<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:thr="http://purl.org/syndication/thread/1.0" xml:lang="en" xml:base="http://www.labyrinth.org/wp1/wp-atom.php">
	<title type="text">Scott... Sit down and shut up!</title>
	<subtitle type="text">This could be bad in so many ways...</subtitle>

	<updated>2010-09-11T05:07:09Z</updated>

	<link rel="alternate" type="text/html" href="http://www.labyrinth.org/wp1" />
	<id>http://www.labyrinth.org/wp1/?feed=atom</id>
	

	<generator uri="http://wordpress.org/" version="3.2.1">WordPress</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/ScottSitDownAndShutUp" /><feedburner:info xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" uri="scottsitdownandshutup" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><link rel="license" type="text/html" href="http://creativecommons.org/licenses/by/2.0/" /><entry>
		<author>
			<name>scott</name>
						<uri>http://www.labyrinth.org/homepages/scott/home.html</uri>
					</author>
		<title type="html"><![CDATA[Incontinence: A bigger threat than malware!]]></title>
		<link rel="alternate" type="text/html" href="http://www.labyrinth.org/wp1/?p=459" />
		<id>http://www.labyrinth.org/wp1/?p=459</id>
		<updated>2010-06-15T15:29:19Z</updated>
		<published>2010-06-15T15:29:15Z</published>
		<category scheme="http://www.labyrinth.org/wp1" term="Security" />		<summary type="html"><![CDATA[Sitting on the airplane the other day and I was bored out of my mind so I picked up the in-flight magazine (US-Air) and started thumbing through to pass the time when I found an interesting article about information security. One of the conclusions astounded me. Based on this, I am left with the conclusion [...]]]></summary>
		<content type="html" xml:base="http://www.labyrinth.org/wp1/?p=459"><![CDATA[<p>Sitting on the airplane the other day and I was bored out of my mind so I picked up the in-flight magazine (US-Air) and started thumbing through to pass the time when I found an interesting article about information security.  One of the conclusions astounded me.</p>
<p><img src="http://www.labyrinth.org/wp1/wp-content/uploads/2010/06/IMG_0278-2.jpg" alt="IMG_0278-2.jpg" border="0" width="384" height="512" /></p>
<p>Based on this, I am left with the conclusion that diapers might hold the key to success.</p>
<p><img src="http://www.labyrinth.org/wp1/wp-content/uploads/2010/06/image.png" alt="image.png" border="0" width="120" height="112" /></p>
]]></content>
		<link rel="replies" type="text/html" href="http://www.labyrinth.org/wp1/?p=459#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://www.labyrinth.org/wp1/?feed=atom&amp;p=459" thr:count="0" />
		<thr:total>0</thr:total>
	</entry>
		<entry>
		<author>
			<name>scott</name>
						<uri>http://www.labyrinth.org/homepages/scott/home.html</uri>
					</author>
		<title type="html"><![CDATA[Windows 7 Less Vulnerable Without Admin Rights]]></title>
		<link rel="alternate" type="text/html" href="http://www.labyrinth.org/wp1/?p=454" />
		<id>http://www.labyrinth.org/wp1/?p=454</id>
		<updated>2010-04-01T23:11:36Z</updated>
		<published>2010-04-01T23:11:33Z</published>
		<category scheme="http://www.labyrinth.org/wp1" term="Operating Systems" />		<summary type="html"><![CDATA[Is anyone surprised here? Windows 7 Less Vulnerable Without Admin Rights: &#8220;Most Windows 7 vulnerabilities can be mitigated by administrative rights limitations, report from BeyondTrust finds&#8221; (Via DarkReading &#8211; All Stories.)]]></summary>
		<content type="html" xml:base="http://www.labyrinth.org/wp1/?p=454"><![CDATA[<p>Is anyone surprised here?  </p>
<p><a href="http://www.darkreading.com/insiderthreat/security/app-security/showArticle.jhtml?articleID=224200601&#038;cid=RSSfeed">Windows 7 Less Vulnerable Without Admin Rights</a>: &#8220;Most Windows 7 vulnerabilities can be mitigated by administrative rights limitations, report from BeyondTrust finds&#8221;</p>
<p>(Via <a href="http://www.darkreading.com/">DarkReading &#8211; All Stories</a>.)</p>
]]></content>
		<link rel="replies" type="text/html" href="http://www.labyrinth.org/wp1/?p=454#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://www.labyrinth.org/wp1/?feed=atom&amp;p=454" thr:count="0" />
		<thr:total>0</thr:total>
	</entry>
		<entry>
		<author>
			<name>scott</name>
						<uri>http://www.labyrinth.org/homepages/scott/home.html</uri>
					</author>
