<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: world-wide]]></title>
    <link>http://securityratty.com/tag/world-wide</link>
    <description></description>
    <pubDate>Fri, 15 Aug 2008 02:50:02 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Boston Court's Meddling With 'Full Disclosure' Is Unwelcome]]></title>
      <link>http://securityratty.com/article/b65bde3bbcffdced12efa1287ce8e1e0</link>
      <guid>http://securityratty.com/article/b65bde3bbcffdced12efa1287ce8e1e0</guid>
      <description><![CDATA[In eerily similar cases in the Netherlands and the United States, courts have recently grappled with the computer-security norm of &quot;full disclosure,&quot; asking whether researchers should be permitted to...]]></description>
      <content:encoded><![CDATA[<p>
In eerily similar cases in the Netherlands and the United States, courts have recently grappled with the computer-security norm of "full disclosure," asking whether researchers should be permitted to disclose details of a fare-card vulnerability that allows people to ride the subway for free.
</p><p>
The "Oyster card" used on the <a href="http://www.schneier.com/essay-229.html">London Tube</a> was at issue in the Dutch case, and a similar fare card used on the <a href="http://blog.wired.com/27bstroke6/2008/08/injunction-requ.html">Boston "T"</a> was the center of the U.S. case. The Dutch court got it right, and the American court, in Boston, <a href="http://blog.wired.com/27bstroke6/2008/08/computer-scient.html ">got it wrong</a> from the start -- despite facing an open-and-shut case of First Amendment prior restraint.
</p><p>
The U.S. court has since <a href="http://blog.wired.com/27bstroke6/2008/08/federal-judge-t.html ">seen the error</a> of its ways -- but the damage is done. The MIT security researchers who were prepared to discuss their Boston findings at the DefCon security conference were <a href="http://blog.wired.com/27bstroke6/2008/08/eff-to-appeal-r.html ">prevented</a> from giving their talk.
</p><p>
The <a href="http://www.schneier.com/essay-146.html">ethics</a> of <a href="http://www.schneier.com/crypto-gram-0111.html#1">full disclosure</a> are intimately familiar to those of us in the computer-security field.  Before full disclosure became the norm, researchers would quietly disclose vulnerabilities to the vendors -- who would routinely ignore them. Sometimes vendors would even threaten researchers with legal action if they disclosed the vulnerabilities. 
</p><p>
Later on, researchers started disclosing the existence of a vulnerability but not the details.  Vendors responded by denying the security holes' existence, or calling them just theoretical.  It wasn't until full disclosure became the norm that vendors began consistently fixing vulnerabilities quickly.  Now that vendors routinely patch vulnerabilities, researchers generally give them advance notice to allow them to patch their systems before the vulnerability is published.  But even with this "responsible disclosure" protocol, it's the threat of disclosure that motivates them to patch their systems.  Full disclosure <a href="http://www.eff.org/files/filenode/MBTA_v_Anderson/letter081208.pdf">is the mechanism</a> (.pdf) by which computer security improves.
</p><p>
Outside of computer security, secrecy is much more the norm.  Some security communities, like locksmiths, behave much like medieval guilds, divulging the secrets of their profession only to those within it.  These communities <a href="http://news.cnet.com/8301-1009_3-10002138-83.html?tag=mncol">hate</a> <a href="http://www.slate.com/id/2195862/">open</a> <a href="http://www.theglobeandmail.com/servlet/story/RTGAM.20080711.wlpicking11/EmailBNStory/lifeMain/">research</a>, and have <a href="http://www.schneier.com/crypto-gram-0302.html#1">responded</a> with <a href="http://www.crypto.com/papers/kiss.html">surprising vitriol</a> to <a href="http://www.crypto.com/papers/flattery.html">researchers</a> who have found serious vulnerabilities in <a href="http://www.wired.com/culture/lifestyle/news/2004/09/64987">bicycle locks</a>, <a href="http://www.crypto.com/papers/safelocks.pdf">combination safes</a> (.pdf), <a href="http://www.crypto.com/masterkey.html">master-key systems</a> and <a href="http://blog.wired.com/27bstroke6/2008/08/medeco-locks-cr.html">many</a> other <a href="http://en.wikipedia.org/wiki/Lock_bumping">security devices</a>.  
</p><p>
Researchers have received a similar reaction from other communities more used to secrecy than openness.  Researchers -- sometimes <a href="http://compsci.ca/blog/lanschool-threatens-compscica-with-legal-actions/">young students</a> -- who discovered and published flaws in copyright-protection schemes, <a href="http://www.freedom-to-tinker.com/?p=1265">voting-machine security</a> and now wireless access cards have all suffered recriminations and sometimes lawsuits for not keeping the vulnerabilities secret.  When Christopher Soghoian created a website allowing people to print fake airline boarding passes, he got <a href="http://www.schneier.com/blog/archives/2006/11/forge_your_own.html">several unpleasant visits</a> from the FBI.
</p><p>
This preference for secrecy comes from confusing a vulnerability with information <em>about</em> that vulnerability.  Using <a href="http://www.schneier.com/crypto-gram-0205.html#1">secrecy as a security measure</a> is fundamentally fragile.  It assumes that the bad guys don't do their own security research.  It assumes that no one else will find the same vulnerability.  It assumes that information won't leak out even if the research results are suppressed.  These assumptions are all incorrect.
</p><p>
The problem isn't the researchers; it's the products themselves.  Companies will only design security as good as what their customers know to ask for.  Full disclosure helps customers evaluate the security of the products they buy, and educates them in how to ask for better security.  The Dutch court got it exactly right when it <a href="http://zoeken.rechtspraak.nl/resultpage.aspx?snelzoeken=true&searchtype=ljn&ljn=BD7578&u_ljn=BD7578">wrote</a>: "Damage to NXP is not the result of the publication of the article but of the production and sale of a chip that appears to have shortcomings."
</p><p>
In a world of forced secrecy, vendors make inflated claims about their products, vulnerabilities don't get fixed, and customers are no wiser.  Security research is stifled, and security technology doesn't improve.  The only beneficiaries are the bad guys.
</p><p>
If you'll forgive the analogy, the ethics of full disclosure parallel the ethics of not paying kidnapping ransoms.  We all know why we don't pay kidnappers: It encourages more kidnappings.  Yet in every kidnapping case, there's someone -- a spouse, a parent, an employer -- with a good reason why, in this one case, we should make an exception. 
</p><p>
The reason we want researchers to publish vulnerabilities is because that's how security improves. But in every case there's someone -- the Massachusetts Bay Transit Authority, the locksmiths, an election machine manufacturer -- who argues that, in this one case, we should make an exception.
</p><p>
We shouldn't.  The benefits of responsibly publishing attacks greatly outweigh the potential harm. Disclosure encourages companies to build security properly rather than relying on shoddy design and secrecy, and discourages them from promising security based on their ability to threaten researchers.  It's how we learn about security, and how we improve future security.
</p>
<p>---</p>

