<?xml version='1.0' encoding='UTF-8'?><rss xmlns:atom='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' version='2.0'><channel><atom:id>tag:blogger.com,1999:blog-3622592209194769260</atom:id><lastBuildDate>Tue, 04 Mar 2008 21:05:15 +0000</lastBuildDate><title>Made4Biz Dynamic IT Security News</title><description/><link>http://www.made4biz-security.com/log/security_log.htm</link><managingEditor>Made4biz Security</managingEditor><generator>Blogger</generator><openSearch:totalResults>204</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-1542300136922006955</guid><pubDate>Sat, 19 Jan 2008 10:27:00 +0000</pubDate><atom:updated>2008-01-19T11:25:17.108Z</atom:updated><title>Hackers threaten elecric supply</title><description>&lt;DIV&gt;&lt;FONT size=2&gt;Needed: Dynamic! Security for Utility Companies. &lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;Can Con Ed be made safe for America? The article from  Washington post tells us: &lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt; &lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;   &lt;DIV&gt;&lt;FONT size=2&gt;In a rare public warning to the power and utility industry,    a CIA analyst this week said cyber attackers have hacked into the computer    systems of utility companies outside the United States and made demands, in at    least one case causing a power outage that affected multiple cities....    &lt;/FONT&gt;&lt;/DIV&gt;   &lt;DIV&gt;&lt;FONT size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt;   &lt;DIV&gt;&lt;FONT size=2&gt;Over the past year to 18 months, there has been "a huge    increase in focused attacks on our national infrastructure networks, . . . and    they have been coming from outside the United States," said Ralph Logan,    principal of the Logan Group, a cybersecurity firm.... &lt;/FONT&gt;&lt;/DIV&gt;   &lt;DIV&gt;&lt;FONT size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt;   &lt;DIV&gt;   &lt;DIV&gt;&lt;FONT size=2&gt;Over the past 10 years, electric utilities, pipelines,    railroads and oil companies have used remotely controlled and monitored    valves, switches and other mechanisms. This has resulted in substantial    savings in man power and other costs.&lt;/FONT&gt;&lt;/DIV&gt;   &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;   &lt;DIV&gt;&lt;FONT size=2&gt;But to do that, the companies have installed wireless    Internet connections to link the devices to central offices....    &lt;/FONT&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt; &lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;   &lt;DIV&gt;&lt;FONT size=2&gt;The electric utility industry has also been adding software    that allows more coordination among different parts of the electricity grid    and will ultimately allow utilities and individuals to control devices    remotely. This is a central part of what many firms call the "utility of the    future," which will be better able to save energy and reduce greenhouse gas    emissions.&lt;/FONT&gt;&lt;/DIV&gt;   &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;   &lt;DIV&gt;&lt;FONT size=2&gt;&lt;EM&gt;"Often there are authentication methods that are less    than secure," Logan said. "Sometimes there are no authentication    methods."&lt;/EM&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt; &lt;DIV&gt;&lt;FONT size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;Dynamic! Security to the rescue, with regional syndication,  location and time sensitive security and fool-proof authentication.  &lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;&lt;STRONG&gt;Hackers Have Attacked Foreign Utilities, CIA Analyst  Says&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;By Ellen Nakashima and Steven Mufson&lt;BR&gt;Washington Post Staff  Writers and Washington Post Staff Writers&lt;BR&gt;Saturday, January 19, 2008;  A04&lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;In a rare public warning to the power and utility industry, a  CIA analyst this week said cyber attackers have hacked into the computer systems  of utility companies outside the United States and made demands, in at least one  case causing a power outage that affected multiple cities.&lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;SPAN class=Fullpost&gt; &lt;DIV&gt;&lt;FONT size=2&gt;"We do not know who executed these attacks or why, but all  involved intrusions through the Internet," Tom Donahue, the CIA's top  cybersecurity analyst, said Wednesday at a trade conference in New  Orleans.&lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;Donahue's comments were "designed to highlight to the audience  the challenges posed by potential cyber intrusions," CIA spokesman George Little  said. The audience was made up of 300 U.S. and international security officials  from the government and from electric, water, oil and gas companies, including  BP, Chevron and the Southern Co.&lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;"We suspect, but cannot confirm, that some of the attackers  had the benefit of inside knowledge," Donahue said. He did not specify where or  when the attacks took place, their duration or the amount of money demanded.  Little said the agency would not comment further.&lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;The remarks come as cyber attackers have made increasingly  sophisticated intrusions into corporate computer systems, costing companies  worldwide more than $20 billion each year, according to some  estimates.&lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;Cyber extortion is a growing threat in the United States, and  attackers have radically increased their take from online gambling sites,  e-commerce sites and banks, which pay the money to prevent sites from being shut  down and to keep the public from knowing their sites have been penetrated, said  Alan Paller, research director at the SANS Institute, the cybersecurity  education group that sponsored the meeting.&lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;"The CIA wouldn't have changed its policy on disclosure if it  wasn't important," Paller said. "Donahue wouldn't have said it publicly if he  didn't think the threat was very large and that companies needed to fix things  right now."&lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;Over the past year to 18 months, there has been "a huge  increase in focused attacks on our national infrastructure networks, . . . and  they have been coming from outside the United States," said Ralph Logan,  principal of the Logan Group, a cybersecurity firm.&lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;It is difficult to track the sources of such attacks, because  they are usually made by people who have disguised themselves by worming into  three or four other computer networks, Logan said. He said he thinks the attacks  were launched from computers belonging to foreign governments or militaries, not  terrorist groups.&lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;Over the past 10 years, electric utilities, pipelines,  railroads and oil companies have used remotely controlled and monitored valves,  switches and other mechanisms. This has resulted in substantial savings in man  power and other costs.&lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;But to do that, the companies have installed wireless Internet  connections to link the devices to central offices.&lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;"In the past, if they wanted to go out and read a gauge on a  gas well, for example, they would have to send a technician in his vehicle; he  would drive 100 miles and physically read the gauge and get back in his truck,"  Logan said. "Now they can read it from headquarters. But it allows attackers a  gateway into the system."&lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;In addition, within the companies' main offices, control  equipment can be accessed from more computers than in the past.&lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;The electric utility industry has also been adding software  that allows more coordination among different parts of the electricity grid and  will ultimately allow utilities and individuals to control devices remotely.  This is a central part of what many firms call the "utility of the future,"  which will be better able to save energy and reduce greenhouse gas  emissions.&lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;"Often there are authentication methods that are less than  secure," Logan said. "Sometimes there are no authentication  methods."&lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;On Thursday, the Federal Energy Regulatory Commission approved  eight cybersecurity standards for electric utilities. They involve identity  controls, training, security "perimeters," physical security of critical cyber  equipment, incident reporting and recovery.&lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;The U.S. electricity grid has always been vulnerable to  outages. "Cybersecurity is a different kind of threat, however," Joseph T.  Kelliher, the commission's chairman, said in a statement this week. "This threat  is a conscious threat posed by a single hacker, or even an organized group that  may be deliberately trying to disrupt the grid."&lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;&lt;A  href="http://www.washingtonpost.com/wp-dyn/content/article/2008/01/18/AR2008011803277_pf.html"&gt;Source&lt;/A&gt;&lt;/FONT&gt;&lt;/DIV&gt;&lt;/SPAN&gt;</description><link>http://www.made4biz-security.com/log/2008/01/hackers-threaten-elecric-supply.html</link><author>Made4biz Security</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-1097174127249635767</guid><pubDate>Wed, 28 Nov 2007 10:59:00 +0000</pubDate><atom:updated>2007-11-28T11:58:00.949Z</atom:updated><title>The man in the browser and how to starve him</title><description>&lt;DIV&gt;&lt;FONT size=2&gt;According to Computerworld, the &lt;A  href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9049080"&gt;'Man  in the browser' is a new threat to online banking&lt;/A&gt;,&amp;nbsp;but we have a  solution. Here is the problem: &amp;nbsp; &lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt; &lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;   &lt;DIV&gt;&lt;FONT size=2&gt;Criminals infecting PCs with malware that is only triggered    when they access their bank accounts are the latest threat to online banking,    according to security software supplier F-Secure.&lt;/FONT&gt;&lt;/DIV&gt;   &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;   &lt;DIV&gt;&lt;FONT size=2&gt;Perpetrators act as a 'man in the browser' by intercepting    HTML code in the Web browser. As bank security measures curb more traditional    threats such as keystroke logging, phishing and pharming, F-Secure warned, the    'man in the browser' attack will increase.&lt;/FONT&gt;&lt;/DIV&gt;   &lt;DIV&gt;&lt;FONT size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt;   &lt;DIV&gt;&lt;FONT size=2&gt;Once a user's PC is infected, the malicious code is only    triggered when the user visits an online bank. The 'man in the browser' attack    then retrieves information, such as logins and passwords, entered on a    legitimate bank site. This personal data is sent directly to an FTP site to be    stored, where it is sold to the highest bidder.&lt;/FONT&gt;&lt;/DIV&gt;   &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;   &lt;DIV&gt;&lt;FONT size=2&gt;Security products using behavioral analysis were the best    solution against such attacks, because the malware was only distributed to the    users of specific banking sites, said Mikko Hypponen, chief research officer    at F-Secure. This meant anti-malware software vendors were unlikely to be able    to quickly release code to tackle all the new threats.&lt;/FONT&gt;&lt;/DIV&gt;   &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;   &lt;DIV&gt;&lt;FONT size=2&gt;Following the enhancements that banks have made to    authentication on their sites, "phishing attacks are becoming less and less    effective and attacks of the 'Man in the Browser' are set to increase," he    warned.&lt;/FONT&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt; &lt;DIV&gt;&lt;FONT size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;The man in the browser is just a variant of the horse in the  browser. The thief in the browser, human or equine, gets cusomers' identity  information and uses it to empty their bank acount or&amp;nbsp;stock brokerage  account. The thieves can invent new software devices faster than the problem can  be fixed for the most part. &lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;There is one solution that is thief-proof: IDentiWall from  Made4Biz-security. IDentiWall&amp;nbsp;can require users to insert a unique one time  password that is sent by SMS to the user's cellphone. If&amp;nbsp;a thief tries to  access the account, the&amp;nbsp;user will get the same SMS with the one-time  password, and has the option of blocking access to the account until username  and password can be changed. &lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;IDentiWall can also send users&amp;nbsp;a summary of  the&amp;nbsp;transaction&amp;nbsp;for confirmation: &lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV&gt;&lt;FONT size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt; &lt;BLOCKQUOTE dir=ltr style="MARGIN-RIGHT: 0px"&gt;   &lt;DIV&gt;"You asked to debit acct # ____________ by $999.&lt;/DIV&gt;   &lt;DIV&gt;&lt;FONT size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt;   &lt;DIV&gt;Press &lt;STRONG&gt;Yes&lt;/STRONG&gt; to continue or &lt;STRONG&gt;No&lt;/STRONG&gt; to    cancel"&lt;BR&gt;&lt;/DIV&gt;&lt;/BLOCKQUOTE&gt; &lt;DIV dir=ltr&gt;&lt;FONT size=2&gt;The prinicple implemented by IDentiWall is that it  gives users control over their online account through a separate, secure channel  - their cellphone. &lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV dir=ltr&gt;&lt;FONT size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt; &lt;DIV dir=ltr&gt;&lt;FONT size=2&gt;The man installed by thieves&amp;nbsp;remains in the  browser, but he isn't being fed anything. &lt;/FONT&gt;&lt;/DIV&gt; &lt;DIV dir=ltr&gt;&amp;nbsp;&lt;/DIV&gt;</description><link>http://www.made4biz-security.com/log/2007/11/man-in-browser-and-how-to-starve-him.html</link><author>Made4biz Security</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-9127002436373279262</guid><pubDate>Wed, 24 Oct 2007 10:23:00 +0000</pubDate><atom:updated>2007-10-24T10:31:04.967Z</atom:updated><title></title><description>&lt;div class=Section1&gt;  &lt;p class=MsoNormal style='background:white'&gt;&lt;b&gt;&lt;font size=4 color="#333333" face="Trebuchet MS"&gt;&lt;span style='font-size:14.5pt;font-family:"Trebuchet MS"; color:#333333;font-weight:bold'&gt;Fingerprint system fails to identify black-listed soccer fans&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=published1 style='line-height:12.55pt;background:white'&gt;&lt;font size=1 color="#a4a4a4" face=Verdana&gt;&lt;span style='font-size:9.0pt'&gt;Published 23 October 2007&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class=subtitle1 style='line-height:12.55pt;background:white'&gt;&lt;b&gt;&lt;font size=1 color="#666666" face=Verdana&gt;&lt;span style='font-size:9.0pt'&gt;Dutch researchers test the reliability of finger print biometrics by placing finger print scanner at three Dutch soccer stadiums for the purpose of identifying more than 6,000 &amp;quot;black listed&amp;quot; volunteers; the fingerprint system failed to spot 15 percent to 20 percent of those on a volunteer black-list &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=MsoNormal style='mso-margin-top-alt:8.35pt;margin-right:8.35pt; margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:12.55pt; background:white'&gt;&lt;font size=1 color="#333333" face=Verdana&gt;&lt;span style='font-size:9.0pt;font-family:Verdana;color:#333333'&gt;This is a story about football, but it has implications beyond the beautiful game. A fingerprint recognition system failed to prevent black-listed fans from entering football grounds and was easily fooled by simple spoofing techniques, according to a trial by Dutch research organisation &lt;a href="http://www.tno.nl/home.cfm?content=rapporten" target="_blank"&gt;&lt;font color="#751038"&gt;&lt;span style='color:#751038'&gt;TNO&lt;/span&gt;&lt;/font&gt;&lt;/a&gt; (organization's motto: &lt;em&gt;&lt;i&gt;&lt;font face=Verdana&gt;&lt;span style='font-family:Verdana'&gt;&amp;quot;Kennis voor zaken&amp;quot;&lt;/span&gt;&lt;/font&gt;&lt;/i&gt;&lt;/em&gt;). Jurgen den Hartog, who undertook the research, said that with a false positive rate of 0.1 percent -- a low rate being a requirement for such a system, given the number of supporters and the fact that false positive could make for trouble -- the fingerprint system failed to spot 15 percent to 20 percent of those on a volunteer black-list, recruited to test the technology, a level he described as &amp;quot;unexpected.&amp;quot; &amp;quot;This has serious implications for a lot of other negative identification scenarios,&amp;quot; den Hartog told a session of the &lt;a href="http://www.computerweekly.com/Articles/2007/08/24/226380/biometrics-move-from-banking-to-borders.htm" target="_blank"&gt;&lt;font color="#751038"&gt;&lt;span style='color:#751038'&gt;Biometrics 2007 conference&lt;/span&gt;&lt;/font&gt;&lt;/a&gt; in &lt;st1:City w:st="on"&gt;&lt;st1:place w:st="on"&gt;Westminster&lt;/st1:place&gt;&lt;/st1:City&gt; last week. &amp;quot;It's very easy not to look like yourself, so I wonder what the impact of these results will be on other programmes.&amp;quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class=MsoNormal style='mso-margin-top-alt:8.35pt;margin-right:8.35pt; margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:12.55pt; background:white'&gt;&lt;em&gt;&lt;i&gt;&lt;font size=1 color="#333333" face=Verdana&gt;&lt;span style='font-size:9.0pt;font-family:Verdana;color:#333333'&gt;InfoSecurity&lt;/span&gt;&lt;/font&gt;&lt;/i&gt;&lt;/em&gt;&lt;font size=1 color="#333333" face=Verdana&gt;&lt;span style='font-size:9.0pt;font-family: Verdana;color:#333333'&gt;'s S. A. Mathieson &lt;a href="http://www.infosecurity-magazine.com/news/071019_tno.html" target="_blank"&gt;&lt;font color="#751038"&gt;&lt;span style='color:#751038'&gt;writes&lt;/span&gt;&lt;/font&gt;&lt;/a&gt; that negative identification fails if a black-listed person can fool the system into thinking they are not on that list, involving technically challenging one-to-many checks. Identity verification checks, such as with passports, require only a one-to-one check that the biometric recorded matches the individual, and fails only if someone else's identity is hijacked. Den Hartog said that fooling the fingerprint systems, LScan 100 scanners provided by NEC and HSB, proved easy for the volunteers, who were asked to attempt such spoofing. They used techniques including latent fingerprints on sticky tape and a layer of glue on fingers: &amp;quot;The trick is, do not press too hard,&amp;quot; he said of the latter. Both techniques also fooled a spoof-resistant scanner from Lumidigm in TNO's labs. Furthermore, the tests brought up other problems: the devices could check twelve fans a minute at best, but as few as four or five a minute on one occasion when it was in direct sunlight by Feyenoord's ground (Giovanni van Bronckhorst, one of our favorite footballers, is playing for the &lt;st1:City w:st="on"&gt;&lt;st1:place w:st="on"&gt;Rotterdam&lt;/st1:place&gt;&lt;/st1:City&gt; club). &amp;quot;The french fries stand outside the stadium couldn't do business any more, because of the queue for our gate,&amp;quot; den Hartog said. &amp;quot;The live system did not meet important requirements of speed, accuracy and robustness against manipulation,&amp;quot; den Hartog concluded. &amp;quot;I think speed and accuracy can be solved, but robustness against manipulation really remains a challenge.&amp;quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class=MsoNormal style='mso-margin-top-alt:8.35pt;margin-right:8.35pt; margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt;line-height:12.55pt; background:white'&gt;&lt;font size=1 color="#333333" face=Verdana&gt;&lt;span style='font-size:9.0pt;font-family:Verdana;color:#333333'&gt;The research involved 6,400 checks at 26 matches at three Dutch football clubs. TNO chose fingerprints in preference to iris or facial recognition, on a range of criteria including speed, reliability, and proof against being fooled. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt; font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;/div&gt;  </description><link>http://www.made4biz-security.com/log/2007/10/fingerprint-system-fails-to-identify.html</link><author>Made4biz Security</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-1074115670587324228</guid><pubDate>Wed, 16 May 2007 14:42:00 +0000</pubDate><atom:updated>2007-05-16T14:45:57.016Z</atom:updated><title>Yet another example of absence of Dynamic Security's protection</title><description>&lt;div class=Section1&gt;  &lt;h1&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;TJX breach-related expenses: $17M and counting&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/h1&gt;  &lt;p class=MsoNormal&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black;font-weight:bold'&gt;Jaikumar Vijayan&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size: 11.0pt;font-family:Arial;color:black'&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;&lt;!-- begin 336x280 ad tag --&gt;May 15, 2007&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt; (Computerworld) The TJX Companies Inc. today &lt;b&gt;&lt;span style='font-weight:bold'&gt;&lt;a href="http://home.businesswire.com/portal/site/tjx/index.jsp?epi-content=GENERIC&amp;amp;newsId=20070515005807&amp;amp;ndmHsc=v2*A938775600000*B1179266441000*C4102491599000*DgroupByDate*J2*N1001148&amp;amp;newsLang=en&amp;amp;beanID=1809476786&amp;amp;viewID=news_view" target=new&gt;announced&lt;/a&gt;&lt;/span&gt;&lt;/b&gt; that it took a $12 million after-tax charge for the quarter ending April 28 in connection with &lt;b&gt;&lt;span style='font-weight: bold'&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;taxonomyName=security&amp;amp;articleId=280123"&gt;the massive data breach it disclosed in January&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;The charge of 3 cents per share included the costs involved in investigating and containing the intrusion, beefing up computer security, communicating with customers, and various legal and other fees, the company said in its first quarter earnings statement. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;The company expects to incur a similar charge of 2 cents to 3 cents per share in the second quarter, as well, TJX said. It also warned investors of even more potential costs down the road. &amp;quot;TJX does not yet have enough information to reasonably estimate the losses it may incur arising from this intrusion, including exposure to payment card companies and banks, exposure in various legal proceedings that are pending or may arise, and related fees and expenses, and other potential liabilities and other costs and expenses,&amp;quot; TJX said in its statement. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;The Framingham, Mass.-based TJX owns several retail brands, including T.J.Maxx, &lt;st1:City w:st="on"&gt;&lt;st1:place w:st="on"&gt;Marshalls&lt;/st1:place&gt;&lt;/st1:City&gt; and Bob's Stores. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;In January, the company announced that someone had broken into its payment systems and illegally accessed card data belonging to customers in the &lt;st1:country-region w:st="on"&gt;U.S.&lt;/st1:country-region&gt;, &lt;st1:country-region w:st="on"&gt;Canada&lt;/st1:country-region&gt;, Puerto Rico, the &lt;st1:country-region w:st="on"&gt;U.K.&lt;/st1:country-region&gt; and &lt;st1:country-region w:st="on"&gt;&lt;st1:place  w:st="on"&gt;Ireland&lt;/st1:place&gt;&lt;/st1:country-region&gt;. In filings with the U.S. Securities and Exchange Commission in March, the company said &lt;b&gt;&lt;span style='font-weight:bold'&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9014782"&gt;45.6 million credit and debit card numbers were stolen&lt;/a&gt;&lt;/span&gt;&lt;/b&gt; over a period of more than 18 months by an unknown number of intruders. That number eclipsed the 40 million records compromised in a mid-2005 breach at CardSystems Solutions Inc. and made the TJX compromise the worst ever in terms of the loss of payment card data. