<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: magical]]></title>
    <link>http://www.securityratty.com/tag/magical</link>
    <description></description>
    <pubDate>Tue, 25 Mar 2008 02:27:19 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Extraordinary Journey from Fundamental Electronics to Fabulous Enchanted Systems with Arduino's and Magical Potions]]></title>
      <link>http://www.securityratty.com/article/a4a9c781028d6546cebed713bcce8f51</link>
      <guid>http://www.securityratty.com/article/a4a9c781028d6546cebed713bcce8f51</guid>
      <description><![CDATA[New Video: Extraordinary Journey from Fundamental Electronics to Fabulous Enchanted Systems with Arduino's and Magical Potions

This is Morgellon and Droop's talks about hacking the Arduino micro...]]></description>
      <content:encoded><![CDATA[New Video:<a href="http://www.irongeek.com/i.php?page=videos/droops-lowtek-arduino-pn12">Extraordinary Journey from Fundamental Electronics to Fabulous Enchanted Systems with Arduino's and Magical Potions</a>
<p></p>
<p align="left">This is Morgellon and Droop's talks about hacking the <a href="http://dailyduino.com/">Arduino</a> micro controller platform from <a href="http://www.phreaknic.info">Phreaknic 12</a>.&nbsp;Droops and Morgellon will take you from basic electronics to building embedded systems. Learn how to build a standalone RFID tag reader with a fancy LCD display or your own oscilloscope or children's toys that speak to you or how to solar power a geothermal heat pump. There may even be some giveaways and contests. Magical Potions will be consumed but not provided. </p>
<p>Check out the following sites by Droops and Morgellon: <br/><a href="http://dailyduino.com/">http://dailyduino.com/</a><br/><a href="http://www.hackermedia.org/">http://www.hackermedia.org/</a></p>
<p>I've done a little work to pull some noise out of the audio, but I may have made it worse in some spots. Thanks go out to the Phreaknic 12 A/V team SomeNinjaMaster, Night Carnage, Greg, Brimstone, Poiu Poiu, Mudflap, and Drunken Pirate for setting up the rigs and capturing the video.</p>
<p><a href="http://feedads.googleadservices.com/~a/-1w0GvsLt4diXUfPsHOAajrNdz8/a"><img src="http://feedads.googleadservices.com/~a/-1w0GvsLt4diXUfPsHOAajrNdz8/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/WllKX0QCAYk" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 29 Oct 2008 19:00:18 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/magical potions">magical potions</category>
      <category domain="http://www.securityratty.com/tag/systems">systems</category>
      <category domain="http://www.securityratty.com/tag/extraordinary journey">extraordinary journey</category>
      <category domain="http://www.securityratty.com/tag/fundamental electronics">fundamental electronics</category>
      <category domain="http://www.securityratty.com/tag/fancy lcd display">fancy lcd display</category>
      <category domain="http://www.securityratty.com/tag/geothermal heat pump">geothermal heat pump</category>
      <category domain="http://www.securityratty.com/tag/morgellon">morgellon</category>
      <category domain="http://www.securityratty.com/tag/fabulous">fabulous</category>
      <category domain="http://www.securityratty.com/tag/phreaknic">phreaknic</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/WllKX0QCAYk/i.php">Extraordinary Journey from Fundamental Electronics to Fabulous Enchanted Systems with Arduino's and Magical Potions</source>
    </item>
    <item>
      <title><![CDATA[Technology Tales from Thailand: KBank Fraud Management]]></title>
      <link>http://www.securityratty.com/article/5f893d1cf14b7adbe58a329292652735</link>
      <guid>http://www.securityratty.com/article/5f893d1cf14b7adbe58a329292652735</guid>
      <description><![CDATA[In The Magical ATM Card and SMS Message in Thailand we talked about booking flights and securely paying using a SMS PayCode and ATM transfer, avoiding the possibility of on-line credit card fraud; and...]]></description>
      <content:encoded><![CDATA[<p>In <a title="The Magical ATM Card and SMS Message in Thailand" rel="bookmark" href="http://www.thecepblog.com/2008/08/03/the-magical-atm-card-and-sms-message-in-thailand/"><span style="color: #105cb6;">The Magical ATM Card and SMS Message in Thailand</span></a> we talked about booking flights and securely paying using a SMS PayCode and ATM transfer, avoiding the possibility of on-line credit card fraud; and in <a title="Keyloggers: Why Banks Need Two-Factor Authentication" rel="bookmark" href="http://www.thecepblog.com/2008/01/14/keyloggers-why-banks-need-two-factor-authentication/"><span style="color: #105cb6;">Keyloggers: Why Banks Need Two-Factor Authentication</span></a> I described how <a href="http://www.kasikornbank.com/portal/site/KBank/?" target="_blank">KBank</a> uses SMS-based one-time-passwords (OTP) to authenticate transactions.   </p>
<p>In addition to the above services, KBank offers a service that permits users to receive an SMS message that details any change in account balance and/or point-of-sale (POS) transaction with your debit card.   I really like this service and the feeling of security knowing when, where and by how much my balance changes or my debit card is used in a transaction.    The KBank POS SMS notification is so fast that when I present my card to a merchant I normally receive an SMS message detailing the transaction before the merchant returns for my signature.  (There is an unfortunate lag in the balance change notification that can run minutes to hours behind real-time, but the POS VISA debit card notification is real-time).</p>
<p>As the story goes,  I should have been using my KBank card and account a few weeks ago and not my US-based VISA debit dard.  Why?</p>
<p>My US-based VISA debit card was cloned sometime on or before August 8th.   I am really careful with this card, so I was surprised the magnetic strip was cloned at a POS merchant.   The fraudster made 7 fraudulent transactions beginning on August 8th for a total of around $2500 USD, mostly on August 11th, before I discovered the fraudulent transactions viewing my account on-line.</p>
<p>This would not have happened with KBank SMS-based transaction notification services.</p>
<p>The first transaction with my cloned VISA debit card was less than $50 USD (I assume the fraudster was &#8220;testing the water&#8221;).   If I was using my KBank card, I would have received an immediate SMS message detailing a POS transaction in Bangkok when I was physically far away from Bangkok in Chiang Mai.   I could have immediately called the bank (or logged in) and blocked the debit card, limiting potential losses to the bank or the merchant to one fraudulent transaction, not seven.</p>
<p>In addition, KBank offers what they call a Web-Shopping VISA card, where you can go into your on-line account (verified by SMS OTP as mentioned) and request a VISA debit card number (with expiration date, CCV etc).   You set the limit from 0 to 500,000 THB (Thai Baht) per day; and you can login to your account and change this anytime (authenticating your transaction with another SMS-based OTP). You can also block or cancel this number anytime and apply for another one.</p>
<p>I am amazed that in Thailand I receive much better anti-fraud prevention and detection services than with banks in the US.   I know of no bank or brokerage in the US that offers the same quality of service and security as KBank in Thailand.  </p>
]]></content:encoded>
      <pubDate>Wed, 20 Aug 2008 03:16:51 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/visa debit card">visa debit card</category>
      <category domain="http://www.securityratty.com/tag/debit card">debit card</category>
      <category domain="http://www.securityratty.com/tag/card">card</category>
      <category domain="http://www.securityratty.com/tag/visa card">visa card</category>
      <category domain="http://www.securityratty.com/tag/kbank">kbank</category>
      <category domain="http://www.securityratty.com/tag/kbank card">kbank card</category>
      <category domain="http://www.securityratty.com/tag/transaction">transaction</category>
      <category domain="http://www.securityratty.com/tag/transaction notification services">transaction notification services</category>
      <category domain="http://www.securityratty.com/tag/fraudulent transaction">fraudulent transaction</category>
      <source url="http://www.thecepblog.com/2008/08/20/technology-tales-from-thailand/">Technology Tales from Thailand: KBank Fraud Management</source>
