<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: short]]></title>
    <link>http://www.securityratty.com/tag/short</link>
    <description></description>
    <pubDate>Mon, 17 Nov 2008 13:43:15 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[KPIs for ISO 27001? Do Such Things Exist?]]></title>
      <link>http://www.securityratty.com/article/806cee7438805a3bb0f2ab1de8fd2c42</link>
      <guid>http://www.securityratty.com/article/806cee7438805a3bb0f2ab1de8fd2c42</guid>
      <description><![CDATA[On Gary Hinsons excellent ISO 27001 Google Group , the following question was just posed
Dear Implementers
What could be the KPIs by which I, being Management Representative
can show complete picture...]]></description>
      <content:encoded><![CDATA[<p>On Gary Hinson&#8217;s excellent <strong><a href="http://groups.google.com/group/iso27001security/">ISO 27001 Google Group</a></strong>, the following question was just posed:</p>
<blockquote><p>Dear Implementers:<br />
What could be the KPIs by which I, being Management Representative,<br />
can show complete picture in a compiled brief/short report? Your<br />
response would be highly awaited.</p></blockquote>
<p>Which I think is a great question!  Talk about no-nonsense.  None of this &#8220;high-falutin&#8221; nonsense about ISO adoption providing &#8216;piece of mind&#8217; and &#8216;common language&#8217; or &#8217;strategic currency&#8217;.  No this is straight from the hip - tell me right now how I can communicate the value of an ISO implementation to non-security management.</p>
<p>I&#8217;m not sure I&#8217;ve got a good answer.  Do you?  You guys (loyal, cool, readers) are really bright and many of you CxSO&#8217;s in your own organizations.  Leave comments and in our next post  I&#8217;ll publish the best and brightest (as well as some of my own thoughts).</p>
]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 10:48:41 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/management representative">management representative</category>
      <category domain="http://www.securityratty.com/tag/kpis">kpis</category>
      <category domain="http://www.securityratty.com/tag/strategic currency">strategic currency</category>
      <category domain="http://www.securityratty.com/tag/high-falutin nonsense">high-falutin nonsense</category>
      <category domain="http://www.securityratty.com/tag/iso adoption">iso adoption</category>
      <category domain="http://www.securityratty.com/tag/non-security management">non-security management</category>
      <category domain="http://www.securityratty.com/tag/iso implementation">iso implementation</category>
      <category domain="http://www.securityratty.com/tag/dear implementers">dear implementers</category>
      <category domain="http://www.securityratty.com/tag/briefshort report">briefshort report</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=525">KPIs for ISO 27001? Do Such Things Exist?</source>
    </item>
    <item>
      <title><![CDATA[Rock Phish-ing in December]]></title>
      <link>http://www.securityratty.com/article/d1eddfe52ced7cf231d9526475837380</link>
      <guid>http://www.securityratty.com/article/d1eddfe52ced7cf231d9526475837380</guid>
      <description><![CDATA[Nothing can warm up the hearth of a security researcher than a batch of currently active Rock Phish domains, fast-fluxing by using U.S based malware infected hosts as infrastructure provider. What is...]]></description>
      <content:encoded><![CDATA[<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/STUqs5QOkBI/AAAAAAAACfw/_V_hnn5FsvY/s1600-h/rock_phishing_december_2008_4.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/STUqs5QOkBI/AAAAAAAACfw/_V_hnn5FsvY/s200/rock_phishing_december_2008_4.png" /></a>Nothing can warm up the hearth of a security researcher than a batch of currently active Rock Phish domains, fast-fluxing by using U.S based malware&nbsp; infected hosts as infrastructure provider. What is this assessment of currently active Rock Phish campaign aiming to achieve? In short, prove that the people that were Rock Phish-ing at the beginning of the year, are exactly the same people that continue Rock Phish-ing at the end of the year, thereby pointing out that as long as they're not where they're supposed to be, they are not going to stop innovating and working on a higher average online time for their campaigns.<br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://3.bp.blogspot.com/_wICHhTiQmrA/STUurE2no7I/AAAAAAAACf4/knoqvo5_Ruk/s1600-h/rock_phishing_december_2008.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_wICHhTiQmrA/STUurE2no7I/AAAAAAAACf4/knoqvo5_Ruk/s200/rock_phishing_december_2008.png" /></a>What's particularly interesting about this campaign, is that compared to previous ones targeting multiple brands, the thousands of malware infected hosts and domains are targeting Alliance &amp; Leicester and Abbey National only.<br />
<br />
Active Rock Phish Domains in fast-flux :<br />
<b>stgsfw7sr .com<br />
q06ciwt60 .com<br />
jnlyf96v4 .com<br />
neegzlh35 .com<br />
7azwmrsg5 .com<br />
pn3ekq976 .com<br />
2coxi8sb6 .com<br />
d8ri1iz5d .com<br />
&nbsp;</b><br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://2.bp.blogspot.com/_wICHhTiQmrA/STUwghNYQnI/AAAAAAAACgI/26zVuduDrUQ/s1600-h/rock_phishing_december_2008_5.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_wICHhTiQmrA/STUwghNYQnI/AAAAAAAACgI/26zVuduDrUQ/s200/rock_phishing_december_2008_5.png" /></a><b>ki7wvgauf .com<br />
5nt5r3keh .com<br />
5nt29884j .com<br />
bgoryomek .com<br />
a725jv8ik .com<br />
fke5nnp8m .com<br />
stgsfw7sr .com<br />
10c0ka49t .com<br />
zp304ju3z .com<br />
j0rykafwn .cn<br />
2j1f .net<br />
<br />
confirm-updates .com<br />
paypal.confirm-updates .com<br />
user-data-confirmation .com<br />
paypal.user-data-confirmation .com<br />
capitalone.updating-informations .com</b><br />
<br />
Sample sub-domain structure :<br />
<b>mybank.alliance-leicester.co.uk.7azwmrsg5 .com<br />
mybank.alliance-leicester.co.uk.bgoryomek .com<br />
mybank.aliance-leicester.co.uk.stgsfw7sr .com<br />
mybank.alliance-leicester.co.uk.zp304ju3z .com<br />
mybank.alliance-leicester.co.uk.5nt29884j .com<br />
mybank.aliance-leicester.co.uk.bgoryomek .com<br />
mybank.alliance-leicester.co.uk.bgoryomek .com<br />
mybank.aliance-leicester.co.uk.stgsfw7sr .com<br />
mybank.alliance-leicester.co.uk.stgsfw7sr .com<br />
mybank.aliance-leicester.co.uk.zp304ju3z .com<br />
mybank.alliance-leicester.co.uk.zp304ju3z .com<br />
myonlineaccounts2.abbeynational.co.uk.pn3ekq976 .com<br />
myonlineaccounts1.abeynational.com.pn3ekq976 .com</b><br />
<br />
<a href="http://4.bp.blogspot.com/_wICHhTiQmrA/STUwTom6U0I/AAAAAAAACgA/EPxpvWuWNnY/s1600-h/rock_phishing_december_2008_3.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://4.bp.blogspot.com/_wICHhTiQmrA/STUwTom6U0I/AAAAAAAACgA/EPxpvWuWNnY/s200/rock_phishing_december_2008_3.png" /></a>DNS servers for the campaigns :<br />
