knew what they were doing, and they did not go through the front. All of our arrangements are in the front," he said.</blockquote></ul></p>

<p>If there's any lesson in these attacks, it's not to focus too much on the specifics of the attacks.  Of course, that's not the way we're programmed to think.  We <a href="http://www.schneier.com/essay-171.html">respond to stories</a> and not analysis.  I don't mean to be sympathetic; this tendency is human and these deaths are really tragic.  But eighteen armed people intent on killing lots of innocents will be able to do just that, and last-line-of-defense countermeasures won't be able to stop them.  Intelligence, investigation, and emergency response.  We have to find and stop the terrorists before they attack, and deal with the aftermath of the attacks we don't stop.  There really is no other way, and I hope that we don't let the tragedy lead us into unwise decisions about how to deal with terrorism.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=4dGOO"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=4dGOO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=qnl9O"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=qnl9O" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 05:03:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mumbai terrorist attacks">mumbai terrorist attacks</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/armed people intent">armed people intent</category>
      <category domain="http://securityratty.com/tag/people focus">people focus</category>
      <category domain="http://securityratty.com/tag/focus">focus</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/terrorism">terrorism</category>
      <category domain="http://securityratty.com/tag/terrorist">terrorist</category>
      <source url="http://www.schneier.com/blog/archives/2008/12/lessons_from_mu.html">Lessons from Mumbai</source>
    </item>
    <item>
      <title><![CDATA[Gonzo: Two Thumbs In and Up]]></title>
      <link>http://securityratty.com/article/6853c438c7bef73e63a300124d9cf5de</link>
      <guid>http://securityratty.com/article/6853c438c7bef73e63a300124d9cf5de</guid>
      <description><![CDATA[Just saw the Hunter S. Thompson movie - Gonzo , and if you are a fan you should to. Lots of good stuff in there, the film links various part of his life and career, and gives a pretty unvarnished view...]]></description>
      <content:encoded><![CDATA[<p><a href="http://en.wikipedia.org/wiki/Hunter_S._Thompson"></a><a style="float: left;" href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553c045c48834-pi"><img  class="at-xid-6a00d83451c75869e200e553c045c48834 " alt="180px-Gonzo_citation" src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553c045c48834-320wi" style="margin: 0px 5px 5px 0px;"></a> Just saw the Hunter S. Thompson movie - <a href="http://www.rottentomatoes.com/m/gonzo_the_life_and_work_of_dr_hunter_s_thompson/">Gonzo</a>, and if you are a fan you should to. Lots of good stuff in there, the film links various part of his life and career, and gives a pretty unvarnished view of the high highs and the low lows. Weaves in writing, politics, and fame seamlessly.

I have never really had as much fun as early on in my career in the early-mid 90s I was a web programmer in Aspen, hacking CGI/PERL. Among the most fun things was building and running HST's site. My boss, Ed, was his neighbor. Ed was also seriously allergic to bees. One day he was alone in his house and got stung. He was dying. Luckily Hunter was due over to his house to watch a basketball game, walked in and called 911. My boss woke up in the ambulance with Hunter pounding on him chest and screaming at him. Ed said - "Waking up to that face screaming at me, I didn't know if I was alive or dead."

Seeing the movie it was also great to see a lot of the Woody Creek folks again like George Stranahan, who lovingly said about Hunter - "my friend and neighbor who never paid his rent, broke up my marriage and taught my children to smoke dope. "

Of course, there was no way he could match his early productivity and this is true of almost all artists. Most of the last two decades were wasted from a writing standpoint. However his <a href="http://proxy.espn.go.com/espn/page2/story?id=1250751">piece</a> written on 9/11 is as good as its gets:

</p><blockquote><p>
	The towers are gone now, reduced to bloody rubble, along with all hopes for Peace in Our Time, in the United States or any other country. Make no mistake about it: We are At War now -- with somebody -- and we will stay At War with that mysterious Enemy for the rest of our lives. 	
	</p></blockquote><blockquote><p>It will be a Religious War, a sort of Christian Jihad, fueled by religious hatred and led by merciless fanatics on both sides. It will be guerilla warfare on a global scale, with no front lines and no identifiable enemy. Osama bin Laden may be a primitive "figurehead" -- or even dead, for all we know -- but whoever put those All-American jet planes loaded with All-American fuel into the Twin Towers and the Pentagon did it with chilling precision and accuracy. The second one was a dead-on bullseye. Straight into the middle of the skyscraper. 	
	</p></blockquote><blockquote><p>Nothing -- even George Bush's $350 billion "Star Wars" missile defense system -- could have prevented Tuesday's attack, and it cost next to nothing to pull off. Fewer than 20 unarmed Suicide soldiers from some apparently primitive country somewhere on the other side of the world took out the World Trade Center and half the Pentagon with three quick and costless strikes on one day. The efficiency of it was terrifying. 	
	</p></blockquote><blockquote><p>We are going to punish somebody for this attack, but just who or what will be blown to smithereens for it is hard to say. Maybe Afghanistan, maybe Pakistan or Iraq, or possibly all three at once. Who knows? Not even the Generals in what remains of the Pentagon or the New York papers calling for WAR seem to know who did it or where to look for them. 	
	</p></blockquote><blockquote><p>This is going to be a very expensive war, and Victory is not guaranteed -- for anyone, and certainly not for anyone as baffled as George W. Bush. All he knows is that his father started the war a long time ago, and that he, the goofy child-President, has been chosen by Fate and the global Oil industry to finish it Now. He will declare a National Security Emergency and clamp down Hard on Everybody, no matter where they live or why. If the guilty won't hold up their hands and confess, he and the Generals will ferret them out by force. 	
	</p></blockquote><blockquote><p>Good luck. He is in for a profoundly difficult job -- armed as he is with no credible Military Intelligence, no witnesses and only the ghost of Bin Laden to blame for the tragedy.
	
</p></blockquote><p>


One unintended lesson I take away from Hunter's life is how important patience is. Obama is a politician and may yet disappoint us all, but I gotta believe Hunter would be seriously impressed. If he had waited another couple of years, he may have seen a lot of the stuff he fought for in 1968 and 72 come to fruition. Sometimes you are just 36-40 years ahead of your time and you have to be ok with that and figure out how to deal if possible. (Note - it sure sometimes feels this way in software security).

