<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: trust]]></title>
    <link>http://securityratty.com/tag/trust</link>
    <description></description>
    <pubDate>Wed, 13 Aug 2008 10:46:48 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Securing Your Gmail With Just a Click]]></title>
      <link>http://securityratty.com/article/607ed5a24c0b50b25a2cbe170ddda454</link>
      <guid>http://securityratty.com/article/607ed5a24c0b50b25a2cbe170ddda454</guid>
      <description><![CDATA[Im learning lessons on security this week, because Ive just brought a new kitten home and she is exploring every nook and cranny in my home. Chewing on my cacti, playing with the blinds, and naturally...]]></description>
      <content:encoded><![CDATA[<p>I&#8217;m learning lessons on security this week, because I&#8217;ve just brought <a rel="nofollow" target="_blank" href="http://flickr.com/photos/sylphbranching/2778845191/">a new kitten </a>home and she is exploring every nook and cranny in my home. Chewing on my cacti, playing with the blinds, and naturally clawing up the couch. I wish there was a way to press a button and kitty-proof my house!</p>
<p>Luckily there now is a way to press a button and get secure gmail with SSL, at least. Thanks to <span class="entry-author-name"><a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~r/Security-Bloggers-Network/~3/370004218/">Martin McKeay</a> for the tip </span>&#8211; the big Goog has enabled HTTPS in the Gmail options settings&#8211;</p>
<blockquote><p>Gmail has been capable of running on SSL for quite some time, but it’s not something that’s enabled by default. I always typed the https in by hand, but I don’t completely trust that method. I’ve used Better Gmail2 in the past, but that doesn’t like FireFox 3 for some reason. There are also a number of <a rel="nofollow" target="_blank" href="http://userscripts.org/scripts/show/1404">scripts</a> for <a rel="nofollow" target="_blank" href="https://addons.mozilla.org/en-US/firefox/addon/748">GreaseMonkey</a> that force Gmail to use SSL, but now Gmail has made it an <a rel="nofollow" target="_blank" href="http://googlesystem.blogspot.com/2008/07/force-gmail-to-use-secure-connection.html">option on the settings page</a>. It’s on the bottom of the page and easy to miss if you’re not looking closely.</p></blockquote>
<p>Good, now I can stop worrying about my email and get to the tough task of securing my apartment instead.</p>
<p><span class="entry-author-name">Go read the full article about this new feature <a rel="nofollow" target="_blank" href="http://feeds.feedburner.com/~r/Security-Bloggers-Network/~3/370004218/">here.</a><br />
</span></p>]]></content:encoded>
      <pubDate>Thu, 21 Aug 2008 11:51:12 +0000</pubDate>
      <category domain="http://securityratty.com/tag/gmail">gmail</category>
      <category domain="http://securityratty.com/tag/force gmail">force gmail</category>
      <category domain="http://securityratty.com/tag/secure gmail">secure gmail</category>
      <category domain="http://securityratty.com/tag/gmail options settings">gmail options settings</category>
      <category domain="http://securityratty.com/tag/page">page</category>
      <category domain="http://securityratty.com/tag/settings page">settings page</category>
      <category domain="http://securityratty.com/tag/ssl">ssl</category>
      <category domain="http://securityratty.com/tag/completely trust">completely trust</category>
      <category domain="http://securityratty.com/tag/martin mckeay">martin mckeay</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/371376583/">Securing Your Gmail With Just a Click</source>
    </item>
    <item>
      <title><![CDATA[Dont click that link, think first.]]></title>
      <link>http://securityratty.com/article/00f591f7bb48f5a7e02e423f7c206f30</link>
      <guid>http://securityratty.com/article/00f591f7bb48f5a7e02e423f7c206f30</guid>
      <description><![CDATA[If the links not from someone you trust, dont click it