<p>
<em>Bruce Schneier is Chief Security Technology Officer of BT Global Services and author of </em><a href="http://www.schneier.com/bf.html">Beyond Fear: Thinking Sensibly About Security in an Uncertain World</a><em>. You can read more of his writings on his <a href="http://www.schneier.com/">website</a>.</em>
</p><br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=bca653e99d30d29fe90a724af1243458" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=bca653e99d30d29fe90a724af1243458" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=FBzLDK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=FBzLDK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=I2e1pk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=I2e1pk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=znpbtk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=znpbtk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=bR68YK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=bR68YK" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=AMJk5K"><img src="http://feeds.wired.com/~f/wired/politics/security?i=AMJk5K" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=ZF5tzk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=ZF5tzk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=iWkWjk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=iWkWjk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=f5xemK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=f5xemK" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/370586608" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/370586609" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 21 Aug 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/computer security improves">computer security improves</category>
      <category domain="http://securityratty.com/tag/security improves">security improves</category>
      <category domain="http://securityratty.com/tag/computer security">computer security</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/mit security researchers">mit security researchers</category>
      <category domain="http://securityratty.com/tag/security devices">security devices</category>
      <category domain="http://securityratty.com/tag/security holes">security holes</category>
      <category domain="http://securityratty.com/tag/disclosure">disclosure</category>
      <category domain="http://securityratty.com/tag/security properly">security properly</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/370586609/securitymatters_0821">Boston Court's Meddling With 'Full Disclosure' Is Unwelcome</source>
    </item>
    <item>
      <title><![CDATA[ScienceLogics 5-Year Anniversary]]></title>
      <link>http://securityratty.com/article/1287b8dac0ea60512bed5f303d15fe55</link>
      <guid>http://securityratty.com/article/1287b8dac0ea60512bed5f303d15fe55</guid>
      <description><![CDATA[August 2003. The largest blackout in U.S. history darkens the Northeast and Midwest, the Blaster worm has been unleashed and Madonna and Britney create a stir at the 2003 MTV Music Video Awards . In...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="164" alt="B-day Cake" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/b-day-cake1.jpg" width="244" align="left" border="0"> August 2003. The largest <a href="http://blogs.wsj.com/biztech/2008/08/13/celebrating-the-anniversary-of-the-big-blackout/?mod=djemTECH" target="_blank">blackout</a> in U.S. history darkens the Northeast and Midwest, the <a href="http://news.cnet.com/2010-1001-5117862.html" target="_blank">Blaster worm</a> has been unleashed and Madonna and Britney create a stir at the <a href="http://en.wikipedia.org/wiki/2003_MTV_Video_Music_Awards" target="_blank">2003 MTV Music Video Awards</a>. In the midst of this <a href="http://www.grid.unep.ch/product/publication/download/ew_heat_wave.en.pdf" target="_blank">hot summer</a> madness, ScienceLogic was founded.
<p>To kick off our celebration of our first five years, we asked <a href="http://www.sciencelogic.com/leadership.htm" target="_blank">ScienceLogic founders</a> Dave Link, Richard Chart and Chris Cordray for their thoughts and memories on events leading to today’s milestone. How and why did they set out on this venture? What happened along the way – expected and unexpected? Why were they successful in times when other new (and established) businesses have come and <a href="http://en.wikipedia.org/wiki/Category:2003_disestablishments" target="_blank">gone</a>?
<p><b>How did you three put together this team?</b>
<p>We all worked together at a large Managed Service Provider for a couple of years before leaving to start ScienceLogic, so we all knew each other and knew our collective strengths. More importantly, each of us had worked with network management tools on some level (sales and marketing, engineering and product development), and knew first-hand all of the customer pain points, from every perspective. So we left and began rapidly figuring out how to build a better network management solution based upon our real world operational experience..
<p><strong>Dave:</strong> One interesting aspect is that our areas of expertise don’t overlap, which has contributed to our success. Chris is excellent with developing the product front-end and interface, Richard handled the backend architecture and engineering and I focused on the technical business side of sales and marketing. Our roles have been to build a product that works well and that provides real value to operations teams that experience the same day to day frustrations that we felt.<b></b>
<p><b>Whose idea was it to start the company?</b>
<p><strong>Dave:</strong> It was really a collective effort. We were all passionate about “getting it right” and not just starting a company. We knew the industry need and between us, we had the knowledge and skill sets to address all of the right aspects of developing a product and a building a business around it.
<p><b>What process did you go through to get started?</b>
<p><strong>Richard:</strong> From the beginning we knew the type of solution the market needed and we knew that we wanted to build it as an appliance. From different vantage points, we had each experienced the effects of long, difficult and expensive installations that still exist with traditional network tools. Every install has unique variations: there are always different server types, varying hardware and software versions, different patches installed, and on and on. Every installation was time consuming and unpredictable. We knew that an appliance model would address all of these variables and save a lot of time on how quickly customers could achieve immediate value.
<p>The harder decisions were around actually starting the business, assessing the market and of course determining the product pricing.
<p><b>EM7 completely flips the traditional model of complex, lengthy and expensive deployments. How did you convince others that the EM7 Meta-Appliance product was valid?</b>
<p><strong>Dave:</strong> Yes, EM7 totally disrupts the traditional model for network management. While others take a narrow approach, we intentionally designed EM7 to focus on the broad problem – managing the data center. How do you cover a variety of technologies and make sure they work seamlessly together? The vision was to make it easier, not harder, for customers.
<p><strong>Chris:</strong> I have to give it to Dave – very early on, he realized the power of a demo. If Dave could get in front of someone, he’d make them a believer. He’d use the Peter Falk/Columbo technique of “let me show you one more thing.” It was very effective. It’s getting easier, but even today people sometimes have to see EM7 in action before they become believers.
<p><b>Can you describe the early days of running a new business?</b>
<p><strong>Dave:</strong> ScienceLogic is a classic case of entrepreneurship. For the first year we worked out of our basements. We kept the costs low in every conceivable way and spent the first year developing the product before we even made a sale.
<p><strong>Chris:</strong> We stayed at lots of odd places when we were on the road, took cheap flights with multiple layovers and purchased lots of our first test equipment on eBay. This was during the dot-com bust so there was lots of equipment for sale on eBay, really cheap!
<p><strong>Richard:</strong> The amount of equipment I had in my house was absolutely crazy. Back then, servers were huge – I had a Cisco 6509 Catalyst, a Compaq Proliant DL380, Brocade switch, IBM Netfinity 4500R, and tons of other machines.
<p><strong>Chris:</strong> I had to install a new circuit box at home because I was blowing breakers. I remember when that 6509 crashed, we revived it and it died again. The second death was final.