Speaking of security:

</p><blockquote>
	<p><a href="http://www.ram.org/contrib/security.html">Security</a> 	
	</p></blockquote><blockquote><p>by Hunter S. Thompson (1955). 	
	</p></blockquote><blockquote><p>Security ... what does this word mean in relation to life as we know it today? For the most part, it means safety and freedom from worry. It is said to be the end that all men strive for; but is security a utopian goal or is it another word for rut? 	
	</p></blockquote><blockquote><p>Let us visualize the secure man; and by this term, I mean a man who has settled for financial and personal security for his goal in life. In general, he is a man who has pushed ambition and initiative aside and settled down, so to speak, in a boring, but safe and comfortable rut for the rest of his life. His future is but an extension of his present, and he accepts it as such with a complacent shrug of his shoulders. His ideas and ideals are those of society in general and he is accepted as a respectable, but average and prosaic man. But is he a man? has he any self-respect or pride in himself? How could he, when he has risked nothing and gained nothing? What does he think when he sees his youthful dreams of adventure, accomplishment, travel and romance buried under the cloak of conformity? How does he feel when he realizes that he has barely tasted the meal of life; when he sees the prison he has made for himself in pursuit of the almighty dollar? If he thinks this is all well and good, fine, but think of the tragedy of a man who has sacrificed his freedom on the altar of security, and wishes he could turn back the hands of time. A man is to be pitied who lacked the courage to accept the challenge of freedom and depart from the cushion of security and see life as it is instead of living it second-hand. Life has by-passed this man and he has watched from a secure place, afraid to seek anything better What has he done except to sit and wait for the tomorrow which never comes? 	
	</p></blockquote><blockquote><p>Turn back the pages of history and see the men who have shaped the destiny of the world. Security was never theirs, but they lived rather than existed. Where would the world be if all men had sought security and not taken risks or gambled with their lives on the chance that, if they won, life would be different and richer? It is from the bystanders (who are in the vast majority) that we receive the propaganda that life is not worth living, that life is drudgery, that the ambitions of youth must he laid aside for a life which is but a painful wait for death. These are the ones who squeeze what excitement they can from life out of the imaginations and experiences of others through books and movies. These are the insignificant and forgotten men who preach conformity because it is all they know. These are the men who dream at night of what could have been, but who wake at dawn to take their places at the now-familiar rut and to merely exist through another day. For them, the romance of life is long dead and they are forced to go through the years on a treadmill, cursing their existence, yet afraid to die because of the unknown which faces them after death. They lacked the only true courage: the kind which enables men to face the unknown regardless of the consequences. 	
	</p></blockquote><blockquote><p>As an afterthought, it seems hardly proper to write of life without once mentioning happiness; so we shall let the reader answer this question for himself: who is the happier man, he who has braved the storm of life and lived or he who has stayed securely on shore and merely existed?
</p></blockquote><p>

A ship is safest at port, but thats not why we build ships. 
</p>]]></content:encoded>
      <pubDate>Thu, 17 Jul 2008 06:10:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/life">life</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/sought security">sought security</category>
      <category domain="http://securityratty.com/tag/personal security">personal security</category>
      <category domain="http://securityratty.com/tag/national security emergency">national security emergency</category>
      <category domain="http://securityratty.com/tag/software security">software security</category>
      <category domain="http://securityratty.com/tag/expensive war">expensive war</category>
      <category domain="http://securityratty.com/tag/war">war</category>
      <category domain="http://securityratty.com/tag/hunter">hunter</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/07/gonzo-two-thumbs-in-and-up.html">Gonzo: Two Thumbs In and Up</source>
    </item>
    <item>
      <title><![CDATA[Young Canadian Model Murdered in Shanghai.]]></title>
      <link>http://securityratty.com/article/5f5db7658c71a70694e1d8076bdf2a7c</link>
      <guid>http://securityratty.com/article/5f5db7658c71a70694e1d8076bdf2a7c</guid>
      <description><![CDATA[This is a very sad story . It needs to get out so other young girls and their parents can learn from this tragedy

I traveled to China last year on a two week business trip. One of the thoughts that...]]></description>
      <content:encoded><![CDATA[This is a very <a href="http://www.msnbc.msn.com/id/25642790/">sad story</a>.  It needs to get out so other young girls and their parents can learn from this tragedy.<br /><span id="fullpost"><br />I traveled to China last year on a two week business trip. One of the thoughts that struck me was that it appeared to be a very law abiding society.  Then when I visited Tiananmen Square, I was reminded of the scene when Government tanks turned on young student protestors and masacared them.  There is much about China that lays beneath the surface.<br /><br />Diana O'Brien was a young model from Canada who was lured to China with promises of "catwalk" modelling opportunities.  Once she arrived there, the opportunities became offers to dance in bars.  Apparently, many young girls go to China thinking they are breaking into the big time when in reality, many of these modelling agencies inlvolve little more than an apartment and a cell phone.<br /><br />The JH model managment company that Diana worked for disappeared when news of her murder broke.  Their website was taken down on Thursday.  Although an official from the State Security Bureau would not comment, her murder seems to have been committed by a street criminal who stabbed her to death near her apartment for her belongings.  <br /><br />Young women and the parents of young women, need to know what they are getting themselves into before they travel to a strange place and put their lives in the hands of people who see them merely as a way to make money.  This coming in the wake of the summer Olympics might cause some to question their own saftey in Beijing.  Some of the age old principles still hold true; Beaware of your surroundings, Never travel alone - always have at least one companion at all times, Always let people know where you are going, Carry a cell phone (and pepper spray it is is allowed)to enable you to call for help.<br /><br />In the streets of Beijing and Shanghai, people will approach you all of the time trying to get you to buy; fake watches, perfume, stamps and many other things.  Most of these people are legitimately trying to make a sale but you do not know who are the ones that may be trying to pick-pocket you or surround you to rob you or lure you off a busy street where you won't be seen so easily.  Walk briskly past them and ignore them.  You should shop whee you are not being hassled and therfore can concentrate on your safety.            <br /><br /></span><em></em><div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Sat, 12 Jul 2008 10:49:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/model">model</category>
      <category domain="http://securityratty.com/tag/cell phone">cell phone</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/china">china</category>
      <category domain="http://securityratty.com/tag/model managment company">model managment company</category>
      <category domain="http://securityratty.com/tag/week business trip">week business trip</category>
      <category domain="http://securityratty.com/tag/walk briskly past">walk briskly past</category>
      <category domain="http://securityratty.com/tag/hold true">hold true</category>
      <category domain="http://securityratty.com/tag/travel">travel</category>
      <source url="http://www.thebulletproofblog.com/2008/07/young-canadian-model-murdered-in.html">Young Canadian Model Murdered in Shanghai.</source>
    </item>
    <item>
      <title><![CDATA[Your 419 Mail Roundup]]></title>
      <link>http://securityratty.com/article/2aa9ff3c4bf96550fcb31a394b91e2bc</link>
      <guid>http://securityratty.com/article/2aa9ff3c4bf96550fcb31a394b91e2bc</guid>
      <description><![CDATA[Are you ready for more 419 missives

