<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: type]]></title>
    <link>http://securityratty.com/tag/type</link>
    <description></description>
    <pubDate>Fri, 07 Nov 2008 06:07:37 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[The Future of Ephemeral Conversation]]></title>
      <link>http://securityratty.com/article/1474b03de8a1d60cdf0aa28759ddce93</link>
      <guid>http://securityratty.com/article/1474b03de8a1d60cdf0aa28759ddce93</guid>
      <description><![CDATA[When he becomes president, Barack Obama will have to give up his BlackBerry. Aides are concerned that his unofficial conversations would become part of the presidential record, subject to subpoena and...]]></description>
      <content:encoded><![CDATA[<p>When he becomes president, Barack Obama will have to <a href="http://www.nytimes.com/2008/11/16/us/politics/16blackberry.html">give up</a> his BlackBerry.  Aides are concerned that his unofficial conversations would become part of the presidential record, subject to subpoena and eventually made public as part of the country's historical record.</p>

<p>This reality of the information age might be particularly stark for the president, but it's no less true for all of us.  Conversation used to be ephemeral.  Whether face-to-face or by phone, we could be reasonably sure that what we said disappeared as soon as we said it. Organized crime bosses worried about phone taps and room bugs, but that was the exception.  Privacy was just assumed.</p>

<p>This has changed.  We chat in e-mail, over SMS and IM, and on social networking websites like Facebook, MySpace, and LiveJournal.  We blog and we Twitter.  These conversations -- with friends, lovers, colleagues, members of our cabinet -- are not ephemeral; they <a href="http://www.schneier.com/essay-109.html">leave their own electronic trails</a>.</p>

<p>We know this intellectually, but we haven't truly internalized it.  We type on, engrossed in conversation, forgetting we're being recorded and those recordings might come back to haunt us later.</p>

<p>Oliver North learned this, way back in 1987, when messages he thought he had deleted were saved by the White House PROFS system, and then subpoenaed in the Iran-Contra affair.  Bill Gates learned this in 1998 when his conversational e-mails were provided to opposing counsel as part of the antitrust litigation discovery process.  Mark Foley learned this in 2006 when his instant messages were <a href="http://abcnews.go.com/WNT/BrianRoss/story?id=2509586">saved and made public</a> by the underage men he talked to.  Paris Hilton learned this in 2005 when her cell phone account was <a href="http://www.washingtonpost.com/wp-dyn/content/article/2005/05/19/AR2005051900711.html">hacked</a>, and Sarah Palin learned it earlier this year when her Yahoo e-mail account was hacked.  Someone in George W. Bush's administration learned this, and <a href="http://www.cnn.com/2007/POLITICS/04/13/white.house.email/index.html">millions of e-mails</a> went mysteriously and conveniently missing.</p>

<p>Ephemeral conversation is dying.</p>

<p>Cardinal Richelieu famously said, :If one would give me six lines written by the hand of the most honest man, I would find something in them to have him hanged."  When all our ephemeral conversations can be saved for later examination, different rules have to apply.  Conversation is not the same thing as correspondence.  Words uttered in haste over morning coffee, whether spoken in a coffee shop or thumbed on a Blackberry, are not official pronouncements.  Discussions in a meeting, whether held in a boardroom or a chat room, are not the same as answers at a press conference.  And privacy isn't just about having something to hide; it <a href="http://www.schneier.com/essay-114.html">has enormous value</a> to democracy, liberty, and our basic humanity.</p>

<p>We can't turn back technology; electronic communications are here to stay and <a href="http://en.wikipedia.org/wiki/NSA_warrantless_surveillance_controversy">even our voice conversations are threatened</a>.  But as technology makes our conversations less ephemeral, we need laws to step in and safeguard ephemeral conversation.  We need a comprehensive data privacy law, protecting our data and communications regardless of where it is stored or how it is processed. We need laws forcing companies to keep it private and delete it as soon as it is no longer needed.  Laws requiring ISPs to store e-mails and other personal communications are exactly what we don't need.</p>

<p>Rules pertaining to government need to be different, because of the <a href="http://www.schneier.com/essay-208.html">power differential</a>.  Subjecting the president's communications to eventual public review increases liberty because it reduces the government's power with respect to the people.  Subjecting our communications to government review decreases liberty because it reduces our power with respect to the government.  The president, as well as other members of government, need some ability to converse ephemerally -- just as they're allowed to have unrecorded meetings and phone calls -- but more of their actions need to be subject to public scrutiny.</p>

<p>But laws can only go so far.  Law or no law, when something is made public it's too late.  And many of us like having complete records of all our e-mail at our fingertips; it's like our offline brains.</p>

<p>In the end, this is cultural.</p>

<p>The Internet is the greatest generation gap since rock and roll.  We're now witnessing one aspect of that generation gap: the younger generation chats digitally, and the older generation treats those chats as written correspondence.  Until our CEOs blog, our Congressmen Twitter, and our world leaders send each other LOLcats &ndash; until we have a Presidential election where both candidates have a complete history on social networking sites from before they were teenagers&ndash; we aren't fully an information age society.</p>

<p>When everyone leaves a public digital trail of their personal thoughts since birth, no one will think twice about it being there.  Obama might be on the younger side of the generation gap, but the rules he's operating under were written by the older side.  It will take another generation before society's tolerance for digital ephemera changes.</p>