clipped from it.toolbox.com

New Social Malware hits the street


As social malware goes, this is a good delivery mechanism for getting people...]]></description>
      <content:encoded><![CDATA[<div > If the links not from someone you trust, dont click it! </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/03707B22-62C7-452D-8FF5-857D11334BEA/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/e3fe0631-cdd6-43d5-bd03-3d96a01a28b8/03707B22-62C7-452D-8FF5-857D11334BEA/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://it.toolbox.com/blogs/managing-infosec/new-social-malware-hits-the-street-26676" href="http://it.toolbox.com/blogs/managing-infosec/new-social-malware-hits-the-street-26676" style="font-size: 11px;">it.toolbox.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://it.toolbox.com/blogs/managing-infosec/new-social-malware-hits-the-street-26676 -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">
		New Social Malware hits the street
	</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://it.toolbox.com/blogs/managing-infosec/new-social-malware-hits-the-street-26676 --><DIV>As social malware goes, this is a good delivery mechanism for getting people to click on links. Most of us have learned that clicking on links from people who you do not know is generally not a good idea. Spinning up the social aspect of malware delivery, using MySpace and Facebook friends should result in a better penetration of the malware because we are used to clicking on links from our friends.<br />
</DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/03707B22-62C7-452D-8FF5-857D11334BEA/blog/" title="blog or email this clip"><img src="http://content7.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 21:15:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/social malware hits">social malware hits</category>
      <category domain="http://securityratty.com/tag/malware delivery">malware delivery</category>
      <category domain="http://securityratty.com/tag/social malware">social malware</category>
      <category domain="http://securityratty.com/tag/links">links</category>
      <category domain="http://securityratty.com/tag/click">click</category>
      <category domain="http://securityratty.com/tag/friends">friends</category>
      <category domain="http://securityratty.com/tag/facebook friends">facebook friends</category>
      <category domain="http://securityratty.com/tag/social aspect">social aspect</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=566">Dont click that link, think first.</source>
    </item>
    <item>
      <title><![CDATA[ScienceLogics 5-Year Anniversary]]></title>
      <link>http://securityratty.com/article/1287b8dac0ea60512bed5f303d15fe55</link>
      <guid>http://securityratty.com/article/1287b8dac0ea60512bed5f303d15fe55</guid>
      <description><![CDATA[August 2003. The largest blackout in U.S. history darkens the Northeast and Midwest, the Blaster worm has been unleashed and Madonna and Britney create a stir at the 2003 MTV Music Video Awards . In...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="164" alt="B-day Cake" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/b-day-cake1.jpg" width="244" align="left" border="0"> August 2003. The largest <a href="http://blogs.wsj.com/biztech/2008/08/13/celebrating-the-anniversary-of-the-big-blackout/?mod=djemTECH" target="_blank">blackout</a> in U.S. history darkens the Northeast and Midwest, the <a href="http://news.cnet.com/2010-1001-5117862.html" target="_blank">Blaster worm</a> has been unleashed and Madonna and Britney create a stir at the <a href="http://en.wikipedia.org/wiki/2003_MTV_Video_Music_Awards" target="_blank">2003 MTV Music Video Awards</a>. In the midst of this <a href="http://www.grid.unep.ch/product/publication/download/ew_heat_wave.en.pdf" target="_blank">hot summer</a> madness, ScienceLogic was founded.
<p>To kick off our celebration of our first five years, we asked <a href="http://www.sciencelogic.com/leadership.htm" target="_blank">ScienceLogic founders</a> Dave Link, Richard Chart and Chris Cordray for their thoughts and memories on events leading to today’s milestone. How and why did they set out on this venture? What happened along the way – expected and unexpected? Why were they successful in times when other new (and established) businesses have come and <a href="http://en.wikipedia.org/wiki/Category:2003_disestablishments" target="_blank">gone</a>?
<p><b>How did you three put together this team?</b>
<p>We all worked together at a large Managed Service Provider for a couple of years before leaving to start ScienceLogic, so we all knew each other and knew our collective strengths. More importantly, each of us had worked with network management tools on some level (sales and marketing, engineering and product development), and knew first-hand all of the customer pain points, from every perspective. So we left and began rapidly figuring out how to build a better network management solution based upon our real world operational experience..
<p><strong>Dave:</strong> One interesting aspect is that our areas of expertise don’t overlap, which has contributed to our success. Chris is excellent with developing the product front-end and interface, Richard handled the backend architecture and engineering and I focused on the technical business side of sales and marketing. Our roles have been to build a product that works well and that provides real value to operations teams that experience the same day to day frustrations that we felt.<b></b>
<p><b>Whose idea was it to start the company?</b>
<p><strong>Dave:</strong> It was really a collective effort. We were all passionate about “getting it right” and not just starting a company. We knew the industry need and between us, we had the knowledge and skill sets to address all of the right aspects of developing a product and a building a business around it.
<p><b>What process did you go through to get started?</b>
<p><strong>Richard:</strong> From the beginning we knew the type of solution the market needed and we knew that we wanted to build it as an appliance. From different vantage points, we had each experienced the effects of long, difficult and expensive installations that still exist with traditional network tools. Every install has unique variations: there are always different server types, varying hardware and software versions, different patches installed, and on and on. Every installation was time consuming and unpredictable. We knew that an appliance model would address all of these variables and save a lot of time on how quickly customers could achieve immediate value.
<p>The harder decisions were around actually starting the business, assessing the market and of course determining the product pricing.
<p><b>EM7 completely flips the traditional model of complex, lengthy and expensive deployments. How did you convince others that the EM7 Meta-Appliance product was valid?</b>
<p><strong>Dave:</strong> Yes, EM7 totally disrupts the traditional model for network management. While others take a narrow approach, we intentionally designed EM7 to focus on the broad problem – managing the data center. How do you cover a variety of technologies and make sure they work seamlessly together? The vision was to make it easier, not harder, for customers.
<p><strong>Chris:</strong> I have to give it to Dave – very early on, he realized the power of a demo. If Dave could get in front of someone, he’d make them a believer. He’d use the Peter Falk/Columbo technique of “let me show you one more thing.” It was very effective. It’s getting easier, but even today people sometimes have to see EM7 in action before they become believers.
<p><b>Can you describe the early days of running a new business?</b>