Of course you are. Plenty of winning lottery tickets, fictitious banks, a wonderfully sick &quot;Robert Mugabe&quot; themed mail and, er, someone called &quot;Captain Frank Bojo&quot;...]]></description>
      <content:encoded><![CDATA[
        Are you ready for more 419 missives?<br /><br />Of course you are. Plenty of winning lottery tickets, fictitious banks, a wonderfully sick "Robert Mugabe" themed mail and, er, someone called "Captain Frank Bojo" after the jump...<br /> 
        Subject:<br />HELLO DEAR<br />From:<br />"abavanagift13 Gazeta.pl" &lt;abavanagift13@gazeta.pl&gt;<br />Date:<br />Sat, 21 Jun 2008 12:26:24 +0000<br />BCC:<br /><br />Hello Dear,<br />&nbsp;<br />&nbsp;My name is Blessing Abavana, the elder daughter of Mr. paul Abavana of Zimbabwe, I am 17 years old with my younger brother (Micheal), we are in Ghana as refuge/asylum since we lost our parents because of the recent war that occurred in our country.please do go through this web page for better understanding with full details:<br />&nbsp;<br />&nbsp;http://www.rte.ie/news/2000/0418/zimbabwe.html<br />&nbsp;<br />&nbsp;I am looking for one&nbsp; who will honestly assist my younger brother and I to realize our inherited funds into your account and as well as invest it into a lucrative business.<br />&nbsp;<br />During the recent war against the farmers in Zimbabwe from the supporters of our President, Robert Mugabe to claim all the white -owned farms to his party members and his followers, he ordered all the white farmers to surrender all their farms to his party members and his followers.<br />&nbsp;<br />&nbsp;My father being one of the few rich and successful black farmers in our country was also victimized because of his opposition to Mugabe's policies. And because he did not support Mugabe's ideas, Mugabe's supporters invaded my father's farm and burnt everything in the farm, killed my father and made away with a lot of items in my father's farm. This action was taken because my late father felt the growing tension on the farm issue, but I guess he never anticipated the tragedy that brought their brutal and sudden death.<br />&nbsp;<br />&nbsp;However with the benefit of hindsight, owing to the looming but deteriorating crisis in my country, Zimbabwe, my father, before his unfortunate death deposited with International Commercial Bank (ICB) here in Accra Ghana the sum of US$ 35MUsd (Thirty Five Million United States Dollars), with the sole aim of acquiring and buying some dredging equipments in setting up of a dredging firm with his partner. With his death and all his assets seized at home and accounts frozen, the family is now in a very difficult situation.<br />&nbsp;<br />&nbsp;After the death of my father, my brother and I escaped to the Republic of Ghana where he had deposited the money in the Bank . And we were permitted to reside here as Political Refugees.<br />&nbsp;<br />&nbsp;So Because of our present and unpleasant status here we decided to contact an overseas firm / individual that can assist us to move this money out Of Ghana because, as asylum seekers, we are not allowed to operate any financial transaction of such amount within Ghana and also to assist in providing me and my brother a permanent residential permit in your country after the money must have been transferred to your account.<br />&nbsp;<br />We have agreed to offer you 30% of the total sum for your assistance, and the rest will be for my brother and I, to Invest in your country under your assistant<br />&nbsp;<br />All I want you to do is to furnish me with the below information including your readiness to assist me achieve this transaction for investment purposes in your country under your supervision. Kindly re-confirm to me the followings:<br /><br />1) Your Full Name:<br />2) Phone, Fax and Mobile<br />3) Profession, Age and Marital Status.<br />4) Nationality<br />&nbsp;<br />&nbsp;I have to re-assure you that this transaction is 100% risk free and should be treated with absolute confidentiality. All the vital documentation/certification that has to do with the origin of the fund is with me for the security reasons.And I will send them to you when we progress.And I guarantee you that this fund is not government fund, drug money, or from arms deals.<br />&nbsp;<br />&nbsp;I will detail you more about&nbsp; the bank&nbsp; immediately I receive your acceptance response. I hope this is the beginning of a prosperous relationship between us.Thanks and God bless you<br />&nbsp;<br />Regards<br /><br />Blessing/Micheal Abavana<br /><br /><b>(Wow, spectacularly sick. Not that we're expecting scammers to have any morals, of course).</b><br /><br />*********************************************************************************************<br /><br /><br />Subject:<br />Lycos Online Lottery Notification<br />From:<br />"LHOUTY MOHAMMED HASSANE" &lt;mhlhouty@menara.ma&gt;<br />Date:<br />Sun, 22 Jun 2008 02:42:53 -0000<br />BCC:<br /><br />LYCOS LOTTERY ONLINE<br />8th Floor<br />1 Stephen Street<br />London<br />W1T 1AL<br />&nbsp;<br />WINNING NOTIFICATION<br />This is to inform you that your email address has won the Lycos Lottery for the year 2008. your email has won you the sum of ?952,350.00 (Nine Hundred And Fifty Two Thousand, Three Hundred And Fifty pounds sterling).<br />You are advised to keep this notice confidential to avoid misinterpretation of funds and unauthorize claims, cheating or fraud.<br />To claim your funds please contact us with the information below.<br />Name: Dr. George Stevenson<br />Tel:+447031991681<br />Email:lycosclaimsdpt@gmail.com<br />&nbsp;<br />It is mandatory that you send us your full names, address, phone number,<br />age, sex and occupation to enable us arrange your claim.<br />&nbsp;<br />Note: Winners were selected through a computer ballot system drawn from Microsoft users from company and individual email addresse users. All winning must be claimed not later than 21 working days from the time of notification. After this date all unclaimed funds will be returned to European Union Treasury as unclaimed funds.<br />&nbsp;<br />Congratulations from mambers and staff of Lycos<br />Lhouty Mohammed Hassane.<br />Lycos Lottery Co-ordinator<br /><br /><b>(A "Lycos Lottery" and they're using a GMail address? Doh).</b><br /><br />*********************************************************************************************<br /><br />Subject:<br />Yukos Oil<br />From:<br />Mr. Timinskiy Vladimir &lt;grooves@bellnet.ca&gt;<br />Date:<br />Wed, 25 Jun 2008 5:38:17 -0400<br />To:<br />&lt;info@yukos.org&gt;<br /><br />I have a profiling amount in an excess of US$100.5M, which I seek you in accommodating for me. You will be rewarded with 4% .If intrested, please reply me for moredetails...&lt;tvlad4@gmail.com&gt;<br />Regards<br />Mr. Timinskiy Vladimir<br /><br /><b>(Short. Sweet. Pointlessly fake).</b><br /><br />*******************************************************************************<br /><br />Subject:<br />Immediate Release of Your FUND Via ATM CARD<br />From:<br />"Mr. Mark Louis" &lt;francois.lapeyronie@wanadoo.fr&gt;<br />Date:<br />Wed, 25 Jun 2008 01:45:09 -0700<br />To:<br />undisclosed-recipients:;<br /><br />SUBJECT: Immediate Release of Your FUND Via ATM CARD<br /><br />Attention: ATM Card Beneficiary,<br /><br />I wish to use this medium to inform you that your CONTRACT/INHERITANCE Paymen of USD$10,000,000.00 (Ten Million United States Dollars) from CENTRAL BANK<br />OF NIGERIA have been RELEASED and APPROVED for onward transfer to you via an ATM CARD which you will use to withdraw all the USD$10,000,000.00 in any<br />ATM SERVICE MACHINE in any part of the world, but the maximum you can withdraw in a day is USD$10,000.00 Only.