<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: vandalism]]></title>
    <link>http://securityratty.com/tag/vandalism</link>
    <description></description>
    <pubDate>Sun, 23 Dec 2007 12:28:23 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Terrorist Fear Mongering Seems to be Working Less Well, Part II]]></title>
      <link>http://securityratty.com/article/6f8cdae72a681b69b75eeee5bb6fec7e</link>
      <guid>http://securityratty.com/article/6f8cdae72a681b69b75eeee5bb6fec7e</guid>
      <description><![CDATA[Last week I wrote about a story that indicated that terrorist fear mongering is working less well. Here's another story, this one from Canada: two pipeline bombings in Northern British Columbia:...]]></description>
      <content:encoded><![CDATA[<p>Last week <a href="http://www.schneier.com/blog/archives/2008/10/terrorist_fear.html">I wrote about a story</a> that indicated that terrorist fear mongering is working less well.  <a href="http://www.cbc.ca/canada/british-columbia/story/2008/10/16/bc-second-pipeline-explosion-dawson-creek.html">Here's</a> another story, this one from Canada: two pipeline bombings in Northern British Columbia:</p>

<blockquote>Investigators are treating the explosions as acts of vandalism, not terrorism, Shields said.

<p>"Under the Criminal Code, it would be characterized as mischief, which is an intentional vandalism. We don't want to characterize this as terrorism. They were very isolated locations and there would seem there was no intent to hurt people," he said.</blockquote></p>

<p>It's not all good, though.  <a href="http://www.philly.com/inquirer/local/pa/chester/20081017_SEPTA_engineers_dislike_new_cars__cabs.html">Here's</a> a story from Philadelphia, where a subway car is criticized because people can see out the front.  Because, um, because terrorist will be able to see out the front, and we all know how dangerous terrorists are:</p>

<blockquote>Marcus Ruef, a national vice president with the Brotherhood of Locomotive Engineers and Trainmen, compared a train cab to an airliner cockpit and said a cab should be similarly secure. He invoked post-9/11 security concerns as a reason to provide a full cab that prevents passengers from seeing the rails and signals ahead.

<p>"We don't think the forward view of the right-of-way should be available to whoever wants to watch ... and the conductor and the engineer should be able to talk privately," Ruef said.</p>

<p>Pat Nowakowski, SEPTA chief of operations, said the smaller cabs pose no security risk. "I have never heard that from a security expert," he said.</blockquote></p>

<p>At least there was pushback against that kind of idiocy.</p>

<p>And from the <a href="http://news.bbc.co.uk/1/hi/uk_politics/7674775.stm">UK</a>:</p>

<blockquote>Transport Secretary Geoff Hoon has said the government is prepared to go "quite a long way" with civil liberties to "stop terrorists killing people".

<p>He was responding to criticism of plans for a database of mobile and web records, saying it was needed because terrorists used such communications.</p>

<p>By not monitoring this traffic, it would be "giving a licence to terrorists to kill people", he said.</blockquote></p>

<p>I hope there will be similar pushback against this "choice."</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=Acn8M"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=Acn8M" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=gnuoM"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=gnuoM" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 22 Oct 2008 02:44:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/terrorist">terrorist</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/terrorist fear">terrorist fear</category>
      <category domain="http://securityratty.com/tag/dangerous terrorists">dangerous terrorists</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/kill people">kill people</category>
      <category domain="http://securityratty.com/tag/cab">cab</category>
      <category domain="http://securityratty.com/tag/stop terrorists">stop terrorists</category>
      <category domain="http://securityratty.com/tag/train cab">train cab</category>
      <source url="http://www.schneier.com/blog/archives/2008/10/terrorist_fear_1.html">Terrorist Fear Mongering Seems to be Working Less Well, Part II</source>
    </item>
    <item>
      <title><![CDATA[Turning off Fire Hydrants in the Name of Terrorism]]></title>
      <link>http://securityratty.com/article/f6930719122f72be0df5cd2f10adaea5</link>
      <guid>http://securityratty.com/article/f6930719122f72be0df5cd2f10adaea5</guid>
      <description><![CDATA[This really pegs the stupid meter: He explains all the district's hydrants, including those in Alexander Ranch, have had their water turned off since just after 9/11 -- something a trade association...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.wfaa.com/sharedcontent/dws/wfaa/latestnews/stories/wfaa080827_lj_hawes.1983f2d0.html">This</a> really pegs the stupid meter:</p>

<blockquote>He explains all the district's hydrants, including those in Alexander Ranch, have had their water turned off since just after 9/11 -- something a trade association spokesman tells us is common practice for rural systems.

