<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: escape]]></title>
    <link>http://www.securityratty.com/tag/escape</link>
    <description></description>
    <pubDate>Mon, 05 May 2008 07:52:27 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Mayhem in Mumbai]]></title>
      <link>http://www.securityratty.com/article/b7902ee86f589ca527ebb734d591a745</link>
      <guid>http://www.securityratty.com/article/b7902ee86f589ca527ebb734d591a745</guid>
      <description><![CDATA[The total number of casualties rise in the financial capital of India after terrorists attack multiple locations

The latest figures suggest that at least 100 people have been killed and as many as...]]></description>
      <content:encoded><![CDATA[The total number of casualties rise in the financial capital of India after terrorists attack multiple locations.<br /><span id="fullpost"><br />The latest figures suggest that at least 100 people have been killed and as many as 900 injured.  Radio and television reporters are saying that it has all the hallmarks of an Al-Qaeda attack.  Locations included a railway station, a cinema, the Taj Hotel, and another very popular restaurant. <br /></span><br />It appears as if the terrorists singled out Westerners as they are reported to have taken British and American tourists hostages and brought them up to the 18th floor of the hotel.  This evening the hotel is on fire and the fate of the hostages is still unknown.<br /><br />The good news for some, is that they were able to escape form the hotel in the confusion.  It appears that the terrorists could have numbered dozens of heavily armed men.  This is definitely not a random attack but a well planned and executed operation aimed at causing mass casualties amnd hitting India's financial markets in much the same way as Wall Street was attacked on 9/11.<br /><br />We do not hear that much about India's terrorist problems in the West but I was made aware of it when I was invited to India to speak on Security matters this time last year.  I have since that time made clients and potenital clients aware of the  security situation.  <br /><br />There has been much outsourcing to India and many U.S. businesses are sending personnel over there as a result.  Those who can afford to have their own professional security protectors should consider that option very carefully.  It could very well turn out being more of a necessity than a luxury in these dangerous times.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Thu, 27 Nov 2008 02:48:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/india">india</category>
      <category domain="http://www.securityratty.com/tag/potenital clients aware">potenital clients aware</category>
      <category domain="http://www.securityratty.com/tag/taj hotel">taj hotel</category>
      <category domain="http://www.securityratty.com/tag/hotel">hotel</category>
      <category domain="http://www.securityratty.com/tag/clients">clients</category>
      <category domain="http://www.securityratty.com/tag/hostages">hostages</category>
      <category domain="http://www.securityratty.com/tag/mass casualties amnd">mass casualties amnd</category>
      <category domain="http://www.securityratty.com/tag/american tourists hostages">american tourists hostages</category>
      <category domain="http://www.securityratty.com/tag/aware">aware</category>
      <source url="http://www.thebulletproofblog.com/2008/11/mayhem-in-mumbai.html">Mayhem in Mumbai</source>
    </item>
    <item>
      <title><![CDATA[Flash 10 Fixes Clickjacking Flaw]]></title>
      <link>http://www.securityratty.com/article/7466eca5f91107c96844d79b2e110ddd</link>
      <guid>http://www.securityratty.com/article/7466eca5f91107c96844d79b2e110ddd</guid>
      <description><![CDATA[Not long after &quot;clickjacking&quot; attacks appeared several weeks ago it became clear that the culprit was Adobe's Flash. And the problem, as we say in the software biz, wasn't a bug, it was a feature....]]></description>
      <content:encoded><![CDATA[Not long after <a href="http://securitywatch.eweek.com/vulnerability_research/clickjacking_browser_attack_details_emerge.html">"clickjacking" attacks appeared several weeks ago</a> it became clear that the culprit was Adobe's Flash. And the problem, as we say in the software biz, wasn't a bug, it was a feature. This feature has been modified in <a href="http://www.eweek.com/c/a/Application-Development/Adobe-Releases-Flash-Player-10/">the new Flash 10 player</a> to address the problem.

The problem is clipboard access. By default, Flash 9 allowed a Flash program to read and write to the clipboard. "Clickjacking" attacks took advantage of this to persistently stuff a value. usually a malicious URL, into the clipboard, in the hope the user would visit it. The attack is as cross-platform as Flash, working on Macs as well as Windows.

In Flash 10 the clipboard methods will only work when called through ActionScript which originates with a user action, like pressing a button. No longer will a silent Flash app be able to hijack the clipboard completely without the user noticing.

This change was just one of <a href="http://www.adobe.com/devnet/flashplayer/articles/fplayer10_security_changes.html">many security changes in the Flash 10 player</a>. Changes in how Flash handles policy files means that developers will have to address their use of them. Errors on socket connect() calls will be handled differently. And much in the same philosophy as with clipboards, file uploads and downloads may only occur in script that begins with a user action. There are other changes as well.