<p>This essay <a href="http://online.wsj.com/article/SB122722381368945937.html">previously appeared</a> on <ui>The Wall Street Journal</a> website (not the print newspaper), and is an update of <a href="http://www.schneier.com/essay-129.html">something I wrote previously</a>.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=jPWiN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=jPWiN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=hlUTN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=hlUTN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 24 Nov 2008 11:06:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ephemeral conversation">ephemeral conversation</category>
      <category domain="http://securityratty.com/tag/conversation">conversation</category>
      <category domain="http://securityratty.com/tag/safeguard ephemeral conversation">safeguard ephemeral conversation</category>
      <category domain="http://securityratty.com/tag/ephemeral">ephemeral</category>
      <category domain="http://securityratty.com/tag/ephemeral conversations">ephemeral conversations</category>
      <category domain="http://securityratty.com/tag/conversations">conversations</category>
      <category domain="http://securityratty.com/tag/generation">generation</category>
      <category domain="http://securityratty.com/tag/generation gap">generation gap</category>
      <category domain="http://securityratty.com/tag/public scrutiny">public scrutiny</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/the_future_of_e.html">The Future of Ephemeral Conversation</source>
    </item>
    <item>
      <title><![CDATA[Another link spammer]]></title>
      <link>http://securityratty.com/article/4dd72baf5933c49893c38cadde935c82</link>
      <guid>http://securityratty.com/article/4dd72baf5933c49893c38cadde935c82</guid>
      <description><![CDATA[Yet another link spammer is cluttering up my in-box. Youd think that after exposing this one , and this one , and this one , theyd know better
The latest set of miscreants operates under the brand...]]></description>
      <content:encoded><![CDATA[<p>Yet another link spammer is cluttering up my in-box. You&#8217;d think that after exposing <a href="http://www.lightbluetouchpaper.org/2007/01/07/human-rights-and-biophysics-strange-similarities/">this one</a>, and <a href="http://www.lightbluetouchpaper.org/2007/08/30/the-interns-of-privila/">this one</a>, and <a href="http://www.lightbluetouchpaper.org/2007/12/20/fatal-wine-waiters/">this one</a>, they&#8217;d know better.</p>
<p>The latest set of miscreants operates under the brand &#8220;<a href="http://www.goodeyeforlinks.com" rel="nofollow">goodeyeforlinks.com</a>&#8221; and claim to &#8220;use white hat SEO techniques in order to get high quality, do-follow links to your website&#8221;. They also claim to be &#8220;professional&#8221; which in this case must mean you pay for their services, since sending out bulk unsolicited email is anything but professional.</p>
<p>Nevertheless, although their long term aim may indeed be to make money from legitimate, albeit foolish, businesses seeking a higher profile, the sites they have been promoting so far are anything but legitimate. In fact they&#8217;ve been fake sites covered with Google adverts (so-called &#8220;<a href="http://www.sabahan.com/2006/06/26/how-mfa-made-for-adsense-sites-make-money/">Made for AdSense</a>&#8221; (MFA) sites).</p>
<p>They started by asking me to link to &#8220;<a href="http://www.entovation.net" rel="nofollow">entovation.net</a>&#8221; which they claim is &#8220;page rank 3&#8243;. In fact it is page rank 3 (!) and a blatant copy of <a href="http://www.acentesolutions.com/">http://www.acentesolutions.com</a> which appears entirely genuine (albeit only page rank 1). They have also been promoting &#8220;<a href="http://www.poland-translation-services.com" rel="nofollow">poland-translation-services.com</a>&#8220;, which claims to be a site offering &#8220;A large team of 2,500 translators specializing in each sector, located in over 30 countries&#8221; &#8230;</p>
<p>However, this site is clearly fake as well. I haven&#8217;t tracked down where it all comes from, but much of <a href="http://poland-translation-services.com/Translate-a-Document.html" rel="nofollow">this page</a> comes from <a href="http://www.intowords.com.ar/espanol/traducciones/traducciones-de-espanol-ingles.html">this Argentinian page</a>, the text of which has been pushed through <a href="http://www.google.com/language_tools?hl=en">Google&#8217;s Spanish to English translation tools</a>&#8230;  which sadly (for example) renders </p>
<blockquote><p>
Comentarios: Se considera foja al equivalente a 500 palabras. Si el documento a traducir es menor a una foja, se lo considerará como una foja.
</p></blockquote>
<p>into </p>
<blockquote><p>
Comments: foja is considered the equivalent of 500 words. If the document is translated to a lesser foja, we will consider as a foja.
</p></blockquote>
<p>which makes the 2500 translators look more than a little bit <a href="http://www.cartoonbank.com/item/124224">foolish</a>!</p>
<p>The fake websites are hosted by <a href="http://www.euroaccess.nl/">EuroAccess Enterprises Ltd.</a> in The Netherlands (which is also where the email spam has been sent from). I&#8217;m not alone in receiving this type of email, further examples can be found <a href="http://archives.neohapsis.com/archives/openbsd/2008-09/1548.html">here</a>, and <a href="http://www.projecthoneypot.org/ip_89.248.172.66">here</a>, and <a href="http://dansdata.blogsome.com/2008/10/16/i-do-like-a-good-link-spam-in-the-morning/">here</a>, and <a href="http://avvoblog.com/2008/11/10/linkbrokers-gone-wild/">here</a>, and <a href="http://www.nabble.com/Link-exchange-with-page-rank-4--Hotel-site-td19973368.html">here</a>, and <a href="http://www.allvoices.com/contributed-news/1522559">here</a>, and even <a href="http://blogpintura.wordpress.com/#comment-5">here (in Spanish)</a>.</p>
<p>EuroAccess have a fine ticketing system for abuse complaints&#8230; so I&#8217;m able to keep track of what they&#8217;re doing about my emails drawing their attention to the fraudsters they are hosting. I am therefore fully aware that they&#8217;ve so far marked my missives as &#8220;Priority: Low&#8221;, and nothing else is recorded to have been done&#8230; However, the tickets are still &#8220;Status: Open&#8221;, so perhaps a little publicity will encourage them to reassess their prioritisation.</p>
]]></content:encoded>
      <pubDate>Sun, 23 Nov 2008 16:45:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/argentinian page">argentinian page</category>
      <category domain="http://securityratty.com/tag/page">page</category>
      <category domain="http://securityratty.com/tag/foja">foja</category>
      <category domain="http://securityratty.com/tag/lesser foja">lesser foja</category>
      <category domain="http://securityratty.com/tag/page rank">page rank</category>
      <category domain="http://securityratty.com/tag/considera foja">considera foja</category>
      <category domain="http://securityratty.com/tag/link spammer">link spammer</category>
      <category domain="http://securityratty.com/tag/link">link</category>
      <category domain="http://securityratty.com/tag/fake">fake</category>
      <source url="http://www.lightbluetouchpaper.org/2008/11/23/another-link-spammer/">Another link spammer</source>
    </item>
    <item>
      <title><![CDATA[OAuth for Secure Mashups]]></title>
      <link>http://securityratty.com/article/f0ebee1b88f03cd2b1ad9ff61f4608ac</link>
      <guid>http://securityratty.com/article/f0ebee1b88f03cd2b1ad9ff61f4608ac</guid>
      <description><![CDATA[Posted by Eric Sachs, Senior Product Manager, Google Security