<p><strong>Dave:</strong> ScienceLogic is a classic case of entrepreneurship. For the first year we worked out of our basements. We kept the costs low in every conceivable way and spent the first year developing the product before we even made a sale.
<p><strong>Chris:</strong> We stayed at lots of odd places when we were on the road, took cheap flights with multiple layovers and purchased lots of our first test equipment on eBay. This was during the dot-com bust so there was lots of equipment for sale on eBay, really cheap!
<p><strong>Richard:</strong> The amount of equipment I had in my house was absolutely crazy. Back then, servers were huge – I had a Cisco 6509 Catalyst, a Compaq Proliant DL380, Brocade switch, IBM Netfinity 4500R, and tons of other machines.
<p><strong>Chris:</strong> I had to install a new circuit box at home because I was blowing breakers. I remember when that 6509 crashed, we revived it and it died again. The second death was final.
<p><b>So you started in your houses – what was your first office space?</b>
<p><strong>Dave:</strong> My friend, the CEO at Ernst &amp; Young Technology had a few extra cubes and a data center in their office that they graciously allowed us to use. Their help was an important step in helping us really formalize the business. We started doing well and adding people, but ironically, their company was downsizing. Before long, many of their original YET people were gone and the ScienceLogic team kept growing in to the open cubes.
<p>Our first leased space was converted warehouse space in Chantilly, VA that once housed an internet radio station. It was cool – it had a large salt water fish tank, a loft, a spiral staircase and a Star Trek door that retracted into the walls with the customary lights and “whooshing” sound.
<p>We outgrew the Chantilly space, leading to our current office in Reston, VA.
<p><b>Who was the first ScienceLogic customer?</b>
<p>Our first paying customer was <a href="http://martinspoint.com/" target="_blank">Martins Point Health Care</a>. We deployed there in July 2004 and are pleased to say they continue to be a ScienceLogic customer. Other early (and still) EM7 <a href="http://www.sciencelogic.com/customers.htm" target="_blank">customers</a> include Navy Knowledge Online and the Department of Transportation. Nearly all of our customers are still actively using EM7 and renewing their maintenance.
<p><b>Where do you see the company in the next 5, 10 or 15 years?</b>
<p>Well, our revenue has doubled year-over-year in each of the last three years, so of course we’d like to continue to grow like that or even faster. In five years we’ve gone from three founders to the point where Dave does not know everyone’s fondest childhood memory. We’ll continue to scale our growth to cover the demands of our growing customer base.
<p><b>Where do you see the industry going over the coming years?</b>
<p><strong>Chris:</strong> IT is always moving and gaining in complexity, so network management is also becoming more complicated. There’s increasing diversity, new standards, virtualization and cloud computing. All of these are today’s technologies. Customers have a mix of the old and the new, so EM7 has to accommodate and support both.
<p><strong>Richard:</strong> Each generation of products has a new set of ways to monitor, but the “old” doesn’t go away. Even when a new, hot technology comes along, the old technologies still need to be supported. We work to ensure EM7 keeps up with both.
<p><strong>Dave:</strong> After five years we’re just hitting our stride and we’re just now reaching the tipping point in awareness of ScienceLogic and EM7. We’re all still passionate about the product and as Chris and Rich said, there’s still a lot do. We’ll continue disrupting the market with EM7. Our vision hasn’t changed, and with the increasing levels of automation that customers demand, the market needs are greater than ever. Our future is as bright, or brighter, than ever and we’ll continue to be looking for smart ways to automate traditionally manual IT Operations processes.
<p><b>What’s your advice for someone interested in starting their own business?</b>
<p><strong>Chris:</strong> Be passionate. That’s what has gotten me through the tough times. I didn’t really appreciate this thought when I heard others say it before. But it’s very true.
<p><strong>Richard:</strong> I agree. We met and talked with lots of people who told us, “That’s been done before.” But we kept going because we truly believed in what we were doing and we knew that while our approach was different, that it would be successful.
<p><strong>Richard:</strong> Be fearless. You can’t be too nervous and you need to be able to expect and handle the stress because it will be there. You have to learn to accept the stressful times as a necessary part of the process of starting out on your own.
<p><strong>Dave:</strong> Know your niche from the beginning and give potential customers a compelling reason to trust you and really benefit from your solution. You have to know the problem, see the gap and have a clear and consistent vision of how to solve the problem. Then you have to execute. If you don’t build your team with “doers” you won’t make it.
<p><strong>Chris:</strong> It helps to have friends. ScienceLogic was built on friendships and relationships, starting with the three of us. If you look at our team, most of our hires are referrals – people who developed and maintained great connections with other great people throughout their careers. Maintain your connections and keep in touch with your network of friends.</p>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 18:39:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/em7 completely flips">em7 completely flips</category>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/network management">network management</category>
      <category domain="http://securityratty.com/tag/network management tools">network management tools</category>
      <category domain="http://securityratty.com/tag/em7 meta-appliance product">em7 meta-appliance product</category>
      <category domain="http://securityratty.com/tag/sciencelogic team">sciencelogic team</category>
      <category domain="http://securityratty.com/tag/team">team</category>
      <category domain="http://securityratty.com/tag/front">front</category>
      <category domain="http://securityratty.com/tag/product front-end">product front-end</category>
      <source url="http://blog.sciencelogic.com/sciencelogics-5-year-anniversary/08/2008">ScienceLogics 5-Year Anniversary</source>
    </item>
    <item>
      <title><![CDATA[MBTA Hack - Is it really this easy?]]></title>
      <link>http://securityratty.com/article/f6ec916b224830aa520ce767a8418965</link>
      <guid>http://securityratty.com/article/f6ec916b224830aa520ce767a8418965</guid>
      <description><![CDATA[A lot of the focus of the MBTA vs MIT case has been discussion of the CharlieCards . These are MiFare classic cards which have been known to be broken earlier this year . There is also a paper...]]></description>
      <content:encoded><![CDATA[<p>A lot of the focus of the MBTA vs MIT case has been discussion of the <a href="http://www.mbta.com/fares_and_passes/charlie/?id=5592">CharlieCards</a>.  These are MiFare classic cards which have been <a href="http://en.wikipedia.org/wiki/MIFARE#Security">known to be broken earlier this year</a>.  There is also a paper disposable card called the <a href="http://www.mbta.com/fares_and_passes/charlie/?id=5592">CharlieTicket</a> that uses a magnetic stripe.  The MIT students presentation states that these are cloneable and forgeable using a $150 magnetic stripe reader/writer.</p>
<p>From the <a href="http://cryptome.org/mbta-v-zack/10-scott-henderson-declaration.pdf">Confidential Memo Prepared for the MBTA</a> which was publicly disclosed by the MBTA is court filing:</p>
