<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">
    <title>Technology Security</title>
    
    <link rel="hub" href="http://hubbub.api.typepad.com/" />
    <link rel="alternate" type="text/html" href="http://securityblog.typepad.com/technology_security/" />
    <id>tag:typepad.com,2003:weblog-1242980</id>
    <updated>2009-09-16T13:56:26-05:00</updated>
    
    <generator uri="http://www.typepad.com/">TypePad</generator>
    <geo:lat>30.17207</geo:lat><geo:long>-97.872845</geo:long><link rel="license" type="text/html" href="http://creativecommons.org/licenses/by/2.0/" /><logo>http://creativecommons.org/images/public/somerights20.gif</logo><link rel="self" href="http://feeds.feedburner.com/TechnologySecurity" type="application/atom+xml" /><feedburner:emailServiceId>TechnologySecurity</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><entry>
        <title>Intelligence Analyst poking around gets the shaft</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/0zXkJnNPl7s/intelligence-analyst-poking-around-gets-the-shaft.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2009/09/intelligence-analyst-poking-around-gets-the-shaft.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00d83453a4e869e20120a5758d06970b</id>
        <published>2009-09-16T13:56:26-05:00</published>
        <updated>2009-09-16T13:56:26-05:00</updated>
        <summary type="html">If you’re going to have security clearance at the National Geospatial-Intelligence Agency, then you should know that anytime you step out of your designated dataset, someone is going to know. That’s why it is hard to believe that Brian Keith...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">&lt;p&gt;&lt;em&gt;&lt;em&gt;&lt;a href="http://www.wired.com/images_blogs/threatlevel/2009/09/nga.png"&gt;&lt;img title="nga" alt="nga" src="http://www.wired.com/images_blogs/threatlevel/2009/09/nga.png" width="163" height="163"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/em&gt;If you’re going to have security clearance at the National Geospatial-Intelligence Agency, then you should know that anytime you step out of your designated dataset, someone is going to know. That’s why it is hard to believe that Brian Keith Montgomery, an intelligence analyst at the NGIA,  unwittingly viewed information regarding a classified operation that he did not have authorization to view. Even though it was within his security clearance, there was a warning that “only officials participating in the operation were allowed to use the password” to view this particular data. Even though he was authorized to use that same password to view other data, he apparently did not see the warning informing him who could and could not view THIS operation’s information. &lt;/em&gt;&lt;/p&gt;  &lt;p&gt;&lt;em&gt;While motive may be that he was just being a curious geek, he will no doubt learn a harsh lesson about being nosey.&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;&lt;em&gt;From wired.com, Kevin Poulsen &lt;a href="http://www.wired.com/threatlevel/2009/09/montgomery/" target="_blank"&gt;writes&lt;/a&gt;:&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;An analyst at a Defense Department spy satellite agency faces federal hacking charges after allegedly poking around in a top-secret system used in a classified terrorism investigation involving the FBI and the U.S. Army.&lt;/p&gt;  &lt;p&gt;Brian Keith Montgomery worked on a covert program for the National Geospatial-Intelligence Agency — the spy agency in charge of satellite and aerial image collection. On April 9, he was carrying out his duties when he saw a message that “provided significant detail about a classified operation” that was unrelated to his job, according to an affidavit filed by a Pentagon investigator.&lt;/p&gt;  &lt;p&gt;The operation is not detailed in the &lt;a href="http://www.wired.com/images_blogs/threatlevel/2009/09/montgomery_affidavit.pdf"&gt;affidavit&lt;/a&gt; (.pdf), but there is a reference to the 902nd Military Intelligence Battalion, an Army counterintelligence unit based at Fort Meade in Maryland, with a presence at more than 50 other locations inside and outside the United States. The 902nd faced controversy in 2005, when NBC News published documents showing the the unit had been &lt;a href="http://www.msnbc.msn.com/id/10481600/"&gt;spying on American anti-war protesters&lt;/a&gt;. Under the guise of fighting terrorism, the group had filed intelligence reports on legal demonstrations, including a weekly protest at an Atlanta recruiting station, and a protest at the University of California at Santa Cruz.&lt;/p&gt;  &lt;p&gt;According to the government, Montgomery ignored a security warning in the message he saw, and twice logged in to a classified system used in the terrorism investigation: first on April 9, when he stayed on for two hours, and then on April 14. He’d gotten the password from another classified message to which he also had legitimate access.&lt;/p&gt;  &lt;p&gt;Curiously, just by accessing the system, Montgomery endangered the terrorism investigation, and “caused harm to the U.S. Army and the FBI,” according to the affidavit by Dexter Wells, an agent with the Defense Criminal Investigative Service.&lt;/p&gt;  &lt;p&gt;Montgomery’s alleged motives are unclear, but he told DCIS that he was very interested in the information in the program, Wells wrote. Montgomery also told investigators that he thought he was allowed to log in to the system, and hadn’t noticed a warning saying that only officials participating in the operation were allowed to use the password.&lt;/p&gt;  &lt;p&gt;“It was not until I was called on the carpet, that I went back and read the warning notice in the message traffic,” Montgomery allegedly told DCIS.&lt;/p&gt;  &lt;p&gt;The nature of the system at issue is not clear, but it was used from all around the United States as part of the terrorism investigation, and was being monitored by the FBI at the time of his alleged access. That’s evidently what led to the probe of Montgomery, who worked at a National Geospatial-Intelligence Agency facility at Fort Belvoir in northern Virginia.&lt;/p&gt;  &lt;p&gt;There are no allegations that Montgomery did anything with the information he obtained.&lt;/p&gt;  &lt;p&gt;He’s charged with a single count of gaining unauthorized access to a protected computer or exceeding authorized access, and obtaining classified information. Prosecutors in the Eastern District of Virginia, where Montgomery was charged Friday, did not return a phone call.&lt;/p&gt;  &lt;p&gt;Michael Mongold&lt;/p&gt;  &lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:7788a143-86d2-4b60-9f1f-799b9b3ff16a" class="wlWriterEditableSmartContent"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/Intelligence+Analyst" rel="tag"&gt;Intelligence Analyst&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Brian+Keith+Montgomery" rel="tag"&gt;Brian Keith Montgomery&lt;/a&gt;,&lt;a href="http://technorati.com/tags/National+Geospatial-Intelligence+Agency" rel="tag"&gt;National Geospatial-Intelligence Agency&lt;/a&gt;,&lt;a href="http://technorati.com/tags/NGIA" rel="tag"&gt;NGIA&lt;/a&gt;,&lt;a href="http://technorati.com/tags/902nd+Military+Intelligence+Battalion" rel="tag"&gt;902nd Military Intelligence Battalion&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Fort+Mead" rel="tag"&gt;Fort Mead&lt;/a&gt;,&lt;a href="http://technorati.com/tags/michael+mongold" rel="tag"&gt;michael mongold&lt;/a&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=0zXkJnNPl7s:gJ1lCEYH11M:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=0zXkJnNPl7s:gJ1lCEYH11M:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=0zXkJnNPl7s:gJ1lCEYH11M:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=0zXkJnNPl7s:gJ1lCEYH11M:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=0zXkJnNPl7s:gJ1lCEYH11M:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=0zXkJnNPl7s:gJ1lCEYH11M:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=0zXkJnNPl7s:gJ1lCEYH11M:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=0zXkJnNPl7s:gJ1lCEYH11M:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=0zXkJnNPl7s:gJ1lCEYH11M:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=0zXkJnNPl7s:gJ1lCEYH11M:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=0zXkJnNPl7s:gJ1lCEYH11M:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2009/09/intelligence-analyst-poking-around-gets-the-shaft.html</feedburner:origLink></entry>
    <entry>
        <title>US Government moves towards OpenID</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/yx3wHGjDzcU/us-government-moves-towards-openid.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2009/09/us-government-moves-towards-openid.html" thr:count="1" thr:updated="2009-11-11T14:50:50-06:00" />
        <id>tag:typepad.com,2003:post-6a00d83453a4e869e20120a5755a44970b</id>
        <published>2009-09-16T13:09:13-05:00</published>
        <updated>2009-09-16T13:09:13-05:00</updated>
        <summary type="html">Jason Miller reports for Federal News Radio about the US government’s attempts to consolidate logins and potentially integrate current PIV card holders into a unified authentication and identity repository for accessing government services. It will be interesting to see where...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">&lt;p&gt;&lt;em&gt;Jason Miller &lt;a href="http://www.federalnewsradio.com/index.php?nid=35&amp;amp;sid=1759859" target="_blank"&gt;reports&lt;/a&gt; for Federal News Radio about the US government’s attempts to consolidate logins and potentially integrate current PIV card holders into a unified authentication and identity repository for accessing government services. It will be interesting to see where this goes but I have the feeling that this is a step closer to what a number of other countries are attempting. In one corner, you have cost saving measures by reducing redundancy and in the other, you have the paranoia and potential misuse of having just one repository of your federal identity. Of course, having numerous repositories of your identity spread amongst different government agencies is no more secure…&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;From the article:&lt;/p&gt;  &lt;p&gt;The &lt;a href="http://www.nih.gov/" target="_blank"&gt;National Institutes of Health&lt;/a&gt; will kick off a pilot in the next few weeks to test how it would use commercial applications, such as &lt;a href="http://info.yahoo.com/center/us/yahoo/" target="_blank"&gt;Yaho&lt;/a&gt;o or &lt;a href="http://www.google.com/intl/en/corporate/" target="_blank"&gt;Google&lt;/a&gt;, to let employees and citizens sign up for services. &lt;/p&gt;  &lt;p&gt;Federal chief information officer Vivek Kundra says the goal is to show how the government could do away with the need for multiple usernames and passwords for government services and use existing commercial infrastructure. &lt;/p&gt;  &lt;p&gt;"One of things we have to recognize is the U.S. government continues to invest in platforms we shouldn't be investing in," says Kundra today at the &lt;a href="http://www.gov2summit.com/" target="_blank"&gt;Gov 2.0 Summit&lt;/a&gt; in Washington sponsored by &lt;a href="http://oreilly.com/" target="_blank"&gt;O'Reilly Media&lt;/a&gt; and &lt;a href="http://www.techweb.com/home" target="_blank"&gt;TechWeb&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;"If you wanted to go out there today and make a reservation for a camping site, the &lt;a href="http://www.doi.gov/" target="_blank"&gt;Department of Interior&lt;/a&gt;, through &lt;a href="http://www.recreation.gov/" target="_blank"&gt;Recreation.gov&lt;/a&gt;, would force you to create an account and you would use once or a couple of times, and you would never use it again. The same thing if you went to the NIH, GSA and every other agency. It leads to poor service and higher costs because a lot of that infrastructure is disposable." &lt;/p&gt;  &lt;p&gt;Kundra says the goal is to use existing platforms for services that are not sensitive. &lt;/p&gt;  &lt;p&gt;"We've been working with the &lt;a href="http://openid.net/ " target="_blank"&gt;OpenID foundation&lt;/a&gt; to look at how we could create a trust framework across the federal government with the providers of Open ID to be able to authenticate and allow people to have access to some of the government services," he says. &lt;/p&gt;  &lt;p&gt;"What this will allow to do is move from Web sites on the federal government's end that are &lt;a href="http://en.wikipedia.org/wiki/Brochureware" target="_blank"&gt;brochureware&lt;/a&gt; to actually be very interactive, service driven sites that American people can use within their own context." &lt;/p&gt;  &lt;p&gt;Kundra says one of the biggest issues for the pilot is the security and privacy issues. &lt;/p&gt;  &lt;p&gt;"We want to make sure that if you signed up for those accounts that you as the consumer have full consent of what is happening with the data, how you authenticate and opting in," he says. &lt;/p&gt;  &lt;p&gt;"At the NIH level, if you want to sign up for a conference, why not use one of those platforms instead of building an entire new infrastructure. Most people have accounts that could be used." &lt;/p&gt;  &lt;p&gt;Don Thibeau, executive director of the OpenID Foundation, says the NIH pilot will show how interactions with researchers and scientists worldwide can be easier. &lt;/p&gt;  &lt;p&gt;"If you are looking for information on the latest information on cancer research, OpenID is an onramp to engage NIH so they can remember who you are," he says. &lt;/p&gt;  &lt;p&gt;"It also allows you to on your choice give permissions for NIH to know more about you. It begins that relationship so they can tailor the kind of content that you have access to or the kind of information they would like to recommend to you at a level of assurance that the citizen is comfortable with." &lt;/p&gt;  &lt;p&gt;Judy Spencer, the chairwoman of the &lt;a href="http://www.idmanagement.gov/fpkipa/" target="_blank"&gt;Federal Public Key Infrastructure Policy Authority&lt;/a&gt;, says the &lt;a href="http://www.cio.gov/" target="_blank"&gt;CIO Council&lt;/a&gt; and &lt;a href="http://www.idmanagement.gov/ficc/index.htm" target="_blank"&gt;Federal Identity Credentialing Committee&lt;/a&gt; are trying to allay some security and privacy concerns about using commercial sites. &lt;/p&gt;  &lt;p&gt;She says they have adopted six privacy principles for this and other pilots: &lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;The user only can opt in; &lt;/li&gt;    &lt;li&gt;The government will accept only a minimal amount of personal information; &lt;/li&gt;    &lt;li&gt;The government will not track the user's activity online; &lt;/li&gt;    &lt;li&gt;The government will not accept any personal identifiable information; &lt;/li&gt;    &lt;li&gt;Users will receive adequate notice that the government is collecting certain information; &lt;/li&gt;    &lt;li&gt;If the service is terminated, the data remains protected. &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Kundra says this concept could be extended to the internal government operations. &lt;/p&gt;  &lt;p&gt;He says because more and more federal employees, and contractors, have secure identity cards under Homeland Security Presidential Directive 12, there are opportunities there as well. &lt;/p&gt;  &lt;p&gt;As of June 1, almost 2.7 million federal employees and 745,000 contractors have &lt;a href="http://www.nextgov.com/the_basics/tb_20080610_8037.php" target="_blank"&gt;HSPD-12&lt;/a&gt; compliant cards. &lt;/p&gt;  &lt;p&gt;The NIH pilot is part of a broader initiative by the Obama administration to better integrate federal identity management, which includes the federal public key infrastructure efforts, HSPD-12 and the &lt;a href="http://www.idmanagement.gov/" target="_blank"&gt;E-Authentication initiative&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;The CIO Council's &lt;a href="http://www.cio.gov/InformationSecurity.cfm" target="_blank"&gt;Information Security and Identity Management Committee&lt;/a&gt; is updating the federal ID management handbook. &lt;/p&gt;  &lt;p&gt;"We are trying to develop a government-wide credential and access management framework or landscape that all of these other initiatives will be able to take advantage of," Spencer says. &lt;/p&gt;  &lt;p&gt;"If we do our job right, then these other entities will be able to leverage that and not have to silo or reinvent these things." &lt;/p&gt;  &lt;p&gt;Spencer, who also spoke at the Gov 2.0 Summit, says the government's success in tackling identity management has been mixed. She says since the early 2000s, initiatives such as e-authentication and HSPD-12 have made identity management easier. &lt;/p&gt;  &lt;p&gt;"We have been stymied in reaching the 300 million American citizens who want to do business with the government," she says. &lt;/p&gt;  &lt;p&gt;"That is why we have started to look at open solutions and leverage those companies that already are doing business with the government." &lt;/p&gt;  &lt;p&gt;The OpenID Foundation says this includes 10 companies, including Yahoo!, &lt;a href="https://www.paypal.com/" target="_blank"&gt;PayPal&lt;/a&gt;, Google, &lt;a href="http://www.equifax.com/home/" target="_blank"&gt;Equifax&lt;/a&gt; and &lt;a href="http://www.aol.com" target="_blank"&gt;AOL&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;Thibeau says this initiative builds on past strategies. &lt;/p&gt;  &lt;p&gt;"This time the government has deliberately reached out to the private sector for [several] things: to meet citizens where they are today, this opportunity brings the citizen identity to the government so unlike previous accounts this doesn't require the citizen or user to do anything new," Thibeau says. &lt;/p&gt;  &lt;p&gt;"It says you will have access to government sites with the identity you have today through the identity provider you have chosen." &lt;/p&gt;  &lt;p&gt;Thibeau says the open ID standard is not owned by any one company, but it is a set of protocols many companies have agreed to follow. &lt;/p&gt;  &lt;p&gt;Spencer says from this pilot citizens will grow more comfortable with using federal services online, and more complex transactions can happen once that trust is establish. &lt;/p&gt;  &lt;p&gt;Michael Mongold&lt;/p&gt;  &lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:5533ec7f-bb83-493c-905e-fe247a678eea" class="wlWriterEditableSmartContent"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/National+Institute+of+Health" rel="tag"&gt;National Institute of Health&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Yahoo" rel="tag"&gt;Yahoo&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Google" rel="tag"&gt;Google&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Paypal" rel="tag"&gt;Paypal&lt;/a&gt;,&lt;a href="http://technorati.com/tags/AOL" rel="tag"&gt;AOL&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Equifax" rel="tag"&gt;Equifax&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Vivek+Kundra" rel="tag"&gt;Vivek Kundra&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Chief+Information+Officer" rel="tag"&gt;Chief Information Officer&lt;/a&gt;,&lt;a href="http://technorati.com/tags/O'Reilly" rel="tag"&gt;O'Reilly&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Technweb" rel="tag"&gt;Technweb&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Department+of+Interior" rel="tag"&gt;Department of Interior&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Gov+2.0+Summit" rel="tag"&gt;Gov 2.0 Summit&lt;/a&gt;,&lt;a href="http://technorati.com/tags/OpenID" rel="tag"&gt;OpenID&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Federal+Public+Key+Infrastructure+Policy+Authority" rel="tag"&gt;Federal Public Key Infrastructure Policy Authority&lt;/a&gt;,&lt;a href="http://technorati.com/tags/CIO+Council" rel="tag"&gt;CIO Council&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Federal+Identity+Credentialing+Committee" rel="tag"&gt;Federal Identity Credentialing Committee&lt;/a&gt;,&lt;a href="http://technorati.com/tags/HSPD-12" rel="tag"&gt;HSPD-12&lt;/a&gt;,&lt;a href="http://technorati.com/tags/E-Authentication" rel="tag"&gt;E-Authentication&lt;/a&gt;,&lt;a href="http://technorati.com/tags/michael+mongold" rel="tag"&gt;michael mongold&lt;/a&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=yx3wHGjDzcU:OF7KwOLHa30:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=yx3wHGjDzcU:OF7KwOLHa30:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=yx3wHGjDzcU:OF7KwOLHa30:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=yx3wHGjDzcU:OF7KwOLHa30:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=yx3wHGjDzcU:OF7KwOLHa30:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=yx3wHGjDzcU:OF7KwOLHa30:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=yx3wHGjDzcU:OF7KwOLHa30:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=yx3wHGjDzcU:OF7KwOLHa30:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=yx3wHGjDzcU:OF7KwOLHa30:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=yx3wHGjDzcU:OF7KwOLHa30:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=yx3wHGjDzcU:OF7KwOLHa30:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2009/09/us-government-moves-towards-openid.html</feedburner:origLink></entry>
    <entry>
        <title>Implementing Identity Management? What to ask</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/uIMwzoB2KIc/implementing-identity-management-what-to-ask.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2009/09/implementing-identity-management-what-to-ask.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00d83453a4e869e20120a56d07da970b</id>
        <published>2009-09-14T11:16:03-05:00</published>
        <updated>2009-09-14T11:17:22-05:00</updated>
        <summary type="html">This is a nice primer for those who don’t know where to start when contemplating an identity management solution. As with most things in technology security, knowing the right questions at the beginning and formulating the right policies is 90%...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">&lt;h5&gt;&lt;strong&gt;This is a nice primer for those who don’t know where to start when contemplating an identity management solution. As with most things in technology security, knowing the right questions at the beginning and formulating the right policies is 90% of the process.&lt;/strong&gt;&lt;/h5&gt;  &lt;h5&gt;&lt;strong&gt;&lt;a href="http://gcn.com/articles/2009/09/14/identity-management-access-control-12-questions.aspx" target="_blank"&gt;From GCN&lt;/a&gt;:&lt;/strong&gt;&lt;/h5&gt;  &lt;p&gt;&lt;strong&gt;“Here are 12 questions to ask before implementing an identity management and access control system.&lt;/strong&gt;&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;&lt;strong&gt;What non-information technology departments and systems need to work with the identity management system? For example, human resources, physical security, finance? Do they already have information or systems in place that will help the initiative? &lt;/strong&gt;&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;What business processes need to be put in place to support identity management? Who will create, implement and manage the processes? &lt;/strong&gt;&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Is a suite or best-of-breed approach best for your organization? Does the suite have everything you need, or will you still need additional components from other vendors? Can you purchase just one part of the suite and add other components later? &lt;/strong&gt;&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;What existing systems will need to integrate with the identity management system? Identity management software typically works well with Web-based or commercial applications but not with custom applications. Who will do the integration? &lt;/strong&gt;&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;What expertise do you have in-house for implementing the system? What outside help is required? &lt;/strong&gt;&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Which features of identity management will you implement first — single sign-on, provisioning, identity life cycle management, role-based access control? &lt;/strong&gt;&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;How will users be de-provisioned so there are no orphan accounts? &lt;/strong&gt;&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Who is responsible for defining roles and access rights and assigning those to users? &lt;/strong&gt;&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Besides agency employees, who else needs access — general public, vendors, contractors, state and local agencies? How will you manage and control them? &lt;/strong&gt;&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;What types of physical components need to be integrated — Homeland Security Presidential Directive 12 smart cards, fingerprint readers, door locks, radio frequency identification chips and sensors? &lt;/strong&gt;&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;What cultural barriers will you have to overcome? How? &lt;/strong&gt;&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;How will you balance security needs with usability? You don't want users using Post-it Notes to keep track of passwords that are too difficult to remember or have excessive help-desk calls for password resets.”&lt;/strong&gt;&lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;&lt;strong&gt;Michael Mongold&lt;/strong&gt;&lt;/p&gt;  &lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:632e3128-f49b-451a-a32b-4773e9e96187" class="wlWriterEditableSmartContent"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/Identity+Management" rel="tag"&gt;Identity Management&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Michael+Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=uIMwzoB2KIc:XJopg9qt66w:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=uIMwzoB2KIc:XJopg9qt66w:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=uIMwzoB2KIc:XJopg9qt66w:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=uIMwzoB2KIc:XJopg9qt66w:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=uIMwzoB2KIc:XJopg9qt66w:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=uIMwzoB2KIc:XJopg9qt66w:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=uIMwzoB2KIc:XJopg9qt66w:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=uIMwzoB2KIc:XJopg9qt66w:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=uIMwzoB2KIc:XJopg9qt66w:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=uIMwzoB2KIc:XJopg9qt66w:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=uIMwzoB2KIc:XJopg9qt66w:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2009/09/implementing-identity-management-what-to-ask.html</feedburner:origLink></entry>