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;The $12 million charge comes on top of the $5 million in breach-related costs cited by TJX in the previous quarter. And that may just be the tip of the iceberg, said Khalid Kark, an analyst at Forrester Research Inc. in &lt;st1:place w:st="on"&gt;&lt;st1:City w:st="on"&gt;Cambridge&lt;/st1:City&gt;,  &lt;st1:State w:st="on"&gt;Mass.&lt;/st1:State&gt;&lt;/st1:place&gt;, who released a report last month on all the factors that need to be included when totaling data breach costs. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Apart from direct expenses related to breach discovery, response and notification, companies also incur a variety of other costs such as those stemming from regulatory fines, lawsuits, and additional security and audit requirements. Several lawsuits have already been filed against TJX, &lt;b&gt;&lt;span style='font-weight:bold'&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9017758"&gt;including one by the Massachusetts Bankers Association&lt;/a&gt;&lt;/span&gt;&lt;/b&gt; seeking tens of millions in restitution for banks that were forced to block and reissue thousands of debit cards following the breach. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;There are also somewhat less tangible costs such as lost employee productivity and opportunity costs that need to be factored in, Kark said. The expenses disclosed by TJX could be &amp;quot;just a fraction&amp;quot; of what the breach could eventually end up costing the company. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;This is something that is going to play out over years,&amp;quot; he said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;!-- HTMLBODY-LOCATED --&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;/div&gt;  </description><link>http://www.made4biz-security.com/log/2007/05/yet-another-example-of-absence-of.html</link><author>Made4biz Security</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-2040497089760452252</guid><pubDate>Tue, 08 May 2007 09:23:00 +0000</pubDate><atom:updated>2007-05-08T09:26:32.171Z</atom:updated><title>IDentiWall is poised to resolve the credit card payment security</title><description>&lt;div class=Section1&gt;  &lt;h1&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Restaurant Chain Beefs Up Payment Card Protections&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/h1&gt;  &lt;p class=MsoNormal&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black;font-weight:bold'&gt;Jaikumar Vijayan&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size: 11.0pt;font-family:Arial;color:black'&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style='margin-bottom:12.0pt'&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black;font-weight:bold'&gt;&lt;!-- begin 336x280 ad tag --&gt;May 07, 2007&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt; (Computerworld) In the past, credit and debit card security wasn&amp;#8217;t a huge concern at The Steak n Shake Co., which operates more than 450 restaurants in the &lt;st1:place w:st="on"&gt;Midwest&lt;/st1:place&gt; and Southeast. But it has been a top priority for the chain&amp;#8217;s IT organization since last August, when the number of card transactions that Steak n Shake processes annually passed the 6 million mark. &lt;br&gt; &lt;br&gt; That put the Indianapolis-based chain into the category of businesses that are subject to the most stringent requirements of a data security standard mandated by the major credit card companies. &lt;br&gt; &lt;br&gt; Moving into the Level 1 classification under the Payment Card Industry (PCI) Data Security Standard had big IT implications for Steak n Shake, said Sean Smith, its director of strategic technology services. The company had been accepting card payments for only about two and a half years, and before August, it was considered a Level 4 merchant &amp;#8212; the lowest tier on the PCI scale. &lt;br&gt; &lt;br&gt; &lt;b&gt;&lt;span style='font-weight:bold'&gt;Requirements Multiplied &lt;/span&gt;&lt;/b&gt;&lt;br&gt; &lt;br&gt; &amp;#8220;We went from ground zero to Tier 1 in a very short period of time,&amp;#8221; Smith said. &amp;#8220;Our PCI requirements and the difficulty of attaining them changed by a magnitude of sixfold to tenfold.&amp;#8221; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size: 11.0pt;font-family:Arial;color:black'&gt;PCI requires all entities that handle payment cards to implement a set of 12 security controls, including data encryption, logical and physical access controls, and activity monitoring and logging. Companies are classified into four groups, depending on the number of card transactions they process annually. Businesses that are in the top group like Steak n Shake are required to undergo quarterly network security scans and an annual on-site security audit. &lt;br&gt; &lt;br&gt; Some of the biggest changes at Steak n Shake had to be made at the restaurant level. For instance, the generic usernames and passwords used in the past to access point-of-sale systems were replaced by a log-in system based on Active Directory that can be centrally monitored and managed. Under PCI, Smith said, &amp;#8220;we need to know who is accessing what, when and where.&amp;#8221; &lt;br&gt; &lt;br&gt; The company also had to roll out tools for centrally managing the IT assets in its restaurants and pushing out software patches and anti&amp;shy;virus updates to the systems. In addition, Smith said, Steak n Shake can now log and audit all restaurant-level transactions involving payment card data, as required by PCI. &lt;br&gt; &lt;br&gt; In another facet of the compliance effort, Steak n Shake is replacing its VSAT satellite communications links with a T1 network that will tie each restaurant to headquarters via secure point-to-point virtual private network connections. And to better secure its network perimeter, the chain is adding intrusion-prevention and -detection tools, plus security event management technology with centralized logging and correlation. &lt;br&gt; &lt;br&gt; Smith declined to disclose what the security upgrades are costing Steak n Shake, which has hired Qualys Inc. to do the required quarterly vulnerability scans of its network perimeter. Qualys will also conduct similar assessments of its internal network to help mitigate potential security threats from insiders. &lt;br&gt; &lt;br&gt; Implementing and demonstrating the controls needed to comply with PCI at Level 1 can be challenging, said Terry Ramos, director of strategic development at Redwood Shores, Calif.-based Qualys. That&amp;#8217;s especially true for a company like Steak n Shake, whose compliance level has abruptly changed, Ramos said. He noted that at Level 4, the PCI mandates are little more than best practices, with no specified validation requirements. &lt;br&gt; &lt;br&gt; Getting reclassified on the PCI scale &amp;#8220;can often be a rude awakening for organizations,&amp;#8221; said Chris Noell, president of TruComply, an Austin-based consulting firm that focuses on the payment card industry. Level 4 companies, he added, &amp;#8220;are rarely aware of their compliance obligation, much less doing anything about it.&amp;#8221; &lt;br&gt; &lt;br&gt; &amp;#8220;The difference can be like night and day,&amp;#8221; agreed Gartner Inc. analyst Avivah Litan. &amp;#8220;Level 1&amp;#8217;s come under a much bigger magnifying glass.&amp;#8221;&lt;/span&gt;&lt;/font&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;/div&gt;  </description><link>http://www.made4biz-security.com/log/2007/05/identiwall-is-poised-to-resolve-credit.html</link><author>Made4biz Security</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-7203650919648327449</guid><pubDate>Wed, 18 Apr 2007 08:49:00 +0000</pubDate><atom:updated>2007-11-28T12:08:06.945Z</atom:updated><category domain='http://www.blogger.com/atom/ns#'>Authentication</category><category domain='http://www.blogger.com/atom/ns#'>Cybercrime</category><title>IDentiWall could stop this thief</title><description>&lt;div class="Section1"&gt;  &lt;h1&gt;&lt;span style="font-size:100%;"&gt;&lt;st1:place st="on"&gt;&lt;st1:country-region st="on"&gt;&lt;b&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style=";font-family:Arial;color:black;"  &gt;Georgia&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/st1:country-region&gt;&lt;/st1:place&gt;&lt;/span&gt;&lt;span style="font-family:Arial;font-size:100%;color:black;"&gt;&lt;span style=";font-family:Arial;color:black;"  &gt; man pleads guilty in peer-to-peer crackdown&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/h1&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-weight: bold;font-family:Arial;color:black;"  &gt;Grant Gross&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;color:black;"&gt;&lt;span style=";font-family:Arial;color:black;"  &gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-weight: bold;font-family:Arial;color:black;"  &gt;&lt;!-- begin 336x280 ad tag --&gt;April 16, 2007&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style="font-family:Arial;font-size:100%;color:black;"&gt;&lt;span style=";font-family:Arial;color:black;"  &gt; (IDG News Service) A man from &lt;st1:place st="on"&gt;&lt;st1:city st="on"&gt;Columbus&lt;/st1:city&gt;, &lt;st1:state st="on"&gt;Ga.&lt;/st1:state&gt;&lt;/st1:place&gt;, has pleaded guilty to two felonies related to distribution of copyrighted materials over a peer-to-peer network, the Department of Justice announced Monday. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:Arial;font-size:100%;color:black;"&gt;&lt;span style=";font-family:Arial;color:black;"  &gt;The plea of Sam Kuonen, 24, is the fifth in a series of convictions arising from the DOJ's Operation D-Elite, an ongoing crackdown against the distribution of movies, software, games and music over peer-to-peer networks using the BitTorrent file-sharing technology.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:Arial;font-size:100%;color:black;"&gt;&lt;span style=";font-family:Arial;color:black;"  &gt;Kuonen was charged with conspiracy to commit criminal copyright infringement and criminal copyright infringement. He faces up to five years in prison and a $250,000 fine, the DOJ said. He faces sentencing July 16 in the U.S. District Court for the District of Kansas.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:Arial;font-size:100%;color:black;"&gt;&lt;span style=";font-family:Arial;color:black;"  &gt;Operation D-Elite has targeted leading members of a peer-to-peer network known as Elite Torrents, the DOJ said in a news release. In its prime, Elite Torrents attracted more than 133,000 members and facilitated the illegal distribution of more than 17,800 titles, which were downloaded over 2 million times, the DOJ said.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:Arial;font-size:100%;color:black;"&gt;&lt;span style=";font-family:Arial;color:black;"  &gt;The Elite Torrents network often included illegal copies of copyright works before they were available in retail stores or movie theaters. Kuonen was an "uploader" to the Elite Torrents network, responsible for supplying the network with the first copy of a particular movie or other title that was then made available to the entire network for downloading, the DOJ said.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:Arial;font-size:100%;color:black;"&gt;&lt;span style=";font-family:Arial;color:black;"  &gt;On May 25, 2005, federal agents shut down the Elite Torrents network by taking control of its main server. Authorities replaced the existing Web page with a law enforcement message announcing that "This Site Has Been Permanently Shut Down by the Federal Bureau of Investigation (FBI) and U.S. Immigration and Customs Enforcement (ICE)." Within only one week, the law enforcement message was viewed over half million times.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span style="font-family:Arial;font-size:100%;color:black;"&gt;&lt;span style=";font-family:Arial;color:black;"  &gt;The Motion Picture Association of America provided "substantial" assistance to the investigation, the DOJ said.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;!-- HTMLBODY-LOCATED --&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Arial;font-size:100%;"&gt;&lt;span style=";font-family:Arial;" &gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;/div&gt;</description><link>http://www.made4biz-security.com/log/2007/04/identiwall-identiwall-identiwall.html</link><author>Made4biz Security</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-7200994755623118894</guid><pubDate>Wed, 18 Apr 2007 08:44:00 +0000</pubDate><atom:updated>2007-04-18T08:46:59.642Z</atom:updated><title>IDentiWall will resolve this issue.</title><description>&lt;div class=Section1&gt;  &lt;h1&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;IRS warns of new e-filing scam that rips off refunds&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/h1&gt;  &lt;p class=MsoNormal&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black;font-weight:bold'&gt;Gregg Keizer&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size: 11.0pt;font-family:Arial;color:black'&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;&lt;!-- begin 336x280 ad tag --&gt;April 16, 2007&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt; (Computerworld) The U.S. Internal Revenue Service is warning Americans of a last-minute online scam where fraudulent sites pose as part of the agency's free tax-preparation service to poach refunds. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;On Friday, the IRS issued an alert saying it had uncovered one or more sites masquerading as part of the &lt;b&gt;&lt;span style='font-weight:bold'&gt;&lt;a href="http://www.irs.gov/efile/article/0,,id=118986,00.html" target=new&gt;Free File program&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;. Free File, a partnership with 19 tax preparation services, offers free preparation and e-filing to anyone with an adjusted gross income under $52,000. It's accessible only through the IRS's own Web site.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;The bogus sites, however, pretend to be part of the program, duping taxpayers into preparing their taxes and submitting them for e-filing. The criminals have been accepting user information, then substituting their own bank account information for refunds before resubmitting the modified returns to a real Free File participant, the IRS said.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;The final days of the tax season always bring tax scams,&amp;quot; IRS Commissioner Mark Everson said in a statement. &amp;quot;Make sure you're really dealing with the IRS. ... The only way to do it is through the secure IRS.gov Web site.&amp;quot; The Treasury Department's inspector general for tax administration is investigating.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;The IRS regularly warns taxpayers of possible scams; security vendors have also gotten in on the act with &lt;b&gt;&lt;span style='font-weight:bold'&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9016362"&gt;e-filing tips&lt;/a&gt;&lt;/span&gt;&lt;/b&gt; of their own.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;The April 17 deadline for filing federal returns is two days later than usual this year, because April 15 fell on a Sunday and today is Emancipation Day, a &lt;st1:place w:st="on"&gt;&lt;st1:State w:st="on"&gt;District   of Columbia&lt;/st1:State&gt;&lt;/st1:place&gt; holiday.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;!-- HTMLBODY-LOCATED --&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt; font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;/div&gt;  </description><link>http://www.made4biz-security.com/log/2007/04/identiwall-will-resolve-this-issue.html</link><author>Made4biz Security</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-7319507735712863619</guid><pubDate>Sun, 15 Apr 2007 09:47:00 +0000</pubDate><atom:updated>2007-04-16T10:25:13.821Z</atom:updated><title>Security Solutions - Do all the following or simply deploy Dynamic! Security</title><description>&lt;span style="font-family:arial;"&gt;&lt;em&gt;&lt;strong&gt;Security crucial as intruders grow sophisticated&lt;/strong&gt; &lt;/em&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&lt;em&gt;&lt;br /&gt;What technology gadgets do the experts love, or would love to have? CNN.com is asking experts in several fields about their favorite high-tech toys. This week, we asked security expert Heath Thompson.&lt;br /&gt;&lt;br /&gt;&lt;/em&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt;&lt;em&gt;&lt;/em&gt;&lt;/span&gt;&lt;span style="font-family:arial;"&gt;(CNN) -- Heath Thompson is vice president, product development for IBM Internet Security Systems.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;The 25-year computer industry veteran says security is going to be increasingly important since consumers are spending more of their lives online and intruders are growing more sophisticated.&lt;br /&gt;Here, he shares with CNN.com some of the key weapons in the security cyberwars.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;1) Biometrics: Biometric readers are the key to the future, literally. Not only do they reduce the number of passwords the average consumer has to remember, but they are truly a unique identifier and one of the strongest forms of security. Today fingerprint readers are built into laptops, but in the near future, I believe these readers will replace the traditional lock and key and be built into smart phones, handheld devices and door locks for the car and home.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Eventually, I also anticipate that people will be able to store biometric information over the Internet so they can identify themselves from any location.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;For instance, rather than carrying keys for safety deposit boxes, mailboxes and office entry, people will be able to access any secure device at any time through identification over the Internet.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;2) Filters: My children are coming into their preteens, and with the popularity of MySpace and YouTube (and the uncertainty of what my children will find) I've begun to think about stronger content filtering that would prevent children from viewing violence, hate, pornography, etc.&lt;br /&gt;Unfortunately, content filtering available through the computer's operating system isn't sufficient. Children are relentless and have figured out how to bypass security settings. Parents need industrial-strength content filtering, and the most economical way to get this would be through their Internet service provider. This type of security would allow parents to control individual usage throughout the home.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;3) Portable security: It's getting to the point where encrypted sites are not sufficient for financial and confidential transactions because Internet attackers have coaxed users to download Trojans unknowingly. The Trojans sit dormant on the computer and wait for the user to authenticate to the network. Once a secure connection is established, the Trojans awaken and capture consumers' identities that can be reused or sold.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Consumers need their banks or ISPs to provide dynamic, downloadable security clients to ensure the machines being used, be it at home or at an airport kiosk, are free of Trojans and other malicious software. Consumers need dynamic protection that follows them to provide security regardless of location.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;4) Secure Internet connections: Today, the Internet is connected to everything -- game consoles, digital video recorders, printers -- even refrigerators are now Web-enabled. Oftentimes these devices have no security settings installed, much less enabled. And even more often people are unaware these devices present an on-ramp into their home network.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;The No. 1 targeted source for attacks is the consumer. When it comes to gaining easy access to user account data, Internet attackers have learned the consumer is much more susceptible and accessible than corporations.&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;For years corporations have been deploying intrusion prevention technology to keep the bad guys off corporate networks. Considering 68 percent of corporations experience six losses of sensitive data every year due to human error, according to IT Policy Compliance Group, employees need consumer-grade intrusion prevention equivalent to what their corporations have to secure their home Internet connections.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Corporate IPS systems would be cost-prohibitive and excessive for consumers and small business owners; however, if consumers could buy secure Internet connectivity through their ISPs, they would be able to protect their Internet Protocol-enabled devices, from today's ever-evolving threats.&lt;br /&gt; &lt;/span&gt;</description><link>http://www.made4biz-security.com/log/2007/04/you-can-do-all-following-or-simply.html</link><author>Made4biz Security</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-3784381605270921466</guid><pubDate>Thu, 12 Apr 2007 16:10:00 +0000</pubDate><atom:updated>2007-04-12T16:12:28.105Z</atom:updated><title>it seems that protection is where we should put our money</title><description>&lt;div class=Section1&gt;  &lt;h1&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Just how much will that data breach cost your company?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/h1&gt;  &lt;p class=MsoNormal&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black;font-weight:bold'&gt;Jaikumar Vijayan&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size: 11.0pt;font-family:Arial;color:black'&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;&lt;!-- begin 336x280 ad tag --&gt;April 11, 2007&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt; (Computerworld) Want to know just how much a data breach is likely to end up costing your company? Darwin Professional Underwriters Inc. may be able to help. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;The Farmington, Conn.-based technology liability insurance company has released a &lt;b&gt;&lt;span style='font-weight:bold'&gt;&lt;a href="http://www.tech-404.com/calculator.html" target=new&gt;free online calculator&lt;/a&gt;&lt;/span&gt;&lt;/b&gt; that it said allows businesses to estimate -- with a fair degree of accuracy -- their financial risk from data theft. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;st1:City w:st="on"&gt;&lt;st1:place w:st="on"&gt;&lt;font size=2 color=black   face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt;Darwin&lt;/span&gt;&lt;/font&gt;&lt;/st1:place&gt;&lt;/st1:City&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial; color:black'&gt;'s Data Loss Cost Calculator uses proprietary algorithms developed with security breach data from media reports and other industry resources, according to the company. Among them was Ponemon Institute LLC's 2006 security breach and cost-analysis survey of 31 companies that had suffered data breaches. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Basically, the calculator allows companies to get hard cost estimates in three major categories: internal investigation expenses, customer notification/crisis management costs, and regulatory and other compliance expenses. Companies input data in the respective fields in the calculator to get instant estimates for costs associated with breach-related activities such as customer notification, credit monitoring, crisis management consulting, state or federal fines, and attorney fees. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;When we talk with different risk managers and CIOs, the constant refrain we hear is, 'Show me how much it costs when someone breaches our information,'&amp;quot; said Adam Sills, lead underwriter for &lt;st1:City w:st="on"&gt;&lt;st1:place w:st="on"&gt;Darwin&lt;/st1:place&gt;&lt;/st1:City&gt;'s technology and information liability initiatives. &amp;quot;There are different statistics from different sources&amp;quot; that have made it hard for companies to asses their financial risk, he said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;The online calculator is &amp;quot;our best guess, using the best information out there for how much this stuff costs,&amp;quot; he said. &amp;quot;These are the hard costs that you can quantify when you have a serious situation.