The flip side of this fix is that it is not implemented in Flash 9. This means that the only way to escape clickjacking attacks is to upgrade to Flash 10.
<p><a href="http://feedads.googleadservices.com/~a/FtymtK-1YQe4YgTHIvGH8JR05Ck/a"><img src="http://feedads.googleadservices.com/~a/FtymtK-1YQe4YgTHIvGH8JR05Ck/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/58cVGsWzlbk" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 16 Oct 2008 10:07:56 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/flash">flash</category>
      <category domain="http://www.securityratty.com/tag/silent flash app">silent flash app</category>
      <category domain="http://www.securityratty.com/tag/flash program">flash program</category>
      <category domain="http://www.securityratty.com/tag/clipboard">clipboard</category>
      <category domain="http://www.securityratty.com/tag/clipboard methods">clipboard methods</category>
      <category domain="http://www.securityratty.com/tag/user">user</category>
      <category domain="http://www.securityratty.com/tag/user action">user action</category>
      <category domain="http://www.securityratty.com/tag/clipboard access">clipboard access</category>
      <category domain="http://www.securityratty.com/tag/clipboard completely">clipboard completely</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/58cVGsWzlbk/flash_10_fixes_clickjacking_flaw.html">Flash 10 Fixes Clickjacking Flaw</source>
    </item>
    <item>
      <title><![CDATA[Trick or Treat]]></title>
      <link>http://www.securityratty.com/article/c004eff4c879f49ca081346223fc7909</link>
      <guid>http://www.securityratty.com/article/c004eff4c879f49ca081346223fc7909</guid>
      <description><![CDATA[October's here, and you can't escape the coming onslaught of Halloween. Children (and quite a few adults) dressed up as vampires, ghosts, goblins and other scary creatures, going around asking people...]]></description>
      <content:encoded><![CDATA[<p>October's here, and you can't escape   the coming onslaught of Halloween. Children (and quite a few adults) dressed up   as vampires, ghosts, goblins and other scary creatures, going around asking   people for treats and threatening them with tricks if they don't provide them. A   cynical person might boil it down to a a combination of scare tactics and   extortion. So what does this have to do with IT security and compliance?   Unfortunately, the way   security and compliance professionals have traditonally gone about obtaining   funds and resources for tools and projects necessary to do their jobs all too   closely parallels what happens on Halloween. <B>We frequently use scare tactics   such as new threats (the trick) to get management to cough up the funding and   resources (the treats) we need to accomplish what we view as our jobs...</b>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/scare tactics">scare tactics</category>
      <category domain="http://www.securityratty.com/tag/compliance professionals">compliance professionals</category>
      <category domain="http://www.securityratty.com/tag/compliance">compliance</category>
      <category domain="http://www.securityratty.com/tag/resources">resources</category>
      <category domain="http://www.securityratty.com/tag/jobs">jobs</category>
      <category domain="http://www.securityratty.com/tag/closely parallels">closely parallels</category>
      <category domain="http://www.securityratty.com/tag/scary creatures">scary creatures</category>
      <category domain="http://www.securityratty.com/tag/treats">treats</category>
      <category domain="http://www.securityratty.com/tag/security">security</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1361">Trick or Treat</source>
    </item>
    <item>
      <title><![CDATA[Be careful what hand you play, and when you play it]]></title>
      <link>http://www.securityratty.com/article/3f792de863bd77b5be976522d12fce8f</link>
      <guid>http://www.securityratty.com/article/3f792de863bd77b5be976522d12fce8f</guid>
      <description><![CDATA[Yet another analogy from the credit crunch shows us security folks that even if we changed jobs we probably wouldn't be able to escape our frustrations. The executive branch is currently trying to win...]]></description>
      <content:encoded><![CDATA[Yet another analogy from the credit crunch shows us security folks that even if we changed jobs we probably wouldn't be able to escape our frustrations. 

The executive branch is currently trying to win over Congress and convince them to hand over a large sum of money, or else something really bad is going to happen. This is a situation I'm sure many security folks have found themselves in, albeit under less extreme circumstances.