    </item>
    <item>
      <title><![CDATA[The Magical ATM Card and SMS Message in Thailand]]></title>
      <link>http://www.securityratty.com/article/1ba59a13d2493ca9d5042d5c2f7ceb4e</link>
      <guid>http://www.securityratty.com/article/1ba59a13d2493ca9d5042d5c2f7ceb4e</guid>
      <description><![CDATA[It was not too long ago that I penned Keyloggers: Why Banks Need Two-Factor Authentication . In that post, I briefly mentioned how a number of banks in Thailand use inexpensive SMS-based two-factor...]]></description>
      <content:encoded><![CDATA[<p>It was not too long ago that I penned <a href="http://www.thecepblog.com/2008/01/14/keyloggers-why-banks-need-two-factor-authentication/">Keyloggers: Why Banks Need Two-Factor Authentication</a>. In that post, I briefly mentioned how a number of banks in Thailand use inexpensive SMS-based two-factor authentication (2FA) with one-time password (OTP) to authenticate transactions.</p>
<p>One of my favorite banks in Thailand is <a href="http://www.kasikornbank.com/portal/site/KBank/?" target="_blank">K-Bank</a>. With K-Bank I can simply walk up to an ATM machine and pay a mobile phone bill, purchase mutual funds, buy insurance, or transact an ever-growing list of services payable at the modern and sleek K-Bank ATM.</p>
<p>For example, tomorrow I fly to Chiang Mai in Northern Thailand and found K-Bank&#8217;s service amazingly better than in the US. For example, I booked my flight as usual (over the phone, but could have used the Internet) and told the reservation agent I was going to pay by ATM. He simply gave me a PayCode and told me I had three hours to go to the ATM and enter the PayCode to perfect my reservation.  I also got the PayCode via SMS.  This gave me the time I needed to make sure I had <a href="http://www.r24.org/whatsonchiangmai.com/chiangmai/fernparadise/pictures/" target="_blank">booked the perfect boutique hotel</a> in Chiang Mai, the <strong><a href="http://www.r24.org/whatsonchiangmai.com/chiangmai/fernparadise/review/" target="_blank">Fern Paradise</a>.</strong></p>
<p>Then, I went out into the beautiful Thai weather and completely my airplane reservation at the ATM machine; which also printed out a receipt with my flight details and reservation number.</p>
<p>It sometimes amazes me how much further advanced some services are in Thailand compared to the US. To me, it feels more secure not to use an on-line payment center or give out my credit card details over the phone. I can simply book a ticket, take a PayCode, and complete the transaction at a nice modern, shiny, K-Bank ATM machine.</p>
<p>Who knows, maybe soon I can select the perfect window seat at the ATM and the receipt will act as my boarding pass!</p>
]]></content:encoded>
      <pubDate>Sun, 03 Aug 2008 09:30:52 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/atm">atm</category>
      <category domain="http://www.securityratty.com/tag/k-bank atm machine">k-bank atm machine</category>
      <category domain="http://www.securityratty.com/tag/sleek k-bank atm">sleek k-bank atm</category>
      <category domain="http://www.securityratty.com/tag/k-bank">k-bank</category>
      <category domain="http://www.securityratty.com/tag/thailand">thailand</category>
      <category domain="http://www.securityratty.com/tag/atm machine">atm machine</category>
      <category domain="http://www.securityratty.com/tag/banks">banks</category>
      <category domain="http://www.securityratty.com/tag/perfect window seat">perfect window seat</category>
      <category domain="http://www.securityratty.com/tag/perfect">perfect</category>
      <source url="http://www.thecepblog.com/2008/08/03/the-magical-atm-card-and-sms-message-in-thailand/">The Magical ATM Card and SMS Message in Thailand</source>
    </item>
    <item>
      <title><![CDATA[Easy Google Income]]></title>
      <link>http://www.securityratty.com/article/78a5400adaadfa51b7dc44e905a348a8</link>
      <guid>http://www.securityratty.com/article/78a5400adaadfa51b7dc44e905a348a8</guid>
      <description><![CDATA[Here's an interesting piece of spam trying to cash in on the Google name that could wind up being quite costly for anyone willing to take a chance and see what it's all about. This was sent to one of...]]></description>
      <content:encoded><![CDATA[
        Here's an interesting piece of spam trying to cash in on the Google name that could wind up being quite costly for anyone willing to take a chance and see what it's all about. This was sent to one of my friends:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/goffer0.html" onclick="window.open('http://blog.spywareguide.com/images/goffer0.html','popup','width=537,height=530,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/goffer0-thumb-337x332.jpg" alt="goffer0.jpg" class="mt-image-none" style="" height="332" width="337" /></a></span><br /> </div><div><div align="center"><br />Click to Enlarge<br /></div><br />Is it a good thing or a bad thing that the office is based in the West Indies and to unsubscribe your email goes to Romania? At any rate, they don't seem to <a href="http://blog.spywareguide.com/images/goffer1.jpg">want my patronage</a> - unfortunately, I'm not particularly interested in free iPods or a Nintendo Wii so a few clicks later and I'm where I should be:<br /><br /><div align="center"><span class="mt-enclosure mt-enclosure-image" style="display: inline;"><a href="http://blog.spywareguide.com/images/goffer2.html" onclick="window.open('http://blog.spywareguide.com/images/goffer2.html','popup','width=878,height=697,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img src="http://blog.spywareguide.com/images/goffer2-thumb-378x300.jpg" alt="goffer2.jpg" class="mt-image-none" style="" height="300" width="378" /></a></span><br /></div></div><div><div align="center"><br />Click to Enlarge<br /></div><br />At the bottom of the page, it says <i>"Google does not sponsor, endorse, and is no way affiliated with Easy Net Income or this promotion."</i><br /><br />Well, they could have fooled me what with all the Google material they've splashed across the site. The quote in the box is interesting, too: <i>"Riches range from a few hundred dollars a month to $50,000 or more a year".</i><br /><br />Go hunting on USA Today though, and the quote doesn't have anything to do with something called "Easy Google Income" - it's to do with <a href="http://www.usatoday.com/tech/news/2005-03-10-google-ads-usat_x.htm">Adsense</a>. Bits missing have been reinserted and bolded:<br /><br />"<b>Tales of AdSense</b> riches range from a few hundred dollars a month to
$50,000 or more a year, <b>though high-dollar paydays are rare. They
require a Web site with tons of traffic and the ability to put in
18-hour days working the system</b>.<br /><br />I think the missing parts are kind of important, don't you? Of course, the CD title clearly makes you think you're going to get some mysterious money magnet, but stops short of telling you whether it would be a program, ebook or magical leprechaun.<br /><br />In fact, what happens is you apparently sign up for the CD at the cost of subscribing yourself to some kind of "free trial" - at the end of which, you have to pay $39.90 a month for access to training courses to "Internet Wealth University" (I swear I'm not making this up). There's also an "activation fee" charged immediately to the card you subscribe with, though I'm guessing you only enter your details once you've entered your name / address and moved onto the second page (which I'm not about to do, in case you were wondering).<br /><br />Internet Wealth University must have an awful lot of poor students, going by the problems people are having <a href="http://www.ripoffreport.com/reports/0/356/RipOff0356749.htm">unsubscribing</a>.<br /><br /><i>"When you try to call the company, you get an automated answering system
that tells you all representatives are busy and then puts you on
hold-forever, or they disconnect you after 5 minutes!"</i><br /><br />Indeed, there's quite a lot of people <a href="http://answers.yahoo.com/question/index?qid=20080630072422AA4Irmi">wondering</a> what this is all about, including the <a href="http://www.friendsinbusiness.com/board1/index.cgi/noframes/read/136859">inevitable concern</a> over <a href="http://answers.yahoo.com/question/index?qid=20080419232112AAh35aR">billing issues</a>.<br /><br />Our advice? Steer well clear. There is a lot of money up for grabs here, but it's all being netted by the people running these websites. Their customers don't appear to be so lucky...<br /><br /></div>
        