&amp;quot; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;The calculator does not include costs associated with any class-action or other lawsuits that might follow a data breach, he said. Neither does it look at the effect on stock prices or reputation, because such numbers can vary by incident and are much harder to generalize. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Such calculators can be pretty useful in helping companies arrive at a better understanding of the financial implications of a breach, said Pete Lindstrom, an analyst at Midvale, Utah-based Burton Group Inc. &amp;quot;I'm a big fan of calculators,&amp;quot; he said. &amp;quot;It grounds security folks in a way that talking ephemerally about brand damage doesn't.&amp;quot; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Although the numbers thrown out by &lt;st1:City w:st="on"&gt;&lt;st1:place w:st="on"&gt;Darwin&lt;/st1:place&gt;&lt;/st1:City&gt;'s calculator may not be always accurate for everyone all the time, they give IT managers &amp;quot;a way to think more concretely about the nature of the problem,&amp;quot; he said. &amp;quot;We need to collect information like this, even if they are broad estimates, to get smarter. This is as good a start as any.&amp;quot; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Avivah Litan, an analyst at Stamford, Conn.-based Gartner Inc., said that such calculators &amp;quot;can give people a way to structure their thinking on the cost implications of a breach. I wouldn't bet my house or my enterprise on these numbers. A lot of the costs are often exaggerated.&amp;quot; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Even so, as tools to get people thinking about the hard costs of security breaches, such calculators can at least offer worst-case estimates, she said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;!-- HTMLBODY-LOCATED --&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;/div&gt;  </description><link>http://www.made4biz-security.com/log/2007/04/it-seems-that-protection-is-where-we.html</link><author>Made4biz Security</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-864096425608083459</guid><pubDate>Tue, 10 Apr 2007 09:33:00 +0000</pubDate><atom:updated>2007-04-10T09:35:46.912Z</atom:updated><title>IDentiWall does not relay exclusively on regular credentials, therefore it wouldn't the hackers any good if they stole it.</title><description>&lt;div class=Section1&gt;  &lt;h1&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Hackers dupe users with spam about bogus U.S.-Iran war&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/h1&gt;  &lt;p class=MsoNormal&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black;font-weight:bold'&gt;Gregg Keizer&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size: 11.0pt;font-family:Arial;color:black'&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;&lt;!-- begin 336x280 ad tag --&gt;April 09, 2007&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt; (Computerworld) A weekend spam run tried to dupe recipients into downloading the infamous &amp;quot;Storm Trojan&amp;quot; by attaching files that posed as videos of a bogus missile strike by the &lt;st1:country-region w:st="on"&gt;U.S.&lt;/st1:country-region&gt; against &lt;st1:country-region w:st="on"&gt;&lt;st1:place w:st="on"&gt;Iran&lt;/st1:place&gt;&lt;/st1:country-region&gt;, antivirus vendors said today. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;The unsolicited e-mail, which arrives with provocative subject lines that include &amp;quot;Missle [sic] Strike: The USA kills more then [sic] 20000 Iranian citizens,&amp;quot; &amp;quot;USA Declares War on &lt;st1:country-region w:st="on"&gt;&lt;st1:place w:st="on"&gt;Iran&lt;/st1:place&gt;&lt;/st1:country-region&gt;,&amp;quot; and &amp;quot;USA Just Have Started World War III,&amp;quot; include attached executable files such as video.exe and readme.exe, said Symantec Corp. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;The underlying threats are actually nothing new,&amp;quot; said Symantec researcher John McDonald on the company's security response team's blog. &amp;quot;They are simply minor variants of Trojan.Peacomm and W32.Mixor, which have been repacked in an attempt to avoid existing detection and appear to have been largely successful at that.&amp;quot; Symantec added that executable file attached to the war-scare spam is actually a worm that downloads and install both Trojan horses. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;According to data from MessageLabs Ltd., Peacomm -- also known as Zhelatin -- was the most prevalent piece of malware in the past 24 hours. It accounted for 32% of all malicious code being distributed worldwide, said MessageLabs. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;By early today, other security companies, including F-Secure Corp., Fortinet Inc., Kaspersky Lab Inc. and Sophos PLC, had released updated signatures to detect the tweaked threat. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Peacomm, which also goes by the nickname &amp;quot;Storm Trojan,&amp;quot; is notable because an outbreak in January and February ended up claiming the prize as the &lt;b&gt;&lt;span style='font-weight:bold'&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9008818"&gt;biggest malware assault&lt;/a&gt;&lt;/span&gt;&lt;/b&gt; since mid-2005. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Previous spam runs of the malware have enticed users with romantic subject headings around Valentine's Day; the malicious code has been spread through &lt;b&gt;&lt;span style='font-weight:bold'&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9011903"&gt;blogs and instant messaging&lt;/a&gt;&lt;/span&gt;&lt;/b&gt; as well as e-mail. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;!-- HTMLBODY-LOCATED --&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;/div&gt;  </description><link>http://www.made4biz-security.com/log/2007/04/identiwall-does-not-relay-exclusively.html</link><author>Made4biz Security</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-3881904997287053190</guid><pubDate>Tue, 10 Apr 2007 09:26:00 +0000</pubDate><atom:updated>2007-04-10T09:28:24.090Z</atom:updated><title>!!!   Dynamic! Security + IDentiWall option help fighting zero-day attacks   !!!</title><description>&lt;!-- Converted from text/rtf format --&gt;  &lt;P DIR=LTR&gt;&lt;B&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;FONT COLOR="#000000" FACE="Arial"&gt;Multiple Defenses Needed to Fight Off Zero-Day Attacks, Say Experts&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/B&gt;&lt;/P&gt;  &lt;P DIR=LTR&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;B&gt;&lt;/B&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;B&gt;&lt;FONT COLOR="#000000" FACE="Arial"&gt;Jaikumar Vijayan&lt;/FONT&gt;&lt;/B&gt;&lt;/SPAN&gt;&lt;/P&gt;  &lt;P DIR=LTR&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;FONT COLOR="#000000" FACE="Arial"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;/P&gt;  &lt;P DIR=LTR&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;B&gt;&lt;/B&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;B&gt;&lt;FONT COLOR="#000000" FACE="Arial"&gt;April 09, 2007&lt;/FONT&gt;&lt;/B&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;FONT COLOR="#000000" FACE="Arial"&gt; (Computerworld) The Windows animated cursor flaw that Microsoft patched last week caused widespread concern because attempted exploits of it were unleashed before the patch became available. But there are a variety of steps that companies can take to try to mitigate the risks posed by the ANI vulnerability and other so-called zero-day security threats.&lt;BR&gt; &lt;BR&gt; The available measures aren&amp;#8217;t a sure bet, IT managers and security analysts cautioned. They added that in the end, patching a flaw is still the most reliable way of protecting systems against attackers who are seeking to take advantage of it. But deploying multiple layers of defenses is a vital element of strategies for dealing with threats for which no immediate fix is available.&lt;BR&gt; &lt;BR&gt; For instance, Lloyd Hession, chief security officer at New York-based BT Radianz, said his company is using software from ConSentry Networks Inc. that can quickly detect compromised systems by any anomalous behavior they exhibit, instead of trying to spot infections solely by looking for virus signatures on machines.&lt;BR&gt; &lt;BR&gt; &amp;#8220;You need to smarten the intelligence within the local network,&amp;#8221; said Hession, who added that the ConSentry tool lets IT staffers at BT Radianz control the connections PCs can make with other systems. He said that can help lower the risk that an infected computer will spread malware across a LAN at the company, which provides telecommunications services to financial firms.&lt;BR&gt; &lt;BR&gt; &amp;#8220;Under the previous model, you could go anywhere in the network once you were within the network,&amp;#8221; Hession said. Now there are automated rules specifying the portions of a network that systems are allowed to access. The rules also limit the other machines that PCs can connect to based on the business needs of end users, he said.&lt;BR&gt; &lt;BR&gt; Another way to minimize zero-day threats is to adopt strict policies for filtering out e-mail attachments, which attackers often use to try to deliver malware to unsuspecting end users.&lt;BR&gt; &lt;BR&gt; Analysts have long advised companies to filter out GIFs, JPEGs, WMVs and other unneeded attachment types from inbound and outbound e-mails. And when deciding which attachments to allow and which to block, it&amp;#8217;s a mistake to assume that only certain types are being used maliciously, said Russ Cooper, senior information security analyst at Cybertrust Inc., a security services firm in Herndon, Va.&lt;BR&gt; &lt;BR&gt; Cooper noted that both GIFs and JPEGs were considered benign until attackers started hiding malicious code in them. &amp;#8220;Don&amp;#8217;t go on the basis of whether something is benign or not,&amp;#8221; he said. &amp;#8220;Look at what you need for your business.&amp;#8221;&lt;BR&gt; &lt;BR&gt; Malicious hackers also like to use HTML e-mail because it lets them more easily hide and deliver attack code to systems. For instance, several of Microsoft&amp;#8217;s e-mail clients, including Outlook Express and Windows Mail for Vista, are vulnerable to attacks that insert a malicious ANI file in an HTML message. Disabling HTML e-mail on systems can help mitigate that risk and blunt many of the phishing attacks that attempt to get users to click on links to malicious Web sites, Cooper said.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt; &lt;/SPAN&gt;&lt;/P&gt;  &lt;P DIR=LTR ALIGN=CENTER&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;B&gt;&lt;/B&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;B&gt;&lt;FONT COLOR="#000000" FACE="Arial"&gt;Additional Protections&amp;nbsp;&lt;/FONT&gt;&lt;/B&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;BR&gt; &lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;FONT COLOR="#000000" FACE="Arial"&gt;Security analysts also suggested the following measures for blocking exploits of unpatched vulnerabilities:&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;  &lt;P DIR=LTR&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;BR&gt; &lt;BR&gt; &lt;FONT COLOR="#000000" FACE="Arial"&gt;&amp;#8226;&amp;nbsp;&amp;nbsp;Turn off JavaScript to prevent some Web-embedded exploits from reaching end users via their browsers. &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;  &lt;P DIR=LTR&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;/P&gt;  &lt;P DIR=LTR&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;FONT COLOR="#000000" FACE="Arial"&gt;&amp;#8226;&amp;nbsp;&amp;nbsp;Restrict administrative privileges to stop remote hackers from gaining full administrative control of systems. &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;  &lt;P DIR=LTR&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;/P&gt;  &lt;P DIR=LTR&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;FONT COLOR="#000000" FACE="Arial"&gt;&amp;#8226;&amp;nbsp;&amp;nbsp;Use updated virus signatures to identify possible attacks from remote sites and initiate responses.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;  &lt;P DIR=LTR&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;/P&gt;  &lt;P DIR=LTR&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;/P&gt;  &lt;P DIR=LTR&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;/P&gt;  &lt;P DIR=LTR&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;BR&gt; &lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;BR&gt; &lt;BR&gt; &lt;FONT COLOR="#000000" FACE="Arial"&gt;It&amp;#8217;s also important to keep an eye on the traffic that&amp;#8217;s leaving your network. Many Trojan horses and bot programs communicate with remote systems to get instructions on what to do next or what information they should upload. Using outbound proxies or firewalls to look for and block such communications could prevent malware programs from calling home, said Johannes Ullrich, chief technology officer at the SANS Institute&amp;#8217;s Internet Storm Center in Bethesda, Md.&lt;BR&gt; &lt;BR&gt; Companies should also consider implementing a &amp;#8220;default deny&amp;#8221; capability at the perimeter of their networks, Cooper said. The idea behind that approach is to allow only specific traffic in and out of a network gateway while blocking everything else by default.&lt;BR&gt; &lt;BR&gt; Cooper said that to determine what traffic should be permitted to enter and leave a network, IT managers can log all inbound and outbound router activity for a period of time to get a picture of what is routinely being transmitted. &amp;#8220;If you&amp;#8217;re worried about breaking functionality, allow everything that has been going through anyway, and deny everything else,&amp;#8221; he said. &amp;#8220;It&amp;#8217;s a great starting point.&amp;#8221;&lt;BR&gt; &lt;BR&gt; Increasingly, though, Trojan horses and bot programs are using trusted network ports such as Port 80 and Port 443, which are used by HTTP and HTTPS traffic, respectively, to communicate with the remote systems controlling them. That makes it harder to detect the illicit traffic using outbound filtering, Hession said.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;FONT COLOR="#000000" FACE="Arial"&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt; &lt;/SPAN&gt;&lt;/P&gt;  &lt;P DIR=LTR&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;SPAN LANG="en-us"&gt;&lt;/SPAN&gt;&lt;/P&gt;  </description><link>http://www.made4biz-security.com/log/2007/04/dynamic-security-identiwall-option-help.html</link><author>Made4biz Security</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-1137674455161086831</guid><pubDate>Sun, 08 Apr 2007 13:27:00 +0000</pubDate><atom:updated>2007-04-08T13:30:21.899Z</atom:updated><title>what if the ID thieves couldn't use the stolen IDs? IDentiWall is doing just that!!!!!!!!!!!!!!</title><description>&lt;div class=Section1&gt;  &lt;h1&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Q&amp;amp;A: How Betty Ostergren makes life a little harder for ID thieves&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/h1&gt;  &lt;p class=MsoNormal&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black;font-weight:bold'&gt;Jaikumar Vijayan&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size: 11.0pt;font-family:Arial;color:black'&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;&lt;!-- begin 336x280 ad tag --&gt;April 05, 2007&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt; (Computerworld) &lt;i&gt;&lt;span style='font-style:italic'&gt;If Massachusetts Secretary of State William Galvin finds himself in the news this week -- and he does -- because of concerns that his office's Web site is exposing Social Security numbers and other personal information online, he can thank -- or blame -- &lt;/span&gt;&lt;/i&gt;&lt;b&gt;&lt;span style='font-weight:bold'&gt;Betty &amp;quot;B.J.&amp;quot; Ostergren&lt;/span&gt;&lt;/b&gt;&lt;i&gt;&lt;span style='font-style:italic'&gt; for the publicity. For nearly five years, the feisty 57-year-old former insurance claims supervisor has led a one-person crusade against county and state government officials around the &lt;st1:country-region w:st="on"&gt;&lt;st1:place w:st="on"&gt;U.S.&lt;/st1:place&gt;&lt;/st1:country-region&gt; Her mission: Stop them from posting public records containing Social Security numbers and other personal data online. It's a &amp;quot;stupid&amp;quot; and &amp;quot;reckless&amp;quot; practice that she says has turned the sites into a feeding ground for identity thieves and other cybercriminals. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/i&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;i&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-style:italic'&gt;Ostergren's site, &lt;b&gt;&lt;span style='font-weight:bold'&gt;&lt;a href="http://www.thevirginiawatchdog.com/" target=new&gt;The Virginia Watchdog&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;, boasts a list of public records containing Social Security numbers belonging to well-known figures -- including former Florida Gov. Jeb Bush and former Texas Congressman Tom Delay -- that she accessed from county sites. She also contacts people whose data she finds and asks them to put pressure on officials to take down the records. In just the last week, she persuaded the secretaries of state in &lt;st1:State w:st="on"&gt;Colorado&lt;/st1:State&gt; and &lt;st1:State w:st="on"&gt;&lt;st1:place w:st="on"&gt;Arizona&lt;/st1:place&gt;&lt;/st1:State&gt; to break links to certain commercial documents and tax liens on their sites that contained personal information. Sometimes her efforts don't work -- as in the case of Galvin, who said that online access to the documents is vital for business. Ostergren talked about how a campaign that began with an attempt to keep her own records offline in Hanover County, Va., has grown into a nationwide mission. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;&lt;i&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-style:italic'&gt;Excerpts from the interview follow:&lt;/span&gt;&lt;/font&gt;&lt;/i&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;What is the status in &lt;st1:State w:st="on"&gt;&lt;st1:place w:st="on"&gt;Virginia&lt;/st1:place&gt;&lt;/st1:State&gt; today? How many counties are still making unredacted public records available online? &lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial; color:black'&gt;As of today in &lt;st1:State w:st="on"&gt;&lt;st1:place w:st="on"&gt;Virginia&lt;/st1:place&gt;&lt;/st1:State&gt;, we have 59 circuit court clerks who have certified to the state compensation board that they have online remote access to these records. There are 62, however, who are not -- and my county is one of them. Those records that they have online in this state are deeds, mortgages, estate details, list of heirs of a deceased person, final divorce decrees with children's names, tax liens, power of attorney, name change documents and others. A lot of these records have Social Security numbers on them. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;Are there many counties around the country doing this? &lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt;Yes there are. It's stupid, it's reckless and it's dangerous. You got people who are cops, FBI agents, Secret Service, the CIA, judges, doctors, abused single women, elderly women -- and here you are putting all their information right out there on the Internet, just because they're public records. Here's a thought: If somebody wants to see a public record, why don't they get in their car and drive down to the courthouse or the secretary of state's office? Don't be spoon-feeding criminals with stuff on the Internet. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;County clerks say all they are doing is making the same public records that are available in the courthouse available on the Internet. They say businesses need these records. What's wrong with that? &lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt;Yeah, but they have Social Security numbers in them. I have driven down to &lt;st1:PlaceName w:st="on"&gt;Miami-Dade&lt;/st1:PlaceName&gt; &lt;st1:PlaceType w:st="on"&gt;County&lt;/st1:PlaceType&gt; in &lt;st1:State w:st="on"&gt;&lt;st1:place  w:st="on"&gt;Florida&lt;/st1:place&gt;&lt;/st1:State&gt; and tried to get Gov. Jeb Bush and his wife's Social Security number off a deed at the courthouse, but it wasn't possible. But I sat here at my computer in &lt;st1:place w:st="on"&gt;&lt;st1:City  w:st="on"&gt;Hanover County&lt;/st1:City&gt;, &lt;st1:State w:st="on"&gt;Va.&lt;/st1:State&gt;&lt;/st1:place&gt;, and got it. Sure, these are open records at the courthouse, as well they should be. But when we first started putting our records in these courthouses however many hundreds of years ago, it was for safekeeping and for different legal purposes. But with the advent of the Internet, everybody wants to put all this crap online with all this personal information, and I just think that it's dead wrong. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;So who really is accessing all of this data? &lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt;Absolutely anybody and everybody can access it. People from outside this country are into these sites and so are people from within this country. Maybe it's your neighbor down the street. A site like the &lt;st1:State w:st="on"&gt;&lt;st1:place w:st="on"&gt;Colorado&lt;/st1:place&gt;&lt;/st1:State&gt; secretary of state's is free and open. Anybody can just simply sign up and get a password and in a minute you can get right in. [The site &lt;b&gt;&lt;span style='font-weight:bold'&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;taxonomyId=13&amp;amp;articleId=9015196"&gt;has temporarily blocked online access&lt;/a&gt;&lt;/span&gt;&lt;/b&gt; to some records as a result of Ostergren's complaints.] If I want to, I can use a fake name and a fake e-mail account. No one knows who's signing up or who's accessing the records. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;But some states and counties require you to pay for these records, don't they? &lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial; color:black'&gt;A subscription is no protection. In &lt;st1:State w:st="on"&gt;Virginia&lt;/st1:State&gt;, for $25 you can sign up to access &lt;st1:place w:st="on"&gt;&lt;st1:PlaceName w:st="on"&gt;Fairfax&lt;/st1:PlaceName&gt;  &lt;st1:PlaceType w:st="on"&gt;County&lt;/st1:PlaceType&gt;&lt;/st1:place&gt;, home of Supreme Court justices, home of the FBI, the CIA, Pentagon officials. You have to sign up, you have to give your name and your address and a notarized signature. But big deal. Seven hijackers (involved in the 9/11 attacks) got their fake &lt;st1:State w:st="on"&gt;&lt;st1:place w:st="on"&gt;Virginia&lt;/st1:place&gt;&lt;/st1:State&gt; drivers license based on a fake notary. So who's to know what's real? You could give them a cell phone number and who's to know that it is not really in &lt;st1:country-region w:st="on"&gt;India&lt;/st1:country-region&gt; or in &lt;st1:City w:st="on"&gt;&lt;st1:place  w:st="on"&gt;Timbuktu&lt;/st1:place&gt;&lt;/st1:City&gt;? I send in $25 and I get a password and a username back in three days or so and then I'm in there sitting on 33 million records and about 5 million Social Security numbers. What's to stop me from having everyone in my neighborhood come to my house and use my computer? How is the clerk of the court in &lt;st1:place w:st="on"&gt;&lt;st1:PlaceName w:st="on"&gt;Fairfax&lt;/st1:PlaceName&gt;  &lt;st1:PlaceType w:st="on"&gt;County&lt;/st1:PlaceType&gt;&lt;/st1:place&gt; going to know who is sitting at my chair in front of my computer? That's where you lose control of those records. There are people downloading them by the gazillions. I'm not saying that public records should not be open. I am saying they should not be available online. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;What are states doing about it? &lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size: 11.0pt;font-family:Arial;color:black'&gt;There are some states like &lt;st1:State w:st="on"&gt;&lt;st1:place w:st="on"&gt;Florida&lt;/st1:place&gt;&lt;/st1:State&gt; that passed a law giving clerks and recorders until Jan. 1, 2008, to get Social Security numbers offline. If a person found out that their Social Security number was online, they can put in a written request and have it removed. In December 2005, &lt;st1:State w:st="on"&gt;&lt;st1:place w:st="on"&gt;North Carolina&lt;/st1:place&gt;&lt;/st1:State&gt; passed a law allowing citizens to remove their Social Security numbers and a couple of other things like driver's license numbers from online records. A person can put in a written request to have their personal information removed. What's the problem with that? Well, it puts the burden on the citizens, and most of them don't even know this little scheme is going on until they get a phone call from me. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;What's your advice to people on this issue? &lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt;I believe one person can make a difference. I have woken people up. I always hear from people and they are always thanking me for what I am doing. And I say, 'Don't just thank me. Spread the word. Do something to help me.' When I die, somebody has to give me credit for what I've done. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;!-- HTMLBODY-LOCATED --&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;/div&gt;  </description><link>http://www.made4biz-security.com/log/2007/04/what-if-id-thieves-couldnt-use-stolen.html</link><author>Made4biz Security</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-2262246624488345296</guid><pubDate>Thu, 05 Apr 2007 17:18:00 +0000</pubDate><atom:updated>2007-04-05T17:21:34.814Z</atom:updated><title>Dynamic Security is the only solution. Need I say more?</title><description>&lt;div class=Section1&gt;  &lt;h1&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Don't use WEP for Wi-Fi security, researchers say&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/h1&gt;  &lt;p class=MsoNormal&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black;font-weight:bold'&gt;Peter Sayer&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size: 11.0pt;font-family:Arial;color:black'&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;&lt;!-- begin 336x280 ad tag --&gt;April 04, 2007&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt; (IDG News Service) The Wi-Fi security protocol WEP should not be relied on to protect sensitive material, according to three German security researchers who have discovered a faster way to crack it. They plan to demonstrate their findings at a security conference in &lt;st1:State w:st="on"&gt;&lt;st1:place w:st="on"&gt;Hamburg&lt;/st1:place&gt;&lt;/st1:State&gt; this weekend. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Mathematicians showed as long ago as 2001 that the RC4 key scheduling algorithm underlying the WEP (Wired Equivalent Privacy) protocol was flawed, but attacks on it required the interception of around 4 million packets of data in order to calculate the full WEP security key. Further flaws found in the algorithm have brought the time taken to find the key down to a matter of minutes -- not necessarily fast enough to break into systems that change their security keys every five minutes. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Now it takes just three seconds to extract a 104-bit WEP key from intercepted data using a 1.7-GHz Pentium M processor. The necessary data can be captured in less than a minute, and the attack requires so much less computing power than previous attacks that it could even be performed in real time by someone walking through an office. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Anyone using Wi-Fi to transmit data they want to keep private, whether it's banking details or just e-mail, should consider switching from WEP to a more robust encryption protocol, the researchers said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;We think this can even be done with some PDAs or mobile phones, if they are equipped with wireless LAN hardware,&amp;quot; said Erik Tews, a researcher in the computer science department at Darmstadt University of Technology in &lt;st1:place w:st="on"&gt;&lt;st1:City w:st="on"&gt;Darmstadt&lt;/st1:City&gt;,  &lt;st1:country-region w:st="on"&gt;Germany&lt;/st1:country-region&gt;&lt;/st1:place&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Tews, along with colleagues Ralf-Philipp Weinmann and Andrei Pyshkin, published a paper about the attack, showing that their method needs far less data to find a key than previous attacks: Just 40,000 packets are needed for a 50% chance of success and 85,000 packets for a 95% chance, they said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Although stronger encryption methods have come along since the first flaws in WEP were discovered, the new attack is still relevant, the researchers said. Many networks still rely on WEP for security: 59% of the 15,000 Wi-Fi networks surveyed in a large German city in September 2006 used it, with only 18% using the newer WPA (Wi-Fi Protected Access) protocol to encrypt traffic. A survey of 490 networks in a smaller German city last month found 46% still using WEP and 27% using WPA. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;In both surveys, over a fifth of networks used no encryption at all, the researchers said in their paper. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Businesses can still protect their networks from the attack, even if they use old hardware incapable of handling the newer WPA encryption. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;For one thing, the researchers said, their attack is active: In order to gather enough of the right kind of data, they send out Address Resolution Protocol requests, prompting computers on the network under attack to reply with unencrypted packets of an easily recognizable length. This should be enough to alert an intrusion-detection system to the attack, they said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Another way to defeat such attacks, which use statistical techniques to identify a number of possible keys and then select the one most likely to be correct for further analysis, is to hide the real security key in a cloud of dummy ones. That's the approach taken by AirDefense Inc. in its WEP Cloaking product, which was released Monday. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;The technique means that businesses can cost-effectively protect networks using old hardware, such as point-of-sale systems, without the need to upgrade every terminal or base station, the company said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;If a network supports WPA encryption, though, users should rely on that instead of WEP to protect private data, Tews said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;Depending on your skills, it will cost you some minutes to some hours to switch your network to WPA. If it would cost you more than some hours of work if such private data becomes public, then you should not use WEP anymore,&amp;quot; he said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;!-- HTMLBODY-LOCATED --&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;/div&gt;  </description><link>http://www.made4biz-security.com/log/2007/04/dynamic-security-is-only-solution-need.html</link><author>Made4biz Security</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-7773123470595174752</guid><pubDate>Thu, 05 Apr 2007 10:39:00 +0000</pubDate><atom:updated>2007-04-05T10:42:26.465Z</atom:updated><title></title><description>&lt;div class=Section1&gt;  &lt;h1&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Five best practices for mitigating zero-day threats like Windows ANI &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/h1&gt;  &lt;p class=MsoNormal&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black;font-weight:bold'&gt;Jaikumar Vijayan&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size: 11.0pt;font-family:Arial;color:black'&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;&lt;!-- begin 336x280 ad tag --&gt;April 03, 2007&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt; (Computerworld) The &lt;b&gt;&lt;span style='font-weight:bold'&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;taxonomyName=windows&amp;amp;articleId=9015343"&gt;Windows animation bug&lt;/a&gt;&lt;/span&gt;&lt;/b&gt; (ANI) caused widespread concern because exploits against it became widely available before Microsoft Corp. &lt;b&gt;&lt;span style='font-weight:bold'&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9015498"&gt;could release a patch&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;. But like other zero-day threats before it, there are measures companies can take to at least try to mitigate the risk from unpatched vulnerabilities, security experts said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;The measures are not a sure bet. And in the end, patching a flaw is still the most reliable way of protecting against exploits seeking to take advantage of it, they said. But deploying multiple layers of defenses is vital to dealing with threats for which no immediate fix is available. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Among them are the following: &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;Restrict e-mail attachments&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial; color:black'&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;One of the ways hackers hope to exploit the ANI flaw -- which Microsoft patched earlier today -- is by trying to get users to click on malicious attachments in spammed e-mails. One way of dealing with this sort of an attack vector is by having strict policies in place for filtering out e-mail attachments. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Security experts have for a long time now advised companies to filter out gif, JPEG, WMV and pretty much most attachment types they don't need from inbound and outbound e-mails. When deciding which attachments to allow and which to deny, it's a mistake to assume that only certain attachment types are maliciously used, said Russ Cooper, senior information security analyst with Cybertrust Inc. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;Don't go on the basis of whether something is benign or not,&amp;quot; Cooper said. After all, both gif and JPEG attachments were once considered benign until hackers started hiding malicious code in them. &amp;quot;Instead, look at what you need for your business,&amp;quot; he said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;If there is a business need for accepting e-mails with attachments -- from a business partner, for example -- see if there's a way to restrict them to just that business partner. Or if you need to exchange zip files, for instance, consider the possibility of renaming the extension to something that just your company and your business partner knows -- and permit only attachments with that extension into your network, Cooper said. &amp;quot;Then you can put gif, JPEG and even animated cursors if you have a need for them into those attachments,&amp;quot; he said. &amp;quot;If you say 'I only want to allow these attachments and nothing else,' you have eliminated every zero-day&amp;quot; threat via e-mail attachments, he said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;Disable HTML e-mail&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial; color:black'&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Hackers and other bad guys like HTML e-mail because it allows them to more easily hide and deliver attack code to a desktop. For instance, several of Microsoft's e-mail clients, including Outlook Express and Windows Mail for &lt;st1:place w:st="on"&gt;Vista&lt;/st1:place&gt;, are vulnerable to attacks that insert a malicious ANI file in an HTML message. Disabling HTML can help mitigate this risk, Cooper said. By doing so, you are also blunting a lot of the phishing attacks that attempt to get users to click on URL links to malicious sites, he said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;Keep an eye on the LAN&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial; color:black'&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Consider tools that don't rely on virus signatures alone to detect infected systems. Instead, implement a way to quickly detect a compromised system by any anomalous behavior it might exhibit, said Lloyd Hession, chief security officer at BT Radianz, a New York-based company that offers telecommunications services to the financial industry. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Also have a way to limit the damage an infected system can do to other LAN-connected systems, he said. BT Radianz, for instance, uses a tool that allows it control over the connections a desktop makes with other systems within the LAN. &amp;quot;Under the previous model, you could go anywhere in the network once you are within the network,&amp;quot; Hession said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Now, there are rules that specify what parts of a network to which a system is allowed access. The rules also spell out what systems that same system can connect to based on the user's business requirements. Such control can help mitigate the risk of an infected computer spreading malicious code to other systems within a network. &amp;quot;You need to smarten the intelligence within the local network&amp;quot; to detect zero-day attacks faster, he said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;Filter outbound traffic&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial; color:black'&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;It's not enough just to inspect the traffic that's coming into your network; it's vital also to keep an eye on what's going out. Many Trojans or bot programs that get installed communicate with a remote system for further instructions on what to do next or what to download. Using outbound proxies or firewalls to look for and block such communications is one way to prevent Trojans and bots from calling home, said Johannes Ullrich, chief technology officer at the SANS Internet Storm Center (ISC) in Bethesda, Md. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Consider implementing a &amp;quot;default deny&amp;quot; capability at the perimeter, Cooper added. The idea is to permit only specific traffic in and out of a network gateway, while blocking everything else by default, Cooper said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;What we are talking about is inbound and outbound rules on your router&amp;quot; to block, for example, outbound IRC attempts and SMTP requests, he said. To get an idea of what traffic to permit through the network, log all inbound and outbound router activity for a period of time and use that information to decide what's permissible and what's not, he said. &amp;quot;If you are worried about breaking functionality, allow everything that has been going through anyway and deny everything else,&amp;quot; he said. &amp;quot;It's a great starting point.&amp;quot; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Increasingly, Trojans and bot programs have begun using well-known ports such as Port 80 to communicate with the remote systems controlling them. That makes it harder to detect such traffic using outbound filtering, Hession said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;Turn off JavaScript; don't give users administrative privileges&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Turning off JavaScript would have prevented some of the Web-embedded ANI exploits from reaching the user via the browser, Ullrich said. Restricting administrative privileges would have mitigated the fallout from an exploit by ensuring that a remote hacker wouldn't gain full administrative control of a system. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Ultimately, &amp;quot;you are less likely to go into emergency patch mode if you have other measures in place&amp;quot; for dealing with such threats, said Ken Dunham, director of Verisign Inc.'s iDefense rapid response team. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Such measures include content filtering at the gateway for ANI files, using updated antivirus software, using snort signature to identify and initiate responses to possible attacks from remote sites and user education, Dunham said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;!-- HTMLBODY-LOCATED --&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;/div&gt;  </description><link>http://www.made4biz-security.com/log/2007/04/five-best-practices-for-mitigating-zero.html</link><author>Made4biz Security</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-3071526605603906354</guid><pubDate>Tue, 03 Apr 2007 14:20:00 +0000</pubDate><atom:updated>2007-04-03T14:23:42.405Z</atom:updated><title>it seems that we aught to speed up IDentiWall to kill all that phishing</title><description>&lt;div class=Section1&gt;  &lt;h1&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Theft of 45.6M Card Numbers Largest Heist Yet&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/h1&gt;  &lt;p class=MsoNormal&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black;font-weight:bold'&gt;Jaikumar Vijayan&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size: 11.0pt;font-family:Arial;color:black'&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p style='margin-bottom:12.0pt'&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black;font-weight:bold'&gt;&lt;!-- begin 336x280 ad tag --&gt;April 02, 2007&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt; (Computerworld) After more than two months of refusing to reveal the size and scope of the high-profile intrusion into its systems, The TJX Companies Inc. finally disclosed details about the extent of the compromise. &lt;br&gt; &lt;br&gt; In filings with the U.S. Securities and Exchange Commission last week, the company said 45.6 million credit and debit card numbers were stolen from two of its systems over a period of more than 18 months by an unknown number of intruders. &lt;br&gt; &lt;br&gt; That total eclipses the 40million records compromised in the mid-2005 breach at the former CardSystems Solutions Inc., and makes the TJX incident the worst publicly disclosed compromise involving the loss of personal card data. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 color="#999999" face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:#999999'&gt;&lt;img width=259 height=178 id="_x0000_i1031" src="cid:image001.jpg@01C77614.610E9E80" style='margin-bottom:5px' alt="The systems that were broken into were located at TJX&amp;#8217;s Framingham, Mass., headquarters. The theft is the worst on record involving personal data." border=0&gt;&lt;br&gt; The systems that were broken into were located at TJX&amp;#8217;s &lt;st1:place w:st="on"&gt;&lt;st1:City  w:st="on"&gt;Framingham&lt;/st1:City&gt;, &lt;st1:State w:st="on"&gt;Mass.&lt;/st1:State&gt;&lt;/st1:place&gt;, headquarters. The theft is the worst on record involving personal data.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class=MsoNormal style='margin-bottom:12.0pt'&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt;&lt;br&gt; &lt;br&gt; In addition, personal data provided in connection with the return of merchandise without receipts by about 451,000 people in 2003 was also stolen, the filing said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;table class=MsoNormalTable border=0 cellspacing=0 cellpadding=0 width=250  bgcolor=black style='width:187.5pt;background:black'&gt;  &lt;tr&gt;   &lt;td style='padding:.75pt .75pt .75pt .75pt'   background="/common/images/site/features/1-pixel_fade.gif"&gt;   &lt;div&gt;   &lt;p class=MsoNormal align=center style='text-align:center'&gt;&lt;b&gt;&lt;font size=2   color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;   color:black;font-weight:bold'&gt;Disappearing Data&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/div&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr&gt;   &lt;td valign=top style='padding:.75pt .75pt .75pt .75pt'&gt;   &lt;table class=MsoNormalTable border=0 cellspacing=0 cellpadding=0 width="100%"    bgcolor="#C64731" style='width:100.0%;background:#C64731'&gt;    &lt;tr height=18 style='height:13.4pt'&gt;     &lt;td rowspan=2 valign=top bgcolor=white style='background:white;padding:     3.0pt 3.0pt 3.0pt 3.0pt;height:13.4pt'&gt;     &lt;h2 align=center style='text-align:center'&gt;&lt;b&gt;&lt;font size=2 color=black     face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt;Top     Commercial Card Data Breaches in &lt;st1:country-region w:st="on"&gt;&lt;st1:place      w:st="on"&gt;U.S.&lt;/st1:place&gt;&lt;/st1:country-region&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/h2&gt;     &lt;div class=MsoNormal align=center style='text-align:center'&gt;&lt;font size=2     color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;     color:black'&gt;     &lt;hr size=2 width="100%" align=center&gt;     &lt;/span&gt;&lt;/font&gt;&lt;/div&gt;     &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span     style='font-size:11.0pt;font-family:Arial;color:black'&gt;&amp;#8226;&amp;nbsp;&amp;nbsp;The TJX     Companies Inc. - 46.5 million &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;     &lt;div class=MsoNormal align=center style='text-align:center'&gt;&lt;font size=2     color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;     color:black'&gt;     &lt;hr size=2 width="100%" align=center&gt;     &lt;/span&gt;&lt;/font&gt;&lt;/div&gt;     &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span     style='font-size:11.0pt;font-family:Arial;color:black'&gt;&amp;#8226;&amp;nbsp;&amp;nbsp;CardSystems     Solutions Inc. - 40 million &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;     &lt;div class=MsoNormal align=center style='text-align:center'&gt;&lt;font size=2     color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;     color:black'&gt;     &lt;hr size=2 width="100%" align=center&gt;     &lt;/span&gt;&lt;/font&gt;&lt;/div&gt;     &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span     style='font-size:11.0pt;font-family:Arial;color:black'&gt;&amp;#8226;&amp;nbsp;&amp;nbsp;iBill     Internet - 17.8 million &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;     &lt;div class=MsoNormal align=center style='text-align:center'&gt;&lt;font size=2     color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;     color:black'&gt;     &lt;hr size=2 width="100%" align=center&gt;     &lt;/span&gt;&lt;/font&gt;&lt;/div&gt;     &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span     style='font-size:11.0pt;font-family:Arial;color:black'&gt;&amp;#8226;&amp;nbsp;&amp;nbsp;BJ&amp;#8217;s     Wholesale Club Inc. - 8 million &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;     &lt;div class=MsoNormal align=center style='text-align:center'&gt;&lt;font size=2     color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;     color:black'&gt;     &lt;hr size=2 width="100%" align=center&gt;     &lt;/span&gt;&lt;/font&gt;&lt;/div&gt;     &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span     style='font-size:11.0pt;font-family:Arial;color:black'&gt;&amp;#8226;&amp;nbsp;&amp;nbsp;Circuit     City Stores Inc. - 2.6 million&lt;br&gt;     &lt;br&gt;     &lt;b&gt;&lt;span style='font-weight:bold'&gt;Source:&lt;/span&gt;&lt;/b&gt; Privacy Rights     Clearinghouse&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;     &lt;/td&gt;     &lt;td style='height:13.4pt;border:none' width=0 height=18&gt;&lt;/td&gt;    &lt;/tr&gt;    &lt;tr height=18 style='height:13.4pt'&gt;     &lt;td style='height:13.4pt;border:none' width=0 height=18&gt;&lt;/td&gt;    &lt;/tr&gt;   &lt;/table&gt;   &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span   style='font-size:11.0pt;font-family:Arial;color:black'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt; &lt;/table&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size: 11.0pt;font-family:Arial;color:black'&gt;&lt;br&gt; &lt;br&gt; Avivah Litan, an analyst at Gartner Inc., expressed surprise at the scope of the breach. &amp;#8220;I had heard rumors that it was bigger than CardSystems, but I was still somewhat shocked it was actually this big.&amp;#8221; &lt;br&gt; &lt;br&gt; The number of stolen records &amp;#8220;makes this the biggest card heist ever,&amp;#8221; Litan said. &amp;#8220;It proves there are very sophisticated cybercriminals out there at large who have the potential to wreak havoc on pure-payment systems. If this isn&amp;#8217;t a wake-up call for stronger card and payment system security, I&amp;#8217;m not sure what is.