<p><b>So you started in your houses – what was your first office space?</b>
<p><strong>Dave:</strong> My friend, the CEO at Ernst &amp; Young Technology had a few extra cubes and a data center in their office that they graciously allowed us to use. Their help was an important step in helping us really formalize the business. We started doing well and adding people, but ironically, their company was downsizing. Before long, many of their original YET people were gone and the ScienceLogic team kept growing in to the open cubes.
<p>Our first leased space was converted warehouse space in Chantilly, VA that once housed an internet radio station. It was cool – it had a large salt water fish tank, a loft, a spiral staircase and a Star Trek door that retracted into the walls with the customary lights and “whooshing” sound.
<p>We outgrew the Chantilly space, leading to our current office in Reston, VA.
<p><b>Who was the first ScienceLogic customer?</b>
<p>Our first paying customer was <a href="http://martinspoint.com/" target="_blank">Martins Point Health Care</a>. We deployed there in July 2004 and are pleased to say they continue to be a ScienceLogic customer. Other early (and still) EM7 <a href="http://www.sciencelogic.com/customers.htm" target="_blank">customers</a> include Navy Knowledge Online and the Department of Transportation. Nearly all of our customers are still actively using EM7 and renewing their maintenance.
<p><b>Where do you see the company in the next 5, 10 or 15 years?</b>
<p>Well, our revenue has doubled year-over-year in each of the last three years, so of course we’d like to continue to grow like that or even faster. In five years we’ve gone from three founders to the point where Dave does not know everyone’s fondest childhood memory. We’ll continue to scale our growth to cover the demands of our growing customer base.
<p><b>Where do you see the industry going over the coming years?</b>
<p><strong>Chris:</strong> IT is always moving and gaining in complexity, so network management is also becoming more complicated. There’s increasing diversity, new standards, virtualization and cloud computing. All of these are today’s technologies. Customers have a mix of the old and the new, so EM7 has to accommodate and support both.
<p><strong>Richard:</strong> Each generation of products has a new set of ways to monitor, but the “old” doesn’t go away. Even when a new, hot technology comes along, the old technologies still need to be supported. We work to ensure EM7 keeps up with both.
<p><strong>Dave:</strong> After five years we’re just hitting our stride and we’re just now reaching the tipping point in awareness of ScienceLogic and EM7. We’re all still passionate about the product and as Chris and Rich said, there’s still a lot do. We’ll continue disrupting the market with EM7. Our vision hasn’t changed, and with the increasing levels of automation that customers demand, the market needs are greater than ever. Our future is as bright, or brighter, than ever and we’ll continue to be looking for smart ways to automate traditionally manual IT Operations processes.
<p><b>What’s your advice for someone interested in starting their own business?</b>
<p><strong>Chris:</strong> Be passionate. That’s what has gotten me through the tough times. I didn’t really appreciate this thought when I heard others say it before. But it’s very true.
<p><strong>Richard:</strong> I agree. We met and talked with lots of people who told us, “That’s been done before.” But we kept going because we truly believed in what we were doing and we knew that while our approach was different, that it would be successful.
<p><strong>Richard:</strong> Be fearless. You can’t be too nervous and you need to be able to expect and handle the stress because it will be there. You have to learn to accept the stressful times as a necessary part of the process of starting out on your own.
<p><strong>Dave:</strong> Know your niche from the beginning and give potential customers a compelling reason to trust you and really benefit from your solution. You have to know the problem, see the gap and have a clear and consistent vision of how to solve the problem. Then you have to execute. If you don’t build your team with “doers” you won’t make it.
<p><strong>Chris:</strong> It helps to have friends. ScienceLogic was built on friendships and relationships, starting with the three of us. If you look at our team, most of our hires are referrals – people who developed and maintained great connections with other great people throughout their careers. Maintain your connections and keep in touch with your network of friends.</p>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 18:39:16 +0000</pubDate>
      <category domain="http://securityratty.com/tag/em7 completely flips">em7 completely flips</category>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/network management">network management</category>
      <category domain="http://securityratty.com/tag/network management tools">network management tools</category>
      <category domain="http://securityratty.com/tag/em7 meta-appliance product">em7 meta-appliance product</category>
      <category domain="http://securityratty.com/tag/sciencelogic team">sciencelogic team</category>
      <category domain="http://securityratty.com/tag/team">team</category>
      <category domain="http://securityratty.com/tag/front">front</category>
      <category domain="http://securityratty.com/tag/product front-end">product front-end</category>
      <source url="http://blog.sciencelogic.com/sciencelogics-5-year-anniversary/08/2008">ScienceLogics 5-Year Anniversary</source>
    </item>
    <item>
      <title><![CDATA[This Generations ApathyThe Age of Specialization and ADD]]></title>
      <link>http://securityratty.com/article/de3980adf7c1fb760b23b64836636412</link>
      <guid>http://securityratty.com/article/de3980adf7c1fb760b23b64836636412</guid>
      <description><![CDATA[Robert Scoble has some interesting commentary this morning about the number of photojournalists with expensive gear covering the Olympics
Hes a bit indignant that so much energy goes to sporting...]]></description>
      <content:encoded><![CDATA[<p>Robert Scoble has some interesting <a rel="nofollow" target="_blank" href="http://scobleizer.com/">commentary</a> this morning about the number of photojournalists with expensive gear covering the Olympics.</p>
<p>He&#8217;s a bit indignant that so much energy goes to sporting events like the Olympics rather than more important news that isn&#8217;t getting reported around the world.</p>
<blockquote><p>This is in a year when tons of journalists are getting laid off.</p>
<p>This is in a year when there are tons of stories around the world that aren’t getting reported on.</p>
<p>Could we take half of those photographers and send them to Russia, for instance</p></blockquote>
<p>Reminds me of a feeling I had back in college as an undergrad student studying social sciences and humanities, about the way my friends who were physicists interacted with the world. They were so awed by the stars, Mars, astrophysics, and it seemed to me interesting but altogether unimportant. They argued they may find something outside our planet that could help solve Earth-bound problems like disease, or find the origins of earth and humanity &#8212; but really they were doing it because they loved it. One of my friends had a good argument, though &#8212; there are enough people right now that we can specialize in what we care about, and there will still be others covering other topics. He could be a physicist and look into the universe&#8217;s origin, while I studied social interaction and writing, and our other friends looked into solving cancer or eradicating invasive plants in the native wetlands. We have to specialize, and there are enough of us to do it too.</p>
<p>I think it&#8217;s the same way in journalism &#8212; whether it&#8217;s sports, celebrity journalism, or coverage of politics and war, there are a lot of opportunities right now for journalists. Of course the business model is changing, and some old-schoolers won&#8217;t know how to roll with that, but generations change slowly; we&#8217;re learning.</p>
<p>Also, the Olympics is seen as more than a sporting event, it&#8217;s also a symbol of world competition and cooperation too &#8212; a way for countries to come together and share entertainment globally. I think that&#8217;s worth covering.</p>
