<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-22537170</atom:id><lastBuildDate>Mon, 07 Jan 2013 08:16:50 +0000</lastBuildDate><category>ethics</category><category>traditions and taboos</category><category>BND</category><category>workshops</category><category>China</category><category>cults</category><category>fingerprinting</category><category>scifi</category><category>malware</category><category>cyber war</category><category>strategy</category><category>phsihing</category><category>enviromental cues</category><category>privacy</category><category>Hilton</category><category>Israel</category><category>House</category><category>case studies</category><category>debate</category><category>CPE</category><category>information security</category><category>Halloween</category><category>online identity</category><category>spam</category><category>apps</category><category>AV</category><category>email</category><category>security operations</category><category>corporate espionage</category><category>stem cells</category><category>border control</category><category>balance</category><category>body language</category><category>facebook</category><category>botnets</category><category>vetting</category><category>Policies</category><category>incident response</category><category>PDF</category><category>authentication</category><category>30 seconds pitch</category><category>success</category><category>on blogging</category><category>elevator pitch</category><category>All Hallows' Eve</category><category>mailing list</category><category>user education</category><category>neighborhood watch</category><category>hotels</category><category>waging war</category><category>EMP</category><category>underline causes</category><category>targeted attacks</category><category>command-line</category><category>Internet Explorer</category><category>microscopic detail</category><category>blogging</category><category>termination notice</category><category>self-help</category><category>ridiculous</category><category>isotf</category><category>buzzwords</category><category>fake whois</category><category>self reflection</category><category>Microsoft</category><category>0day</category><category>IDS</category><category>car hacking</category><category>estonia</category><category>route announcements</category><category>manipulation</category><category>spam legalization</category><category>affecting change</category><category>reverse engineering</category><category>worms</category><category>rapport</category><category>hacking</category><category>advertising</category><category>skeptics</category><category>trolling</category><category>underestimated</category><category>leadership</category><category>Air travel security</category><category>Spyware</category><category>even experts make mistakes</category><category>industrial espionage</category><category>user stupidity</category><category>porn</category><category>systems</category><category>email vector</category><category>Obama</category><category>user power</category><category>learning</category><category>lessons learned</category><category>computer-based attacks</category><category>mentoring</category><category>IDF</category><category>spying</category><category>TSA</category><category>the unseen</category><category>responsibility claims</category><category>global monitoring</category><category>citizcitizen journalism</category><category>appreciative inquiry</category><category>critical infrastructure</category><category>dark reading</category><category>security psychology</category><category>419</category><category>ghostnet</category><category>Scortched Earth</category><category>bounces</category><category>Google</category><category>awareness</category><category>Hebrew</category><category>debating</category><category>cool</category><category>basic components</category><category>phishing</category><category>Adware</category><category>conference running</category><category>bio</category><category>remote root</category><category>No Surprises</category><category>wireless</category><category>Omegle</category><category>joe job</category><category>vaccines</category><category>logical fallacies</category><category>civil disobidience</category><category>vigilantism</category><category>laser</category><category>sad</category><category>flame wars</category><category>herding cats</category><category>data mining</category><category>funny</category><category>doctors</category><category>Afghanistan</category><category>reimage</category><category>public information</category><category>economic considerations</category><category>cost vs. benefit</category><category>dangerous</category><category>SSL encryption</category><category>firefox</category><category>encryption</category><category>psychology</category><category>Robert Cialdini</category><category>web 2.0</category><category>sales</category><category>secrecy</category><category>broadband routers</category><category>David Chess</category><category>Tibet</category><category>c2</category><category>fad of the month</category><category>georgia</category><category>group dynamics</category><category>science fiction</category><category>Gartner</category><category>SCADA</category><category>greasemonkey</category><category>ISPs</category><category>Economist</category><category>Adobe</category><category>Deterrence</category><category>business</category><category>cyber crime</category><category>estdomains</category><category>remembrance</category><category>law enforcement</category><category>security</category><category>ubiquity</category><category>RAT</category><category>investigation tactics</category><category>abuse</category><category>parliamentary debate</category><category>SMOFS</category><category>funsec</category><category>international relations</category><category>climate change</category><category>holding hand</category><category>security by obscurity</category><category>exploring human nature</category><category>forensics</category><category>meta discussion</category><category>introducting yourself</category><category>hiring</category><category>IDA Pro</category><category>introductions</category><category>regulation</category><category>rationalizations</category><category>PR</category><category>hearding cats</category><category>respect</category><category>Zak Dechovich</category><category>Russia</category><category>WHO</category><category>stories</category><category>RBN</category><category>comic strip</category><category>exploit</category><category>email portability</category><category>syndicated</category><category>influence</category><category>trusted communities</category><category>empty spaces</category><category>atrivo</category><category>security theater</category><category>debugging</category><category>econonically hidden</category><category>persuasion</category><category>comics</category><category>Kevin Martin</category><category>Trojan horses</category><category>existential risks</category><category>citizen of the Internet</category><category>evolution</category><category>browsers</category><category>social-proof</category><category>Oil industry</category><category>anti-spam</category><category>ridicule</category><category>bad networks</category><category>spam-y</category><category>social networking</category><category>SMTP</category><category>inspiring</category><category>picture</category><category>python</category><category>Mozilla</category><category>rumors</category><category>computer spying</category><category>internet</category><category>interesting incidents</category><category>chat</category><category>can we get back to saving the world already?</category><category>FOM</category><category>bulletproof hosting</category><category>linux</category><category>embarassing</category><category>scarcity</category><category>FlashGot</category><category>social engineering</category><category>translation</category><category>law</category><category>information warfare</category><category>politics</category><category>random</category><category>civil society</category><category>communication</category><category>communities</category><category>IDA Python</category><category>Intelligence</category><category>human element</category><category>BP</category><category>stock exchange</category><category>ICANN</category><category>spear phishing</category><category>pyFox</category><category>ISOI</category><category>anonymity</category><category>Imri Goldberg</category><category>when first blogging</category><category>history</category><category>AUP</category><category>psychics</category><category>anime</category><category>traffic</category><category>series</category><category>failure</category><category>lusers</category><category>euology</category><title>Musings of an Over-Grown Dwarf</title><description /><link>http://gadievron.blogspot.com/</link><managingEditor>noreply@blogger.com (Gadi Evron)</managingEditor><generator>Blogger</generator><openSearch:totalResults>77</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/MusingsOfAnOver-grownDwarf" /><feedburner:info uri="musingsofanover-growndwarf" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-3243620411761763852</guid><pubDate>Thu, 18 Mar 2010 14:56:00 +0000</pubDate><atom:updated>2010-03-18T17:00:21.896+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">microscopic detail</category><category domain="http://www.blogger.com/atom/ns#">laser</category><category domain="http://www.blogger.com/atom/ns#">forensics</category><category domain="http://www.blogger.com/atom/ns#">fingerprinting</category><category domain="http://www.blogger.com/atom/ns#">border control</category><category domain="http://www.blogger.com/atom/ns#">authentication</category><title>Using Laser To Fingerprint Paper</title><description>I like it when old technologies and known scientific facts are used in a new way that makes them &lt;a href="http://nanotechwire.com/news.asp?nid=2254"&gt;pure genius&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
A discovery of old, which will change the future.&lt;br /&gt;
&lt;blockquote&gt;Ingenia Technology Limited today launches an exciting breakthrough proprietary technology, developed by Imperial College London and Durham University - the Laser Surface Authentication system (LSA). The LSA system recognises the inherent 'fingerprint' within all materials such as paper, plastic, metal and ceramics.&lt;br /&gt;
&lt;br /&gt;
The LSA system is a whole new approach to security and could prove valuable in the war against terrorism through its ability to make secure the authenticity of passports, ID cards and other documents such as birth certificates.&lt;br /&gt;
&lt;br /&gt;
This technological breakthrough has been masterminded by Professor Russell Cowburn, Professor of Nanotechnology in the Department of Physics at Imperial College London.&lt;br /&gt;
&lt;br /&gt;
Every paper, plastic, metal and ceramic surface is microscopically different and has its own 'fingerprint'. Professor Cowburn's LSA system uses a laser to read this naturally occurring 'fingerprint'. The accuracy of measurement is often greater than that of DNA with a reliability of at least one million trillion.&lt;br /&gt;
&lt;br /&gt;
The inherent 'fingerprint' is impossible to replicate and can be easily read using a low-cost portable laser scanner. This applies to almost all paper and plastic documents, including passports, credit cards and product packaging.&lt;/blockquote&gt;More on the science behind this:&lt;br /&gt;
&lt;blockquote&gt;"A unique 'fingerprint' is formed by microscopic surface imperfections on almost all paper documents, plastic cards and product packaging. That is what makes it possible to develop a much cheaper system to combat fraud. This inherent identity code is virtually impossible to modify. It can easily be read using a low-cost portable laser scanner.&lt;br /&gt;