<br /><br />We have mandated IBTC CHARTERED BANK PLC, to send you the ATM CARD and PIN NUMBER which you will use to withdraw all your USD$10 Million Dollars in<br />any ATM SERVICE MACHINE in any part of the world. You are therefore advice to contact the Head of ATM CARD Department of IBTC CHARTERED BANK PLC;<br /><br />Contact Person: Dr. Olu James<br />Office email address:&nbsp;&nbsp; pcfc_nigeria@yahoo.com<br />Private: +2347084501007<br />Office:018969906<br /><br />Tell Dr. Olu James that you received a message from the CENTRAL BANK OF NIGERIA. Instructing him to send you the ATM CARD and PIN NUMBER which you will use<br />to withdraw your USD$10 Million Dollars in any ATM SERVICE MACHINE in any part of the world, also send him your direct phone number and contact address<br />where you want him to send the ATM CARD and PIN NUMBER to you. We are very sorry for the plight you have gone through in the past years. Thanks for adhering to this instruction and once again accept our congratulations.<br /><br />Best Regards.<br />Mr. Mark Louis.<br />Executive Governor,<br /><br />Central Bank of Nigeria {CBN}.<br /><br /><b>(Ah, the old "Let's lure them in with the magical bank card" trick).</b><br /><br /><br />******************************************************************************************<br /><br />Subject:<br />CONTACT THE FEDEX COMPANY FOR YOUR FUNDS<br />From:<br />"SAMUEL DUNBAR" &lt;samuel_dunbar0013@ig.com.br&gt;<br />Date:<br />Fri, 20 Jun 2008 12:33:43 +0100<br />BCC:<br /><br />Dear Friend,<br /><br />Compliment of the new year, I have been waiting for you since to come down here and pick your Bank Draft which my boss left with me before he travelled to England but I did not hear from you since that time till today. I went to the bank to confirm whether the draft is getting close to expire as it had been long time my boss issued the draft. The director of the bank told me that before the draft will get to you, that it will expire. Then I told him to help me and cash the cashier bank draft of $1,500.000.00 to cash payment.<br /><br />However, I have successfully cashed the draft and packaged it in a box and have registered it in the Fedex Express Company Service here in Benin Republic because I will travell to see my boss in England and will not come back till August 20th 2008. You have to contact the Fedex Express Company Service to know when they will deliver your package to your address. I have paid for the delivering charges and insurance fees. The only money you have to send to them is their security keeping feeswhich is USD$135.00 USD to receive your package. Don't be deceived by any body.<br /><br />This is their Contact Address;<br />Attn: Cheif Mr. George Kobra (Director)<br />Tel:&nbsp; +229-9799 2240<br />E-mail: fc.bj@sify.com<br /><br />Send them your contacts information to enable them locate you<br />&nbsp;immediately they arrived in your country with your package.<br /><br />This is the information they needed from you.<br /><br />1. Your full name:.....<br />2. Your shipping/home address:.....<br />3. Your tel no #......<br />4. Your current office tel no #<br />5. A copy of your passport.<br /><br />Try to contact them as soon as possible to avoid increasement of the security keeping fees Note; I didn't tell the Fedex Express Company Service that it's money inside the box, I registered it as a church of a Church Minister Materials. This is to avoid delay or any upfront problem during the delivery. So, do not let them know that the package contents money. Do let me know as soon as you received your package. You will contact&nbsp; me only through e-mail as my phone is no longe available now that I am out from our country. Contact me at samdunbar1986@yahoo.com and I will reply as soon as I can.<br />I wish you and your family Long Life,<br />Prosperity and Happy 2008.<br /><br />Thanks and Remain Blessed.<br /><br />Yours sincerely,<br />Mr.Samuel Dunbar<br />(Secretary)<br /><br /><b>(Honestly, if you contact FedEx they'll give you tons of money....)</b><br /><br />****************************************************************************************<br /><br />That's your lot for another week....<br />
    ]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 09:29:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/central bank">central bank</category>
      <category domain="http://securityratty.com/tag/bank">bank</category>
      <category domain="http://securityratty.com/tag/magical bank card">magical bank card</category>
      <category domain="http://securityratty.com/tag/bank draft">bank draft</category>
      <category domain="http://securityratty.com/tag/email address">email address</category>
      <category domain="http://securityratty.com/tag/office email address">office email address</category>
      <category domain="http://securityratty.com/tag/bank immediately">bank immediately</category>
      <category domain="http://securityratty.com/tag/lycos lottery">lycos lottery</category>
      <category domain="http://securityratty.com/tag/office">office</category>
      <source url="http://blog.spywareguide.com/2008/06/your-419-mail-roundup.html">Your 419 Mail Roundup</source>
    </item>
    <item>
      <title><![CDATA[Trip Report: PH-Neutral]]></title>
      <link>http://securityratty.com/article/16f4b3a55157f829576693064e2b93d2</link>
      <guid>http://securityratty.com/article/16f4b3a55157f829576693064e2b93d2</guid>
      <description><![CDATA[I spent the weekend in Berlin attending a conference called PH-Neutral, run primarily by the Phenoelit crew. This was the first European security conference Ive attended and I found it quite different...]]></description>
      <content:encoded><![CDATA[<p>I spent the weekend in Berlin attending a conference called PH-Neutral, run primarily by the <a href="http://www.phenoelit.de/">Phenoelit</a> crew.  This was the first European security conference I&#8217;ve attended and I found it quite different from any North American security gathering I&#8217;ve been to, such as <a href="http://blackhat.com">BlackHat</a>, <a href="http://cansecwest.com/">CanSecWest</a>, <a href="http://www.sourceboston.com/">SOURCE Boston</a>, <a href="http://www.microsoft.com/technet/security/bluehat/default.mspx">BlueHat</a>, or <a href="http://rsaconference.com/">RSA</a>.  Everything was far more casual and laid back, which is something I had heard about European conferences but hadn&#8217;t experienced until now (even EUSecWest is held in a club whereas CanSecWest is in a Marriott).</p>
<p><a href='http://www.veracode.com/blog/wp-content/uploads/2008/05/2525962901_6c15d2f291_o.jpg'><center><img src="http://www.veracode.com/blog/wp-content/uploads/2008/05/2525962901_6c15d2f291_o-300x225.jpg" alt="PH-Neutral Bridge" title="2525962901_6c15d2f291_o" width="300" height="225" class="aligncenter size-medium wp-image-103 photoborder" /></center></a></p>
<p>The event was held at <a href="http://www.insel-berlin.net/">Die Insel</a>, on a tiny island a few kilometers outside of Berlin&#8217;s city center, near Treptower Park.  The venue is mostly used for live music so basically it feels like a dark, somewhat dingy club (certainly the bathrooms are reminiscent of a club).  The presentations were on the 3rd floor in a room that probably held about 60 people in close quarters; to handle overflow, a closed-circuit feed was being simulcast on the 4th floor, which was a bit less crowded and, more importantly, opened out onto a rooftop deck which meant better ventilation.  The bottom floor led out to a Biergarten with tables, beach chairs, and a stage which was used for DJing.  The layout was actually pretty efficient for allowing around 200 people to mill about and socialize/network while not having to stray too far from where the talks were presented.</p>