		<title type="html"><![CDATA[Cool Fly By Video&#8230;]]></title>
		<link rel="alternate" type="text/html" href="http://www.labyrinth.org/wp1/?p=452" />
		<id>http://www.labyrinth.org/wp1/?p=452</id>
		<updated>2010-03-31T16:31:07Z</updated>
		<published>2010-03-31T16:31:03Z</published>
		<category scheme="http://www.labyrinth.org/wp1" term="General" /><category scheme="http://www.labyrinth.org/wp1" term="Government" />		<summary type="html"><![CDATA[I found this to be mildly entertaining&#8230;]]></summary>
		<content type="html" xml:base="http://www.labyrinth.org/wp1/?p=452"><![CDATA[<p>I found this to be mildly entertaining&#8230;</p>
<p><object width="480" height="385"><param name="movie" value="http://www.youtube.com/v/7Dr2ZB36p9Y&#038;hl=en_US&#038;fs=1&#038;"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/7Dr2ZB36p9Y&#038;hl=en_US&#038;fs=1&#038;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="320" height="200"></embed></object></p>
]]></content>
		<link rel="replies" type="text/html" href="http://www.labyrinth.org/wp1/?p=452#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://www.labyrinth.org/wp1/?feed=atom&amp;p=452" thr:count="0" />
		<thr:total>0</thr:total>
	</entry>
		<entry>
		<author>
			<name>scott</name>
						<uri>http://www.labyrinth.org/homepages/scott/home.html</uri>
					</author>
		<title type="html"><![CDATA[SCO vs. Novell&#8230; SCO 0 / Novell +1]]></title>
		<link rel="alternate" type="text/html" href="http://www.labyrinth.org/wp1/?p=450" />
		<id>http://www.labyrinth.org/wp1/?p=450</id>
		<updated>2010-03-31T16:23:24Z</updated>
		<published>2010-03-31T16:23:21Z</published>
		<category scheme="http://www.labyrinth.org/wp1" term="Operating Systems" /><category scheme="http://www.labyrinth.org/wp1" term="Technology" />		<summary type="html"><![CDATA[Stick a fork in SCO&#8230; they are cooked! http://www.novell.com/prblogs/?p=2153 Decision in the SCO Group vs. Novell Jury trial March 30th, 2010 by Ian Bruce Today, the jury in the District Court of Utah trial between SCO Group and Novell issued a verdict. Novell is very pleased with the jury’s decision confirming Novell’s ownership of the [...]]]></summary>
		<content type="html" xml:base="http://www.labyrinth.org/wp1/?p=450"><![CDATA[<p>Stick a fork in SCO&#8230; they are cooked!</p>
<p><a href="http://www.novell.com/prblogs/?p=2153">http://www.novell.com/prblogs/?p=2153</a></p>
<p>Decision in the SCO Group vs. Novell Jury trial</p>
<p>March 30th, 2010 by Ian Bruce </p>
<p>Today, the jury in the District Court of Utah trial between SCO Group and Novell issued a verdict.</p>
<p>Novell is very pleased with the jury’s decision confirming Novell’s ownership of the Unix copyrights, which SCO had asserted to own in its attack on Linux. Novell remains committed to promoting Linux, including by defending Linux on the intellectual property front.</p>
<p>This decision is good news for Novell, for Linux, and for the open source community.</p>
]]></content>
		<link rel="replies" type="text/html" href="http://www.labyrinth.org/wp1/?p=450#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://www.labyrinth.org/wp1/?feed=atom&amp;p=450" thr:count="0" />
		<thr:total>0</thr:total>
	</entry>
		<entry>
		<author>
			<name>scott</name>
						<uri>http://www.labyrinth.org/homepages/scott/home.html</uri>
					</author>
		<title type="html"><![CDATA[The Biggest Cloud Provider]]></title>
		<link rel="alternate" type="text/html" href="http://www.labyrinth.org/wp1/?p=448" />
		<id>http://www.labyrinth.org/wp1/?p=448</id>
		<updated>2010-03-23T14:45:14Z</updated>
		<published>2010-03-23T14:45:06Z</published>
		<category scheme="http://www.labyrinth.org/wp1" term="Networks" /><category scheme="http://www.labyrinth.org/wp1" term="Security" />		<summary type="html"><![CDATA[Network World has an interesting article on cloud providers. Turns out, the largest cloud services provider is, in fact, the criminals, and botnets. http://www.networkworld.com/community/node/58829]]></summary>
		<content type="html" xml:base="http://www.labyrinth.org/wp1/?p=448"><![CDATA[<p>Network World has an interesting article on cloud providers.  Turns out, the largest cloud services provider is, in fact, the criminals, and botnets.</p>
<p><a href="http://www.networkworld.com/community/node/58829">http://www.networkworld.com/community/node/58829</a></p>
]]></content>