    <entry>
        <title>Legal Hazards of Federated Identity</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/CCnLw0LGHps/legal-hazards-of-federated-identity.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2009/09/legal-hazards-of-federated-identity.html" thr:count="1" thr:updated="2009-09-14T16:32:38-05:00" />
        <id>tag:typepad.com,2003:post-6a00d83453a4e869e20120a56b9868970b</id>
        <published>2009-09-14T05:10:50-05:00</published>
        <updated>2009-09-14T05:10:50-05:00</updated>
        <summary type="html">Beyond the technical complexities of Identity Federation, Thomas Smedinghoff explains what is truly holding back wider-spread adoption of federated identification models. “’Who are you?’ is a fundamental question for all online business activities. Whether a company wants to allow employees,...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">&lt;p&gt;Beyond the technical complexities of Identity Federation, Thomas Smedinghoff &lt;a href="http://www.cio.com/article/178001/Legal_Obstacles_Delaying_Federated_Identity_Management?page=1&amp;amp;taxonomyId=1419" target="_blank"&gt;explains&lt;/a&gt; what is truly holding back wider-spread adoption of federated identification models.&lt;/p&gt;  &lt;p&gt;“’Who are you?’ is a fundamental question for all online business activities. Whether a company wants to allow employees, contractors or business partners to remotely access its networks, or engage in online commercial transactions, the need to authenticate the identity of the remote party is a critical one. &lt;/p&gt;  &lt;p&gt;   &lt;p&gt;&lt;a href="http://www.csoonline.com/fundamentals/abc_id_management_pf.html "&gt;&lt;/a&gt;&lt;/p&gt; Moreover, in today's security-conscious environment, authentication is a legal issue. A company's legal obligation to provide information security clearly includes a duty to properly authenticate persons seeking access to the company's computer systems or services. For example, in a recent case brought by the victim of identity theft, the issuer of a credit card was held liable for failing to properly authenticate the identity of the applicant/imposter. &lt;/p&gt;  &lt;p&gt;Enter federated identity management, a promising approach to dealing with the cost and complexity of addressing this often-difficult identity problem. Much work is being done by groups such as Liberty Alliance, WS-Federation and others to develop technical specifications that allow a business to verify the identity of a person seeking to access its systems by obtaining a digital credential issued by a third party. Yet the concept of federated identity management raises critical legal issues that often get overlooked in the struggle to develop appropriate specifications. And failure to recognize and address these legal issues will delay the widespread implementation of federated identity options. &lt;/p&gt;  &lt;p&gt;&lt;a href="http://ad.doubleclick.net/click;h=v8/38a8/0/0/%2a/j;44306;0-0;0;16129298;14617-580/80;0/0/0;;~aopt=2/1/62/0;~sscs=%3f"&gt;&lt;img border="0" alt="Click here to find out more!" src="http://m1.2mdn.net/viewad/817-grey.gif"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;At its essence, identity management has two components. First, individuals (or businesses or devices) must be properly identified (e.g., this is &lt;a href="http://www.cio.com/article/178001/subject/John+Smith"&gt;John Smith&lt;/a&gt;, an employee of ABC company who works in accounting). Second, a mechanism must be devised to verify that someone claiming to be a particular person and seeking remote access is, in fact, the same person as the one previously identified (e.g., the person claiming to be John Smith and seeking remote access to the accounting database is really John Smith because he has presented the shared secret we gave to the person we previously identified as John Smith). &lt;/p&gt;  &lt;p&gt;Traditionally, each business has handled its own identity management. That is, a company identified its own employees and customers and then set up a mechanism, such as a system of shared secrets or passwords, by which those persons could be authenticated for remote network access. Today, however, businesses and government agencies are increasingly looking to third parties to handle the difficult—and often expensive—task of identification. And users, overloaded with passwords, are looking for a one-stop option. &lt;/p&gt;  &lt;p&gt;Federated identity has emerged as a promising solution. A federated identity model enables the portability of identity information or identity tokens across different systems and entities. Thus, for example, one organization (e.g., the &lt;a href="http://www.cio.com/article/178001/subject/Social+Security+Administration"&gt;Social Security Administration&lt;/a&gt;) can authenticate a person by relying on an identity assertion made by a separate organization (e.g., a bank) that previously identified the person when he opened an account. So long as a protocol exists for sharing the identity data between the bank and SSA, that person can do business with SSA using the user ID and password issued by his bank. &lt;/p&gt;  &lt;p&gt;That assumes, of course, that SSA trusts the identity verification process used by the bank, and that the bank can appropriately limit its liability risk should it make a mistake. These issues, among many others, are some of the key legal problems that must be addressed before the process will scale. &lt;/p&gt;  &lt;p&gt;While the technical details and specifications of a federated identity system can become quite complex, the legal issues are readily apparent by looking at an oversimplified summary of what actually happens: &lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Someone (a relying party) wants to know something about the identity of a particular person (the subject). The subject may, for example, be an individual seeking access to the relying party's network, a person seeking to enter into an online contract with the relying party or someone seeking to access an account with the relying party. &lt;/li&gt;    &lt;li&gt;To provide the required identity information, a third party that has previously identified the subject (the identity provider) issues a digital credential or token to make an assertion about the identity of the subject to the relying party. &lt;/li&gt;    &lt;li&gt;The token is communicated to the relying party (by either the subject or the identity provider, depending on the system involved) and the relying party validates the token, and then relies on the associated identity assertion from the identity provider in order to grant access to the subject or proceed with the proposed transaction.&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;There are, of course, many ways to accomplish the foregoing, ranging from relatively simple user ID and password systems to very complex public key infrastructures. But in all cases there are some very basic questions that need to be asked, all of which raise potentially significant legal issues. &lt;/p&gt;  &lt;p&gt;&lt;a href="http://ad.doubleclick.net/click;h=v8/38a8/0/0/%2a/j;44306;0-0;0;16129298;14617-580/80;0/0/0;;~aopt=2/1/62/0;~sscs=%3f"&gt;&lt;img border="0" alt="Click here to find out more!" src="http://m1.2mdn.net/viewad/817-grey.gif"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Identification Process&lt;/strong&gt; First and foremost, what is the process that the identity provider uses to establish the identity of the subject? That process is critical to the reliability of an identity assertion. For example, does the identity provider do an in-person interview of the subject and examine multiple government-issued photo identification documents, or does it simply rely on the subject's self-asserted claims made over the Internet? And what mechanisms are in place to ensure that the identity provider has actually complied with that process? For example, is there a requirement for an external audit? &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Personal Information&lt;/strong&gt; What are the rules that govern the privacy and security of the personal information about the subject that is collected by the identity provider? Since the subject must provide the identity provider with certain personal information to establish his or her identity, the protection of that information becomes critical. Likewise, if the identity provider will be communicating some of that information to a relying party as part of an identity assertion, the subject needs to know what rights the relying party has to use and further communicate, and what obligations it has to protect, that information. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Scope of Assertion&lt;/strong&gt; What is the scope of the identity assertion? For example, does an assertion that someone is "&lt;a href="http://www.cio.com/article/178001/subject/Bill+Gates"&gt;Bill Gates&lt;/a&gt;" mean that this person is Bill Gates of Microsoft, Bill Gates of Peoria, &lt;a href="http://www.cio.com/article/178001/subject/Illinois"&gt;Illinois&lt;/a&gt;, or some other random person with that name? Does it mean that this person has a bank account in the name of Bill Gates? Or does it simply mean that this person &lt;em&gt;claims&lt;/em&gt; to be Bill Gates? The answer to this type of question will have a significant impact on the willingness of the relying party to proceed with different types of transactions on the basis of the identity assertion. And it will also affect the liability of the identity provider in the event the assertion is incorrect. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Use of Assertion&lt;/strong&gt; What type of transaction is appropriate for use of the identity assertion? The level of identity checking required to make an identity assertion for accessing the control processes of a nuclear reactor is presumably much greater than the identity verification necessary to justify access to the local garden club website. The identity provider will want to limit the scope of the use of an identity assertion. &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Liability&lt;/strong&gt; The potential liability of the each of the parties is also important to consider. Specifically, what is the liability of the subject for providing false identity information, or for failing to protect the password or key necessary to initiate an identity assertion? What is the liability of the identity provider for failing to follow proper identification procedures that result in an incorrect identity assertion? What is the liability of the relying party for trusting a fraudulent assertion (e.g., in the case of identity theft), especially in a case where it could have determined that the assertion was false?&lt;/p&gt;  &lt;p&gt;There are a variety of possible approaches to developing a legal infrastructure to address questions like these. They include enacting legislation or regulations (such as those we see in some other countries), establishing a set of private system rules that all parties contractually agree to (such as used by funds transfer systems and in the credit card industry), establishing public standards that parties publicly agree to and are audited against as a condition of participating (as in the case of Extended Validation SSL certificates), entering into a series of one-on-one contractual relationships (such as the federal government has been doing with selected identity providers), and relying on public disclosures of practices (such as with the traditional PKI approach). Each of these approaches has positive and negative attributes. &lt;/p&gt;  &lt;p&gt;Without some type of a legal framework to address these issues, however, a federated identity model will likely not scale. At least in the case of economically significant transactions, the risks to each of the parties of such unresolved issues are simply too great to justify reliance on the federated process. These questions, and others like them, are the legal land mines that stand in the way of a viable federated identity management infrastructure.”&lt;/p&gt;  &lt;p&gt;Michael Mongold&lt;/p&gt;  &lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:65b3f200-c7de-4bbd-8ab9-7e9b3e4ff744" class="wlWriterEditableSmartContent"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/Federated+Identity" rel="tag"&gt;Federated Identity&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Identification+Process" rel="tag"&gt;Identification Process&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Personal+Information" rel="tag"&gt;Personal Information&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Scope+of+Assertion" rel="tag"&gt;Scope of Assertion&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Use+of+Assertion" rel="tag"&gt;Use of Assertion&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Liability" rel="tag"&gt;Liability&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Federation" rel="tag"&gt;Federation&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Identity" rel="tag"&gt;Identity&lt;/a&gt;,&lt;a href="http://technorati.com/tags/michael+mongold" rel="tag"&gt;michael mongold&lt;/a&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=CCnLw0LGHps:6Nd2Q8TrDoc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=CCnLw0LGHps:6Nd2Q8TrDoc:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=CCnLw0LGHps:6Nd2Q8TrDoc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=CCnLw0LGHps:6Nd2Q8TrDoc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=CCnLw0LGHps:6Nd2Q8TrDoc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=CCnLw0LGHps:6Nd2Q8TrDoc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=CCnLw0LGHps:6Nd2Q8TrDoc:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=CCnLw0LGHps:6Nd2Q8TrDoc:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=CCnLw0LGHps:6Nd2Q8TrDoc:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=CCnLw0LGHps:6Nd2Q8TrDoc:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=CCnLw0LGHps:6Nd2Q8TrDoc:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2009/09/legal-hazards-of-federated-identity.html</feedburner:origLink></entry>
    <entry>
        <title>The breadth and complexities of identity management</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/Mp1lud-JcMA/the-breadth-and-complexities-of-identity-management.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2009/09/the-breadth-and-complexities-of-identity-management.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00d83453a4e869e20120a5650d6a970b</id>
        <published>2009-09-11T16:33:36-05:00</published>
        <updated>2009-09-11T16:33:36-05:00</updated>
        <summary type="html">From multi-factor authentication to single sign-on to user provisioning: identity management can be an incredibly broad and complex endeavor. In a great article, Drew Robb writing for GCN gives a high level example of why this industry is so nebulous...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">&lt;h4&gt;From multi-factor authentication to single sign-on to user provisioning: identity management can be an incredibly broad and complex endeavor. In a great article, &lt;a href="http://gcn.com/articles/2009/09/14/identity-management-access-control-systems.aspx" target="_blank"&gt;Drew Robb writing for GCN&lt;/a&gt; gives a high level example of why this industry is so nebulous yet so necessary…&lt;/h4&gt;  &lt;p&gt;“Identity management and access control systems have a simple purpose: ensure that users can access only the data and applications they need. However, getting to that point is not so simple.&lt;/p&gt;  &lt;p&gt;Many large organizations have a variety of systems in operation. Different parts of the organization might manage those systems, and they might have a range of processes to acquire user information and approvals.&lt;/p&gt;  &lt;p&gt;“When a large government organization takes on a project to automate provisioning, it must include the request process, the approval process, the routing, and, ultimately, the provisioning of credentials and entitlements into the target systems,” said Gregg Kreizman, &lt;a href="http://www.gartner.com/technology/home.jsp" target="_blank"&gt;Gartner’s&lt;/a&gt; research director. “Many user provisioning projects have failed because organizations didn't take into account the amount of business process change involved.”&lt;/p&gt;  &lt;p&gt;Although some organizations have failed to implement identity management systems, there also have been successful deployments. And integrated identity management and access control suites are making it easier to achieve the desired result.&lt;/p&gt;  &lt;p&gt;“The issue here is balancing privacy, security and ease of use for the user,” said Jon Oltsik, principal analyst at &lt;a href="http://www.enterprisestrategygroup.com/" target="_blank"&gt;Enterprise Strategy Group&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Define the scope&lt;/p&gt;  &lt;p&gt;Implementing an identity management system goes beyond just making sure people have their &lt;a href="http://www.dhs.gov/xabout/laws/gc_1217616624097.shtm" target="_blank"&gt;Homeland Security Presidential Directive 12&lt;/a&gt; &lt;a href="http://www.rsa.com/glossary/default.asp?id=1072" target="_blank"&gt;Personal Identity Verification cards&lt;/a&gt; and can remember their passwords.&lt;/p&gt;  &lt;p&gt;“What we consider to be identity and access management is really a combination of at least a dozen different technologies,” said Bill Nagel, an analyst at &lt;a href="http://www.forrester.com/rb/research" target="_blank"&gt;Forrester Research&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Forrester Research evaluates identity management vendors based on 14 different technologies: directories, enterprise single sign-on, entitlement management, federation, identity audit, metadirectories, multifactor authentication, password management, privileged user and password management, provisioning, role management, user-centric identity, virtual directories, and Web single sign-on.&lt;/p&gt;  &lt;p&gt;Gartner tracks vendors in three different categories related to identity management: single sign-on, user provisioning and Web access management.&lt;/p&gt;  &lt;p&gt;When implementing an identity management system, organizations need to agree on what is necessary to meet business needs, a process that starts with determining what you have in place. That review should include policies, procedures, workflows, hardware, data sources and software, and it must include all departments.&lt;/p&gt;  &lt;p&gt;“A lot of people are coming to realize that ID management is, first and foremost, not a technology problem,” said Paul Donfried, vice president of identity and access management at &lt;a href="http://www.saic.com/" target="_blank"&gt;Science Applications International Corp.&lt;/a&gt; “It is an issue that permeates organizations, and you tend to find certain functions that had to historically manage identities.”&lt;/p&gt;  &lt;p&gt;A human resources department typically will run an employment eligibility check on applicants before hiring them and might already have the organizational structure, chain of command and employee roles loaded into a human resources management system. That data can serve as a basis for creating the identities, roles and authorizations in the system.&lt;/p&gt;  &lt;p&gt;For example, when the Agriculture Department needed to implement HSPD-12, it used the department's &lt;a href="http://74.125.47.132/search?q=cache:C4BPV23Q7BIJ:i2i.nfc.usda.gov/Customer_Support/Presentations/Dantagnan%2520EmpowHR%25209.0-0708.ppt+PeopleSoft+EmpowHR&amp;amp;cd=1&amp;amp;hl=en&amp;amp;ct=clnk&amp;amp;gl=us" target="_blank"&gt;PeopleSoft EmpowHR&lt;/a&gt; system as the authoritative starting point for employment status and then expanded it to cover contractors and state and local government employees who also needed access. Procurement employees know what vendors should be included. Payroll and security staff members can contribute other information that the system should incorporate.&lt;/p&gt;  &lt;p&gt;Next, find out the business needs of the stakeholders. In addition to IT access, be sure to consider additional functions that might be needed, such as verification of electronic signatures. From there, design an implementation project that meets those needs and will engender support.&lt;/p&gt;  &lt;p&gt;“You need to think about the business needs of agencies and not think of it as purely an exercise in deploying technology,” said Gerry Gebel, vice president and service director of &lt;a href="http://www.burtongroup.com/Research/Idps.aspx" target="_blank"&gt;Burton Group’s Identity and Privacy Strategies.&lt;/a&gt; “This will result in a more successful deployment, happy customers and increased likelihood that they will invest in future identity management improvements.”&lt;/p&gt;  &lt;p&gt;Selecting products&lt;/p&gt;  &lt;p&gt;After determining the business needs, you can start looking at the software available to automate the processes. As with other types of enterprise software, the initial choice is between buying an identity management suite and taking a best-of-breed approach. However, with identity management software, software packages could be composed of products that other vendors recently acquired because the market is rapidly consolidating.&lt;/p&gt;  &lt;p&gt;“Sometimes, these products have been integrated seamlessly, but with others, it is an ongoing process,” Nagel said.&lt;/p&gt;  &lt;p&gt;There are five main vendors in the identity management field: &lt;a href="http://www.ca.com/us/identity-access-management.aspx" target="_blank"&gt;CA&lt;/a&gt;, &lt;a href="http://www-01.ibm.com/software/tivoli/solutions/identity-mgmt/" target="_blank"&gt;IBM&lt;/a&gt;, &lt;a href="http://www.novell.com/products/identitymanager/" target="_blank"&gt;Novell&lt;/a&gt;, &lt;a href="http://www.oracle.com/technology/products/id_mgmt/index.html" target="_blank"&gt;Oracle&lt;/a&gt; and &lt;a href="http://www.sun.com/software/identity/index.jsp" target="_blank"&gt;Sun Microsystems&lt;/a&gt;. Although Oracle recently acquired Sun, Nagel said there is significant redundancy between the two companies’ identity management offerings. It isn't known yet whether Sun's suite will be able to improve the strength of Oracle's offering, which is already ranked No. 1 by Forrester and Gartner.&lt;/p&gt;  &lt;p&gt;In addition to those five vendors, dozens of other large and small companies offer niche products. Donfried said that when selecting a product — whether it's a suite or best of breed — the first thing to look for is flexibility.&lt;/p&gt;  &lt;p&gt;“More than anything, you want to avoid locking in to any single vendor or any type of proprietary solution,” he said. “Whatever we view as the right standard and the right solution today, by the time we have it installed, configured and operational, it is outdated.”&lt;/p&gt;  &lt;p&gt;Oltsik recommended keeping an eye on the emergence of what he calls Identity 2.0 technologies, such as the open-source, Web-based single-sign-on systems &lt;a href="http://openid.net/" target="_blank"&gt;OpenID&lt;/a&gt; and the &lt;a href="http://shibboleth.internet2.edu/" target="_blank"&gt;Shibboleth System&lt;/a&gt;, in addition to Microsoft's &lt;a href="http://www.microsoft.com/windows/products/winfamily/cardspace/default.mspx" target="_blank"&gt;CardSpace&lt;/a&gt;. Those technologies provide users with claims-based authentication, single sign-on and data privacy.