The people with the check books seldom know anything about what you're doing. Congress is full of politicians, not economists or experts on the banking system. They need to rely on their gut feeling to do the right thing. Same thing with your management, <B>so it's up to you to guide them towards the right decision -- in their language</b>...
]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 20:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/security folks">security folks</category>
      <category domain="http://www.securityratty.com/tag/check books seldom">check books seldom</category>
      <category domain="http://www.securityratty.com/tag/congress">congress</category>
      <category domain="http://www.securityratty.com/tag/extreme circumstances">extreme circumstances</category>
      <category domain="http://www.securityratty.com/tag/credit crunch">credit crunch</category>
      <category domain="http://www.securityratty.com/tag/executive branch">executive branch</category>
      <category domain="http://www.securityratty.com/tag/hand">hand</category>
      <category domain="http://www.securityratty.com/tag/system">system</category>
      <category domain="http://www.securityratty.com/tag/analogy">analogy</category>
      <source url="http://www.rsa.com/blog/blog_entry.aspx?id=1358">Be careful what hand you play, and when you play it</source>
    </item>
    <item>
      <title><![CDATA[Random Stupidity in the Name of Terrorism]]></title>
      <link>http://www.securityratty.com/article/c81bd0a4e004add0a54874f8bf604a84</link>
      <guid>http://www.securityratty.com/article/c81bd0a4e004add0a54874f8bf604a84</guid>
      <description><![CDATA[An air traveller in Canada is first told by an airline employee that it is &quot;illegal&quot; to say certain words, and then that if he raised a fuss he would be falsely accused: When we boarded a little...]]></description>
      <content:encoded><![CDATA[An air traveller in Canada is first <a href="http://www.theglobeandmail.com/servlet/story/RTGAM.20080627.blatch28/BNStory/specialComment/home">told</a> by an airline employee that it is "illegal" to say certain words, and then that if he raised a fuss he would be falsely accused:

<blockquote>When we boarded a little later, I asked for the ninny's name. He refused and hissed, "If you make a scene, I'll call the pilot and you won't be flying tonight."</blockquote>

More on the British <a href="http://www.theregister.co.uk/2008/06/23/police_photographer_stops/">war on photographers</a>.

A British man is forced to give up his <a href="http://uk.news.yahoo.com/skynews/20080624/tuk-bus-spotter-labelled-a-paedophile-45dbed5.html">hobby</a> of photographing busses due to harrassment.

<blockquote>The credit controller, from Gloucester, says he now suffers "appalling" abuse from the authorities and public who doubt his motives.

The bus-spotter, officially known as an omnibologist, said: "Since the 9/11 attacks there has been a crackdown.

"The past two years have absolutely been the worst. I have had the most appalling abuse from the public, drivers and police over-exercising their authority.

Mr McCaffery, who is married, added: "We just want to enjoy our hobby without harassment.

"I can deal with the fact someone might think I'm a terrorist, but when they start saying you're a paedophile it really hurts."</blockquote>

Is <a href="http://www.cnn.com/2008/WORLD/meast/07/02/israel.bulldozer/">everything</a> illegal and damaging now terrorism?

<blockquote>Israeli authorities are investigating why a Palestinian resident of Jerusalem rammed his bulldozer into several cars and buses Wednesday, killing three people before Israeli police shot him dead.

Israeli authorities are labeling it a terrorist attack, although they say there is no clear motive and the man -- a construction worker -- acted alone. It is not known if he had links to any terrorist organization.</blockquote>

Boston public school locked down after someone <a href="http://www.boston.com/news/odd/articles/2008/06/25/school_locked_down_after_ninja_sighted_in_woods/">saw</a> a ninja:

<blockquote>Turns out the ninja was actually a camp counselor dressed in black karate garb and carrying a plastic sword.

Police tell the Asbury Park Press the man was late to a costume-themed day at a nearby middle school.</blockquote>

And finally, not terrorism-related but a fine newspaper headline:  "<a href="http://ap.google.com/article/ALeqM5h1AqbvSMYPxJrla6-Fgym8WIzEsgD91KNJD00">Giraffe helps camels, zebras escape from circus</a>":

<blockquote>Amsterdam police say 15 camels, two zebras and an undetermined number of llamas and potbellied swine briefly escaped from a traveling Dutch circus after a giraffe kicked a hole in their cage.</blockquote>