    ]]></content:encoded>
      <pubDate>Tue, 29 Jul 2008 13:58:49 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/google">google</category>
      <category domain="http://www.securityratty.com/tag/easy google income">easy google income</category>
      <category domain="http://www.securityratty.com/tag/google material">google material</category>
      <category domain="http://www.securityratty.com/tag/adsense riches range">adsense riches range</category>
      <category domain="http://www.securityratty.com/tag/internet wealth university">internet wealth university</category>
      <category domain="http://www.securityratty.com/tag/adsense">adsense</category>
      <category domain="http://www.securityratty.com/tag/riches range">riches range</category>
      <category domain="http://www.securityratty.com/tag/mysterious money magnet">mysterious money magnet</category>
      <category domain="http://www.securityratty.com/tag/awful lot">awful lot</category>
      <source url="http://blog.spywareguide.com/2008/07/easy-google-income.html">Easy Google Income</source>
    </item>
    <item>
      <title><![CDATA[Links for 2008-07-23 [del.icio.us]]]></title>
      <link>http://www.securityratty.com/article/4c8a5b54d951b74d6db1eb5a6e4deea5</link>
      <guid>http://www.securityratty.com/article/4c8a5b54d951b74d6db1eb5a6e4deea5</guid>
      <description><![CDATA[Sponsored Posting: What is GRC and why should I care? | RiskBloggers.com
Burton Group Identity Blog: Chasing the magical GRC...]]></description>
      <content:encoded><![CDATA[<ul>
<li><a href="http://www.riskbloggers.com/neupart/2008/07/sponsored-posting-what-is-grc-and-why-should-i-care/">Sponsored Posting: What is GRC and why should I care? | RiskBloggers.com</a></li>
<li><a href="http://bgidps.typepad.com/bgidps/2008/07/chasing-the-mag.html">Burton Group Identity Blog: Chasing the magical GRC animal</a></li>
</ul><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/344250688" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 23 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/grc">grc</category>
      <category domain="http://www.securityratty.com/tag/magical grc animal">magical grc animal</category>
      <category domain="http://www.securityratty.com/tag/identity blog">identity blog</category>
      <category domain="http://www.securityratty.com/tag/burton">burton</category>
      <category domain="http://www.securityratty.com/tag/riskbloggers">riskbloggers</category>
      <category domain="http://www.securityratty.com/tag/care">care</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/344250688/anton18">Links for 2008-07-23 [del.icio.us]</source>
    </item>
    <item>
      <title><![CDATA[Interview with Paul Cannon, Mozy Software Engineer]]></title>
      <link>http://www.securityratty.com/article/0cc76ea91cbf8ad59a01671da9da1295</link>
      <guid>http://www.securityratty.com/article/0cc76ea91cbf8ad59a01671da9da1295</guid>
      <description><![CDATA[Mozy Awesome Process
Sometimes people come up to me and say, Paul, how is it that Mozy has created such an unrelenting output of Awesome
Today I have been authorized to share with you some of the...]]></description>
      <content:encoded><![CDATA[<p><span style="font-size: small;"><span style="font-weight: bold;">Mozy Awesome Process</span></span><br />
Sometimes people come up to me and say, &#8220;Paul, how is it that Mozy has created such an unrelenting output of Awesome?&#8221;</p>
<p>Today I have been authorized to share with you some of the unique facets of the Mozy Awesome Process that until now have been tightly controlled trade secrets of Mozy, Inc. It all starts with giant robots (virtually perpetual sources of raw Awesome). We attach them to special Awesome Siphons of our own design and pipe the yield directly into our engineers&#8217; development workstations. Further, peripheral Awesome needs are farmed from old He-Man reruns, a roomful of ninjas wailing on electric guitars, and our captive Happy Fun Ball.</p>
<p>The crude Awesome is skillfully transformed by Mozy engineers into powerful software and hardware configurations, then carefully inspected and regulated according to a host of eldritch acronyms: SWAGs, PMQs, PRDs, and the ever-inspiring CFRRCs. Once a successful creation is stamped with the Seal of Acronymic Approval for Mozy (SAAM), it is subjected to final endorsement by the mystical, revered Mozy Leprecorn*. Finally, a highly trained team of Box Monks put the new Awesomery into place in the Mozy systems, where it becomes available to you, the user.</p>
<p>Our rigorous Awesome Enforcement Policies and Magical Oversight have brought us to what we believe is the most Awesome-efficient development process in the world of backup software.</p>
<p>Be safe,<br />
Paul Cannon<br />
Mozy Software Engineer</p>
<p>*Leprecorn (noun): a rare but phenomenal creature; half Unicorn, half Leprechaun, and all magical.</p>
<p><a title="Mozy" href="http://www.mozy.com/?ref=3f9a896b&amp;kbid=38419&amp;m=4&amp;i=77" target="_blank">Visit Mozy now for a great reliable online backup service, I use it myself.</a></p>
<p><img src="file:///C:/Users/SPYWAR~1/AppData/Local/Temp/moz-screenshot.jpg" alt="" /></p>
<p><img src="file:///C:/Users/SPYWAR~1/AppData/Local/Temp/moz-screenshot-1.jpg" alt="" /></p>
<p><img src="file:///C:/Users/SPYWAR~1/AppData/Local/Temp/moz-screenshot-2.jpg" alt="" /></p>
<p><span style="font-size: small;"><span style="font-weight: bold;">Vote for Mozy</span></span><br />
Lifehacker is currently holding an online backup showdown. Show your love for Mozy. <a title="Vote for Mozy on Lifehacker.com" href="http://click.news.mozy.com/?ju=fe3415747265057c761075&amp;ls=fdf011757767027476137173&amp;m=fef012747c6103&amp;l=fe881576736c01787d&amp;s=fe601679776d007d7014&amp;jb=ffcf14&amp;t=">Vote now</a>.</p>
]]></content:encoded>
      <pubDate>Wed, 16 Jul 2008 11:00:49 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/mozy">mozy</category>
      <category domain="http://www.securityratty.com/tag/mozy systems">mozy systems</category>
      <category domain="http://www.securityratty.com/tag/visit mozy">visit mozy</category>
      <category domain="http://www.securityratty.com/tag/mozy awesome process">mozy awesome process</category>
      <category domain="http://www.securityratty.com/tag/mozy software engineer">mozy software engineer</category>
      <category domain="http://www.securityratty.com/tag/awesome">awesome</category>
      <category domain="http://www.securityratty.com/tag/special awesome siphons">special awesome siphons</category>
      <category domain="http://www.securityratty.com/tag/mozy leprecorn">mozy leprecorn</category>
      <category domain="http://www.securityratty.com/tag/raw awesome">raw awesome</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=504">Interview with Paul Cannon, Mozy Software Engineer</source>
    </item>
    <item>
      <title><![CDATA[Your 419 Mail Roundup]]></title>
      <link>http://www.securityratty.com/article/2aa9ff3c4bf96550fcb31a394b91e2bc</link>
      <guid>http://www.securityratty.com/article/2aa9ff3c4bf96550fcb31a394b91e2bc</guid>
      <description><![CDATA[Are you ready for more 419 missives