&lt;/p&gt;  &lt;p&gt;“It is too early for agencies to 'buy' an Identity 2.0 solution, but they should be paying attention to and supporting standards and product development,” Oltsik said. “Since ID 2.0 is built to support anonymity and privacy, it may be a perfect fit for e-government initiatives like online voting and health care reform, enabling cost-saving e-government initiatives without violating the legislative or regulatory requirements around privacy.”&lt;/p&gt;  &lt;p&gt;Gradual implementation&lt;/p&gt;  &lt;p&gt;Fully implementing an identity management system is a multiyear project involving more than just IT.&lt;/p&gt;  &lt;p&gt;“The biggest mistake is not having a vision of the end state right at the beginning and not having full commitment to go through the process,” Forrester’s Nagel said.&lt;/p&gt;  &lt;p&gt;After agreeing on a vision, it is a matter of selecting which aspect to implement first and carrying that through to completion so there is an observable improvement and return on investment. Targeting commercial and Web-based products will make for quick success before tackling the more complex problems of integrating existing applications.&lt;/p&gt;  &lt;p&gt;“When we look at the larger agencies, it tends to be their legacy applications and their legacy environment that becomes very complex,” Donfried said.”&lt;/p&gt;  &lt;p&gt;Michael Mongold&lt;/p&gt;  &lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:60e3f6cf-2659-46d4-ae4b-7b95023b1281" class="wlWriterEditableSmartContent"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/Identity+Management" rel="tag"&gt;Identity Management&lt;/a&gt;,&lt;a href="http://technorati.com/tags/GCN" rel="tag"&gt;GCN&lt;/a&gt;,&lt;a href="http://technorati.com/tags/CA" rel="tag"&gt;CA&lt;/a&gt;,&lt;a href="http://technorati.com/tags/IBM" rel="tag"&gt;IBM&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Sun" rel="tag"&gt;Sun&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Oracle" rel="tag"&gt;Oracle&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Forrester+Research" rel="tag"&gt;Forrester Research&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Gartner" rel="tag"&gt;Gartner&lt;/a&gt;,&lt;a href="http://technorati.com/tags/SIAC" rel="tag"&gt;SIAC&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Enterprise+Strategy+Group" rel="tag"&gt;Enterprise Strategy Group&lt;/a&gt;,&lt;a href="http://technorati.com/tags/HSPD-12" rel="tag"&gt;HSPD-12&lt;/a&gt;,&lt;a href="http://technorati.com/tags/PIV" rel="tag"&gt;PIV&lt;/a&gt;,&lt;a href="http://technorati.com/tags/single+sign-on" rel="tag"&gt;single sign-on&lt;/a&gt;,&lt;a href="http://technorati.com/tags/entitlement+management" rel="tag"&gt;entitlement management&lt;/a&gt;,&lt;a href="http://technorati.com/tags/federation" rel="tag"&gt;federation&lt;/a&gt;,&lt;a href="http://technorati.com/tags/identity+audit" rel="tag"&gt;identity audit&lt;/a&gt;,&lt;a href="http://technorati.com/tags/metadirectories" rel="tag"&gt;metadirectories&lt;/a&gt;,&lt;a href="http://technorati.com/tags/multi-factor+authentication" rel="tag"&gt;multi-factor authentication&lt;/a&gt;,&lt;a href="http://technorati.com/tags/password+management" rel="tag"&gt;password management&lt;/a&gt;,&lt;a href="http://technorati.com/tags/privileged+user" rel="tag"&gt;privileged user&lt;/a&gt;,&lt;a href="http://technorati.com/tags/user-centric+identity" rel="tag"&gt;user-centric identity&lt;/a&gt;,&lt;a href="http://technorati.com/tags/role+management" rel="tag"&gt;role management&lt;/a&gt;,&lt;a href="http://technorati.com/tags/virtual+directories" rel="tag"&gt;virtual directories&lt;/a&gt;,&lt;a href="http://technorati.com/tags/user+provisioning" rel="tag"&gt;user provisioning&lt;/a&gt;,&lt;a href="http://technorati.com/tags/web+access+management" rel="tag"&gt;web access management&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Science+Applications+International+Corp." rel="tag"&gt;Science Applications International Corp.&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Peoplesoft+EmpowHR" rel="tag"&gt;Peoplesoft EmpowHR&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Burton+Group" rel="tag"&gt;Burton Group&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Identity+and+Privacy+Strategies" rel="tag"&gt;Identity and Privacy Strategies&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Novell" rel="tag"&gt;Novell&lt;/a&gt;,&lt;a href="http://technorati.com/tags/OpenID" rel="tag"&gt;OpenID&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Shibboleth+System" rel="tag"&gt;Shibboleth System&lt;/a&gt;,&lt;a href="http://technorati.com/tags/OpenCard" rel="tag"&gt;OpenCard&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Microsoft" rel="tag"&gt;Microsoft&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Michael+Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=Mp1lud-JcMA:yTOuBClOyLA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=Mp1lud-JcMA:yTOuBClOyLA:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=Mp1lud-JcMA:yTOuBClOyLA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=Mp1lud-JcMA:yTOuBClOyLA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=Mp1lud-JcMA:yTOuBClOyLA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=Mp1lud-JcMA:yTOuBClOyLA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=Mp1lud-JcMA:yTOuBClOyLA:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=Mp1lud-JcMA:yTOuBClOyLA:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=Mp1lud-JcMA:yTOuBClOyLA:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=Mp1lud-JcMA:yTOuBClOyLA:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=Mp1lud-JcMA:yTOuBClOyLA:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2009/09/the-breadth-and-complexities-of-identity-management.html</feedburner:origLink></entry>
    <entry>
        <title>Bio-Key wins with FBI</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/eStJ98GCVMA/bio-key-wins-with-fbi.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2009/09/bio-key-wins-with-fbi.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00d83453a4e869e20120a5bb248b970c</id>
        <published>2009-09-11T14:03:10-05:00</published>
        <updated>2009-09-11T14:03:10-05:00</updated>
        <summary type="html">After shedding their law enforcement division last month, it looks like Bio-Key's focus on straight biometrics is proving fruitful. From Bio-key: BIO-key Biometric Technology Selected as Part of the Next Generation FBI AFIS System “FBI Next Generation Identification Automated Finger...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">&lt;p&gt;After shedding their law enforcement division last month, it looks like Bio-Key's focus on straight biometrics is proving fruitful.&lt;/p&gt;  &lt;p&gt;From Bio-key:&lt;/p&gt;  &lt;p&gt;&lt;b&gt;BIO-key&lt;/b&gt;&lt;b&gt; Biometric Technology Selected as Part of the Next Generation FBI AFIS System&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;em&gt;“FBI Next Generation Identification Automated Finger Identification System Based on Fusion of BIO-key and MorphoTrak Biometric Algorithms&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;&lt;em&gt;&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;&lt;b&gt;Wall, NJ, September 10, 2009&lt;/b&gt; - BIO-key International, a leader in finger-based biometric identification and wireless public safety solutions, announced today that the contract recently awarded by Lockheed Martin to provide fingerprint identification technology for the FBI's Next Generation Identification (NGI) system is based on the fusion of BIO-key and MorphoTrak biometric algorithms. The fusion of the algorithms of these two powerful biometric providers was a key component to delivering the speed, accuracy and reliability of the solution that was selected.&lt;/p&gt;  &lt;p&gt;"This is the most important award the company has ever received and it may be the most important biometric contract ever awarded," said Mike DePasquale, BIO-key's CEO.&lt;/p&gt;  &lt;p&gt;It is no exaggeration to say that the U.S. FBI is the most discerning and most demanding fingerprint user in the world. The award of the contract for the FBI's NGI system was the result of a competitive trade study process that rigorously and objectively evaluated vendors' solutions. BIO-key and MorphoTrak were able to fuse their two fingerprint biometric algorithms to deliver unsurpassed speed and accuracy results from a single fingerprint sample. This innovative technology achievement advances the finger matching process beyond what has been previously been available.&lt;/p&gt;  &lt;p&gt;"We appreciate the privilege of being selected to be part of this vital national identification project along with MorphoTrak and we look forward to working with the FBI and its contractors including Lockheed Martin to successfully implement and support the most advanced biometric system ever deployed," Mr. DePasquale added.&lt;/p&gt;  &lt;p&gt;"The results we have been able to achieve are extraordinary," stated Mira LaCous, Vice President of Technology and Development.  "BIO-key's core algorithm accuracy and image enhancement/correction solutions provided major improvements to the FBI's current system, and we believe surpassed all other competing technologies. The BIO-key technology provided to MorphoTrak has been developed in the United States and is being used today by our customers in commercial applications, as well as other major large scale civil ID programs..”&lt;/p&gt;  &lt;p&gt;"The selection of BIO-key technology by the FBI, through their contractors Lockheed Martin and MorphoTrak, to be part of the NGI system, validates that BIO-key has some of the industry's most accurate and scalable fingerprint matching technology,” CEO DePasquale observed. “Other agencies and commercial customers, looking to take advantage of the research, testing and decision by the FBI may now reasonably conclude: ’If it is good enough for the FBI, it's certainly good enough for our organization’."  Mr. DePasquale concluded that ‘We are thrilled with how well BIO-key is positioned and with the quality of our references as we look to our future biometric business potential.’”&lt;/p&gt;  &lt;p&gt;Michael Mongold&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=eStJ98GCVMA:4RGQmcNLxfw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=eStJ98GCVMA:4RGQmcNLxfw:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=eStJ98GCVMA:4RGQmcNLxfw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=eStJ98GCVMA:4RGQmcNLxfw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=eStJ98GCVMA:4RGQmcNLxfw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=eStJ98GCVMA:4RGQmcNLxfw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=eStJ98GCVMA:4RGQmcNLxfw:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=eStJ98GCVMA:4RGQmcNLxfw:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=eStJ98GCVMA:4RGQmcNLxfw:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=eStJ98GCVMA:4RGQmcNLxfw:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=eStJ98GCVMA:4RGQmcNLxfw:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2009/09/bio-key-wins-with-fbi.html</feedburner:origLink></entry>
    <entry>
        <title>Lenovo facial recognition = fail</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/NR4RKTotWBw/lenovo-facial-recognition-fail.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2009/09/lenovo-facial-recognition-fail.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00d83453a4e869e20120a5bb1a88970c</id>
        <published>2009-09-11T13:47:25-05:00</published>
        <updated>2009-09-11T13:47:25-05:00</updated>
        <summary type="html">Well, sort of. It did recognize the face but unfortunately it was a picture of the face on a phone. Again, we have some not-so-great press for facial recognition. And sadly, this will only help confuse more potential customers of...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">&lt;p&gt;Well, sort of. It did recognize the face but unfortunately it was a picture of the face on a phone.&lt;/p&gt;  &lt;p&gt;Again, we have some not-so-great press for facial recognition. And sadly, this will only help confuse more potential customers of biometrics about the difference between identification products and authentication products...&lt;/p&gt;  &lt;p&gt;From a &lt;a href="http://www.expertreviews.co.uk/news/267829/lenovo-veriface-biometrics-can-be-fooled-by-a-mobile-phone.html" target="_blank"&gt;Computer Shopper review&lt;/a&gt;…&lt;/p&gt;  &lt;p&gt;”&lt;a href="http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&amp;amp;lndocid=MIGR-72561" target="_blank"&gt;Lenovo's VeriFace application&lt;/a&gt; uses your laptop's webcam to automatically unlock your computer when your face is in front of it. Well, that's the theory. When we tested it, we found that a photo of the laptop's owner worked just as well.&lt;/p&gt;  &lt;p&gt; &lt;a href="http://www.expertreviews.co.uk/#"&gt;&lt;img border="0" src="http://photos.computershopper.co.uk/picture_library/dir_247/it_portal_pic_123763_t.jpg" width="130"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Taking a picture on an HTC Hero and waving the &lt;a href="http://www.expertreviews.co.uk/#" target="_blank"&gt;phone's&lt;/a&gt; screen in front of our G550 &lt;a href="http://www.expertreviews.co.uk/#" target="_blank"&gt;laptop's&lt;/a&gt; webcam caused the system to unlock. All it required was a judicious bit of phone waving to minimize reflections. There seems to be no built-in mechanism to tell a live face from a photo of one.&lt;/p&gt;  &lt;p&gt;The other problem with the system is that while it's running and hunting for a face it's hammering the computer's hard disk, as we could tell from the drive activity light. That's not something we like to see on a laptop, particularly when it's running on battery power.&lt;/p&gt;  &lt;p&gt;It's a nice idea in theory, but the poor security it offers means that we'd rather stick with entering a password or using a fingerprint scanner.”&lt;/p&gt;  &lt;p&gt;Michael Mongold&lt;/p&gt;  &lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:495681a9-7b5c-4775-9c7a-4e254cef1c31" class="wlWriterEditableSmartContent"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/Lenovo" rel="tag"&gt;Lenovo&lt;/a&gt;,&lt;a href="http://technorati.com/tags/VeriFace" rel="tag"&gt;VeriFace&lt;/a&gt;,&lt;a href="http://technorati.com/tags/biometric" rel="tag"&gt;biometric&lt;/a&gt;,&lt;a href="http://technorati.com/tags/mobile+phone" rel="tag"&gt;mobile phone&lt;/a&gt;,&lt;a href="http://technorati.com/tags/HTC" rel="tag"&gt;HTC&lt;/a&gt;,&lt;a href="http://technorati.com/tags/facial+recognition" rel="tag"&gt;facial recognition&lt;/a&gt;,&lt;a href="http://technorati.com/tags/G550" rel="tag"&gt;G550&lt;/a&gt;,&lt;a href="http://technorati.com/tags/webcam" rel="tag"&gt;webcam&lt;/a&gt;,&lt;a href="http://technorati.com/tags/michael+mongold" rel="tag"&gt;michael mongold&lt;/a&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=NR4RKTotWBw:MMJBbIASIBE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=NR4RKTotWBw:MMJBbIASIBE:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=NR4RKTotWBw:MMJBbIASIBE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=NR4RKTotWBw:MMJBbIASIBE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=NR4RKTotWBw:MMJBbIASIBE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=NR4RKTotWBw:MMJBbIASIBE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=NR4RKTotWBw:MMJBbIASIBE:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=NR4RKTotWBw:MMJBbIASIBE:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=NR4RKTotWBw:MMJBbIASIBE:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=NR4RKTotWBw:MMJBbIASIBE:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=NR4RKTotWBw:MMJBbIASIBE:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2009/09/lenovo-facial-recognition-fail.html</feedburner:origLink></entry>
    <entry>
        <title>Biometric surveillance forecast to surge</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/D9kI61Y_gsY/biometric-surveillance-forecast-to-surge.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2009/09/biometric-surveillance-forecast-to-surge.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00d83453a4e869e20120a560cc1c970b</id>
        <published>2009-09-10T10:07:45-05:00</published>
        <updated>2009-09-10T10:07:45-05:00</updated>
        <summary type="html">In a forecast from Acuity Market Intelligence, the market share of biometric surveillance applications within the biometric industry will reach $872 million in annual revenue by 2017. According to new forecasts from Acuity Market Intelligence, Surveillance posts the strongest market...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">&lt;p&gt;In a forecast from Acuity Market Intelligence, the market share of biometric surveillance applications within the biometric industry will reach $872 million in annual revenue by 2017.&lt;/p&gt;  &lt;p&gt;&lt;i&gt;According to new forecasts from Acuity Market Intelligence, Surveillance posts the strongest market share gain of all biometric applications from 2009 to 2017 growing from less than 1% to nearly 8% of total market revenue and representing a CAGR over the forecast period of 60.99%.&lt;/i&gt;&lt;/p&gt;  &lt;p&gt;Louisville, CO - September 9, 2009 -- Acuity Market Intelligence of Louisville, Colorado, an emerging technology strategy and research consultancy with a proven record of accurately anticipating biometrics market trends, today announced that Acuity's new research report "The Future of Biometrics" reveals that the market for Biometric Surveillance is expected to grow at an astounding compound annual growth rate (CAGR) of 60.99% from 2009 through 2017. Surveillance is projected to post the strongest market share gain of all biometric applications from less than 1% to nearly 8% of total market value representing growth from $19 million to $872 million in annual revenue.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://securityblog.typepad.com/.a/6a00d83453a4e869e20120a560cc0e970b-pi"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="Biometrics_Market_Share_by_Application" border="0" alt="Biometrics_Market_Share_by_Application" src="http://securityblog.typepad.com/.a/6a00d83453a4e869e20120a560cc14970b-pi" width="473" height="186"&gt;&lt;/img&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;"Biometric Surveillance is the ultimate dream application of intelligence and defense communities and the waking nightmare of privacy and civil liberty advocates", says Acuity Principal C. Maxine Most. "Until now the conflict and debate have been largely academic. However, today, there are biometric technologies providing distance-based, real-time, non-cooperative image capture i.e. surveillance. Both Face and Iris recognition are commercially available in the two-meter range and are on the verge of operating in the ten-meter range. Another emerging biometric of interest in the surveillance arena is gait recognition. This is particularly useful when trying to identify an individual whose face and/or iris are not visible".&lt;/p&gt;  &lt;p&gt;These finding are part of the wealth of industry insight available in the "The Future of Biometrics" market research report published in August 2009. This report offers Acuity's trademark brand of hype-free analysis into the trends, drivers, and opportunities that will shape the biometrics industry and presents detailed market forecasts for 2009 through 2017.&lt;/p&gt;  &lt;p&gt;Key Forecasts from "The Future of Biometrics":&lt;/p&gt;  &lt;p&gt;- Commercial deployment revenues match Public Sector revenues by 2014 and then surpass Public Sector revenues by 2017 representing growth form nearly 41% to just over 55% of the total global market for biometrics core technology.&lt;/p&gt;  &lt;p&gt;- Revenue growth rates vary significantly across regions. The Central and South American region will experience the highest CAGR over the forecast period of 39.46% while growing from nearly 4% to nearly 13% of total global revenues. Overall market dominance will shift from Europe and the US to Asia. North America and EMEA's percentages of total global revenues will decrease over the forecast period form 37% to 26% and 38% to 29% respectively. By 2017, the Asia Pacific Region will generate the greatest percent of revenues for the biometrics industry with more than 32% of global revenues.&lt;/p&gt;  &lt;p&gt;- The dominance of AFIS/Livescan and Fingerprint continues thorough the forecast period. However, by 2017 Iris and Face recognition begin to rival their dominance together accounting for more than 33% of global revenues. Vein, Voice, and Signature will experience modest growth from 3% to 6%, 2% to 5%, and 0.7% to 1.6% respectively over the forecast period.&lt;/p&gt;  &lt;p&gt;- Transactions will ultimately provide the majority of industry revenue. Information and Financial Transactions for the Commercial sector by 2012 and eGoverment for the Public Sector by 2017. By 2017, Information Transactions will represent 12.21% of the global market, Financial Services 18.22% of the global market, and eGovernment will represent 14.23% of the global market.&lt;/p&gt;  &lt;p&gt;- The percent of revenue from Identification Services declines over the forecast period but only from 65% to 47%. Surveillance and Monitoring posts the strongest percentage gain growing from less than 1% to nearly 8% of total market revenue representing a CAGR over the forecast period of a startling 60.99%.&lt;/p&gt;  &lt;p&gt;About Acuity Market Intelligence   &lt;br&gt;Acuity Market Intelligence (&lt;a href="http://www.acuity-mi.com"&gt;www.acuity-mi.com&lt;/a&gt;) is an emerging technology strategy and research consultancy with a proven record of accurately anticipating biometric and associated identification solutions market trends. The company provides strategic planning, market research and analysis, sector tracking, opportunity sizing, solution and deployment analysis, due diligence, executive briefings, and customized consulting. Acuity publishes the industry leading biometrics market analysis newsletter, the Biometrics Market Intelligence eUpdate. Qualified readers can subscribe at &lt;a href="http://www.biometricsmi.com"&gt;www.biometricsmi.com&lt;/a&gt; . Founded in October 2001, Acuity is headquartered in Louisville, Colorado, USA with clients in the United States, Asia and Europe.&lt;/p&gt;  &lt;p&gt;Michael Mongold&lt;/p&gt;  &lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:3f3f1180-8eee-4e9f-97df-ab4e37ac96ec" class="wlWriterEditableSmartContent"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/Biometric" rel="tag"&gt;Biometric&lt;/a&gt;,&lt;a href="http://technorati.com/tags/forecast" rel="tag"&gt;forecast&lt;/a&gt;,&lt;a href="http://technorati.com/tags/surveillance" rel="tag"&gt;surveillance&lt;/a&gt;,&lt;a href="http://technorati.com/tags/monitoring" rel="tag"&gt;monitoring&lt;/a&gt;,&lt;a href="http://technorati.com/tags/acuity+market+intelligence" rel="tag"&gt;acuity market intelligence&lt;/a&gt;,&lt;a href="http://technorati.com/tags/biometric+market+intelligence" rel="tag"&gt;biometric market intelligence&lt;/a&gt;,&lt;a href="http://technorati.com/tags/applications" rel="tag"&gt;applications&lt;/a&gt;,&lt;a href="http://technorati.com/tags/fingerprint" rel="tag"&gt;fingerprint&lt;/a&gt;,&lt;a href="http://technorati.com/tags/voice" rel="tag"&gt;voice&lt;/a&gt;,&lt;a href="http://technorati.com/tags/vein" rel="tag"&gt;vein&lt;/a&gt;,&lt;a href="http://technorati.com/tags/iris" rel="tag"&gt;iris&lt;/a&gt;,&lt;a href="http://technorati.com/tags/signature" rel="tag"&gt;signature&lt;/a&gt;,&lt;a href="http://technorati.com/tags/AFIS" rel="tag"&gt;AFIS&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Livescan" rel="tag"&gt;Livescan&lt;/a&gt;,&lt;a href="http://technorati.com/tags/recognition" rel="tag"&gt;recognition&lt;/a&gt;,&lt;a href="http://technorati.com/tags/face" rel="tag"&gt;face&lt;/a&gt;,&lt;a href="http://technorati.com/tags/michael+mongold" rel="tag"&gt;michael mongold&lt;/a&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=D9kI61Y_gsY:kpo3l3W491k:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=D9kI61Y_gsY:kpo3l3W491k:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=D9kI61Y_gsY:kpo3l3W491k:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=D9kI61Y_gsY:kpo3l3W491k:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=D9kI61Y_gsY:kpo3l3W491k:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=D9kI61Y_gsY:kpo3l3W491k:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=D9kI61Y_gsY:kpo3l3W491k:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=D9kI61Y_gsY:kpo3l3W491k:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=D9kI61Y_gsY:kpo3l3W491k:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=D9kI61Y_gsY:kpo3l3W491k:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=D9kI61Y_gsY:kpo3l3W491k:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2009/09/biometric-surveillance-forecast-to-surge.html</feedburner:origLink></entry>