<p><a href='http://www.veracode.com/blog/wp-content/uploads/2008/05/2525962813_b842faf96d_o.jpg'><center><img src="http://www.veracode.com/blog/wp-content/uploads/2008/05/2525962813_b842faf96d_o-225x300.jpg" alt="Bridge to Die Insel" title="2525962813_b842faf96d_o" width="225" height="300" class="aligncenter size-medium wp-image-102 photoborder" /></center></a></p>
<p>As far as the event itself, when I said &#8220;laid back&#8221; earlier, don&#8217;t interpret that to mean disorganized or watered down in any way.  It was run with stereotypical German efficiency, from badging to presentations to the after-hours parties.  The presentations were just as technical and relevant as any of the more &#8220;corporate&#8221; conferences.  Unfortunately for me, I don&#8217;t know that many people in European security circles, and most of the ones I do know weren&#8217;t in attendance.  Those I did meet, however, were impressively smart and well-versed.  Nobody was trying to conduct business transactions or slip away for meetings, which is inevitably what happens when only technical folks are present!</p>
<p><a href='http://www.veracode.com/blog/wp-content/uploads/2008/05/2526783152_fed88680d4_o.jpg'><center><img src="http://www.veracode.com/blog/wp-content/uploads/2008/05/2526783152_fed88680d4_o-225x300.jpg" alt="PH-Neutral Registration" title="2526783152_fed88680d4_o" width="225" height="300" class="alignnone size-medium wp-image-101 photoborder" /></center></a></p>
<p>For me, a few talks stood out.  Fukami and BeF&#8217;s talk on <a href="https://www.flashsec.org/mediawiki/images/5/57/SWF_and_the_Malware_Tragedy.pdf">SWF and the Malware Tragedy</a> discussed methods for automated static detection of malware in Flash movies.  Much of it centered on heuristics related to inconsistencies in the file format or tag structure, abnormal concentrations of strings in the constant pool, or the existence of various obfuscation techniques.  Ultimately, there are false positive issues to be addressed but that is just a fact of life with static analysis, and it will be an iterative process to refine those heuristics as the attack vectors evolve.  I thought this talk was particularly timely given the increasing prevalence of Flash as a conduit for exploits/malware, such as the most recent <a href="http://trailofbits.com/2008/05/28/flash-zero-day-attacks-wow/">Flash 0day</a> that made the news (granted, this was an exploit against Flash itself, not just using Flash as a delivery mechanism, but close enough).</p>
<p>I also enjoyed pierre&#8217;s talk on counterintelligence, basically a mélange of wiretapping and other bugging devices discovered in the wild.  War stories are always interesting, particularly when it comes to the realm of physical security.  One of the x-ray images he showed of a bugged pen was identical to a pen that I own (minus the bugging device of course&#8230; I hope).  The feel of the talk reminded me a bit of James Atkinson&#8217;s talk at SOURCE, &#8220;Telephone Defenses Against the Dark Arts&#8221; (video: <a href="http://sourceboston2008.blip.tv/file/799027/">Part 1</a> and <a href="http://sourceboston2008.blip.tv/file/800299/">Part 2</a>), which also got rave reviews.  </p>
<p>Mike Eddington&#8217;s presentation on the <a href="http://peachfuzz.sourceforge.net/">Peach 2</a> fuzzing framework was also quite interesting.  Peach 2 was released several months back but I haven&#8217;t really been paying much attention to it or any other fuzzing tool for some time.  In fact the last time I really had to implement a protocol fuzzer, I was using SPIKE 2.9, so that gives you some indication of how long it&#8217;s been.  Peach 2 includes some powerful built-in capabilities such as node relationships (e.g. field 1 represents the length of field 2; field 10 is a CRC-32 of fields 1 through 9), data transforms (those with battle scars from ASN.1 will be happy), state machines (packets 1 and 2 have to be normal in order to fuzz packet 3), monitoring agents (detecting when a crash happens and under what conditions), and much more.  I am itching to go fuzz something now just so I can tinker with Peach.</p>
<p>All in all, it was a good trip and I enjoyed the opportunity to see how things are done across the pond, and to do a little sightseeing in a historic and beautiful city.</p>
]]></content:encoded>
      <pubDate>Wed, 28 May 2008 16:56:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/talk">talk</category>
      <category domain="http://securityratty.com/tag/james atkinsons talk">james atkinsons talk</category>
      <category domain="http://securityratty.com/tag/flash">flash</category>
      <category domain="http://securityratty.com/tag/flash movies">flash movies</category>
      <category domain="http://securityratty.com/tag/recent flash 0day">recent flash 0day</category>
      <category domain="http://securityratty.com/tag/befs talk">befs talk</category>
      <category domain="http://securityratty.com/tag/dingy club">dingy club</category>
      <category domain="http://securityratty.com/tag/conference">conference</category>
      <category domain="http://securityratty.com/tag/european security conference">european security conference</category>
      <source url="http://www.veracode.com/blog/?p=98">Trip Report: PH-Neutral</source>
    </item>
    <item>
      <title><![CDATA[Ted Kennedy: a lifetime of achievement, regrets of a world that could have been]]></title>
      <link>http://securityratty.com/article/46c0e216b7084846a34fe3d594d53e76</link>
      <guid>http://securityratty.com/article/46c0e216b7084846a34fe3d594d53e76</guid>
      <description><![CDATA[I usually stay away from politics on my blog. As I have said before, it is my blog and I can write what I want, but politics usually is just to controversial for me to write on. Upon hearing the...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><div>I usually stay away from politics on my blog. As I have said before, it is my blog and I can write what I want, but politics usually is just to controversial for me to write on. Upon hearing the <a href="http://news.yahoo.com/s/ap/20080521/ap_on_re_us/kennedy">terrible news</a> about Ted Kennedy's malignant brain tumor, I was moved to write something, than thought twice about it and thought yet again. However, Ted Kennedy and his life and times has been such an influence and part of my life, that I am compelled to write. So on this night where it appears that an African-American has won <a href="http://www.cnn.com/2008/POLITICS/02/29/delegate.counter/index.html?iref=mpstoryview">a majority of the pledged delegates</a> of the Democratic Party, while running against a woman, I think it only fitting to remember Ted Kennedy. I do not mean this as a eulogy or obituary and in fact hope against all that I have read and heard that a miracle will grant him many more years of serving in the Senate. But it seems Teddy has a tough road ahead and this is as good as a time as any to speak out.<br /><br />One of my earliest memories of current events was when Ted's brother John was assassinated. I was a little boy playing catch with my Dad when my Mom came to the door and called us in because something terrible had happened. I didn't really understand, but my parents told me that the President (who I had seen with VP Johnson drive by in a motorcade months before) had been shot. I don't remember a lot more of the details, but do remember Oswald getting shot and some pictures of the funeral. The mind of a young boy is quickly filled with other things though and I moved on past that horrific November day.</div>