<b>ns1.thecherrydns .com<br />
ns2.thecherrydns .com <br />
ns3.thecherrydns .com <br />
ns4.thecherrydns .com <br />
ns5.thecherrydns .com <br />
ns6.thecherrydns .com <br />
<br />
ns10.realgoodnameserver .com<br />
ns1.realgoodnameserver .com<br />
rens2.realgoodnameserver .com<br />
rns3.realgoodnameserver .com<br />
ns4.realgoodnameserver .com<br />
ns8.realgoodnameserver .com<br />
<br />
ns6.myboomdns .com<br />
ns4.myboomdns .com</b><br />
<br />
<div style="text-align: left;"></div><div class="separator" style="clear: both; text-align: center;"></div><a href="http://1.bp.blogspot.com/_wICHhTiQmrA/STUw5WuMSYI/AAAAAAAACgQ/VgFTgLTJK58/s1600-h/rock_phishing_december_2008_7.png" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_wICHhTiQmrA/STUw5WuMSYI/AAAAAAAACgQ/VgFTgLTJK58/s200/rock_phishing_december_2008_7.png" /></a><b>Domains registrant :</b><br />
Name : Pan Wei wei<br />
Organization : Pan Wei wei<br />
Address : BaoChun Rd. 27, No. 3, 1F, Apt. 1903<br />
City : Bejing<br />
Province/State : Beijing<br />
Country : CN<br />
Postal Code : 100176<br />
Phone Number : 010-010-58022118-58022118<br />
Fax : 86-010-58022118-58022118<br />
Email : 127@126.com<br />
<br />
These well known Rock Phish campaigners, have been naturally multitasking on several different underground fronts throughout the year. For instance, their <b>2j1f .net</b> is known to have been <a href="http://www.bobbear.co.uk/morganinvestment.html">hosting money mule company's site</a>, and also, it was used in a previously analyzed <a href="http://ddanchev.blogspot.com/2008/06/phishing-campaign-spreading-across.html">phishing campaign that was spreading across Facebook</a> in June. Need more evidence on the consolidation that's been ongoing for over an year and half now? An infamous money mule recruiting company (<b>Cash-Transfers Inc.</b>) was also taking advantage of the <a href="http://ddanchev.blogspot.com/2008/07/money-mule-recruiters-use-asproxs-fast.html">fast-flux network offered by the ASProx botnet masters</a> in July.<br />
<br />
As a firm believer in that "the whole is greater than the sum of its parts", the popular "sitting duck" cybercrime infrastructure hosting model will be either replaced by a cybercrime infrastructure relying entirely on legitimate services, or one where the average malware infected Internet user would be temporarily used as a hosting provider.<br />
<br />
If millions were made by using the "sitting duck" hosting model, how many would be made using the others, given that they would inevitably increase the average online time for a malicious campaign?<br />
<br />
<b>Related Rock Phish research :</b><br />
<a href="http://ddanchev.blogspot.com/2007/09/209-host-locked.html">209 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/12/2091-host-locked.html">209.1 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/11/661-host-locked.html">66.1 Host Locked</a><br />
<a href="http://ddanchev.blogspot.com/2007/07/confirm-your-gullibility.html">Confirm Your Gullibility</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/assessing-rock-phish-campaign.html">Assessing a Rock Phish Campaign</a><br />
<br />
<b>Related fast-flux research : </b><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-flux-spam-and-scams-increasing.html">Fast-Flux Spam and Scams Increasing</a><br />
<a href="http://ddanchev.blogspot.com/2007/10/fast-fluxing-yet-another-pharmacy-scam.html">Fast Fluxing Yet Another Pharmacy Scam</a><br />
<a href="http://ddanchev.blogspot.com/2007/09/storm-worms-fast-flux-networks.html">Storm Worm's Fast Flux Networks</a><br />
<b> </b><a href="http://ddanchev.blogspot.com/2007/11/managed-fast-flux-provider.html">Managed Fast Flux Provider</a><br />
<a href="http://ddanchev.blogspot.com/2008/10/managed-fast-flux-provider-part-two.html">Managed Fast Flux Provider - Part Two</a><br />
<a href="http://ddanchev.blogspot.com/2008/07/obfuscating-fast-fluxed-sql-injected.html">Obfuscating Fast Fluxed SQL Injected Domains</a><br />
<a href="http://ddanchev.blogspot.com/2008/05/storm-worm-hosting-pharmaceutical-scams.html">Storm Worm Hosting Pharmaceutical Scams</a><br />
<a href="http://blogs.zdnet.com/security/?p=1122">Fast-Fluxing SQL injection attacks executed from the Asprox botnet</a><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=kNW2O"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=kNW2O" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=zUymO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=zUymO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=gesYo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=gesYo" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=RrC8o"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=RrC8o" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=w0L7O"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=w0L7O" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=hj0KO"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=hj0KO" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?a=P9KQo"><img src="http://feeds.feedburner.com/~f/DanchoDanchevOnSecurityAndNewMedia?i=P9KQo" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~4/472451974" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 04:12:31 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/fast flux networks">fast flux networks</category>
      <category domain="http://www.securityratty.com/tag/fast">fast</category>
      <category domain="http://www.securityratty.com/tag/fast-flux spam">fast-flux spam</category>
      <category domain="http://www.securityratty.com/tag/fast-flux">fast-flux</category>
      <category domain="http://www.securityratty.com/tag/fast flux provider">fast flux provider</category>
      <category domain="http://www.securityratty.com/tag/mybank">mybank</category>
      <category domain="http://www.securityratty.com/tag/fast-flux research">fast-flux research</category>
      <category domain="http://www.securityratty.com/tag/rock phish-ing">rock phish-ing</category>
      <category domain="http://www.securityratty.com/tag/provider">provider</category>
      <source url="http://feeds.feedburner.com/~r/DanchoDanchevOnSecurityAndNewMedia/~3/472451974/rock-phish-ing-in-december.html">Rock Phish-ing in December</source>
    </item>
    <item>
      <title><![CDATA[Rexam Global CIO Paul Martin discusses packing it up]]></title>
      <link>http://www.securityratty.com/article/3260f239489d2a2c3f792740c9a417e5</link>
      <guid>http://www.securityratty.com/article/3260f239489d2a2c3f792740c9a417e5</guid>
      <description><![CDATA[Paul Martin is talking about his plans to head back home to the US when we meet in London on a bright autumn day at Rexam's very smart offices by the Thames on Millbank, just a short walk to the...]]></description>