    <entry>
        <title>Potential chaos looms for Philippine elections and biometric enrollment</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/XEB6V1_KcT8/potential-chaos-looms-for-philippine-elections-and-biometric-enrollment.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2009/09/potential-chaos-looms-for-philippine-elections-and-biometric-enrollment.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00d83453a4e869e20120a55d7e96970b</id>
        <published>2009-09-09T13:25:47-05:00</published>
        <updated>2009-09-09T13:25:47-05:00</updated>
        <summary type="html">MANILA, Philippines—The Commission on Elections (Comelec) has urged voters to verify before October 31 the status of their registration to know if they need to enroll their biometrics or reactivate their registration to vote in the 2010 polls, an official...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">&lt;p&gt;MANILA, Philippines—The Commission on Elections (&lt;a href="http://en.wikipedia.org/wiki/Commission_on_Elections_(Philippines)"&gt;Comelec&lt;/a&gt;) has urged voters to verify before October 31 the status of their registration to know if they need to enroll their biometrics or reactivate their registration to vote in the 2010 polls, an official said.&lt;/p&gt;  &lt;p&gt;Comelec spokesman James Jimenez said verification of registration status can be done in two ways: by asking the election officer in the district where he or she is enlisted and through Comelec's &lt;a href="http://www.comelec.gov.ph/findprecinct/findprecinct.aspx"&gt;Online Find Precinct&lt;/a&gt; page.&lt;/p&gt;  &lt;p&gt;“The poll body encourages every Filipino voter to check the status of their registration and avail of our Find Precinct online service. Right now, we have updated the &lt;a href="http://newsinfo.inquirer.net/breakingnews/nation/view/20090908-224227/Voters-urged-to-check-registration-status#"&gt;database&lt;/a&gt; to include approved registration records until June 2009 so those who registered before June can check their registration. Or they can call or visit their local Comelec offices,” said Jimenez.&lt;/p&gt;  &lt;p&gt;Apart from failure to vote in at least two elections, records of a voter will be deactivated and removed from the computerized voters' list (CVL) if he or she has been imprisoned, convicted for crimes against national &lt;a href="http://newsinfo.inquirer.net/breakingnews/nation/view/20090908-224227/Voters-urged-to-check-registration-status#"&gt;security&lt;/a&gt;, declared insane and lost Filipino citizenship, said Jimenez.&lt;/p&gt;  &lt;p&gt;To vote in the next elections, a deactivated voter should file a sworn &lt;a href="http://newsinfo.inquirer.net/breakingnews/nation/view/20090908-224227/Voters-urged-to-check-registration-status#"&gt;application&lt;/a&gt; for reactivation of registration.&lt;/p&gt;  &lt;p&gt;For records with wrong, misspelled or typographical errors in name, birth date or birth place, a voter should:&lt;/p&gt;  &lt;p&gt;• File an application for correction of entries with the election officer    &lt;br&gt;• File an application for change of name if his name is changed by reason of marriage (common for women), by court order and by order of the Civil Registrar or Consul General.&lt;/p&gt;  &lt;p&gt;A voter seeking transfer of registration after a change in residence can apply for transfer of registration to the election office of his new residence. Even if the transfer of residence is within the same city or municipality but will result in change of precinct, a voter must file transfer of registration, said Jimenez.&lt;/p&gt;  &lt;p&gt;“Voters are responsible for making sure that their registration record is active and that their names are included and their records correct in the CVL so they can act on it before the end of registration period on October 31,” said Jimenez.&lt;/p&gt;  &lt;p&gt;Jimenez urged registered voters included in the June hearing of the Registration Election Board to visit the Find Precinct &lt;a href="http://newsinfo.inquirer.net/breakingnews/nation/view/20090908-224227/Voters-urged-to-check-registration-status#"&gt;website&lt;/a&gt;, fill up their full names and birth dates on the required fields and gain access to the status of their record, biometrics and even find their precinct number.&lt;/p&gt;  &lt;p&gt;If the database shows the record is deactivated, a voter needs to file an application reactivation so that his records will be included in the computerized voter's list (CVL) for the next elections, said Jimenez.&lt;/p&gt;  &lt;p&gt;If a voter has an active registration record but has no biometrics, he or she should proceed to the election office of the district where he or she is registered to complete the voter information by enrolling biometrics comprising of &lt;a href="http://newsinfo.inquirer.net/breakingnews/nation/view/20090908-224227/Voters-urged-to-check-registration-status#"&gt;digital signature&lt;/a&gt;, photo and finger &lt;a href="http://newsinfo.inquirer.net/breakingnews/nation/view/20090908-224227/Voters-urged-to-check-registration-status#"&gt;print&lt;/a&gt; specimens, he added.&lt;/p&gt;  &lt;p&gt;Voters who filed an application for transfer of registration can also check if their record reflects their new address, after the quarterly REB hearing where their application was approved.&lt;/p&gt;  &lt;p&gt;As of July, there are 2.7 million new voters approved by Comelec and six million records delisted from the CVL, making the total number of voters at 45,487,634.&lt;/p&gt;  &lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:17af7da8-2def-4b78-88f3-41ac28f0990c" class="wlWriterEditableSmartContent"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/Philippine" rel="tag"&gt;Philippine&lt;/a&gt;,&lt;a href="http://technorati.com/tags/vote" rel="tag"&gt;vote&lt;/a&gt;,&lt;a href="http://technorati.com/tags/registration" rel="tag"&gt;registration&lt;/a&gt;,&lt;a href="http://technorati.com/tags/biometric" rel="tag"&gt;biometric&lt;/a&gt;,&lt;a href="http://technorati.com/tags/enroll" rel="tag"&gt;enroll&lt;/a&gt;,&lt;a href="http://technorati.com/tags/cvl" rel="tag"&gt;cvl&lt;/a&gt;,&lt;a href="http://technorati.com/tags/comelec" rel="tag"&gt;comelec&lt;/a&gt;,&lt;a href="http://technorati.com/tags/commission+on+elections" rel="tag"&gt;commission on elections&lt;/a&gt;,&lt;a href="http://technorati.com/tags/2010+polls" rel="tag"&gt;2010 polls&lt;/a&gt;,&lt;a href="http://technorati.com/tags/michael+mongold" rel="tag"&gt;michael mongold&lt;/a&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=XEB6V1_KcT8:JR_WciGz424:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=XEB6V1_KcT8:JR_WciGz424:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=XEB6V1_KcT8:JR_WciGz424:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=XEB6V1_KcT8:JR_WciGz424:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=XEB6V1_KcT8:JR_WciGz424:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=XEB6V1_KcT8:JR_WciGz424:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=XEB6V1_KcT8:JR_WciGz424:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=XEB6V1_KcT8:JR_WciGz424:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=XEB6V1_KcT8:JR_WciGz424:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=XEB6V1_KcT8:JR_WciGz424:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=XEB6V1_KcT8:JR_WciGz424:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2009/09/potential-chaos-looms-for-philippine-elections-and-biometric-enrollment.html</feedburner:origLink></entry>
    <entry>
        <title>Multi-Spectral imaging biometrics</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/QTTGwbEIcgo/multi-spectral-imaging-biometrics.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2009/09/multi-spectral-imaging-biometrics.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00d83453a4e869e20120a55d76e3970b</id>
        <published>2009-09-09T13:18:20-05:00</published>
        <updated>2009-09-09T13:19:58-05:00</updated>
        <summary type="html">In this week’s podcast at SecureIDNews, Phil Scarfo of Lumidigm and Zack Martin of Regarding ID discuss new fronts in biometric authentication methodologies. Check it out… Technorati Tags: multi-spectral,imaging,biometrics,secureidnews,lumidigm,regarding id,biometric,authentication,michael mongold</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">&lt;p&gt;In this week’s podcast at SecureIDNews, Phil Scarfo of &lt;a href="http://www.lumidigm.com/"&gt;Lumidigm&lt;/a&gt; and Zack Martin of &lt;a href="http://www.regardingid.com/"&gt;Regarding ID&lt;/a&gt; discuss new fronts in biometric authentication methodologies. &lt;a href="http://www.secureidnews.com/2009/09/08/episode-38-multi-spectral-imaging-biometrics"&gt;Check it out…&lt;/a&gt;&lt;/p&gt;  &lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:4de9dfa4-e9f8-49f8-814f-613ab112cd61" class="wlWriterEditableSmartContent"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/multi-spectral" rel="tag"&gt;multi-spectral&lt;/a&gt;,&lt;a href="http://technorati.com/tags/imaging" rel="tag"&gt;imaging&lt;/a&gt;,&lt;a href="http://technorati.com/tags/biometrics" rel="tag"&gt;biometrics&lt;/a&gt;,&lt;a href="http://technorati.com/tags/secureidnews" rel="tag"&gt;secureidnews&lt;/a&gt;,&lt;a href="http://technorati.com/tags/lumidigm" rel="tag"&gt;lumidigm&lt;/a&gt;,&lt;a href="http://technorati.com/tags/regarding+id" rel="tag"&gt;regarding id&lt;/a&gt;,&lt;a href="http://technorati.com/tags/biometric" rel="tag"&gt;biometric&lt;/a&gt;,&lt;a href="http://technorati.com/tags/authentication" rel="tag"&gt;authentication&lt;/a&gt;,&lt;a href="http://technorati.com/tags/michael+mongold" rel="tag"&gt;michael mongold&lt;/a&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=QTTGwbEIcgo:BIzfzAfPwBU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=QTTGwbEIcgo:BIzfzAfPwBU:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=QTTGwbEIcgo:BIzfzAfPwBU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=QTTGwbEIcgo:BIzfzAfPwBU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=QTTGwbEIcgo:BIzfzAfPwBU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=QTTGwbEIcgo:BIzfzAfPwBU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=QTTGwbEIcgo:BIzfzAfPwBU:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=QTTGwbEIcgo:BIzfzAfPwBU:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=QTTGwbEIcgo:BIzfzAfPwBU:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=QTTGwbEIcgo:BIzfzAfPwBU:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=QTTGwbEIcgo:BIzfzAfPwBU:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2009/09/multi-spectral-imaging-biometrics.html</feedburner:origLink></entry>
    <entry>
        <title>CompletelyOnline.com - Biometrics Shaking Up Internet Defensive Driving in NY</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/2kAC2gUPvUQ/completelyonlinecom---biometrics-shaking-up-internet-defensive-driving-in-ny.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2009/09/completelyonlinecom---biometrics-shaking-up-internet-defensive-driving-in-ny.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00d83453a4e869e20120a55d6e3b970b</id>
        <published>2009-09-09T13:12:07-05:00</published>
        <updated>2009-09-09T13:12:07-05:00</updated>
        <summary type="html">NEW YORK, Sept. 8 -- The New York State Department of MotorVehicles has approved the CompletelyOnline biometric face recognition methodfor student ID validation for use in its Internet defensive driving pilotprogram. Unlike other biometric methods also approved for the pilot,CompletelyOnline...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">&lt;p&gt;&lt;a href="http://ad.doubleclick.net/click;h=v8/38a3/0/0/%2a/t;44306;0-0;0;38919074;1627-170/40;0/0/0;;~okv=;seg1=10018;type=featured_broker;sz=170x40;articleID=US181282 08-Sep-2009 PRN20090908;~aopt=2/0/c0/0;~sscs=%3f"&gt;&lt;img border="0" alt="" src="http://m1.2mdn.net/viewad/817-grey.gif"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;NEW YORK, Sept. 8 -- The &lt;a href="http://www.nydmv.state.ny.us/"&gt;New York State Department of MotorVehicles&lt;/a&gt; has approved the &lt;a href="http://www.completelyonline.com/"&gt;CompletelyOnline&lt;/a&gt; biometric face recognition methodfor student ID validation for use in its Internet defensive driving pilotprogram. Unlike other biometric methods also approved for the pilot,CompletelyOnline has the unique ability to authenticate a student's identitymuch the same way his identity would be authenticated in a classroom course. This distinction has already made a big change to New York's online defensivedriving industry: The first course sponsor to use CompletelyOnline has beenapproved to deliver an online course with no graded exams - a first in thenation.&lt;/p&gt;  &lt;p&gt;By submitting an image of the driver's license along with the biometric sampleof his face, the student is proving his identity over the Internet the sameway he would be proving his identity in person. "Face recognition is theideal solution for distance learning applications for several reasons," saysArmen GeoSimonian, President and CEO of CompletelyOnline.com(R). "The face isboth the only human-readable biometric characteristic and the only biometric characteristic that can be authenticated against a driver's license. It istruly the closest thing to being in the classroom."&lt;/p&gt;  &lt;p&gt;The &lt;a href="http://www.nysp.com/"&gt;New York Safety Program&lt;/a&gt; (NYSP), is the first course sponsor in New York touse CompletelyOnline, and is launching their "no graded exams" Internet coursethis week. According to President and CEO of NYSP Anthony Perlongo, "With thehelp of the CompletelyOnline technology, NYSP has developed an onlinepresentation that we believe comes as close as possible to our classroomdelivery. We believe that the combination of NYSP's hard earned reputationand the superior face recognition methodology offered byCompletelyOnline.com(R) is the reason that the NYS DMV has set this remarkableprecedent." &lt;/p&gt;  &lt;p&gt;Benefits of taking a DMV approved defensive driving course include both apoint reduction from a driver's record and an insurance discount. The ideabehind the pilot program was to make these courses, which were previously onlyavailable in a classroom, more accessible to busy drivers who would nototherwise be able to attend in person. Student ID validation is a requirementfor all defensive driving courses in the pilot program. According to the NYSDMV 650,000 drivers attend an approved classroom course every year. Theyexpect 100,000 drivers to take the course over the Internet in the first yearof the pilot.&lt;/p&gt;  &lt;p&gt;About CompletelyOnline.com&lt;/p&gt;  &lt;p&gt;CompletelyOnline.com was established in 2004 and provides its uniquepatented CompletelyOnline biometric face recognition methodology to Internetdefensive driving courses in California, Texas, Nevada and Idaho. CompletelyOnline.com continues to expand its reach in the defensive drivingindustry and in other e-learning markets.&lt;/p&gt;  &lt;p&gt; &lt;a href="http://www.completelyonline.com"&gt;www.completelyonline.com&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;About New York Safety Program&lt;/p&gt;  &lt;p&gt;The New York Safety Program has been educating drivers in New York since 1980. Founder Anthony Perlongo, has been a nationally prominent leader in the fieldof driver safety. His accomplishments as a State and National President ofthe Driver Education Guild among others have brought him recognition as adriving safety expert throughout the country. &lt;a href="http://www.nysponline.com"&gt;www.nysponline.com&lt;/a&gt;&lt;/p&gt;  &lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:8531a63c-5f13-486e-a63a-f3ccdc7e28eb" class="wlWriterEditableSmartContent"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/New+York+Safety+Online" rel="tag"&gt;New York Safety Online&lt;/a&gt;,&lt;a href="http://technorati.com/tags/CompletelyOnline.com" rel="tag"&gt;CompletelyOnline.com&lt;/a&gt;,&lt;a href="http://technorati.com/tags/completelyonline" rel="tag"&gt;completelyonline&lt;/a&gt;,&lt;a href="http://technorati.com/tags/New+York+State+Department+of+Motor+Vehicles" rel="tag"&gt;New York State Department of Motor Vehicles&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Michael+Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=2kAC2gUPvUQ:O28zKSWo8lc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=2kAC2gUPvUQ:O28zKSWo8lc:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=2kAC2gUPvUQ:O28zKSWo8lc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=2kAC2gUPvUQ:O28zKSWo8lc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=2kAC2gUPvUQ:O28zKSWo8lc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=2kAC2gUPvUQ:O28zKSWo8lc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=2kAC2gUPvUQ:O28zKSWo8lc:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=2kAC2gUPvUQ:O28zKSWo8lc:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=2kAC2gUPvUQ:O28zKSWo8lc:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=2kAC2gUPvUQ:O28zKSWo8lc:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=2kAC2gUPvUQ:O28zKSWo8lc:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2009/09/completelyonlinecom---biometrics-shaking-up-internet-defensive-driving-in-ny.html</feedburner:origLink></entry>
    <entry>
        <title>Smartmatic and NEC Argentina Join Forces in a Strategic Alliance</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/zJDnYrcyb5w/smartmatic-and-nec-argentina-join-forces-in-a-strategic-alliance.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2009/09/smartmatic-and-nec-argentina-join-forces-in-a-strategic-alliance.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00d83453a4e869e20120a55d60a9970b</id>
        <published>2009-09-09T13:03:08-05:00</published>
        <updated>2009-09-09T13:03:08-05:00</updated>
        <summary type="html">LA PAZ, Bolivia-- NEC Argentina, a subsidiary of giant Japanese IT multinational NEC Corporation, announced it has selected Smartmatic as strategic partner to develop a biometric registration system for the Bolivian National Electoral Court (known as the CNE). NEC Argentina`s...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">&lt;p&gt;LA PAZ, Bolivia--&lt;/p&gt;  &lt;p&gt; &lt;a href="http://www.nec.com.ar/"&gt;NEC Argentina&lt;/a&gt;, a subsidiary of giant Japanese IT multinational NEC Corporation, announced it has selected &lt;a href="http://www.smartmatic.com/"&gt;Smartmatic&lt;/a&gt; as strategic partner to develop a biometric registration system for the &lt;a href="http://www.cne.org.bo/"&gt;Bolivian National Electoral Court&lt;/a&gt; (known as the CNE). NEC Argentina`s selection of Smartmatic is aimed at adding still more technical prowess to help in its commitment to completely revamp Bolivia`s voter registration system. &lt;/p&gt;  &lt;p&gt;"It is gratifying that a world leader in biometric registration like NEC has chosen Smartmatic for its technology and support capabilities, toward achieving a transparent biometric register in record time. We are honored to take part in this historic enhancement of the Bolivian voting system", said Antonio Mugica, CEO, Smartmatic. &lt;/p&gt;  &lt;p&gt;THE CNE`S VOTER REGISTRATION GOALS &lt;/p&gt;  &lt;p&gt;The Bolivian CNE has set an important and dramatic voter registration goal. Over a period of three months (August to October 2009), the CNE hopes to register approximately 4 million Bolivian voters, including Bolivians living abroad in Argentina, the United States, Spain and Brazil. &lt;/p&gt;  &lt;p&gt;A new electoral law, recently approved by the Congress of Bolivia, mandates the use of biometric registration to increase security and protect the rights of voters. The new registration, which will include digital data such as citizens` fingerprints, pictures and signatures, will first prove its usefulness in the December 2009 Bolivian general elections. &lt;/p&gt;  &lt;p&gt;To implement the new registration process, the CNE is expected to use 3.000 new registration stations, comprised of 1,700 stationary and 1,300 mobile stations. &lt;/p&gt;  &lt;p&gt;DAILY REGISTRATION: POTENTIAL OF 60,000 PLUS VOTERS &lt;/p&gt;  &lt;p&gt;To support a potential daily registration of 60.000 people, NEC Argentina and Smartmatic will work together as follows: &lt;/p&gt;  &lt;p&gt;-- As project leader, NEC Argentina will provide the equipment to be used in the data capture stations, such as computers and fingerprint scanners. &lt;/p&gt;  &lt;p&gt;-- In addition, NEC will supply its cutting-edge recognition and fingerprint duplicate detection software (AFIS). &lt;/p&gt;  &lt;p&gt;-- Smartmatic will be in charge of supplying peripheral equipment and technical staff training; and of the logistics of the whole event, including equipment allocation and staff to the various CNE offices in the country. &lt;/p&gt;  &lt;p&gt;WHY SMARTMATIC? &lt;/p&gt;  &lt;p&gt;NEC turned to Smartmatic due to its experience in managing elections in countries with complex geographies, such as Venezuela and the Philippines, under intense time pressure. Bolivia`s geography, including high elevation sites and steep mountainous landscapes, presents an added degree of difficulty for equipment distribution and deployment. &lt;/p&gt;  &lt;p&gt;"NEC selected Smartmatic for three powerful reasons: its successful experience in mission-critical projects, its cutting-edge technology and its team, one of the most qualified worldwide to deal with this kind of project", said Jorge Vargas, Marketing &amp;amp; International Business Director, NEC Argentina. &lt;/p&gt;  &lt;p&gt;About Smartmatic &lt;/p&gt;  &lt;p&gt;Smartmatic is a multinational company that designs and deploys technological solutions aimed at helping governments fulfill, in the most efficient way, their commitments with their citizens. It is one of the largest cutting-edge technology suppliers, with a wide and proven experience in the United States, Asia, Latin America and the Caribbean. &lt;/p&gt;  &lt;p&gt;Smartmatic aims to help societies become more efficient and transparent, through technological innovations and it is responsible for several top and advanced innovations available in the market around three business areas: electronic auditable voting systems, intelligent and integrated security platforms, and advanced solutions for people registration and authentication for a wide range of government applications. &lt;/p&gt;  &lt;p&gt;About NEC Argentina &lt;/p&gt;  &lt;p&gt;NEC Argentina operates as a wholly-owned subsidiary of NEC Corporation. A pioneer in the integration of computer systems and communications, NEC Argentina offers solutions to different vertical segments, being today a Technological Development Center in government integrated solutions for Latin-America. &lt;/p&gt;  &lt;p&gt;Established in Buenos Aires since 1978, NEC Argentina is one of the leader suppliers of the technological area with a vast experience in the development and setting up of integral solutions like e-gov, healthcare, education, biometrics, security and convergent solutions. The company has set up successful projects in Argentina, Bolivia, Brazil, Chile, Ecuador, Venezuela, El Salvador, Costa Rica, Mexico as well as in different parts of the world, through NEC Corporation. &lt;/p&gt;  &lt;p&gt;Smartmatic &lt;/p&gt;  &lt;p&gt;Samira Saba, Marketing/Communications Manager +582127062500 ssaba@smartmatic.com or NEC Argentina Gabriela Romero, Marketing/Communications +54-1140106000 (int. 6016) &lt;a href="mailto:info@nec.com.ar"&gt;info@nec.com.ar&lt;/a&gt;&lt;/p&gt;  &lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:9601bc24-2d7b-4c44-a441-bd03c7f698a0" class="wlWriterEditableSmartContent"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/Smartmatic" rel="tag"&gt;Smartmatic&lt;/a&gt;,&lt;a href="http://technorati.com/tags/NEC+Argentina" rel="tag"&gt;NEC Argentina&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Bolivian+National+Electoral+Court" rel="tag"&gt;Bolivian National Electoral Court&lt;/a&gt;,&lt;a href="http://technorati.com/tags/CNE" rel="tag"&gt;CNE&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Michael+Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=zJDnYrcyb5w:VWVs_AIDdj0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=zJDnYrcyb5w:VWVs_AIDdj0:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=zJDnYrcyb5w:VWVs_AIDdj0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=zJDnYrcyb5w:VWVs_AIDdj0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=zJDnYrcyb5w:VWVs_AIDdj0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=zJDnYrcyb5w:VWVs_AIDdj0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=zJDnYrcyb5w:VWVs_AIDdj0:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=zJDnYrcyb5w:VWVs_AIDdj0:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=zJDnYrcyb5w:VWVs_AIDdj0:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=zJDnYrcyb5w:VWVs_AIDdj0:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=zJDnYrcyb5w:VWVs_AIDdj0:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2009/09/smartmatic-and-nec-argentina-join-forces-in-a-strategic-alliance.html</feedburner:origLink></entry>