A year ago, a number of large and small websites announced a new open standard called OAuth . This standard is designed to provide a...]]></description>
      <content:encoded><![CDATA[<span class="byline-author">Posted by Eric Sachs, Senior Product Manager, Google Security</span><br /><br />A year ago, a number of large and small websites announced a new open standard called <a href="http://oauth.net/" id="hz33" title="OAuth">OAuth</a>. This standard is designed to provide a secure and privacy-preserving technique for enabling specific private data on one site to be accessed by another site.  One popular reason for that type of cross-site access is data portability in areas such as personal health records (such as Google Health or Microsoft Healthvault), as well as social networks (such as OpenSocial enabled sites). I originally became involved in this space in the summer of 2005, when Google started developing a feature called <a href="http://code.google.com/apis/accounts/docs/AuthSub.html" id="e3yh" title="AuthSub">AuthSub</a>, which was one of the pre-cursors of OAuth. That was a proprietary protocol, but one that has been used by hundreds of websites to provide add-on services to Google Account users by getting permission from users to access data in their Google Accounts.  In fact, that was the key feature that a few of us used to start the Google Health portability effort back when it was only a prototype project with a few dedicated Googlers.  <div id="zq.s" style="margin-top: 0px; margin-bottom: 0px;"><br /></div>  <div id="zq.s1" style="margin-top: 0px; margin-bottom: 0px;"> However, with the development of a common Internet standard in OAuth, we see much greater potential for data portability and secure mash-ups. Today we <a href="http://igoogledeveloper.blogspot.com/2008/11/sign-in-to-myspace-aol-mail-and-google.html">announced</a> that the gadget platform now supports OAuth, and the interoperability of this standard was demonstrated by new iGoogle gadgets that AOL and MySpace both built to enable users to see their respective AOL or MySpace mailboxes (and other information) while on iGoogle. However, to ensure the user's privacy, this only works after the user has authorized AOL or MySpace to make their data available to the gadget running on iGoogle.  We also previously <a href="http://googledataapis.blogspot.com/2008/10/whats-that-google-data-gadgets.html" id="w6.8" title="announced">announced</a> that third-party developers can build their own iGoogle gadgets that access the OAuth-enabled APIs for Google applications such as Calendar, Picasa, and Docs. In fact, since both the gadget platform and OAuth technology are open standards, we are working to help other companies who run services similar to iGoogle to enhance them with support for these standards. Once that is in place, these new OAuth-powered gadgets that are available on iGoogle will also work on those other sites, including many of the gadgets that Google offers for its own applications. This provides a platform for some interesting mash-ups.  For example, a third-party developer could create a single gadget that uses OAuth to access both Google OAuth-enabled APIs (such as a Gmail user's <a href="http://code.google.com/apis/contacts/" id="v05v" title="address book">address book</a>) and <a href="http://developer.myspace.com/community/myspace/dataavailability.aspx" id="lewp" title="MySpace OAuth enabled APIs">MySpace OAuth-enabled APIs</a> (such as a user's friend list) and display a mashup of the combination.  </div>  <div id="d23k" style="margin-top: 0px; margin-bottom: 0px;"><br /></div>  <div id="ivuk" style="margin-top: 0px; margin-bottom: 0px;"> While the combination of OAuth with gadgets is an exciting new use of the technology, most of the use of OAuth is between websites, such as to enable a user of Google Health to allow a clinical trial matching site to access his or her health profile.  I previously mentioned that one privacy control provided by OAuth is that it defines a standard way for users to authorize one website to make their data accessible to another website. In addition, OAuth provides a way to do this without the first site needing to reveal the identity of the user -- it simply provides a different opaque security token to each additional website the user wants to share his or her data with.  It would allow a mutual fund, for example, to provide an iGoogle gadget to their customers that would run on iGoogle and show the user the value of his or her mutual fund, but without giving Google any unique information about the user, such as a social security number or account number.  In the future, maybe we will even see industries like banks use standards such as OAuth to allow their customers to authorize utility companies to perform direct debit from the user's bank account without that person having to actually share his or her bank account number with the utility vendor. </div>  <div id="pvsw" style="margin-top: 0px; margin-bottom: 0px;"><br /></div>  <div id="odub" style="margin-top: 0px; margin-bottom: 0px;"> The OAuth community is continuing to enhance this standard and is very interested in having more companies engaged with its development. The <a href="http://oauth.net/" id="q6e4" title="OAuth">OAuth.net</a> website has more details about the current standard, and I maintain a <a href="http://sites.google.com/site/oauthgoog/" id="uw8z" title="website">website</a> with advanced information about Google's use of OAuth, including work on integrating OAuth with desktop apps, and integrating with federation standards such as OpenID and SAML.  If you're interested in engaging with the OAuth community, please get in touch with us. </div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?a=LcHtN"><img src="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?i=LcHtN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?a=7jAKn"><img src="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?i=7jAKn" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/458667878" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 14:41:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/oauth">oauth</category>
      <category domain="http://securityratty.com/tag/oauth community">oauth community</category>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/google accounts">google accounts</category>
      <category domain="http://securityratty.com/tag/oauth technology">oauth technology</category>
      <category domain="http://securityratty.com/tag/google security">google security</category>
      <category domain="http://securityratty.com/tag/account">account</category>
      <category domain="http://securityratty.com/tag/bank account">bank account</category>
      <category domain="http://securityratty.com/tag/gadget">gadget</category>
      <source url="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~3/458667878/oauth-for-secure-mashups.html">OAuth for Secure Mashups</source>
    </item>
    <item>
      <title><![CDATA[OAuth for Secure Mashups]]></title>
      <link>http://securityratty.com/article/dce22eb7ff2c1aceec169c6236231696</link>
      <guid>http://securityratty.com/article/dce22eb7ff2c1aceec169c6236231696</guid>
      <description><![CDATA[Posted by Eric Sachs, Senior Product Manager, Google Security