      <content:encoded><![CDATA[Paul Martin is talking about his plans to head back home to the US when we meet in London on a bright autumn day at Rexam's very smart offices by the Thames on Millbank, just a short walk to the Palace of Westminster in one direction and the Tate Britain art collection in the other.]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 21:00:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/paul martin">paul martin</category>
      <category domain="http://www.securityratty.com/tag/britain art collection">britain art collection</category>
      <category domain="http://www.securityratty.com/tag/bright autumn day">bright autumn day</category>
      <category domain="http://www.securityratty.com/tag/rexam">rexam</category>
      <category domain="http://www.securityratty.com/tag/smart offices">smart offices</category>
      <category domain="http://www.securityratty.com/tag/short walk">short walk</category>
      <category domain="http://www.securityratty.com/tag/thames">thames</category>
      <category domain="http://www.securityratty.com/tag/head">head</category>
      <category domain="http://www.securityratty.com/tag/millbank">millbank</category>
      <source url="http://www.networkworld.com/news/2008/120208-rexam-global-cio-paul-martin.html?fsrc=rss-security">Rexam Global CIO Paul Martin discusses packing it up</source>
    </item>
    <item>
      <title><![CDATA[BlueHat SDL Sessions Wrap-up]]></title>
      <link>http://www.securityratty.com/article/5bc4bc363bab903a7f7f8a6245e3234d</link>
      <guid>http://www.securityratty.com/article/5bc4bc363bab903a7f7f8a6245e3234d</guid>
      <description><![CDATA[Hi everyone, Bryan here. The debut BlueHat SDL Sessions are over, and they were a resounding success: 96% of attendees completing evaluation surveys reported that they will be able to apply knowledge...]]></description>
      <content:encoded><![CDATA[<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>Hi everyone, Bryan here. The debut </FONT><A href="http://blogs.msdn.com/sdl/archive/2008/09/25/sdl-sessions-at-bluehat.aspx"><FONT face=Calibri size=3>BlueHat SDL Sessions</FONT></A><FONT face=Calibri size=3> are over, and they were a resounding success: 96% of attendees completing evaluation surveys reported that they will be able to apply knowledge that they learned in the SDL sessions to make their products more secure. This is a great score and I’d like to thank all of our speakers and the BlueHat planning team for their hard work. As for the other 4% of attendees, we’ll just have to work that much harder next year to bring them actionable guidance for dealing with new vulnerabilities.</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>As promised, we recorded all of the day’s presentations and we’ve published them on </FONT><A href="http://technet.microsoft.com/en-us/security/cc748656.aspx#day2"><FONT face=Calibri color=#0000ff size=3>TechNet</FONT></A><FONT face=Calibri size=3>:</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd282968.aspx"><FONT face=Calibri color=#0000ff size=3>Keynote Address</FONT></A><FONT face=Calibri size=3> by Scott Charney, Corporate VP, Microsoft Trustworthy Computing</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd282977.aspx"><FONT face=Calibri color=#0000ff size=3>Threat Modeling at EMC and Microsoft</FONT></A><FONT face=Calibri size=3> by Danny Dhillon of EMC and Adam Shostack of the Microsoft SDL team (of course)</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285253.aspx"><FONT face=Calibri color=#0000ff size=3>Mitigations Unplugged</FONT></A><FONT face=Calibri size=3> by Matt Miller, Microsoft Security Science team</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285262.aspx"><FONT face=Calibri color=#0000ff size=3>Concurrency Attacks on Web Applications</FONT></A><FONT face=Calibri size=3> by Scott Stender and Alex Vidergar of iSEC Partners</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285263.aspx"><FONT face=Calibri color=#0000ff size=3>Fuzzed Enough? When it’s OK to Put the Shears Down</FONT></A><FONT face=Calibri size=3> by Jason Shirk, Dave Weinstein and Lars Opstad, Microsoft Security Science team</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285265.aspx"><FONT face=Calibri color=#0000ff size=3>Real World Code Review – Using the Right Tools in the Right Place at the Right Time</FONT></A><FONT face=Calibri size=3> by Vinnie Liu of Stach &amp; Liu</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>In addition to the presentations, we also recorded some short interviews (about 10 minutes long) with each of the speakers. If you’re just looking for a quick summary of a particular talk, these interviews are the place to start:</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285269.aspx"><FONT face=Calibri color=#0000ff size=3>Threat Modeling at EMC</FONT></A><FONT face=Calibri size=3>, Danny Dhillon</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285454.aspx"><FONT face=Calibri color=#0000ff size=3>Threat Modeling at Microsoft</FONT></A><FONT face=Calibri size=3>, Adam Shostack</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285260.aspx"><FONT face=Calibri color=#0000ff size=3>Mitigations Unplugged</FONT></A><FONT face=Calibri size=3>, Matt Miller</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285461.aspx"><FONT face=Calibri color=#0000ff size=3>Concurrency Attacks on Web Applications</FONT></A><FONT face=Calibri size=3>, Scott Stender and Alex Vidergar</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285279.aspx"><FONT face=Calibri color=#0000ff size=3>Fuzzed Enough?</FONT></A><FONT face=Calibri size=3> Jason Shirk and Dave Weinstein</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><A href="http://technet.microsoft.com/en-us/security/dd285463.aspx"><FONT face=Calibri color=#0000ff size=3>Real World Code Review</FONT></A><FONT face=Calibri size=3>, Vinnie Liu</FONT></P>
<P class=MsoNormal style="MARGIN: 0in 0in 10pt"><FONT face=Calibri size=3>I hope at least 96% of online readers will be able to directly apply this material to their products, just like the show attendees. Please post back and let us know, either way. And let us know what you’d like to see for next year. We have big plans to build on our success and make SDL Sessions 2.0 even bigger and better than the first.</FONT></P><img src="http://blogs.msdn.com/aggbug.aspx?PostID=9161040" width="1" height="1">]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 14:51:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/sdl sessions">sdl sessions</category>
      <category domain="http://www.securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://www.securityratty.com/tag/microsoft trustworthy">microsoft trustworthy</category>
      <category domain="http://www.securityratty.com/tag/microsoft sdl team">microsoft sdl team</category>
      <category domain="http://www.securityratty.com/tag/vinnie liu">vinnie liu</category>
      <category domain="http://www.securityratty.com/tag/liu">liu</category>