<p><a href="http://cryptome.org/mbta-v-zack/10-scott-henderson-declaration.pdf"><img class="alignnone size-full wp-image-241" title="memo-excerpt" src="http://www.veracode.com/blog/wp-content/uploads/2008/08/memo-excerpt.png" alt="" width="678" height="127" /></a></p>
<p>This seems to break all the rules of integrity of sensitive data storage. How could someone store money on a magnetic stripe in 2008 and not store an identifier that references the account in a central database?</p>
<p>The tickets do have a unique identifier generated when the card is initially purchased so a fraud detection system could be in place or is planned. But this would require tracking the value on the ticket or the usage of the ticket centrally so it isn&#8217;t clear why the value is stored on the card in the first place.</p>
<p>There are so many question about the security of this public system.  Fraud costs the Massachusetts taxpayer money and refitting an insecure, ill-designed system costs the Massachusetts taxpayer money. [Disclosure: I am a Massachusetts taxpayer.]</p>
<p>It should be a requirement that the current system or the (hopefully) upgraded system be tested by an independent organization that specializes in cryptosystems.  If the independent testing uncovers vulnerabilities, they need to be fixed before the system is fielded. Then the system should be retested to verify the fixes.  Once the system is deemed secure by an independent organization, a summary of the test document should be published for public inspection.  It should include the types of testing conducted and the results.</p>
<p>The public trust requires inspection of taxpayer funded projects to make sure they meet acceptible standards and vendors held responsible for deficiencies.  Projects that use computers and software should not get a free pass. It will be interesting to see if the CharlieTicket system is ever held up to public scrutiny.</p>
<p><img src="file:///C:/DOCUME~1/cwysopal/LOCALS~1/Temp/moz-screenshot.jpg" alt="" /></p>
]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 09:19:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/massachusetts taxpayer">massachusetts taxpayer</category>
      <category domain="http://securityratty.com/tag/taxpayer">taxpayer</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/fraud detection system">fraud detection system</category>
      <category domain="http://securityratty.com/tag/system costs">system costs</category>
      <category domain="http://securityratty.com/tag/public system">public system</category>
      <category domain="http://securityratty.com/tag/massachusetts taxpayer money">massachusetts taxpayer money</category>
      <category domain="http://securityratty.com/tag/charlieticket system">charlieticket system</category>
      <category domain="http://securityratty.com/tag/charlieticket">charlieticket</category>
      <source url="http://www.veracode.com/blog/?p=238">MBTA Hack - Is it really this easy?</source>
    </item>
    <item>
      <title><![CDATA[MBTA Hack: Is It Really This Easy?]]></title>
      <link>http://securityratty.com/article/1b9874427cf921ef00de8a56a8a8cab9</link>
      <guid>http://securityratty.com/article/1b9874427cf921ef00de8a56a8a8cab9</guid>
      <description><![CDATA[A lot of the focus of the MBTA vs MIT case has been discussion of the CharlieCards . These are MiFare classic cards which have been known to be broken earlier this year . There is also a paper...]]></description>
      <content:encoded><![CDATA[<p>A lot of the focus of the MBTA vs MIT case has been discussion of the <a href="http://www.mbta.com/fares_and_passes/charlie/?id=5592">CharlieCards</a>.  These are MiFare classic cards which have been <a href="http://en.wikipedia.org/wiki/MIFARE#Security">known to be broken earlier this year</a>.  There is also a paper disposable card called the <a href="http://www.mbta.com/fares_and_passes/charlie/?id=5592">CharlieTicket</a> that uses a magnetic stripe.  The MIT students presentation states that these are cloneable and forgeable using a $150 magnetic stripe reader/writer.</p>
<p>From the <a href="http://cryptome.org/mbta-v-zack/10-scott-henderson-declaration.pdf">Confidential Memo Prepared for the MBTA</a> which was publicly disclosed by the MBTA is court filing:</p>
<p><a href="http://cryptome.org/mbta-v-zack/10-scott-henderson-declaration.pdf"><center><img class="alignnone size-full wp-image-241 photoborder" title="memo-excerpt" src="http://www.veracode.com/blog/wp-content/uploads/2008/08/memo-excerpt.png" alt="" width="576" height="108" /></center></a></p>
<p>This seems to break all the rules of integrity of sensitive data storage. How could someone store money on a magnetic stripe in 2008 and not store an identifier that references the account in a central database?</p>
<p>The tickets do have a unique identifier generated when the card is initially purchased so a fraud detection system could be in place or is planned. But this would require tracking the value on the ticket or the usage of the ticket centrally so it isn&#8217;t clear why the value is stored on the card in the first place.</p>
<p>There are so many question about the security of this public system.  Fraud costs the Massachusetts taxpayer money and refitting an insecure, ill-designed system costs the Massachusetts taxpayer money. [Disclosure: I am a Massachusetts taxpayer.]</p>
<p>It should be a requirement that the current system or the (hopefully) upgraded system be tested by an independent organization that specializes in cryptosystems.  If the independent testing uncovers vulnerabilities, they need to be fixed before the system is fielded. Then the system should be retested to verify the fixes.  Once the system is deemed secure by an independent organization, a summary of the test document should be published for public inspection.  It should include the types of testing conducted and the results.</p>
<p>The public trust requires inspection of taxpayer funded projects to make sure they meet acceptible standards and vendors held responsible for deficiencies.  Projects that use computers and software should not get a free pass. It will be interesting to see if the CharlieTicket system is ever held up to public scrutiny.</p>
<p><img src="file:///C:/DOCUME~1/cwysopal/LOCALS~1/Temp/moz-screenshot.jpg" alt="" /></p>
]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 09:19:29 +0000</pubDate>
      <category domain="http://securityratty.com/tag/massachusetts taxpayer">massachusetts taxpayer</category>
      <category domain="http://securityratty.com/tag/taxpayer">taxpayer</category>
      <category domain="http://securityratty.com/tag/system">system</category>
      <category domain="http://securityratty.com/tag/fraud detection system">fraud detection system</category>
      <category domain="http://securityratty.com/tag/system costs">system costs</category>
      <category domain="http://securityratty.com/tag/public system">public system</category>
      <category domain="http://securityratty.com/tag/massachusetts taxpayer money">massachusetts taxpayer money</category>
      <category domain="http://securityratty.com/tag/charlieticket system">charlieticket system</category>
      <category domain="http://securityratty.com/tag/charlieticket">charlieticket</category>
      <source url="http://www.veracode.com/blog/2008/08/mbta-hack-is-it-really-this-easy/">MBTA Hack: Is It Really This Easy?</source>
    </item>
    <item>
      <title><![CDATA[When turning updates off really doesnt]]></title>
      <link>http://securityratty.com/article/ad6bfd3501bc1cd24c641aab64e8f592</link>
      <guid>http://securityratty.com/article/ad6bfd3501bc1cd24c641aab64e8f592</guid>
      <description><![CDATA[In any business dealings, if you cant trust the company to do what they say they will do, You go elsewhere right? Its your decision. Not in this instance folks