    <entry>
        <title>Brazil votes on biometrics</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/L8LE7X_7CJ4/brazil-votes-on-biometrics.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2009/09/brazil-votes-on-biometrics.html" thr:count="2" thr:updated="2009-09-11T12:08:45-05:00" />
        <id>tag:typepad.com,2003:post-6a00d83453a4e869e20120a5b3cdce970c</id>
        <published>2009-09-09T12:51:43-05:00</published>
        <updated>2009-09-09T12:51:43-05:00</updated>
        <summary type="html">Brazil votes on biometrics Security Document World (press release) Brazil votes on biometrics 08 September 2009 Brazil’s Superior Electoral Court (TSE) has selected Suprema’s RealScan-D live scanner for nationwide biometric voter registration. The RealScan-D live scanner is a portable, USB-powered...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">&lt;p&gt;&lt;a href="http://www.google.com/url?sa=X&amp;amp;q=http://www.securitydocumentworld.com/public/index.cfm%3F%26m1%3Dc_10%26m2%3Dc_4%26m3%3De_0%26m4%3De_0%26subItemID%3D1835&amp;amp;ct=ga&amp;amp;cd=XcwVSbc5fH0&amp;amp;usg=AFQjCNFwenSSvsk6dlnEuQU4YECfvpZBGg"&gt;Brazil votes on &lt;b&gt;biometrics&lt;/b&gt;&lt;/a&gt;    &lt;br&gt;Security Document World (press release)    &lt;br&gt;&lt;/p&gt;  &lt;h4&gt;Brazil votes on biometrics&lt;/h4&gt;  &lt;h5&gt;08 September 2009&lt;/h5&gt;  &lt;p&gt;Brazil’s Superior Electoral Court (TSE) has selected &lt;a href="http://www.supremainc.com/eng/main.php"&gt;Suprema’s&lt;/a&gt; RealScan-D live scanner for nationwide biometric voter registration.&lt;/p&gt;  &lt;p&gt;The RealScan-D live scanner is a portable, USB-powered device designed for bundling with mobile jump-kits when used at voter registration and voting sites.&lt;/p&gt;  &lt;p&gt;Suprema says TSE’s voter biometric identification programme aims to protect citizen’s voting rights by preventing any possible frauds. &lt;/p&gt;  &lt;p&gt;According to TSE, the Brazilian government aims to implement biometric voting system to all states to enhance its consolidation of citizens’ rights. &lt;/p&gt;  &lt;p&gt;“We are very proud of the order from TSE as it is the world’s largest fingerprint registration system for voting,” says Ismael Akiyama, CEO at Akiyama Technologia, Suprema’s local partner in Brazil.&lt;/p&gt;  &lt;p&gt;Suprema has also recently won government projects in Slovenia, Japan and Mexico for criminal and public ID applications.&lt;/p&gt;  &lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:29516028-d5a9-4a3a-b1e3-e26fe11c1495" class="wlWriterEditableSmartContent"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/Brazil" rel="tag"&gt;Brazil&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Superior+Electoral+Court" rel="tag"&gt;Superior Electoral Court&lt;/a&gt;,&lt;a href="http://technorati.com/tags/TSE" rel="tag"&gt;TSE&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Suprema" rel="tag"&gt;Suprema&lt;/a&gt;,&lt;a href="http://technorati.com/tags/RealScan-D" rel="tag"&gt;RealScan-D&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Michael+Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=L8LE7X_7CJ4:IVllsHQXbyE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=L8LE7X_7CJ4:IVllsHQXbyE:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=L8LE7X_7CJ4:IVllsHQXbyE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=L8LE7X_7CJ4:IVllsHQXbyE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=L8LE7X_7CJ4:IVllsHQXbyE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=L8LE7X_7CJ4:IVllsHQXbyE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=L8LE7X_7CJ4:IVllsHQXbyE:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=L8LE7X_7CJ4:IVllsHQXbyE:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=L8LE7X_7CJ4:IVllsHQXbyE:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=L8LE7X_7CJ4:IVllsHQXbyE:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=L8LE7X_7CJ4:IVllsHQXbyE:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2009/09/brazil-votes-on-biometrics.html</feedburner:origLink></entry>
    <entry>
        <title>I see youre gangsta  tattoos, biometrics, and the police</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/GOgZ91UndOg/i-see-youre-gangsta-tattoos-biometrics-and-the-police.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2009/06/i-see-youre-gangsta-tattoos-biometrics-and-the-police.html" thr:count="1" thr:updated="2009-07-22T08:49:54-05:00" />
        <id>tag:typepad.com,2003:post-68247653</id>
        <published>2009-06-18T12:20:23-05:00</published>
        <updated>2009-06-18T12:20:23-05:00</updated>
        <summary type="html">A gangster's main method of creativity and self-expression is becoming increasingly detrimental to their freedom. Law enforcement agencies have long used any means of verifiable markings to link a suspect to eyewitness accounts of crimes. As a fairly permanent and...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">&lt;p&gt;A gangster's &lt;a href="http://www.gangink.com/" target="_blank"&gt;main method&lt;/a&gt; of creativity and self-expression is becoming increasingly detrimental to their &lt;a href="http://www.allposters.com/-sp/I-Noticed-That-You-re-Gangster-I-m-Pretty-Gangster-Myself-Posters_i2357443_.htm" target="_blank"&gt;freedom&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;Law enforcement agencies have long used any means of verifiable markings to link a suspect to eyewitness accounts of crimes. As a fairly permanent and distinct marker in identifying an individual, tattoos have been an invaluable tool in pursuing “persons of interest” over the years. &lt;/p&gt;  &lt;p&gt;                        &lt;a href="http://securityblog.typepad.com/.a/6a00d83453a4e869e201157128c89b970b-pi"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="i_m_gangsta" border="0" alt="i_m_gangsta" src="http://securityblog.typepad.com/.a/6a00d83453a4e869e201157128c8a5970b-pi" width="244" height="167"&gt;&lt;/img&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Now, science has brought us a tool to help the process of searching through databases of thousands of tattoos to find that special someone, that much easier and quicker.&lt;/p&gt;  &lt;p&gt;Enter &lt;a href="http://spie.org/x35455.xml?highlight=x2412&amp;amp;ArticleID=x35455" target="_blank"&gt;Tattoo-ID&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;Anil Jain and Jung-Eun Lee of Michigan State University’s Department of Computer Science and Engineering have developed a new methodology to categorizing and identifying scars, marks, and tattoos (SMTs). They have labeled the new process Tattoo-ID and believe that it will help law enforcement agencies more accurately and quickly link an SMT with the individual they are interested in. &lt;/p&gt;  &lt;p&gt;Currently, law enforcement agencies use the standards for SMT classification as stated by &lt;a href="http://fingerprint.nist.gov/standard/" target="_blank"&gt;ANSI/NIST-ITL 1-2007&lt;/a&gt;. Which, according to Mr. Jain and Mr. Lee, is subjective, time-consuming, and is not scalable to meet the rapid growth in tattoo design.&lt;/p&gt;  &lt;p&gt;With Tattoo-ID, the researchers believe their method can meet the needs of SMT identification as the needs of law enforcement grows.&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Our approach is one of content-based image retrieval using features (e.g., color, shape, and texture), instead of labels or keywords, to compute the similarity between two images.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Currently the program is seeing 835 out of 1000 images correctly identified with the first attempt out of a database of 64,000.&lt;/p&gt;  &lt;p&gt;Although blurred images and low quality image sources create lower success rates, Mr. Jain and Mr. Lee feel that by tweaking their current process and with the addition of new algorithms in their software, the tool will be able to resolve a larger number of SMTs quicker and more accurately, with even larger image databases.&lt;/p&gt;  &lt;p&gt;Michael Mongold&lt;/p&gt;  &lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:6febe938-9f1f-47a4-b29e-e715999b1294" class="wlWriterEditableSmartContent"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/Gangster" rel="tag"&gt;Gangster&lt;/a&gt;,&lt;a href="http://technorati.com/tags/tattoo" rel="tag"&gt;tattoo&lt;/a&gt;,&lt;a href="http://technorati.com/tags/police" rel="tag"&gt;police&lt;/a&gt;,&lt;a href="http://technorati.com/tags/law+enforcement" rel="tag"&gt;law enforcement&lt;/a&gt;,&lt;a href="http://technorati.com/tags/agencies" rel="tag"&gt;agencies&lt;/a&gt;,&lt;a href="http://technorati.com/tags/michael+mongold" rel="tag"&gt;michael mongold&lt;/a&gt;,&lt;a href="http://technorati.com/tags/SMT" rel="tag"&gt;SMT&lt;/a&gt;,&lt;a href="http://technorati.com/tags/michigan+state+university" rel="tag"&gt;michigan state university&lt;/a&gt;,&lt;a href="http://technorati.com/tags/anil+jain" rel="tag"&gt;anil jain&lt;/a&gt;,&lt;a href="http://technorati.com/tags/jung-eun+lee" rel="tag"&gt;jung-eun lee&lt;/a&gt;,&lt;a href="http://technorati.com/tags/scar" rel="tag"&gt;scar&lt;/a&gt;,&lt;a href="http://technorati.com/tags/mark" rel="tag"&gt;mark&lt;/a&gt;,&lt;a href="http://technorati.com/tags/biometric" rel="tag"&gt;biometric&lt;/a&gt;,&lt;a href="http://technorati.com/tags/identification" rel="tag"&gt;identification&lt;/a&gt;,&lt;a href="http://technorati.com/tags/suspect" rel="tag"&gt;suspect&lt;/a&gt;,&lt;a href="http://technorati.com/tags/victim" rel="tag"&gt;victim&lt;/a&gt;,&lt;a href="http://technorati.com/tags/ANSI" rel="tag"&gt;ANSI&lt;/a&gt;,&lt;a href="http://technorati.com/tags/NIST" rel="tag"&gt;NIST&lt;/a&gt;,&lt;a href="http://technorati.com/tags/ITL" rel="tag"&gt;ITL&lt;/a&gt;,&lt;a href="http://technorati.com/tags/1-2007" rel="tag"&gt;1-2007&lt;/a&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=GOgZ91UndOg:CxgT1bLfQ9s:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=GOgZ91UndOg:CxgT1bLfQ9s:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=GOgZ91UndOg:CxgT1bLfQ9s:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=GOgZ91UndOg:CxgT1bLfQ9s:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=GOgZ91UndOg:CxgT1bLfQ9s:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=GOgZ91UndOg:CxgT1bLfQ9s:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=GOgZ91UndOg:CxgT1bLfQ9s:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=GOgZ91UndOg:CxgT1bLfQ9s:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=GOgZ91UndOg:CxgT1bLfQ9s:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=GOgZ91UndOg:CxgT1bLfQ9s:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=GOgZ91UndOg:CxgT1bLfQ9s:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2009/06/i-see-youre-gangsta-tattoos-biometrics-and-the-police.html</feedburner:origLink></entry>
    <entry>
        <title>Lxlabs head commits suicide</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/IpIy9-Jxa3Q/lx-labs-head-commits-suicide.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2009/06/lx-labs-head-commits-suicide.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-67941923</id>
        <published>2009-06-10T12:05:03-05:00</published>
        <updated>2009-06-10T12:14:49-05:00</updated>
        <summary type="html">Sadly, the CTO and founder of Lxlabs was discovered dead in his home in Bangalore Monday morning, from an apparent suicide. As reported in The Times of India, K T Ligesh,32, was found by a friend, hanging in his room....</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">&lt;p&gt;Sadly, the CTO and founder of Lxlabs was discovered dead in his home in Bangalore Monday morning, from an apparent suicide. As reported in &lt;a href="http://timesofindia.indiatimes.com/Bangalore/Techie-hangs-himself-in-HSR-Layout-/articleshow/4633101.cms" target="_blank"&gt;The Times of India&lt;/a&gt;, K T Ligesh,32, was found by a friend, hanging in his room.&lt;/p&gt;  &lt;p&gt;As I discussed &lt;a href="http://securityblog.typepad.com/technology_security/2009/06/webhost-hacked-vm-vulnerability.html" target="_blank"&gt;yesterday&lt;/a&gt;, up to 100,000 websites had been erased due to a vulnerability in &lt;a href="http://lxlabs.com/" target="_blank"&gt;Lxlabs&lt;/a&gt;’ software at webhost provider, &lt;a href="http://www.vaserv.com/" target="_blank"&gt;VAServ&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;According to various reports, Mr. Ligesh was deeply agitated over recently losing a project to another company, as well as living with the loss of both his sister and mother a few years ago to suicide by hanging. &lt;/p&gt;  &lt;p&gt;Despite what other contributing factors may be at play in Mr. Ligesh’s decision to take his own life, it cannot be clearer that the actions of the hackers that attacked VAServ’s websites played a significant role in this tragedy.&lt;/p&gt;  &lt;p&gt;I assume the criminals that infiltrated VAServ’s infrastructure and destroyed the efforts of so many; that created so much anxiety and distress and then caused untold financial damages – that they never really MEANT for someone to die either directly or indirectly from their actions. But it doesn’t really matter, the results of unintended consequences are always just as bad as as the results of those that are intended. They are still a product of someone’s actions or inactions and they are still responsible (if even just partially). &lt;/p&gt;  &lt;p&gt;Unfortunately, knowing how often hackers are brought to justice, we can also assume that this wrong will never be righted. RIP K T Ligesh&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=IpIy9-Jxa3Q:L3DtzT1Sn0I:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=IpIy9-Jxa3Q:L3DtzT1Sn0I:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=IpIy9-Jxa3Q:L3DtzT1Sn0I:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=IpIy9-Jxa3Q:L3DtzT1Sn0I:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=IpIy9-Jxa3Q:L3DtzT1Sn0I:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=IpIy9-Jxa3Q:L3DtzT1Sn0I:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=IpIy9-Jxa3Q:L3DtzT1Sn0I:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=IpIy9-Jxa3Q:L3DtzT1Sn0I:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=IpIy9-Jxa3Q:L3DtzT1Sn0I:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=IpIy9-Jxa3Q:L3DtzT1Sn0I:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=IpIy9-Jxa3Q:L3DtzT1Sn0I:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2009/06/lx-labs-head-commits-suicide.html</feedburner:origLink></entry>
    <entry>
        <title>Webhost hacked  VM vulnerability blamed</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/gSlRtMaSJDA/webhost-hacked-vm-vulnerability.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2009/06/webhost-hacked-vm-vulnerability.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-67895037</id>
        <published>2009-06-09T09:58:48-05:00</published>
        <updated>2009-06-09T10:00:03-05:00</updated>
        <summary type="html">According to the Register, a hacker attacked a Webhosting company’s virtual server infrastructure on Sunday and erased up to 100,000 sites. Vaserv.com was hit by a calculated attack on its virtualization application which left roughly half of Vaserv’s customer without...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">&lt;p&gt;According to the &lt;a href="http://www.theregister.co.uk/2009/06/08/webhost_attack/" target="_blank"&gt;Register&lt;/a&gt;, a hacker attacked a Webhosting company’s virtual server infrastructure on Sunday and erased up to 100,000 sites. &lt;/p&gt;  &lt;p&gt;Vaserv.com was hit by a calculated attack on its virtualization application which left roughly half of Vaserv’s customer without a website.&lt;/p&gt;  &lt;p&gt;Rus Foster, a director at Vaserv, stated that &lt;a href="http://lxlabs.com/" target="_blank"&gt;LXLabs&lt;/a&gt;’s &lt;a href="http://lxlabs.com/software/hypervm/" target="_blank"&gt;HyperVM&lt;/a&gt; had been compromised during a zero-day exploit. They are currently trying to reach LXLabs to find a solution.&lt;/p&gt;  &lt;p&gt;Visiting Vaserv’s website show’s an organization in full triage/crisis mode.&lt;/p&gt;  &lt;p&gt;At the time of this writing, Vaserv’s &lt;a href="http://www.vaserv.com/" target="_blank"&gt;site&lt;/a&gt; is just a text document showing the status of their server recovery progress (or lack thereof). &lt;/p&gt;  &lt;p&gt;&lt;a href="http://securityblog.typepad.com/.a/6a00d83453a4e869e201156fefe065970c-pi"&gt;&lt;img title="vaserv" style="border-top-width: 0px; display: inline; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="289" alt="vaserv" src="http://securityblog.typepad.com/.a/6a00d83453a4e869e2011570e4b959970b-pi" width="475" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Pretty tough times as an administrator (both for a system and web admin). &lt;/p&gt;  &lt;p&gt;A very thin but important silver lining is the encryption Vaserv implemented that allowed them to keep the actual data from being usable by the hacker(s).&lt;/p&gt;  &lt;p&gt;Ultimately, this shows me two things: &lt;/p&gt;  &lt;p&gt;1) How organizations’ reliances on VMs have created a keystone in the arch where a hacker can pinpoint their attacks to reach maximum destructiveness. If a hacker wants to access data for the sake of profit, they go after the database. Alternatively, if they want to go for destructiveness, they can vector in on the VM infrastructure. &lt;/p&gt;  &lt;p&gt;VMs are a business reality for large organizations which must rely on fewer physical machines that hold far more virtual servers running many more services. Ultimately this allows enterprises to leverage their rack space more efficiently, but creates a more appealing and concentrated target for people bent on mayhem. Thus, as this VM-reality matures in the TecSec community, the strength and security of the VM infrastructure itself becomes exponentially more important. &lt;/p&gt;  &lt;p&gt;In the past, we’ve had to worry about the OS and the applications within it but now we must be concerned with the layer that manages the operating systems themselves. No doubt all webhosting companies are going to re-evaluate their VM security posture as news of this spreads. &lt;em&gt;As for the TecSec community at large, we will need to pay closer attention to what risks VMs pose from motivated individuals.&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;and 2) How incredibly malicious hackers can be. At one time, there was the idea that someone would deface a site to make a statement or to show a webmaster his site was vulnerable. Wiping out 100,000 websites, however, is beyond explanation.&lt;/p&gt;  &lt;p&gt;Michael Mongold&lt;/p&gt;  &lt;div class="wlWriterEditableSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:498a3cfa-9362-4d10-9b3e-c84af6e7d156" style="padding-right: 0px; display: inline; padding-left: 0px; float: none; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;del.icio.us Tags: &lt;a href="http://del.icio.us/popular/Rus+Foster" rel="tag"&gt;Rus Foster&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/LXLabs" rel="tag"&gt;LXLabs&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/HyperVM" rel="tag"&gt;HyperVM&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/webhosting" rel="tag"&gt;webhosting&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/hacker" rel="tag"&gt;hacker&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/attack" rel="tag"&gt;attack&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/virtual+machine" rel="tag"&gt;virtual machine&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/vm" rel="tag"&gt;vm&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/tecsec" rel="tag"&gt;tecsec&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/michael+mongold" rel="tag"&gt;michael mongold&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/website" rel="tag"&gt;website&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/Register" rel="tag"&gt;Register&lt;/a&gt;&lt;/div&gt;  &lt;div class="wlWriterEditableSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:26f33dd9-30cb-41d3-bae5-1dc58c84d23d" style="padding-right: 0px; display: inline; padding-left: 0px; float: none; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/Rus+Foster" rel="tag"&gt;Rus Foster&lt;/a&gt;,&lt;a href="http://technorati.com/tags/LXLabs" rel="tag"&gt;LXLabs&lt;/a&gt;,&lt;a href="http://technorati.com/tags/HyperVM" rel="tag"&gt;HyperVM&lt;/a&gt;,&lt;a href="http://technorati.com/tags/webhosting" rel="tag"&gt;webhosting&lt;/a&gt;,&lt;a href="http://technorati.com/tags/hacker" rel="tag"&gt;hacker&lt;/a&gt;,&lt;a href="http://technorati.com/tags/attack" rel="tag"&gt;attack&lt;/a&gt;,&lt;a href="http://technorati.com/tags/virtual+machine" rel="tag"&gt;virtual machine&lt;/a&gt;,&lt;a href="http://technorati.com/tags/vm" rel="tag"&gt;vm&lt;/a&gt;,&lt;a href="http://technorati.com/tags/tecsec" rel="tag"&gt;tecsec&lt;/a&gt;,&lt;a href="http://technorati.com/tags/michael+mongold" rel="tag"&gt;michael mongold&lt;/a&gt;,&lt;a href="http://technorati.com/tags/website" rel="tag"&gt;website&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Register" rel="tag"&gt;Register&lt;/a&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=gSlRtMaSJDA:gfp6tIHw9EY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=gSlRtMaSJDA:gfp6tIHw9EY:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=gSlRtMaSJDA:gfp6tIHw9EY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=gSlRtMaSJDA:gfp6tIHw9EY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=gSlRtMaSJDA:gfp6tIHw9EY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=gSlRtMaSJDA:gfp6tIHw9EY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=gSlRtMaSJDA:gfp6tIHw9EY:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=gSlRtMaSJDA:gfp6tIHw9EY:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=gSlRtMaSJDA:gfp6tIHw9EY:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=gSlRtMaSJDA:gfp6tIHw9EY:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=gSlRtMaSJDA:gfp6tIHw9EY:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2009/06/webhost-hacked-vm-vulnerability.html</feedburner:origLink></entry>
    <entry>
        <title>Virginia Patients at Risk</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/Nj0L5o_dyGU/virginia-patients-at-risk.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2009/06/virginia-patients-at-risk.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-67873589</id>
        <published>2009-06-08T18:29:47-05:00</published>
        <updated>2009-06-08T18:29:47-05:00</updated>