<div> <br />Next when I was a bit older, the crazy year of '68 was upon us. I was still fairly young, but I remember riots in the cities, pictures on the news of the war and Bobby Kennedy, the Senator from NY running for President when President Johnson said he would not run. Martin Luther King was shot and killed and so was Bobby shortly after. By now I was old enough to realize the tragedy of these killings. I remember hearing Teddy's eulogy of Bobby and thinking what a terrible thing to have happened to this family, losing two of their sons like this. <br /><br />For me it was the start of a life long interest in all things Kennedy. I read many books about all of the Kennedy's and lamented what could have been if not for the bullets that killed first John and than Bobby. A key part of my core political beliefs was that if John Kennedy would have served out his first term and been re-elected, how different the world would have been.&nbsp; If Bobby Kennedy had been elected President instead of Nixon, what would the world look like now? There was always a sense that Teddy, the baby Kennedy brother would rise up and take the mantle and place that seemed to belong to this family. He would restore Camelot. Alas it was not to be. His time just never came. Though he ran a noble race, Chappaquiddick haunted and doomed his candidacy. After that Teddy was the patron of a family that just seemed unable to escape tragedy. One mishap after another befell this family that had been previously granted so much good fortune. It truly did seem as if they were cursed. Teddy himself had his ups and downs with drinking and divorce and the health of his children. Though he asked us to never let the dream die, the legacy of Camelot did seem to pass on.<br /><br />Through it all Ted Kennedy continued to do good work for this country in the Senate. Looking back Teddy's legislative record has probably had more of an influence on this country than either of his brothers had. His name is attached to many of the greatest laws passed over the last 40 years. Teddy was also a great orator. Many say that his <a href="http://www.youtube.com/watch?v=ydHc-ExClqw">finest speech was as the keynote speaker</a> at the 1980 Democratic Convention, when he mounted his challenge to a sitting President Carter. But for me Teddy's finest moment was in delivering the eulogy for his brother Bobby. The &quot;some man ask why, Bobby dreamed of what could be and asked why not&quot; speech never ceases to move me. I include this You Tube as a tribute to Ted Kennedy and all that he and his brothers meant to me along with my prayers for a recovery from this terrible condition.</div>