&lt;br /&gt;
"Since all non-reflective surfaces have naturally occurring roughness that is a source of physical randomness, our technology can provide in-built security for a range of objects such as passports, ID and credit cards and pharmaceutical packaging. It can be cheaper and more reliable than current methods such as holograms and security ink.&lt;br /&gt;
&lt;br /&gt;
"Our research team used the optical phenomenon of 'laser speckle' to examine the fine structure of different surfaces using a focused laser.&lt;br /&gt;
&lt;br /&gt;
"We tried the technique on a variety of materials including matt-finish plastic cards, identity cards and coated paperboard packaging. The result was a clear recognition between the samples. This continued even after they were subjected to rough handling, including submersion in water, scorching, scrubbing with an abrasive cleaning pad and being scribbled on with thick black marker.&lt;br /&gt;
&lt;br /&gt;
"The beauty of this system is that we do not need to modify the item being protected in any way with tags, chips or ink - it is as if documents and packaging had their own unique DNA. This makes protection secret, simple to integrate into the manufacturing process and immune to attack.&lt;br /&gt;
&lt;br /&gt;
"It can be applied retrospectively and is no threat to personal privacy."&lt;/blockquote&gt;Look for this at the immigration desk verifying your passport, five years from now.&lt;br /&gt;
&lt;br /&gt;
Gadi Evron,&lt;br /&gt;
ge@linuxbox.org.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/RI1iX5Q2JOc/using-laser-to-fingerprint-paper.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>6</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2010/03/using-laser-to-fingerprint-paper.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-5242890246519172616</guid><pubDate>Thu, 18 Mar 2010 14:10:00 +0000</pubDate><atom:updated>2010-03-18T16:34:57.455+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">car hacking</category><category domain="http://www.blogger.com/atom/ns#">law enforcement</category><category domain="http://www.blogger.com/atom/ns#">interesting incidents</category><category domain="http://www.blogger.com/atom/ns#">facebook</category><category domain="http://www.blogger.com/atom/ns#">investigation tactics</category><category domain="http://www.blogger.com/atom/ns#">privacy</category><category domain="http://www.blogger.com/atom/ns#">hacking</category><category domain="http://www.blogger.com/atom/ns#">stock exchange</category><title>An interesting day in information security</title><description>A Mafia boss was caught because of his &lt;a href="http://abcnews.go.com/International/facebook-finds-mafia-boss/story?id=10124958"&gt;using Facebook&lt;/a&gt;, while unrelated to that the EFF released the result of their Freedom of Information request for material on how &lt;a href="http://www.eweek.com/c/a/Security/Social-Network-Privacy-Concerns-Raised-by-Undercover-Police-Tactics-409306/"&gt;law enforcement uses social networking&lt;/a&gt; to investigate suspects. "under cover".&lt;br /&gt;
&lt;br /&gt;
The SEC moved to freeze portfolios and accounts following attacks by a Russian hacker, &lt;a href="http://www.wired.com/threatlevel/2010/03/manipulated-stock-prices/"&gt;who manipulated stocks&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
InfoSecurity magazine has a story on &lt;a href="http://www.infosecurity-magazine.com/view/8033/espionage-in-sport/"&gt;espionage in sport&lt;/a&gt;, mentioning how where there's a motive, cyber-crime follows.&lt;br /&gt;
&lt;br /&gt;
And of course, the leading story (which I discovered thanks to a post on Facebook by Dave Aitel) is how an hacker (if that is a descriptive word in this case) b&lt;a href="http://www.wired.com/threatlevel/2010/03/hacker-bricks-cars/"&gt;roke into 100 cars&lt;/a&gt; to cause inconvenience, such as honking, or immobilizing customer the cars.&lt;br /&gt;
&lt;br /&gt;
He hijacked the remote control system ("web-based vehicle-immobilization system normally used to get the attention of consumers delinquent in their auto payments") by logging on with an account of an employee. He used to be an employee himself, until fired later on.&lt;br /&gt;
&lt;br /&gt;
Also, check out this extremely interesting paper from Cormac Herley at Microsoft Research on why people reject security advice:&lt;br /&gt;
&lt;a href="http://research.microsoft.com/en-us/um/people/cormac/papers/2009/SoLongAndNoThanks.pdf"&gt;So Long, And No Thanks for the Externalities&lt;/a&gt;: &lt;br /&gt;
The Rational Rejection of Security Advice by Users&lt;br /&gt;
&lt;br /&gt;
Gadi Evron,&lt;br /&gt;
ge@linuxbox.org.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/BfvMQxuBpuI/interesting-day-in-information-security.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>0</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2010/03/interesting-day-in-information-security.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-2086751118893907074</guid><pubDate>Mon, 22 Feb 2010 15:06:00 +0000</pubDate><atom:updated>2010-02-22T17:07:23.086+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">email portability</category><category domain="http://www.blogger.com/atom/ns#">Israel</category><title>Email Portability Approved by Knesset Committee</title><description>The email portability bill has just been approved by the Knesset's committee for legislation, sending it on its way for the full legislation process of the Israeli parliament.&lt;br /&gt;
&lt;br /&gt;
While many users own a free email account, many in Israel still make use of their ISP's email service.&lt;br /&gt;
&lt;br /&gt;
According to this proposed bill, when a client transfers to a different ISP the email address will optionally be his to take along, "just like" mobile providers do today with phone numbers.&lt;br /&gt;
&lt;br /&gt;
This new legislation makes little technological sense, and will certainly be a mess to handle operationally as well as beurocratically, but it certainly is interesting, and at least the notion is beautiful.&lt;br /&gt;
&lt;br /&gt;
The proposed bill can be found here [Doc, Hebrew]:&lt;br /&gt;
&lt;a href="http://my.ynet.co.il/pic/computers/22022010/mail.doc"&gt;http://my.ynet.co.il/pic/computers/22022010/mail.doc&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Linked to from this ynet (leading Israeli news site) story, here:&lt;br /&gt;
&lt;a href="http://www.ynet.co.il/articles/0,7340,L-3852744,00.html"&gt;http://www.ynet.co.il/articles/0,7340,L-3852744,00.html&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Gadi Evron,&lt;br /&gt;
ge@linuxbox.org.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/8Rxv81q-JFc/email-portability-approved-by-knesset.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>0</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2010/02/email-portability-approved-by-knesset.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-5386703276962194081</guid><pubDate>Mon, 22 Feb 2010 14:09:00 +0000</pubDate><atom:updated>2010-02-22T16:12:47.520+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">broadband routers</category><category domain="http://www.blogger.com/atom/ns#">botnets</category><category domain="http://www.blogger.com/atom/ns#">CPE</category><category domain="http://www.blogger.com/atom/ns#">worms</category><title>Chuck Norris Botnet and Broadband Routers</title><description>Last week &lt;a href="http://praguemonitor.com/2010/02/16/czech-experts-uncover-global-virus-network"&gt;Czech researchers&lt;/a&gt; released information on a new worm which exploits CPE devices (broadband routers) by means such as default passwords, constructing a large DDoS botnet. Today this story hit &lt;a href="http://www.pcworld.com/businesscenter/article/189868/chuck_norris_botnet_karatechops_routers_hard.html"&gt;international news&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
When I raised this issue before in 2007 on the NANOG mailing list, some other vetted mailing lists and on CircleID &lt;a href="http://www.circleid.com/posts/broadband_routers_botnets/"&gt;here&lt;/a&gt; and &lt;a href="http://www.circleid.com/posts/broadband_router_insecurity/"&gt;here&lt;/a&gt;, the consensus was that the vendors will not change their position on default settings unless "something happens", I guess this is it, but I am not optimistic on seeing activity from vendors on this now, either.&lt;br /&gt;
&lt;br /&gt;
The spread of insecure broadband modems (DSL and Cable) is extremely wide-spread, with numerous ISPs, large and small, whose entire (read significant portions of) broadband population is vulnerable. In tests Prof. Randy Vaughn and I conducted with some ISPs in 2007-8 the results have not been promising.&lt;br /&gt;
&lt;br /&gt;
Further, many of these devices world wide serve as infection mechanisms for the computers behind them, with hijacked DNS that points end-users to malicious web sites.&lt;br /&gt;
&lt;br /&gt;
On the ISPs end, much like in the early days of botnets, many service providers did not see these devices as their responsibility -- even though in many cases they are the providers of the systems, and these posed a potential DDoS threat to their networks. As a mind-set, operationally taking responsibility for devices located at the homes of end users made no sense, and therefore the stance ISPs took on this issue was understandable, if irresponsible.&lt;br /&gt;
&lt;br /&gt;
As we can't rely on the vendors, ISPs should step up, and at the very least ensure that devices they provide to their end users are properly set up (a significant number of iSPs already pre-configure them for support purposes).&lt;br /&gt;
&lt;br /&gt;
The Czech researchers have done a good job and I'd like to thank them for sharing their research with us.&lt;br /&gt;
&lt;br /&gt;
In &lt;a href="http://www.pcworld.com/businesscenter/article/189868/chuck_norris_botnet_karatechops_routers_hard.html"&gt;this article&lt;/a&gt; by Robert McMillan, some details are shared in English:&lt;br /&gt;
&lt;blockquote&gt;Discovered by Czech researchers, the botnet has been spreading by taking advantage of poorly configured routers and DSL modems, according to Jan Vykopal, the head of the network security department with Masaryk University's Institute of Computer Science in Brno, Czech Republic.&lt;br /&gt;
&lt;br /&gt;
The malware got the Chuck Norris moniker from a programmer's Italian comment in its source code: "in nome di Chuck Norris," which means "in the name of Chuck Norris." Norris is a U.S. actor best known for his martial arts films such as "The Way of the Dragon" and "Missing in Action."&lt;br /&gt;
&lt;br /&gt;
Security experts say that various types of botnets have infected millions of computers worldwide to date, but Chuck Norris is unusual in that it infects DSL modems and routers rather than PCs.&lt;br /&gt;
&lt;br /&gt;
It installs itself on routers and modems by guessing default administrative passwords and taking advantage of the fact that many devices are configured to allow remote access. It also exploits a known vulnerability in D-Link Systems devices, Vykopal said in an e-mail interview.&lt;br /&gt;
&lt;br /&gt;
A D-Link spokesman said he was not aware of the botnet, and the company did not immediately have any comment on the issue.&lt;br /&gt;
&lt;br /&gt;
Like an earlier router-infecting botnet called Psyb0t, Chuck Norris can infect an MIPS-based device running the Linux operating system if its administration interface has a weak username and password, he said. This MIPS/Linux combination is widely used in routers and DSL modems, but the botnet also attacks satellite TV receivers.&lt;/blockquote&gt;Read more, &lt;a href="http://www.pcworld.com/businesscenter/article/189868/chuck_norris_botnet_karatechops_routers_hard.html"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Gadi Evron,&lt;br /&gt;