Of course you are. Plenty of winning lottery tickets, fictitious banks, a wonderfully sick &quot;Robert Mugabe&quot; themed mail and, er, someone called &quot;Captain Frank Bojo&quot;...]]></description>
      <content:encoded><![CDATA[
        Are you ready for more 419 missives?<br /><br />Of course you are. Plenty of winning lottery tickets, fictitious banks, a wonderfully sick "Robert Mugabe" themed mail and, er, someone called "Captain Frank Bojo" after the jump...<br /> 
        Subject:<br />HELLO DEAR<br />From:<br />"abavanagift13 Gazeta.pl" &lt;abavanagift13@gazeta.pl&gt;<br />Date:<br />Sat, 21 Jun 2008 12:26:24 +0000<br />BCC:<br /><br />Hello Dear,<br />&nbsp;<br />&nbsp;My name is Blessing Abavana, the elder daughter of Mr. paul Abavana of Zimbabwe, I am 17 years old with my younger brother (Micheal), we are in Ghana as refuge/asylum since we lost our parents because of the recent war that occurred in our country.please do go through this web page for better understanding with full details:<br />&nbsp;<br />&nbsp;http://www.rte.ie/news/2000/0418/zimbabwe.html<br />&nbsp;<br />&nbsp;I am looking for one&nbsp; who will honestly assist my younger brother and I to realize our inherited funds into your account and as well as invest it into a lucrative business.<br />&nbsp;<br />During the recent war against the farmers in Zimbabwe from the supporters of our President, Robert Mugabe to claim all the white -owned farms to his party members and his followers, he ordered all the white farmers to surrender all their farms to his party members and his followers.<br />&nbsp;<br />&nbsp;My father being one of the few rich and successful black farmers in our country was also victimized because of his opposition to Mugabe's policies. And because he did not support Mugabe's ideas, Mugabe's supporters invaded my father's farm and burnt everything in the farm, killed my father and made away with a lot of items in my father's farm. This action was taken because my late father felt the growing tension on the farm issue, but I guess he never anticipated the tragedy that brought their brutal and sudden death.<br />&nbsp;<br />&nbsp;However with the benefit of hindsight, owing to the looming but deteriorating crisis in my country, Zimbabwe, my father, before his unfortunate death deposited with International Commercial Bank (ICB) here in Accra Ghana the sum of US$ 35MUsd (Thirty Five Million United States Dollars), with the sole aim of acquiring and buying some dredging equipments in setting up of a dredging firm with his partner. With his death and all his assets seized at home and accounts frozen, the family is now in a very difficult situation.<br />&nbsp;<br />&nbsp;After the death of my father, my brother and I escaped to the Republic of Ghana where he had deposited the money in the Bank . And we were permitted to reside here as Political Refugees.<br />&nbsp;<br />&nbsp;So Because of our present and unpleasant status here we decided to contact an overseas firm / individual that can assist us to move this money out Of Ghana because, as asylum seekers, we are not allowed to operate any financial transaction of such amount within Ghana and also to assist in providing me and my brother a permanent residential permit in your country after the money must have been transferred to your account.<br />&nbsp;<br />We have agreed to offer you 30% of the total sum for your assistance, and the rest will be for my brother and I, to Invest in your country under your assistant<br />&nbsp;<br />All I want you to do is to furnish me with the below information including your readiness to assist me achieve this transaction for investment purposes in your country under your supervision. Kindly re-confirm to me the followings:<br /><br />1) Your Full Name:<br />2) Phone, Fax and Mobile<br />3) Profession, Age and Marital Status.<br />4) Nationality<br />&nbsp;<br />&nbsp;I have to re-assure you that this transaction is 100% risk free and should be treated with absolute confidentiality. All the vital documentation/certification that has to do with the origin of the fund is with me for the security reasons.And I will send them to you when we progress.And I guarantee you that this fund is not government fund, drug money, or from arms deals.<br />&nbsp;<br />&nbsp;I will detail you more about&nbsp; the bank&nbsp; immediately I receive your acceptance response. I hope this is the beginning of a prosperous relationship between us.Thanks and God bless you<br />&nbsp;<br />Regards<br /><br />Blessing/Micheal Abavana<br /><br /><b>(Wow, spectacularly sick. Not that we're expecting scammers to have any morals, of course).</b><br /><br />*********************************************************************************************<br /><br /><br />Subject:<br />Lycos Online Lottery Notification<br />From:<br />"LHOUTY MOHAMMED HASSANE" &lt;mhlhouty@menara.ma&gt;<br />Date:<br />Sun, 22 Jun 2008 02:42:53 -0000<br />BCC:<br /><br />LYCOS LOTTERY ONLINE<br />8th Floor<br />1 Stephen Street<br />London<br />W1T 1AL<br />&nbsp;<br />WINNING NOTIFICATION<br />This is to inform you that your email address has won the Lycos Lottery for the year 2008. your email has won you the sum of ?952,350.00 (Nine Hundred And Fifty Two Thousand, Three Hundred And Fifty pounds sterling).<br />You are advised to keep this notice confidential to avoid misinterpretation of funds and unauthorize claims, cheating or fraud.<br />To claim your funds please contact us with the information below.<br />Name: Dr. George Stevenson<br />Tel:+447031991681<br />Email:lycosclaimsdpt@gmail.com<br />&nbsp;<br />It is mandatory that you send us your full names, address, phone number,<br />age, sex and occupation to enable us arrange your claim.<br />&nbsp;<br />Note: Winners were selected through a computer ballot system drawn from Microsoft users from company and individual email addresse users. All winning must be claimed not later than 21 working days from the time of notification. After this date all unclaimed funds will be returned to European Union Treasury as unclaimed funds.<br />&nbsp;<br />Congratulations from mambers and staff of Lycos<br />Lhouty Mohammed Hassane.<br />Lycos Lottery Co-ordinator<br /><br /><b>(A "Lycos Lottery" and they're using a GMail address? Doh).</b><br /><br />*********************************************************************************************<br /><br />Subject:<br />Yukos Oil<br />From:<br />Mr. Timinskiy Vladimir &lt;grooves@bellnet.ca&gt;<br />Date:<br />Wed, 25 Jun 2008 5:38:17 -0400<br />To:<br />&lt;info@yukos.org&gt;<br /><br />I have a profiling amount in an excess of US$100.5M, which I seek you in accommodating for me. You will be rewarded with 4% .If intrested, please reply me for moredetails...&lt;tvlad4@gmail.com&gt;<br />Regards<br />Mr. Timinskiy Vladimir<br /><br /><b>(Short. Sweet. Pointlessly fake).