      <category domain="http://www.securityratty.com/tag/web applications">web applications</category>
      <category domain="http://www.securityratty.com/tag/matt miller">matt miller</category>
      <category domain="http://www.securityratty.com/tag/jason shirk">jason shirk</category>
      <source url="http://blogs.msdn.com/sdl/archive/2008/12/01/bluehat-sdl-sessions-wrap-up.aspx">BlueHat SDL Sessions Wrap-up</source>
    </item>
    <item>
      <title><![CDATA[Celebrity's Bodyguard Caught on Camera]]></title>
      <link>http://www.securityratty.com/article/81cffb6766a5b98cf121e07a6e081430</link>
      <guid>http://www.securityratty.com/article/81cffb6766a5b98cf121e07a6e081430</guid>
      <description><![CDATA[Paparazzi seem to draw bodyguards to their cameras like moths to a light bulb

This recent grapple caught on video was aired on the Fox News show in the &quot; Kelly's Court &quot; segment. Megyn Kelly acted as...]]></description>
      <content:encoded><![CDATA[Paparazzi seem to draw bodyguards to their cameras like moths to a light bulb. <br /><span id="fullpost"><br />This recent grapple caught on video was aired on the Fox News show in the "<a href="http://www.comcast.net/data/fan/html/popup.html?v=934615342">Kelly's Court</a>" segment.  Megyn Kelly acted as the judge while two other lawyers debated whether the photographer had a chance of winning a civil suit   <br /></span><br />The celebrity, John Meyer, appeared to be exiting a restaurant with a friend when a photographer tried to take a picture.  Although the clip was relatively short, it appeared as if Mr. Meyer's E.P. agent went over the top in trying to block the photogapher from taking the picture.<br /><br />From a professional E.P. point of view, the matter could have been handled with much decorum and expertise.  Mr. Meyer should have been closely escorted to his vehicle and placed inside out of harm's way.  Since there only appeared to be one E.P. agent (who also doubled up as driver), when he went charging at the photographer, he left his Principal unprotected.<br /><br />For some reason, many of the people employed to protect celebrities seem more preoccupied with making sure that pictures are not taken rather than ensuring the safety of their Principal.  What makes it all the more ironic, is the fact that these celebrities are usually out in the public eye and therefore can not realistically expect total privacy.<br /><br />If you are a Personal Protection Specialist and you find yourself in this position, remember two things.  Firstly, always remember your duty to protect your Principal.  If you are doing it alone, who will be looking after them when you are rolling around the floor with a photographer?<br /><br />Secondly, remember that you can be sued civilly - and do not take that literally, there is nothing civil about it.  You may or may not be prosecuted criminally, but if you lose a civil suit, it could mean that you'll be spending the rest of your working life paying that photographer who is claiming neck injuires and all kinds of trauma.<br /><br />A picture may be worth a thousand words, but it is hardly worth ruining your career and life.<div class="blogger-post-footer">Visit Sexton Executive Security at www.sextonsecurity.com</div>]]></content:encoded>
      <pubDate>Sun, 23 Nov 2008 18:14:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/civil">civil</category>
      <category domain="http://www.securityratty.com/tag/photographer">photographer</category>
      <category domain="http://www.securityratty.com/tag/civil suit">civil suit</category>
      <category domain="http://www.securityratty.com/tag/kelly">kelly</category>
      <category domain="http://www.securityratty.com/tag/megyn kelly acted">megyn kelly acted</category>
      <category domain="http://www.securityratty.com/tag/celebrities">celebrities</category>
      <category domain="http://www.securityratty.com/tag/protect celebrities">protect celebrities</category>
      <category domain="http://www.securityratty.com/tag/meyer">meyer</category>
      <category domain="http://www.securityratty.com/tag/john meyer">john meyer</category>
      <source url="http://www.thebulletproofblog.com/2008/11/celebritys-bodyguard-caught-on-camera.html">Celebrity's Bodyguard Caught on Camera</source>
    </item>
    <item>
      <title><![CDATA[Not Your Father's Data Breach]]></title>
      <link>http://www.securityratty.com/article/6e6dd929bba96e08b0dee7eee16ea946</link>
      <guid>http://www.securityratty.com/article/6e6dd929bba96e08b0dee7eee16ea946</guid>
      <description><![CDATA[I am surprised this doesn't happen more often, or become public when it does happen, and I suspect it will


Corporate custodians of confidential medical data should be closely monitoring events...]]></description>
      <content:encoded><![CDATA[<p>I am surprised <a href="http://www.stltoday.com/blogzone/the-platform/published-editorials/2008/11/express-scripts-data-breach-is-bitter-medicine/"><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">this</span></a><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "> doesn&#39;t happen more often, or become public when it does happen, and I suspect it will:</span></p><div><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-size: 16px; line-height: 17px; "><strong style="font-style: normal; font-weight: bold; "><span style="font-style: normal; font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Corporate custodians</span></strong><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&#0160;of confidential medical data should be closely monitoring events connected to a nightmarish computer security breach in the St. Louis region.</span></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Express Scripts is one of the nation’s largest pharmacy benefits managers. The company, with headquarters in St. Louis County, handles approximately 500 million prescriptions per year for 50 million workers at 1,600 American companies. Early in October, it received an extortion letter, the details of which it released on Nov. 6.</span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The letter included personal information on about 75 Express Scripts clients — Social Security numbers, dates of birth and, in some cases, information about prescription medications. Whoever sent the letter demanded money from the company — the amount has not been disclosed — and threatened to use the Internet to reveal personal and medical information about millions of people if the demands were not met.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">...</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-size: 16px; line-height: 17px; "><strong style="font-style: normal; font-weight: bold; "><span style="font-style: normal; font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Beyond&#0160;</span></strong><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">the scale of the problem for Express Scripts — and the potential impact on the company is enormous — the issue extends well beyond the mounting concerns about identity theft, a phenomenon with which most people have become at least somewhat familiar.