ge@linuxbox.org.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/02RbuB-0JFU/chuck-norris-botnet-and-broadband.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>0</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2010/02/chuck-norris-botnet-and-broadband.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-3269666848922638765</guid><pubDate>Thu, 18 Feb 2010 04:16:00 +0000</pubDate><atom:updated>2010-02-18T06:16:37.366+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Spyware</category><category domain="http://www.blogger.com/atom/ns#">Adware</category><category domain="http://www.blogger.com/atom/ns#">firefox</category><category domain="http://www.blogger.com/atom/ns#">Policies</category><category domain="http://www.blogger.com/atom/ns#">Mozilla</category><category domain="http://www.blogger.com/atom/ns#">FlashGot</category><category domain="http://www.blogger.com/atom/ns#">No Surprises</category><category domain="http://www.blogger.com/atom/ns#">AUP</category><title>Mozilla Add-on Policies and Spyware Surprises</title><description>Following up on my previous post, I wrote a full accounting of how I discovered FlashGot illegitimate behavior, as well as how Mozilla's policies work on such issues:&lt;br /&gt;
&lt;a href="http://www.darkreading.com/blog/archives/2010/02/mozillas_addon.html"&gt;http://www.darkreading.com/blog/archives/2010/02/mozillas_addon.html&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Gadi Evron,&lt;br /&gt;
ge@linuxbox.org.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;&lt;/b&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/_6uKIHNnKyk/mozilla-add-on-policies-and-spyware.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>0</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2010/02/mozilla-add-on-policies-and-spyware.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-8090103525912366768</guid><pubDate>Tue, 16 Feb 2010 07:45:00 +0000</pubDate><atom:updated>2010-02-16T09:45:49.136+02:00</atom:updated><title>Flashgot Firefox Plugin Now Spyware</title><description>FlashGot Firefox plugin, a long-time download assistant, now acts like spyware.&lt;br /&gt;
&lt;br /&gt;
It gives you recommendations IN Google search to another search site, according to your searches.&lt;br /&gt;
&lt;br /&gt;
Gadi Evron,&lt;br /&gt;
ge@linuxbox.org.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;&lt;/b&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/gEht8vqIdnY/flashgot-firefox-plugin-now-spyware.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>0</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2010/02/flashgot-firefox-plugin-now-spyware.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-8671023777522844640</guid><pubDate>Sun, 14 Feb 2010 16:52:00 +0000</pubDate><atom:updated>2010-02-15T04:15:59.691+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">manipulation</category><category domain="http://www.blogger.com/atom/ns#">stories</category><category domain="http://www.blogger.com/atom/ns#">communication</category><category domain="http://www.blogger.com/atom/ns#">politics</category><title>Personal Story, Tactical Communication and Conversation Manipulation</title><description>[syndicated from my personal blog, &lt;a href="http://gevron.livejournal.com/40376.html"&gt;here&lt;/a&gt;]&lt;br /&gt;
&lt;br /&gt;
Going back home from meeting friends for a beer, I was excited. It's not often that I encounter something cool to do which also appeals to my youth's old tactical nature. When I do, I jump it! This is a story of how someone tried to manipulate me, and how I countered.&lt;br /&gt;
&lt;br /&gt;
The two friends with me discussed a fascinating topic I didn't even know existed, and simply because I saw that I could do so, I decided to bring this topic to a larger audience, creating a mini-conference on the subject.&lt;br /&gt;
&lt;br /&gt;
First on my list was to find a location, so I sent an email to a local academic who could be a good partner for this, and called a couple of other friends to get them on board, arranged for speakers, PR and other necessities.&lt;br /&gt;
&lt;br /&gt;
The next day I received an answer with a phone number, and within a few hours had the academic in question on my cell phone. He asked me to call his land line, and I did. Our conversation was very easy-going and friendly in tone. Smiles splattered on our faces.&lt;br /&gt;
&lt;br /&gt;
I told him I am excited to speak with him, as he obviously has more experience on this particular subject. I was differential as academic ego demands, showing him the respect he deserves, but in tone -- I remained an equal.&lt;br /&gt;
&lt;br /&gt;
I made my case, and he cut in, asking "Can you explain what you have in mind? We ran a conference on this four years ago. Do you have something new to warrant an event?"&lt;br /&gt;
&lt;br /&gt;
"No," I answered honestly in an &lt;i&gt;interrupt&lt;/i&gt; of my own. He apparently didn't expect that, so I asked to continue my pitch, and then did.&lt;br /&gt;
&lt;br /&gt;
A lot changed in the last four years, and even if not, in a university environment four years ia an eternity -- with many new students who would appreciate this event. I had better arguments than these, and as my purpose was cooperation rather than confrontation, I preferred to move on.&lt;br /&gt;
&lt;br /&gt;
I explained how this topic is exciting, how it has direct impact on both higher education as well as real implications for daily life, governance, and the economy. I used two anecdotal examples to illustrate this, and my excitement probably dripped all over him, even over the phone.&lt;br /&gt;
&lt;br /&gt;
"Well," he responded, "let me tell you about an idea I had."&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;DING DING DING DING DING&lt;/i&gt;&lt;br /&gt;
Warning bells sounded in my head. "Happily, what's your idea?&lt;br /&gt;
&lt;br /&gt;
He told me about an event he thought of, which sounded interesting. As he spoke I got about three ideas running in my head on the subject, but I listened quietly. "I would like to work with you, and if you can take some time to think of ideas for what we can do at this event, I'd appreciate us talking about them."&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Stay on message&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
"Of course," I said, "I'd be more than happy to." And I was. "However", I continued with the same breath, "this conversation is about the first idea, so while I'd definitely like to discuss this with you further later, let's stick to the first one for now."&lt;br /&gt;
&lt;br /&gt;
"Alright." he said, and we discussed a bit further, at which point he said "well, last year we ran a small event on this topic, and there was real innovation there which we could showcase. What will be new here?"&lt;br /&gt;
&lt;br /&gt;
I explained a bit more on why I am excited, and why the topic is relevant, and how such an event can be beneficial. Then I decided to change tactics to show my resolve.&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Stay on message, clarify position&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
"As you know, I am a security professional."&lt;br /&gt;
&lt;br /&gt;
"Yes, that is where I know you from. Security, Internet, Cyber Warfare... Why does this subject interest you?"&lt;br /&gt;
&lt;br /&gt;
"Truth be told," I happily jumped in, "I am excited. I learned to be a strategic person, but at heart, I am a tactical person, energized by excitement. I am excited about this topic, and I am willing to put the time into making this event happen. I will make it happen, but as I know of your vast expertise, I decided I must approach you first."&lt;br /&gt;
&lt;br /&gt;
After more deliberation he asked me "What do you think of my event idea? I'd appreciate your opinion on ideas for it, and we can get back together on this after you think about it."&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;DING DING DING DING DING&lt;/i&gt;&lt;br /&gt;
Alarm bells rang again.&lt;br /&gt;
&lt;br /&gt;
"I already thought about it, and have three ideas so far."&lt;br /&gt;
&lt;br /&gt;
"Oh, great! What are your ideas?"&lt;br /&gt;
&lt;br /&gt;
I shared two, as my short-term memory had already erased the third. I told him as much, and I think he believed me, but it could be seen as a lure or a trick. We were extremely friendly. He asked me to email him the third one if I remember it. I promised to do so.&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Stay on message&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
"I'd like however, to finish our discussion of my idea for now, as there is a time constraint."&lt;br /&gt;
&lt;br /&gt;
When he heard I want to get it done within a month rather than a year, he was shocked. I told him how excited I am about the specific speakers I want to bring, and how one of them is leaving the country to join his new wife, and he is a major source of my energy for this. I mentioned how I understand if his events schedule is already closed for the coming year, but wanted to make sure and contact him first.&lt;br /&gt;
&lt;br /&gt;
It wasn't my intention to go cold on him or play "girl negotiation" by appearing not interested, but rather to give him  way out. But whether it was my excitement or the "girl tactic", or even the ego massage, it seemed to work.&lt;br /&gt;
&lt;br /&gt;
He got excited about this speaker as well, and asked about getting him on video before he leaves. Then....&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;BANG BANG BANG BANG BANG&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
A trick I've never seen before, which unlike the ones used up to now, is purely manipulative from whatever perspective you may look at it.&lt;br /&gt;
&lt;br /&gt;
"How about we both take a couple of days to think of our two ideas, then get back together and pick one?"&lt;br /&gt;
&lt;br /&gt;
This is wrong on so many levels. To begin with, his idea is not on the agenda. Second, he assumes I am willing to give up on my idea. Third, he assumes it's one or the other, this is a false choice logical fallacy.&lt;br /&gt;
&lt;br /&gt;
More importantly, with this trick he can potentially achieve four immediately obvious things. First, wipe the slate clean to run his arguments by me again. Second, put distance between the chats so that I have time to move from my strong position, and consider his, perhaps feeling uncomfortable turning him down again. Third, it puts the subject on the agenda. And fourth, potentially try to wear me down, as most people won't call again in two days, or in two months. &lt;br /&gt;
&lt;br /&gt;
I didn't miss a beat.&lt;br /&gt;
&lt;br /&gt;
"I would be happy to discuss your idea separately, it sounds very interesting and I'd be happy to work with you on it. However, my resources are limited and at this time I am only interested in working on this one."&lt;br /&gt;
&lt;br /&gt;
I added my winning argument: "I believe that I can get very good PR coverage for this mini-event, and get cooperation with Famous-Non-Profit which will also be happy to cover a part of the costs."&lt;br /&gt;
&lt;br /&gt;
He lighted up at the mention of PR. We spoke for a bit and he asked me for a few days to speak with his boss. A few days when I have only a month to get things going are critical, so I wasn't happy about it. But the request was reasonable. He threw the ball into my court though, so when I got off the phone, I sent him an email.&lt;br /&gt;
&lt;br /&gt;
I detailed five good ideas for his event, mentioned I was happy to talk with him, and was looking forward to hear from him soon. I also attached my phone number.&lt;br /&gt;