</b><br /><br />*******************************************************************************<br /><br />Subject:<br />Immediate Release of Your FUND Via ATM CARD<br />From:<br />"Mr. Mark Louis" &lt;francois.lapeyronie@wanadoo.fr&gt;<br />Date:<br />Wed, 25 Jun 2008 01:45:09 -0700<br />To:<br />undisclosed-recipients:;<br /><br />SUBJECT: Immediate Release of Your FUND Via ATM CARD<br /><br />Attention: ATM Card Beneficiary,<br /><br />I wish to use this medium to inform you that your CONTRACT/INHERITANCE Paymen of USD$10,000,000.00 (Ten Million United States Dollars) from CENTRAL BANK<br />OF NIGERIA have been RELEASED and APPROVED for onward transfer to you via an ATM CARD which you will use to withdraw all the USD$10,000,000.00 in any<br />ATM SERVICE MACHINE in any part of the world, but the maximum you can withdraw in a day is USD$10,000.00 Only.<br /><br />We have mandated IBTC CHARTERED BANK PLC, to send you the ATM CARD and PIN NUMBER which you will use to withdraw all your USD$10 Million Dollars in<br />any ATM SERVICE MACHINE in any part of the world. You are therefore advice to contact the Head of ATM CARD Department of IBTC CHARTERED BANK PLC;<br /><br />Contact Person: Dr. Olu James<br />Office email address:&nbsp;&nbsp; pcfc_nigeria@yahoo.com<br />Private: +2347084501007<br />Office:018969906<br /><br />Tell Dr. Olu James that you received a message from the CENTRAL BANK OF NIGERIA. Instructing him to send you the ATM CARD and PIN NUMBER which you will use<br />to withdraw your USD$10 Million Dollars in any ATM SERVICE MACHINE in any part of the world, also send him your direct phone number and contact address<br />where you want him to send the ATM CARD and PIN NUMBER to you. We are very sorry for the plight you have gone through in the past years. Thanks for adhering to this instruction and once again accept our congratulations.<br /><br />Best Regards.<br />Mr. Mark Louis.<br />Executive Governor,<br /><br />Central Bank of Nigeria {CBN}.<br /><br /><b>(Ah, the old "Let's lure them in with the magical bank card" trick).</b><br /><br /><br />******************************************************************************************<br /><br />Subject:<br />CONTACT THE FEDEX COMPANY FOR YOUR FUNDS<br />From:<br />"SAMUEL DUNBAR" &lt;samuel_dunbar0013@ig.com.br&gt;<br />Date:<br />Fri, 20 Jun 2008 12:33:43 +0100<br />BCC:<br /><br />Dear Friend,<br /><br />Compliment of the new year, I have been waiting for you since to come down here and pick your Bank Draft which my boss left with me before he travelled to England but I did not hear from you since that time till today. I went to the bank to confirm whether the draft is getting close to expire as it had been long time my boss issued the draft. The director of the bank told me that before the draft will get to you, that it will expire. Then I told him to help me and cash the cashier bank draft of $1,500.000.00 to cash payment.<br /><br />However, I have successfully cashed the draft and packaged it in a box and have registered it in the Fedex Express Company Service here in Benin Republic because I will travell to see my boss in England and will not come back till August 20th 2008. You have to contact the Fedex Express Company Service to know when they will deliver your package to your address. I have paid for the delivering charges and insurance fees. The only money you have to send to them is their security keeping feeswhich is USD$135.00 USD to receive your package. Don't be deceived by any body.<br /><br />This is their Contact Address;<br />Attn: Cheif Mr. George Kobra (Director)<br />Tel:&nbsp; +229-9799 2240<br />E-mail: fc.bj@sify.com<br /><br />Send them your contacts information to enable them locate you<br />&nbsp;immediately they arrived in your country with your package.<br /><br />This is the information they needed from you.<br /><br />1. Your full name:.....<br />2. Your shipping/home address:.....<br />3. Your tel no #......<br />4. Your current office tel no #<br />5. A copy of your passport.<br /><br />Try to contact them as soon as possible to avoid increasement of the security keeping fees Note; I didn't tell the Fedex Express Company Service that it's money inside the box, I registered it as a church of a Church Minister Materials. This is to avoid delay or any upfront problem during the delivery. So, do not let them know that the package contents money. Do let me know as soon as you received your package. You will contact&nbsp; me only through e-mail as my phone is no longe available now that I am out from our country. Contact me at samdunbar1986@yahoo.com and I will reply as soon as I can.<br />I wish you and your family Long Life,<br />Prosperity and Happy 2008.<br /><br />Thanks and Remain Blessed.<br /><br />Yours sincerely,<br />Mr.Samuel Dunbar<br />(Secretary)<br /><br /><b>(Honestly, if you contact FedEx they'll give you tons of money....)</b><br /><br />****************************************************************************************<br /><br />That's your lot for another week....<br />
    ]]></content:encoded>
      <pubDate>Wed, 25 Jun 2008 09:29:29 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/central bank">central bank</category>
      <category domain="http://www.securityratty.com/tag/bank">bank</category>
      <category domain="http://www.securityratty.com/tag/magical bank card">magical bank card</category>
      <category domain="http://www.securityratty.com/tag/bank draft">bank draft</category>
      <category domain="http://www.securityratty.com/tag/email address">email address</category>
      <category domain="http://www.securityratty.com/tag/office email address">office email address</category>
      <category domain="http://www.securityratty.com/tag/bank immediately">bank immediately</category>
      <category domain="http://www.securityratty.com/tag/lycos lottery">lycos lottery</category>
      <category domain="http://www.securityratty.com/tag/office">office</category>
      <source url="http://blog.spywareguide.com/2008/06/your-419-mail-roundup.html">Your 419 Mail Roundup</source>
    </item>
    <item>
      <title><![CDATA[Its All Friggin Magic, Mkay?]]></title>
      <link>http://www.securityratty.com/article/22c7dc12b338751ca5fdfce977683aff</link>
      <guid>http://www.securityratty.com/article/22c7dc12b338751ca5fdfce977683aff</guid>
      <description><![CDATA[OK, whoever named this product should be shot: Ashampoo Magical Security
However, as much as I love sprinkling on the Magic FISMA Fairy Dust , Magical Security is craziness
I wont go into too much...]]></description>
      <content:encoded><![CDATA[<p>OK, whoever named this product should be shot:  <a href="http://www.ashampoo-security.com/product.php?idstring=0704&amp;session_langid=2" target="_blank">Ashampoo Magical Security</a>.</p>
<p>However, as much as I love sprinkling on the <a href="http://www.guerilla-ciso.com/archives/216" target="_blank">Magic FISMA Fairy Dust</a>, &#8220;Magical Security&#8221; is craziness.</p>
<p>I won&#8217;t go into too much detail on hackers, shampoo, washing, and <a href="http://en.wikipedia.org/wiki/South_Pacific_(musical)" target="_blank">South Pacific</a>.  I have a feeling I&#8217;ll get plenty of comments to that effect.</p>