		<link rel="replies" type="text/html" href="http://www.labyrinth.org/wp1/?p=448#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://www.labyrinth.org/wp1/?feed=atom&amp;p=448" thr:count="0" />
		<thr:total>0</thr:total>
	</entry>
		<entry>
		<author>
			<name>scott</name>
						<uri>http://www.labyrinth.org/homepages/scott/home.html</uri>
					</author>
		<title type="html"><![CDATA[DDoS Againt Aussie Government Websites]]></title>
		<link rel="alternate" type="text/html" href="http://www.labyrinth.org/wp1/?p=443" />
		<id>http://www.labyrinth.org/wp1/?p=443</id>
		<updated>2010-02-16T16:51:36Z</updated>
		<published>2010-02-16T16:03:15Z</published>
		<category scheme="http://www.labyrinth.org/wp1" term="Government" /><category scheme="http://www.labyrinth.org/wp1" term="Security" /><category scheme="http://www.labyrinth.org/wp1" term="Technology" />		<summary type="html"><![CDATA[What a great name for an anti-government operation&#8230; Anonymous Unfurls ‘Operation Titstorm’: &#8221; Several Australian government websites were slowly recovering Wednesday hours after the online prankster group Anonymous unleashed a massive distributed denial-of-service attack to protest the country’s evolution toward internet censorship. The group, which previously brought down Scientology’s websites has also undertaken a host [...]]]></summary>
		<content type="html" xml:base="http://www.labyrinth.org/wp1/?p=443"><![CDATA[<p>What a great name for an anti-government operation&#8230;</p>
<p><a href="http://www.wired.com/threatlevel/2010/02/anonymous-unfurls-operation-titstorm/#comments">Anonymous Unfurls ‘Operation Titstorm’</a>: &#8221;</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="392" height="309" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/eEc80U46hIQ&amp;hl=en_US&amp;fs=1&amp;" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="392" height="309" src="http://www.youtube.com/v/eEc80U46hIQ&amp;hl=en_US&amp;fs=1&amp;" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p>Several Australian government websites were slowly recovering Wednesday hours after the online prankster group Anonymous unleashed a massive distributed denial-of-service attack to protest the country’s evolution toward internet censorship.</p>
<p>The group, which previously <a href="http://www.wired.com/threatlevel/2010/01/guilty-plea-in-scientology-ddos-attack/">brought down Scientology’s websites</a> has also undertaken a host of other online pranks. It dubbed the new attack ‘Operation Titstorm’ to protest the government’s move to require the filtering of pornography that uses adult actors if they appear underage. Violent material targeting children is also to be censored.</p>
<p><a href="http://blog.wired.com/27bstroke6/2008/09/palin-hacker-gr.html">Anonymous’ past targets</a> include uncool virtual worlds, an epilepsy message board and a Neo-Nazi webcaster. The group sent Australian media e-mail messages <a href="http://www.smh.com.au/technology/technology-news/operation-titstorm-hackers-bring-down-government-websites-20100210-nqku.html">warning of the attack</a>, the <cite>Sydney Morning Herald</cite> said.</p>
<p><a href="http://www.wired.com/images_blogs/threatlevel/2010/02/picture-27.png"><img class="alignright size-full wp-image-13551" title="picture-27" src="http://www.wired.com/images_blogs/threatlevel/2010/02/picture-27.png" alt="picture-27" width="350" height="216" /></a></p>
<p>‘No government should have the right to refuse its citizens access to information solely because they perceive it to be unwanted,’ the e-mail said. ‘The Australian government will learn that one does not mess with our porn. No one messes with our access to perfectly legal (or illegal) content for any reason.’</p>
<p>At one point Thursday, parliament’s website was felled after getting 7.5 million hits a second. Usually, it receives a few hundred a second.</p>
<p>Flyers seeking recruits for Wednesday’s barrage said the group would follow the service attack with ‘a shitstorm of porn e-mail, fax spam, black faxes and prank phone calls to government offices.’</p>
<p>(Via <a href="http://www.wired.com/threatlevel">Wired: Threat Level</a>.)</p>
]]></content>
		<link rel="replies" type="text/html" href="http://www.labyrinth.org/wp1/?p=443#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://www.labyrinth.org/wp1/?feed=atom&amp;p=443" thr:count="0" />
		<thr:total>0</thr:total>
	</entry>
		<entry>
		<author>
			<name>scott</name>