&lt;br /&gt;
As I said when I started this post, he really is a good guy, and very friendly. But he is also a politician. He is an expert communicator who interviewed people live for a decade as a journalist. So while I dislike manipulative behavior I recognize that for some, such behavior is more than acceptable. In fact, it is regular m.o. and needs to be expected as part of the game.&lt;br /&gt;
&lt;br /&gt;
Thing is, even just a few years ago I would have gotten stuck after his first &lt;i&gt;interrupt&lt;/i&gt;, and either ended up working on his event without realizing it -- or by being too friendly. Worse still, I could have mishandled the communication in a potentially offensive fashion. Some years ago more, and I wouldn't have been able to play the game, and would have taken offense.&lt;br /&gt;
&lt;br /&gt;
Being able to switch gears into "I'm being manipulated", think fast on my feet with my responses, and keep the conversation on track for my purposes (also the stated agenda of the call) -- all while keeping the rapport going without losing one heart beat, got me very excited. The content of the call was suddenly secondary.&lt;br /&gt;
&lt;br /&gt;
While I am extremely straight-forward and honest in my communication style to a point of bluntness, I am a work in progress and am always learning. And I must admit, when two professionals meet, the conversation is happening on a completely different level. I am just surprised he didn't read through me that I was on to every single trick, when I was able to deflect them all. Or maybe he did and kept throwing them at me anyway to try and outwit me?&lt;br /&gt;
&lt;br /&gt;
The cynic in me may in retrospect reconsider the first thing he ever said to me, to call him back on land line, as a manipulative gesture to get me in a compliant mood. But that would be too paranoid -- wouldn't it?&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;There are a few issues to consider about this encounter&lt;/u&gt;:&lt;br /&gt;
&lt;br /&gt;
1. What was his motive? Perhaps he confused me for a hungry young hot shot, and wanted to use my excitement for his own ends. Perhaps a clear-cut switch-a-roo to get me to work on his event, "stealing" me from mine. Thus, bringing the conversation to where he wants it.&lt;br /&gt;
&lt;br /&gt;
Then again, maybe he was just trying to end the conversation non-confrontationally.&lt;br /&gt;
&lt;br /&gt;
2. His main tricks, in order were: change subject, switch-a-roo, get back together in 2 days.&lt;br /&gt;
&lt;br /&gt;
3. What can you do to counter such tricks? After all, you may not always have a quick wit about you, or know the specific tricks.&lt;br /&gt;
&lt;br /&gt;
The answer is similar to holding your own in politics: Stay on message. Know what your message is and stick to it. Others may try to confuse you, throw you off, and introduce a red-herring such as sending it for discussion in committee. Stay on message.&lt;br /&gt;
&lt;br /&gt;
4. More importantly, the conversation made it clear it is quite possible he has no political power on this front, and thus can't give me what I want anyway.&lt;br /&gt;
&lt;br /&gt;
Which brings us to...&lt;br /&gt;
&lt;br /&gt;
5. What is your goal?&lt;br /&gt;
I kept going as I wanted to convince him, and after a fashion, I did get the best possible alternative result. But why keep at it if it won't achieve my goal?&lt;br /&gt;
&lt;br /&gt;
Two tricks such as he used can be excuses as part of natural discussion, at the third, why keep at it? By this time it is clear to both sides what's going on and no positive result can come out of it.&lt;br /&gt;
&lt;br /&gt;
More importantly, my purpose is to achieve a goal, and if I am not going to, why stay on a call that is probably uncomfortable for at least one of the sides, and as sure as the sky is blue, wastes my time?&lt;br /&gt;
&lt;br /&gt;
If my purpose is not adversarial, why treat the situation as a battle? Cooperative discussion is a much better approach. As no cooperation was likely to happen, keeping the discussion going was pointless.&lt;br /&gt;
&lt;br /&gt;
In summary, it didn't work out. But you should not get me wrong, I have a lot of respect for the guy. But it was one of the more fascinating five minutes in my life these past few months.&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Here are some articles I wrote on similar experiences I had&lt;/u&gt;:&lt;br /&gt;
&lt;a href="http://gevron.livejournal.com/11841.html"&gt;I'm interested, but in you&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://gevron.livejournal.com/32719.html"&gt;Snap! Jazz music and mass hypnosis&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://gevron.livejournal.com/29557.html"&gt;WTF! Or, wow, this never happened to me before!&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Gadi Evron,&lt;br /&gt;
ge@linuxbox.org.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;&lt;/b&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/10a-dxoWjFE/personal-story-tactical-communication.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>0</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2010/02/personal-story-tactical-communication.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-7295801068363910400</guid><pubDate>Sun, 14 Feb 2010 07:17:00 +0000</pubDate><atom:updated>2010-02-14T09:17:29.126+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">case studies</category><category domain="http://www.blogger.com/atom/ns#">malware</category><category domain="http://www.blogger.com/atom/ns#">IDS</category><title>Case study: undetected malware</title><description>&lt;a href="http://www.cyberwart.com/blog/2010/01/09/undetected-malware-case-study-jan2010-01/"&gt;&lt;img src="http://www.cyberwart.com/blog/wp-content/uploads/2010/01/010910_0402_UndetectedM12.png"&gt;&lt;/a&gt;&lt;br /&gt;
In this case study from The George Washington University, researchers Sara Laughlin and Matthew Wollenweber released their work on previously undetected malware they discovered via their IDS system. Unknown to most anti virus products, and proceeded to analyze it:&lt;br /&gt;
&lt;blockquote&gt;On January 7th, 2010 GWU ISS Security identified a potential threat by a signature alert on a network sensor. Later analysis confirmed a security threat not currently detected by most antivirus products. This report details how the malware was detected and the analysis of the threat. Additionally, we hope this informs readers of a current threat.&lt;/blockquote&gt;This report underscores how anti virus products while a critical part of any computer's security, are insufficient by themselves, and inherently incomplete as a reactive solution.&lt;br /&gt;
&lt;br /&gt;
I applaud the good work from the researchers, and even more, the fact they took the time to write and to release this report. These are barely ever public, and they earned my respect.&lt;br /&gt;
&lt;br /&gt;
You can read the complete article here:&lt;br /&gt;
&lt;a href="http://www.cyberwart.com/blog/2010/01/09/undetected-malware-case-study-jan2010-01/"&gt;http://www.cyberwart.com/blog/2010/01/09/undetected-malware-case-study-jan2010-01/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Gadi Evron,&lt;br /&gt;
ge@linuxbox.org.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;&lt;/b&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/oS6Y_KMwbds/case-study-undetected-malware.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>0</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2010/02/case-study-undetected-malware.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-71783590597420078</guid><pubDate>Mon, 08 Feb 2010 09:19:00 +0000</pubDate><atom:updated>2010-02-08T11:20:26.908+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">dark reading</category><category domain="http://www.blogger.com/atom/ns#">series</category><category domain="http://www.blogger.com/atom/ns#">security</category><category domain="http://www.blogger.com/atom/ns#">PR</category><title>Security PR: Article Series</title><description>In a five-part article series on Dark Reading, I explored how tech and security companies can be  more successful with PR, and build their brand by discovering the wealth of resources they already have.&lt;br /&gt;
&lt;br /&gt;
Many companies I contract with ask me one of the following questions: What is a good PR strategy for releasing a security vulnerability? What if we have nothing to say to reporters? Many people speak of social networking, what's real? How do we get our name out there?&lt;br /&gt;
&lt;br /&gt;
A previous series on articles I wrote was on &lt;a href="http://gadievron.blogspot.com/2009/09/lessons-i-learned-from-cyber-crime.html"&gt;Lessons I Learned from Cybercrime&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
I started this series on PR almost by accident, when discussing why some security blogs are more successful than others, and continued with articles trying to answer some of the other questions.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://www.darkreading.com/blog/archives/2009/12/security_bloggi.html"&gt;The Secret Sauce For Security Blogging&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;
&lt;blockquote&gt;About how some security blogs manage to engage their audience better than others and make their readers feel more in touch with what's happening -- on top of earning credibility. &lt;/blockquote&gt;&lt;b&gt;&lt;a href="http://www.darkreading.com/blog/archives/2009/12/security_pr_how.html"&gt;Security PR: How To Talk To Reporters&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;
&lt;blockquote&gt;Here are some tips for security professionals and security public relations representatives on how to pitch reporters when you have something new and exciting to share.&lt;/blockquote&gt;&lt;b&gt;&lt;a href="http://www.darkreading.com/blog/archives/2009/12/security_pr_str.html"&gt;Security PR: How To Disclose A Vulnerability&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;
&lt;blockquote&gt;When your team discovers a new security vulnerability in a third-party product, there are ways to handle it correctly to achieve maximum visibility.&lt;/blockquote&gt;&lt;b&gt;&lt;a href="http://www.darkreading.com/blog/archives/2010/01/security_pr_we.html"&gt;We Have Nothing To Say -- Or Do We?&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;
&lt;blockquote&gt;The first rule of appearing smart, they say, is to keep quiet, but keeping quiet doesn't help your PR. What are you to do?&lt;/blockquote&gt;&lt;b&gt;&lt;a href="http://darkreading.com/blog/archives/2010/02/security_pr_bra.html"&gt;'Brand' Your Employees&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;
&lt;blockquote&gt;You might want your product to be in the news every day, and for your PR to create miracles for you. But if you want attention, then your company must speak out on big security issues and news. But there are challenges, and your employees may be the answer.&lt;/blockquote&gt;Gadi Evron,&lt;br /&gt;
ge@linuxbox.org.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;&lt;/b&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/h24g-zwLno8/security-pr-article-series.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>0</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2010/02/security-pr-article-series.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-7911883119030481052</guid><pubDate>Tue, 26 Jan 2010 06:42:00 +0000</pubDate><atom:updated>2010-01-26T08:50:42.907+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">industrial espionage</category><category domain="http://www.blogger.com/atom/ns#">China</category><category domain="http://www.blogger.com/atom/ns#">Hilton</category><category domain="http://www.blogger.com/atom/ns#">corporate espionage</category><category domain="http://www.blogger.com/atom/ns#">computer spying</category><category domain="http://www.blogger.com/atom/ns#">Oil industry</category><title>Corporate espionage in the news: Hilton and the Oil industry</title><description>Is anyone calling espionage by means of computers cyber-espionage yet? I hope not. At least they shouldn't call it cyber war.&lt;br /&gt;