clipped from windowssecrets.com

Youll...]]></description>
      <content:encoded><![CDATA[<div > In any business dealings, if you cant trust the company to do what they say they will do,<br/>You go elsewhere right?<br/>Its your decision. Not in this instance folks. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/B5BE1F57-04DA-47A4-81B1-6DCC22F654F6/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/9d9b6101-4fcd-4b38-800c-4f4f98154898/B5BE1F57-04DA-47A4-81B1-6DCC22F654F6/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://windowssecrets.com/comp/080814" href="http://windowssecrets.com/comp/080814" style="font-size: 11px;">windowssecrets.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://windowssecrets.com/comp/080814 --><B><br />
You&#8217;ll get a new Windows Update, like it or not<br />
</B></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://windowssecrets.com/comp/080814 --><DIV><br />
This time, Microsoft is being more up-front about its forthcoming<br />
refresh of Windows Update. For example, product manager Michelle Haven described in a<br />
<A href="http://WindowsSecrets.com/links/$P20d/fee5a4h/?url=blogs.technet.com%2Fmu%2Farchive%2F2008%2F07%2F03%2Fupcoming-update-to-windows-update.aspx" class="nwindow" target="_blank">blog post</A> on July 3 some new features that the upgrade will add.</DIV></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://windowssecrets.com/comp/080814 --><DIV><br />
The new version will reportedly reduce the time WU takes to scan for and send out new updates. In addition, if you use the online version of WU, and you click an update for more information, the new version will offer you more links with additional details.</DIV></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://windowssecrets.com/comp/080814 --><DIV><br />
But the Redmond company hasn&#8217;t changed the wording of the Control Panel settings that appear to prevent Windows Update from performing silent downloads — but don&#8217;t.</DIV></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://windowssecrets.com/comp/080814 --><DIV><br />
In light of these potentially misleading controls, a few tricks on managing Windows Update are just what the doctor ordered.</DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/B5BE1F57-04DA-47A4-81B1-6DCC22F654F6/blog/" title="blog or email this clip"><img src="http://content7.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 09:31:32 +0000</pubDate>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/prevent windows">prevent windows</category>
      <category domain="http://securityratty.com/tag/online version">online version</category>
      <category domain="http://securityratty.com/tag/version">version</category>
      <category domain="http://securityratty.com/tag/redmond company">redmond company</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/product manager michelle">product manager michelle</category>
      <category domain="http://securityratty.com/tag/control panel settings">control panel settings</category>
      <category domain="http://securityratty.com/tag/additional details">additional details</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=559">When turning updates off really doesnt</source>
    </item>
    <item>
      <title><![CDATA[Fog of the Future: Cloud Computings on the Horizon]]></title>
      <link>http://securityratty.com/article/b0444080036cffd2f313acaf1bcf9b99</link>
      <guid>http://securityratty.com/article/b0444080036cffd2f313acaf1bcf9b99</guid>
      <description><![CDATA[If you trust the media and are looking to the future, you might be thinking a good deal about Cloud Computing according to ComputerWorld, this could be the next big movement
Ive heard the buzzwords...]]></description>
      <content:encoded><![CDATA[<p>If you trust the media and are looking to the future, you might be thinking a good deal about <a rel="nofollow" target="_blank" href="http://blogs.computerworld.com/forecast_calls_for_clouds_are_we_ready">Cloud Computing</a> &#8212; according to ComputerWorld, this could be the next big movement.</p>
<p>I&#8217;ve heard the buzzwords but wasn&#8217;t exactly sure what they meant&#8211;luckily, when there&#8217;s media hype, there are definitions, too. According to <a rel="nofollow" target="_blank" href="http://www.thestandard.com/news/2008/08/04/quicker-path-clouds">this article</a>, cloud computing is exemplified by Software as a Service &#8212; outsourced, hosted platforms and software that perform services for companies. </p>
<p>Another <a rel="nofollow" target="_blank" href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&#038;articleId=9111689">article </a>puts it slightly differently:</p>
<blockquote><p>OK, let us look at what form of computing in being provided via the cloud. In this model, all IT applications and facilities (i.e. compute, storage and network) are provided as a service rather than dedicated infrastructure. This is intended to allow any user, independent of client platform, to access IT services without knowledge or concern of their location or form. Sound familiar &#8212; it&#8217;s a service-oriented architecture (SOA)!</p>
<p>In addition, cloud computing incorporates almost every computing manifestation within the IT world: distributed, grid, utility, on-demand, open-source, Web services, P2P, Web 2.0 and, last but not least, software as a service.</p>
<p>It also accommodates thin, thick and mobile clients and allows integration of corporate, commercial and service provider cloud-accessed resources. As an example, in this model, storage is a service resource that is accessed via the cloud, not a dedicated user resource.</p></blockquote>
<p>Honestly I read that last one first and found the definition a bit dense. It sounds like a summation of everything that makes up our Internet infrastructure already, so how is that different than the Internet itself? Well, cloud computing isn&#8217;t about what service or devices are being supported &#8212; it&#8217;s more about how it&#8217;s being provided&#8211; it is a location-independent style of computing. The first article calls it &#8220;platform as a service.&#8221;</p>
<p>Have you heard better definitions of what cloud computing is and does? Share them in the comments below. Thanks!</p>]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 08:56:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <category domain="http://securityratty.com/tag/service provider">service provider</category>
      <category domain="http://securityratty.com/tag/service resource">service resource</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/perform services">perform services</category>
      <category domain="http://securityratty.com/tag/web services">web services</category>
      <category domain="http://securityratty.com/tag/internet infrastructure">internet infrastructure</category>
      <category domain="http://securityratty.com/tag/internet">internet</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/365101308/">Fog of the Future: Cloud Computings on the Horizon</source>
    </item>
    <item>
      <title><![CDATA[The web browser is sick but wheres the cure?]]></title>
      <link>http://securityratty.com/article/c1a26694b7d3db2c185a5f976e06cc90</link>
      <guid>http://securityratty.com/article/c1a26694b7d3db2c185a5f976e06cc90</guid>
      <description><![CDATA[Blogger: Ramon Krikken
The web browser is one of those peculiar pieces of software, having to accept input from arbitrary sources and then parse and render the data that is sent to it. Part of this it...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Blogger: Ramon Krikken</p>