						<uri>http://www.labyrinth.org/homepages/scott/home.html</uri>
					</author>
		<title type="html"><![CDATA[China-Google Roundup or can we call this GhostNet 2 yet???]]></title>
		<link rel="alternate" type="text/html" href="http://www.labyrinth.org/wp1/?p=441" />
		<id>http://www.labyrinth.org/wp1/?p=441</id>
		<updated>2010-01-13T23:10:16Z</updated>
		<published>2010-01-13T23:10:11Z</published>
		<category scheme="http://www.labyrinth.org/wp1" term="Economic" /><category scheme="http://www.labyrinth.org/wp1" term="Government" /><category scheme="http://www.labyrinth.org/wp1" term="Security" /><category scheme="http://www.labyrinth.org/wp1" term="Technology" />		<summary type="html"><![CDATA[So it appears that the &#8220;highly sophisticated and targeted attack&#8221; has apparently impacted somewhere between 20 and 34 large companies; including Google. The initial post from Google last night. Then, just moments later, Adobe released a very similarly-worded announcement stating that they had also been a victim of an attack as well. Then, sort of [...]]]></summary>
		<content type="html" xml:base="http://www.labyrinth.org/wp1/?p=441"><![CDATA[<p>So it appears that the &#8220;highly sophisticated and targeted attack&#8221; has apparently impacted somewhere between 20 and 34 large companies; including Google.</p>
<p>The <a href="http://googleblog.blogspot.com/2010/01/new-approach-to-china.html">initial post from Google</a> last night.</p>
<p>Then, just moments later, Adobe released a very <a href="http://blogs.adobe.com/conversations/2010/01/adobe_investigates_corporate_n.html">similarly-worded announcement</a> stating that they had also been a victim of an attack as well.</p>
<p>Then, <a href="http://googleenterprise.blogspot.com/2010/01/keeping-your-data-safe.html">sort of an update</a>, from Google with some additional snippets of information:</p>
<p>There appears to be a lack of clarity as to how pervasive this attack really was.  For instance, <a href="http://googleblog.blogspot.com/2010/01/new-approach-to-china.html">the post on Google&#8217;s blog</a> last night states the number &#8220;20&#8243;.  A <a href="http://www.bloomberg.com/apps/news?pid=20601080&#038;sid=aU43JmiuDJaQ">Bloomberg.com post</a> stated this morning that there were 34 companies involved.  Either way, the number of companies involved is mind-boggling.  </p>
<p>Some additional commentary:</p>
<p>Evgeny Morozov has a great post/analysis over on <a href="http://neteffect.foreignpolicy.com/posts/2010/01/13/doubting_the_sincerity_of_googles_threat">Foreign Policy</a>.  I am not so sure I can come to the same conclusion given that he presupposes that China&#8217;s reaction to Google&#8217;s statement will be to simply shut Google.cn off.  It may not come down quite like that.</p>
<p>Robert McMillan from IDG had great coverage that was carried in multiple places, like <a href="http://www.pcworld.com/businesscenter/article/186786/google_attack_part_of_widespread_spying_effort.html">this article on PCWorld</a>.</p>
<p>But I think the most telling snippet out of all of this is the statement issued by Hillary Clinton, Secretary of State, on the US Department of State website <a href="http://www.state.gov/secretary/rm/2010/01/135105.htm">here</a>.  The reason I think this is the most telling is because the fact that the Secretary of State issues a statement basically saying to China &#8220;you&#8217;d better have a really really good explanation for this&#8221; is remarkable given the current state of the  economic relationship between China and the US (I am going to refrain from providing my opinion on this).  You don&#8217;t see something like this every day.</p>
<p>Finally, as a resource you might want to consider, Tim Mullen re-shared his <a href="http://www.securityfocus.com/infocus/1900/1">informative article</a> on how to block access to an entire country using Microsoft&#8217;s ISA server, on Full-Disclosure this afternoon.</p>
]]></content>
		<link rel="replies" type="text/html" href="http://www.labyrinth.org/wp1/?p=441#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://www.labyrinth.org/wp1/?feed=atom&amp;p=441" thr:count="0" />
		<thr:total>0</thr:total>
	</entry>
		<entry>
		<author>
			<name>scott</name>
						<uri>http://www.labyrinth.org/homepages/scott/home.html</uri>
					</author>
		<title type="html"><![CDATA[Official Google Blog: A new approach to China]]></title>