&lt;br /&gt;
Two news stories of computerized espionage reached me today.&lt;br /&gt;
&lt;br /&gt;
The first, regarding the Oil industry, was sent by Marc Sachs to a SCADA security mailing list we both read. The second, about the hotel industry, was sent by Deb Geisler to science fiction convention runners (SMOFS) mailing list we both read.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;US oil industry hit by cyberattacks: Was China involved?&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://www.csmonitor.com/USA/2010/0125/US-oil-industry-hit-by-cyberattacks-Was-China-involved"&gt;http://www.csmonitor.com/USA/2010/0125/US-oil-industry-hit-by-cyberattacks-Was-China-involved&lt;/a&gt;&lt;br /&gt;
&lt;blockquote&gt;At least three US oil companies were the target of a series of previously undisclosed cyberattacks that may have originated in China and that experts say highlight a new level of sophistication in the growing global war of Internet espionage.&lt;/blockquote&gt;&lt;b&gt;Starwood Charges That Top Hilton Execs Abetted Espionage&lt;/b&gt;&lt;br /&gt;
&lt;a href="http://www.meetings-conventions.com/article_ektid31918.aspx"&gt;http://www.meetings-conventions.com/article_ektid31918.aspx&lt;/a&gt;&lt;br /&gt;
&lt;blockquote&gt;Starwood's claim points to a "mountain of undisputed evidence," including e-mails among Hilton senior management, that Klein and Lalvani worked with others within Starwood to steal sensitive documents by sending them via personal e-mail accounts, among other methods, and that such information was shared and used by all of Hilton's luxury and lifestyle brands, as well as in the development of Hilton's now-shelved Denizen brand. In the new filing, Starwood says, "This case is extraordinary, and presents the clearest imaginable case of corporate espionage, theft of trade secrets, unfair competition and computer fraud...Hilton's conduct is outrageous."&lt;/blockquote&gt;As to whether China is involved, maybe. But the automatic blaming has got to stop. Many other countries have been known to be conducting corporate espionage, such as &lt;a href="http://samvak.tripod.com/pp144.html"&gt;France&lt;/a&gt;, and as the second story above shows, so do corporations themselves.&lt;br /&gt;
&lt;br /&gt;
But.. here are a few questions:&lt;br /&gt;
&lt;br /&gt;
- My dog barked, was China involved?&lt;br /&gt;
- The traffic light turned red, was China involved?&lt;br /&gt;
- I am tired. Is China involved?&lt;br /&gt;
&lt;br /&gt;
Gadi Evron,&lt;br /&gt;
ge@linuxbox.org.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;&lt;/b&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/OMDyCnFf8UY/corporate-espionage-in-news-hilton-and.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>0</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2010/01/corporate-espionage-in-news-hilton-and.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-2356130805557814792</guid><pubDate>Sun, 24 Jan 2010 17:08:00 +0000</pubDate><atom:updated>2010-01-24T20:32:51.460+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">joe job</category><category domain="http://www.blogger.com/atom/ns#">apps</category><category domain="http://www.blogger.com/atom/ns#">facebook</category><category domain="http://www.blogger.com/atom/ns#">abuse</category><title>Bill Brenner Joe Jobbed by a Facebook App</title><description>My friend Bill Brenner, editor of CSO Magazine, just warned friends in his Facebook status message that someone may be trying to get them to add an application to their wall by using his name.&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;Bill Brenner:  Some cyber-dope is apparently trying to use my name to infect your machine with the message "Bill Brenner has posted something on your wall." Do not click on it. It's a trick. Repeat: If you get a bunch of messages from me saying I posted something called "news feed" on your wall, do not allow the app access.&lt;/blockquote&gt;&lt;br /&gt;
I don't know if this is targeted against Bill (if so, congratulations Bill! Your made it!) or if a malicious app is using names of friends to get people to add it. But this is certainly an interesting development.&lt;br /&gt;
&lt;br /&gt;
Bill, stay strong and ignore. I passed it over to Facebook security. And people, remember to be careful of what you click on!&lt;br /&gt;
&lt;br /&gt;
This is why I like Bill, he immediately warned everybody.&lt;br /&gt;
&lt;br /&gt;
Gadi Evron,&lt;br /&gt;
ge@linuxbox.org.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;&lt;/b&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/Tk30usVR7kk/bill-brenner-joe-jobbed-by-facebook-app.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>1</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2010/01/bill-brenner-joe-jobbed-by-facebook-app.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-3630995150265836846</guid><pubDate>Sat, 23 Jan 2010 06:38:00 +0000</pubDate><atom:updated>2010-01-23T08:47:27.225+02:00</atom:updated><title>Perhaps it's time to regulate Microsoft as critical infrastructure?</title><description>Microsoft has put a lot into securing its code, and is very good at doing so. However, is it doing enough?&lt;br /&gt;
&lt;br /&gt;
My main argument is about the policy of handling vulnerabilities for 6 months without patching (such as the Google attacks 0day apparently was) and the policy of waiting a whole month before patching this very same vulnerability when it first became an in-the-wild 0day exploit (it has now been patched, ahead of schedule).&lt;br /&gt;
&lt;br /&gt;
Microsoft is the main proponent of responsible disclosure, and has shown it is a responsible vendor. Also, patching vulnerabilities is far from easy, and Microsoft has done a tremendous job at getting it done. I simply call on it to stay responsible and amend its faulty and dangerous policies. A whole month as the default response to patching a 0day? Really?&lt;br /&gt;
&lt;br /&gt;
With their practical monopoly, and the resulting monoculture, perhaps their policies ought to be examined for regulation as critical infrastructure, if they can't bring themselves to be more responsible on their own.&lt;br /&gt;
&lt;br /&gt;
This is the first time in a long while that I find it fit to criticize Microsoft on security. Perhaps they have grown complacent with the PR nightmare of full disclosure a decade behind them, with most vulnerabilities now "sold" to them directly or indirectly by the security industry.&lt;br /&gt;
&lt;br /&gt;
Gadi Evron,&lt;br /&gt;
ge@linuxbox.org.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;&lt;/b&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/V3qoaAKnY0s/perhaps-its-time-to-regulate-microsoft.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>1</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2010/01/perhaps-its-time-to-regulate-microsoft.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-3903875991282665926</guid><pubDate>Sat, 23 Jan 2010 06:08:00 +0000</pubDate><atom:updated>2010-01-23T08:38:51.894+02:00</atom:updated><title>Large Hadron Collider, Nessus, and the InterWebz</title><description>CERN put the Large Hadron Collider through &lt;a href="http://www.controlenguk.com/article.aspx?ArticleID=31000"&gt;some rigorous tests&lt;/a&gt;, and apparently at first some of the Siemens manufactured SCADA systems failed. While they are apparently better now, and I am happy to see how serious CERN is about security, this does beg the question.... WAIT! You mean it's connected to the Internet? I suddenly don't feel so safe.&lt;br /&gt;
&lt;blockquote&gt;&lt;b&gt;Protection against external access&lt;/b&gt;&lt;br /&gt;
‘Redundant installations such as the Simatic S7-400H fault-tolerant type of controllers may offer a high degree of operational safety. But who can guarantee that no one will take over the controller, crash it and compromise its security?’ asks Dr. Stefan Lüders from the computer security team of the IT department at CERN. ‘Most controllers, field devices and even actuators are now directly connected to Ethernet.’&lt;br /&gt;
&lt;br /&gt;
The team led by Dr. Lüders therefore developed a special test bench for dedicated examination of the vulnerability of controllers, SCADA (Supervisory Control and Data Acquisition) systems and other Ethernet-connected devices in the market to cyber-attacks. This not only relates to protection against hackers with more or less criminal intent, but also against viruses and worms that can be introduced through a variety of channels—including USB sticks and CF cards. In contrast to the usual patches that can be installed in an office environment, controllers cannot be easily updated daily with the latest antivirus protection, even if it is available.&lt;br /&gt;
&lt;br /&gt;
As part of the validation of controllers used at CERN, at the test bench on Control System Security at CERN (TOCSSiC), 31 devices from seven manufacturers were systematically tested for penetration resistance with the vulnerability scanners Nessus and Netwox. Taking all different firmware versions into account, this led to 53 tests in total. In addition to interference through overload (Denial of Service, DoS), the tests also included provoked attacks on vulnerabilities in operating systems by infiltration of malicious software and ‘malicious’ manipulation of TCP/IP-based protocols. About one third of the tested devices failed these tests and has shown severe security problems.&lt;br /&gt;
&lt;br /&gt;
Approximately one third of the devices came from the Simatic S7 product series, some with an integrated Ethernet interface, some with separate communication processors, such as the CP 343-1 Lean for the S7-300 series.&lt;br /&gt;
&lt;br /&gt;
The poor test results led to a ‘very productive interaction with Siemens’ and ultimately made ‘Simatic controllers significantly more secure over the years; now they meet the stringent requirements at CERN,’ summarises Dr. Lüders.&lt;/blockquote&gt;Gadi Evron,&lt;br /&gt;
ge@linuxbox.org.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;&lt;/b&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/ToVP9qTPBtU/large-hadron-collider-nessus-and.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>0</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2010/01/large-hadron-collider-nessus-and.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-8257410077616370598</guid><pubDate>Sat, 23 Jan 2010 04:14:00 +0000</pubDate><atom:updated>2010-01-23T08:39:11.711+02:00</atom:updated><title>China's CNCERT response to Google</title><description>China responds to Google's accusations on its CNCERT web site, &lt;a href="http://www.china.com.cn/info/digi/2010-01/23/content_19293274.htm"&gt;here&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Johannes Ullrich just brought this to my attention on Facebook.&lt;br /&gt;
&lt;br /&gt;
In short, CNCERT wrote that China is the biggest victim of cyber attacks, and that Google lacks evidence to link the recent attacks to China as the perpetrator.&lt;br /&gt;
&lt;br /&gt;
Gadi Evron,&lt;br /&gt;