<p>In the second post, Robert Scoble says there are plenty of great journalists but the public doesn&#8217;t care. In some ways I have to agree with that, but I don&#8217;t think it&#8217;s negative, necessarily. I had a conversation with someone the other day about world news reportage. He says, &#8220;I was just reading this story, but what does it matter to me if there&#8217;s a flood in some city in another country I&#8217;ll never visit and some farmer lost his sheep?&#8221; World news is only important when it&#8217;s relevant, so it&#8217;s no wonder that many people don&#8217;t care &#8212; if they don&#8217;t know much about the area, and it doesn&#8217;t affect them, they have no incentive to give it full attention. You can call that apathy, but I think it&#8217;s an important selectivity skill that humans have. We have to choose what to give priority to, so if nothing stands out as being particularly important, we just ignore it or gloss over it. Human nature&#8230;</p>
<p>Also I think the common person today just gets desensitized and doesn&#8217;t know where to turn their energy, when surrounded by so many crises. Either you focus on one specialty and do your best to work toward one cause in your life &#8212; and maybe that&#8217;s just in the course of your daily work &#8212; or you become a complete Attention-Deficit-Disorder case and bounce from one problem to the next, without knowing how to solve anything. That just causes a sense of bewilderment, despair, and either that bogs you down or eventually you get desensitized.</p>
<p>There&#8217;s a commenter on Scoble&#8217;s blog, Spencer, who talks about this generation&#8217;s apathy. There are so many people who want to blame today&#8217;s generation or the young generation for this &#8220;apathy&#8221; that they sense. But I see it as a survival mechanism that arises from the way information flows these days. We&#8217;re surrounded by crises, everyone wants us to know about them &#8212; the water shortage, global warming, death in Iraq, the national deficit. Okay, crisis, I get it. But no one gives a real clear idea on what any individual is really supposed to do to solve the problem. You can&#8217;t get involved with one global cause, without ignoring all the others, and if you do get involved it&#8217;s likely to become your life&#8217;s purpose. Most people are concerned with other things &#8212; their families, their work, personal development, their homes and futures, and really that&#8217;s enough to take up all their time.</p>
<p>I&#8217;m always amazed when I read about the early unionists. Emma Goldman for example, the activist who pushed for the 8-hr workday, and campaigned for free love in the early 1900s when women were still wearing corsets, used to work 16 hour factory days as a seamstress, then lead meetings late into the night. Today we lead cushy lives comparatively&#8211;8 hour days, plus commute and lunch, family time, dinner time, gym maybe, sleep&#8230; but it still doesn&#8217;t seem like we ever have enough energy and time.</p>
<p>What Emma had that most people today don&#8217;t, is a community living in the same conditions as herself, with clear goals about what they were campaigning for, and a cause that affected their own daily lives. Today, unionism and local activism is in much shorter supply, in part due to the many people who work fairly comfy desk jobs, and the problem that everyone has his own specialization, works in a cubicle, does his or her own thing. The problems we&#8217;re facing today in terms of global warming, global water shortage, aren&#8217;t the same kinds of problems that activists have fought for in the past, and there&#8217;s no clear road map for how to solve them. Our leaders sure aren&#8217;t leading the way.</p>
<p>What we do have, at least, is the Olympics, which is an age old symbol of international cooperation, play and competition&#8230;so, uh, go sports! As for full disclosure, I don&#8217;t actually have a TV and haven&#8217;t watched the Olympics in many years, but I do try taking short showers&#8211;does that help?</p>]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 09:46:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/world news reportage">world news reportage</category>
      <category domain="http://securityratty.com/tag/world">world</category>
      <category domain="http://securityratty.com/tag/world competition">world competition</category>
      <category domain="http://securityratty.com/tag/world news">world news</category>
      <category domain="http://securityratty.com/tag/global water shortage">global water shortage</category>
      <category domain="http://securityratty.com/tag/global">global</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <category domain="http://securityratty.com/tag/solve earth-bound">solve earth-bound</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/369359733/">This Generations ApathyThe Age of Specialization and ADD</source>
    </item>
    <item>
      <title><![CDATA[U.S. at risk of cyberattacks, experts say]]></title>
      <link>http://securityratty.com/article/fa73c305e0e98f80ceac4e035b61d227</link>
      <guid>http://securityratty.com/article/fa73c305e0e98f80ceac4e035b61d227</guid>
      <description><![CDATA[Experts say the recent computer attacks on Georgia signal a new kind of cyber war. The U.S. is not fully prepared for a large-scale, coordinated attack, experts say. Such attacks can be mounted...]]></description>
      <content:encoded><![CDATA[Experts say the recent computer attacks on Georgia signal a new kind of cyber war. The U.S. is not fully prepared for a large-scale, coordinated attack, experts say. Such attacks can be mounted anonymously and cheaply from anywhere in the world. A cyberattack on the U.S. could hobble utilities, transportation and other infrastructure]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 08:50:01 +0000</pubDate>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/experts">experts</category>
      <category domain="http://securityratty.com/tag/recent computer attacks">recent computer attacks</category>
      <category domain="http://securityratty.com/tag/cyber war">cyber war</category>
      <category domain="http://securityratty.com/tag/georgia signal">georgia signal</category>
      <category domain="http://securityratty.com/tag/hobble utilities">hobble utilities</category>
      <category domain="http://securityratty.com/tag/large-scale">large-scale</category>
      <category domain="http://securityratty.com/tag/infrastructure">infrastructure</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <source url="http://digg.com/security/U_S_at_risk_of_cyberattacks_experts_say">U.S. at risk of cyberattacks, experts say</source>
    </item>
    <item>
      <title><![CDATA[Aussie security company set to be bought by Symantec ]]></title>
      <link>http://securityratty.com/article/53ea99ae1f62dc9f8cbebbf532de0260</link>
      <guid>http://securityratty.com/article/53ea99ae1f62dc9f8cbebbf532de0260</guid>
      <description><![CDATA[Symantec has announced it has signed an agreement to acquire Australian security vendor PC Tools. The privately held PC Tools, which is headquartered in Sydney, has risen to global prominence since...]]></description>
      <content:encoded><![CDATA[Symantec has announced it has signed an agreement to acquire Australian security vendor PC Tools. The privately held PC Tools, which is headquartered in Sydney, has risen to global prominence since hitting the world stage in 2003 with its security and privacy products for Windows-based PCs.]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/symantec">symantec</category>
      <category domain="http://securityratty.com/tag/global prominence">global prominence</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/privacy products">privacy products</category>
      <category domain="http://securityratty.com/tag/world stage">world stage</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/privately held">privately held</category>
      <category domain="http://securityratty.com/tag/sydney">sydney</category>
      <category domain="http://securityratty.com/tag/pcs">pcs</category>
      <source url="http://www.networkworld.com/news/2008/081908-symantec-buys-pctools.html?fsrc=rss-security">Aussie security company set to be bought by Symantec </source>
    </item>
    <item>
      <title><![CDATA[Cyberattack Against Georgia Preceded Real Attack]]></title>
      <link>http://securityratty.com/article/05aa9f87510a1d42d2691aadc95f19a7</link>
      <guid>http://securityratty.com/article/05aa9f87510a1d42d2691aadc95f19a7</guid>
      <description><![CDATA[This is interesting: Exactly who was behind the cyberattack is not known. The Georgian government blamed Russia for the attacks, but the Russian government said it was not involved. In the end,...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.nytimes.com/2008/08/13/technology/13cyber.html">This</a> is interesting:</p>