A year ago, a number of large and small websites announced a new open standard called OAuth . This standard is designed to provide a...]]></description>
      <content:encoded><![CDATA[<span class="byline-author">Posted by Eric Sachs, Senior Product Manager, Google Security</span><br /><br />A year ago, a number of large and small websites announced a new open standard called <a href="http://oauth.net/" id="hz33" title="OAuth">OAuth</a>. This standard is designed to provide a secure and privacy-preserving technique for enabling specific private data on one site to be accessed by another site.  One popular reason for that type of cross-site access is data portability in areas such as personal health records (such as Google Health or Microsoft Healthvault), as well as social networks (such as OpenSocial enabled sites). I originally became involved in this space in the summer of 2005, when Google started developing a feature called <a href="http://code.google.com/apis/accounts/docs/AuthSub.html" id="e3yh" title="AuthSub">AuthSub</a>, which was one of the pre-cursors of OAuth. That was a proprietary protocol, but one that has been used by hundreds of websites to provide add-on services to Google Account users by getting permission from users to access data in their Google Accounts.  In fact, that was the key feature that a few of us used to start the Google Health portability effort back when it was only a prototype project with a few dedicated Googlers.  <div id="zq.s" style="margin-top: 0px; margin-bottom: 0px;"><br /></div>  <div id="zq.s1" style="margin-top: 0px; margin-bottom: 0px;"> However, with the development of a common Internet standard in OAuth, we see much greater potential for data portability and secure mash-ups. Today we <a href="http://igoogledeveloper.blogspot.com/2008/11/sign-in-to-myspace-aol-mail-and-google.html">announced</a> that the gadget platform now supports OAuth, and the interoperability of this standard was demonstrated by new iGoogle gadgets that AOL and MySpace both built to enable users to see their respective AOL or MySpace mailboxes (and other information) while on iGoogle. However, to ensure the user's privacy, this only works after the user has authorized AOL or MySpace to make their data available to the gadget running on iGoogle.  We also previously <a href="http://googledataapis.blogspot.com/2008/10/whats-that-google-data-gadgets.html" id="w6.8" title="announced">announced</a> that third-party developers can build their own iGoogle gadgets that access the OAuth-enabled APIs for Google applications such as Calendar, Picasa, and Docs. In fact, since both the gadget platform and OAuth technology are open standards, we are working to help other companies who run services similar to iGoogle to enhance them with support for these standards. Once that is in place, these new OAuth-powered gadgets that are available on iGoogle will also work on those other sites, including many of the gadgets that Google offers for its own applications. This provides a platform for some interesting mash-ups.  For example, a third-party developer could create a single gadget that uses OAuth to access both Google OAuth-enabled APIs (such as a Gmail user's <a href="http://code.google.com/apis/contacts/" id="v05v" title="address book">address book</a>) and <a href="http://developer.myspace.com/community/myspace/dataavailability.aspx" id="lewp" title="MySpace OAuth enabled APIs">MySpace OAuth-enabled APIs</a> (such as a user's friend list) and display a mashup of the combination.  </div>  <div id="d23k" style="margin-top: 0px; margin-bottom: 0px;"><br /></div>  <div id="ivuk" style="margin-top: 0px; margin-bottom: 0px;"> While the combination of OAuth with gadgets is an exciting new use of the technology, most of the use of OAuth is between websites, such as to enable a user of Google Health to allow a clinical trial matching site to access his or her health profile.  I previously mentioned that one privacy control provided by OAuth is that it defines a standard way for users to authorize one website to make their data accessible to another website. In addition, OAuth provides a way to do this without the first site needing to reveal the identity of the user -- it simply provides a different opaque security token to each additional website the user wants to share his or her data with.  It would allow a mutual fund, for example, to provide an iGoogle gadget to their customers that would run on iGoogle and show the user the value of his or her mutual fund, but without giving Google any unique information about the user, such as a social security number or account number.  In the future, maybe we will even see industries like banks use standards such as OAuth to allow their customers to authorize utility companies to perform direct debit from the user's bank account without that person having to actually share his or her bank account number with the utility vendor. </div>  <div id="pvsw" style="margin-top: 0px; margin-bottom: 0px;"><br /></div>  <div id="odub" style="margin-top: 0px; margin-bottom: 0px;"> The OAuth community is continuing to enhance this standard and is very interested in having more companies engaged with its development. The <a href="http://oauth.net/" id="q6e4" title="OAuth">OAuth.net</a> website has more details about the current standard, and I maintain a <a href="http://sites.google.com/site/oauthgoog/" id="uw8z" title="website">website</a> with advanced information about Google's use of OAuth, including work on integrating OAuth with desktop apps, and integrating with federation standards such as OpenID and SAML.  If you're interested in engaging with the OAuth community, please get in touch with us. </div><div class="feedflare">
<a href="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?a=RbYKY1QI"><img src="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?d=41" border="0"></img></a> <a href="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?a=livMlZFo"><img src="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?i=livMlZFo" border="0"></img></a>
</div><img src="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~4/bEpTg1dntxU" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 14:41:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/oauth">oauth</category>
      <category domain="http://securityratty.com/tag/oauth community">oauth community</category>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/google accounts">google accounts</category>
      <category domain="http://securityratty.com/tag/oauth technology">oauth technology</category>
      <category domain="http://securityratty.com/tag/google security">google security</category>
      <category domain="http://securityratty.com/tag/account">account</category>
      <category domain="http://securityratty.com/tag/bank account">bank account</category>
      <category domain="http://securityratty.com/tag/gadget">gadget</category>
      <source url="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/bEpTg1dntxU/oauth-for-secure-mashups.html">OAuth for Secure Mashups</source>
    </item>
    <item>
      <title><![CDATA[A late look at Interop NY 2008]]></title>
      <link>http://securityratty.com/article/a809cae08aacaa70769cecc5883f1d96</link>
      <guid>http://securityratty.com/article/a809cae08aacaa70769cecc5883f1d96</guid>
      <description><![CDATA[Boy, time flies when youre having fun. Ive just gotten my first opportunity to look back at the statistics from Interop NY 2008. Of all the statistics, the ticketing ones have proven to be the most...]]></description>