Are llamas really that hard to count?<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=eQI3GJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=eQI3GJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=tEUVdJ"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=tEUVdJ" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 03 Jul 2008 08:57:04 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/police">police</category>
      <category domain="http://www.securityratty.com/tag/israeli police shot">israeli police shot</category>
      <category domain="http://www.securityratty.com/tag/giraffe">giraffe</category>
      <category domain="http://www.securityratty.com/tag/terrorist">terrorist</category>
      <category domain="http://www.securityratty.com/tag/israeli authorities">israeli authorities</category>
      <category domain="http://www.securityratty.com/tag/giraffe helps camels">giraffe helps camels</category>
      <category domain="http://www.securityratty.com/tag/authorities">authorities</category>
      <category domain="http://www.securityratty.com/tag/boston public school">boston public school</category>
      <category domain="http://www.securityratty.com/tag/terrorist organization">terrorist organization</category>
      <source url="http://www.schneier.com/blog/archives/2008/07/random_stupidit.html">Random Stupidity in the Name of Terrorism</source>
    </item>
    <item>
      <title><![CDATA[EU bloggers under assault by the European Parliament - they need your help]]></title>
      <link>http://www.securityratty.com/article/42471dd2ecc3d3795053ea76949e5eeb</link>
      <guid>http://www.securityratty.com/article/42471dd2ecc3d3795053ea76949e5eeb</guid>
      <description><![CDATA[One of the nice things about having started the SBN was that I have gotten to meet (mostly virtually) many security bloggers from around the world. Some of the most prolific contributors to the...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>One of the nice things about having started the <a href="http://networks.feedburner.com/Security-Bloggers-Network/feed" target="_blank">SBN</a> was that I have gotten to meet (mostly virtually) many security <a class="zem_slink" title="Blog" href="http://en.wikipedia.org/wiki/Blog" rel="wikipedia">bloggers</a> from around the world.&nbsp; Some of the most prolific contributors to the content of the SBN has been the members of the <a href="http://pipes.yahoo.com/pipes/pipe.run?_id=ViJDI2KQ3BGXtQrlnkartA&amp;_render=rss" target="_blank">Belgian Security Bloggers Network</a>.&nbsp; I received word today from one of the authors of one of the blogs, <a href="http://belsec.skynetblogs.be/post/5962674/alarm--european-parliament-wants-to-take-on-b" target="_blank">belsec</a>, that they are under assault by the EU government.&nbsp; It seems in their wisdom, the <a href="http://www.europarl.europa.eu/meetdocs/2004_2009/documents/pr/712/712320/712320en.pdf" target="_blank">European Parliament has decided</a> that in the interests of &quot;media pluralism&quot;, all blog owners should declare their ownership, affiliations and status of weblog authors.</p>

<p>The explanatory notes of the proposed regulation says this:</p><blockquote><p><em>In this context the report points out that the undetermined and unindicated status of authors and publishers of weblogs causes uncertainties regarding impartiality, reliability, source protection, applicability of ethical codes and the assignment of liability in the event of lawsuits.<br />It recommends clarification of the legal status of different categories of weblog authors and publishers as well as disclosure of interests and voluntary labelling of weblogs.</em></p></blockquote><p>As the belsec author points out, disclosure of their identities would effectively silence their voices.&nbsp; There is no first amendment freedom of speech or <a class="zem_slink" title="Freedom of the press" href="http://en.wikipedia.org/wiki/Freedom_of_the_press" rel="wikipedia">freedom of press</a> constitutional right in Europe. Of course if forced to do so, the Belgian authors could take up blogs based here in the US and escape the disclosure laws of the EU, but why should they have too.&nbsp; The EU is a democratic, progressive entity.&nbsp; Forcing these bloggers to make their &quot;status and identity&quot; public should not be mandatory here.</p>

<p>Blogs are todays pamphlets.&nbsp; Basic <a class="zem_slink" title="Freedom of speech" href="http://en.wikipedia.org/wiki/Freedom_of_speech" rel="wikipedia">freedom of expression</a>, speech and press have been protected for hundreds of years. Forcing these bloggers to identify themselves is a violation of their rights.&nbsp; What would <a class="zem_slink" title="Thomas Paine" href="http://en.wikipedia.org/wiki/Thomas_Paine" rel="wikipedia">Thomas Paine</a> and others like him think of this restriction? </p>

<p>If you feel that this is an unfair and unjust restriction on bloggers rights, blog about it. It is our right and to do so and we should use the medium to do so.&nbsp; If you are a EU citizen write to your representative and demand that this proposed regulation does not go into effect!</p>

<p>Do not take your right to blog lightly.&nbsp; If you don't stand up for it, it can be taken away from you.</p>

<p><em>&quot;The world is my country, all mankind are my brethren, and to do good is my religion.&quot; - </em>Thomas Paine </p>