<blockquote>Exactly who was behind the cyberattack is not known. The Georgian government blamed Russia for the attacks, but the Russian government said it was not involved. In the end, Georgia, with a population of just 4.6 million and a relative latecomer to the Internet, saw little effect beyond inaccessibility to many of its government Web sites, which limited the government's ability to spread its message online and to connect with sympathizers around the world during the fighting with Russia.

<p>[...]</p>

<p>In Georgia, media, communications and transportation companies were also attacked, according to security researchers. Shadowserver saw the attack against Georgia spread to computers throughout the government after Russian troops entered the Georgian province of South Ossetia. The National Bank of Georgia's Web site was defaced at one point. Images of 20th-century dictators as well as an image of Georgia's president, Mr. Saakashvili, were placed on the site. "Could this somehow be indirect Russian action? Yes, but considering Russia is past playing nice and uses real bombs, they could have attacked more strategic targets or eliminated the infrastructure kinetically," said Gadi Evron, an Israeli network security expert. "The nature of what's going on isn't clear," he said.</p>

<p>[...]</p>

<p>In addition to D.D.O.S. attacks that crippled Georgia's limited Internet infrastructure, researchers said there was evidence of redirection of Internet traffic through Russian telecommunications firms beginning last weekend. The attacks continued on Tuesday, controlled by software programs that were located in hosting centers controlled by a Russian telecommunications firms. A Russian-language Web site, stopgeorgia.ru, also continued to operate and offer software for download used for D.D.O.S. attacks.</blockquote></p>

<p>Welcome to 21st century warfare.</p>

<blockquote>"It costs about 4 cents per machine," Mr. Woodcock said. "You could fund an entire cyberwarfare campaign for the cost of replacing a tank tread, so you would be foolish not to."</blockquote><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=FRnMDK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=FRnMDK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=O8aHKK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=O8aHKK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 18 Aug 2008 09:11:09 +0000</pubDate>
      <category domain="http://securityratty.com/tag/georgia">georgia</category>
      <category domain="http://securityratty.com/tag/indirect russian action">indirect russian action</category>
      <category domain="http://securityratty.com/tag/russian">russian</category>
      <category domain="http://securityratty.com/tag/georgian government">georgian government</category>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/russian troops">russian troops</category>
      <category domain="http://securityratty.com/tag/spread">spread</category>
      <category domain="http://securityratty.com/tag/georgia spread">georgia spread</category>
      <category domain="http://securityratty.com/tag/government web sites">government web sites</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/cyberattack_aga.html">Cyberattack Against Georgia Preceded Real Attack</source>
    </item>
    <item>
      <title><![CDATA[Old laws dont cover Cybercrime]]></title>
      <link>http://securityratty.com/article/f9bae1b796c4a6d1b215809f4cbd3027</link>
      <guid>http://securityratty.com/article/f9bae1b796c4a6d1b215809f4cbd3027</guid>
      <description><![CDATA[We really need to get our laws updated quickly. Cybercrime is up 20
Businesses are being targeted more routinely