<div class="youtube-video"><embed src="http://www.youtube.com/v/FiCLi9ddqlM" width="425" height="355" type="application/x-shockwave-flash" wmode="transparent"></embed> </div></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=1oE6ag"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=1oE6ag" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=MMYVHH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=MMYVHH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=cQDvkH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=cQDvkH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=BHEnLH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=BHEnLH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=bRDG6H"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=bRDG6H" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=Q8X8mh"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=Q8X8mh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=HIvGxh"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=HIvGxh" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/294782921" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 20 May 2008 20:04:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ted kennedy">ted kennedy</category>
      <category domain="http://securityratty.com/tag/kennedy">kennedy</category>
      <category domain="http://securityratty.com/tag/remember ted kennedy">remember ted kennedy</category>
      <category domain="http://securityratty.com/tag/ted">ted</category>
      <category domain="http://securityratty.com/tag/john kennedy">john kennedy</category>
      <category domain="http://securityratty.com/tag/bobby kennedy">bobby kennedy</category>
      <category domain="http://securityratty.com/tag/bobby">bobby</category>
      <category domain="http://securityratty.com/tag/bobby shortly">bobby shortly</category>
      <category domain="http://securityratty.com/tag/remember">remember</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/294782921/ted-kennedy-a-l.html">Ted Kennedy: a lifetime of achievement, regrets of a world that could have been</source>
    </item>
    <item>
      <title><![CDATA[FBI warns of China earthquake e-mail scams]]></title>
      <link>http://securityratty.com/article/4e4cde7e99db981e380ab3b89a9e61f3</link>
      <guid>http://securityratty.com/article/4e4cde7e99db981e380ab3b89a9e61f3</guid>
      <description><![CDATA[It's become a familiar pattern: after the tragedy, the...]]></description>
      <content:encoded><![CDATA[It's become a familiar pattern: after the tragedy, the spam.]]></content:encoded>
      <pubDate>Tue, 20 May 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/familiar pattern">familiar pattern</category>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/tragedy">tragedy</category>
      <source url="http://www.networkworld.com/news/2008/052108-fbi-warns-of-china-earthquake.html?fsrc=rss-security">FBI warns of China earthquake e-mail scams</source>
    </item>
    <item>
      <title><![CDATA[Teen Involved in MySpace Suicide Hoax Says Adult Also Participated]]></title>
      <link>http://securityratty.com/article/17c9576693ad64a5e51111e8284b3997</link>
      <guid>http://securityratty.com/article/17c9576693ad64a5e51111e8284b3997</guid>
      <description><![CDATA[Despite denials, 47-year-old Lori Drew actively participated in the MySpace hoax that led to the suicide of 13-year-old Megan Meier, according to a teenager who admits her own role in the...]]></description>
      <content:encoded><![CDATA[Despite denials, 47-year-old Lori Drew actively participated in the MySpace hoax that led to the suicide of 13-year-old Megan Meier, according to a teenager who admits her own role in the tragedy.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=03db846d93ee10714a81530fc64c2885" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=03db846d93ee10714a81530fc64c2885" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=2C1k0qG"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=2C1k0qG" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=Hhum0Ag"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=Hhum0Ag" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=IdLW23g"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=IdLW23g" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=8WG1FxG"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=8WG1FxG" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=nV3vFpG"><img src="http://feeds.wired.com/~f/wired/politics/security?i=nV3vFpG" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=oxDJjvg"><img src="http://feeds.wired.com/~f/wired/politics/security?i=oxDJjvg" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=CqGiSEg"><img src="http://feeds.wired.com/~f/wired/politics/security?i=CqGiSEg" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=JACCczG"><img src="http://feeds.wired.com/~f/wired/politics/security?i=JACCczG" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/262168887" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/262168894" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 01 Apr 2008 15:15:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/13-year-old megan meier">13-year-old megan meier</category>
      <category domain="http://securityratty.com/tag/myspace hoax">myspace hoax</category>
      <category domain="http://securityratty.com/tag/47-year-old lori">47-year-old lori</category>
      <category domain="http://securityratty.com/tag/suicide">suicide</category>
      <category domain="http://securityratty.com/tag/tragedy">tragedy</category>
      <category domain="http://securityratty.com/tag/led">led</category>
      <category domain="http://securityratty.com/tag/teenager">teenager</category>
      <category domain="http://securityratty.com/tag/actively">actively</category>
      <category domain="http://securityratty.com/tag/denials">denials</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/262168894/teen-fingers-lo.html">Teen Involved in MySpace Suicide Hoax Says Adult Also Participated</source>
    </item>
    <item>
      <title><![CDATA[E-crime and Socioeconomic Factors]]></title>
      <link>http://securityratty.com/article/d739bfc3f7406135dee2bcfc65ac9b93</link>
      <guid>http://securityratty.com/article/d739bfc3f7406135dee2bcfc65ac9b93</guid>
      <description><![CDATA[Interesting points by F-Secure with two main issues covered, namely the lack of employment opportunities for skilled IT people who turn to cyber crime to make a living, and the emerging economies...]]></description>
      <content:encoded><![CDATA[<a href="http://bp2.blogger.com/_wICHhTiQmrA/R4_jRz8-M2I/AAAAAAAABUo/3wgycsHHMOk/s1600-h/malware_creation.jpg"><img id="BLOGGER_PHOTO_ID_5156589993505731426" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://bp2.blogger.com/_wICHhTiQmrA/R4_jRz8-M2I/AAAAAAAABUo/3wgycsHHMOk/s200/malware_creation.jpg" border="0" /></a>Interesting <a href="http://www.f-secure.com/f-secure/pressroom/news/fsnews_20080117_1_eng.html">points by F-Secure</a> with two main issues covered, namely the lack of employment opportunities for skilled IT people who turn to cyber crime to make a living, and the emerging economies across the globe, whose citizens in their early stages of embracing new economic models will suffer from the inevitable unequal distribution of income due to their government's lack of experience or motivation. To me, however, it's more sociocultural than socioeconomic factors that contribute to these future developments. Several more key points worth discussing :<br /><br />- <strong>Malware is no longer created, it's being generated</strong><br /><br />The myth of someone reinventing the wheel, namely coding a malware bot from scratch is no longer realistic. Modern malware is open source, modular, localized to different languages, comes with extensive documentation/comments and HOWTO guides/videos. Moreover, these publicly obtainable open source malware bots were released in the wild for free, namely, the coders that originally started the "generators" or the "compilers" generation took, and enjoyed only the fame that came with coming up with the most widely used and successful bot family. Take Pinch for instance and the recent arrest of the "coders". New and improved versions of Pinch are making their rounds online, but how is this possible since the people behind it are no longer able to update it? To achieve immortality for Pinch, they've released it as open source tool, namely anyone can use its successful foundation for any other upcoming innovation. The original coders are gone, the "malware generators" and the "compilers" are cheering since they still have access to the tool. Another popular entry obstacle such as advanced coding skills is gone, anyone can compile, generate and spread the samples, or used them for targeted attacks.<br /><br />- <strong>"Will code malware for food" type of individuals don't really exist anymore</strong><br /><br />A cat doesn't eat mice when it's hungry, it eats mice when it's already been fed, and therefore does it for prestige and entertainment. Storm Worm is not released by the "desperation department", it's an investment on behalf of someone who will monetize the infected hosts, or who has outsourced the infection process to botnet aggregators. Moreover, there's no lack of IT employment opportunities in times of growing economy, exactly the opposite, the economy is booming, investments are made in networks and infrastructure and therefore people will start receiving incentives for training and therefore the demand for IT experts will increase given the government is visionary enough to invest in the long-term, in terms of education and training. If it's not, structural unemployment will undermine the local industry, you'll end up with software engineers working at the local McDonald's during the day, and coding malware during the night - a stereotype. For instance, go through <a href="http://www.iht.com/articles/2007/10/20/europe/21levy.php">this article</a> and notice the quote regarding the attitude towards the U.S. Malware coders/generators aren't on the verge of starvation, they're on a mission with or without actually realizing it :<br /><br />"<em>I don't see in this a big tragedy," said a respondent who used the name Lightwatch. "Western countries played not the smallest role in the fall of the Soviet Union. But the Russians have a very amusing feature — they are able to get up from their knees, under any conditions or under any circumstances. As for the West? "You are getting what you deserve.</em>"<br /><br />It's a type of "Why are you doing me a favour that I still cannnot appreciate?" issue, collectivism vs individualistic societies. E-crime is not just easy to outsource, but the entry barriers in space are so low, we can easily argue it's no longer about the lack of capabilities, but the lack of motivation to participate, and actually survive, that drive E-crime particularly in respect to malware. From an economic perspective, the <a href="http://ddanchev.blogspot.com/2007/03/underground-economys-supply-of-goods.html">Underground Economy's high liquidity</a> is perhaps the most logical incentive to participate, which is a clear indication on the <a href="http://ddanchev.blogspot.com/2007/10/dynamics-of-malware-industry.html">transparency and communication</a> that parties involved have managed to achieve.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=JBIxthD"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=JBIxthD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=K7IlCmD"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=K7IlCmD" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=En3mKxd"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=En3mKxd" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=LHT7Ypd"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=LHT7Ypd" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=IQgcZ6D"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=IQgcZ6D" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=pE0lY8D"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=pE0lY8D" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=5qS9IEd"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=5qS9IEd" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/220380251" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 21 Jan 2008 04:49:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/code malware">code malware</category>
      <category domain="http://securityratty.com/tag/modern malware">modern malware</category>
      <category domain="http://securityratty.com/tag/malware generators">malware generators</category>
      <category domain="http://securityratty.com/tag/source tool">source tool</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/malware bot">malware bot</category>
      <category domain="http://securityratty.com/tag/source malware bots">source malware bots</category>
      <category domain="http://securityratty.com/tag/e-crime">e-crime</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/220380251/e-crime-and-socioeconomic-factors.html">E-crime and Socioeconomic Factors</source>
    </item>
    <item>
      <title><![CDATA[Cops with guns...what will they think of next?]]></title>
      <link>http://securityratty.com/article/0036ed7b80f4fcbafdd659c2b6211011</link>
      <guid>http://securityratty.com/article/0036ed7b80f4fcbafdd659c2b6211011</guid>
      <description><![CDATA[The recent article in the Arizona Republic regarding Campus Police Officers now being able to carry guns, is made to sound like some kind of &quot;breaking news&quot; flash