<div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/4f5ed85c-539c-4c67-8e62-8644ef78190e/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_a.png?x-id=4f5ed85c-539c-4c67-8e62-8644ef78190e" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>
]]></content:encoded>
      <pubDate>Thu, 12 Jun 2008 05:38:11 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/bloggers">bloggers</category>
      <category domain="http://www.securityratty.com/tag/weblog authors">weblog authors</category>
      <category domain="http://www.securityratty.com/tag/authors">authors</category>
      <category domain="http://www.securityratty.com/tag/bloggers rights">bloggers rights</category>
      <category domain="http://www.securityratty.com/tag/freedom">freedom</category>
      <category domain="http://www.securityratty.com/tag/legal status">legal status</category>
      <category domain="http://www.securityratty.com/tag/blog owners">blog owners</category>
      <category domain="http://www.securityratty.com/tag/basic freedom">basic freedom</category>
      <category domain="http://www.securityratty.com/tag/status">status</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/06/eu-bloggers-und.html">EU bloggers under assault by the European Parliament - they need your help</source>
    </item>
    <item>
      <title><![CDATA[EU bloggers under assault by the European Parliament - they need your help]]></title>
      <link>http://www.securityratty.com/article/495d89a1106383a495fba74b3adf8fdb</link>
      <guid>http://www.securityratty.com/article/495d89a1106383a495fba74b3adf8fdb</guid>
      <description><![CDATA[One of the nice things about having started the SBN was that I have gotten to meet (mostly virtually) many security bloggers from around the world. Some of the most prolific contributors to the...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>One of the nice things about having started the <a href="http://networks.feedburner.com/Security-Bloggers-Network/feed" target="_blank">SBN</a> was that I have gotten to meet (mostly virtually) many security bloggers from around the world.&nbsp; Some of the most prolific contributors to the content of the SBN has been the members of the <a href="http://pipes.yahoo.com/pipes/pipe.run?_id=ViJDI2KQ3BGXtQrlnkartA&amp;_render=rss" target="_blank">Belgian Security Bloggers Network</a>.&nbsp; I received word today from one of the authors of one of the blogs, <a href="http://belsec.skynetblogs.be/post/5962674/alarm--european-parliament-wants-to-take-on-b" target="_blank">belsec</a>, that they are under assault by the EU government.&nbsp; It seems in their wisdom, the <a href="http://www.europarl.europa.eu/meetdocs/2004_2009/documents/pr/712/712320/712320en.pdf" target="_blank">European Parliament has decided</a> that in the interests of "media pluralism", all blog owners should declare their ownership, affiliations and status of weblog authors.</p> <p>The explanatory notes of the proposed regulation says this:</p> <blockquote> <p><em>In this context the report points out that the undetermined and unindicated status of authors<br>and publishers of weblogs causes uncertainties regarding impartiality, reliability, source<br>protection, applicability of ethical codes and the assignment of liability in the event of<br>lawsuits.<br>It recommends clarification of the legal status of different categories of weblog authors and<br>publishers as well as disclosure of interests and voluntary labelling of weblogs.</em></p></blockquote> <p>As the belsec author points out, disclosure of their identities would effectively silence their voices.&nbsp; There is no first amendment freedom of speech or freedom of press constitutional right in Europe. Of course if forced to do so, the Belgian authors could take up blogs based here in the US and escape the disclosure laws of the EU, but why should they have too.&nbsp; The EU is a democratic, progressive entity.&nbsp; Forcing these bloggers to make their "status and identity" public should not be mandatory here.&nbsp; </p> <p>If you feel that this is a restriction on bloggers rights, blog about it. It is our right and to do so and we should use the medium to do so.&nbsp; If you are a EU citizen write to your representative and demand that this proposed regulation does not go into effect!</p> <p>Do not take your right to blog lightly.&nbsp; If you don't stand up for it, it can be taken away from you.</p> <p><em>"The world is my country, all mankind are my brethren, and to do good is my religion." - </em>Thomas Paine </div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=RZd6mh"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=RZd6mh" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=cFCkbI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=cFCkbI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=2okMgI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=2okMgI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=YN5ouI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=YN5ouI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=ApS9WI"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=ApS9WI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=oYLcIi"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=oYLcIi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=ebgmPi"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=ebgmPi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/310405700" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 12 Jun 2008 04:38:35 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/bloggers">bloggers</category>
      <category domain="http://www.securityratty.com/tag/weblog authors">weblog authors</category>
      <category domain="http://www.securityratty.com/tag/authors">authors</category>
      <category domain="http://www.securityratty.com/tag/legal status">legal status</category>
      <category domain="http://www.securityratty.com/tag/blog owners">blog owners</category>
      <category domain="http://www.securityratty.com/tag/status">status</category>
      <category domain="http://www.securityratty.com/tag/blog">blog</category>
      <category domain="http://www.securityratty.com/tag/bloggers rights">bloggers rights</category>
      <category domain="http://www.securityratty.com/tag/european parliament">european parliament</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/310405700/eu-bloggers-und.html">EU bloggers under assault by the European Parliament - they need your help</source>
    </item>
    <item>
      <title><![CDATA[Sometimes, It Takes a Thief to Catch a Thief]]></title>
      <link>http://www.securityratty.com/article/b0dcc475c6854e10377cec5768a9572e</link>
      <guid>http://www.securityratty.com/article/b0dcc475c6854e10377cec5768a9572e</guid>
      <description><![CDATA[News from Portfolio.com