      <content:encoded><![CDATA[<p>Boy, time flies when you&#8217;re having fun.  I&#8217;ve just gotten my first opportunity to look back at the statistics from Interop NY 2008.  Of all the statistics, the ticketing ones have proven to be the most interesting - especially when you compare them to the Las Vegas show earlier in the year.  If you look back at the <a href="http://blog.sciencelogic.com/interop-vegas-2008-a-tale-of-user-error/06/2008" target="_blank">details of that ticketing review</a> the stats clearly showed that most tickets were opened due to user error.  In NY, while &#8220;user error&#8221; dominated the other categories, &#8220;facilities&#8221; came a close second.  The InteropNet Help Desk opened a total of 94 tickets during Interop NY.  Of these tickets, 42 turned out to be user error.  Coming in second, with 17 tickets were issues with the facilities, with the most common issue being cabling that had gotten damaged between installation and the time the exhibitor was trying to use it.   In Las Vegas, despite the show being significantly larger, we only saw 6 tickets of that type.  I guess you can chalk that up as yet another reason that doing shows at The Javits Center is so much fun! (Don&#8217;t ask Julia about dealing with the Javits Center. She&#8217;ll talk your ear off.)</p>
<p>After Interop Las Vegas you may have seen our analysis of the data that we collected and delivered in our NOC view.  I thought I&#8217;d recreate the same data for NY and do a short comparison.</p>
<p>1) Like in Vegas, uptime for the network 100%.  This is no small feat considering that we introduced a new wrinkle in NY, taking down the primary NOC while the education portion of the show was still going on.  This was a forced failover to the backup systems, and it went flawlessly.  I&#8217;d like to give a little credit to EM7 on the 100% uptime as it caught a failover to battery power that allowed AC to be restored before a series of critical equipment would have gone down.</p>
<p>2) Again like Vegas, the average monitored device in the show network didn&#8217;t even hit 10% CPU utilization.  Still lots of computing overhead availabe in the show network.</p>
<p>3) The NY show network wasn&#8217;t nearly as busy as in Las Vegas, sustaining an average of only 27Mbps of usage (versus 56 Mbps) in Vegas.</p>
<p>4) Power consumption for the network and NOC in NY clocked in at 445kwh per day, about 25% less than the Las Vegas show.  This wasn&#8217;t because the equipment was any more power efficient, but instead because the show was smaller and therefore there was less network gear.</p>
<p>5) Finally, a stat we didn&#8217;t track too carefully in Las Vegas, but that I find interesting.  During show hours the wireless network average 1,100 users attached.  That&#8217;s a lot of people and a lot of wireless devices.</p>
<p>The good news is there was nothing too unexpected in the data, overall the smaller show led to a smaller number of tickets and smaller consumption of resources across the board.  We hope to have the opportunity to work with the InteropNet team again next year and take a look at this data year-over-year for each show.</p>
]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 18:41:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/vegas">vegas</category>
      <category domain="http://securityratty.com/tag/interop las vegas">interop las vegas</category>
      <category domain="http://securityratty.com/tag/las vegas">las vegas</category>
      <category domain="http://securityratty.com/tag/wireless network average">wireless network average</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/interop">interop</category>
      <category domain="http://securityratty.com/tag/network gear">network gear</category>
      <category domain="http://securityratty.com/tag/user error">user error</category>
      <category domain="http://securityratty.com/tag/tickets">tickets</category>
      <source url="http://blog.sciencelogic.com/a-late-look-at-interop-ny-2008/11/2008">A late look at Interop NY 2008</source>
    </item>
    <item>
      <title><![CDATA[Hosting Meets the Cloud Debate Part II]]></title>
      <link>http://securityratty.com/article/3a3393b304f09ea17d212e2f5b730d65</link>
      <guid>http://securityratty.com/article/3a3393b304f09ea17d212e2f5b730d65</guid>
      <description><![CDATA[I have to say that Part II of this session was much anticipated after the lively interaction yesterday. It turned out to be less of a debate and more like a fireside chat. (image from pro.corbis.com...]]></description>
      <content:encoded><![CDATA[<p><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="220" alt="clip_image002" src="http://blog.sciencelogic.com/wp-content/uploads/2008/11/clip-image0024.jpg" width="323" align="left" border="0" />I have to say that Part II of this session was much anticipated after the lively interaction yesterday. It turned out to be less of a debate and more like a fireside chat. <a href="http://pro.corbis.com/images/CB042667.jpg?size=572&amp;uid=%7bDA13F798-FDA1-4B54-BFA9-4B15492E024F%7d" target="_blank">(image from pro.corbis.com)</a></p>
<p>The analysts paired up today:   <br />Antonio Piraino (<a href="http://www.t1r.com/" target="_blank">Tier1 Research</a>)    <br /><a href="http://the451group.com/about/bio_detail.php?eid=113" target="_blank">William Fellows</a> (<a href="http://the451group.com/" target="_blank">The 451 Group</a>)</p>
<p><em>My usual disclaimers on live-blogging: doesn&#8217;t include everything covered (just what was most interesting to me) and had to paraphrase some answers because I simply cannot type that fast. </em></p>
<p><strong>Quick definition of Cloud Computing     <br /></strong><strong>WF:</strong> The cloud is a continuum of grid, virtualization and utility done right. It is about provisioning services instead of servers; flexible computing instead of fixed assets. Done right, the cloud abstracts users from the complexity of grid. <a href="http://www.the451group.com/images/content/ice/ice_iceberg.jpg">Cloud computing is IT as a service</a>. Cloud computing is the Third Way &#8211; not entirely in-house or outsourced, but an optimized hybridized version of both. In light of the Goldman Sachs report out resetting IT spending forecast from up 6% to down 1%, don&#8217;t underestimate the ability for enterprises to move from capex to opex by buying cloud computing instead of building it themselves.</p>
<p>The 451 Group conducted a survey on cloud computing in March, and then revisited it a month ago. Some interesting results:</p>
<ul>
<li>84% have no plans to develop an internal cloud. 5% had no answer to this question. And for the 10% who did answer &#8211; the uses for a private/internal cloud were the same as those for a public cloud. </li>
<li>Top 6 vendors they look to help them develop an internal cloud: <a href="http://www.alleyinsider.com/2008/11/microsoft-s-smart-cloud-catch-up-plan-three-years-of-free-software-msft-" target="_blank">Microsoft</a>, <a href="http://topnews.in/ibm-expand-its-cloud-computing-efforts-285364" target="_blank">IBM</a>, Cisco, HP, Oracle, VMware </li>
</ul>
<p><strong><em>Is it all &#8220;upside&#8221; when it comes to cloud computing?       <br /></em></strong><strong>     <br />WF:</strong> Watch out for the Trojan horse, the red flag. What about the software needed to manage all this stuff? Any management software needs to take a holistic approach to solve the problem.</p>
<p><strong>AP:</strong> Increased management requirements and capability &#8211; this is actually a great story for managed hosters who can hold your hand while getting you up into the cloud. Hosters alleviate the pain points, and this is why we&#8217;re going to see continued growth and focus in the managed hosting sector.</p>
<p><strong>WF:</strong> I would argue that they&#8217;re too expensive. <a href="http://tech.blorge.com/Structure:%20/2008/10/25/amazons-ec2-cloud-moves-into-production/" target="_blank">Look at Amazon</a> &#8211; 10 cents a hit adds up.</p>
<p><strong>AP:</strong> It&#8217;s almost impossible to do an apples-to-apples comparison between cloud providers. One reason is that they charge differently. I&#8217;d say that when you&#8217;re talking about the big cloud providers, you are right &#8211; that they are expensive over the long-term, but for use in the short-term, they can be optimal.</p>