In a way, I suppose it is, since...]]></description>
      <content:encoded><![CDATA[<a href="http://bp1.blogger.com/_1UFxC-OgSnA/R4hkRrmhh7I/AAAAAAAAACo/KgCcLIAuB0Q/s1600-h/Fotolia_5018694_S.jpg"><img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://bp1.blogger.com/_1UFxC-OgSnA/R4hkRrmhh7I/AAAAAAAAACo/KgCcLIAuB0Q/s320/Fotolia_5018694_S.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5154480028450391986" /></a><br />The recent article in the <a href="http://www.azcentral.com/news/articles/0107phx-security0109.html">Arizona Republic </a>regarding Campus Police Officers now being able to carry guns, is made to sound like some kind of "breaking news" flash.    <br /><span id="fullpost"><br />In a way, I suppose it is, since campus officers in Maricopa County were unarmed prior to this.  The State law which came into effect in October takes the decision out of the hands of the campus authorities.  Police officers carrying guns would be news in Great Britain or India but it is strange to think of any U.S. law enforcement officer not having the authority to carry a weapon.  <br /><br />No doubt, the tragedy at Virginia Tech. last year changed a lot of minds regarding the need for campus police to be armed.  If campus police are trained to the same standards as any other department in the State, there is no reason why they should not be armed.  As the article points out, private security officers working at the campus will not be armed.  <br /><br />I just hope that the officers' guns will have bullets.  Does that sound strange?  You might think it impossible that they would not have ammunition but I have been told by soldiers who have been stationed at several U.S. bases that they had weapons but were ordered to keep their weapons unloaded.  I understand fear of liability, but I think that is going too far.  If you can not trust the person carrying a gun and who does so for a living, that sounds like their training is questionable.<br /><br />I can guarantee that the bad guys will have bullets in their guns if and when they show up.  I can also guarantee that they are not influenced by the Marquis of Queensbury's rules and will not wait for the good guys to load their weapons.          <br /></span><div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Sat, 12 Jan 2008 03:27:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/campus authorities">campus authorities</category>
      <category domain="http://securityratty.com/tag/campus">campus</category>
      <category domain="http://securityratty.com/tag/campus police">campus police</category>
      <category domain="http://securityratty.com/tag/campus officers">campus officers</category>
      <category domain="http://securityratty.com/tag/campus police officers">campus police officers</category>
      <category domain="http://securityratty.com/tag/officers">officers</category>
      <category domain="http://securityratty.com/tag/guns">guns</category>
      <category domain="http://securityratty.com/tag/security officers">security officers</category>
      <category domain="http://securityratty.com/tag/police officers">police officers</category>
      <source url="http://www.thebulletproofblog.com/2008/01/cops-with-gunswhat-will-they-think-of.html">Cops with guns...what will they think of next?</source>
    </item>
  </channel>
</rss>