clipped from www.crime-research.org

Scene of the Cybercrime: Inside Todays...]]></description>
      <content:encoded><![CDATA[<div>We really need to get our laws updated quickly. Cybercrime is up 20%.<br />
Businesses are being targeted more routinely.</div>
<table style="border: 4px solid #e5e5e5; margin: 12px 0px; background: #ffffff none repeat scroll 0%; font-family: arial; color: #333333; width: 100%; clear: left;" border="0" cellspacing="0" cellpadding="0" width="100%">
<tbody>
<tr>
<td valign="top">
<table class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;" border="0" cellspacing="0" cellpadding="0" width="100%">
<tbody>
<tr>
<td valign="top">
<table style="border-bottom: 1px solid #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee; background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;" border="0" cellspacing="0" cellpadding="0" width="100%">
<tbody>
<tr>
<td valign="top"><a title="go to this clipmark" href="http://clipmarks.com/clipmark/64B02289-0173-4D25-8D18-B2E876E5E3D6/"><img style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" src="http://content.clipmarks.com/blog_icon/a09d3640-cf18-4e6d-b96e-e15292ab93eb/64B02289-0173-4D25-8D18-B2E876E5E3D6/" border="0" alt="" width="19" height="19" /></a>clipped from <a style="font-size: 11px;" title="http://www.crime-research.org/news/10.08.2008/3498/" href="http://www.crime-research.org/news/10.08.2008/3498/">www.crime-research.org</a></td>
</tr>
</tbody>
</table>
<table style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;" border="0" cellspacing="0" cellpadding="0" width="100%">
<tbody>
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.crime-research.org/news/10.08.2008/3498/ --></p>
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Scene of the Cybercrime: Inside Today&#8217;s Cybercrime World</div>
</td>
</tr>
</tbody>
</table>
<table style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;" border="0" cellspacing="0" cellpadding="0" width="100%">
<tbody>
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.crime-research.org/news/10.08.2008/3498/ --></p>
<div>
<div></div>
<p>Today we live and work in a world of global connectivity. We can exchange casual conversation or conduct multimillion-dollar monetary transactions with people on the other side of the planet quickly and inexpensively. The proliferation of personal computers, easy access to the Internet, and a booming market for related new communications devices have changed the way we spend our leisure time and the way we do business.</p></div>
</td>
</tr>
</tbody>
</table>
</td>
</tr>
</tbody>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" border="0" cellspacing="0" cellpadding="0" width="100%">
<tbody>
<tr>
<td style="background:transparent;border-width:0px;padding:0px;"></td>
<td style="border-width: 0px; padding: 0px; background: transparent none repeat scroll 0%; width: 107px;" width="107" align="right"><a title="blog or email this clip" href="http://clipmarks.com/share/64B02289-0173-4D25-8D18-B2E876E5E3D6/blog/"><img style="border-width:0px;padding:0px;margin:0px;" src="http://content6.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" /></a></td>
</tr>
</tbody>
</table>
</div>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
      <pubDate>Sat, 16 Aug 2008 12:38:41 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cybercrime">cybercrime</category>
      <category domain="http://securityratty.com/tag/exchange casual conversation">exchange casual conversation</category>
      <category domain="http://securityratty.com/tag/planet quickly">planet quickly</category>
      <category domain="http://securityratty.com/tag/quickly">quickly</category>
      <category domain="http://securityratty.com/tag/communications devices">communications devices</category>
      <category domain="http://securityratty.com/tag/easy access">easy access</category>
      <category domain="http://securityratty.com/tag/monetary transactions">monetary transactions</category>
      <category domain="http://securityratty.com/tag/personal computers">personal computers</category>
      <category domain="http://securityratty.com/tag/leisure time">leisure time</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=561">Old laws dont cover Cybercrime</source>
    </item>
    <item>
      <title><![CDATA[Should BRIC be BIIC?]]></title>
      <link>http://securityratty.com/article/aa3f442ce62735204c29d3d8180fc691</link>
      <guid>http://securityratty.com/article/aa3f442ce62735204c29d3d8180fc691</guid>
      <description><![CDATA[People who follow emerging economies know BRIC (Brazil, Russia, India, China). There are some serious doubts on Russia's margin of safety for investors,(see previous post ), noted China bull Jim...]]></description>
      <content:encoded><![CDATA[<p>People who follow emerging economies know BRIC (Brazil, Russia, India, China). There are some serious doubts on Russia&#39;s margin of safety for investors,(see previous <a href="http://1raindrop.typepad.com/1_raindrop/2008/08/corporate-identity-theft.html">post</a>), noted China bull <a href="http://www.moneymorning.com/2008/04/15/jim-rogers-chinas-economic-advance-is-all-but-unstoppable/">Jim Rogers</a></p><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal; ">&quot;Q: Where do you see Russia fitting into this as it comes onto the scene?</span></p><p><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal; ">Rogers: I don’t. Russia will continue to disintegrate. The Soviet Union has already broken up into 15 countries. Putin controls Petersburg, Moscow, a few airports, et cetera, but Russia never has been a homogeneous [nation] - I mean, in the Soviet Union there were 124 - the &quot;official&quot; number was 124 - ethnic, linguistic, religious, historic and national groups.&#160;</span></p><p><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal; ">It’s broken up into 15 states. It’ll be 50 … it’ll be 100 [states] before it’s over. Ukraine may break up next. Who knows who’ll break up [after that]? Maybe even parts of Russia.&#160;</span></p><p><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal; ">To the bulls who say I’m wrong, my rejoinder is this: Let me ask you about Chechnya. The Russians have been trying to deal with Chechnya for 15 years with no success.&#160;</span></p><p><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal; ">Chechnya’s the size of Connecticut. Chechnya has a million-and-a-half people. If they can’t handle Chechnya, how is the Soviet Union, or Russia, going to handle these other places that are pulling away?&#160;</span></p><p><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal; ">There’s capitalism there, but it’s outlaw capitalism. If you’re good with dealing with the Mafia, you can probably make a fortune, if you’re on the ground [there]. For the most part, they have a lot of natural resources, which has been great.&#160;</span></p><p><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal; ">They have huge foreign reserves, but they’re stripping the assets.