		<link rel="alternate" type="text/html" href="http://www.labyrinth.org/wp1/?p=439" />
		<id>http://www.labyrinth.org/wp1/?p=439</id>
		<updated>2010-01-13T00:27:22Z</updated>
		<published>2010-01-13T00:27:18Z</published>
		<category scheme="http://www.labyrinth.org/wp1" term="Economic" /><category scheme="http://www.labyrinth.org/wp1" term="Government" /><category scheme="http://www.labyrinth.org/wp1" term="Security" /><category scheme="http://www.labyrinth.org/wp1" term="Technology" />		<summary type="html"><![CDATA[Wow&#8230; they are willing to actually forego doing business in China. It&#8217;s about time someone stood up to this kind of behavior! Official Google Blog:&#8221; A new approach to China 1/12/2010 03:00:00 PM Like many other well-known organizations, we face cyber attacks of varying degrees on a regular basis. In mid-December, we detected a highly [...]]]></summary>
		<content type="html" xml:base="http://www.labyrinth.org/wp1/?p=439"><![CDATA[<p>Wow&#8230; they are willing to actually forego doing business in China.  It&#8217;s about time someone stood up to this kind of behavior!</p>
<p><a href="http://googleblog.blogspot.com/">Official Google Blog</a>:&#8221; </p>
<p>A new approach to China<br />
1/12/2010 03:00:00 PM</p>
<p>Like many other well-known organizations, we face cyber attacks of varying degrees on a regular basis. In mid-December, we detected a highly sophisticated and targeted attack on our corporate infrastructure originating from China that resulted in the theft of intellectual property from Google. However, it soon became clear that what at first appeared to be solely a security incident&#8211;albeit a significant one&#8211;was something quite different.</p>
<p>First, this attack was not just on Google. As part of our investigation we have discovered that at least twenty other large companies from a wide range of businesses&#8211;including the Internet, finance, technology, media and chemical sectors&#8211;have been similarly targeted. We are currently in the process of notifying those companies, and we are also working with the relevant U.S. authorities.</p>
<p>Second, we have evidence to suggest that a primary goal of the attackers was accessing the Gmail accounts of Chinee human rights activists. Based on our investigation to date we believe their attack did not achieve that objective. Only two Gmail accounts appear to have been accessed, and that activity was limited to account information (such as the date the account was created) and subject line, rather than the content of emails themselves.</p>
<p>Third, as part of this investigation but independent of the attack on Google, we have discovered that the accounts of dozens of U.S.-, China- and Europe-based Gmail users who are advocates of human rights in China appear to have been routinely accessed by third parties. These accounts have not been accessed through any security breach at Google, but most likely via phishing scams or malware placed on the users&#8217; computers.</p>
<p>We have already used information gained from this attack to make infrastructure and architectural improvements that enhance security for Google and for our users. In terms of individual users, we would advise people to deploy reputable anti-virus and anti-spyware programs on their computers, to install patches for their operating systems and to update their web browsers. Always be cautious when clicking on links appearing in instant messages and emails, or when asked to share personal information like passwords online. You can read more here about our cyber-security recommendations. People wanting to learn more about these kinds of attacks can read this U.S. government report (PDF), Nart Villeneuve&#8217;s blog and this presentation on the GhostNet spying incident.</p>
<p>We have taken the unusual step of sharing information about these attacks with a broad audience not just because of the security and human rights implications of what we have unearthed, but also because this information goes to the heart of a much bigger global debate about freedom of speech. In the last two decades, China&#8217;s economic reform programs and its citizens&#8217; entrepreneurial flair have lifted hundreds of millions of Chinese people out of poverty. Indeed, this great nation is at the heart of much economic progress and development in the world today.</p>