</span></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The greater problem is the unique nature of personal medical records, the importance of moving to computerization of such records to improve health safety and reduce costs and the irreversibility of the damage people can suffer if confidential medical information becomes public. The stakes are so high that a federal law establishes strict standards for maintaining the privacy of medical information and stiff fines for failing to do so.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Medical records of all kinds — paper and, especially, electronic — must be protected with the most sophisticated kinds of security systems available, including backup protections and automatic alerts of security violations. Yet Express Scripts learned of this breach in the “worst way,” as InformationWeek.com security correspondent George Hulme put it in an online report: “via an extortion letter.”</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; font-size: 16px; line-height: 17px; "><strong style="font-style: normal; font-weight: bold; "><span style="font-style: normal; font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The Express Scripts</span></strong><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&#0160;breach raises many questions for all elements of the health industry: hospitals, clinics and doctors’ practices, benefits management firms, insurance companies, pharmacies, employers and government agencies:</span></span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Are they using the most advanced information security technology possible? Do they minimize the amount of data they collect and keep it only as long as necessary? Do they have strict protocols governing access to personal and medical data — and systems to enforce those protocols? If criminals were to hack into their systems, how would the companies know? How soon? And are the systems capable of instantly cutting off illegal access as soon as a breach is discovered?</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; font-size: 16px; line-height: 17px; "><strong style="font-style: normal; font-weight: bold; "><span style="font-style: normal; font-weight: bold; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Confronted</span></strong><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&#0160;with a grave breach of electronic security, Express Scripts has responded by contacting law enforcement, establishing an informational website, offering a substantial reward and hiring a private consulting firm to help clients who have privacy concerns and investigate situations that “appear to be tied to identity theft” and provide “identity restoration services.” There is no question that the company is taking the situation extremely seriously.</span></span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Given the ongoing criminal situation, information about how Express Scripts’ data systems were compromised — and whether it could have been avoided — has yet to be disclosed. But the American people have the right to expect that their sensitive personal and medical information is zealously protected and kept secure — not only by Express Scripts but also by every person or company entrusted with it.</span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><p><span style="color: #333333; font-size: 16px; line-height: 17px; "><div><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">The reason I am surprised this doesn&#39;t happen more often is that many Fortune 500 companies have oceans and oceans of personal data. Almost the only companies that have even tried to get to a medium level assurance are financial companies, yet many of the other companies have as much or even more data, with lower assurance. All that was lacking in the mix was an incentive and a bit of creativity and risk taking by the bad guys.</span></span></p><div><span style="color: #333333; line-height: 17px;"><br /></span></div><div><span style="color: #333333; line-height: 17px;">I posted this to the security metrics list and Andy Jaquith quoted it in his great book S<a href="http://1raindrop.typepad.com/1_raindrop/2007/08/chicken-soup-fo.html">ecurity Metrics</a>:</span></div><div><span style="color: #333333; line-height: 17px;"><br /></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; ">&quot;Customers and customer relationships...have tangible measurable value to businesses, and their value is much easier to communicate to those who fund projects. So in an enterprise risk management scenartio, their vlaue informs the risk management process...[For example, consider] a farmer deciding which crop to grow. A farmer interested in short term profits may grow the same high yield crop every year, but over time this would burn the fields out. The long term focused farmer would rotate the crops and invest in things that build the value of the farm and soil over time. Investing in security on behalf of your customers is like this. The investment made in securing your customer&#39;s data build current and future value for them. Measuring the value of the customer and relationships helps to target where to allocate security resources.&quot;</span></p></blockquote><div><span style="color: #333333; line-height: 17px;"><br /></span></div><div><span style="color: #333333; line-height: 17px;">Of course this is the opposite of how most organizations do risk management and security architecture, and now, the fields have turned brown.<br /></span><div><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><div><span style="color: #333333; line-height: 17px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">(Thanks to Chris for pointing me to this story)</span></div></div></div>]]></content:encoded>
      <pubDate>Thu, 20 Nov 2008 06:37:59 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/information">information</category>
      <category domain="http://www.securityratty.com/tag/personal information">personal information</category>
      <category domain="http://www.securityratty.com/tag/medical information">medical information</category>
      <category domain="http://www.securityratty.com/tag/data">data</category>
      <category domain="http://www.securityratty.com/tag/personal">personal</category>
      <category domain="http://www.securityratty.com/tag/personal medical records">personal medical records</category>
      <category domain="http://www.securityratty.com/tag/medical records">medical records</category>
      <category domain="http://www.securityratty.com/tag/systems">systems</category>
      <category domain="http://www.securityratty.com/tag/security systems">security systems</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/11/not-your-fathers-data-breach.html">Not Your Father's Data Breach</source>