<p><strong>WF:</strong> The cloud is setting big expectations. Can IT deliver? It&#8217;s nice to talk about &#8220;shared resources for the greater good&#8221; but in any organization, you will still run into issues of power and control! Plus it&#8217;s still early days for resolution of regulatory issues and compliance around the cloud.</p>
<p><strong>Final Thoughts</strong></p>
<p><strong>AP:</strong> Think of the opportunities of using cloud computing resources in the areas of testing and pre-production &#8211; short-term use/environment (quick up/quick down), inexpensive, opex not capex. We&#8217;re already seeing the cloud fostering much innovation.</p>
<p><strong>WF:</strong> &#8220;It&#8217;s okay to fall in love with the term.&#8221; It is real but keep the expectations lower and realistic.</p>
<p><strong>AP:</strong> I agree with you. The reality is that the cloud is driving a very fundamental underlying platform change. This is not just a term or something that will fall out of fashion. There&#8217;s a real need to build trust in the cloud and leveraging shared resources in this way &#8211; so use the cloud computing term cautiously; don&#8217;t abuse it and make the cloud seem like IT&#8217;s new toy.</p>
]]></content:encoded>
      <pubDate>Wed, 12 Nov 2008 18:35:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/public cloud">public cloud</category>
      <category domain="http://securityratty.com/tag/cloud providers">cloud providers</category>
      <category domain="http://securityratty.com/tag/cloud abstracts users">cloud abstracts users</category>
      <category domain="http://securityratty.com/tag/privateinternal cloud">privateinternal cloud</category>
      <category domain="http://securityratty.com/tag/internal cloud">internal cloud</category>
      <category domain="http://securityratty.com/tag/term">term</category>
      <category domain="http://securityratty.com/tag/pre-production short-term useenvironment">pre-production short-term useenvironment</category>
      <category domain="http://securityratty.com/tag/short-term">short-term</category>
      <source url="http://blog.sciencelogic.com/hosting-meets-the-cloud-debate-part-ii/11/2008">Hosting Meets the Cloud Debate Part II</source>
    </item>
    <item>
      <title><![CDATA[On Security & Risk Management Innovation]]></title>
      <link>http://securityratty.com/article/044cbc91b90e3bcf8694d48ef0276511</link>
      <guid>http://securityratty.com/article/044cbc91b90e3bcf8694d48ef0276511</guid>
      <description><![CDATA[Pre-Script - It should be noted that the outcome of this discussion - in the last paragraph - is one smart way you can approach the We need to reduce your budget discussion (if that discussion hasnt...]]></description>
      <content:encoded><![CDATA[<p><span style="color: #666699;"><em>Pre-Script - It should be noted that the outcome of this discussion - in the last paragraph - is one smart way you can approach the “We need to reduce your budget” discussion (if that discussion hasn’t come already).</em></span></p>
<p>I’ve often read people who say that we (security, risk management) need to “think like the attacker”.  And when you read this sort of article, that usually alludes to trying to anticipate the tactics an attacker might use to mess with your C, I, or A.  Smart stuff, that, and very useful when architecting security solutions.  But as I was training some folks Monday, I was thinking in the back of my head about Threat Capability (TCap) in FAIR.  As you might know, we like to estimate the capability of a threat to apply some level of “force” against our assets.  This ability to apply force is a byproduct of the attacker&#8217;s skills and resources.  And thinking of how an attacker applies skills and resources, I came across another way we might “think” like an attacker.</p>
<p>Traditionally, I’ve thought of “skills” as being a byproduct of the toolset an attacker has.  This mindset probably stems from my time with Penetration Testing teams, where in the process of scoping the  PenTest I would ask our clients to select the level of effort that they wanted us to throw at them.  If a client chose “high” we’d throw every ‘spoit we had at them.  If they chose “low” we’d limit ourselves to a more commonly available toolset.</p>
<p>But while the resources part of TCap is time &amp; materials (money) - the skills are really more than just the toolset.  Skills would include the ability of the attacker to be creative and innovative.    As an example of that innovation from those PenTesting days - when we got a “high” effort request, we would always try to couple that with some “social engineering”-type of attack, or some unique means of delivering an existing exploit.  Our creativity was not necessarily a byproduct of a unique exploit or tool we had, but the process by which we might deliver pre-existing or commonly available exploits.  I remember when we first got ahold of a handful of 32mb thumb drives (hey, 32mb was <em>huge</em> back then) and &#8220;dropped&#8221; a few in the lobby of a client&#8217;s retail space.  The keystroke loggers and phone-home script weren&#8217;t new, but using the thumb drive as delivery vehicle certainly was.</p>
<p>So I’ve started to really think about this concept of innovation, and how if “thinking like an attacker” means to be innovative, we ought to do the same.  I’ve been thinking of two main categories of innovation this morning.</p>
<p><strong>INNOVATION</strong></p>
<p>The first I’ll call <em><strong>Technology Innovation</strong></em>.  And by Technology Innovation, I mean some new, unique, “ahead of the curve” technology that an attacker can use against us.  The obvious example of which is a zero-day.  It’s that “high” tool set our PenTesters would use against the clients.  For security departments, this might be the latest security product designed to enhance our ability to P, D, and/or R.</p>
<p>Alternately, we can be creative in the way we deliver (manage) existing technology.  I think of this as<strong> Process Innovation</strong>.  It’s doing more with what we already have, just like the PenTest team would be creative in the delivery of an existing exploit.</p>
<p>Unfortunately for us - attackers have traditionally had quite a leg up on us in terms of Process Innovation.  It is much easier fro them to be creative, as they are free of political constraints and bureaucracy.  In contrast, when the security industry tries Process Innovation, the results are checklists and “standards”.  It’s committees and consensus.  An extreme example of which might be something like SABSA - a great work if you want to understand some very smart people’s comprehensive understanding of organizational security  - but the “adoption”of which will do very little to help you be innovative in P/D/R.</p>
<p>It’s worth noting that ultimately, this is one reason <strong>I don’t like regulatory compliance efforts</strong> - <strong>they simply serve to prove how mundane your security department is</strong>,  wasting valuable resources that could be spent on creating ways to be more effective.</p>
<p><strong>PROCESS INNOVATION AS A SUBSTITUTE FOR TECHNOLOGY INNOVATION</strong></p>
<p>As we come to the close of 2009, some surveys suggest that security spending isn’t horribly impacted yet by the economy (the latest from E&amp;Y points to only 5% of their respondents getting budget cuts).  But if this is a protracted downturn, and because InfoSec is an operational expense, I would expect cash to become more and more difficult to keep.  And regardless if technology spends do slow, I believe it makes sense to think about Process Innovation because I see Process Innovation as a means to increase effectiveness without significant capital expenditures (effectiveness increases because our ability to manage risk has a direct correlation to the amount of risk we have).</p>