&#160;</span></p><p><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal; ">They’re not reinvesting for the most part in productive capacity. They’re stripping the assets. You know, oil production has peaked in Russia, even though there could conceivably be gigantic amounts of oil there somewhere. Nearly everything has peaked, because they have been stripping the assets, rather than reinvesting. &quot;</span></p></blockquote><div><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;"><br /></span></div><div><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;">To quote Charles Barkley &quot;that&#39;s why I don&#39;t eat shrimp.&quot; The future for all the BRIC countries is probably bright in the long run, but in the short run where is the margin of safety for an investor in Russia?</span></div><div><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;"><br /></span></div><div><span style="font-family: &#39;Times New Roman&#39;; font-size: 16px; line-height: normal;">Maybe instead of BRIC it should BIIC - Brazil, India, Indonesia and China. Indonesia just reported its seventh consecutive quarter of GDP growth in excess of 6%. Its the fourth largest country in the world with 240 million people and 17,000 islands. Its one to watch.</span></div>]]></content:encoded>
      <pubDate>Sat, 16 Aug 2008 06:14:34 +0000</pubDate>
      <category domain="http://securityratty.com/tag/russia">russia</category>
      <category domain="http://securityratty.com/tag/bric">bric</category>
      <category domain="http://securityratty.com/tag/handle">handle</category>
      <category domain="http://securityratty.com/tag/soviet union">soviet union</category>
      <category domain="http://securityratty.com/tag/handle chechnya">handle chechnya</category>
      <category domain="http://securityratty.com/tag/chechnya">chechnya</category>
      <category domain="http://securityratty.com/tag/countries">countries</category>
      <category domain="http://securityratty.com/tag/bric countries">bric countries</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/should-bric-be-biic.html">Should BRIC be BIIC?</source>
    </item>
    <item>
      <title><![CDATA[Links List 8.15.08]]></title>
      <link>http://securityratty.com/article/803e2f6db1563e98882d0a71faf66398</link>
      <guid>http://securityratty.com/article/803e2f6db1563e98882d0a71faf66398</guid>
      <description><![CDATA[Cloud Computing will also cure the common cold! Not really. But amidst all the hype and overly-used marketing speak its hard to tell the difference. Researchers from the University of Michigan...]]></description>
      <content:encoded><![CDATA[<p>Cloud Computing will also cure the common cold! Not really. But amidst all the hype and overly-used marketing speak it&#8217;s hard to tell the difference. Researchers from the University of Michigan announced CloudAV, a network service using the <a href="http://www.infoworld.com/article/08/08/08/Researchers_look_to_cloud_computing_to_fight_malware_1.html?source=NLC-TB&amp;cgd=2008-08-08">&#8220;cloud-computing&#8221; concept to fight malware</a>. Please stop the insanity! I&#8217;m just waiting for someone to put &#8220;my&#8221; and &#8220;cloud computing&#8221; together&#8230;</p>
<p>Here&#8217;s an interesting post on High Earth Orbit about the usage and promotion of <a href="http://highearthorbit.com/open-source-in-defense/">open source software for defense</a> contracts. As a developer of open source tools, Andrew Turner of course brings up some &#8220;pros&#8221; for the government to push open source, but it&#8217;s the &#8220;cons&#8221; that are really interesting. A big &#8220;con&#8221; &#8211; the US government having something called &#8220;<a href="http://tech.slashdot.org/article.pl?sid=08/08/04/2253246">sovereign immunity</a>&#8221; which apparently means something like it can&#8217;t be sued unless it consents to be sued. Hunh &#8211; the Republic of ScienceLogic-Land? Closing the loop here, a federal appeals court just boosted open-source software licenses by saying that any infringements can now get more <a href="http://weblog.infoworld.com/openresource/archives/2008/08/court_rules_tha.html?source=rss">severe remedies under copyright law</a> (instead of contract law); here&#8217;s the case, <a href="http://blawgletter.typepad.com/bbarnett/2008/08/can-you-copyrig.html">Jacobsen v Katzer</a>. But apparently not if it&#8217;s the <a href="http://arstechnica.com/news.ars/post/20080804-air-force-cracks-software-carpet-bombs-dmca.html">US government</a>?? Who knows more?</p>
<p>Does Linus Torvalds hate everyone except for developers? You have to check out this article on an email exchange he had with Network World this week, talking about how fed up he is with the &#8220;<a href="http://www.infoworld.com/article/08/08/14/Torvalds_Fed_up_with_the_security_circus_1.html">security circus</a>&#8221;. Over the course of the exchange and some other comments from last month, he manages to blast security folk, OpenBSD (on security) in particular, vendors and PR people (of course). In the midst of the barrage of colorful language, it&#8217;s difficult to really get his point &#8211; which if you can dig it out, ends up being surprisingly sensible.</p>
<p>Sharon Taylor, Chief Architect of ITIL V3, recently wrote that with the release of the latest version of ITIL<a href="http://itmanagersinbox.com/345/itil-v3-and-business-service-management/">, BSM is now an &#8216;ITIL best practice</a>.&#8217; You say potato&#8230; &#8220;The distinction between IT and the business has blurred, and the language of IT has been replaced with the language of the business.&#8221;</p>
]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 16:04:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/source software">source software</category>
      <category domain="http://securityratty.com/tag/open-source software licenses">open-source software licenses</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/blast security folk">blast security folk</category>
      <category domain="http://securityratty.com/tag/colorful language">colorful language</category>
      <category domain="http://securityratty.com/tag/language">language</category>
      <category domain="http://securityratty.com/tag/itil">itil</category>
      <category domain="http://securityratty.com/tag/email exchange">email exchange</category>
      <source url="http://blog.sciencelogic.com/links-list-81508/08/2008">Links List 8.15.08</source>
    </item>
    <item>
      <title><![CDATA[UK Police Seize War on Terror Board Game]]></title>
      <link>http://securityratty.com/article/3f568c502112697df18ef85b916ccd1c</link>
      <guid>http://securityratty.com/article/3f568c502112697df18ef85b916ccd1c</guid>
      <description><![CDATA[They said -- and it's almost to stupid to believe -- that: the balaclava &quot;could be used to conceal someone's identity or could be used in the course of a criminal act
Don't they realize that...]]></description>
      <content:encoded><![CDATA[<p>They <a href="http://www.cambridge-news.co.uk/cn%5Fnews%5Fhome/DisplayArticle.asp?ID=338658">said</a> -- and it's almost to stupid to believe -- that:</p>