Also on Portfolio
Time for Tech to Throw Everything Into Energy
Hollywood Frets Over Corruption Crackdown
McCaw's Back to Remake the Wireless Landscape
Subscribe to Portfolio...]]></description>
      <content:encoded><![CDATA[<!-- PORTFOLIO.COM LINKS -->
<div class="content_sharing">
<strong>News from Portfolio.com</strong><br/>
<a href="http://www.portfolio.com/?TID=wiredpartner"><img src="http://www.wired.com/images/article/full/2008/03/logo_portfolio.jpg" class="portfolio_img"></a><br clear="all"/>
<div class="content_sharing_txt">
<p><strong>Also on Portfolio</strong></p>
<!-- LINK #1 -->
<p><a http://www.portfolio.com/views/blogs/the-tech-observer/2008/06/09/time-for-the-tech-industry-to-throw-everything-into-energy/?TID=wiredpartner">
Time for Tech to Throw Everything Into Energy</cite></a></p>
<!-- LINK #2 -->
<p><a href="http://www.portfolio.com/news-markets/top-5/2008/06/06/Feds-Hunt-Foreign-Corruption/?TID=wiredpartner">
Hollywood Frets Over Corruption Crackdown</a></p>
<!-- LINK #3 -->
<p><a href="http://www.portfolio.com/executives/features/2008/06/07/Craig-McCaws-Latest-Venture/?TID=wiredpartner">
McCaw's Back to Remake the Wireless Landscape</a></p>
</div>
<div class="content_sharing_sub"><a href="https://w1.buysub.com/pubs/N3/FOL/self_fol_control_TVL.jsp?cds_page_id=39267&cds_mag_code=FOL&id=1205777661443&lsid=80771311187037701&vid=2&cds_response_key=I8CNAAA9&cds_mag_code=FOL">Subscribe to Portfolio magazine</a></div>
</div>

<p>Apollo Robbins won't say whether he's ever stolen anything in his life, but it's clear he could if he wanted to. Having grown up in Missouri with three half-brothers who were all involved in various criminal activities (one of them is in the witness protection program after testifying against former colleagues of his), the 34-year-old Robbins was indoctrinated at an early age into the finer aspects of pickpocketing and con games.</p> 

<p>He eventually developed those skills into a successful career as a sleight-of-hand artist and performer in Las Vegas. His latest act, though, has him starring as a corporate security consultant. In this role, it is less his dexterous hands that appeals to his clients than his mastery of all aspects of criminal cons, grifts, and social-engineering ploys.</p>

<p>"When you're trying to steal something, you find the weakest link and work that," Robbins says. "Nowadays, as technology gets better and security systems get harder to break through, the weakest link in any system is the human running it."</p>

<p>Robbins founded his consulting operation, Whizmob Inc. (the name comes from the street term for a team of pickpockets working together), two years ago while still performing full-time.</p>

<p>After doing a show a few years back in which he pickpocketed Secret Service agents accompanying former president Jimmy Carter, the resulting publicity led several law-enforcement agencies and other groups to contact him about his techniques.</p>

<p>"At first, I'd refer them to security people I knew," says Robbins. "Then I realized that instead of being a referral service, I could capitalize on this."</p>

<p>It was a good time to get in on the act. Information security consulting, which barely existed in the mid '90s, has become an estimated $10 billion to $12 billion business as the need to protect sensitive information stored on computers and servers has become a more central concern.</p>

<p>Today, Robbins counts the N.F.L., TNT, and several Fortune 500 companies among his customers. He recently advised the N.F.L. on information security protection at this year's Super Bowl in Phoenix to combat the expected flow of thieves and con artists lured by all the deep-pocketed spectators coming to town.</p> 

<p>His work included getting a major hotel to upgrade its WiFi security so that fake access programs known as Trojans couldn't extract valuable data and password information from unsuspecting guests' computers. And at the stadium where the game was held, Robbins and his team identified areas where pickpockets would most likely operate—specifically, places with lots of traffic where bumping into people would be customary, and easy access to exits for escape purposes.</p> 

<p>Besides the shadier elements of Robbins' childhood, his father, a blind minister, instilled in him a strong sense of morality. "It was like living in two worlds," Robbins says.</p> 

<p>In many ways, he still is living in two worlds, since he keeps in regular contact with some professional thieves he knows in order to stay abreast of the latest cons. (While he doesn't pay them, Robbins says that "a lot of these guys are really good at what they do but they can't exactly discuss it with a lot of people.") But increasingly, Robbins is spending time in the more staid settings of the corporations that hire him to vet their security systems.</p>