&amp;#8221; &lt;br&gt; &lt;br&gt; In its filing, TJX said it is in the process of contacting individuals affected by the breach. &lt;br&gt; &lt;br&gt; &amp;#8220;Given the scale and geographic scope of our business and computer systems and the time frames involved in the computer intrusion, our investigation has required a substantial period of time to date and is not completed,&amp;#8221; the company said. &lt;br&gt; &lt;br&gt; Framingham, Mass.-based TJX, the owner of T.J. Maxx, Marshalls and Bob&amp;#8217;s Stores, disclosed inJanuary that someone had illegally accessed one of its payment systems and stolen card data from an unspecified number of customers in the U.S., Canada, Puerto Rico, the U.K. and Ireland. &lt;br&gt; &lt;br&gt; At the time, TJX said it believed the intrusion took place in May 2006 but wasn&amp;#8217;t discovered until mid-December &amp;#8212; seven months later. A few weeks after its initial disclosure of the breach, the company said that an investigation by IBM and General Dynamics Corp. had concluded that the intrusion may have taken place in July 2005. &lt;br&gt; &lt;br&gt; TJX has confirmed that its systems were first accessed in July 2005 and then on several more occasions in 2005, 2006 and even in mid-January 2007 &amp;#8212; after the breach was discovered. However, no data appears to have been stolen after Dec. 18, when the intrusion was first noticed, it said. &lt;br&gt; &lt;br&gt; The systems that were broken into, which were located at the company&amp;#8217;s headquarters, processed and stored data related to payment cards, checks and merchandise returned without receipts. &lt;br&gt; &lt;br&gt; The data breach affected customers of TJX&amp;#8217;s T.J. Maxx, Marshalls, HomeGoods and A.J. Wright stores in the &lt;st1:country-region w:st="on"&gt;U.S.&lt;/st1:country-region&gt; and &lt;st1:place w:st="on"&gt;Puerto Rico&lt;/st1:place&gt;. Also affected were customers of its Winners and HomeSense stores in &lt;st1:country-region w:st="on"&gt;Canada&lt;/st1:country-region&gt; and TK Maxx stores in the &lt;st1:country-region w:st="on"&gt;&lt;st1:place w:st="on"&gt;U.K.&lt;/st1:place&gt;&lt;/st1:country-region&gt;, the company said. &lt;br&gt; &lt;br&gt; The filing said the company is having difficulty determining exactly what kind of data was stolen, because a lot of the data is deleted by TJX in the normal course of business. &lt;br&gt; &lt;br&gt; &amp;#8220;In addition, the technology used by the intruder has, to date, made it impossible for us to determine the contents of most of the files we believe were stolen in 2006,&amp;#8221; the company said. It did not identify the technology. &lt;br&gt; &lt;br&gt; Customer names and addresses were not included with any of the card data believed stolen from the &lt;st1:City w:st="on"&gt;&lt;st1:place w:st="on"&gt;Framingham&lt;/st1:place&gt;&lt;/st1:City&gt; systems, TJX said. &lt;br&gt; &lt;br&gt; The company said that by April 3, 2006, it had begun to mask payment card personal identification number data, &amp;#8220;some other portions of payment card transaction information&amp;#8221; and check transaction data. &lt;br&gt; &lt;br&gt; The company reported that it has spent about $5million in connection with the breach. It warned that potential future costs are still undetermined and noted that several lawsuits have been filed against it since the breach was announced. &lt;br&gt; &lt;br&gt; One TJX shareholder, the Arkansas Carpenters Pension Fund, recently sued the company for its failure to divulge more details about the breach. &lt;br&gt; &lt;br&gt; TJX&amp;#8217;s disclosure came just days after six &lt;st1:State w:st="on"&gt;&lt;st1:place  w:st="on"&gt;Florida&lt;/st1:place&gt;&lt;/st1:State&gt; residents were arrested and charged with launching a multimillion-dollar statewide credit card fraud ring using information stolen from the company. Losses experienced by Wal-Mart Stores Inc. and other retailers due to the fraud have so far totaled at least $8 million.&lt;/span&gt;&lt;/font&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;/div&gt;  </description><link>http://www.made4biz-security.com/log/2007/04/it-seems-that-we-aught-to-speed-up.html</link><author>Made4biz Security</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-8487715114521345320</guid><pubDate>Sun, 01 Apr 2007 09:13:00 +0000</pubDate><atom:updated>2007-04-01T09:16:36.363Z</atom:updated><title>Dynamic Security with the IDentiWall option could resolve the issue for them</title><description>&lt;div class=Section1&gt;  &lt;h1&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Failed VA security contract was 'an open checkbook,' report says&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/h1&gt;  &lt;p class=MsoNormal&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black;font-weight:bold'&gt;Jaikumar Vijayan&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size: 11.0pt;font-family:Arial;color:black'&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;&lt;!-- begin 336x280 ad tag --&gt;March 29, 2007&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt; (Computerworld) A 10-year, $103 million contract for a security incident response center at the Department of Veterans Affairs (VA) had to be aborted after less than three years because of funding problems caused by bad planning and administration. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Instead of yielding a state-of-the-art security readiness and response capability, the contract became &amp;quot;an open checkbook&amp;quot; that resulted in the award of nearly two dozen noncompetitive task orders, inflated prices, overpayments and unaccounted-for equipment purchases totaling $35 million. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Those are just some of the findings of an audit by VA Inspector General George Opfer into the planning, award and administration of the Central Incident Response Capability (CIRC) contract awarded to the Veterans Affairs Security Team LLC (VAST) in July 2002. VAST was incorporated as a Texas-based limited liability corporation one week before the contract was awarded. The now-defunct company was owned by several small businesses led by Washington-based SecureInfo Corp. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;According to Opfer's report, much of the problems with the $102.7 million CIRC contract had to do with the addition of requirements for a Managed Security Services (MSS) component. While there appears to have been adequate acquisition planning for the CIRC requirements, there is no evidence of similar planning for MSS requirements, the report said. In fact, it is still unclear when the decision was made to include MSS requirements in the CIRC contract. There is also no documentation to show that the VA's program office considered at any point whether it would make sense to award separate contracts. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;We found that deficiencies in the planning, solicitation, evaluation of proposals, award and administration of the contract for MSS resulted in uncontrolled spending, overpayments and illegal contracting actions that resulted in the ultimate demise of the contract due to lack of funding,&amp;quot; Opfer said in his report. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;One modification -- made three months after the contract was awarded to VAST -- added new language that changed the MSS component from a firm fixed-price contract to a so-called Indefinite Delivery Indefinite Quantity contract. &amp;quot;The modification allowed VA to issue task orders to fill requests from field facilities and Office of Cyber Security for MSS at additional cost,&amp;quot; Opfer said in his report. The VA began issuing such task orders in August, shortly after the contract was signed -- even though the contract change that legitimized such orders was not made until October, the report said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Under the original pact awarded to VAST in 2002, $82.9 million was earmarked for recurring labor costs over 10 years, with the remaining $19.8 million meant for equipment and supply costs. But because of the task orders, the potential value of the contract shot up from $102.7 million to about $250 million. Though this sort of a &amp;quot;cardinal change&amp;quot; was prohibited, it was still approved by the VA's Office of General Counsel. That approval came one day after counsel asked for an opinion on the modification by the officer in charge of the contract, Opfer noted in his report. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;This made the contract an open checkbook in that it resulted in the award of 22 noncompetitive task orders valued at approximately $48.6 million, with little assurance of price reasonableness and no planned funding,&amp;quot; the report said. At least 17 of the task orders were out of scope and thus prohibited changes under the original contract, Opfer said in his report. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;A lack of clarity surrounding the modifications may have resulted in VAST being overpaid about $3.8 million for MSS services it never delivered and an additional $4.7 million in duplicate payments. On top of that, the VA also spent about $35 million on equipment and supplies, but has no record of what the equipment is or where it may be. Because the VA revised the tasks that were the basis of the original award -- and sought new proposals from VAST -- it wound up paying about $6.76 million more than had been earmarked for the original contract in the first year. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;As a result of the errors, the VA managed had spent about $91.8 million in less than three years when the plug was pulled. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Opfer's report also blasted the VA's vendor selection process. Little due diligence appears to have been put into evaluating vendor qualifications and ensuring that the prices being quoted were reasonable. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;For instance, the CIRC contract was specifically meant for small businesses, which VAST was not, Opfer said. VAST, in its original response to the VA contract, described itself as a joint venture involving six small businesses teamed with three large businesses -- Compaq, Signal and SAIC. Such an association should have automatically disqualified VAST as a small business, the report said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Just before the contract was awarded, VAST also changed its status from joint venture to limited liability corporation with no small business status. And because VAST appeared to have no assets, the VA may be hard-pressed to recover any excess money it paid the company, the report said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Christopher Fountain, CEO of SecureInfo, disagreed with Opfer's conclusions and denied that VAST had been overpaid during its work for the VA. &amp;quot;At no time during the review were we alerted to any such concerns&amp;quot; by the IG's office, Fountain said. &amp;quot;They never told us they had found anything&amp;quot; that was a cause for concern during the review, he said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;In fact, when the contract was allowed to expire, it was VAST that incurred &amp;quot;several million dollars in liability&amp;quot; resulting from equipment purchases and other expenses, he said. Fountain also disagreed with Opfer's conclusion that VAST was not a small business. He maintained that the company was in fact a small business at all times during its contract with the VA. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;We believe that the government realized great value from the work we did perform for them,&amp;quot; Fountain said. &amp;quot;We believe we [set up] one of the most advanced security operations center in the federal government.&amp;quot; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Also disagreeing with Opfer's finding was the VA's acting general counsel. In a statement responding to Opfer's audit, the general counsel's office maintained that the modifications made to the CIRC contract were legal. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;But Robert Howard, the assistant secretary of IT for VA, said in a response that he concurred with the report's findings and had launched an inventory of equipment as recommended by Opfer. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;The VA did not respond to a request for comment. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;!-- HTMLBODY-LOCATED --&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;/div&gt;  </description><link>http://www.made4biz-security.com/log/2007/04/dynamic-security-with-identiwall-option.html</link><author>Made4biz Security</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-280126039999068636</guid><pubDate>Sun, 01 Apr 2007 09:11:00 +0000</pubDate><atom:updated>2007-04-01T09:14:32.946Z</atom:updated><title>IDentiWall is the solution for human errors</title><description>&lt;div class=Section1&gt;  &lt;h1&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;TJX data breach: At 45.6M card numbers, it's the biggest ever&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/h1&gt;  &lt;p class=MsoNormal&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black;font-weight:bold'&gt;Jaikumar Vijayan&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size: 11.0pt;font-family:Arial;color:black'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;&lt;!-- begin 336x280 ad tag --&gt;March 29, 2007&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt; (Computerworld) After more than two months of refusing to reveal the size and scope of its data breach, TJX Companies Inc. is finally offering more details about the extent of the compromise. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;In filings with the U.S. Securities and Exchange Commission yesterday, the company said 45.6 million credit and debit card numbers were stolen from one of its systems over a period of more than 18 months by an unknown number of intruders. That number eclipses the 40 million records compromised in the mid-2005 breach at CardSystems Solutions and makes the TJX compromise the worst ever involving the loss of personal data. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;In addition, personal data provided in connection with the return of merchandise without receipts by about 451,000 individuals in 2003 was also stolen. The company is in the process of contacting individuals affected by the breach, TJX said in its filings. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;Given the scale and geographic scope of our business and computer systems and the time frames involved in the computer intrusion, our investigation has required a substantial period of time to date and is not completed,&amp;quot; the company said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Framingham, Mass.-based TJX is the owner of a number of retail brands, including T.J.Maxx, &lt;st1:City w:st="on"&gt;&lt;st1:place  w:st="on"&gt;Marshalls&lt;/st1:place&gt;&lt;/st1:City&gt; and Bob's Stores. In January, the company announced that someone &lt;b&gt;&lt;span style='font-weight:bold'&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9009158"&gt;had illegally accessed one of its payment systems&lt;/a&gt;&lt;/span&gt;&lt;/b&gt; and made off with card data belonging to an unspecified number of customers in the U.S., Canada, Puerto Rico and potentially the U.K. and Ireland. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;At the time, TJX said it believed the intrusion took place in May 2006 but wasn't discovered until mid-December -- seven months later. A few weeks later, the company revised those dates and said that an investigation by IBM and General Dynamics, two companies it hired in the wake of the breach discovery, believed the intrusion may have taken place in July 2005. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Several banks and credit unions around the country and in the other affected regions had to block and reissue thousands of payment cards as a result of the breach. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;In its filing, TJX confirmed that its systems were first accessed illegally in July 2005 and then on several occasions later in 2005, 2006 and even once in mid-January 2007 -- after the breach had already been discovered. However, no data appears to have been stolen after Dec. 18, when the intrusion was first noticed. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;The systems that were broken into were based in &lt;st1:City w:st="on"&gt;&lt;st1:place w:st="on"&gt;Framingham&lt;/st1:place&gt;&lt;/st1:City&gt; and processed and stored information related to payment cards, checks and merchandise returned without receipts. The data breach affected customers of its T.J.Maxx, Marshalls, HomeGoods and A.J. Wright stores in the &lt;st1:country-region w:st="on"&gt;U.S.&lt;/st1:country-region&gt; and &lt;st1:place w:st="on"&gt;Puerto Rico&lt;/st1:place&gt;. Also affected were customers of its Winners and HomeSense stores in &lt;st1:country-region w:st="on"&gt;Canada&lt;/st1:country-region&gt; and TK Maxx stores in the &lt;st1:country-region w:st="on"&gt;&lt;st1:place w:st="on"&gt;U.K.&lt;/st1:place&gt;&lt;/st1:country-region&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;It is hard to know exactly what kind of data was stolen because a lot of the information accessed by intruders was deleted by the company in the normal course of business. &amp;quot;In addition, the technology used by the intruder has, to date, made it impossible for us to determine the contents of most of the files we believe were stolen in 2006,&amp;quot; the company said. It did not elaborate on the technology it was referring to. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Customer names and addresses were not included with any of the payment card data believed stolen from the &lt;st1:City w:st="on"&gt;&lt;st1:place  w:st="on"&gt;Framingham&lt;/st1:place&gt;&lt;/st1:City&gt; systems, TJX said. Also, the company &amp;quot;generally&amp;quot; did not store Track 2 data from the magnetic stripe on the back of payment cards for transactions after September 2003, TJX said. Also by April 3, 2006, the company had begun to mask payment card PIN data and &amp;quot;some other portions of payment card transaction information&amp;quot; as well as check transaction information, the company said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;We are continuing to try to identify information stolen in the computer intrusion through our investigation, but other than the information provided ... we believe that we may never be able to identify much of the information believed stolen,&amp;quot; TJX said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;The company has so far spent about $5 million in connection with the breach, although it is hard to say what other costs may be incurred, the company warned. It cited several lawsuits that have been filed against it since the breach was announced. The company was sued recently by the Arkansas Carpenters Pension Fund, one of its shareholders, for its failure to divulge more details about the breach. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Avivan Litan, an analyst with Stamford,Conn.based Gartner Inc., expressed surprise at the scope of the breach. &amp;quot;I had heard rumors that it was bigger than CardSystems, but I was still somewhat shocked it was actually this big.&amp;quot; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;The number involved in the breach &amp;quot;makes this the biggest card heist ever,&amp;quot; she said. &amp;quot;It proves there are still very sophisticated cybercriminals out there at large who have the potential to wreak havoc on pure-payment systems and who have already stolen millions of dollars from consumers and financial institutions,&amp;quot; she said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;If this isn't a wakeup call for stronger card and payment system security, I'm not sure what is,&amp;quot; she said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;TJX's disclosure comes just days after six &lt;st1:State w:st="on"&gt;&lt;st1:place w:st="on"&gt;Florida&lt;/st1:place&gt;&lt;/st1:State&gt; residents were arrested for allegedly launching a multimillion-dollar statewide credit card fraud ring &lt;b&gt;&lt;span style='font-weight:bold'&gt;&lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9013942"&gt;using information stolen from the company&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;. Losses experienced by Wal-Mart Stores Inc. and other retailers because of the fraud have so far totaled at least $8 million. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;/div&gt;  </description><link>http://www.made4biz-security.com/log/2007/04/identiwall-is-solution-for-human-errors.html</link><author>Made4biz Security</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-5958324994582130247</guid><pubDate>Wed, 28 Mar 2007 17:30:00 +0000</pubDate><atom:updated>2007-03-28T17:33:36.647Z</atom:updated><title>The coming IDentiWall era will protect us from phishers and ID thieves </title><description>&lt;div class=Section1&gt;  &lt;h1&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Web attacks get personal&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/h1&gt;  &lt;p class=MsoNormal&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black;font-weight:bold'&gt;Matt Hines&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size: 11.0pt;font-family:Arial;color:black'&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;&lt;!-- begin 336x280 ad tag --&gt;March 27, 2007&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt; (InfoWorld) Malware purveyors are increasingly tailoring their virus distribution and attack techniques to take advantage of different classes of end-users, according to researchers with the Internet Security Systems' X-Force team at IBM. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Top experts with the Atlanta-based research operation said that malware writers, phishing scheme operators, and botnet herders are more frequently employing so-called personalization tools to make their attacks more effective.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Much like the online marketing companies that gather bits of information to target advertising at individual Web users, cyber-criminals are creating malware outlets and code executions that scan readily-available details about users' computing habits and traits to find appropriate recipients for their work.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;The approach uses any information that is found to isolate the right attack to deliver based on factors like the particular Web browser or operating system that an individual who being targeted is using.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;By combining the more intelligent threat delivery approach with hard-to-detect Trojan, botnet, and cross-site scripting attacks, cutting-edge criminals are finding plenty of ways to take advantage of end users, said Gunter Ollman, director of security strategy for IBM ISS.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;With every Web page request, people send out a header that describes their browser and also tells you what language the request is being made in and sometimes even the cache level of the host it is running on; there's a lot of information in there, including the IP address of the person making the request,&amp;quot; Ollman said.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;According to X-Force's 2006 annual report on security trends, 30 percent of malicious Web sites were already using personalization techniques by the end of last year. The company said it is expecting that number to grow rapidly in 2007.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;By combining the IP address and all the host details in the browser, we're seeing that attackers build sites that ensure they only use exploits that will work against a specific host,&amp;quot; the expert said.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;In addition to determining which version of browser or OS software someone is using, many of the attacks can assess what level of security patch a particular program has in place, according to the researcher.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Cyber-criminals are also loading malware-infected Web pages with numerous code execution threats to assault many different aspects of varied sets of users with dozens of pieces of code being served up on a single URL.