<p>The web browser is one of those peculiar pieces of software, having to accept input from arbitrary sources and then parse and render the data that is sent to it. Part of this it does by itself, and other parts are taken care of by handlers and plug-ins. In doing so, it displays hypertext, images, videos, and even runs active content like Flash, JavaScript, and ActiveX. </p>

<p>But however much we love the browser, we’ve also come to hate the myriad of vulnerabilities that affect it. Everything from cross-site scripting to remote code execution via maliciously formed animated cursor files and Flash content can make browsing a hazardous activity. The browser is sick, and that’s not desirable for a platform we use for important business and personal transactions.</p>

<p>Worsening the browser’s diagnosis is the <a href="http://taossa.com.nyud.net:8080/archive/bh08sotirovdowdslides.pdf">recent paper</a> from Mark Dowd and Alexander Sotirov, sub-titled “Setting back browser security by 10 years,” which discusses how to bypass Microsoft Vista’s memory protection capabilities with some added effort for the exploit designers. It’s not that all of the techniques are necessarily new, but the browser appears to be particularly vulnerable to easy exploitation. </p>

<p>Surprising? Not exactly, when we take into account that the browser is suffering from the same disease as the general purpose operating system: bloat and compatibility. We expect the browser to do ever more, but everything we used it for before still needs to work as if it were yesterday. It feels a bit like people insisting on using a cardboard box as a safe, and wondering why their money keeps getting stolen.</p>

<p>It’s not like we haven’t been working on the browser’s cure, though. There have been some improvements in the browsers themselves, the operating systems have also implemented compensating controls, but most of all, there has been an enormous push for securing the web applications that deliver the data in the first place. Unfortunately, the latter two won’t help secure the browser in the long run.</p>

<p>The first issue is that not all content will come from ‘nice’ servers, the second that the server can only make an educated guess on how a browser will parse and render a given set of data, and the third that operating system controls have their own limitations, whether by design or implementation (for example needing to re-compile existing code to enable certain protections.) The browser, in the end, has to be mostly responsible for keeping itself safe; the operating system must assist it in doing so.</p>

<p>So we’re in a pickle. The browser is sick (and the operating system is too), but it’s hard to cure it without a redesign that will undoubtedly impact compatibility, the ever-so-desired multi-functionality, or its ease of use. We can layer defenses by using web filtering in the enterprise environment, but in the end – for the consumer market in particular – we need to fix the browser itself. I can think of a few things I think might help: </p>

<ul><li>Some kind of <a href="http://people.mozilla.com/~bsterne/site-security-policy/">site security policy</a>&nbsp; to restrict where the browser loads auxiliary content from, and which data it can ‘trust’, when loading a web page (I’d prefer mandatory enforcement, and adding an HTML tag to be able to indicate blocks of untrustworthy data.)</li>

<li>Restricted compartments for plug-ins to run in, ensuring that their bugs cannot easily affect the whole browser.</li>

<li>Better software development practices for the plug-ins and content parsers themselves, so that they’re less vulnerable, and compiled with the latest protection measures to begin with.</li></ul>

<p>All of this means more work, and some of it means a lot of unhappy reactions when things stop working. Even then we will of course still have to deal with additional vulnerabilities, such as those that may be present in hardware, but we will at least have taken prudent steps to ‘find a cure.’</p>