<p>"These hydrants need to be cut off in a way to prevent vandalism or any kind of terrorist activity, including something in the water lines," Hodges said.</p>

<p>But Hodges says fire departments know, or should have known, the water valves can be turned back on with a tool.</blockquote></p>

<p>One, fires are much more common than terrorism -- keeping fire hydrants on makes much more sense than turning them off.  Two, what sort of terrorism is possible using working fire hydrants?  Three, if the water valves can be "turned back on with a tool," how does turning them off prevent fire-hydrant-related terrorism?</p>

<p>More and more, it seems as if public officials in this country have simply gone insane.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=65IeL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=65IeL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=A1h0L"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=A1h0L" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 11 Sep 2008 09:59:42 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hydrants">hydrants</category>
      <category domain="http://securityratty.com/tag/fire hydrants">fire hydrants</category>
      <category domain="http://securityratty.com/tag/water valves">water valves</category>
      <category domain="http://securityratty.com/tag/water">water</category>
      <category domain="http://securityratty.com/tag/terrorism">terrorism</category>
      <category domain="http://securityratty.com/tag/water lines">water lines</category>
      <category domain="http://securityratty.com/tag/prevent">prevent</category>
      <category domain="http://securityratty.com/tag/common">common</category>
      <category domain="http://securityratty.com/tag/prevent vandalism">prevent vandalism</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/turning_off_fir.html">Turning off Fire Hydrants in the Name of Terrorism</source>
    </item>
    <item>
      <title><![CDATA[How I became a soldier in the Georgia-Russia cyberwar.]]></title>
      <link>http://securityratty.com/article/cb0690279b2cb6030191ba8c0c9a09d8</link>
      <guid>http://securityratty.com/article/cb0690279b2cb6030191ba8c0c9a09d8</guid>
      <description><![CDATA[As Russian and Georgian troops fight on the ground, there's a parallel war happening in cyberspace. In recent weeks, Georgia's government Web sites have been besieged by denial-of-service attacks and...]]></description>
      <content:encoded><![CDATA[As Russian and Georgian troops fight on the ground, there's a parallel war happening in cyberspace. In recent weeks, Georgia's government Web sites have been besieged by denial-of-service attacks and acts of vandalism. Just like in traditional warfare, there's a lot of confusion about what's going on in this technological battle—nobody seems to kno]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 04:20:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/georgian troops fight">georgian troops fight</category>
      <category domain="http://securityratty.com/tag/government web sites">government web sites</category>
      <category domain="http://securityratty.com/tag/traditional warfare">traditional warfare</category>
      <category domain="http://securityratty.com/tag/parallel war">parallel war</category>
      <category domain="http://securityratty.com/tag/technological battlenobody">technological battlenobody</category>
      <category domain="http://securityratty.com/tag/recent weeks">recent weeks</category>
      <category domain="http://securityratty.com/tag/georgia">georgia</category>
      <category domain="http://securityratty.com/tag/cyberspace">cyberspace</category>
      <category domain="http://securityratty.com/tag/lot">lot</category>
      <source url="http://digg.com/security/How_I_became_a_soldier_in_the_Georgia_Russia_cyberwar">How I became a soldier in the Georgia-Russia cyberwar.</source>
    </item>
    <item>
      <title><![CDATA[Think "liability" if you want to stay out of trouble.]]></title>
      <link>http://securityratty.com/article/d9485be5d4b45a749942f44d816889ae</link>
      <guid>http://securityratty.com/article/d9485be5d4b45a749942f44d816889ae</guid>
      <description><![CDATA[I speak a lot about liability, but not everyone gets it