<p>"It's a good time to be in the business," he says.</p><br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=e0ef6c5b7f8aabc5c9704039f85d55ea" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=e0ef6c5b7f8aabc5c9704039f85d55ea" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=k4A9yI"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=k4A9yI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=LjLX9i"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=LjLX9i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=ARnnbi"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=ARnnbi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=oiubTI"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=oiubTI" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=aaQPZI"><img src="http://feeds.wired.com/~f/wired/politics/security?i=aaQPZI" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=jADEoi"><img src="http://feeds.wired.com/~f/wired/politics/security?i=jADEoi" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=fzbN2i"><img src="http://feeds.wired.com/~f/wired/politics/security?i=fzbN2i" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Xz7O5I"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Xz7O5I" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/308162761" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/308162762" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 09 Jun 2008 13:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/robbins">robbins</category>
      <category domain="http://www.securityratty.com/tag/apollo robbins">apollo robbins</category>
      <category domain="http://www.securityratty.com/tag/robbins counts">robbins counts</category>
      <category domain="http://www.securityratty.com/tag/34-year-old robbins">34-year-old robbins</category>
      <category domain="http://www.securityratty.com/tag/information security protection">information security protection</category>
      <category domain="http://www.securityratty.com/tag/time">time</category>
      <category domain="http://www.securityratty.com/tag/information security">information security</category>
      <category domain="http://www.securityratty.com/tag/full-time">full-time</category>
      <category domain="http://www.securityratty.com/tag/security people">security people</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/308162762/portfolio_0609">Sometimes, It Takes a Thief to Catch a Thief</source>
    </item>
    <item>
      <title><![CDATA[Ted Kennedy: a lifetime of achievement, regrets of a world that could have been]]></title>
      <link>http://www.securityratty.com/article/46c0e216b7084846a34fe3d594d53e76</link>
      <guid>http://www.securityratty.com/article/46c0e216b7084846a34fe3d594d53e76</guid>
      <description><![CDATA[I usually stay away from politics on my blog. As I have said before, it is my blog and I can write what I want, but politics usually is just to controversial for me to write on. Upon hearing the...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><div>I usually stay away from politics on my blog. As I have said before, it is my blog and I can write what I want, but politics usually is just to controversial for me to write on. Upon hearing the <a href="http://news.yahoo.com/s/ap/20080521/ap_on_re_us/kennedy">terrible news</a> about Ted Kennedy's malignant brain tumor, I was moved to write something, than thought twice about it and thought yet again. However, Ted Kennedy and his life and times has been such an influence and part of my life, that I am compelled to write. So on this night where it appears that an African-American has won <a href="http://www.cnn.com/2008/POLITICS/02/29/delegate.counter/index.html?iref=mpstoryview">a majority of the pledged delegates</a> of the Democratic Party, while running against a woman, I think it only fitting to remember Ted Kennedy. I do not mean this as a eulogy or obituary and in fact hope against all that I have read and heard that a miracle will grant him many more years of serving in the Senate. But it seems Teddy has a tough road ahead and this is as good as a time as any to speak out.<br /><br />One of my earliest memories of current events was when Ted's brother John was assassinated. I was a little boy playing catch with my Dad when my Mom came to the door and called us in because something terrible had happened. I didn't really understand, but my parents told me that the President (who I had seen with VP Johnson drive by in a motorcade months before) had been shot. I don't remember a lot more of the details, but do remember Oswald getting shot and some pictures of the funeral. The mind of a young boy is quickly filled with other things though and I moved on past that horrific November day.</div>

<div> <br />Next when I was a bit older, the crazy year of '68 was upon us. I was still fairly young, but I remember riots in the cities, pictures on the news of the war and Bobby Kennedy, the Senator from NY running for President when President Johnson said he would not run. Martin Luther King was shot and killed and so was Bobby shortly after. By now I was old enough to realize the tragedy of these killings. I remember hearing Teddy's eulogy of Bobby and thinking what a terrible thing to have happened to this family, losing two of their sons like this. <br /><br />For me it was the start of a life long interest in all things Kennedy. I read many books about all of the Kennedy's and lamented what could have been if not for the bullets that killed first John and than Bobby. A key part of my core political beliefs was that if John Kennedy would have served out his first term and been re-elected, how different the world would have been.&nbsp; If Bobby Kennedy had been elected President instead of Nixon, what would the world look like now? There was always a sense that Teddy, the baby Kennedy brother would rise up and take the mantle and place that seemed to belong to this family. He would restore Camelot. Alas it was not to be. His time just never came. Though he ran a noble race, Chappaquiddick haunted and doomed his candidacy. After that Teddy was the patron of a family that just seemed unable to escape tragedy. One mishap after another befell this family that had been previously granted so much good fortune. It truly did seem as if they were cursed. Teddy himself had his ups and downs with drinking and divorce and the health of his children. Though he asked us to never let the dream die, the legacy of Camelot did seem to pass on.<br /><br />Through it all Ted Kennedy continued to do good work for this country in the Senate. Looking back Teddy's legislative record has probably had more of an influence on this country than either of his brothers had. His name is attached to many of the greatest laws passed over the last 40 years. Teddy was also a great orator. Many say that his <a href="http://www.youtube.com/watch?v=ydHc-ExClqw">finest speech was as the keynote speaker</a> at the 1980 Democratic Convention, when he mounted his challenge to a sitting President Carter. But for me Teddy's finest moment was in delivering the eulogy for his brother Bobby. The &quot;some man ask why, Bobby dreamed of what could be and asked why not&quot; speech never ceases to move me. I include this You Tube as a tribute to Ted Kennedy and all that he and his brothers meant to me along with my prayers for a recovery from this terrible condition.</div>