<p>The bad news is, of course, that great innovation is hard.  It is R &amp; D.  Failure is usually a pre-requisite to success.</p>
<p>The good news is, our current state is so bad that many of us don’t need to come up with a whizbang new way of reducing software defects in the SDLC as innovation.  Simply inserting a risk analyst into the PMO’s processes might count as a big enough victory. Be cautioned, though,  that if we’re substituting the risk reductions provided by technology acquisition - Process Innovation might actually be even more &#8220;expensive&#8221; as it requires us to expend political capital.   But there are (forgive the term) innovative ways to spend this political capital.</p>
<p>For example, by taking a second now and figuring out the 3 things that the rest of the organization can do to make your life easier, when that “I need to reduce your budget” talk comes, you can be prepared to negotiate.  Get a political capital &#8220;loan&#8221; or &#8220;investment&#8221; from the C-Suite reducing your budget.  Something to the effect of: “I expected this, and am happy to give up my budget.  But if our tolerance for risk hasn’t changed, what I’d like to do is get you to personally back my office on three projects I’ve identified that can reduce our risk without requiring significant capital expenditure.”</p>
]]></content:encoded>
      <pubDate>Wed, 12 Nov 2008 11:23:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/innovation">innovation</category>
      <category domain="http://securityratty.com/tag/process">process</category>
      <category domain="http://securityratty.com/tag/process innovation">process innovation</category>
      <category domain="http://securityratty.com/tag/call technology innovation">call technology innovation</category>
      <category domain="http://securityratty.com/tag/technology innovation">technology innovation</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/risk management">risk management</category>
      <category domain="http://securityratty.com/tag/attackers skills">attackers skills</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=516">On Security &amp; Risk Management Innovation</source>
    </item>
    <item>
      <title><![CDATA[Zeus Crimeware Kit Gets a Carding Layout]]></title>
      <link>http://securityratty.com/article/2dadca90df89c26f3f517a1e2b237afd</link>
      <guid>http://securityratty.com/article/2dadca90df89c26f3f517a1e2b237afd</guid>
      <description><![CDATA[With cybercriminals clearly expressing their nostalgia for several notorious and already shut down credit card fraud communities, they seem to have found a way to once again give their self-esteem a...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SRgXkf4easI/AAAAAAAACbU/eTHcGM--Oww/s1600-h/zeus_new_layout_22.GIF" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SRgXkf4easI/AAAAAAAACbU/eTHcGM--Oww/s200/zeus_new_layout_22.GIF" /></a>With cybercriminals clearly expressing their nostalgia for several notorious and already shut down credit card fraud communities, they seem to have found a way to once again give their self-esteem a boost. Following the <a href="http://ddanchev.blogspot.com/2008/11/modified-zeus-crimeware-kit-gets.html">ongoing modification</a> of open source <a href="http://ddanchev.blogspot.com/2008/09/modified-zeus-crimeware-kit-comes-with.html">crimeware kits</a> and the inevitable innovation introduced <a href="http://ddanchev.blogspot.com/2008/06/zeus-crimeware-kit-vulnerable-to.html">by third parties</a>, last week a new layout was introduced for Zeus, once again courtesy of a group that's piggybacking on Zeus popularity.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div>It's particularly interesting to see how a one-man operation evolves into a group of third-party developers starting to claim ownership rights over the modified versions despite that they're basically brandjacking the Zeus brand and building business models on the top of it.<br />
<br />
<a href="http://2.bp.blogspot.com/_wICHhTiQmrA/SRgZzIlf-eI/AAAAAAAACbc/YsBowySVmSk/s1600-h/zeus_new_layout_11.GIF" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/SRgZzIlf-eI/AAAAAAAACbc/YsBowySVmSk/s200/zeus_new_layout_11.GIF" /></a>Open source crimeware and web malware exploitation kits on the other hand undermine the business model of a great number of "<a href="http://ddanchev.blogspot.com/2008/07/coding-spyware-and-malware-for-hire.html">malware/spyware for hire</a>" vendors, which surprisingly doesn't stop them from continuing offering their services and products which are often using the de facto crimeware kits as the foundations for their propositions. Are the buyers even aware of this fact? From a buyer's perspective in times when most of the output is sold in bulk form, or access to the botnet rented for a specific period of time, the buyer doesn't care about the cybercrime platform of use, but is looking for transparent ways to justify the investment he's made into renting the service.<br />
<br />
Now that Zeus administrators and their cybercrime clerks in the face of those managing the campaigns knowingly or unknowingly knowing the type of campaigns and the data that they manage, can <a href="http://ddanchev.blogspot.com/2008/09/modified-zeus-crimeware-kit-comes-with.html">listen to their favorite music within Zeus</a> and choose different layouts for the command and control interfaces while commiting cybercrime, what's next?<br />
<br />
<a href="http://ddanchev.blogspot.com/2008/08/web-based-botnet-command-and-control.html">Convergence</a> and improved monetization.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=fQb6N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=fQb6N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Rhj0N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Rhj0N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=9MADn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=9MADn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Kqtmn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Kqtmn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=Cqo2N"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=Cqo2N" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=pkhEN"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=pkhEN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=i9tYn"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=i9tYn" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/448333234" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 10 Nov 2008 02:53:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/zeus">zeus</category>
      <category domain="http://securityratty.com/tag/zeus administrators">zeus administrators</category>
      <category domain="http://securityratty.com/tag/zeus popularity">zeus popularity</category>
      <category domain="http://securityratty.com/tag/source crimeware kits">source crimeware kits</category>
      <category domain="http://securityratty.com/tag/cybercrime">cybercrime</category>
      <category domain="http://securityratty.com/tag/cybercrime clerks">cybercrime clerks</category>
      <category domain="http://securityratty.com/tag/source crimeware">source crimeware</category>
      <category domain="http://securityratty.com/tag/zeus brand">zeus brand</category>
      <category domain="http://securityratty.com/tag/cybercrime platform">cybercrime platform</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/448333234/zeus-crimeware-kit-gets-carding-layout.html">Zeus Crimeware Kit Gets a Carding Layout</source>
    </item>
    <item>
      <title><![CDATA[Great advice form the Trend Micro site]]></title>
      <link>http://securityratty.com/article/144d065accb5aaa5a0686af5ccc083e2</link>
      <guid>http://securityratty.com/article/144d065accb5aaa5a0686af5ccc083e2</guid>
      <description><![CDATA[Clickjacking is a very real threat and I believe it will become more pronounced in the future. It would be well for you to educate yourselves in its dangers