<!-- Social Bookmarks BEGIN --><div class="social_bookmark"><em>Bookmark to:</em><br /><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://del.icio.us/post?url=http://www.guerilla-ciso.com/archives/417&amp;title=It%26%238217%3Bs+All+Friggin%26%238217%3B+Magic%2C+Mkay%3F" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Del.icio.us"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/delicious.png" border="0" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Del.icio.us" alt="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Del.icio.us" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://digg.com/submit?phase=2&amp;url=http://www.guerilla-ciso.com/archives/417&amp;title=It%26%238217%3Bs+All+Friggin%26%238217%3B+Magic%2C+Mkay%3F" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to digg"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/digg.png" border="0" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to digg" alt="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to digg" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://reddit.com/submit?url=http://www.guerilla-ciso.com/archives/417&amp;title=It%26%238217%3Bs+All+Friggin%26%238217%3B+Magic%2C+Mkay%3F" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to reddit"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/reddit.png" border="0" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to reddit" alt="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to reddit" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://feedmelinks.com/categorize?from=toolbar&amp;op=submit&amp;name=It%26%238217%3Bs+All+Friggin%26%238217%3B+Magic%2C+Mkay%3F&amp;url=http://www.guerilla-ciso.com/archives/417&amp;version=0.7" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Feed Me Links"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/feedmelinks.png" border="0" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Feed Me Links" alt="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Feed Me Links" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.technorati.com/faves?add=http://www.guerilla-ciso.com/archives/417" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Technorati"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/technorati.png" border="0" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Technorati" alt="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Technorati" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://myweb2.search.yahoo.com/myresults/bookmarklet?u=http://www.guerilla-ciso.com/archives/417&amp;t=It%26%238217%3Bs+All+Friggin%26%238217%3B+Magic%2C+Mkay%3F" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Yahoo My Web"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/yahoo_myweb.png" border="0" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Yahoo My Web" alt="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Yahoo My Web" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.stumbleupon.com/refer.php?url=http://www.guerilla-ciso.com/archives/417&amp;title=It%26%238217%3Bs+All+Friggin%26%238217%3B+Magic%2C+Mkay%3F" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Stumble Upon"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/stumbleupon.png" border="0" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Stumble Upon" alt="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Stumble Upon" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http://www.guerilla-ciso.com/archives/417&amp;title=It%26%238217%3Bs+All+Friggin%26%238217%3B+Magic%2C+Mkay%3F" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Google Bookmarks"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/google.png" border="0" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Google Bookmarks" alt="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Google Bookmarks" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.squidoo.com/lensmaster/bookmark?http://www.guerilla-ciso.com/archives/417" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Squidoo"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/squidoo.png" border="0" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Squidoo" alt="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Squidoo" /></a><a class="social_img" onclick="window.open(this.href, '_blank', 'scrollbars=yes,menubar=no,height=600,width=750,resizable=yes,toolbar=no,location=no,status=no'); return false;" href="http://www.bloglines.com/sub/http://www.guerilla-ciso.com/archives/417" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Bloglines"><img src="http://www.guerilla-ciso.com/wp-content/plugins/social_bookmarks/bloglines.png" border="0" title="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Bloglines" alt="Add 'It&#8217;s All Friggin&#8217; Magic, Mkay?' to Bloglines" /></a></div>
<!-- Social Bookmarks END --><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=Z8DYhI"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=Z8DYhI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/TheGuerillaCiso?a=Geooyi"><img src="http://feeds.feedburner.com/~f/TheGuerillaCiso?i=Geooyi" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheGuerillaCiso/~4/313852981" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 17 Jun 2008 11:04:44 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/ashampoo magical security">ashampoo magical security</category>
      <category domain="http://www.securityratty.com/tag/magical security">magical security</category>
      <category domain="http://www.securityratty.com/tag/south pacific">south pacific</category>
      <category domain="http://www.securityratty.com/tag/plenty">plenty</category>
      <category domain="http://www.securityratty.com/tag/effect">effect</category>
      <category domain="http://www.securityratty.com/tag/craziness">craziness</category>
      <category domain="http://www.securityratty.com/tag/comments">comments</category>
      <category domain="http://www.securityratty.com/tag/shampoo">shampoo</category>
      <category domain="http://www.securityratty.com/tag/detail">detail</category>
      <source url="http://feeds.feedburner.com/~r/TheGuerillaCiso/~3/313852981/417">Its All Friggin Magic, Mkay?</source>
    </item>
    <item>
      <title><![CDATA[Slow removal of child sexual abuse image websites]]></title>
      <link>http://www.securityratty.com/article/57964ad3f0792552b81619b8b34f176c</link>
      <guid>http://www.securityratty.com/article/57964ad3f0792552b81619b8b34f176c</guid>
      <description><![CDATA[On Friday last week The Guardian ran a story on an upcoming research paper by Tyler Moore and myself which will be presented at the WEIS conference later this month. We had determined that child...]]></description>