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Many of the threats are hidden in individual elements of Web pages, including flash files, pdfs and images, which may each contain multiple attacks meant to take advantage of different vulnerabilities.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Ollman said that ISS has also observed that these more advanced malware efforts are also collecting IP address information from end users to ensure that they don't repeatedly send the same threats to their computers. The smartest groups are also trading information about IP addresses known to be used by security researchers to keep their latest work from being discovered.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;If you browse that type of malware site, it will serve exploit code, but only try it once; they know that people might start to get suspicious if the same part of a site crashes twice or acts abnormally,&amp;quot; said Ollman. &amp;quot;These attackers don't want people to get copies of their new code or to know what sites they have hosting the content; they know that sites get closed down or added to black lists very quickly these days if they're not careful.&amp;quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Ollman said that most of the exploits do not deliver spyware, but instead pass along smaller files known as droppers that are less likely to be identified by anti-virus systems that sit quietly but then call out across the Internet and draw-in real malware programs.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Many of the eventual spyware programs that are downloaded are even stealthy, the researcher said. The attacks frequently wait until a user opens a specific site or application before springing to life and beginning to intercept users' details, according to ISS's research.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;!-- HTMLBODY-LOCATED --&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;/div&gt;  </description><link>http://www.made4biz-security.com/log/2007/03/coming-identiwall-era-will-protect-us.html</link><author>Made4biz Security</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-1424518352183500917</guid><pubDate>Wed, 28 Mar 2007 17:26:00 +0000</pubDate><atom:updated>2007-03-28T17:29:26.186Z</atom:updated><title>IDentiWall case</title><description>&lt;div class=Section1&gt;  &lt;h1&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;ID theft threats have surged 200% since Jan. 1&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/h1&gt;  &lt;p class=MsoNormal&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black;font-weight:bold'&gt;Gregg Keizer&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size: 11.0pt;font-family:Arial;color:black'&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;&lt;!-- begin 336x280 ad tag --&gt;March 28, 2007&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt; () Identity theft threats jumped 200% in the first two months of 2007, a security company said today, noting that fraudsters have shifted to simpler, more effective tactics. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Cyveillance Inc. of Arlington, Va., compiled data from its Internet sweeps to report that the average daily count of URLs hosting malicious downloads climbed to 60,000 in February, 200% over the December 2006 figure. A single-day spike in midmonth came close to 140,000 such sites. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;The traditional phishing technique is being replaced by putting a URL in the e-mail,&amp;quot; said Manoj Srivastava, Cyveillance's CTO. &amp;quot;The trend now is to use the browser as the attack vector.&amp;quot; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Phishing attacks have shifted from the usual e-mails that try to con users into visiting reproductions of legitimate pages, then duping them into entering their personal information. Instead, thieves simply stick a link in an e-mail message and count on users' gullibility. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;It works,&amp;quot; Todd Bransford, vice president of marketing for Cyveillance, said when asked what might be behind the rise. &amp;quot;It's proved to be a highly effective way of taking control of someone's PC.&amp;quot; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Malicious sites typically exploit browser vulnerabilities to conduct &amp;quot;drive-by&amp;quot; downloads, installing bot Trojans that let a hacker control the machine or password-stealing keyloggers on compromised systems. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Srivastava speculated that another reason for the rapid rise in malicious sites is, ironically, the effectiveness of antiphishing software. &amp;quot;The phishing detection business has gotten good -- ours included -- and [so] it's far easier to detect conventional phishing techniques&amp;quot; than to gauge the potential for harm from a Web site. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;The quick climb might also be a result of the increasing ease with which identity thefts are crafted. &amp;quot;[Phishing] kits have become common. It's so simple to launch attacks now that there's something of a geometric progression going on with the numbers,&amp;quot; said Srivastava. &amp;quot;The economics and risks involved being what they are, more people are learning about identity theft and how to make money from it. This looks like an inflection point.&amp;quot; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Cyveillance also uncovered hundreds of thousands of credit and debit card account numbers in its sweeps of IRC channels and server logs of botnet operators. In the first two months of the year, the company's monitoring technology found more than 320,000 credit and debit card numbers, more than 1.4 million potential Social Security numbers and approximately 1.3 million account log-on credentials. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;We're pretty solid on those numbers,&amp;quot; said Srivastava. Although the Social Security numbers were not actually verified, he said, they match the nine-digit criteria and the algorithm used to construct the numerical strings. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;!-- HTMLBODY-LOCATED --&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;/div&gt;  </description><link>http://www.made4biz-security.com/log/2007/03/identiwall-case.html</link><author>Made4biz Security</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-7003392274942664851</guid><pubDate>Wed, 28 Mar 2007 16:59:00 +0000</pubDate><atom:updated>2007-03-28T17:02:50.277Z</atom:updated><title>you can hide your information or you can also use IDentiWall</title><description>&lt;div class=Section1&gt;  &lt;h1&gt;&lt;st1:State w:st="on"&gt;&lt;st1:place w:st="on"&gt;&lt;b&gt;&lt;font size=2 color=black   face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt;Calif.&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/st1:place&gt;&lt;/st1:State&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial; color:black'&gt; official ends online access to public records with Social Security numbers&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/h1&gt;  &lt;p class=MsoNormal&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black;font-weight:bold'&gt;Jaikumar Vijayan&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size: 11.0pt;font-family:Arial;color:black'&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;&lt;!-- begin 336x280 ad tag --&gt;March 27, 2007&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt; (Computerworld) Three years after it first made available certain documents containing Social Security numbers and other sensitive data on its Web site, the &lt;st1:State w:st="on"&gt;&lt;st1:place w:st="on"&gt;California&lt;/st1:place&gt;&lt;/st1:State&gt; secretary of state's office last week finally shut down online access to the records because of identity theft concerns. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;In a statement &lt;b&gt;&lt;span style='font-weight:bold'&gt;&lt;a href="http://www.ss.ca.gov/executive/press_releases/2007/DB07_009.pdf" target=new&gt;(download PDF)&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;, Secretary of State Debra Bowen said her office was also freezing bulk electronic sales of its Uniform Commercial Code (UCC) database until all but the last four digits of Social Security numbers were removed from documents. There are approximately 2 million UCC filings on record with the secretary of state's office; about a third contain Social Security numbers. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Bowen said her office is considering using redaction technology to block out the first five digits of the Social Security numbers from UCC documents. And it has posted a warning online urging UCC filers not to include the numbers in their documents. Bowen also announced support for legislation sponsored by state Assembly member Dave Jones (D-Sacramento) that would require no more than four digits from an individual's Social Security number on public records -- both at the state and county levels. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Officials in Bowen's office could not be reached for comment. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;UCC documents are financial statement filed with the state by banks and other creditors when an individual takes out certain types of loans. The documents are considered public records and are available for purchase by the public. Over the past few years, several states have been posting images of such records on their Web sites without redacting any of the sensitive information -- much to the outrage of privacy advocates. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;This is yet another place where our laws haven't kept pace with advances in technology,&amp;quot; Bowen said in the statement. &amp;quot;To make the agency more business-friendly, previous Secretaries of State have made these records available on the Internet. However, until we find a way to remove all but the last four digits of people's Social Security numbers from the records in the electronic database, I've decided to pull the plug on the system.&amp;quot; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Bowen's decision came just weeks after her office was notified by Jones about the easy availability of Social Security numbers on its Web site, and the danger that poses for potential identity theft. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;An aide to Jones today described how he purchased about 20 UCC records from the site at $6 per record and discovered that 14 of them contained Social Security numbers, full names, addresses and even images of signatures. &amp;quot;It was totally easy to get those records,&amp;quot; said the aide, who asked his name not be used. All it involved was clicking through as a nonsubscriber, entering some basic contact information and credit card details and searching for records using common last names, he said. One record contained Social Security numbers for seven people. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;Californians like to fancy ourselves about being so good on privacy,&amp;quot; the aide said. &amp;quot;But what we saw on the site was mind-boggling.&amp;quot; Because state laws prohibit the posting of such information in public records at the county level, &amp;quot;it was surprising to see this happening at the state level.&amp;quot; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;But California is not the only state to post UCC documents on the Web, nor is it the first one to take the postings down, said B.J. Ostergren, a privacy advocate in Richmond, Va., who has been pressing state and county governments to remove such data from their Web sites. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Ostergren runs &lt;b&gt;&lt;span style='font-weight:bold'&gt;&lt;a href="http://www.opcva.com/watchdog/" target=new&gt;The Virginia Watchdog&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;, which has for the past several years documented cases where county governments and secretary of state offices around the country have routinely posted sensitive data online. Many are moving to block online access to the information because of heightened privacy concerns, she said. Some, such as the &lt;st1:State w:st="on"&gt;&lt;st1:place w:st="on"&gt;Ohio&lt;/st1:place&gt;&lt;/st1:State&gt; secretary of state's office, did so only after being threatened with a class action lawsuit. Even then, that state has not been entirely successful in removing the sensitive information. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Among the states that have pulled down images of UCC documents with Social Security numbers are &lt;st1:State w:st="on"&gt;Oregon&lt;/st1:State&gt;, &lt;st1:State w:st="on"&gt;Missouri&lt;/st1:State&gt;, &lt;st1:State w:st="on"&gt;New Mexico&lt;/st1:State&gt;, &lt;st1:State w:st="on"&gt;Vermont&lt;/st1:State&gt;, &lt;st1:State w:st="on"&gt;New York&lt;/st1:State&gt; and &lt;st1:State w:st="on"&gt;&lt;st1:place w:st="on"&gt;North Carolina&lt;/st1:place&gt;&lt;/st1:State&gt;, Ostergren said. But several other states continue to make UCC documents containing sensitive data either available for free or for purchase, she said. The list includes &lt;st1:State w:st="on"&gt;Florida&lt;/st1:State&gt;, &lt;st1:country-region w:st="on"&gt;Georgia&lt;/st1:country-region&gt;, &lt;st1:State w:st="on"&gt;Iowa&lt;/st1:State&gt;, &lt;st1:State w:st="on"&gt;Maryland&lt;/st1:State&gt; and &lt;st1:State w:st="on"&gt;&lt;st1:place w:st="on"&gt;Massachusetts&lt;/st1:place&gt;&lt;/st1:State&gt;, Ostergren said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;!-- HTMLBODY-LOCATED --&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;/div&gt;  </description><link>http://www.made4biz-security.com/log/2007/03/you-can-hide-your-information-or-you.html</link><author>Made4biz Security</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-2992172793208393217</guid><pubDate>Wed, 28 Mar 2007 16:56:00 +0000</pubDate><atom:updated>2007-03-28T16:59:27.107Z</atom:updated><title>IDentiWall, IDentiWall, IDentiWall.......</title><description>&lt;div class=Section1&gt;  &lt;h1&gt;&lt;st1:country-region w:st="on"&gt;&lt;st1:place w:st="on"&gt;&lt;b&gt;&lt;font size=2   color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;   color:black'&gt;UK&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/st1:place&gt;&lt;/st1:country-region&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial; color:black'&gt; e-crime chief: Cyber criminals are undeterred&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/h1&gt;  &lt;p class=MsoNormal&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black;font-weight:bold'&gt;Jeremy Kirk&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size: 11.0pt;font-family:Arial;color:black'&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;&lt;!-- begin 336x280 ad tag --&gt;March 27, 2007&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt; (IDG News Service) Last year, the &lt;st1:country-region w:st="on"&gt;&lt;st1:place w:st="on"&gt;United Kingdom&lt;/st1:place&gt;&lt;/st1:country-region&gt; dissolved the National High-Tech Crime Unit (NHTCU), the agency responsible for investigating computer crime. The unit was folded into the Serious Organized Crime Agency (SOCA), a new organization that investigates fraud, drug trafficking and immigration-related crime. Critics charged that online crime would become a lower priority. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Nearly a year later, SOCA is &amp;quot;not achieving the kind of long-term impact on serious and organized crime ... that's needed,&amp;quot; said William Hughes, SOCA's director general, at the International e-Crime Congress in London on Tuesday.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;The agency has a 94 percent conviction rate and made 684 arrests from April 2006 through February, mostly for drug trafficking but also including some e-crime, Hughes said. However, online banking fraud in the &lt;st1:country-region w:st="on"&gt;&lt;st1:place w:st="on"&gt;U.K.&lt;/st1:place&gt;&lt;/st1:country-region&gt; continues unabated. Online banking fraud losses in the &lt;st1:country-region w:st="on"&gt;&lt;st1:place w:st="on"&gt;U.K.&lt;/st1:place&gt;&lt;/st1:country-region&gt; rose to $44.5 million in 2006, up from $30.8 million in 2005 and $16.2 million in 2004, according to the Association for Payment Clearing Services, a payments trade group,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Sharon Lemon, a 30-year police veteran who headed the NHTCU, is now in charge of the e-crime unit within SOCA. She spoke on the sidelines of the e-crime conference on how the new unit has been running since becoming part of SOCA last year. What follows is an edited transcript of the interview:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;IDG News Service:&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial; color:black'&gt; Given the growth in online crime, how do you prioritize cases?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Sharon Lemon:&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial; color:black'&gt; It's such a big area that we've had to really regroup and consider what our priorities are. To enable that, we need to be informed, so we've got a comprehensive knowledge base. We're not just randomly chasing people who happen to attract our attention. We've got a quite significant assessments team who assess the crime on the Internet and assess the threat, look at the new approaches. As a result, we'll consider the best operation. So it's much more focused and thought through.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;IDGNS:&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial; color:black'&gt; How significant is the amount of money lost as part of an incident?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Lemon:&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial; color:black'&gt; If you have a look at the combined effect of many, many low-level amount frauds, that's organized crime. By attacking some 300,000 people for a small amount, it's the same as one person losing £300,000. We look at emerging trends, what's happening on the criminal forums and then decide what's the best approach. It's not always traditional prosecution. We've got to look at different approaches. Traditional prosecutions always have a place, but they are very long and complex, and by the time we get to court, the cyber criminals have come up with something new. So we need to be as flexible and responsive as they are.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;IDGNS:&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial; color:black'&gt; What types of online crimes has the unit focused its energy on?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Lemon:&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial; color:black'&gt; Most of our investigations have been around fraud, which I summarize as lying to get your money. A lot of traditional investigation techniques apply but just online. I think we get a bit intoxicated by the IT element of it. It's just normal crime. That's why we need our international partners, because with this type of crime it's not the person next door, it could be the person on the other end of the world.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;IDGNS:&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial; color:black'&gt; Can you describe the backgrounds of investigators in the unit?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Lemon:&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial; color:black'&gt; We've got a really good mix. We've got traditional law enforcement and we have experienced technical people. We have people interested in the subject matter, a really diverse group. That's changed. Previously in the NHTCU, it was mostly law enforcement. We found that having people from different sectors has proved really effective, and we're hoping perhaps to do some industry exchanges and perhaps get some people from academia. That's our approach.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;IDGNS:&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial; color:black'&gt; The &lt;st1:country-region w:st="on"&gt;&lt;st1:place w:st="on"&gt;U.K.&lt;/st1:place&gt;&lt;/st1:country-region&gt; recently amended its computer crime law and increased the penalties for some offenses. Do you think that will have some deterrent effect?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Lemon:&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial; color:black'&gt; No, I don't think that really at the moment cyber criminals have got any real threat from law enforcement. I'm not proud to say that, but that's the way I feel.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;!-- HTMLBODY-LOCATED --&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;/div&gt;  </description><link>http://www.made4biz-security.com/log/2007/03/identiwall-identiwall-identiwall.html</link><author>Made4biz Security</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-7717139915883030962</guid><pubDate>Wed, 28 Mar 2007 16:52:00 +0000</pubDate><atom:updated>2007-03-28T16:55:01.272Z</atom:updated><title>rest assure that the soon coming IDentiWall will solve the fishing problem</title><description>&lt;div class=Section1&gt;  &lt;h1&gt;&lt;b&gt;&lt;font size=5 color=black face=Arial&gt;&lt;span style='font-size:20.0pt; font-family:Arial;color:black'&gt;PayPal asking e-mail services to block messages&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/h1&gt;  &lt;p class=MsoNormal&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:10.0pt;font-family:Arial;color:black;font-weight:bold'&gt;Jeremy Kirk&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size: 10.0pt;font-family:Arial;color:black'&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:10.0pt; font-family:Arial;color:black;font-weight:bold'&gt;&lt;!-- begin 336x280 ad tag --&gt;March 27, 2007&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:10.0pt;font-family:Arial;color:black'&gt; (IDG News Service) PayPal, the Internet-based money transfer system owned by eBay Inc., is trying to persuade e-mail providers to block messages that lack digital signatures, which are aimed at cutting down on phishing scams, a company attorney said Tuesday. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:10.0pt; font-family:Arial;color:black'&gt;So far, no agreements have been reached, but the idea is one that PayPal would like to see from other e-commerce businesses, said Joseph E. Sullivan, PayPal's associate general counsel, at the International E-Crime Congress in &lt;st1:City w:st="on"&gt;&lt;st1:place w:st="on"&gt;London&lt;/st1:place&gt;&lt;/st1:City&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:10.0pt; font-family:Arial;color:black'&gt;An agreement with, for example, Google Inc. for its Gmail service could potentially stop spam messages that look legitimate and bypass spam filters.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:10.0pt; font-family:Arial;color:black'&gt;PayPal is using several technologies to digitally sign its e-mails now, including DomainKeys, Sullivan said. DomainKeys, a technology developed by Yahoo Inc., enables verification of the sender and integrity of the message that's sent.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:10.0pt; font-family:Arial;color:black'&gt;PayPal is one of the most highly spoofed brands, with fraudsters sending out spam to lure vulnerable users to look-a-like Web sites where their log-in details and passwords are collected and abused for profit.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:10.0pt; font-family:Arial;color:black'&gt;Once a hacker has gained control of a PayPal account, it's possible to send money to other PayPal accounts or purchase goods. PayPal has introduced rules to counter fraud, such as limits on how much money can be transferred. PayPal also compensates users who've had their accounts hijacked, Sullivan said.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:10.0pt; font-family:Arial;color:black'&gt;But the phishing problem is getting worse than when he started working for eBay five years ago, Sullivan said.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:10.0pt; font-family:Arial;color:black'&gt;Last week, Sullivan said he got a call from his father, who said he'd fell prey to a phishing scam. While spam filtering technologies have improved and awareness around phishing is rising, users tend to be the weakest point, falling for sometimes very convincing social engineering tricks.