I have seen medical doctors, dentists, business people of all walks of life and lawyers (it is surprising how many lawyers disregard...]]></description>
      <content:encoded><![CDATA[I speak a lot about liability, but not everyone gets it.<br /><span id="fullpost"><br />I have seen medical doctors, dentists, business people of all walks of life and lawyers (it is surprising how many lawyers disregard liability)pay little attention to potential lawsuits.  The latest category to leave themselves open, have been auctioneers. <br /></span><br />The current foreclosure crisis has meant that many properties are being auctioned off.  We have been providing security officers at some of the properties in order to make sure that people do not try to steal or commit vandalism when viewing the houses.  There was an incident recently in which a bidder decided to withdraw his offer after his bid became the winning bid.  He probaly got cold feet.<br /><br />While he should not have reneged on his offer to buy the property, it was a civil matter best left to civil remedy.  Unfortunately, the auctioneers involved decided to take the law into their own hands and would not let the man leave the property.  The man became anxious and informed them that he was having difficulty breathing and needed to go to his car for his asthma medication.  <br /><br />Was this true?  Maybe, maybe not - but would it be wise to gamble with a person's health when you already had their personal details and you could easily have obtained his vehicle registration if he decided to leave?<br />Thankfully, our security officer knew better that to get involved with blocking the man's way.  The auctioneers stood in front of his vehicle and yelled at him.  Eventually the man drove off.     <br /><br />If you represent a financial institution, a law firm or an auctioneering firm, you need to think twice before you act inappropriately.  I have no doubt that had that man had a serious attack and if he died as a result, his next of kin would have sued for umpteen millions.  When it comes to situations like this, you need to think rationally and realize what is involved.  What was the worse thing that could have happened when the person decided to renege on his offer?  <br /><br />Apparently, he would have signed forms and the like and most probably he could be sued civilly for not fulfilling his obligations after delivering the winning bid.  At the end of the day, the note holder would be in a strong position.  Even if the person had given false information and could not be subsequently located, all they had to do was to put the property back on the market.  What could that have cost, a couple of thousand in extra advertising and the like?  That would have been much better than having to pay the next of kin many millions - not to mention the bad publicity.<br /><br />We talk a lot about liability because it is a very real threat.  Think "threat mitigation".  Those who do not, may pay a very high price.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Sun, 03 Aug 2008 21:12:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/liability">liability</category>
      <category domain="http://securityratty.com/tag/lawyers disregard liability">lawyers disregard liability</category>
      <category domain="http://securityratty.com/tag/law firm">law firm</category>
      <category domain="http://securityratty.com/tag/auctioneers stood">auctioneers stood</category>
      <category domain="http://securityratty.com/tag/auctioneers">auctioneers</category>
      <category domain="http://securityratty.com/tag/law">law</category>
      <category domain="http://securityratty.com/tag/lawyers">lawyers</category>
      <category domain="http://securityratty.com/tag/property">property</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <source url="http://www.thebulletproofblog.com/2008/08/think-liability-if-you-want-to-stay-out.html">Think "liability" if you want to stay out of trouble.</source>
    </item>
    <item>
      <title><![CDATA[CATSA: XRay Machines Are Not For Gum Wrappers]]></title>
      <link>http://securityratty.com/article/56971d439bfed2c3e4bf5ae86ec6b28c</link>
      <guid>http://securityratty.com/article/56971d439bfed2c3e4bf5ae86ec6b28c</guid>
      <description><![CDATA[Well, the US may have the TSA in all of its glory. Here in Canada however, we have the Canadian Air Transport Security Authority (CATSA) and theyre pissed at airport screeners in this country
From The...]]></description>
      <content:encoded><![CDATA[<p>Well, the US may have the TSA in all of its glory. Here in Canada however, we have the Canadian Air Transport Security Authority (CATSA) and they&#8217;re pissed at airport screeners in this country. </p>
<p>From The Canadian Press:</p>