    </item>
    <item>
      <title><![CDATA[Mamma.com: Insider trading and XSS]]></title>
      <link>http://www.securityratty.com/article/56fd5d403c630cbec7e9ec62becaafc5</link>
      <guid>http://www.securityratty.com/article/56fd5d403c630cbec7e9ec62becaafc5</guid>
      <description><![CDATA[Mamma.com 's got issues other than Mark Cuban's insider trading allegations. As a point of reference for this conversation, Mamma.com is ranked 4064 on Alexa as of today
I won't profess to following...]]></description>
      <content:encoded><![CDATA[<a href="http://mamma.com/" target="_blank">Mamma.com</a>'s got issues other than Mark Cuban's insider trading allegations. As a point of reference for this conversation, Mamma.com is ranked <a href="http://www.alexa.com/search?q=mamma.com" target="_blank">4064</a> on <a href="http://www.alexa.com" target="_blank">Alexa</a> as of today.<br />I won't profess to following Mr. Cuban's public life and the occasional antics. Obviously, he's a colorful and popular figure; certainly in Dallas, if not nationally. <br />What follows is not a judgment of Mr. Cuban or his pending legal challenges. I'm sure the process will play itself out accordingly.<br />A quick summary and some reference material:<br />The SEC has <a href="http://www.businessweek.com/the_thread/blogspotting/archives/2008/11/sec_hits_mark_c.html?chan=technology_technology+index+page_top+stories" target="_blank">filed</a> insider trading charges against Mr. Cuban. "According to the SEC, Cuban dumped 600,000 shares, or all of his 6.3% stake, in the search engine Mamma.com (The Mother of All Search Engines), in June 2004 after learning about private financing that the company was proposing. By selling, he avoided losing $750,000, the SEC alleges."<br />The whole issue for Mr. Cuban was <a href="http://blogmaverick.com/2008/11/17/the-sec/" target="_blank">PIPE</a> financing because it's "dilutive to existing shareholders’ stakes."<br />That's the long and the short of the current issue, and again, not my real interest here, with the exception of the bet I made with myself regarding the probable web application security posture of mamma.com. <br />All this talk about a popular site immediately sets off the little bell in my head (I hear it a lot). <span style="font-weight:bold;"><br />"What's wrong with the site?" is always the first question I ask myself.</span> <br /><br />I was not disappointed. <br /><br />Mamma.com exhibits the following issues:<br />1) XSS vulnerability in the <span style="font-style:italic;">utfout<span style="font-weight:bold;"><span style="font-style:italic;"></span></span></span> variable.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_kVOWaY1TAF0/SSNDBtG5jhI/AAAAAAAAAEs/rIT7buzVsao/s1600-h/mamma1.png" target="_blank"><img style="cursor:pointer; cursor:hand;width: 320px; height: 184px;" src="http://1.bp.blogspot.com/_kVOWaY1TAF0/SSNDBtG5jhI/AAAAAAAAAEs/rIT7buzVsao/s320/mamma1.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5270129685521075730" /></a><br /><br />2) XSS vulnerability in the <span style="font-style:italic;">qtype</span> variable.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_kVOWaY1TAF0/SSNDSxiGVeI/AAAAAAAAAE0/E-McmPqvoDQ/s1600-h/mamma2.png" target="_blank"><img style="cursor:pointer; cursor:hand;width: 320px; height: 201px;" src="http://3.bp.blogspot.com/_kVOWaY1TAF0/SSNDSxiGVeI/AAAAAAAAAE0/E-McmPqvoDQ/s320/mamma2.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5270129978766677474" /></a><br /><br />3) XSS vulnerability in their Mammajobs site at the <span style="font-style:italic;">pid</span> variable. This one's weirder still; if you drop an IFRAME in, it simply redirects to any URL you include in the IFRAME string.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_kVOWaY1TAF0/SSNDd-U7c0I/AAAAAAAAAE8/GCrCAoYom5k/s1600-h/mamma3.png" target="_blank"><img style="cursor:pointer; cursor:hand;width: 320px; height: 99px;" src="http://4.bp.blogspot.com/_kVOWaY1TAF0/SSNDd-U7c0I/AAAAAAAAAE8/GCrCAoYom5k/s320/mamma3.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5270130171179660098" /></a><br /><br />4) The prospect of CSRF (rather pointless here given that its just a search engine, but but still defies best practices) appears likely given that mamma.com blindly accepts updates via GET and POST with no sign of a formkey (canary) in sight.<br /><br />I figured it best to stop there, and have submitted all these to Copernic (the Momma parent company). <br />I am however truly disappointed that an enterprise as ambitious and motivated as Momma/Copernic seems to have thrown the baby out with the bath water when it comes to web application security.<br />With regard to Mark Cuban dumping his shares: maybe he was afraid of getting pwned. ;-) All kidding aside, it's a shame that the whimsical and pessimistic thoughts regarding web site security that bounce around in my head inevitably bear themselves out.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/11/mammacom-insider-trading-and-xss.html&title=Mamma.com:%20Insider%20trading%20and%20XSS " title="Mamma.com: Insider trading and XSS ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/11/mammacom-insider-trading-and-xss.html" title="Mamma.com: Insider trading and XSS ">digg</a> | <a href="http://slashdot.org/submit.pl?url=http://holisticinfosec.blogspot.com/2008/11/mammacom-insider-trading-and-xss.html">Submit to Slashdot</a>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 06:55:00 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/mamma">mamma</category>
      <category domain="http://www.securityratty.com/tag/mark cuban">mark cuban</category>
      <category domain="http://www.securityratty.com/tag/cuban">cuban</category>
      <category domain="http://www.securityratty.com/tag/engine">engine</category>
      <category domain="http://www.securityratty.com/tag/engine mamma">engine mamma</category>
      <category domain="http://www.securityratty.com/tag/xss vulnerability">xss vulnerability</category>
      <category domain="http://www.securityratty.com/tag/site">site</category>
      <category domain="http://www.securityratty.com/tag/insider">insider</category>
      <category domain="http://www.securityratty.com/tag/web site security">web site security</category>
      <source url="http://holisticinfosec.blogspot.com/2008/11/mammacom-insider-trading-and-xss.html">Mamma.com: Insider trading and XSS</source>
    </item>
    <item>
      <title><![CDATA[The Neuroscience of Cons]]></title>
      <link>http://www.securityratty.com/article/1612b3705bc2d5e59aa4c3d5c4ee99ae</link>
      <guid>http://www.securityratty.com/article/1612b3705bc2d5e59aa4c3d5c4ee99ae</guid>
      <description><![CDATA[Fascinating : The key to a con is not that you trust the conman, but that he shows he trusts you . Conmen ply their trade by appearing fragile or needing help, by seeming vulnerable. Because of THOMAS...]]></description>