<p>We launched Google.cn in January 2006 in the belief that the benefits of increased access to information for people in China and a more open Internet outweighed our discomfort in agreeing to censor some results. At the time we made clear that &#8220;we will carefully monitor conditions in China, including new laws and other restrictions on our services. If we determine that we are unable to achieve the objectives outlined we will not hesitate to reconsider our approach to China.&#8221;</p>
<p>These attacks and the surveillance they have uncovered&#8211;combined with the attempts over the past year to further limit free speech on the web&#8211;have led us to conclude that we should review the feasibility of our business operations in China. We have decided we are no longer willing to continue censoring our results on Google.cn, and so over the next few weeks we will be discussing with the Chinese government the basis on which we could operate an unfiltered search engine within the law, if at all. We recognize that this may well mean having to shut down Google.cn, and potentially our offices in China.</p>
<p>The decision to review our business operations in China has been incredibly hard, and we know that it will have potentially far-reaching consequences. We want to make clear that this move was driven by our executives in the United States, without the knowledge or involvement of our employees in China who have worked incredibly hard to make Google.cn the success it is today. We are committed to working responsibly to resolve the very difficult issues raised.&#8221;</p>
<p>&#8220;</p>
]]></content>
		<link rel="replies" type="text/html" href="http://www.labyrinth.org/wp1/?p=439#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://www.labyrinth.org/wp1/?feed=atom&amp;p=439" thr:count="0" />
		<thr:total>0</thr:total>
	</entry>
		<entry>
		<author>
			<name>scott</name>
						<uri>http://www.labyrinth.org/homepages/scott/home.html</uri>
					</author>
		<title type="html"><![CDATA[SecureWorks Releases Guidelines to the Healthcare Industry]]></title>
		<link rel="alternate" type="text/html" href="http://www.labyrinth.org/wp1/?p=437" />
		<id>http://www.labyrinth.org/wp1/?p=437</id>
		<updated>2010-01-06T19:51:32Z</updated>
		<published>2010-01-06T19:51:29Z</published>
		<category scheme="http://www.labyrinth.org/wp1" term="Government" /><category scheme="http://www.labyrinth.org/wp1" term="Security" /><category scheme="http://www.labyrinth.org/wp1" term="Social" /><category scheme="http://www.labyrinth.org/wp1" term="Technology" />		<summary type="html"><![CDATA[Read about it here&#8230; FTA: SecureWorks&#8217; Recommended Information Security Guidelines: * Security Risk Assessments &#8211; Performing regular security risk assessments will give your organization a much better understanding of the actual risks posed to your Protected Health Information (PHI) and Personally Identifiable Information (PII). This process will also look at the controls you have in [...]]]></summary>
		<content type="html" xml:base="http://www.labyrinth.org/wp1/?p=437"><![CDATA[<p>Read about it <a href="http://www.dotmed.com/news/story/11175/">here</a>&#8230;</p>
<p>FTA:</p>
<p><a href="http://www.secureworks.com/compliance/industries/healthcare">SecureWorks&#8217;</a> Recommended Information Security Guidelines:</p>
<p>* Security Risk Assessments &#8211; Performing regular security risk assessments will give your organization a much better understanding of the actual risks posed to your Protected Health Information (PHI) and Personally Identifiable Information (PII). This process will also look at the controls you have in place compared with regulatory requirements, and help you determine if there are any gaps. It will also give you an opportunity to compare your security posture with others in the industry. Recommendations made as a part of this process can be integrated into your overall information security program, keeping your security safeguards current, as well as helping your organization show diligence and a commitment to compliance.</p>
<p>* Intrusion Prevention and Detection Services (IPS/IDS) &#8211; The implementation of IDS and IPS enables you to detect and block attempts by cyber criminals to access data on your servers and your network. Proactive alerting mechanisms and monitoring services can notify you of attempted cyber attacks and allow you to respond in real-time as a component of your Information Security Program. It is much less costly, both from a monetary and reputational perspective, to prevent a cyber breach then to be faced with notifying affected individuals and the HHS, as required by the HITECH Act.</p>