clipped from newsletters.trendmicro.com
...]]></description>
      <content:encoded><![CDATA[<div > Clickjacking is a very real threat and I believe it will become more pronounced in the future.<br/>It would be well for you to educate yourselves in its dangers. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/90299BB8-A716-4448-A8AD-314482964239/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/053b7efe-9688-4086-8537-53ad92391c51/90299BB8-A716-4448-A8AD-314482964239/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://newsletters.trendmicro.com/servlet/website/ResponseForm?mgLEVTTB_UUTA_.40ev.2e_0okLHm_9RILkJkptL_0kLgK" href="http://newsletters.trendmicro.com/servlet/website/ResponseForm?mgLEVTTB_UUTA_.40ev.2e_0okLHm_9RILkJkptL_0kLgK" style="font-size: 11px;">newsletters.trendmicro.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://newsletters.trendmicro.com/servlet/website/ResponseForm?mgLEVTTB_UUTA_.40ev.2e_0okLHm_9RILkJkptL_0kLgK --><br />
<table background="undefined" bgcolor="">
<tr><TD bgcolor="#f3f3f3" valign="top" colspan="2">Threat and Cybercrime Trends: Click or Treat</TD></tr>
</table>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://newsletters.trendmicro.com/servlet/website/ResponseForm?mgLEVTTB_UUTA_.40ev.2e_0okLHm_9RILkJkptL_0kLgK --><DIV>Halloween may be over, but unfortunately, every click includes a trick when you get clickjacked. Clickjacking is a scary, new security threat similar to cross-site scripting—an attack that dates back to the 1990s?. The threat occurs when hackers and scammers hide malicious content under the guise of legitimate Web pages—in essence stealing your mouse click. Hackers can use iFRAMES or malicious JavaScript to load this content from a third-party site using any browser. And clickjacking uses any type of link—from image links in the form of buttons to text links. Unfortunately, you do not even know when you land on a hijacked page.</DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/90299BB8-A716-4448-A8AD-314482964239/blog/" title="blog or email this clip"><img src="http://content6.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_091108031903"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=091108031903&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=091108031903&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=091108031903&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_091108031903" /></a></P>]]></content:encoded>
      <pubDate>Sun, 09 Nov 2008 12:19:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/threat">threat</category>
      <category domain="http://securityratty.com/tag/security threat similar">security threat similar</category>
      <category domain="http://securityratty.com/tag/threat occurs">threat occurs</category>
      <category domain="http://securityratty.com/tag/click includes">click includes</category>
      <category domain="http://securityratty.com/tag/click">click</category>
      <category domain="http://securityratty.com/tag/linkfrom image links">linkfrom image links</category>
      <category domain="http://securityratty.com/tag/real threat">real threat</category>
      <category domain="http://securityratty.com/tag/web pagesin essence">web pagesin essence</category>
      <category domain="http://securityratty.com/tag/mouse click">mouse click</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=651">Great advice form the Trend Micro site</source>
    </item>
    <item>
      <title><![CDATA[VC and IPO Outlook]]></title>
      <link>http://securityratty.com/article/33a99f11764689af12c7674da3dc0464</link>
      <guid>http://securityratty.com/article/33a99f11764689af12c7674da3dc0464</guid>
      <description><![CDATA[Forbes interviews venture capitalist Charlie Harris. He is the Chairman of Harris and Harris (NASDAQ: TINY ) a venture capital fund which is focused on funding nanotech companies. He is bullish...]]></description>
      <content:encoded><![CDATA[<p>Forbes <a href="http://www.forbes.com/video/?video=fvn/wolf/jw_harris110508">interviews</a> venture capitalist Charlie Harris. He is the Chairman of <a href="http://tinytechvc.com/">Harris and Harris</a>&#0160;(NASDAQ:<a href="http://finance.google.com/finance?q=tiny">TINY</a>) a venture capital fund which is focused on funding nanotech companies. He is bullish looking forward from today for a couple of reasons</p><br /><div>1. We have an eight year back log of good companies and ideas due to a poor IPO environment, we have had an eight year drought in IPOs but still lots of good ideas out there.</div><br /><div>2. Clean tech theme has a lot of room left to grow</div><br /><div>3. The recent financial crisis has revealed and removed a lot of risks</div><br /><div>4. The best businesses are started in times of economic distress. Dislocation equals opportunity. Companies that start during financial distress have tremendous discipline to survive.</div><br /><div>Somewhat surprisingly for a person with 100% of his fund invested in nanotech, he does not see nanotech as the leader of a next IPO bookm. He seems to see nanotech as an enabling technology (my words not his) so you will see nanotech enabling clean fuel, cancer drugs and so on, and these individual spaces could boom, but not an &quot;all things nanotech&quot; type boom.</div>]]></content:encoded>
      <pubDate>Fri, 07 Nov 2008 06:07:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nanotech companies">nanotech companies</category>
      <category domain="http://securityratty.com/tag/companies">companies</category>
      <category domain="http://securityratty.com/tag/nanotech">nanotech</category>
      <category domain="http://securityratty.com/tag/fund">fund</category>
      <category domain="http://securityratty.com/tag/venture capital fund">venture capital fund</category>
      <category domain="http://securityratty.com/tag/poor ipo environment">poor ipo environment</category>
      <category domain="http://securityratty.com/tag/dislocation equals opportunity">dislocation equals opportunity</category>
      <category domain="http://securityratty.com/tag/clean tech theme">clean tech theme</category>
      <category domain="http://securityratty.com/tag/recent financial crisis">recent financial crisis</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/11/vc-and-ipo-outlook.html">VC and IPO Outlook</source>
    </item>
  </channel>
</rss>