      <content:encoded><![CDATA[<p><a href="http://blogs.psychologytoday.com/blog/the-moral-molecule/200811/how-run-a-con">Fascinating</a>: </p>

<blockquote>The key to a con is not that you trust the conman, <i>but that he shows he trusts you</i>. Conmen ply their trade by appearing fragile or needing help, by seeming vulnerable. Because of THOMAS [The Human Oxytocin Mediated Attachment System], the human brain makes us feel good when we help others--this is the basis for attachment to family and friends and cooperation with strangers. "I need your help" is a potent stimulus for action.</blockquote>

<p>This is interesting.  They say that all cons rely on the mark's greed to work. But this short essay implies that greed is only a secondary factor.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=xsRHN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=xsRHN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=7DDsN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=7DDsN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 03:32:42 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/attachment system">attachment system</category>
      <category domain="http://www.securityratty.com/tag/attachment">attachment</category>
      <category domain="http://www.securityratty.com/tag/short essay implies">short essay implies</category>
      <category domain="http://www.securityratty.com/tag/cons rely">cons rely</category>
      <category domain="http://www.securityratty.com/tag/human oxytocin">human oxytocin</category>
      <category domain="http://www.securityratty.com/tag/greed">greed</category>
      <category domain="http://www.securityratty.com/tag/secondary factor">secondary factor</category>
      <category domain="http://www.securityratty.com/tag/human brain">human brain</category>
      <category domain="http://www.securityratty.com/tag/potent stimulus">potent stimulus</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/the_neuroscienc.html">The Neuroscience of Cons</source>
    </item>
    <item>
      <title><![CDATA[A late look at Interop NY 2008]]></title>
      <link>http://www.securityratty.com/article/a809cae08aacaa70769cecc5883f1d96</link>
      <guid>http://www.securityratty.com/article/a809cae08aacaa70769cecc5883f1d96</guid>
      <description><![CDATA[Boy, time flies when youre having fun. Ive just gotten my first opportunity to look back at the statistics from Interop NY 2008. Of all the statistics, the ticketing ones have proven to be the most...]]></description>
      <content:encoded><![CDATA[<p>Boy, time flies when you&#8217;re having fun.  I&#8217;ve just gotten my first opportunity to look back at the statistics from Interop NY 2008.  Of all the statistics, the ticketing ones have proven to be the most interesting - especially when you compare them to the Las Vegas show earlier in the year.  If you look back at the <a href="http://blog.sciencelogic.com/interop-vegas-2008-a-tale-of-user-error/06/2008" target="_blank">details of that ticketing review</a> the stats clearly showed that most tickets were opened due to user error.  In NY, while &#8220;user error&#8221; dominated the other categories, &#8220;facilities&#8221; came a close second.  The InteropNet Help Desk opened a total of 94 tickets during Interop NY.  Of these tickets, 42 turned out to be user error.  Coming in second, with 17 tickets were issues with the facilities, with the most common issue being cabling that had gotten damaged between installation and the time the exhibitor was trying to use it.   In Las Vegas, despite the show being significantly larger, we only saw 6 tickets of that type.  I guess you can chalk that up as yet another reason that doing shows at The Javits Center is so much fun! (Don&#8217;t ask Julia about dealing with the Javits Center. She&#8217;ll talk your ear off.)</p>
<p>After Interop Las Vegas you may have seen our analysis of the data that we collected and delivered in our NOC view.  I thought I&#8217;d recreate the same data for NY and do a short comparison.</p>
<p>1) Like in Vegas, uptime for the network 100%.  This is no small feat considering that we introduced a new wrinkle in NY, taking down the primary NOC while the education portion of the show was still going on.  This was a forced failover to the backup systems, and it went flawlessly.  I&#8217;d like to give a little credit to EM7 on the 100% uptime as it caught a failover to battery power that allowed AC to be restored before a series of critical equipment would have gone down.</p>
<p>2) Again like Vegas, the average monitored device in the show network didn&#8217;t even hit 10% CPU utilization.  Still lots of computing overhead availabe in the show network.</p>
<p>3) The NY show network wasn&#8217;t nearly as busy as in Las Vegas, sustaining an average of only 27Mbps of usage (versus 56 Mbps) in Vegas.</p>
<p>4) Power consumption for the network and NOC in NY clocked in at 445kwh per day, about 25% less than the Las Vegas show.  This wasn&#8217;t because the equipment was any more power efficient, but instead because the show was smaller and therefore there was less network gear.</p>
<p>5) Finally, a stat we didn&#8217;t track too carefully in Las Vegas, but that I find interesting.  During show hours the wireless network average 1,100 users attached.  That&#8217;s a lot of people and a lot of wireless devices.</p>
<p>The good news is there was nothing too unexpected in the data, overall the smaller show led to a smaller number of tickets and smaller consumption of resources across the board.  We hope to have the opportunity to work with the InteropNet team again next year and take a look at this data year-over-year for each show.</p>
]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 18:41:11 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/vegas">vegas</category>
      <category domain="http://www.securityratty.com/tag/interop las vegas">interop las vegas</category>
      <category domain="http://www.securityratty.com/tag/las vegas">las vegas</category>
      <category domain="http://www.securityratty.com/tag/wireless network average">wireless network average</category>
      <category domain="http://www.securityratty.com/tag/network">network</category>
      <category domain="http://www.securityratty.com/tag/interop">interop</category>
      <category domain="http://www.securityratty.com/tag/network gear">network gear</category>
      <category domain="http://www.securityratty.com/tag/user error">user error</category>
      <category domain="http://www.securityratty.com/tag/tickets">tickets</category>
      <source url="http://blog.sciencelogic.com/a-late-look-at-interop-ny-2008/11/2008">A late look at Interop NY 2008</source>
    </item>
    <item>
      <title><![CDATA[Rational Risk Management, Angry Italians, and Irrational Security Analysts]]></title>
      <link>http://www.securityratty.com/article/616867e9cd4e8203d8c23c0bef989749</link>