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:10.0pt; font-family:Arial;color:black'&gt;&amp;quot;I think one lesson we've learned is that education isn't going to stop this,&amp;quot; Sullivan said. &amp;quot;Phishing attacks are too good now. Every company that does business on the Internet is being targeted by phishing scams now.&amp;quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:10.0pt; font-family:Arial;color:black'&gt;The number of phishing sites is also rising. A report released last week by the Anti-Phishing World Group, a consortium of vendors and government agencies, said the number of fraudulent Web sites in January reached an all-time high of 29,930.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;!-- HTMLBODY-LOCATED --&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:10.0pt; font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;/div&gt;  </description><link>http://www.made4biz-security.com/log/2007/03/rest-assure-that-soon-coming-identiwall.html</link><author>Made4biz Security</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-4857205341528010843</guid><pubDate>Tue, 27 Mar 2007 14:32:00 +0000</pubDate><atom:updated>2007-03-27T14:35:45.156Z</atom:updated><title>here we go again...</title><description>&lt;div class=Section1&gt;  &lt;h1&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Senators question smart card ID requirements&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/h1&gt;  &lt;p class=MsoNormal&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black;font-weight:bold'&gt;Grant Gross&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size: 11.0pt;font-family:Arial;color:black'&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;&lt;!-- begin 336x280 ad tag --&gt;March 26, 2007&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt; (IDG News Service) Senators and privacy advocates on Monday questioned a &lt;st1:country-region w:st="on"&gt;&lt;st1:place w:st="on"&gt;U.S.&lt;/st1:place&gt;&lt;/st1:country-region&gt; government plan to move ahead with smart card drivers license requirements, saying the cost will run into the billions of dollars and the cards could allow the government to track residents. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;The Real ID Act,&amp;nbsp;&lt;a href="http://www.computerworld.com/securitytopics/security/story/0,10801,101657,00.html?source=NLT_PM&amp;amp;nid=101657" target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font face=Arial&gt;&lt;span style='font-family:Arial'&gt;tacked onto&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;a military spending bill in 2005, would require states to save digital copies of source documents such as birth certificates for drivers licenses and it would require states to share information in their drivers license databases. The goal of the new cards, which would include digital photographs and personal information in a machine-readable chip, would be to better ensure that the people carrying the ID cards are who they say they are.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Congress passed the Real ID Act in response to the Sept. 11, 2001, terrorist attacks on the &lt;st1:country-region w:st="on"&gt;&lt;st1:place  w:st="on"&gt;U.S.&lt;/st1:place&gt;&lt;/st1:country-region&gt; The 9/11 Commission recommended that the government take steps to better ensure the validity of U.S. IDs. The pilot of the airplane that crashed into the Pentagon held three state drivers licenses, all of them fake, said Robert Barth, assistant secretary for policy development at the U.S. Department of Homeland Security.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;Real ID is fundamental to the security of our nation,&amp;quot; Barth told the Senate Subcommittee on Oversight of Government Management.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;But Senator George Voinovich, an Ohio Republican, complained that much of the cost for implementing Real ID would be passed on to states. DHS has estimated the cost of implementing Real ID at $14.6 billion over 10 years.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Voinovich also questioned how secure the cards would be. &amp;quot;You're going to be able to guarantee that information is going to remain private?&amp;quot; he asked Barth.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;No one can guarantee that any data will be 100 percent secure, Barth answered, but a federal system would be &amp;quot;vastly, vastly&amp;quot; more secure than 50 separate state drivers license systems. &amp;quot;Whenever you have human beings involved ... you can't say there's zero risk,&amp;quot; he said.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Voinovich pressed the question, asking if there were technological methods of defeating the proposed ID cards.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;We're going to provide the safeguards and do everything possible to prevent that from happening,&amp;quot; Barth said.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Privacy advocates have also questioned the Real IDs, saying the data on the cards would allow the government to track citizens. &amp;quot;The machine readable zone on each Real ID license will provide a digital trail everywhere it is read,&amp;quot; said Timothy Sparapani, legislative counsel for the American Civil Liberties Union.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Members of Congress have proposed that the Real ID card be required in order to vote, get a new job, obtain government benefits and travel on airplanes and trains, Sparapani said. &amp;quot;Senators should expect that no person would be able to function in our society without providing a Real ID-compliance license,&amp;quot; he said.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;In addition, the advocacy group the Center for Democracy and Technology said during a press briefing last week that the legislation doesn't restrict which employees of state drivers license bureaus can access the databases of private information. The Real ID act has no requirement for the security of the shared databases, said Jim Dempsey, CDT's policy director.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;&amp;quot;The act doesn't mention the word privacy, and it barely mentions the word security,&amp;quot; Dempsey said.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;But Senator John Warner, a Virginia Republican, defended the Real ID Act. &amp;quot;We've got to come to the realization that the life before us is not the life behind us,&amp;quot; he said. &amp;quot;We are facing some very, very serious threats.&amp;quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;!-- HTMLBODY-LOCATED --&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;/div&gt;  </description><link>http://www.made4biz-security.com/log/2007/03/here-we-go-again.html</link><author>Made4biz Security</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-5272721362288862220</guid><pubDate>Sun, 25 Mar 2007 14:53:00 +0000</pubDate><atom:updated>2007-04-16T11:16:38.745Z</atom:updated><title>A new cold war irrupted just because they didn't use Dynamic! Security</title><description>&lt;div class="Section1"&gt;&lt;h1&gt;&lt;b&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-size:100%;"&gt;Oracle charges 'corporate theft,' slaps SAP with lawsuit&lt;?xml:namespace prefix = o /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/h1&gt;&lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="FONT-WEIGHT: bold;font-family:Arial;color:black;"  &gt;Todd R. Weiss&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;b&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="FONT-WEIGHT: bold;font-family:Arial;color:black;"  &gt;&lt;!-- begin 336x280 ad tag --&gt;March 22, 2007&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt; (Computerworld) Painting a picture of what it calls "corporate theft on a grand scale," enterprise software vendor Oracle Corp. today sued German software rival SAP AG, alleging that SAP "has stolen thousands of proprietary, copyrighted software products and other confidential materials that Oracle developed to service its own support customers." &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt;In a 44-page lawsuit &lt;b&gt;&lt;span style="FONT-WEIGHT: bold"&gt;&lt;a href="http://www.oracle.com/sapsuit/complaint.pdf" target="new"&gt;(download PDF)&lt;/a&gt;&lt;/span&gt;&lt;/b&gt; filed today in U.S. District Court in the Northern District of California, Oracle alleges that SAP "has copied and swept thousands of Oracle software products and other proprietary and confidential materials onto its own servers" as part of a plan to compile "an illegal library of Oracle's copyrighted software code and other materials." &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt;"This storehouse of stolen Oracle intellectual property enables SAP to offer cut rate support services to customers who use Oracle software, and to attempt to lure them to SAP's applications software platform and away from Oracle's," the lawsuit alleges. Oracle said it filed the suit to "stop SAP's illegal intrusions and theft, to prevent SAP from using the materials it has illegally acquired to compete with Oracle and to recover damages and attorneys' fees." &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt;A spokesman for SAP &lt;?xml:namespace prefix = st1 /&gt;&lt;st1:country-region st="on"&gt;&lt;st1:place st="on"&gt;Americas&lt;/st1:place&gt;&lt;/st1:country-region&gt; declined to comment on the suit. "We have just been notified of the lawsuit, and have taken note of the Oracle press release. We are still reviewing the matter, and, until we have a chance to study the allegations, SAP will follow its standard policy of not commenting on pending litigation," said Bill Wohl. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt;The amount of damages being sought by Oracle was not revealed in the lawsuit. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt;The suit cites 11 claims, including allegations that SAP violated the Federal Computer Fraud and Abuse Act and the California Computer Data Access and Fraud Act; engaged in unfair competition; engaged in intentional and negligent interference with prospective economic advantage; and civil conspiracy. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt;The lawsuit also alleges that "SAP is engaged in systematic, illegal access to -- and taking from -- Oracle's computerized customer support systems. ... SAP gained repeated and unauthorized access, in many cases by use of pretextual customer log-in credentials, to Oracle's proprietary, password-protected customer support Web site." &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt;The alleged incidents were discovered in late November 2006, according to the lawsuit. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt;The case &lt;b&gt;&lt;span style="FONT-WEIGHT: bold"&gt;&lt;a href="http://www.computerworld.com/softwaretopics/software/story/0,10801,108567,00.html"&gt;may reflect a recent trend&lt;/a&gt;&lt;/span&gt;&lt;/b&gt;, as third-party support services firms try to lure IT managers away from getting their support from the original software vendor toward lower-cost options from other providers. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt;The lawsuit alleges that "the access and download activity Oracle observed on its systems in late November and December 2006 did not resemble the authorized, limited access to which its customers were entitled. Instead, SAP employees using the log-in credentials of Oracle customers with expired or soon-to-expire support rights had, in a matter of a few days or less, accessed and copied thousands of individual software and support materials." &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt;In one case, using one customer's credentials, "SAP suddenly downloaded an average of over 1,800 items per day for four days straight (compared to that customer's normal downloads averaging 20 per month)," according to the suit. "Other purported customers hit the Oracle site and harvested software and support materials after they had canceled all support with Oracle in favor of SAP's TN division. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt;"Oracle has found many examples of similar activity," the lawsuit said -- including more than 10,000 unauthorized downloads of material relating to hundreds of different programs. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt;The downloads originated from an Internet Protocol (IP) address in Bryan, Texas, which is the location of an SAP America branch office and home to its wholly owned subsidiary SAP TN. SAP TN, according to the lawsuit, provides technical support services for versions of Oracle's PeopleSoft and JD Edwards applications. The lawsuit goes on to allege that SAP's motivation for its activities began after Oracle's January 2005 acquisition of PeopleSoft. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt;"SAP AG had no answer for the business proposition the new Oracle offered," the suit alleged. "Not only do many SAP AG customers use Oracle's superior database software programs, but now Oracle offered a deeper, broader product line of enterprise applications software programs to compete against SAP AG." &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt;"Rather than improve its own products and offerings, SAP AG instead considered how to undermine Oracle," the suit states. "One way was to hit at Oracle's customer base -- and potentially increase its own -- by acquiring and bankrolling a company that claimed the ability to compete with Oracle support and maintenance services on Oracle's own software products." &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt;An Oracle spokeswoman also declined to comment on the lawsuit. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt;Charles King, principal analyst with Pund-IT Inc. in &lt;st1:place st="on"&gt;&lt;st1:city st="on"&gt;Hayward&lt;/st1:city&gt;, &lt;st1:state st="on"&gt;Calif.&lt;/st1:state&gt;&lt;/st1:place&gt;, called the lawsuit "a curious state of affairs. Oracle has been trying very hard to remake itself as a company that looks more like SAP than as the classic Oracle," King said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt;SAP provides a wide range of end-to-end business software applications, which is what Oracle has been trying to do through its acquisitions over the last several years, he said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt;"For SAP, the database is one part ... but simply one part of the technical underpinnings" needed by users. "Oracle started on the database side, and as time has gone on, the company has recognized that being a database specialist [alone] was not a way to sustain growth." &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt;Oracle reacted by adding other application lines and becoming more like SAP, King said. "I think they've become very successful at pursuing that strategy." &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt;Mervyn Adrian, an analyst with Cambridge, Mass.-based Forrester Research Inc., said that until the case is dissected, it's important not to assume that any of the alleged actions were done by SAP as corporate policy. Instead, any activity could have been the work of individual employees. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt;"One always has to be careful to separate the acts of individuals from corporate acts," &lt;st1:city st="on"&gt;&lt;st1:place st="on"&gt;Adrian&lt;/st1:place&gt;&lt;/st1:city&gt; said. "It's hard for me to believe that a company would build such a program to do such a thing. It seems less than credible." &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt;It is, however, "pretty routine for people [and companies] to look at each other's [Web] sites and grab whatever they can," he said. In cases such as those alleged in the Oracle lawsuit, that "usually represents misguided behavior on the part of individuals," he said. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-family:Arial;color:black;"&gt;&lt;span style="font-family:Arial;color:black;"&gt;"This may turn out to be a tempest in a teapot," with someone ultimately being found to have done something wrong and then being disciplined, &lt;st1:city st="on"&gt;&lt;st1:place st="on"&gt;Adrian&lt;/st1:place&gt;&lt;/st1:city&gt; said. "I frankly doubt that [SAP is] driving its strategy based on pirated information on what their competition is doing. I don't think what they find in a Dumpster at Oracle changes their strategy on any basis." Computerworld&lt;i&gt;&lt;span style="FONT-STYLE: italic"&gt;'s Marc L. Songini contributed to this report.&lt;/span&gt;&lt;/i&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;!-- HTMLBODY-LOCATED --&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-family:Arial;"&gt;&lt;span style="font-family:Arial;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;</description><link>http://www.made4biz-security.com/log/2007/03/new-called-war-irrupted-just-because.html</link><author>Made4biz Security</author></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-3622592209194769260.post-1182037405400295499</guid><pubDate>Sun, 25 Mar 2007 14:42:00 +0000</pubDate><atom:updated>2007-03-25T14:45:11.983Z</atom:updated><title>FYI</title><description>&lt;div class=Section1&gt;  &lt;h1&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black'&gt;Ten dangerous claims about smart phone security&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/h1&gt;  &lt;table class=MsoNormalTable border=0 cellpadding=0 width=375 style='width:281.3pt'&gt;  &lt;tr&gt;   &lt;td style='padding:.75pt .75pt .75pt .75pt'&gt;   &lt;div style='z-index:99999' id="OUTER_DIV_19782112_11174833653196"&gt;   &lt;p class=MsoNormal&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span   style='font-size:11.0pt;font-family:Arial;color:black;font-weight:bold'&gt;Jon   Espenschied&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span   style='font-size:11.0pt;font-family:Arial;color:black'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;   &lt;/div&gt;   &lt;/td&gt;  &lt;/tr&gt; &lt;/table&gt;  &lt;p&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt; font-family:Arial;color:black;font-weight:bold'&gt;  &lt;iframe id=dclk999 marginwidth=0 marginheight=0  src="http://ad.doubleclick.net/adi/idg.us.cpw.security/index;pos=imu;tile=3;sz=336x280;ord=5900419102369034?"  frameborder=0 width=0 scrolling=no height=0 borderCOLOR="#000000" MotifIFrameID="GlobalTemplate_19782112_1174833653196"  dartGlobalTemplateVersion="16_06"&gt;  March 23, 2007&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span  style='font-size:11.0pt;font-family:Arial;color:black'&gt; (Computerworld) My  heart sank when I first saw Al Gore pull out his BlackBerry. It was in the  waning weeks of the 2000 presidential campaign, and there he was on the TV,  tapping away on his then-novel converged device.&amp;nbsp;Though I had no  evidence, I was positive that whatever he was reading had already been perused  by some conservative skunk works, with his responses scrutinized not long  after.&amp;nbsp;Given recent revelations about the opposition's&amp;nbsp;&lt;a  href="http://www.slate.com/id/2161312/entry/0/" target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font  face=Arial&gt;&lt;span style='font-family:Arial'&gt;ethics&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;and  panting obsession with&amp;nbsp;&lt;a  href="http://www.cbsnews.com/stories/2006/01/19/politics/main1223080.shtml"  target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font face=Arial&gt;&lt;span style='font-family:Arial'&gt;domestic  spying&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;, I still suspect that any eavesdropping  technically possible at the time was probably being done. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;So imagine my dismay when I saw &lt;a  href="http://www.poy.org/63/15/ae03_04.php" target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font  face=Arial&gt;&lt;span style='font-family:Arial'&gt;Sen. Barack Obama&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;pulling  a BlackBerry from his coat pocket shortly after announcing his candidacy for  president. Like many others addicted to their converged devices (Sen. John  McCain was apparently&amp;nbsp;&lt;a  href="http://thinkprogress.org/2007/01/24/mccain-falls-asleep/" target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font  face=Arial&gt;&lt;span style='font-family:Arial'&gt;indulging&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;during  the last State of the Union speech, not sleeping), he's become a constant  user, and he now uses it to manage a large portion of his communications.  While I hope these politicians have IT staffers paying attention to this sort  of thing, more often than not, a series of underinformed security and privacy  assumptions are made shortly before sensitive information starts flowing.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;Many common assumptions about the security and  privacy of smart phones or other handheld converged devices are off-base or  just flat-out wrong. For any high-value target -- whether that's a political  candidate or an organization with valuable financial or personal data -- a  little more thought ought to go into the process of selecting and deploying  any device handling important data.&amp;nbsp;It makes sense then to challenge the  more widespread assumptions and consider how to handle oft-ignored risks.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;1. It's just a phone with cool features, right?&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;font  size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;  color:black'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;No, it's not. There's been a major shift in  smart phone architecture in the past few years.&amp;nbsp;Yesterday's phone ran an  embedded operating system with software hooks written for the specific model's  CPU, interface,&amp;nbsp;&lt;a href="http://en.wikipedia.org/wiki/Vocoder"  target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font face=Arial&gt;&lt;span style='font-family:Arial'&gt;vocoder&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;  &amp;nbsp;and radio. Today's mobile converged device is more likely to run  software considerably more advanced and versatile than desktop systems just 10  years ago. That versatility is an enemy of security because it turns the  underlying security architecture on its head.&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;It used to be that a phone or small handheld  device had a default-deny security model, because every feature was added from  the ground up. There were no extraneous services running on the device,  because every one was purpose-built.&amp;nbsp;Now most converged devices run  commodity operating systems, such as &lt;a href="http://www.symbian.com/"  target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font face=Arial&gt;&lt;span style='font-family:Arial'&gt;Symbian  OS&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp; (owned in part by Nokia and Sony  Ericsson) or Microsoft's Windows&amp;nbsp;&lt;a  href="http://en.wikipedia.org/wiki/Image:Windows_CE_Timeline.png"  target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font face=Arial&gt;&lt;span style='font-family:Arial'&gt;CE/Mobile&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;family,  that have portability as a core design goal.&amp;nbsp;This means there are plenty  of communications services and data handling hooks in the code base, and it's  up to phone and application developers to ensure unused code is removed or  disabled where not appropriate.&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;No one wants to annoy customers, so more often  than not, a wide range of services and interfaces is included and enabled --  equivalent to a default-allow stance. While I'm a fan of open systems, it's  worth evaluating a mobile device that provides the features you want and no  more in the base configuration -- perhaps a&amp;nbsp;&lt;a  href="http://www.technewsworld.com/story/44222.html" target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font  face=Arial&gt;&lt;span style='font-family:Arial'&gt;&amp;quot;feature phone&amp;quot;&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;  &amp;nbsp;instead of&amp;nbsp;a smart phone -- and place less priority on the capacity  for upgrades and expansion.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;&lt;!--page--&gt;2. It's stable, just like any other  purpose-built appliance.