ge@linuxbox.org.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;&lt;/b&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/gjm36KkND8s/chinas-cncert-response-to-google.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>1</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2010/01/chinas-cncert-response-to-google.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-3968600065519603576</guid><pubDate>Sat, 16 Jan 2010 10:13:00 +0000</pubDate><atom:updated>2010-01-16T12:13:22.243+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">traffic</category><category domain="http://www.blogger.com/atom/ns#">interesting incidents</category><category domain="http://www.blogger.com/atom/ns#">advertising</category><category domain="http://www.blogger.com/atom/ns#">porn</category><category domain="http://www.blogger.com/atom/ns#">Russia</category><title>Traffic Video Ads Replaced with Porn</title><description>Fergie (Paul Ferguson, one of my favorite people in the world), posted &lt;a href="http://www.foxnews.com/scitech/2010/01/15/russian-hackers-jam-automobile-traffic-porn/"&gt;a news item&lt;/a&gt; to the funsec mailing list:&lt;blockquote&gt;Traffic jerked to a standstill as rubbernecking motorists ogled a pornographic clip posted by hackers on big-screen video billboards in Moscow, Russian news agencies reported Friday.&lt;br /&gt;
&lt;br /&gt;
The company that operates the billboards, Panno.ru, said hackers were behind a graphic sex video broadcast late Thursday night on two roadside screens along Moscow's Garden Ring Road, one of the city's busiest arteries.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.foxnews.com/scitech/2010/01/15/russian-hackers-jam-automobile-traffic-porn/"&gt;&lt;img src="http://www.foxnews.com/static/managed/img/Scitech/Panno_billboard_monster_397x224.jpg"&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
"This was an attack by hackers on the computers, as a result of which one of the commercial video clips was swapped for an indecent video," Panno.ru commercial director Viktor Laptev told RIA-Novosti.&lt;/blockquote&gt;Gadi Evron,&lt;br /&gt;
ge@linuxbox.org.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;&lt;/b&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/_dbcTqtObXQ/traffic-video-ads-replaced-with-porn.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>0</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2010/01/traffic-video-ads-replaced-with-porn.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-4754592140701335501</guid><pubDate>Fri, 15 Jan 2010 11:55:00 +0000</pubDate><atom:updated>2010-01-16T12:17:43.315+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Adobe</category><category domain="http://www.blogger.com/atom/ns#">corporate espionage</category><category domain="http://www.blogger.com/atom/ns#">Microsoft</category><category domain="http://www.blogger.com/atom/ns#">PDF</category><category domain="http://www.blogger.com/atom/ns#">ghostnet</category><category domain="http://www.blogger.com/atom/ns#">China</category><category domain="http://www.blogger.com/atom/ns#">Internet Explorer</category><category domain="http://www.blogger.com/atom/ns#">interesting incidents</category><category domain="http://www.blogger.com/atom/ns#">computer spying</category><category domain="http://www.blogger.com/atom/ns#">Google</category><category domain="http://www.blogger.com/atom/ns#">0day</category><category domain="http://www.blogger.com/atom/ns#">email vector</category><category domain="http://www.blogger.com/atom/ns#">targeted attacks</category><title>China Hacks Google, Etc.</title><description>Many news sources are reporting on how Google and other corporations were hacked by China.&lt;br /&gt;
&lt;br /&gt;
The reports, depending on vendor, blame either PDF files via email as the original perpetrator, or lay most of the blame on an Internet Explorer 0day.&lt;br /&gt;
&lt;br /&gt;
Unlike my colleagues (save for the ones reporting), I rather not discuss this too much before more data is available.&lt;br /&gt;
&lt;br /&gt;
Regardless of what really happened, which I hope we will know more on later, these things are clear:&lt;br /&gt;
&lt;br /&gt;
1. Unlike GhostNet, which showed an interesting attack, but unfortunately many of us jumped to conclusions without evidence that it was China behind them -- based on Ethos alone I'd like to think that when Google says China did it, they know. Although being a commercial company with their own agenda, I am saving final judgement.&lt;br /&gt;
&lt;br /&gt;
2. The 0day disclosed here shows a higher level of sophistication, as well as m.o. which has been shown to be used by China in the past.&lt;br /&gt;
&lt;br /&gt;
3. If this was China, which some recent talk seems to make ambiguous, but still likely; they would have more than just one weapon in their arsenal.&lt;br /&gt;
&lt;br /&gt;
4. This incident has brought cyber security once again to the awareness of the public, in a way no other incident since Georgia has succeeded, and to political awareness in a way no incident since Estonia has done.&lt;br /&gt;
&lt;br /&gt;
Gadi Evron,&lt;br /&gt;
ge@linuxbox.org.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;&lt;/b&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/RTVb5lviUbo/china-hacks-google-etc.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>0</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2010/01/china-hacks-google-etc.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-7113721357303083522</guid><pubDate>Thu, 14 Jan 2010 10:29:00 +0000</pubDate><atom:updated>2010-01-16T12:17:55.589+02:00</atom:updated><title>Online Pharmacy Scammer Speaks</title><description>Reddit has an interesting subsection called IAmA, AMAA -- I am a... Ask me absolutely anything -- in which different people with varying life stories open up and let people ask them questions. One of the most recent IAmA's is from a person who used to work as a fake doctor at an online pharmacy. A good read:&lt;br /&gt;
&lt;a href="http://www.reddit.com/r/IAmA/comments/apcv0/i_was_a_doctor_at_an_online_pharmacy_i_did_not/"&gt;http://www.reddit.com/r/IAmA/comments/apcv0/i_was_a_doctor_at_an_online_pharmacy_i_did_not/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
A few months a go a "legal" spammer spoke out on IAmA, as well:&lt;br /&gt;
&lt;a href="http://www.reddit.com/r/IAmA/comments/9xrn1/iama_person_who_sends_spam_email_for_a_living_ama/"&gt;http://www.reddit.com/r/IAmA/comments/9xrn1/iama_person_who_sends_spam_email_for_a_living_ama/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Enjoy,&lt;br /&gt;
Gadi Evron,&lt;br /&gt;
ge@linuxbox.org.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;&lt;/b&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/g_bpf1qUYIk/online-pharmacy-scammer-speak-out.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>1</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2010/01/online-pharmacy-scammer-speak-out.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-7050666047907244388</guid><pubDate>Tue, 12 Jan 2010 11:32:00 +0000</pubDate><atom:updated>2010-01-16T12:18:04.647+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">comics</category><category domain="http://www.blogger.com/atom/ns#">security theater</category><category domain="http://www.blogger.com/atom/ns#">Air travel security</category><category domain="http://www.blogger.com/atom/ns#">respect</category><category domain="http://www.blogger.com/atom/ns#">TSA</category><category domain="http://www.blogger.com/atom/ns#">comic strip</category><title>Getting back at the TSA</title><description>Many in the security community are continually annoyed with the TSA and air safety, mumbling security theater &lt;i&gt;this&lt;/i&gt; and idiots &lt;i&gt;that&lt;/i&gt;. Following the undies bomber incident, these mumbling turned into rumblings, and then into a "let's get back at the TSA" joking spree, which I was more than happy to jump ahead of.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.applegeeks.com/lite/index.php?aglitecomic=2010-01-08"&gt;&lt;img src="http://www.applegeeks.com/lite/strips/aglite561.jpg" alt="AppleGeeks Lite 561"&gt;&lt;/a&gt;&lt;br /&gt;
via &lt;a href="http://www.applegeeks.com/lite/index.php?aglitecomic=2010-01-08"&gt;AppleGeeks Lite 561&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
And indeed, folks on the funsec mailing list had some fun with it.&lt;br /&gt;
phester wrote:&lt;blockquote&gt;I've considered carrying a bag of dildoes when I fly. I imagine a conversation something like this;&lt;br /&gt;
&lt;br /&gt;
TSA: What's this?!?&lt;br /&gt;
&lt;br /&gt;
Me: A bunch of dildoes.&lt;br /&gt;
&lt;br /&gt;
TSA: Why are you carrying a bunch of dildoes?&lt;br /&gt;
&lt;br /&gt;
Me: It makes me feel safe.&lt;br /&gt;
&lt;br /&gt;
TSA: How does a bunch of dildoes make you feel safe?&lt;br /&gt;
&lt;br /&gt;
Me: I've been asking the same thing since they created the TSA.&lt;br /&gt;
&lt;/blockquote&gt;This was indeed fun, and we had a good laugh. Erik Harrison replied with the often quoted TSA joke:&lt;blockquote&gt;TSA: "Nine times out of ten, it's an electric razor but, every once and a while, it's a dildo. Of course, it's company policy never to imply ownership in the event of a dildo. We have to use the indefinite article. A dildo, never your dildo."&lt;/blockquote&gt;After a bit more fun, I responded seriously:&lt;blockquote&gt;If it was me, I would say it was my dildo every time. It would be interesting to see their faces, but more importantly, if it's not mine, it might be a terrorist who put it in my bag. Bad idea: an exploded bag, a cavity search and 3 hours to 3 days later...&lt;/blockquote&gt;But more than the TSA not having a sense of humour, this is really about respect, and about understanding that they can take no chances with you not being serious:&lt;blockquote&gt;It's great to joke about, but not to practice as a joke. As I said earlier, bad idea.&lt;br /&gt;
&lt;br /&gt;
Don't mess with:&lt;br /&gt;
1. People trying to do their jobs.&lt;br /&gt;
2. People who are on alert for criminals and terrorists.&lt;br /&gt;
3. People who have the power to arrest you.&lt;br /&gt;
4. People who have guns to do their job.&lt;br /&gt;
and:&lt;br /&gt;
5. People who are forced to check you completely with the mere mention of a joke, as it might not be a joke.&lt;br /&gt;
&lt;/blockquote&gt;All-in-all, we had a good time playing with this, but we should all keep in mind that regardless of what we may think of the TSA and others around the world, some jokes are just not worth the price of a cavity search -- or at the very least 10 more minutes in line.&lt;br /&gt;
&lt;br /&gt;
Gadi Evron,&lt;br /&gt;
ge@linuxbox.org.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;&lt;/b&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/3LywLA9rITc/getting-back-at-tsa.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>0</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2010/01/getting-back-at-tsa.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-4545193873287531348</guid><pubDate>Tue, 12 Jan 2010 09:59:00 +0000</pubDate><atom:updated>2010-01-16T12:18:19.711+02:00</atom:updated><title>New subject specific blog from me: Pathos Daily</title><description>I have been interested in human communication for a while now, be it debate and rhetoric on the one hand, or social/non-verbal psychology and persuasion on the other. I often come across links of interest, and share them with friends. Or have thoughts on the subject and share them here.&lt;br /&gt;
&lt;br /&gt;
I decided that with the effort of emailing out links, I can also easily blog them. And so, I started a new blog on this subject matter, to specifically post links to interesting news stories and comic strips.&lt;br /&gt;
&lt;br /&gt;
It is called Pathos Daily, and you can read it at:&lt;br /&gt;
&lt;a href="http://pathosdaily.blogspot.com/"&gt;http://pathosdaily.blogspot.com/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Gadi Evron,&lt;br /&gt;