<blockquote>the balaclava "could be used to conceal someone's identity or could be used in the course of a criminal act".</blockquote>

<p>Don't they realize that balaclavas are <a href="http://www.google.com/search?hl=en&client=opera&rls=en&hs=OZD&q=balaclava+sale+UK&btnG=Search">for sale</a> everywhere in the UK?  Or that scarves, hoods, handkerchiefs, and dark glasses could also be used to conceal someone's identity?</p>

<p>The game sounds like it could be fun, though:</p>

<blockquote>Each player starts as an empire filled with good intentions and a determination to liberate the world from terrorists and from each other.

<p>Then the reality of world politics kicks and terrorist states emerge.</p>

<p>Andrew said: "The terrorists can win and quite often do and it's global anarchy. It sums up the randomness of geo-politics pretty well."</p>

<p>In their cardboard version of realpolitik George Bush's "Axis of Evil" is reduced to a spinner in the middle of the board, which determines which player is designated a terrorist state.</p>

<p>That person then has to wear a balaclava (included in the box set) with the word "Evil" stitched on to it.</blockquote></p>

<p>Buy yours <a href="http://www.waronterrortheboardgame.com/">here</a>; I first <a href="http://www.schneier.com/blog/archives/2006/12/war_on_terror_t.html">blogged about it</a> in 2006.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=gzxk4K"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=gzxk4K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=fQtAMK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=fQtAMK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 15 Aug 2008 02:50:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/world">world</category>
      <category domain="http://securityratty.com/tag/world politics kicks">world politics kicks</category>
      <category domain="http://securityratty.com/tag/realpolitik george bush">realpolitik george bush</category>
      <category domain="http://securityratty.com/tag/player starts">player starts</category>
      <category domain="http://securityratty.com/tag/player">player</category>
      <category domain="http://securityratty.com/tag/geo-politics pretty">geo-politics pretty</category>
      <category domain="http://securityratty.com/tag/conceal">conceal</category>
      <category domain="http://securityratty.com/tag/game sounds">game sounds</category>
      <category domain="http://securityratty.com/tag/cardboard version">cardboard version</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/uk_police_seize.html">UK Police Seize War on Terror Board Game</source>
    </item>
  </channel>
</rss>