      <content:encoded><![CDATA[<p>On Friday last week <a href="http://www.guardian.co.uk/technology/2008/jun/06/internet.childprotection">The Guardian ran a story</a> on an upcoming research paper by <a href="http://www.cl.cam.ac.uk/~twm29">Tyler Moore</a> and <a href="http://www.cl.cam.ac.uk/~rnc1">myself</a> which will be presented at the <a href="http://weis2008.econinfosec.org/">WEIS</a> conference later this month. We had determined that child sexual abuse image websites were removed from the Internet far slower than any other category of content we looked at, excepting <a href="http://www.ciparx.ca/pages/fraudulent_pharmacies.html">illegal pharmacies</a> hosted on <a href="http://www.honeynet.org/papers/ff/fast-flux.html">fast-flux networks</a>; and we&#8217;re unsure if anyone is seriously trying to remove them at all!<br />
<span id="more-336"></span></p>
<p>It is perhaps timely that this week three large ISPs in the USA have <a href="http://www.startribune.com/nation/19753019.html">announced</a> that they have decided to block access to child sexual abuse image newsgroups on Usenet and remove sites hosting this material from their servers. This was initially <a href="http://www.nytimes.com/2008/06/10/nyregion/10internet.html">inaccurately reported</a> so as to imply the installation of blocking systems for other people&#8217;s websites; which is <a href="http://www.efa.org.au/censorship/mandatory-isp-blocking/">unlikely to be especially effective</a>, and may even <a href="http://www.cl.cam.ac.uk/~rnc1/cleanfeed.pdf">provide an &#8220;oracle&#8221;</a> by which the people who seek illegal material can locate new websites to visit.</p>
<p>Our new paper, <a href="http://www.cl.cam.ac.uk/~rnc1/takedown.pdf">&#8220;The Impact of Incentives on Notice and Take-Down&#8221;</a>, examines a number of different types of wicked Internet content and discusses how effective people are at getting the material removed by serving notices upon the website owners who host it. We have a number of interesting results, but perhaps the most striking is that although phishing websites impersonating banks are generally removed in a couple of hours, the mean lifetime for a website hosting child abuse images is almost a month and even the median (the time by which half of the sites are removed) is 12 days.</p>
<p>We believe that the reason that the child abuse image websites are removed so slowly is that the <a href="http://www.iwf.org.uk">Internet Watch Foundation</a> (IWF), who collate a list of illegal sites, is only prepared to talk directly with the hosting ISPs within the UK. If the site is hosted abroad (which is now 99.8% of all sites) the IWF informs the <a href="http://www.ceop.gov.uk/">UK police</a>, who pass the message on to law enforcement in the relevant country, and that clearly leads to considerable delays. Furthermore, the same parochial attitude appears to be taken by similar organisations in other countries.</p>
<p>The IWF are a member of <a href="http://www.inhope.org">INHOPE</a>, an association of child sexual abuse image reporting hotline organisations operating in 29 countries, and the IWF will also pass reports to the appropriate INHOPE members. However, in the US, which hosts around half of all the illegal sites, IWF tell us that <a href="http://www.missingkids.com/missingkids/servlet/PageServlet?PageId=169">NCMEC</a> the hotline operator there will only pass on notices to their members &#8212; and that means that American ISPs do not get a timely notice.</p>
<p>We think it is the close involvement with the police, who have to operate within a particular jurisdiction, which leads the IWF to believe that they would be &#8220;treading on other people&#8217;s toes&#8221; if they contacted ISPs outside the UK. I assume that this is why I was firmly told in an email this week that they &#8220;are not permitted or authorised to issue notices to takedown content to anyone outside the UK&#8221;. Indeed, this echoed in a <a href="http://www.guardian.co.uk/uk/2008/jun/11/ukcrime.children">letter to The Guardian today</a> by John Carr who says &#8220;The IWF cannot issue a notice to a Polish or Irish internet service provider&#8221;.</p>
<p>We don&#8217;t think there is some magical international permission given to the people who try to take down any of the other types of content we studied &#8212; from phishing, to fake escrow sites, to illegal pharmacies. It only seems to be INHOPE members, dealing with child sexual abuse images, who are not prepared to make an attempt!</p>
<p>Besides this issue, we have a number of other interesting results in the paper (so do read it!) For example we looked at <a href="http://www.bobbear.co.uk/">&#8220;mule recruitment websites&#8221;</a> &#8212; with job adverts for payment processors who will be conned into handling the proceeds of phishing scams in the belief that they&#8217;re handling payments for legitimate companies. These sites are only taken down by <a href="http://www.aa419.org">volunteer</a> (amateur) efforts &#8212; since they don&#8217;t attack any particular bank, but the whole industry, no particular bank is prepared to put in any effort to remove them. Unsurprisingly, their average lifetime is 13 days (mean 8 days) &#8212; far longer than the phishing websites &#8212; which is not good news for <a href="http://suckerswanted.blogspot.com/">gullible consumers</a>.</p>
]]></content:encoded>
      <pubDate>Wed, 11 Jun 2008 10:02:32 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/image">image</category>
      <category domain="http://www.securityratty.com/tag/image websites">image websites</category>
      <category domain="http://www.securityratty.com/tag/websites">websites</category>
      <category domain="http://www.securityratty.com/tag/child sexual">child sexual</category>
      <category domain="http://www.securityratty.com/tag/child">child</category>
      <category domain="http://www.securityratty.com/tag/image newsgroups">image newsgroups</category>
      <category domain="http://www.securityratty.com/tag/sites">sites</category>
      <category domain="http://www.securityratty.com/tag/illegal sites">illegal sites</category>
      <category domain="http://www.securityratty.com/tag/fake escrow sites">fake escrow sites</category>
      <source url="http://www.lightbluetouchpaper.org/2008/06/11/slow-removal-of-child-sexual-abuse-image-websites/">Slow removal of child sexual abuse image websites</source>
    </item>
    <item>
      <title><![CDATA[The Security Mindset]]></title>
      <link>http://www.securityratty.com/article/e48a4db680e3646bb79fbb06352c67d7</link>
      <guid>http://www.securityratty.com/article/e48a4db680e3646bb79fbb06352c67d7</guid>
      <description><![CDATA[Uncle Milton Industries has been selling ant farms to children since 1956. Some years ago, I remember opening one up with a friend. There were no actual ants included in the box. Instead, there was a...]]></description>
      <content:encoded><![CDATA[<p>Uncle Milton Industries has been selling ant farms to children since 1956. Some years ago, I remember opening one up with a friend. There were no actual ants included in the box.  Instead, there was a card that you filled in with your address, and the company would mail you some ants. My friend expressed surprise that you could get ants sent to you in the mail.</p>