ge@linuxbox.org.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;&lt;/b&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/rZviHVEyieY/new-subject-specific-blog-from-me.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>0</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2010/01/new-subject-specific-blog-from-me.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-163229168041333200</guid><pubDate>Sun, 10 Jan 2010 13:30:00 +0000</pubDate><atom:updated>2010-01-16T12:18:31.140+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">social engineering</category><category domain="http://www.blogger.com/atom/ns#">Omegle</category><category domain="http://www.blogger.com/atom/ns#">funny</category><category domain="http://www.blogger.com/atom/ns#">picture</category><title>Funny! Mario &amp; Luigi on Omegle: Password Social Engineering</title><description>This is a &lt;a href="http://i.imgur.com/vf09X.jpg"&gt;funny picture&lt;/a&gt; describing a chat on Omegle, which not only made me ROFL, but also teaches social engineering!&lt;br /&gt;
&lt;br /&gt;
Sometimes learning about security and hacking can come from odd sources. :)&lt;br /&gt;
&lt;br /&gt;
&lt;img src="http://i.imgur.com/vf09X.jpg" height=300 width=450&gt;&lt;br /&gt;
&lt;br /&gt;
Gadi Evron,&lt;br /&gt;
ge@linuxbox.org&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;&lt;/b&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/npUqU7QkZRY/funny-mario-luigi-on-omegle-password.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>0</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2010/01/funny-mario-luigi-on-omegle-password.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-8149141617593642675</guid><pubDate>Fri, 08 Jan 2010 18:45:00 +0000</pubDate><atom:updated>2010-01-16T12:18:41.214+02:00</atom:updated><title>Putting Trojan Horses on Chips!</title><description>This is a story about a contest to put &lt;a href="http://spectrum.ieee.org/semiconductors/design/creative-winners-in-hardware-trojan-contest/"&gt;Trojan horses on chips&lt;/a&gt;. Very interesting from an hardware hacking perspective, as well as a trusting trust and supply chain security perspective.&lt;blockquote&gt;5 January 2010—In November, engineering students from five top universities gathered at the Polytechnic Institute of NYU, in Brooklyn, N.Y., for the Embedded Systems Challenge. The aim was to test new attacks and defenses against an underappreciated breed of Trojan horse—embedded malware built into integrated circuits.&lt;br /&gt;
&lt;br /&gt;
The winning team’s results, set to appear in journals and at conference proceedings in 2010, reveal how vulnerable many systems are to "chip attacks" The contest also demonstrated the high degree of technical sophistication required for these attacks, making it more likely that attackers will pursue specialized applications, such as sensitive military equipment or high-security financial computers. Attacking Dad’s new Windows 7 PC probably isn’t worth the extreme investment of time and money—especially when cheaper and quicker phishing and software-based malware attacks still work all too well.&lt;/blockquote&gt;Definitely worth a read!&lt;br /&gt;
&lt;br /&gt;
Gadi Evron,&lt;br /&gt;
ge@linuxbox.org.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;&lt;/b&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/JbZVNDIhJMs/putting-trojan-horses-on-chips.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>0</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2010/01/putting-trojan-horses-on-chips.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-3973451323087489302</guid><pubDate>Wed, 30 Dec 2009 01:18:00 +0000</pubDate><atom:updated>2010-01-16T12:18:55.471+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">security theater</category><category domain="http://www.blogger.com/atom/ns#">Air travel security</category><category domain="http://www.blogger.com/atom/ns#">TSA</category><title>Air Travel Security: Practical Industry Suggestions From Us</title><description>&lt;div&gt;I am just a security guy, as are many others who will read this. Perhaps it is time us "simple" security guys got together and write some recommendations for air travel security? Get our voice out there as an organized professional group, which can in turn lobby for our professional recommendations.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;Then we can edit them, vote on them, and submit them to the government for consideration in the upcoming brouhaha of committee discussions.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;&lt;b&gt;Here are mine&lt;/b&gt;, just to get the ball rolling:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;u&gt;Strategic&lt;/u&gt;:&lt;br /&gt;
0. Review useless technologies which are there for beyond the security  theater purposes (which do matter) and start eliminating bad projects. Your  purpose in security theater was to maintain air travel and keep people  calm, right?&lt;br /&gt;
1. An investment in better intelligence (no brainer)&lt;br /&gt;
2. Create a "always strip-search" list rather than just "no fly" list., so that lesser threats can be dealt with responsibly without compromising the usefulness of the no fly one. I am sure they already have one, but they should layer this rather than deal with extremes.&lt;br /&gt;
3. Hire better agents (education/ability... better pay). Should be a small  increase per person, but it will cost a lot in total. Then again, how  much do all the current b/s additions cost?&lt;br /&gt;
4. Yours?&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;Tactical&lt;/u&gt;:&lt;br /&gt;
1. Copy Israel's air security training manual for agents. Israel's  tactics may not be able to scale to the US level, but the training can.&lt;br /&gt;
2. Stop panicking and alienating people, so they are calmer and you can  more easily identify suspicious people, so that this new training is  more effective. Heck, do it anyway. Send TSA agents to some workshop on  being nice. Or make shifts shorter.&lt;br /&gt;
3. Put "human sniffer" walk-through machines in every airport, for  international flights.&lt;br /&gt;
4. Buy the better brand of baggage screening &amp;amp;&amp;amp; X-ray machines for  international flights (remember the liquid issue with checking for  explosives in the last scare?) &lt;div&gt;5. Some people suggested to start profiling and leave PC behind, but I'm not touching that.&lt;br /&gt;
6. Yours?&lt;br /&gt;
&lt;br /&gt;
Some of these are very high cost. Some of these are (on scale) very low cost.&lt;br /&gt;
Some of these should replace other high-cost idiocies, such as creating  two new mega-airports, which is sound security-wise, but will only add  an hop to the threat to jump over, with the same silly tests in yet another airport, rather  than add a filter.  Or full-body scans which will be of limited help, and insult us all.&lt;br /&gt;
&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;What are yours? Join the discussion!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;Gadi Evron,&lt;/div&gt;&lt;div&gt;ge@linuxbox.org.&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;
&lt;b&gt;&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;&lt;/b&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/PPlR55y65uU/air-travel-security-practical-industry.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>5</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2009/12/air-travel-security-practical-industry.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-8133755212082963224</guid><pubDate>Fri, 18 Dec 2009 17:28:00 +0000</pubDate><atom:updated>2010-01-16T12:19:09.972+02:00</atom:updated><title>Spymaster sees Israel as world cyberwar leader</title><description>&lt;span id="articleText"&gt;&lt;p&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;p&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;blockquote&gt;&lt;p&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;p&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;/blockquote&gt;&lt;p&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;/blockquote&gt;Reuters &lt;a href="http://www.reuters.com/article/idUSTRE5BE30920091215"&gt;reports&lt;/a&gt; from the Institute for National Security Studies (INSS), a Tel Aviv University think tank, where Major General Amos Yadlin, IDF chief of military intelligence, spoke:&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;In a policy address, Major-General Amos Yadlin, chief of military intelligence, listed vulnerability to hacking among national threats that also included the Iranian nuclear project, Syria and Islamist guerrillas along the Jewish state's borders.&lt;/p&gt;&lt;span id="midArticle_3"&gt;&lt;/span&gt;&lt;p&gt;Yadlin said Israeli armed forces had the means to provide network security and launch cyber attacks of their own.&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;He further said, as mentioned in &lt;a href="http://www.pc.co.il/?p=23806"&gt;this&lt;/a&gt; Israeli publication, that other countries, such as the United States and Great Britain, are establishing units for cyber defense, and that Israel has soldiers and officers on the job.&lt;/p&gt;&lt;p&gt;In fact, just today I heard a lecture by the director of the CIA who, as is general United States policy, places cyber security on the map when discussing issues such as proliferation of nuclear weapons and international terrorism.&lt;/p&gt;&lt;p&gt;HaAretz, an Israeli newspaper, &lt;a href="http://www.haaretz.co.il/captain/spages/1135362.html"&gt;quotes &lt;/a&gt;Major-General Yaldin as saying:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;blockquote&gt;"Fighting in the cyber dimension is as significant as the introduction of fighting in the aerial dimension in the early 20th century." (my translation)&lt;/blockquote&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;If this statement is to be believed, Israel is active in cyberspace. And yet, why would Israel admit that, regardless of if it really happens?&lt;/p&gt;&lt;p&gt;One option is that Israel decided it needs to show that its military is on par with other militaries around the world.&lt;/p&gt;&lt;p&gt;&lt;span class="Apple-style-span"   style="  line-height: 22px; font-family:arial, helvetica, sans;font-size:14px;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;blockquote&gt;"Preserving the lead in this field is especially important given the dizzying pace of change," Yadlin said.&lt;/blockquote&gt;&lt;/span&gt;&lt;div&gt;&lt;span id="articleText"&gt;&lt;p&gt;On the surface, disclosing cyber space activity, which your enemies can develop as well, or push to develop more of, seems silly.&lt;/p&gt;&lt;p&gt;After all, Major-General Yadlin said:&lt;/p&gt;&lt;p&gt;&lt;span id="articleText"&gt;&lt;/span&gt;&lt;/p&gt;&lt;blockquote&gt;"Cyberspace grants small countries and individuals a power that was heretofore the preserve of great states,"&lt;/blockquote&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;As Israel, much like the Western world, is very advanced technologically, it is more reliant on computers than many of its enemies and neighbors, and is therefore more at risk from potential cyber attacks. With attacks against Israel's internet presence these last few years, it may not be a silly idea after all.&lt;/p&gt;&lt;p&gt;With the world becoming more aware of threats to computer systems, investment in cyber security rising and more and more security incidents being disclosed; countries around the globe invest in cyber capabilities. Indeed, Israel too, which has been under internet attacks for years, needs to buckle up and do more to combat the threats.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Major-General Yadlin also mentioned cyber attacks fit well with Israel's doctrine for military offensives (mistranslated below as defense). This bit is tricky, and I will try and read between the lines.