</div>
<img src="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~4/364862623" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 14 Aug 2008 07:11:14 +0000</pubDate>
      <category domain="http://securityratty.com/tag/browser">browser</category>
      <category domain="http://securityratty.com/tag/web browser">web browser</category>
      <category domain="http://securityratty.com/tag/browser appears">browser appears</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/cure">cure</category>
      <category domain="http://securityratty.com/tag/browser security">browser security</category>
      <category domain="http://securityratty.com/tag/content">content</category>
      <category domain="http://securityratty.com/tag/runs active content">runs active content</category>
      <category domain="http://securityratty.com/tag/browsers cure">browsers cure</category>
      <source url="http://feeds.feedburner.com/~r/SecurityAndRiskManagementStrategiesBlog/~3/364862623/the-web-browser.html">The web browser is sick but wheres the cure?</source>
    </item>
    <item>
      <title><![CDATA[UPDATES GALORE! or, THE PRONOUN WE MEANS YOU AND ME!]]></title>
      <link>http://securityratty.com/article/6ebd2507c3c7a5fbc11f6123a9af9559</link>
      <guid>http://securityratty.com/article/6ebd2507c3c7a5fbc11f6123a9af9559</guid>
      <description><![CDATA[So much traveling, so little blogging. Sorry everyone. Ive gotta say first that I really enjoyed meeting readers and friends of the blog this past two weeks
Today, allow me to update you on FAIR and...]]></description>
      <content:encoded><![CDATA[<p>So much traveling, so little blogging.  Sorry everyone.  I&#8217;ve gotta say first that I really enjoyed meeting readers and friends of the blog this past two weeks.</p>
<p>Today, allow me to update you on FAIR and the movement towards a formal, open standard.  There&#8217;s a couple of cool things going on in our little risk-world.</p>
<p>First, The Open Group Security Forum continues to move towards a formal adoption of FAIR.</p>
<p><strong>WHAT DO YOU MEAN &#8220;WE&#8221; - YOU GOT A STANDARDS BODY IN YOUR POCKET OR SOMETHING?</strong></p>
<p>Our meeting in Chicago a few weeks ago was great, but also slightly disturbing for me. I got pronoun-confusion syndrome.   I&#8217;m used to using the &#8220;we&#8221; pronoun to refer to RMI, or Jack and myself as we vet the models.  So without even thinking I would said &#8220;we have been looking at how loss occurs, and may want to change the model some&#8221; and The Open Group Members freaked out (rightfully so).  Adrian Seccombe gently reminded me that the &#8220;we&#8221; was now the Security Forum, and that &#8220;we&#8221; didn&#8217;t go changing things at will without vetting against each other.  Man I love this stuff.  I get to run our thoughts and ideas past some great folks now - you know, those smart people who tend to have really complex problems and are trying hard to solve them.<br />
<span style="color: #000080;"><strong><br />
Formal Adoption:  Soon, Very Soon Now</strong></span></p>
<p>Formal Adoption basically means we&#8217;ve made this document, everyone is close to saying that they generally like it, and once that finally happens then &#8220;bam&#8221;, we&#8217;re ready to move onward and upward with better things (see Cookbooks, below).  We&#8217;ve got a couple of changes to the current document that have been requested that aren&#8217;t a big deal.  For example, one request is that we make some statement about general applicability of FAIR to risk domains outside of the IT realm.   But once additions like that and others are done, this long process should be complete.</p>
<p><span style="color: #000080;"><strong>New Document Moving Towards Public Release:</strong></span></p>
<p>We&#8217;ve got a basic document that should be public in the next few weeks on <em><strong>&#8220;What Makes a Good Risk Assessment Methodology&#8221;</strong></em> - written by yours truly and Jack.  It&#8217;s a very high-level document, and serves two purposes:</p>
<ul>
<li>For novices it helps parse out what is important in any undertaking to understand corporate risk (the repeated discussions on the ISO 27001 mailing list make me think it would be a place ripe for such a document).</li>
<li>For those who &#8220;know&#8221; risk, it helps to re-establish some fundamental principles like the use of scales (ratio, please), the implications of dealing in probabilities, what attributes like consistency and defensibility mean, how &#8220;risk&#8221; should be reported to the business (something you know, meaningful) and so on.</li>
</ul>
<p>When this doc is deemed ready for public consumption I&#8217;ll be sure to post on this blog here.</p>
<p><strong>COOKBOOKS, EUROPEAN AGENCIES, AND, IRON CHEF &#8220;RISK&#8221; - WHOSE CUISINE WILL REIGN SUPREME?</strong></p>
<p>One interesting thing that came up in the Chicago meeting was that <strong><a href="http://www.enisa.europa.eu/">ENISA</a></strong> (The European Network and Information Security Agency) developed a very nice document that reviewed something like 18 different risk assessment methodologies against their Criteria for Goodness.  FAIR was one of the ones they reviewed, and we (the royal &#8220;we&#8221; used there to include all us FAIR-Folk) did awfully well.  Things of interest:</p>
<ol>
<li>They based their work on the current introduction paper which is not at all a step-by-step guide towards an organizational risk assessment (what ENISA really wanted) and we did pretty well.  Well enough that if we had developed a paper along the lines of NIST 800-30 or OCTAVE for the use of FAIR in a formal process, we could have done <em><strong>really, really</strong></em> well.  Like won-the-bake-off kind of well.</li>
<li>FAIR is actually not at all incongruous to many of the risk assessment methodologies offered, and in fact compliments many of them by letting those methodologies develop real, structured probabilities.  Think OCTAVE, where they basically say &#8220;math is (probabilities are) hard, so if you want to do them for reals, good luck!  But here&#8217;s a nonsensical way to do things if you want to believe in <span style="color: #ff00ff;"><em>magic-fairy risk</em></span>&#8220;.  FAIR fits right in there by stomping on the magic-fairy risk with the jack-boots of rationality.  FAIR similarly helps other risk standards that might lack structured probability development.</li>
</ol>
<p>So The Open Group Security Forum decided that though we could create a new document and totally p0wn any future ENISA bake-off, there wasn&#8217;t much demand for the development of that documentation by the membership  - a point which was made quite apparent at the beginning of the discussion when one large European company CISO asked &#8220;What&#8217;s ENISA?&#8221;  Relevancy is everything, I suppose.</p>
<p>But that second item up there - the one about helping rather than competing with other &#8220;risk assessment methodologies&#8221; - really struck a chord.  So &#8220;we&#8221; (The Security Forum) are going to develop some &#8220;Cookbooks&#8221; that basically are high-level documents that say &#8220;If you want to use FAIR with (OCTAVE/COSO/CoBIT/Whatever) here&#8217;s how it fits, makes it better, and improves your life.  I&#8217;m pretty excited about these, and our first document looks like it&#8217;s going to be COSO integration.</p>
<p><strong>THE OPEN GROUP SECURITY FORUM - THEY&#8217;RE A TRUSTING BUNCH (WITH QUALIFICATION, OF COURSE)<br />
</strong></p>
<p>Finally, many people have asked me &#8220;Why work with The Open Group?&#8221;  There are many reasons, to be sure, but I will give you one example.  Members of the Security Forum there are not only great at vetting the model and getting consensus on risk and risk factors - but they&#8217;re quick to start applying.  So in Chicago, I thought I&#8217;d be talking about FAIR and the standard and fighting groupthink.  Nope.  Not at all.  In fact, the forum members spent more time suddenly discussing use of FAIR in a new Trust Model they&#8217;re developing.  So all of the sudden, I&#8217;m part of a new and exciting project to develop a Trust Model - how cool is that?  While formal adoption of the Trust Model will be necessarily long and deliberate - the collaboration and development is happening much faster than I can keep up with.  But if you all will allow me, it will help me get my head around it all by blogging about it later this week.  So be prepared to read about me dealing in &#8220;Trust&#8221; a little bit.</p>
]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 11:24:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk assessment methodologies">risk assessment methodologies</category>
      <category domain="http://securityratty.com/tag/security forum">security forum</category>
      <category domain="http://securityratty.com/tag/forum">forum</category>
      <category domain="http://securityratty.com/tag/magic-fairy risk">magic-fairy risk</category>
      <category domain="http://securityratty.com/tag/risk standards">risk standards</category>
      <category domain="http://securityratty.com/tag/fair">fair</category>
      <category domain="http://securityratty.com/tag/risk-world">risk-world</category>
      <category domain="http://securityratty.com/tag/fair similarly helps">fair similarly helps</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=381">UPDATES GALORE! or, THE PRONOUN WE MEANS YOU AND ME!</source>
    </item>
    <item>
      <title><![CDATA[Trust No One?]]></title>
      <link>http://securityratty.com/article/cbe272a22113c011f34b6644f8b4ea09</link>
      <guid>http://securityratty.com/article/cbe272a22113c011f34b6644f8b4ea09</guid>
      <description><![CDATA[Sorry to go all X-Files on you, but I received an EMail earlier today that really drives home how paranoid we probably all are about Phishing nowadays