      <guid>http://www.securityratty.com/article/616867e9cd4e8203d8c23c0bef989749</guid>
      <description><![CDATA[Hope you all had a great weekend. I had meant to point you earlier to a FAIR analysis that Chris Hayes did over at his Blog . But Ive been a little busy, and before I could mention it, Stuart King put...]]></description>
      <content:encoded><![CDATA[<p>Hope you all had a great weekend.  I had meant to point you earlier to a <strong><a href="http://risktical.com/2008/11/06/security-template-exception-part-2-%E2%80%93-the-assessment/">FAIR analysis that Chris Hayes did over at his Blog</a></strong>.  But I&#8217;ve been a little busy, and before I could mention it, Stuart King <strong><a href="http://www.computerweekly.com/blogs/stuart_king/2008/11/ive-written-up-a-report.html">put up a kind of angry response</a></strong> on his ComputerWorld blog.  Snark aside, there are a couple of other really troubling aspects of Stuart&#8217;s reaction to Chris&#8217; analysis that I thought we could talk about this morning.</p>
<blockquote><p>The problem is that (Chris&#8217; analysis is) completely impractical. I&#8217;ll take a recent, and fairly typical situation as an example. I was taking issue with the manner in which remote access was being provisioned for a third party vendor to connect to a system hosted by one of our European business units. To cut a long story short, it was not only a breach of policy but highly insecure. I wanted the access to be disconnected, the business unit director wanted my risk assessment. And he didn&#8217;t want to wait for it.</p>
<p>To quote Chris Hayes, spending time on working out <em> <strong>the expected effectiveness of controls, over a given timeframe, as measured against a baseline level of force </strong></em>was not going to pacify an angry Italian fearful that my decision was going to cost him money. He wanted my explanation of the risk and more importantly, what I was going to offer as a solution to keep his business functioning</p></blockquote>
<p>As Chris is someone who actually does this for a living in a large company, and this is typical of his actual day job, I really find Stuart&#8217;s &#8220;impractical&#8221; comment to be, um, misinformed.</p>
<p>Also, I think Stuart mistakes the purpose of a risk analysis.  The purpose of the risk analysis is not to force someone to be &#8220;secure&#8221;, but to provide knowledge for decision making.  Using it as a &#8220;hammer&#8221; to knock in the nail of your personal risk tolerance impairs efficiency and in the long run retards &#8220;security&#8221; as it creates political resentment.  Seriously, who cares if something might violate policy or not in a pre-implementation discussion?  Policies are not stone tablets handed down from on high, they are state-in-time codification of the <em><strong>data owners </strong></em>risk tolerance.  This risk tolerance changes sometimes, and that&#8217;s OK.</p>
<p>To that extent, I appreciate (and I&#8217;m sure Chris does, as well) that risk analysis does not create rationality in the data owner.  Someone who sees you as a speedbump on the route to progress they may not be ready to appreciate your point of view even if it is stated in the most rational manner possible.   But it&#8217;s worth noting (and Stuart&#8217;s example is indicative of this point) that <em><strong>risk analysis does not create rationality in the analyst, either</strong></em>.  If one is being so &#8220;security minded&#8221; as to ignore the risk tolerance of the business owner - we&#8217;re bound to get a reaction similar to that Stuart encountered.  In fact, a practical risk analysis like Chris performed on his blog, done in 30 minutes, should identify the critical point of disagreement between Stuart and the data owner (again, Stuart doesn&#8217;t own the data, the agitated Italian does).</p>
<p>But let&#8217;s stay rational and open to alternatives to what Chris offers.  Stuart states his approach to risk analysis as:</p>
<blockquote><p>When I need to document a risk assessment I use a very simple form: list the threats, state the level of vulnerability, list the associated operational costs and potential revenue hits. High, medium, or low risk? Describe the controls and options. Write up who needs to do what, and how much of their time it&#8217;s going to take. Job done.</p></blockquote>
<p>At first glance, I don&#8217;t think what Chris has done is any less efficient, and it provides greater insight (using Frequency and Capability instead of just &#8216;listing the threats&#8217;).  But what is key here is that Chris&#8217; approach is consistent and defensible.  Less generous risk geeks and CSO&#8217;s I know would have no little difficulty with Stuart&#8217;s approach.  But to particularly answer Stuart&#8217;s main objection (impracticality) I would offer that with practice, Chris&#8217; work is probably quicker and easier than Stuart&#8217;s described process as it eliminates much of the ambiguity an immature risk analysis creates - reducing the need for further discussion and arguments with data owners (regardless of disposition or nationality).</p>
<p>Finally the irony of Stuart&#8217;s post is that the reason he had this confrontation may in fact be because he was incapable of bringing a salient model for risk to the table, one that identified the factors that create risk and developed a defensible belief statement concerning risk.   We&#8217;ll never know if one would have helped him in this isolated instance, but I can tell you that in organizations like Chris&#8217;, good risk models and strong risk anlayses create operational efficiencies, reduce costs, and streamlines intra-departmental communications.</p>
]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 13:43:15 +0000</pubDate>
      <category domain="http://www.securityratty.com/tag/risk">risk</category>
      <category domain="http://www.securityratty.com/tag/risk tolerance">risk tolerance</category>
      <category domain="http://www.securityratty.com/tag/risk models">risk models</category>
      <category domain="http://www.securityratty.com/tag/practical risk analysis">practical risk analysis</category>
      <category domain="http://www.securityratty.com/tag/strong risk anlayses">strong risk anlayses</category>
      <category domain="http://www.securityratty.com/tag/generous risk geeks">generous risk geeks</category>
      <category domain="http://www.securityratty.com/tag/immature risk analysis">immature risk analysis</category>
      <category domain="http://www.securityratty.com/tag/quote chris hayes">quote chris hayes</category>
      <category domain="http://www.securityratty.com/tag/chris hayes">chris hayes</category>
      <source url="http://riskmanagementinsight.com/riskanalysis/?p=520">Rational Risk Management, Angry Italians, and Irrational Security Analysts</source>
    </item>
  </channel>
</rss>