<blockquote><p>&#8220;Continued inspections across the country have revealed that garbage and other items &#8230; are still being dropped inside the top panel openings of some X-ray machines,&#8221; says a bulletin issued earlier this year by the Canadian Air Transport Security Authority.</p>
<p>&#8220;Likewise, warning labels and hazard warning signs are being damaged and are sometimes completely removed from the units.&#8221;</p>
<p>The rebuke, obtained under the Access to Information Act, is the second time officers have been warned about dropping junk into the X-ray scanners. An earlier bulletin in August 2006 raised the same issue.</p>
<p>&#8220;Effective immediately, screening personnel caught performing any above-listed act, or similar act of vandalism to CATSA equipment will be immediately restricted from performing all screening functions.&#8221;</p>
<p>Any offending officer could be permanently removed from the job, the document says.</p></blockquote>
<p>Next time you fly via a Canadian airport see if the screeners can toss out an empty coffee cup or wrapper for ya. Just for giggles.</p>
<p><a href="http://canadianpress.google.com/article/ALeqM5juFuoRo-uneme4Kw1dVVvVkJyMJg">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=PJvZjM"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=PJvZjM" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=kaUAaI"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=kaUAaI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=nJyt9i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=nJyt9i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=TlUq4i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=TlUq4i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=Ku9gHi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=Ku9gHi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=iYdN1i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=iYdN1i" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/307342359" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 08 Jun 2008 08:58:43 +0000</pubDate>
      <category domain="http://securityratty.com/tag/catsa">catsa</category>
      <category domain="http://securityratty.com/tag/similar act">similar act</category>
      <category domain="http://securityratty.com/tag/act">act</category>
      <category domain="http://securityratty.com/tag/screeners">screeners</category>
      <category domain="http://securityratty.com/tag/airport screeners">airport screeners</category>
      <category domain="http://securityratty.com/tag/time officers">time officers</category>
      <category domain="http://securityratty.com/tag/empty coffee cup">empty coffee cup</category>
      <category domain="http://securityratty.com/tag/top panel openings">top panel openings</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/307342359/">CATSA: XRay Machines Are Not For Gum Wrappers</source>
    </item>
    <item>
      <title><![CDATA[The Top Ten Cybersecurity Threats for 2008]]></title>
      <link>http://securityratty.com/article/b43db5d914623d8f344e300df3791a50</link>
      <guid>http://securityratty.com/article/b43db5d914623d8f344e300df3791a50</guid>
      <description><![CDATA[Here is the final list of the top ten cybersecurity threats for 2008
On-line masquerading to abuse, attack, blackmail, bully, extort, or molest others
Criminal fraud by password and identity theft via...]]></description>
      <content:encoded><![CDATA[<div class='snap_preview'><br /><p>Here is the final list of the top ten cybersecurity threats for 2008:</p>
<p>— On-line masquerading to abuse, attack, blackmail, bully, extort, or molest others.</p>
<p>— Criminal fraud by password and identity theft via phishing, spyware, malware and theft of hardware.</p>
<p>— Criminal use of botnets and botnet-like technologies for economic gain, for example email spam and denial of service attacks.</p>
<p>— Cyberterrorism, bulling, vandalism and other forms of electronic violence and malfeasance.</p>
<p>— Subversion of democratic political processes.</p>
<p>— Criminal manipulation and subversion of financial markets.</p>
<p>— Spying and theft of data by governments, industry, terrorists and other criminals.</p>
<p>— Denial-of-service attacks by criminals and terrorists.</p>
<p>— Sabotage, theft and other attacks by disgruntled employees and insiders.</p>
<p>— Natural disasters, accidents or errors without malicious intent.</p>
<p><span style="font-family:Georgia;"></span></p>
<p><span style="font-family:Georgia;">Acknowledgements and References</span></p>
<p><span style="font-family:Georgia;">A special word of appreciation for the reviews, comments and suggestions from the <a href="http://www.isc2.org">Certified Information Systems and Security Professionals</a> (CISSPs) community and the <a target="_blank" href="http://www.linkedin.com">LinkedIn</a> professional network.</span></p>