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;blockquote&gt;"I would like to point out in this esteemed forum that the cyberwarfare field fits well with the state of Israel's defense doctrine,"&lt;/blockquote&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;While Major-General Yadlin in all probability meant something along the lines of being bold and staying ahead of the curve, as in the same sentence he also spoke of Israeli youth and innovation, mentioning how Israel is often referred to as the "start-up country":&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;blockquote&gt;"This is an enterprise that is entirely blue and white (Israeli) and does not rely on foreign assistance or technology. It is a field that is very well known to young Israelis, in a country that was recently crowned a 'start-up nation'."&lt;/blockquote&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;It is possible, although unlikely, that he meant to indeed discuss Israel's defense doctrine, thus possibly speaking about deterrence in cyberspace.&lt;/p&gt;&lt;p&gt;Deterrence is an integral part of Israel's defense doctrine, with the goal, in broad lines, of widening the window between inevitable Arab attacks by a strong response, some would say a disproportionate one, which will score a quick and decisive victory. Hopefully deterring them from attacking again. This strategy has roots in Israel's history all the way back to Ben Gurion's time and the formation of Israel.&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Deterrence on the Internet, however, is mostly nonsense. This due to inability to identify who it is actually attacking you, and then if somehow successful, if it is really them or if their computer has been taken over by yet another attacker. Is someone trying to frame another as your attacker? Is your attacker even a nation-state to begin with, rather than an organization that doesn't care about retaliation?&lt;/p&gt;&lt;p&gt;On the internet, you may know who your enemies are rivals are, but you may never find out who is attacking you. The Internet is perfect for plausible deniability.&lt;/p&gt;&lt;p&gt;If this was the thinking behind the announcement, which I'd like to think is not the case, then the strategy was copied from the United States where this silliness has been going on now for a few years. The US strategic experts have been using Mutual Deterrence (or MAD, Mutually Assured Destruction) for over 70 years now, and feel comfortable with it. Therefore, when they needed to tackle the cyber realm, they immediately started pushing for a deterrence strategy even though cyber experts have been warning about it continually.&lt;/p&gt;&lt;p&gt;Deterrence for the most part, doesn't work online. It is my hope Israel does not repeat the American mistake on this matter and that I am right, and Major-General Yaldin was only speaking of Israel's spirit, where commanding officers lead the charge rather than wait behind.&lt;/p&gt;&lt;p&gt;From a completely different perspective, cyber warfare has been recognized as a strategic weapon on par with weapons of mass destruction for at least two decades. Israel does not admit strategic capabilities such as Nuclear Weapons, if it has them. Should it admit cyber capabilities?&lt;/p&gt;&lt;p&gt;&lt;span id="articleText"&gt;&lt;/span&gt;&lt;/p&gt;&lt;blockquote&gt;"The potential exists here for applying force ... capable of compromising the military controls and the economic functions of countries, without the limitations of range and location."&lt;/blockquote&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;While cyberspace is certainly strategic, the analogy to nuclear weapons is relatively weak.&lt;/p&gt;&lt;p&gt;There are obvious differences between the nuclear world and the cyber world, such as with tactical cyber uses of a very targeted nature -- without collateral damage, and in international law governing the proliferation of nuclear arms, while the cyber realm is in its infancy. In fact, the United States, Russia and the United Nations arms control committee are as I write these lines engaged in early discussions on securing cyberspace, and limiting military use of this realm.&lt;/p&gt;&lt;p&gt;When I first heard of the speech by Major-General Yaldin, I was highly disappointed with Israel for taking this route of public disclosure. Now, I am not so sure.&lt;/p&gt;&lt;p&gt;Disclosing that Israel is ready to defend itself and potentially engage its enemies in cyberspace right along-side the physical world, certainly has merit considering recent world events such as the attacks against Estonia and Georgia. I am just left wondering if this indeed discloses a real capability, or is just public relations.&lt;/p&gt;&lt;p&gt;I can personally attest from my years of defending Israel's internet, that Israel is under constant attack in cyberspace, and this intensifies whenever political tensions mount.&lt;/p&gt;&lt;p&gt;"At times it would seem," said Major-General Yaldin, "that our enemies would like to give a special award to Western companies whose products can be bought off-the-shelf at a reasonable price." (my translation)&lt;/p&gt;&lt;p&gt;Regardless, putting cyber security on the agenda along-side with Iranian nuclear weapons, Syria and Islamist guerrillas, is a step in the right direction to defending against the threats of cyberspace.&lt;/p&gt;&lt;p&gt;Gadi Evron,&lt;br /&gt;
ge@linuxbox.org.&lt;/p&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;b&gt;&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;&lt;/b&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/Ztp3gUpI1K8/spymaster-sees-israel-as-world-cyberwar.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>3</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2009/12/spymaster-sees-israel-as-world-cyberwar.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-1441418050390394407</guid><pubDate>Thu, 26 Nov 2009 16:27:00 +0000</pubDate><atom:updated>2010-01-16T12:19:18.788+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">civil society</category><category domain="http://www.blogger.com/atom/ns#">law</category><category domain="http://www.blogger.com/atom/ns#">debating</category><category domain="http://www.blogger.com/atom/ns#">debate</category><category domain="http://www.blogger.com/atom/ns#">climate change</category><category domain="http://www.blogger.com/atom/ns#">mailing list</category><category domain="http://www.blogger.com/atom/ns#">civil disobidience</category><category domain="http://www.blogger.com/atom/ns#">privacy</category><category domain="http://www.blogger.com/atom/ns#">hacking</category><title>Was the ClimateGate Hacker Justified? Join the Debate!</title><description>A few days ago a story broke where someone hacked into a global warming research institute and stole all emails from the past 10 years, proving a conspiracy.&lt;br /&gt;
&lt;br /&gt;
In the vast amount of emails stolen, some emails were also found with clear-cut lies, showing how some scientists conspired to deceive in scientific research about data that did not fit their agenda of proving global warming.&lt;br /&gt;
&lt;br /&gt;
I am opening the subject for debate on &lt;a href="http://whitestar.linuxbox.org/mailman/listinfo/debate"&gt;the debate mailing list&lt;/a&gt;. It is a fascinating topic covering several subjects such as 'does the end justify the means?', 'irresponsible disclosure of personal data', 'is it justifiable to break the law?' and 'civil disobedience and the hackers' role in keeping society honest'.&lt;br /&gt;
&lt;br /&gt;
Here are some possible questions to get the wheels rolling:&lt;br /&gt;
&lt;br /&gt;
- Is the action taken by the hacker legal, ethical, and/or moral? Was the action justifiable?&lt;br /&gt;
&lt;br /&gt;
- Do you believe the harm done as a result is justified for the good (disclosure) that came out of it?&lt;br /&gt;
&lt;br /&gt;
- Can this be treated as civil disobedience?&lt;br /&gt;
&lt;br /&gt;
For background, check out this story:&lt;br /&gt;
&lt;a href="http://www.examiner.com/x-25061-Climate-Change-Examiner~y2009m11d20-ClimateGate--Climate-centers-server-hacked-revealing-documents-and-emails"&gt;http://www.examiner.com/x-25061-Climate-Change-Examiner~y2009m11d20-ClimateGate--Climate-centers-server-hacked-revealing-documents-and-emails&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Another source:&lt;br /&gt;
&lt;a href="http://noconsensus.wordpress.com/2009/11/19/leaked-foia-files-62-mb-of-gold/
"&gt;http://noconsensus.wordpress.com/2009/11/19/leaked-foia-files-62-mb-of-gold/&lt;br /&gt;
&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Join the debate mailing list, now! :)&lt;br /&gt;
&lt;a href="http://whitestar.linuxbox.org/mailman/listinfo/debate"&gt;http://whitestar.linuxbox.org/mailman/listinfo/debate&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Please state your opinions openly, and let's discuss!&lt;br /&gt;
&lt;br /&gt;
Gadi Evron,&lt;br /&gt;
ge@linuxbox.org.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;&lt;/b&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/le_ZqQNN5No/was-climategate-hacker-justified-join.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>7</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2009/11/was-climategate-hacker-justified-join.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-22537170.post-4768670999524704947</guid><pubDate>Wed, 18 Nov 2009 17:16:00 +0000</pubDate><atom:updated>2010-01-16T12:19:47.244+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">internet</category><category domain="http://www.blogger.com/atom/ns#">critical infrastructure</category><category domain="http://www.blogger.com/atom/ns#">mailing list</category><category domain="http://www.blogger.com/atom/ns#">isotf</category><title>Announcement: Critical Internet Infrastructure WG is now open to public participation</title><description>ISOTF Critical Internet Infrastructure WG is now open to public participation.&lt;br /&gt;
&lt;br /&gt;
The group holds top experts on internet technology, critical infrastructure, and internet governance, from around the globe.&lt;br /&gt;
&lt;br /&gt;
Together, we discuss definitions, problems, challenges and solutions in securing and assuring the reliability of the global internet infrastructure, which is critical infrastructure for a growing number of nations, corporations and indeed, individuals -- world wide.&lt;br /&gt;
&lt;br /&gt;
The group started as a closed and private forum, to discuss technical and operational risks, as other venues limited discussion of critical internet resources to politically charged subjects such ascontrol of ICANN and ARIN, thus overshadowing other important aspects.&lt;br /&gt;
&lt;br /&gt;
As of November 18th 2009, the list is open for public access, to advance public awareness of the issues, and bring new talent on board.&lt;br /&gt;
&lt;br /&gt;
The group is hosted by the ISOTF, but is governed by members.&lt;br /&gt;
&lt;br /&gt;
Note: SCADA, network operations, and other related issues should be discussed in the appropriate forums, elsewhere. This group deals with the internet.&lt;br /&gt;
&lt;br /&gt;
To subscribe:&lt;br /&gt;
&lt;a href="http://isotf.org/mailman/listinfo/cii"&gt;http://isotf.org/mailman/listinfo/cii&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Gadi Evron for ISOTF-CII-WG.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;&lt;a href="http://twitter.com/gadievron"&gt;Follow me on twitter! http://twitter.com/gadievron&lt;/a&gt;&lt;/b&gt;</description><link>http://feedproxy.google.com/~r/MusingsOfAnOver-grownDwarf/~3/pz5GdyJuJsg/announcement-critical-internet.html</link><author>noreply@blogger.com (Gadi Evron)</author><thr:total>0</thr:total><feedburner:origLink>http://gadievron.blogspot.com/2009/11/announcement-critical-internet.html</feedburner:origLink></item></channel></rss>