Entitled &quot;Chris Boyd, would you be able to spot...]]></description>
      <content:encoded><![CDATA[
        Sorry to go all X-Files on you, but I received an EMail earlier today that really drives home how paranoid we probably all are about Phishing nowadays.<br /><br />Entitled "Chris Boyd, would you be able to spot a fake email?", it was apparently from Paypal:<br /><br /><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><img alt="fakeornot1.jpg" src="http://blog.spywareguide.com/images/fakeornot1.jpg" class="mt-image-none" style="" height="468" width="437" /></span><br /> <div><br /><i>"Protect yourself from phishing: Paypal is working with Gmail and Yahoo! to block fake Paypal emails from your inbox. Learn how".</i><br /><br />As it turns out, the email <i>was</i> legitimate - but as soon as I hear someone asking me "Can you spot a fake Email", my brain is sadly conditioned to assume the mail asking me that question is <i>fake too</i>.<br /><br />Kind of depressing, isn't it? At any rate, it's interesting how certain words / phrases in mails will automatically set alarm bells ringing. If I'd received <a href="http://anti-virus-rants.blogspot.com/2008/08/is-sympatico-training-their-users-to-be.html">this email</a>, I'd have deleted it as soon as I saw the phrase "Your download to win contest has arrived".<br /><br /><i>Download to Win Contest</i>?? That sounds so very, very wrong, doesn't it?<br /></div>
        
    ]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 10:46:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake email">fake email</category>
      <category domain="http://securityratty.com/tag/fake">fake</category>
      <category domain="http://securityratty.com/tag/email">email</category>
      <category domain="http://securityratty.com/tag/set alarm bells">set alarm bells</category>
      <category domain="http://securityratty.com/tag/paypal">paypal</category>
      <category domain="http://securityratty.com/tag/win">win</category>
      <category domain="http://securityratty.com/tag/chris boyd">chris boyd</category>
      <category domain="http://securityratty.com/tag/spot">spot</category>
      <category domain="http://securityratty.com/tag/download">download</category>
      <source url="http://blog.spywareguide.com/2008/08/trust-no-one.html">Trust No One?</source>
    </item>
  </channel>
</rss>