        <summary type="html">Known: a hacker gained access to the Virginia Prescription Monitoring Program and then asked for a ransom of $10 million. According to The Virginian-Pilot, the following is also known: The database contains records of more than 35 million prescriptions dispensed...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">&lt;p&gt;                      &lt;a href="http://securityblog.typepad.com/.a/6a00d83453a4e869e201156fe7db74970c-pi"&gt;&lt;img title="idtheft" style="border-top-width: 0px; display: inline; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="163" alt="idtheft" src="http://securityblog.typepad.com/.a/6a00d83453a4e869e2011570dcb692970b-pi" width="244" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Known: a hacker gained access to the Virginia Prescription Monitoring Program and then asked for a ransom of $10 million. According to &lt;a href="http://hamptonroads.com/2009/06/officials-hacker-may-have-stolen-social-security-numbers" target="_blank"&gt;The Virginian-Pilot&lt;/a&gt;, the following is also known: &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;The database contains records of more than 35 million prescriptions dispensed since 2006 for certain federally controlled drugs with a high potential for abuse, such as OxyContin, Vicodin and Xanax.&lt;/p&gt;    &lt;p&gt;The records include patients' name, address and date of birth, the name and quantity of the drug prescribed, and identifying numbers for the doctor and pharmacist.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;What is unknown, is if the hacker gained access to the customer’s social security numbers which were placed along side many of the customer’s pharmacy records. Throw in 1,400 or so doctors and pharmacists that entered their social security numbers and you have the potential for a real mess. &lt;/p&gt;  &lt;p&gt;Also, unknown is if the database was encrypted. The hacker stated that he had copied the database and deleted the commonwealth’s backups of the database although Virginia claims to still have access to its backups&lt;/p&gt;  &lt;p&gt;One thing is for certain, some administrator is hating their life right now while they have to explain why 530,000 patients must now watch their credit report and bank accounts more diligently than ever. &lt;/p&gt;  &lt;p&gt;Finally, there is the irony where the Roanoke Times &lt;a href="http://www.roanoke.com/news/roanoke/wb/204492" target="_blank"&gt;reports&lt;/a&gt; that:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;…lawmakers were told that the VDHP ranked in the top 5 percent of state agencies in an audit of information security. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Not the most confidence-inspiring statement the state could make.&lt;/p&gt;  &lt;p&gt;Databases are ultimately one of the great prizes for hackers. In one fell swoop they can acquire more data than if they stole 100,000 laptops. This is an excellent example why database security and encryption should be paramount for any organization that stores sensitive information. Way to learn one the hard way, Virginia.&lt;/p&gt;  &lt;p&gt;Michael Mongold&lt;/p&gt;  &lt;div class="wlWriterEditableSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:cb3c6947-c504-4f7a-8a85-40ca01a75c5a" style="padding-right: 0px; display: inline; padding-left: 0px; float: none; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;del.icio.us Tags: &lt;a href="http://del.icio.us/popular/Virginia+Department+of+Health+Professions" rel="tag"&gt;Virginia Department of Health Professions&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/hacker" rel="tag"&gt;hacker&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/Virginia+Prescription+Monitoring+Program" rel="tag"&gt;Virginia Prescription Monitoring Program&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/Michael+Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/theft" rel="tag"&gt;theft&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/data" rel="tag"&gt;data&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/encryption" rel="tag"&gt;encryption&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/database" rel="tag"&gt;database&lt;/a&gt;&lt;/div&gt;  &lt;div class="wlWriterEditableSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:6e756549-6834-4a48-93f3-1a01ee4ef2ed" style="padding-right: 0px; display: inline; padding-left: 0px; float: none; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/Virginia+Department+of+Health+Professions" rel="tag"&gt;Virginia Department of Health Professions&lt;/a&gt;,&lt;a href="http://technorati.com/tags/hacker" rel="tag"&gt;hacker&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Virginia+Prescription+Monitoring+Program" rel="tag"&gt;Virginia Prescription Monitoring Program&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Michael+Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;,&lt;a href="http://technorati.com/tags/theft" rel="tag"&gt;theft&lt;/a&gt;,&lt;a href="http://technorati.com/tags/data" rel="tag"&gt;data&lt;/a&gt;,&lt;a href="http://technorati.com/tags/encryption" rel="tag"&gt;encryption&lt;/a&gt;,&lt;a href="http://technorati.com/tags/database" rel="tag"&gt;database&lt;/a&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=Nj0L5o_dyGU:dyBi3N8DHzE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=Nj0L5o_dyGU:dyBi3N8DHzE:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=Nj0L5o_dyGU:dyBi3N8DHzE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=Nj0L5o_dyGU:dyBi3N8DHzE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=Nj0L5o_dyGU:dyBi3N8DHzE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=Nj0L5o_dyGU:dyBi3N8DHzE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=Nj0L5o_dyGU:dyBi3N8DHzE:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=Nj0L5o_dyGU:dyBi3N8DHzE:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=Nj0L5o_dyGU:dyBi3N8DHzE:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=Nj0L5o_dyGU:dyBi3N8DHzE:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=Nj0L5o_dyGU:dyBi3N8DHzE:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2009/06/virginia-patients-at-risk.html</feedburner:origLink></entry>
    <entry>
        <title>Security enhancement for iPhone = Find My iPhone</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/pEm-k4W72RI/security-enhancement-for-iphone-find-my-iphone.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2009/06/security-enhancement-for-iphone-find-my-iphone.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-67853871</id>
        <published>2009-06-08T13:54:26-05:00</published>
        <updated>2009-06-08T13:54:26-05:00</updated>
        <summary type="html">For those who have been pushing their company to adopt the iPhone as a business device, at least now you can present the security argument as a little stronger. A few minutes ago, Apple unveiled at WWDC a remote wipe...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">&lt;p&gt;For those who have been pushing their company to adopt the iPhone as a business device, at least now you can present the security argument as a little stronger. &lt;/p&gt;  &lt;p&gt;                                        &lt;a href="http://securityblog.typepad.com/.a/6a00d83453a4e869e201156fe5f81e970c-pi"&gt;&lt;img title="iphone1" style="border-right: 0px; border-top: 0px; display: inline; border-left: 0px; border-bottom: 0px" height="240" alt="iphone1" src="http://securityblog.typepad.com/.a/6a00d83453a4e869e201156fe5f823970c-pi" width="128" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;A few minutes ago, Apple unveiled at WWDC a remote wipe feature through its new ‘Find My iPhone” application.&lt;/p&gt;  &lt;p&gt;In addition to allowing you to remotely erase your iPhone (something available on other devices for some time now), you can also view where your iPhone is on a map, make your iPhone beep so that you can locate it (even if it is in ‘silent mode’), AND display a message to the person who &lt;strike&gt;stole&lt;/strike&gt; found your phone. Perhaps something like “I know you have my iPhone, I know where you’re at – I’m coming to get it”. &lt;/p&gt;  &lt;p&gt;The catch? You must subscribe to Apple’s MobileMe service to have access to the ‘Find My iPhone” features. Still, for companies who have potentially sensitive data stored on their iPhone, this becomes a no-brainer.&lt;/p&gt;  &lt;p&gt;Michael Mongold&lt;/p&gt;  &lt;div class="wlWriterEditableSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:96b62123-75da-45f8-8de1-08f75639cd7b" style="padding-right: 0px; display: inline; padding-left: 0px; float: none; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;del.icio.us Tags: &lt;a href="http://del.icio.us/popular/Apple" rel="tag"&gt;Apple&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/iPhone" rel="tag"&gt;iPhone&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/Find+My+iPhone" rel="tag"&gt;Find My iPhone&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/MobileMe" rel="tag"&gt;MobileMe&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/Michael+Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/WWDC" rel="tag"&gt;WWDC&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/application" rel="tag"&gt;application&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/remote+wipe" rel="tag"&gt;remote wipe&lt;/a&gt;&lt;/div&gt;  &lt;div class="wlWriterEditableSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:1a6bc925-d223-4083-9156-358d5ae9f807" style="padding-right: 0px; display: inline; padding-left: 0px; float: none; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/Apple" rel="tag"&gt;Apple&lt;/a&gt;,&lt;a href="http://technorati.com/tags/iPhone" rel="tag"&gt;iPhone&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Find+My+iPhone" rel="tag"&gt;Find My iPhone&lt;/a&gt;,&lt;a href="http://technorati.com/tags/MobileMe" rel="tag"&gt;MobileMe&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Michael+Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;,&lt;a href="http://technorati.com/tags/WWDC" rel="tag"&gt;WWDC&lt;/a&gt;,&lt;a href="http://technorati.com/tags/application" rel="tag"&gt;application&lt;/a&gt;,&lt;a href="http://technorati.com/tags/remote+wipe" rel="tag"&gt;remote wipe&lt;/a&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=pEm-k4W72RI:AywVf3MRi-o:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=pEm-k4W72RI:AywVf3MRi-o:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=pEm-k4W72RI:AywVf3MRi-o:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=pEm-k4W72RI:AywVf3MRi-o:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=pEm-k4W72RI:AywVf3MRi-o:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=pEm-k4W72RI:AywVf3MRi-o:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=pEm-k4W72RI:AywVf3MRi-o:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=pEm-k4W72RI:AywVf3MRi-o:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=pEm-k4W72RI:AywVf3MRi-o:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=pEm-k4W72RI:AywVf3MRi-o:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=pEm-k4W72RI:AywVf3MRi-o:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2009/06/security-enhancement-for-iphone-find-my-iphone.html</feedburner:origLink></entry>
    <entry>
        <title>Worst ISP in the US = Pricewert</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/8St97vdaIuk/worst-isp-in-the-us-pricewert.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2009/06/worst-isp-in-the-us-pricewert.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-67850923</id>
        <published>2009-06-08T13:12:31-05:00</published>
        <updated>2009-06-08T13:57:18-05:00</updated>
        <summary type="html">Well, that’s according to the FTC who shut their connectivity off late last week. And if their claims are accurate, I believe they have a pretty good case for giving Pricewert the title. According to the FTC’s press release, Pricewert...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">&lt;p&gt;Well, that’s according to the FTC who shut their connectivity off late last week. And if their claims are accurate, I believe they have a pretty good case for giving Pricewert the title. &lt;/p&gt;  &lt;p&gt;                     &lt;a href="http://securityblog.typepad.com/.a/6a00d83453a4e869e201156fe5a0e7970c-pi"&gt;&lt;img title="evil-monkey" style="border-top-width: 0px; display: inline; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="223" alt="evil-monkey" src="http://securityblog.typepad.com/.a/6a00d83453a4e869e201156fe5a0fc970c-pi" width="244" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;According to the FTC’s &lt;a href="http://www.ftc.gov/opa/2009/06/3fn.shtm" target="_blank"&gt;press release&lt;/a&gt;, Pricewert (AKA 3FN, APS Telecom, among others), knowingly hosted child pornography, malware, and spam servers which were responsible for depositing trojan horses, viruses, spyware, phishing attacks, botnet cnc servers, as well as numerous additional web sites with illegal material on them.&lt;/p&gt;  &lt;p&gt;If you have ever wondered why a website can exist that can do so much damage or why spam servers can clog your e-mail with so much time/money wasting data or where the truly bad/sick people on the web go for their disease, this is it. &lt;/p&gt;  &lt;p&gt;The claim states that by ignoring security groups’ notices to disconnect the offending sites and by frequently changing the source IP address of the servers, Pricewert was able to provide criminals a safe haven on the web.&lt;/p&gt;  &lt;p&gt;If the allegations are true, let’s hope that the government doesn’t wait so long next time to find organizations like this on the web and shut down this conduit of crime and filth.&lt;/p&gt;  &lt;p&gt;Michael Mongold&lt;/p&gt;  &lt;div class="wlWriterEditableSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:eca9128e-74c2-40dd-8c3c-44061c7c9ed4" style="padding-right: 0px; display: inline; padding-left: 0px; float: none; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/FTC" rel="tag"&gt;FTC&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Pricewert" rel="tag"&gt;Pricewert&lt;/a&gt;,&lt;a href="http://technorati.com/tags/3FN" rel="tag"&gt;3FN&lt;/a&gt;,&lt;a href="http://technorati.com/tags/APS+Telecom" rel="tag"&gt;APS Telecom&lt;/a&gt;,&lt;a href="http://technorati.com/tags/IPS" rel="tag"&gt;IPS&lt;/a&gt;,&lt;a href="http://technorati.com/tags/trojan" rel="tag"&gt;trojan&lt;/a&gt;,&lt;a href="http://technorati.com/tags/viruses" rel="tag"&gt;viruses&lt;/a&gt;,&lt;a href="http://technorati.com/tags/botnet" rel="tag"&gt;botnet&lt;/a&gt;,&lt;a href="http://technorati.com/tags/phishing" rel="tag"&gt;phishing&lt;/a&gt;,&lt;a href="http://technorati.com/tags/spyware" rel="tag"&gt;spyware&lt;/a&gt;,&lt;a href="http://technorati.com/tags/illegal" rel="tag"&gt;illegal&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Federal+Trade+Commission" rel="tag"&gt;Federal Trade Commission&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Michael+Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;&lt;/div&gt;  &lt;div class="wlWriterEditableSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:23bc6a92-0be4-4102-8682-d57af2531563" style="padding-right: 0px; display: inline; padding-left: 0px; float: none; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;del.icio.us Tags: &lt;a href="http://del.icio.us/popular/FTC" rel="tag"&gt;FTC&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/Pricewert" rel="tag"&gt;Pricewert&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/3FN" rel="tag"&gt;3FN&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/APS+Telecom" rel="tag"&gt;APS Telecom&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/IPS" rel="tag"&gt;IPS&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/trojan" rel="tag"&gt;trojan&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/viruses" rel="tag"&gt;viruses&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/botnet" rel="tag"&gt;botnet&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/phishing" rel="tag"&gt;phishing&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/spyware" rel="tag"&gt;spyware&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/illegal" rel="tag"&gt;illegal&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/Federal+Trade+Commission" rel="tag"&gt;Federal Trade Commission&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/Michael+Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=8St97vdaIuk:0t-8Y2dDS-8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=8St97vdaIuk:0t-8Y2dDS-8:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=8St97vdaIuk:0t-8Y2dDS-8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=8St97vdaIuk:0t-8Y2dDS-8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=8St97vdaIuk:0t-8Y2dDS-8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=8St97vdaIuk:0t-8Y2dDS-8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=8St97vdaIuk:0t-8Y2dDS-8:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=8St97vdaIuk:0t-8Y2dDS-8:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=8St97vdaIuk:0t-8Y2dDS-8:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=8St97vdaIuk:0t-8Y2dDS-8:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=8St97vdaIuk:0t-8Y2dDS-8:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2009/06/worst-isp-in-the-us-pricewert.html</feedburner:origLink></entry>
    <entry>
        <title>Smart Cards are not rocket science</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/hdfxJPa8uXQ/smart-cards-are-not-rocket-science.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2009/06/smart-cards-are-not-rocket-science.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-67625813</id>
        <published>2009-06-04T08:53:09-05:00</published>
        <updated>2009-06-04T09:04:51-05:00</updated>
        <summary type="html">NASA may have to reissue more than 70,000 smart cards that have been provided to NASA employees over the past three years due to security concerns. Prior to the Homeland Security Presidential Directive 12 (HSPD-12) mandate for a Personal Identity...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">&lt;p&gt;&lt;a href="http://www.nasa.gov/" target="_blank"&gt;NASA&lt;/a&gt; may have to reissue more than 70,000 smart cards that have been provided to NASA employees over the past three years due to security concerns.&lt;/p&gt;  &lt;p&gt;                    &lt;a href="http://securityblog.typepad.com/.a/6a00d83453a4e869e2011570bed2a5970b-pi"&gt;&lt;img title="NasaLogo" style="border-top-width: 0px; display: inline; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="203" alt="NasaLogo" src="http://securityblog.typepad.com/.a/6a00d83453a4e869e201156fc9996b970c-pi" width="244" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Prior to the &lt;a href="http://hspd12.usda.gov/" target="_blank"&gt;Homeland Security Presidential Directive 12 (HSPD-12)&lt;/a&gt; mandate for a &lt;a href="http://csrc.nist.gov/groups/SNS/piv/index.html" target="_blank"&gt;Personal Identity Verification (PIV)&lt;/a&gt; card, NASA was in the process of deploying their own common badging and access control system (CBACS) - as were a number of other agencies. However, according to a report filed by NASA’s &lt;a href="http://oig.nasa.gov/" target="_blank"&gt;Inspector General&lt;/a&gt;, they did not follow federal guidelines for insuring the proper transition and oversight from their own card implementation to the new PIV standards.&lt;/p&gt;  &lt;p&gt;Although the Inspector General’s office did not find that any cards had been distributed to individuals with inappropriate access, it leaves the door open for that possibility.&lt;/p&gt;  &lt;p&gt;At the heart of the issue is this:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“While NASA properly assessed the PIV card issuer for satisfaction of Federal requirements at both organization and facility levels, found deficiencies, and developed a corrective action plan in accordance with Federal guidance, the Agency did not monitor corrective actions to ensure that identified deficiencies were corrected nor initiate timely reassessment. If the reassessment of the PIV card issuer reveals that significant deficiencies continue to exist and those deficiencies affect the integrity of the PIV cards, NASA could be required to discontinue PIV card issuer operations and reissue its PIV cards, which we estimate could cost a minimum of $1 million.”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Ouch. And the audit did not even include Jet Propulsion Laboratories due to their own &lt;a href="http://www.spaceref.com/news/viewsr.html?pid=24134" target="_blank"&gt;PIV issues&lt;/a&gt;. &lt;/p&gt;  &lt;p&gt;Ultimately, if the Inspector General’s office is able to confirm that the credential provider’s failings persisted after NASA’s knowledge of them AND if it resulted in any inappropriate issuance – 98% of NASA’s employees will have to undergo the badging process again.&lt;/p&gt;  &lt;p&gt;For the Inspector General’s full report, click &lt;a href="http://www.hq.nasa.gov/office/oig/hq/audits/reports/FY09/IG-09-015.pdf" target="_blank"&gt;here&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Michael Mongold&lt;/p&gt;  &lt;div class="wlWriterEditableSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:209305b2-c331-4c0a-a461-b3e9fabb20be" style="padding-right: 0px; display: inline; padding-left: 0px; float: none; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;del.icio.us Tags: &lt;a href="http://del.icio.us/popular/NASA" rel="tag"&gt;NASA&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/PIV" rel="tag"&gt;PIV&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/HSPD-12" rel="tag"&gt;HSPD-12&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/JPL" rel="tag"&gt;JPL&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/Inspector+General" rel="tag"&gt;Inspector General&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/Michael+Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/CBAC" rel="tag"&gt;CBAC&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/Homeland+Security+Presidential+Directive" rel="tag"&gt;Homeland Security Presidential Directive&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/Personal+Identity+Verification" rel="tag"&gt;Personal Identity Verification&lt;/a&gt;&lt;/div&gt;  &lt;div class="wlWriterEditableSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:eac04e79-a496-489c-9a5a-a5c9a2a529bd" style="padding-right: 0px; display: inline; padding-left: 0px; float: none; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/NASA" rel="tag"&gt;NASA&lt;/a&gt;,&lt;a href="http://technorati.com/tags/PIV" rel="tag"&gt;PIV&lt;/a&gt;,&lt;a href="http://technorati.com/tags/HSPD-12" rel="tag"&gt;HSPD-12&lt;/a&gt;,&lt;a href="http://technorati.com/tags/JPL" rel="tag"&gt;JPL&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Inspector+General" rel="tag"&gt;Inspector General&lt;/a&gt;,&lt;a href="http://technorati.com/tags/CBAC" rel="tag"&gt;CBAC&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Michael+Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Homeland+Security+Presidential+Directive" rel="tag"&gt;Homeland Security Presidential Directive&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Personal+Identity+Verification" rel="tag"&gt;Personal Identity Verification&lt;/a&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=hdfxJPa8uXQ:4eHWeYPaucs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=hdfxJPa8uXQ:4eHWeYPaucs:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=hdfxJPa8uXQ:4eHWeYPaucs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=hdfxJPa8uXQ:4eHWeYPaucs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=hdfxJPa8uXQ:4eHWeYPaucs:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=hdfxJPa8uXQ:4eHWeYPaucs:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=hdfxJPa8uXQ:4eHWeYPaucs:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=hdfxJPa8uXQ:4eHWeYPaucs:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=hdfxJPa8uXQ:4eHWeYPaucs:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=hdfxJPa8uXQ:4eHWeYPaucs:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=hdfxJPa8uXQ:4eHWeYPaucs:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2009/06/smart-cards-are-not-rocket-science.html</feedburner:origLink></entry>
    <entry>
        <title>Congress set to impose biometric competition in airports</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/mRO6wX18jRo/congress-set-to-impose-biometric-competition-in-airports.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2009/06/congress-set-to-impose-biometric-competition-in-airports.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-67615947</id>
        <published>2009-06-04T00:50:02-05:00</published>
        <updated>2009-06-04T00:50:02-05:00</updated>
        <summary type="html">If it isn’t broke, don’t fix it – even if it could possibly save money. That’s what the airports are saying to congress now that legislation is before the House to revamp the biometric technology selection process at airports around...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">&lt;p&gt;If it isn’t broke, don’t fix it – even if it could possibly save money. That’s what the airports are saying to congress now that legislation is before the House to revamp the biometric technology selection process at airports &lt;/p&gt;  &lt;p&gt;                     &lt;a href="http://securityblog.typepad.com/.a/6a00d83453a4e869e2011570bdc1e8970b-pi"&gt;&lt;img title="tsa-logo" style="border-top-width: 0px; display: inline; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="241" alt="tsa-logo" src="http://securityblog.typepad.com/.a/6a00d83453a4e869e2011570bdc1f4970b-pi" width="244" border="0"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;around the country. I feel for the airports, since they seem to have a system in place that they like and on the face of it, is relatively inexpensive. However, I’m sure there is a number of access solution providers that are eager to take a stab at winning the business. &lt;a href="http://washingtontechnology.com/articles/2009/06/03/congress-urged-not-to-disrupt-tsa-biometrics-work.aspx" target="_blank"&gt;Here’s the whole story&lt;/a&gt;… {via &lt;a href="http://washingtontechnology.com/Home.aspx" target="_blank"&gt;Washington Technology&lt;/a&gt;}&lt;/p&gt;  &lt;div class="wlWriterEditableSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:298c8762-4054-44bd-9ea6-296d9e950f65" style="padding-right: 0px; display: inline; padding-left: 0px; float: none; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/tsa" rel="tag"&gt;tsa&lt;/a&gt;,&lt;a href="http://technorati.com/tags/airport" rel="tag"&gt;airport&lt;/a&gt;,&lt;a href="http://technorati.com/tags/biometric" rel="tag"&gt;biometric&lt;/a&gt;,&lt;a href="http://technorati.com/tags/technology" rel="tag"&gt;technology&lt;/a&gt;,&lt;a href="http://technorati.com/tags/michael+mongold" rel="tag"&gt;michael mongold&lt;/a&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=mRO6wX18jRo:O18hGiyoknU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=mRO6wX18jRo:O18hGiyoknU:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=mRO6wX18jRo:O18hGiyoknU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=mRO6wX18jRo:O18hGiyoknU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=mRO6wX18jRo:O18hGiyoknU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=mRO6wX18jRo:O18hGiyoknU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=mRO6wX18jRo:O18hGiyoknU:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=mRO6wX18jRo:O18hGiyoknU:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=mRO6wX18jRo:O18hGiyoknU:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=mRO6wX18jRo:O18hGiyoknU:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=mRO6wX18jRo:O18hGiyoknU:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2009/06/congress-set-to-impose-biometric-competition-in-airports.html</feedburner:origLink></entry>