<p>* Data Loss Prevention (DLP) &#8211; A DLP solution can help monitor your network traffic for possible leakage of PII such as social security numbers and PHI, such as Health Level 7 (HL7) codes (medical standards/procedures codes), etc.</p>
<p>* Log Monitoring &#8211; Log Monitoring centralizes and correlates audit logs from your applications and systems to allow you to identify improper access to sensitive patient data from internal or external sources. Proactive monitoring or regular reviews of logs is a key step in ensuring that your patient data is secure, as well as in meeting the short time-window required by the HITECH Act for notification of a breach.</p>
<p>* Web Application Security Testing and Web Application Firewalls &#8211; Web applications are becoming more common in healthcare environments. Due to their increasing role in the IT business environment and prevalence of security flaws, web applications are a frequent target of Internet hackers. Healthcare organizations and business associates should perform web application security testing regularly and when significant changes are made to the web applications in order to protect against current security threats. Also, the implementation of a web application firewall can help protect against emerging attacks being launched from cyber criminals.</p>
<p>* Encryption &#8211; Implementing strong encryption policies and technologies on mobile devices, laptops, portable storage and backup tapes is key to reducing your risks with regards to improper data disclosure.</p>
]]></content>
		<link rel="replies" type="text/html" href="http://www.labyrinth.org/wp1/?p=437#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://www.labyrinth.org/wp1/?feed=atom&amp;p=437" thr:count="0" />
		<thr:total>0</thr:total>
	</entry>
		<entry>
		<author>
			<name>scott</name>
						<uri>http://www.labyrinth.org/homepages/scott/home.html</uri>
					</author>
		<title type="html"><![CDATA[New Attack Locates Web Users Via XSS, Google Data &#124; threatpost]]></title>
		<link rel="alternate" type="text/html" href="http://www.labyrinth.org/wp1/?p=435" />
		<id>http://www.labyrinth.org/wp1/?p=435</id>
		<updated>2010-01-06T18:01:45Z</updated>
		<published>2010-01-06T18:01:41Z</published>
		<category scheme="http://www.labyrinth.org/wp1" term="Security" /><category scheme="http://www.labyrinth.org/wp1" term="Technology" />		<summary type="html"><![CDATA[Check this out&#8230; incredible! New Attack Locates Web Users Via XSS, Google Data &#124; threatpost by Dennis Fisher The security researcher who created the MySpace XSS worm in 2005 has developed a technique that enables an attacker to accurately locate a Web user with GPS coordinates, without using IP-based geolocation. Samy Kamkar, the author of [...]]]></summary>
		<content type="html" xml:base="http://www.labyrinth.org/wp1/?p=435"><![CDATA[<p>Check this out&#8230; incredible!</p>
<p><a href="http://threatpost.com/en_us/blogs/new-attack-locates-web-users-xss-google-data-010510">New Attack Locates Web Users Via XSS, Google Data | threatpost</a></p>
<p>by Dennis Fisher</p>
<p>The security researcher who created the MySpace XSS worm in 2005 has developed a technique that enables an attacker to accurately locate a Web user with GPS coordinates, without using IP-based geolocation.</p>
<p>Samy Kamkar, the author of the infamous Samy worm that spread through MySpace, on Monday published information about a new technique that can be used to exploit a vulnerability in some home Internet routers and, when combined with other information, pinpoint a user&#8217;s physical location. The tactic utilizes a combination of cross-site scripting and some freely available tools and information on the Web.</p>
<p>(Via <a href="http://threatpost.com/en_us/blogs/new-attack-locates-web-users-xss-google-data-010510">Threatpost</a>.)</p>
]]></content>
		<link rel="replies" type="text/html" href="http://www.labyrinth.org/wp1/?p=435#comments" thr:count="0" />
		<link rel="replies" type="application/atom+xml" href="http://www.labyrinth.org/wp1/?feed=atom&amp;p=435" thr:count="0" />
		<thr:total>0</thr:total>
	</entry>
	</feed><!-- Dynamic Page Served (once) in 7.218 seconds -->