<div class="youtube-video"><embed src="http://www.youtube.com/v/FiCLi9ddqlM" width="425" height="355" type="application/x-shockwave-flash" wmode="transparent"></embed> </div></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=1oE6ag"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=1oE6ag" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=MMYVHH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=MMYVHH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=cQDvkH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=cQDvkH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=BHEnLH"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=BHEnLH" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=bRDG6H"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=bRDG6H" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=Q8X8mh"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=Q8X8mh" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=HIvGxh"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=HIvGxh" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/294782921" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 20 May 2008 20:04:43 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/ted kennedy">ted kennedy</category>
      <category domain="http://www.securityratty.com/tag/kennedy">kennedy</category>
      <category domain="http://www.securityratty.com/tag/remember ted kennedy">remember ted kennedy</category>
      <category domain="http://www.securityratty.com/tag/ted">ted</category>
      <category domain="http://www.securityratty.com/tag/john kennedy">john kennedy</category>
      <category domain="http://www.securityratty.com/tag/bobby kennedy">bobby kennedy</category>
      <category domain="http://www.securityratty.com/tag/bobby">bobby</category>
      <category domain="http://www.securityratty.com/tag/bobby shortly">bobby shortly</category>
      <category domain="http://www.securityratty.com/tag/remember">remember</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/294782921/ted-kennedy-a-l.html">Ted Kennedy: a lifetime of achievement, regrets of a world that could have been</source>
    </item>
    <item>
      <title><![CDATA[Cloud Computing and Security For The Masses: Interview on NPR]]></title>
      <link>http://www.securityratty.com/article/d49ca0c4436e96b33089d50f7d820a36</link>
      <guid>http://www.securityratty.com/article/d49ca0c4436e96b33089d50f7d820a36</guid>
      <description><![CDATA[Cloud Computing is starting to escape the technical and business press
The proof
I was invited to talk about Cloud Computing and Security on NPR Morning Edition
NPR - National Public Radio - is a US...]]></description>
      <content:encoded><![CDATA[<p><img class="left" src="http://media.npr.org/images/logo_npr_125.gif" alt="US National Public Radio" width="125" height="42" /></p>
<p>Cloud Computing is starting to escape the technical and business press.</p>
<p>The proof?</p>
<p>I was invited to talk about Cloud Computing and Security on NPR &#8220;Morning Edition&#8221;.</p>
<p>NPR - National Public Radio - is a US based, non-commercial radio station covering news, talk and current affairs.  British readers may find it similar to BBC Radio 4.</p>
<p>Every Monday, the &#8220;Morning Edition&#8221; has a technology theme.  The Cloud Computing segment was high level and aimed primarily at a non-tech audience.  I always find it hard to answer the question &#8216;what is Cloud Computing?&#8217; as there are so many different definitions.  Regardless, it was a great chance to talk about an exciting technology and highlight the need for a real security conversation between the providers and people interested in IT security - the primary reason why I created cloudsecurity.org.</p>
<p>The show boasts a very impressive audience - around 13 million!  I&#8217;ve never before had the opportunity to confuse that many people in one shot ;-).</p>
<p>If you would like to listen (its short - 3.5 mins), click <a href="http://www.npr.org/templates/story/story.php?storyId=90180142">here</a>.</p>
<p>I&#8217;d like to publicly thank Nina at NPR for reaching out and extend a warm &#8216;Welcome&#8217; to any NPR listeners who have dropped by.  Feel free to leave a message below or <a href="http://cloudsecurity.org/contact/">email me</a> if you have any comments or questions.</p>
<img src="http://feeds.feedburner.com/~r/CloudSecurity/~4/283882968" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 05 May 2008 07:52:27 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/security">security</category>
      <category domain="http://www.securityratty.com/tag/npr">npr</category>
      <category domain="http://www.securityratty.com/tag/cloud">cloud</category>
      <category domain="http://www.securityratty.com/tag/real security conversation">real security conversation</category>
      <category domain="http://www.securityratty.com/tag/npr listeners">npr listeners</category>
      <category domain="http://www.securityratty.com/tag/national public radio">national public radio</category>
      <category domain="http://www.securityratty.com/tag/technology theme">technology theme</category>
      <category domain="http://www.securityratty.com/tag/technology">technology</category>
      <category domain="http://www.securityratty.com/tag/non-commercial radio station">non-commercial radio station</category>
      <source url="http://feeds.feedburner.com/~r/CloudSecurity/~3/283882968/">Cloud Computing and Security For The Masses: Interview on NPR</source>
    </item>
  </channel>
</rss>