    <entry>
        <title>Clean Security Bill of Health?</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/v_cKen5cn_k/clean-security-bill-of-health.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2009/06/clean-security-bill-of-health.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-67607661</id>
        <published>2009-06-03T18:31:35-05:00</published>
        <updated>2009-06-03T18:31:35-05:00</updated>
        <summary type="html">What if a doctor told you that you had a clean bill of health, only to find that he missed a dangerous growth which later caused significant damage because it was not treated earlier? This is basically the gist of...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">&lt;p&gt;What if a doctor told you that you had a clean bill of health, only to find that he missed a dangerous growth which later caused significant damage because it was not treated earlier?&lt;/p&gt;  &lt;p&gt;&lt;a href="http://dockets.justia.com/docket/court-azdce/case_no-2:2009cv01088/case_id-445012/" target="_blank"&gt;This is basically the gist of a lawsuit that Merrick Bank has brought against Savvis in a federal complaint.&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;The short-term affects of this lawsuit will no doubt have a chilling effect on the compliance-service industry as they recognize their own vulnerability in signing off on an audit. &lt;/p&gt;  &lt;p&gt;It has always been critical that if you are giving someone a stamp of approval, that they truly meet the standard that has been defined. It’s important that your beef has been properly &lt;a href="http://www.aboutlawsuits.com/e-coli-and-foreign-object-lead-to-ground-beef-recalls-4235/" target="_blank"&gt;approved by the USDA&lt;/a&gt; and it’s important that your compliance with a security standard (Visa’s &lt;a href="http://usa.visa.com/merchants/risk_management/cisp.html?ep=v_sym_cisp&amp;amp;symlinkref=http://www.google.com/search%3Frlz%3D1C1CHMB_enUS291US304%26sourceid%3Dchrome%26ie%3DUTF-8%26q%3Dvisa%2Bcisp" target="_blank"&gt;Cardholder Information Security Program&lt;/a&gt; or CISP, in this case) has been thoroughly vetted and approved. &lt;/p&gt;  &lt;p&gt;No doubt, there have been security “stamps of approval” that have been given out to organizations in the past that might not have been deserving and we’ll never hear about them. And this might not be one of those times since we’ll have to wait until Savvis has had an opportunity defend itself and we hear the ruling by the court. However, it is inevitable that we would see a lawsuit occur at some point. &lt;/p&gt;  &lt;p&gt;If you tell me, or rather, guarantee me that I am compliant with a regulation or meet a certain standard or criteria and then I am fined a significant amount of money ($16 million in this case) because I am not, you can rest assured I will come to you for some answers and some compensation. &lt;/p&gt;  &lt;p&gt;What can be done to avoid this? This certainly invokes a number of questions. After all, companies are paying these auditors to insure they can bypass this whole mess. Ultimately, it will require more transparency of the actions performed by the auditing organization and the certifications of each individual auditor. If an auditor has passed a certification and his actions (or inactions) lead to a failure like this, should his certification be revoked? For my two cents, I believe this moves us a step closer to requiring a license-like structure for data security auditors that could have a better mechanism for granting and revoking its credentials. Ultimately, passing a test and receiving a certificate has limited if any accountability on an individual level.&lt;/p&gt;  &lt;p&gt;However, the question that will be addressed first is what culpability an auditing organization has when damages occur to a customer they have certified as compliant. For this, we will have to stay tuned to how the court rules. One thing we know for sure, companies that perform audits will take another look at how their contracts are worded and review carefully how they perform their contracts.&lt;/p&gt;  &lt;p&gt; &lt;/p&gt;  &lt;p&gt;Michael Mongold&lt;/p&gt;  &lt;div class="wlWriterEditableSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:fd7183f9-a151-4710-a3f5-b42fe6aa733f" style="padding-right: 0px; display: inline; padding-left: 0px; float: none; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;del.icio.us Tags: &lt;a href="http://del.icio.us/popular/savvus" rel="tag"&gt;savvus&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/Merrick" rel="tag"&gt;Merrick&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/Visa" rel="tag"&gt;Visa&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/CISP" rel="tag"&gt;CISP&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/Cardholder+Information+Security+Program" rel="tag"&gt;Cardholder Information Security Program&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/CardSystems" rel="tag"&gt;CardSystems&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/pay+by+touch" rel="tag"&gt;pay by touch&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/Michael+Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/audit" rel="tag"&gt;audit&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/security" rel="tag"&gt;security&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/technology" rel="tag"&gt;technology&lt;/a&gt;,&lt;a href="http://del.icio.us/popular/compliance" rel="tag"&gt;compliance&lt;/a&gt;&lt;/div&gt;  &lt;p&gt;   &lt;div class="wlWriterEditableSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:c8a72f8e-c813-4e75-baba-6228ba3d9989" style="padding-right: 0px; display: inline; padding-left: 0px; float: none; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati Tags: &lt;a href="http://technorati.com/tags/savvus" rel="tag"&gt;savvus&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Merrick" rel="tag"&gt;Merrick&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Visa" rel="tag"&gt;Visa&lt;/a&gt;,&lt;a href="http://technorati.com/tags/CISP" rel="tag"&gt;CISP&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Cardholder+Information+Security+Program" rel="tag"&gt;Cardholder Information Security Program&lt;/a&gt;,&lt;a href="http://technorati.com/tags/CardSystems" rel="tag"&gt;CardSystems&lt;/a&gt;,&lt;a href="http://technorati.com/tags/pay+by+touch" rel="tag"&gt;pay by touch&lt;/a&gt;,&lt;a href="http://technorati.com/tags/Michael+Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;,&lt;a href="http://technorati.com/tags/audit" rel="tag"&gt;audit&lt;/a&gt;,&lt;a href="http://technorati.com/tags/security" rel="tag"&gt;security&lt;/a&gt;,&lt;a href="http://technorati.com/tags/technology" rel="tag"&gt;technology&lt;/a&gt;,&lt;a href="http://technorati.com/tags/compliance" rel="tag"&gt;compliance&lt;/a&gt;&lt;/div&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=v_cKen5cn_k:7197uHSash8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=v_cKen5cn_k:7197uHSash8:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=v_cKen5cn_k:7197uHSash8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=v_cKen5cn_k:7197uHSash8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=v_cKen5cn_k:7197uHSash8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=v_cKen5cn_k:7197uHSash8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=v_cKen5cn_k:7197uHSash8:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=v_cKen5cn_k:7197uHSash8:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=v_cKen5cn_k:7197uHSash8:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=v_cKen5cn_k:7197uHSash8:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=v_cKen5cn_k:7197uHSash8:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2009/06/clean-security-bill-of-health.html</feedburner:origLink></entry>
    <entry>
        <title>VA vs USB</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/jPrCKaddjdo/va-vs-usb.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2007/06/va-vs-usb.html" thr:count="1" thr:updated="2008-03-16T13:27:08-05:00" />
        <id>tag:typepad.com,2003:post-35806752</id>
        <published>2007-06-26T08:25:49-05:00</published>
        <updated>2007-06-26T08:25:49-05:00</updated>
        <summary type="html">This is a little stale but I wanted to talk about it anyway. With their latest actions, I believe the Department of Veterans Affairs is quickly becoming the poster child for reformed data loss victims. (important to note that, in...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">
&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&lt;font size="3"&gt;This is a little stale but I wanted to talk about it anyway.&amp;nbsp;With their latest actions, I believe the&amp;nbsp;&lt;a title="Opens a seperate web page to the VA" href="http://www.va.gov/" target="_blank"&gt;Department of Veterans Affairs&lt;/a&gt;&amp;nbsp;is quickly becoming the poster child for reformed &lt;a title="Opens a link to the VA's data security page" href="http://www.usa.gov/veteransinfo/" target="_blank"&gt;data loss victims&lt;/a&gt;. &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;(important to note that, in this case,&amp;nbsp;the data&amp;nbsp;was eventually recovered)&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;The VA announced a few weeks ago that they have purchased 25,000 USB drives with built-in encryption from &lt;a title="Opens a seperate web page to Kanguru" href="http://www.kanguru.com/" target="_blank"&gt;Kanguru&lt;/a&gt;.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;The built-in AES-256 encryption will help insure that only authorized users can gain access to the USB drive and will prevent another&amp;nbsp;major meltdown if lost or stolen.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Also, it should be noted that Kanguru says that they can prevent users from attaching the devices to the network based on a device&amp;nbsp;identification number.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;I believe that this is a great step but one that must be accompanied by some level of control. I have stated in this blog a number of times that a policy without the means to enforce it, is just window dressing.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;So, kudos to the VA on a positive step and showing corporate America the direction to move in. Just make sure that you keep the momentum going and block access to the unauthorized USB devices out there. &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Michael Mongold&lt;/font&gt;&lt;/p&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:3da5d70a-2e28-4343-97e3-72c2907f36c6" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati tags: &lt;a href="http://technorati.com/tags/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Data%20encryption" rel="tag"&gt;Data encryption&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Kanguru" rel="tag"&gt;Kanguru&lt;/a&gt;, &lt;a href="http://technorati.com/tags/VA" rel="tag"&gt;VA&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Veterans%20Affairs" rel="tag"&gt;Veterans Affairs&lt;/a&gt;, &lt;a href="http://technorati.com/tags/USB%20encryption" rel="tag"&gt;USB encryption&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:11a90205-6389-4989-b5d7-810ff3a41614" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;LiveJournal tags: &lt;a href="http://www.livejournal.com/interests.bml?int=Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Data%20encryption" rel="tag"&gt;Data encryption&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Kanguru" rel="tag"&gt;Kanguru&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=VA" rel="tag"&gt;VA&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Veterans%20Affairs" rel="tag"&gt;Veterans Affairs&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=USB%20encryption" rel="tag"&gt;USB encryption&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:576ac30d-005b-47b2-9b8d-0b957ed4b65a" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;IceRocket tags: &lt;a href="http://blogs.icerocket.com/search?q=Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Data%20encryption" rel="tag"&gt;Data encryption&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Kanguru" rel="tag"&gt;Kanguru&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=VA" rel="tag"&gt;VA&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Veterans%20Affairs" rel="tag"&gt;Veterans Affairs&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=USB%20encryption" rel="tag"&gt;USB encryption&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:e0f9bee4-40c4-4404-ae9a-b670209137ec" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Flickr tags: &lt;a href="http://flickr.com/photos/tags/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Data%20encryption" rel="tag"&gt;Data encryption&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Kanguru" rel="tag"&gt;Kanguru&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/VA" rel="tag"&gt;VA&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Veterans%20Affairs" rel="tag"&gt;Veterans Affairs&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/USB%20encryption" rel="tag"&gt;USB encryption&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:dfeff91e-05df-4fc9-8c3d-f3a603a194f4" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;del.icio.us tags: &lt;a href="http://del.icio.us/popular/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Data%20encryption" rel="tag"&gt;Data encryption&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Kanguru" rel="tag"&gt;Kanguru&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/VA" rel="tag"&gt;VA&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Veterans%20Affairs" rel="tag"&gt;Veterans Affairs&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/USB%20encryption" rel="tag"&gt;USB encryption&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:d5e15126-c724-473a-bec7-10146b882890" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;BuzzNet tags: &lt;a href="http://www.buzznet.com/tags/Michael%20Mongold/" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Data%20encryption/" rel="tag"&gt;Data encryption&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Kanguru/" rel="tag"&gt;Kanguru&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/VA/" rel="tag"&gt;VA&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Veterans%20Affairs/" rel="tag"&gt;Veterans Affairs&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/USB%20encryption/" rel="tag"&gt;USB encryption&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:6eab1532-ff80-4a43-9d3f-e0ce75eb11ea" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;43 Things tags: &lt;a href="http://www.43things.com/tag/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Data%20encryption" rel="tag"&gt;Data encryption&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Kanguru" rel="tag"&gt;Kanguru&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/VA" rel="tag"&gt;VA&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Veterans%20Affairs" rel="tag"&gt;Veterans Affairs&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/USB%20encryption" rel="tag"&gt;USB encryption&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=jPrCKaddjdo:Z-d6WMZRCTY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=jPrCKaddjdo:Z-d6WMZRCTY:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=jPrCKaddjdo:Z-d6WMZRCTY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=jPrCKaddjdo:Z-d6WMZRCTY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=jPrCKaddjdo:Z-d6WMZRCTY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=jPrCKaddjdo:Z-d6WMZRCTY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=jPrCKaddjdo:Z-d6WMZRCTY:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=jPrCKaddjdo:Z-d6WMZRCTY:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=jPrCKaddjdo:Z-d6WMZRCTY:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=jPrCKaddjdo:Z-d6WMZRCTY:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=jPrCKaddjdo:Z-d6WMZRCTY:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2007/06/va-vs-usb.html</feedburner:origLink></entry>
    <entry>
        <title>Shameless Self-Promotion</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/PZASDNEU2Wo/shameless-self-.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2007/06/shameless-self-.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-35768942</id>
        <published>2007-06-25T14:07:52-05:00</published>
        <updated>2007-06-25T14:07:52-05:00</updated>
        <summary type="html">Since I only do this blog for my own narcissistic pleasure, won't you please go to Austin's "Best of" poll and vote for me as the best blogger? Many humble thanks, my friends! http://www.austinchronicle.com/feedback/bestof/07/ Michael Mongold Technorati tags: Michael Mongold,...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">
&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&lt;font size="3"&gt;Since I only do this blog for my own narcissistic pleasure, won't you please go to Austin's "Best of" poll and vote for me as the best blogger? Many humble thanks, my friends!&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;&lt;/font&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;&lt;a title="http://www.austinchronicle.com/feedback/bestof/07/" href="http://www.austinchronicle.com/feedback/bestof/07/"&gt;http://www.austinchronicle.com/feedback/bestof/07/&lt;/a&gt;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;&lt;/font&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Michael Mongold&lt;/font&gt;&lt;/p&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:6ecefc33-d12e-4491-ac30-1aa7e2b352d9" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati tags: &lt;a href="http://technorati.com/tags/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Austin" rel="tag"&gt;Austin&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Best%20of" rel="tag"&gt;Best of&lt;/a&gt;, &lt;a href="http://technorati.com/tags/narcissism" rel="tag"&gt;narcissism&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:32879cbb-d56d-42c5-a156-c4a0d19b01e7" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;LiveJournal tags: &lt;a href="http://www.livejournal.com/interests.bml?int=Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Austin" rel="tag"&gt;Austin&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Best%20of" rel="tag"&gt;Best of&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=narcissism" rel="tag"&gt;narcissism&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:e6a8b629-9468-44bf-95fc-2ea24bea49bb" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;IceRocket tags: &lt;a href="http://blogs.icerocket.com/search?q=Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Austin" rel="tag"&gt;Austin&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Best%20of" rel="tag"&gt;Best of&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=narcissism" rel="tag"&gt;narcissism&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:f3d2a392-240d-4428-9542-aad14109e7e4" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Flickr tags: &lt;a href="http://flickr.com/photos/tags/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Austin" rel="tag"&gt;Austin&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Best%20of" rel="tag"&gt;Best of&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/narcissism" rel="tag"&gt;narcissism&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:2dbd0cad-167b-423e-976a-e3a63fde1c2f" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;del.icio.us tags: &lt;a href="http://del.icio.us/popular/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Austin" rel="tag"&gt;Austin&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Best%20of" rel="tag"&gt;Best of&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/narcissism" rel="tag"&gt;narcissism&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:c4041138-a11f-4a48-bdc7-65b6d915059d" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;BuzzNet tags: &lt;a href="http://www.buzznet.com/tags/Michael%20Mongold/" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Austin/" rel="tag"&gt;Austin&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Best%20of/" rel="tag"&gt;Best of&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/narcissism/" rel="tag"&gt;narcissism&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:efa5dcee-c6d1-429a-b0a0-0cfe5421b64d" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;43 Things tags: &lt;a href="http://www.43things.com/tag/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Austin" rel="tag"&gt;Austin&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Best%20of" rel="tag"&gt;Best of&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/narcissism" rel="tag"&gt;narcissism&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=PZASDNEU2Wo:AILmDJ1TNNQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=PZASDNEU2Wo:AILmDJ1TNNQ:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=PZASDNEU2Wo:AILmDJ1TNNQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=PZASDNEU2Wo:AILmDJ1TNNQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=PZASDNEU2Wo:AILmDJ1TNNQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=PZASDNEU2Wo:AILmDJ1TNNQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=PZASDNEU2Wo:AILmDJ1TNNQ:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=PZASDNEU2Wo:AILmDJ1TNNQ:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=PZASDNEU2Wo:AILmDJ1TNNQ:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=PZASDNEU2Wo:AILmDJ1TNNQ:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=PZASDNEU2Wo:AILmDJ1TNNQ:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2007/06/shameless-self-.html</feedburner:origLink></entry>
    <entry>
        <title>Quicken backdoor outed...</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/eU4k2spmQcE/quicken-backdoo.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2007/06/quicken-backdoo.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-35761138</id>
        <published>2007-06-25T10:45:59-05:00</published>
        <updated>2007-06-25T10:45:59-05:00</updated>
        <summary type="html">A Russian firm, ElcomSoft, is now selling a password recovery tool that helps you gain access to Quicken, Quicken Lawyer, and QuickBooks for only $99 for a commercial license. ElcomSoft gained access to files encrypted by Quicken's software by discovering...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">