<p><span style="font-family:Georgia;"></span><span style="font-family:Georgia;">In particular, comments and suggestions from Gary Hinson, Bill Marlow, Eugene Schultz, Mike Smith, Lea Viljanen, and Alex Voytov were used to refine and improve the list.  Thank you.</span></p>
<p><span style="font-family:Georgia;">This project was motivated by my friend and colleague in Thailand, Dr. Prinya Hom-anek.</span></p>
<p><span style="font-family:Georgia;">An on-line Google spreadsheet of the comments on <a rel="bookmark" href="http://thecepblog.com/2007/12/06/the-top-ten-cybersecurity-threats-for-2008-final-draft/" title="The Top Ten Cybersecurity Threats for 2008 - Final Draft">The Top Ten Cybersecurity Threats for 2008 - Final Draft</a> and my resolution of the comments can be found <a target="_blank" href="http://spreadsheets.google.com/pub?key=pmBkoe87yC4LszWNkx0csGw">here.</a></span></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/eventprocessing.wordpress.com/161/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/eventprocessing.wordpress.com/161/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/eventprocessing.wordpress.com/161/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/eventprocessing.wordpress.com/161/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/eventprocessing.wordpress.com/161/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/eventprocessing.wordpress.com/161/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/eventprocessing.wordpress.com/161/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/eventprocessing.wordpress.com/161/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/eventprocessing.wordpress.com/161/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/eventprocessing.wordpress.com/161/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/eventprocessing.wordpress.com/161/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/eventprocessing.wordpress.com/161/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thecepblog.com&blog=1100533&post=161&subd=eventprocessing&ref=&feed=1" /></div>]]></content:encoded>
      <pubDate>Sat, 05 Jan 2008 14:22:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cybersecurity threats">cybersecurity threats</category>
      <category domain="http://securityratty.com/tag/theft">theft</category>
      <category domain="http://securityratty.com/tag/criminal">criminal</category>
      <category domain="http://securityratty.com/tag/criminal manipulation">criminal manipulation</category>
      <category domain="http://securityratty.com/tag/identity theft">identity theft</category>
      <category domain="http://securityratty.com/tag/top">top</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/comments">comments</category>
      <category domain="http://securityratty.com/tag/service attacks">service attacks</category>
      <source url="http://thecepblog.com/2008/01/05/the-top-ten-cybersecurity-threats-for-2008/">The Top Ten Cybersecurity Threats for 2008</source>
    </item>
    <item>
      <title><![CDATA[DHS f*cking up Wikipedia]]></title>
      <link>http://securityratty.com/article/e04cfa38ef1aa86f46164486b7cfa70c</link>
      <guid>http://securityratty.com/article/e04cfa38ef1aa86f46164486b7cfa70c</guid>
      <description><![CDATA[This host, n021.dhs.gov, is registered to the United States Department of Homeland Security, and may be shared by multiple users.&quot;....&quot;Please stop adding nonsense to Wikipedia. It is considered...]]></description>
      <content:encoded><![CDATA["This host, n021.dhs.gov, is registered to the United States Department of Homeland Security, and may be shared by multiple users."...."Please stop adding nonsense to Wikipedia. It is considered vandalism."]]></content:encoded>
      <pubDate>Sun, 23 Dec 2007 12:28:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wikipedia">wikipedia</category>
      <category domain="http://securityratty.com/tag/homeland security">homeland security</category>
      <category domain="http://securityratty.com/tag/dhs">dhs</category>
      <category domain="http://securityratty.com/tag/multiple users">multiple users</category>
      <category domain="http://securityratty.com/tag/department">department</category>
      <category domain="http://securityratty.com/tag/stop">stop</category>
      <category domain="http://securityratty.com/tag/vandalism">vandalism</category>
      <category domain="http://securityratty.com/tag/gov">gov</category>
      <category domain="http://securityratty.com/tag/host">host</category>
      <source url="http://digg.com/security/DHS_f_cking_up_Wikipedia">DHS f*cking up Wikipedia</source>
    </item>
  </channel>
</rss>