<p>I replied: "What's really interesting is that these people will send a tube of live ants to anyone you tell them to."</p>

<p>Security requires a particular mindset. Security professionals -- at least the good ones -- see the world differently. They can't walk into a store without noticing how they might shoplift. They can't use a computer without wondering about the security vulnerabilities.  They can't vote without trying to figure out how to vote twice. They just can't help it.</p>

<p><a href="http://www.smartwater.com/products/securitySolutions.html">SmartWater</a> is a liquid with a unique identifier linked to a particular owner. "The idea is for me to paint this stuff on my valuables as proof of ownership," I <a href="http://www.schneier.com/blog/archives/2005/02/smart_water.html">wrote</a> when I first learned about the idea. "I think a better idea would be for me to paint it on <em>your</em> valuables, and then call the police."</p>

<p>Really, we can't help it.</p>

<p>This kind of thinking is not natural for most people. It's not natural for engineers. Good engineering involves thinking about how things can be made to work; the security mindset involves thinking about how things can be made to fail. It involves thinking like an attacker, an adversary or a criminal. You don't have to exploit the vulnerabilities you find, but if you don't see the world that way, you'll never notice most security problems.</p>

<p>I've often speculated about how much of this is innate, and how much is teachable. In general, I think it's a particular way of looking at the world, and that it's far easier to teach someone domain expertise -- cryptography or software security or safecracking or document forgery -- than it is to teach someone a security mindset.</p>

<p>Which is why <a href="http://www.cs.washington.edu/education/courses/484/08wi/">CSE 484</a>, an undergraduate computer-security course taught this quarter at the University of Washington, is so interesting to watch. Professor Tadayoshi Kohno is trying to teach a <a href="http://cubist.cs.washington.edu/Security/2007/11/22/why-a-computer-security-course-blog/">security mindset</a>.</p>

<p>You can see the results in the <a href="http://cubist.cs.washington.edu/Security/">blog</a> the students are keeping. They're encouraged to post <a href="http://cubist.cs.washington.edu/Security/category/security-reviews/">security reviews</a> about random things:  <a href="http://cubist.cs.washington.edu/Security/2008/02/10/security-review-smart-<br />
pillboxes-maybe-too-smart/">smart pill boxes</a>, <a href="http://cubist.cs.washington.edu/Security/2008/02/10/security-review-quiet-care/">Quiet Care Elder Care monitors</a>, <a href="http://cubist.cs.washington.edu/Security/2008/01/18/security-review-apples-time-capsule/">Apple's Time Capsule</a>, <a href="http://cubist.cs.washington.edu/Security/2008/02/10/security-review-gm-onstar/">GM's OnStar</a>, <a href="http://cubist.cs.washington.edu/Security/2008/02/03/security-review-traffic-lights/">traffic lights</a>, <a href="http://cubist.cs.washington.edu/Security/2008/01/11/un-safe-deposit-box-security-review/">safe deposit boxes</a>, and <a href="http://cubist.cs.washington.edu/Security/2008/01/13/social-engineering-your-way-into-a-dorm-room/">dorm room security</a>.</p>

<p>One <a href="http://cubist.cs.washington.edu/Security/2008/03/14/security-review-michaels-toyota-service-center/">recent one</a> is about an automobile dealership. The poster described how she was able to retrieve her car after service just by giving the attendant her last name. Now any normal car owner would be happy about how easy it was to get her car back, but someone with a security mindset immediately thinks: "Can I really get a car just by knowing the last name of someone whose car is being serviced?"</p>

<p>The rest of the blog post speculates on how someone could steal a car by exploiting this security vulnerability, and whether it makes sense for the dealership to have this lax security. You can quibble with the analysis -- I'm curious about the liability that the dealership has, and whether their insurance would cover any losses -- but that's all domain expertise. The important point is to notice, and then question, the security in the first place.</p>

<p>The lack of a security mindset explains a lot of bad security out there: voting machines, electronic payment cards, <a href=" http://www.schneier.com/blog/archives/2008/03/hacking_medical_1.html">medical devices</a>, ID cards, internet protocols. The designers are so busy making these systems work that they don't stop to notice how they might fail or be made to fail, and then how those failures might be exploited. Teaching designers a security mindset will go a long way toward making future technological systems more secure.</p>

<p>That part's obvious, but I think the security mindset is beneficial in many more ways. If people can learn how to think outside their narrow focus and see a bigger picture, whether in technology or politics or their everyday lives, they'll be more sophisticated consumers, more skeptical citizens, less gullible people.</p>

<p>If more people had a security mindset, services that compromise privacy wouldn't have such a sizable market share -- and Facebook would be totally different. Laptops wouldn't be lost with millions of unencrypted Social Security numbers on them, and we'd all learn a lot fewer security lessons the hard way. The power grid would be more secure. Identity theft would go way down. Medical records would be more private. If people had the security mindset, they wouldn't have tried to look at <a http="http://www.msnbc.msn.com/id/23640143">Britney Spears' medical records</a>, since they would have realized that they would be caught.</p>

<p>There's nothing magical about this particular university class; anyone can exercise his security mindset simply by trying to look at the world from an attacker's perspective. If I wanted to evade this particular security device, how would I do it? Could I follow the letter of this law but get around the spirit? If the person who wrote this advertisement, essay, article or television documentary were unscrupulous, what could he have done? And then, how can I protect myself from these attacks?</p>

<p>The security mindset is a valuable skill that everyone can benefit from, regardless of career path.</p>

<p>This essay <a href="http://www.wired.com/politics/security/commentary/securitymatters/2008/03/securitymatters_0320">originally appeared</a> on Wired.com.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=GkQ6ayF"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=GkQ6ayF" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=HHzos3F"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=HHzos3F" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 25 Mar 2008 02:27:19 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/security mindset">security mindset</category>
      <category domain="http://www.securityratty.com/tag/mindset">mindset</category>
      <category domain="http://www.securityratty.com/tag/security mindset immediately">security mindset immediately</category>
      <category domain="http://www.securityratty.com/tag/security mindset explains">security mindset explains</category>
      <category domain="http://www.securityratty.com/tag/security mindset simply">security mindset simply</category>
      <category domain="http://www.securityratty.com/tag/security">security</category>
      <category domain="http://www.securityratty.com/tag/security mindset involves">security mindset involves</category>
      <category domain="http://www.securityratty.com/tag/involves">involves</category>
      <category domain="http://www.securityratty.com/tag/security requires">security requires</category>
      <source url="http://www.schneier.com/blog/archives/2008/03/the_security_mi.html">The Security Mindset</source>
    </item>
  </channel>
</rss>