&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;font size=2 color=black  face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;Don't assume that the lack of operating system  patches and application updates for a smart phone means that they aren't  needed.&amp;nbsp;In the short&amp;nbsp;&lt;a  href="http://www.viruslist.com/en/analysis?pubid=170773606" target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font  face=Arial&gt;&lt;span style='font-family:Arial'&gt;history&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;of  mobile malware, Symbian received bad press by playing host to the first,  the&amp;nbsp;&lt;a  href="http://www.viruslist.com/en/viruses/encyclopedia?virusid=60663"  target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font face=Arial&gt;&lt;span style='font-family:Arial'&gt;Cabir&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;worm.  However, Windows CE wasn't far behind with the&amp;nbsp;&lt;a  href="http://www.viruslist.com/en/viruses/encyclopedia?virusid=60590"  target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font face=Arial&gt;&lt;span style='font-family:Arial'&gt;Duts&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;virus  and&amp;nbsp;&lt;a  href="http://www.viruslist.com/en/viruses/encyclopedia?virusid=56883"  target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font face=Arial&gt;&lt;span style='font-family:Arial'&gt;Brador&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;Trojan.&amp;nbsp;Even  single-purpose network devices are periodically found vulnerable to network  and service exploits, and vendors ought to make updates available in a timely  manner.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;The bad news is that mobile platform vendors  are still very slow to issue operating system and application  patches.&amp;nbsp;The only practical way to mitigate this is through a mix of  process and technology: Teach users proper skepticism of e-mailed attachments  and unexpected connection or update confirmations, and implement&amp;nbsp;&lt;a  href="http://usa.kaspersky.com/products/antivirus-mobile.php" target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font  face=Arial&gt;&lt;span style='font-family:Arial'&gt;anti-malware&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;  &amp;nbsp;programs for those who just keep clicking &amp;quot;OK.&amp;quot;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;3. Communications are encrypted from end to  end.&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span  style='font-size:11.0pt;font-family:Arial;color:black'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;BlackBerry and Sidekick users may have heard  that their communications are encrypted &amp;quot;end to end,&amp;quot; but e-mail and  other communications are encrypted only from the phone to the phone company or  service provider's servers.&amp;nbsp;Beyond that point, e-mail, instant messages  and file transfers may be transmitted unencrypted over the public Internet by  default.&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;This is less of a concern for closed  organizations where everyone involved uses the same services, but vendors,  partners, consultants and others outside the organization often use their own  e-mail addresses and smart phones on other carriers. There's no guarantee of  message encryption in these cases, and the risk is no better or worse than any  other Internet e-mail.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;4. The connection's secure unless I use Wi-Fi  in a cafe.&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span  style='font-size:11.0pt;font-family:Arial;color:black'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;Some might be concerned about the cellular  connection itself.&amp;nbsp;The GPRS and EDGE data protocols used by T-Mobile and  Cingular are based on GSM, and GSM authentication algorithms such as&amp;nbsp;&lt;a  href="http://cryptome.org/gsm-a512.htm" target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font  face=Arial&gt;&lt;span style='font-family:Arial'&gt;A5&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;have  been&amp;nbsp;&lt;a href="http://cryptome.org/gsm-joke.htm" target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font  face=Arial&gt;&lt;span style='font-family:Arial'&gt;broken&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;in  ways that allow a motivated eavesdropper to reconstruct voice and data  conversations with only a few thousand dollars of equipment.&amp;nbsp;CDMA and  associated algorithms are mildly more secure (&lt;a  href="http://www.qualcomm.com.au/PublicationsDocs/authsecslides.pdf"  target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font face=Arial&gt;&lt;span style='font-family:Arial'&gt;PDF  format&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;), but many carriers choose not to  implement all of the security controls available because of performance and  handset compatibility.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;Use a VPN to mitigate this problem for  sensitive data and make sure essential services are encrypted at the  application level using SSL or similar protocols. While it might seem  redundant, using a voice-over-IP client through a smart phone's VPN data  connection is one way to ensure that voice calls are private.&amp;nbsp;Direct  SIP-compliant VoIP clients are best for this; closed-protocol applications  such as Skype Mobile may try to route across a public connection even if a VPN  is available. It also may relay connections between&amp;nbsp;&lt;a  href="http://en.wiktionary.org/wiki/NAT" target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font  face=Arial&gt;&lt;span style='font-family:Arial'&gt;NAT&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;  endpoints through random clients on the Internet, so it's not a good candidate  in this scenario.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;It's also worth noting that VoIP with AEC, one  of the features of Windows Mobile 5, is not encryption. AEC refers to Acoustic  Echo Canceling, not the NIST Advanced Encryption Standard (&amp;quot;&lt;a  href="http://www.iaik.tu-graz.ac.at/research/krypto/AES/" target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font  face=Arial&gt;&lt;span style='font-family:Arial'&gt;AES&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;  &amp;quot;) described in FIPS 197.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;&lt;!--page--&gt;5. E-mails and messages are secure  from prying eyes.&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;font size=2 color=black  face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;Whoever controls your smart phone application  server has access to your data.&amp;nbsp;While smart phone service providers and  software packages all provide a modicum of access control, administrators with  root access can always get at your information if they want.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;While your corporate IT department might not be  spying on marketing on behalf of finance, Obama might want to take note that  congressional IT&amp;nbsp;&lt;a  href="http://whitepapers.techrepublic.com.com/casestudy.aspx?docid=164813"  target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font face=Arial&gt;&lt;span style='font-family:Arial'&gt;organizations&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;that  serve both Democratic and Republican senators have had several incidents  involving e-mail disclosures to other parties.&amp;nbsp;In the midst of the Mark  Foley scandal, it was interesting to note a person&amp;nbsp;&lt;a  href="http://www.harpers.org/sb-republicans-1160492797.html" target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font  face=Arial&gt;&lt;span style='font-family:Arial'&gt;described&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;in  the media as a &amp;quot;Democratic operative&amp;quot; was able to retrieve and  forward messages sent months earlier from a Republican representative's smart  phone.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;Know where messages and other data reside when  sent from a smart phone. If service is provided by a neutral vendor, make sure  you have a service-level agreement that considers whether your data may be  commingled with other businesses -- possibly your competitors -- on the same  systems. Those with specific competitive concerns ought to run their own  systems using their own administrative staff. Obama would do well to use a  device controlled by the Democratic National Committee or his own campaign,  rather than one managed by Senate IT staff and easily influenced pages.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;6. Using a mobile phone constitutes out-of-band  communication.&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span  style='font-size:11.0pt;font-family:Arial;color:black'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;A phone call over a landline used to be an  acceptable method for communicating out-of-band administrative information.  For example, a system administrator might call you back at your desk to  verbally give you a new password (which you then changed, right?). This worked  because the desk phone was isolated from the network and system resources to  which you were being given access.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;Not so anymore. If you lose your smart phone  and IT calls you back on that mobile number to confirm the trouble ticket, is  it a meaningful method of verifying the identity or location of the person who  answers? Of course not. Possession of the number means little if anything  anymore, especially since most phones will allow answering of an incoming call  even when locked.&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;IT help desks should cross callbacks off the  list of acceptable methods of identity verification for anything to do with  mobile devices or remote access. The new BlackBerry Smart Card&amp;nbsp;&lt;a  href="http://na.blackberry.com/eng/ataglance/security/products/smartcard.jsp"  target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font face=Arial&gt;&lt;span style='font-family:Arial'&gt;Reader&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;is  a viable option for those who need to authenticate using something they  possess, and while similar options lag a little on other platforms, they  are&amp;nbsp;&lt;a href="http://msdn2.microsoft.com/en-us/ms881565.aspx"  target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font face=Arial&gt;&lt;span style='font-family:Arial'&gt;available&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;&lt;!--page--&gt;7. I trust the integrity of data and  applications on a smart phone.&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;font size=2  color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;  color:black'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;On modern desktop and server systems, file  systems with journaling, database-like features and integrated backup are  common. Not so with mobile devices, where almost all data integrity relies  upon some sort of synchronization with a stable fixed server system for backup  and management.&amp;nbsp;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;Windows Mobile users can use a variety of  synchronization options to ensure that messages and data on the mobile device  are consistent with a central Microsoft-based repository such as Exchange,  SharePoint or even&amp;nbsp;&lt;a  href="http://agramont.net/blogs/conrad/archive/2007/01/10/Using-Groove-2007-as-a-_1C20_Roaming-Folder_1D20_-for-mobile-and-multi_2D00_computer-users.aspx"  target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font face=Arial&gt;&lt;span style='font-family:Arial'&gt;Groove&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;file-share  workspaces. BlackBerry &lt;st1:City w:st="on"&gt;&lt;st1:place w:st="on"&gt;Enterprise&lt;/st1:place&gt;&lt;/st1:City&gt;  users have over-the-air device security options that include data  synchronization and backup, and remote shutdown options for lost devices. (A  product called&amp;nbsp;&lt;a href="http://www.mobilecreek.com/products.htm"  target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font face=Arial&gt;&lt;span style='font-family:Arial'&gt;SyncBerry&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;provides  advanced sync and backup features to SyncML-capable systems, and extends some  of the BlackBerry goodness to Symbian users.)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;T-Mobile's Sidekick, on the other hand, stores  very little data locally because it's constantly&amp;nbsp;&lt;a  href="http://everything2.com/index.pl?node_id=1432028&amp;amp;lastnode_id=0"  target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font face=Arial&gt;&lt;span style='font-family:Arial'&gt;synchronizing&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;with  the servers at Danger Inc., the manufacturer. If the device is lost, damaged  or reset, data can be reloaded on the device by logging in with a name and  password. However, this means that data is stored at a service provider with  which individuals have a rather one-sided service-level agreement unsuitable  for corporate use.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;All of this can be protected by setting the  device to require a passcode at start-up. If the wrong passcode is entered  four times on Sidekick, local data is erased but can be restored by a remote  password reset on the management Web site. Security administrators might  lament the scarcity of people who use this feature, but it's interesting to  note that the young&amp;nbsp;&lt;a href="http://www.evanwashere.com/StolenSidekick/"  target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font face=Arial&gt;&lt;span style='font-family:Arial'&gt;thief&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;who  acquired up the now-famous Sidekick II in New York last year was identified  and arrested only because she had access to the phone, sent messages and took  pictures of herself -- which then synchronized with the legitimate owner's  account on the Danger servers.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;What about application integrity? OK, you say,  you'll just install digitally signed or approved applications. A few months  ago, some enterprising pot-stirrers managed to buy a BlackBerry code-signing  key from RIM (arguably the most security-oriented of the smart phone vendors)  for&amp;nbsp;&lt;a  href="http://securitywatch.eweek.com/exploits_and_attacks/cracking_the_blackberry_with_a_100_key.html"  target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font face=Arial&gt;&lt;span style='font-family:Arial'&gt;$100&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;,  no questions asked.&amp;nbsp;This is all bad.&amp;nbsp;Users tricked into giving  network access to unsigned applications may be opening themselves up to all  sorts of spyware, message relay and other malware, but signed applications  don't even require consent to suspicious prompts. It's far better to teach  astute users about acceptable applications and forbid the rest from installing  anything. The choice of installable applications ought to be from a whitelist  -- or no list.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;8. Information deleted from a smart phone is  gone, right?&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span  style='font-size:11.0pt;font-family:Arial;color:black'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;Most converged devices have relatively small  storage capacities, and use variants of the venerable FAT file system. When a  file is deleted, the markers for the beginning and end of the data on the  storage media are removed so that it is no longer retrievable by normal means  (orphaned). However, the actual data remains until it's overwritten. There are  no guarantees against orphaned data. In fact, the whole practice of cell phone  forensics rests on the availability of orphaned data and logs.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;I'm not aware of any smart phone that comes  with a secure delete function to remove orphaned file system  data.&amp;nbsp;Perhaps, Apple will include the file system wiping&amp;nbsp;&lt;a  href="http://www.apple.com/macosx/features/security/" target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font  face=Arial&gt;&lt;span style='font-family:Arial'&gt;option&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;from  OS X in its forthcoming iPhone, but it's not present in any of the other major  players' offerings. With many smart phones offering basic word processing and  spreadsheet applications, residual data from deleted copies becomes even more  of an issue.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;IT staffers responsible for disposal of  outdated smart phones should use tools to ensure that residual data is  removed.&amp;nbsp;The simple method is to copy and erase chunks of data onto the  device in a manner that fills the flash memory or hard disk, but forensically  sound methods are available from various&amp;nbsp;&lt;a  href="http://www.paraben-forensics.com/handheld_forensics.html" target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font  face=Arial&gt;&lt;span style='font-family:Arial'&gt;vendors&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;.  If the device memory can't be erased, it should be destroyed -- a damaged but  repairable smart phone ought not be found in the trash. Those resorting to a  hammer are&amp;nbsp;&lt;a  href="http://gizmodo.com/gadgets/laptops/actual-video-of-an-exploding-laptop-battery-214322.php"  target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font face=Arial&gt;&lt;span style='font-family:Arial'&gt;advised&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;to  remove the Li-Ion battery first.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;&lt;!--page--&gt;9. Spying on my smart phone is hard.&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;font  size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;  color:black'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;Think spying on your activities is  hard?&amp;nbsp;Think again. Most smart phones have no equivalent of Bluetooth  authentication when plugged in; they just become slave USB devices and give up  all your data. Worse yet, a rogue employee, jealous husband or political  opponent can buy backdoor malware ... uh, &amp;quot;remote phone monitoring&amp;quot;  software&amp;nbsp;&lt;a href="http://www.flexispy.com/" target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font  face=Arial&gt;&lt;span style='font-family:Arial'&gt;here&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;and  keep ongoing tabs on communications. If they manage to install the spendy  version on your phone (or trick you into doing it), it even includes remote  microphone activation and generates a tidy Excel spreadsheet of your activities  each day.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;Flexispy is cheap, oriented toward consumers  and very worrisome. It's only available for Symbian so far, but less-polished  remote viewing software or illicit copies of management tools are available  for BlackBerry, Windows Mobile and other platforms. It's not clear if  anti-malware products send alerts upon finding these, so the best policy now  is to educate users on physical security and admonish them not to install  unexpected software or updates.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;10. Abuse is minimal because the network and  phones are constrained.&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;font size=2 color=black  face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;color:black'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;Four words: Remember ASCII art  porn.&amp;nbsp;Network miscreants will work with what's available, and resource  limitations only make those inclined to misbehave do so in more creative ways.  The difference is that smart phones are quite capable, and modern 2.5G and 3G  phone networks provide surprisingly adequate bandwidth. For example, there are  now multiple BitTorrent clients for&amp;nbsp;&lt;a  href="http://www.symbian-freak.com/news/006/10/sym_torrent.htm" target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font  face=Arial&gt;&lt;span style='font-family:Arial'&gt;Symbian&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;as  well as other platforms, some phones are adept at seamlessly switching between  cellular and unsecured Wi-Fi networks, and with the price point for 4+ GB  flash cards dropping below $100, there's lots to worry about.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;To paraphrase Steve Jobs, misuse of technology  is a social problem, not a technological one. Having a well-defined policy for  the use of converged devices is essential prior to deployment. Conversely,  rolling out smart phones without proper guidance will lead to all sorts of  havoc. Users might respect pay-per-minute airtime as a corporate asset, but  unless instructed otherwise they'll think of flat-rate data services as free  connectivity on someone else's network (not covered by your policy), and the  phone itself as corporate tribal adornment suitable for display anywhere,  anytime.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;b&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;More to consider&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;font  size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;font-family:Arial;  color:black'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;Am I advocating Naomi Campbell's&amp;nbsp;&lt;a  href="http://galleryoftheabsurd.typepad.com/14/2006/04/the_naomi_campb.html"  target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font face=Arial&gt;&lt;span style='font-family:Arial'&gt;method&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;&amp;nbsp;of  disposing of one's fancy mobile?&amp;nbsp;No, in fact, just this month I bought a  new smart phone.&amp;nbsp;While I'm no fan of troublesome devices -- two  colleagues recently commented that their new WM5 phones rarely crash more than  once per day now -- mobile e-mail and Internet access are quickly becoming de  rigueur.&amp;nbsp;I made a list of the functions I needed and tried to avoid  models that included features I would not use or could not secure.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;Readers looking for a structured set of  criteria for evaluating and selecting a specific smart phone product are  encouraged to read NIST Special Publication 800-48 (&lt;a  href="http://csrc.nist.gov/publications/nistpubs/800-48/NIST_SP_800-48.pdf"  target="_blank"&gt;&lt;strong&gt;&lt;b&gt;&lt;font face=Arial&gt;&lt;span style='font-family:Arial'&gt;PDF  format&lt;/span&gt;&lt;/font&gt;&lt;/b&gt;&lt;/strong&gt;&lt;/a&gt;).&amp;nbsp;It's a little dated, but when  mobile system and application developers are rediscovering every mistake they  made a decade ago with remote desktop and laptop systems, these old documents  are right on the mark.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black'&gt;&lt;br&gt;  &lt;b&gt;&lt;span style='font-weight:bold'&gt;Jon Espenschied&lt;/span&gt;&lt;/b&gt; &lt;em&gt;&lt;i&gt;&lt;font  face=Arial&gt;&lt;span style='font-family:Arial'&gt;has been at play in the security  industry for enough years to become enthusiastic, blasé, cynical, jaded,  content and enthusiastic again. He is currently a senior security consultant  in &lt;st1:City w:st="on"&gt;&lt;st1:place w:st="on"&gt;Seattle&lt;/st1:place&gt;&lt;/st1:City&gt;,  where his advice has been ignored by CEOs, auditors and sysadmins alike.&lt;/span&gt;&lt;/font&gt;&lt;/i&gt;&lt;/em&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p&gt;&lt;i&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial;color:black;font-style:italic'&gt;This column has been edited  to correct a misstatement: The Symbian OS is in fact owned in part by Nokia  and Sony Ericsson.&lt;/span&gt;&lt;/font&gt;&lt;/i&gt;&lt;font size=2 color=black face=Arial&gt;&lt;span  style='font-size:11.0pt;font-family:Arial;color:black'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;p class=MsoNormal&gt;&lt;font size=2 face=Arial&gt;&lt;span style='font-size:11.0pt;  font-family:Arial'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;  &lt;/div&gt;  </description><link>http://www.made4biz-security.com/log/2007/03/fyi.html</link><author>Made4biz Security</author></item></channel></rss>