&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&lt;font size="3"&gt;A Russian firm, &lt;a title="Opens a seperate web page to ElcomSoft" href="http://www.elcomsoft.com/index.html" target="_blank"&gt;ElcomSoft&lt;/a&gt;, is now selling a password recovery tool that helps you gain access to Quicken, Quicken Lawyer, and QuickBooks for only $99 for a commercial license. &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;ElcomSoft gained access to files encrypted by&amp;nbsp;Quicken's&amp;nbsp;software by discovering a backdoor that Quicken had placed in their software for password recovery scenarios.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;ElcomSoft discovered that &lt;a title="Opens a seperate web page to Intuit" href="http://quicken.intuit.com/" target="_blank"&gt;Quicken&lt;/a&gt; had implemented a 512-bit RSA key. After factorizing the key, ElcomSoft promptly moved forward with a solution that can instantly remove the passwords protecting Quicken files.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;The result is, if placed in the wrong hands, this product could potentially open a number of customers to the exposure of very sensitive data to competitors and the public, alike.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Quicken has responded that they take this threat seriously and are working on resolving the issue.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Until they have provided a work around for the backdoor, make sure you keep a tight hold on any Quicken documents.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Michael Mongold&lt;/font&gt;&lt;/p&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:b1b073c0-8764-4635-8e71-a12427c5cf5f" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;43 Things tags: &lt;a href="http://www.43things.com/tag/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/ElcomSoft" rel="tag"&gt;ElcomSoft&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Quicken" rel="tag"&gt;Quicken&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/QuickBooks" rel="tag"&gt;QuickBooks&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Quicken%20Lawyer" rel="tag"&gt;Quicken Lawyer&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/RSA" rel="tag"&gt;RSA&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/data%20encryption" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/backdoor" rel="tag"&gt;backdoor&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:3e5ccdad-87f6-4f4e-8b72-68cd4b4c12d7" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;BuzzNet tags: &lt;a href="http://www.buzznet.com/tags/Michael%20Mongold/" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/ElcomSoft/" rel="tag"&gt;ElcomSoft&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Quicken/" rel="tag"&gt;Quicken&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/QuickBooks/" rel="tag"&gt;QuickBooks&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Quicken%20Lawyer/" rel="tag"&gt;Quicken Lawyer&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/RSA/" rel="tag"&gt;RSA&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/data%20encryption/" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/backdoor/" rel="tag"&gt;backdoor&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:4af367cd-a106-41ee-aac6-fa88332323fc" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;del.icio.us tags: &lt;a href="http://del.icio.us/popular/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/ElcomSoft" rel="tag"&gt;ElcomSoft&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Quicken" rel="tag"&gt;Quicken&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/QuickBooks" rel="tag"&gt;QuickBooks&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Quicken%20Lawyer" rel="tag"&gt;Quicken Lawyer&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/RSA" rel="tag"&gt;RSA&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/data%20encryption" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/backdoor" rel="tag"&gt;backdoor&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:59b85840-eaac-497f-a20a-32c0652ec170" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Flickr tags: &lt;a href="http://flickr.com/photos/tags/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/ElcomSoft" rel="tag"&gt;ElcomSoft&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Quicken" rel="tag"&gt;Quicken&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/QuickBooks" rel="tag"&gt;QuickBooks&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Quicken%20Lawyer" rel="tag"&gt;Quicken Lawyer&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/RSA" rel="tag"&gt;RSA&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/data%20encryption" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/backdoor" rel="tag"&gt;backdoor&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:17821387-5bb7-41f3-8c35-b2d610adcd67" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;IceRocket tags: &lt;a href="http://blogs.icerocket.com/search?q=Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=ElcomSoft" rel="tag"&gt;ElcomSoft&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Quicken" rel="tag"&gt;Quicken&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=QuickBooks" rel="tag"&gt;QuickBooks&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Quicken%20Lawyer" rel="tag"&gt;Quicken Lawyer&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=RSA" rel="tag"&gt;RSA&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=data%20encryption" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=backdoor" rel="tag"&gt;backdoor&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:8c9b15ea-ae5c-44af-99cf-b5437068d613" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;LiveJournal tags: &lt;a href="http://www.livejournal.com/interests.bml?int=Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=ElcomSoft" rel="tag"&gt;ElcomSoft&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Quicken" rel="tag"&gt;Quicken&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=QuickBooks" rel="tag"&gt;QuickBooks&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Quicken%20Lawyer" rel="tag"&gt;Quicken Lawyer&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=RSA" rel="tag"&gt;RSA&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=data%20encryption" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=backdoor" rel="tag"&gt;backdoor&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:0b4dc930-e9da-4e88-8393-e0a07f737735" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati tags: &lt;a href="http://technorati.com/tags/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://technorati.com/tags/ElcomSoft" rel="tag"&gt;ElcomSoft&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Quicken" rel="tag"&gt;Quicken&lt;/a&gt;, &lt;a href="http://technorati.com/tags/QuickBooks" rel="tag"&gt;QuickBooks&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Quicken%20Lawyer" rel="tag"&gt;Quicken Lawyer&lt;/a&gt;, &lt;a href="http://technorati.com/tags/RSA" rel="tag"&gt;RSA&lt;/a&gt;, &lt;a href="http://technorati.com/tags/data%20encryption" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://technorati.com/tags/backdoor" rel="tag"&gt;backdoor&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=eU4k2spmQcE:IZiTzWnW9pc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=eU4k2spmQcE:IZiTzWnW9pc:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=eU4k2spmQcE:IZiTzWnW9pc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=eU4k2spmQcE:IZiTzWnW9pc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=eU4k2spmQcE:IZiTzWnW9pc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=eU4k2spmQcE:IZiTzWnW9pc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=eU4k2spmQcE:IZiTzWnW9pc:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=eU4k2spmQcE:IZiTzWnW9pc:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=eU4k2spmQcE:IZiTzWnW9pc:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=eU4k2spmQcE:IZiTzWnW9pc:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=eU4k2spmQcE:IZiTzWnW9pc:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2007/06/quicken-backdoo.html</feedburner:origLink></entry>
    <entry>
        <title>Senforce integrates encryption into NAC</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/O1El7m6tZ8s/senforce-integr.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2007/06/senforce-integr.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-35619476</id>
        <published>2007-06-21T11:43:40-05:00</published>
        <updated>2007-06-21T11:43:40-05:00</updated>
        <summary type="html">Senforce announced on Monday that they will incorporate data encryption into their NAC offering. Back in March, I suggested that a natural evolution of encryption and NAC would eventually bring the two together. Kind of like chocolate and peanut butter....</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">
&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&lt;font size="3"&gt;Senforce &lt;a title="Opens a seperate web page to Senforce" href="http://www.networkworld.com/news/2007/061907-senforce-encryption.html" target="_blank"&gt;announced&lt;/a&gt;&amp;nbsp;on&amp;nbsp;Monday&amp;nbsp;that they will incorporate data encryption into their NAC offering.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Back in March, I &lt;a title="A link to my NAC and Encryption article back in March" href="http://securityblog.typepad.com/technology_security/2007/03/disk_encryption.html" target="_blank"&gt;suggested&lt;/a&gt; that a natural evolution of encryption and NAC would eventually bring the two together. Kind of like chocolate and peanut butter.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Now, &lt;a title="A link to Senforce's SES page" href="http://www.senforce.com/ses.html" target="_blank"&gt;Senforce&lt;/a&gt; is making a play in that direction.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;I'll spare you the trauma of reading their press release. Suffice to say after they finish huffing about how they are the leader and all that - you know, the usual press release BS. They eventually say a little bit about how they are planning to prevent "thumbsucking". &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;A term that they are a little overly proud of creating.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;(Thumbsucking refers to data that is&amp;nbsp;"sucked" off of corporate devices and onto USB drives. The term "slurping" has been around longer and refers to programs that automatically search for certain file types on a hard drive and pull them over to an iPod or other removable device when it attaches to the computer.)&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;So, verbiage aside, I am glad to see someone pick up this angle of data security. Right now, everyone I speak to is concerned about USB proliferation in the workplace. For organizations that have sensitive data (i.e. everyone), this is a critical issue. &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;The beauty of NAC is that it can easily incorporate new technologies and flash points into controllable security policies as they arise. This kind of flexibility and control are what is required as data security evolves.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;I always tell organizations that without NAC, your security policies have no teeth.&amp;nbsp;policies are basically words on a paper with no means of observing or enforcing behaviour. NAC gives you the ability to change all of that. &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Quite honestly, I'm not sure how CEOs/CFOs/CIOs/CISOs can sleep at night - with all of the current regulatory constraints that are flying around, not knowing what is on the network, and then not having the ability to do anything about what is on your network, even if you did know.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Hmmm - guess I should be glad I'm not in that position.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;So, while I can't recommend Senforce's offering yet since I haven't had a chance to play with it, I will say that I like the thought they have put into the features listed and look forward to seeing more of it (and the offerings from other NAC vendors)&amp;nbsp;in the future.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Michael Mongold&lt;/font&gt;&lt;/p&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:ed428351-d0a3-4d7b-9a17-1283e27a1757" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati tags: &lt;a href="http://technorati.com/tags/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Senforce" rel="tag"&gt;Senforce&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Senforce%20Encryption%20Solution" rel="tag"&gt;Senforce Encryption Solution&lt;/a&gt;, &lt;a href="http://technorati.com/tags/SES" rel="tag"&gt;SES&lt;/a&gt;, &lt;a href="http://technorati.com/tags/thumbsucking" rel="tag"&gt;thumbsucking&lt;/a&gt;, &lt;a href="http://technorati.com/tags/USB%20encryption" rel="tag"&gt;USB encryption&lt;/a&gt;, &lt;a href="http://technorati.com/tags/data%20encryption" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Network%20Access%20Control" rel="tag"&gt;Network Access Control&lt;/a&gt;, &lt;a href="http://technorati.com/tags/NAC" rel="tag"&gt;NAC&lt;/a&gt;, &lt;a href="http://technorati.com/tags/slurping" rel="tag"&gt;slurping&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:09bd7a2d-1b02-4965-ac6e-6802bb8d0292" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;IceRocket tags: &lt;a href="http://blogs.icerocket.com/search?q=Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Senforce" rel="tag"&gt;Senforce&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Senforce%20Encryption%20Solution" rel="tag"&gt;Senforce Encryption Solution&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=SES" rel="tag"&gt;SES&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=thumbsucking" rel="tag"&gt;thumbsucking&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=USB%20encryption" rel="tag"&gt;USB encryption&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=data%20encryption" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Network%20Access%20Control" rel="tag"&gt;Network Access Control&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=NAC" rel="tag"&gt;NAC&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=slurping" rel="tag"&gt;slurping&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:c66d07ea-8ae2-46d8-a98a-3fc8b90a0564" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Flickr tags: &lt;a href="http://flickr.com/photos/tags/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Senforce" rel="tag"&gt;Senforce&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Senforce%20Encryption%20Solution" rel="tag"&gt;Senforce Encryption Solution&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/SES" rel="tag"&gt;SES&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/thumbsucking" rel="tag"&gt;thumbsucking&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/USB%20encryption" rel="tag"&gt;USB encryption&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/data%20encryption" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Network%20Access%20Control" rel="tag"&gt;Network Access Control&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/NAC" rel="tag"&gt;NAC&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/slurping" rel="tag"&gt;slurping&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:64c206cf-4300-46dc-a959-2354caae73df" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;del.icio.us tags: &lt;a href="http://del.icio.us/popular/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Senforce" rel="tag"&gt;Senforce&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Senforce%20Encryption%20Solution" rel="tag"&gt;Senforce Encryption Solution&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/SES" rel="tag"&gt;SES&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/thumbsucking" rel="tag"&gt;thumbsucking&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/USB%20encryption" rel="tag"&gt;USB encryption&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/data%20encryption" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Network%20Access%20Control" rel="tag"&gt;Network Access Control&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/NAC" rel="tag"&gt;NAC&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/slurping" rel="tag"&gt;slurping&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:c41ce969-833a-4b80-ab99-7143080e56e1" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;BuzzNet tags: &lt;a href="http://www.buzznet.com/tags/Michael%20Mongold/" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Senforce/" rel="tag"&gt;Senforce&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Senforce%20Encryption%20Solution/" rel="tag"&gt;Senforce Encryption Solution&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/SES/" rel="tag"&gt;SES&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/thumbsucking/" rel="tag"&gt;thumbsucking&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/USB%20encryption/" rel="tag"&gt;USB encryption&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/data%20encryption/" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Network%20Access%20Control/" rel="tag"&gt;Network Access Control&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/NAC/" rel="tag"&gt;NAC&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/slurping/" rel="tag"&gt;slurping&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:95715766-c604-4760-8159-17d6941bb8bc" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;43 Things tags: &lt;a href="http://www.43things.com/tag/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Senforce" rel="tag"&gt;Senforce&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Senforce%20Encryption%20Solution" rel="tag"&gt;Senforce Encryption Solution&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/SES" rel="tag"&gt;SES&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/thumbsucking" rel="tag"&gt;thumbsucking&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/USB%20encryption" rel="tag"&gt;USB encryption&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/data%20encryption" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Network%20Access%20Control" rel="tag"&gt;Network Access Control&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/NAC" rel="tag"&gt;NAC&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/slurping" rel="tag"&gt;slurping&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:11c1f859-9cf6-4774-9a6f-d3aa6cc0fa9f" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;LiveJournal tags: &lt;a href="http://www.livejournal.com/interests.bml?int=Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Senforce" rel="tag"&gt;Senforce&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Senforce%20Encryption%20Solution" rel="tag"&gt;Senforce Encryption Solution&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=SES" rel="tag"&gt;SES&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=thumbsucking" rel="tag"&gt;thumbsucking&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=USB%20encryption" rel="tag"&gt;USB encryption&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=data%20encryption" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Network%20Access%20Control" rel="tag"&gt;Network Access Control&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=NAC" rel="tag"&gt;NAC&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=slurping" rel="tag"&gt;slurping&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=O1El7m6tZ8s:TXo1NL7JKmI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=O1El7m6tZ8s:TXo1NL7JKmI:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=O1El7m6tZ8s:TXo1NL7JKmI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=O1El7m6tZ8s:TXo1NL7JKmI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=O1El7m6tZ8s:TXo1NL7JKmI:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=O1El7m6tZ8s:TXo1NL7JKmI:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=O1El7m6tZ8s:TXo1NL7JKmI:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=O1El7m6tZ8s:TXo1NL7JKmI:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=O1El7m6tZ8s:TXo1NL7JKmI:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=O1El7m6tZ8s:TXo1NL7JKmI:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=O1El7m6tZ8s:TXo1NL7JKmI:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2007/06/senforce-integr.html</feedburner:origLink></entry>
    <entry>
        <title>Government buys encryption</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/Cc6dMqYTXmU/government_buys.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2007/06/government_buys.html" thr:count="7" thr:updated="2009-09-11T12:42:45-05:00" />
        <id>tag:typepad.com,2003:post-35571846</id>
        <published>2007-06-20T11:07:32-05:00</published>
        <updated>2007-06-20T11:07:32-05:00</updated>
        <summary type="html">Can I get an "Amen?" The General Services Administration just announced that they have selected 10 data encryption companies to "guard sensitive, unclassified data that reside on laptops, mobile computing gadgets and thumb drives." The ten companies are: Mobile Armor's...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">
&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&lt;font size="3"&gt;Can I get an "Amen?" The General Services Administration &lt;a title="Opens a seperate web page to prnewswire" href="http://sev.prnewswire.com/computer-electronics/20070618/DCM08418062007-1.html" target="_blank"&gt;just announced&lt;/a&gt; that they have selected 10 data encryption companies to "guard sensitive, unclassified data that reside on laptops, mobile computing gadgets and thumb drives."&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;font size="3"&gt;The ten companies are:&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;&lt;a title="Opens a seperate web page to Mobile Armor" href="http://www.mobilearmor.com/dataarmor.html" target="_blank"&gt;Mobile Armor's Data Armor&lt;/a&gt;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;&lt;a title="Opens a seperate web page to SafeBoot" href="http://www.safeboot.com/products/device-encryption/pc/" target="_blank"&gt;Safeboot's SafeBoot Device Encryption&lt;/a&gt;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;&lt;a title="Opens a seperate web page to Information Security" href="http://www.infoseccorp.com/products/secretagent/contents.htm" target="_blank"&gt;Information Security's Secret Agent&lt;/a&gt;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;&lt;a title="Opens a seperate web page at SafeNet" href="http://www.safenet-inc.com/products/data_at_rest_protection/Protectdrive.asp" target="_blank"&gt;SafeNet's SafeNet ProtectDrive&lt;/a&gt;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;&lt;a title="Opens a seperate web page at Encryption Solutions" href="http://www.encryptionsolutions.net/" target="_blank"&gt;Encryption Solution's SkyLOCK At-Rest&lt;/a&gt;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;&lt;a title="Opens a seperate web page to Spyrus" href="http://www.spyrus.com/products/talismands.asp" target="_blank"&gt;Spyrus' Talisman/DS Data Security Suite&lt;/a&gt;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;&lt;a title="Opens a seperate web page to WinMagic" href="http://www.winmagic.com/solutions/securedoc.html" target="_blank"&gt;WinMagic's SecureDoc&lt;/a&gt;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;&lt;a title="Opens a seperate web page to CREDANT" href="http://www.credant.com/content/blogcategory/72/151/" target="_blank"&gt;CREDANT's CREDANTMobile Guardian&lt;/a&gt;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;&lt;a title="Opens a seperate web page to Guardian Edge" href="http://www.guardianedge.com/products/" target="_blank"&gt;GuardianEdge's Data Protection Platform&lt;/a&gt;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;It is an interesting line-up of encryption vendors with some of the usual suspects included and then a few that made it from out of left field and then a few notables that were left off.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Of the surprises on the list:&lt;/font&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;font size="3"&gt;Information Security&lt;/font&gt;  &lt;ul&gt; &lt;li&gt;&lt;font size="3"&gt;A small player who caters to the federal space&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;li&gt;&lt;font size="3"&gt;Encryption Solution&lt;/font&gt;  &lt;ul&gt; &lt;li&gt;&lt;font size="3"&gt;Finding information on this company was like pulling teeth. Not much of a presence in the market. However, with government contracts, it's always fun to see who has been doing the most lobbying&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;font size="3"&gt;&lt;/font&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Of the surprises OFF the list:&lt;/font&gt;&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;font size="3"&gt;Utimaco&lt;/font&gt;  &lt;ul&gt; &lt;li&gt;&lt;font size="3"&gt;With about a quarter of all of the encryption licenses in the world, their absence is definitely noteworthy. Perhaps because their German?&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt; &lt;li&gt;&lt;font size="3"&gt;Pointsec&lt;/font&gt;  &lt;ul&gt; &lt;li&gt;&lt;font size="3"&gt;The other 800 pound gorilla in the encryption market. Recent purchase by Checkpoint should have made them more palatable to the government, but I guess they're still too Swedish.&lt;/font&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;&lt;font size="3"&gt;It was good to see WinMagic make the list. They're a good group of guys and I'm sure they worked hard to get this deal. &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;It appears that Guardian Edge may be back in the good graces of the government after winning and then losing the VA deal. Word is that they are having a lot of problems financially so we'll have to see if this keeps them afloat for awhile longer.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Also, good to see Mobile Armor. I have been hearing a lot of good things about their software and look forward to getting my hands on some of it soon.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;To put things into perspective, the deal is worth at least $79 million dollars over the next five years.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;On top of all of the government agencies that can get in on this deal, state and local governments can get the same&amp;nbsp;pricing through the winning&amp;nbsp;vendors for their various organizations. This represents a tremendous opportunity for local and state authorities to provide encryption for their user's data at greatly reduced costs.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;So if you are a local or state agency, jump on this deal because it is unlikely you will find better pricing on your own.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Michael Mongold&lt;/font&gt;&lt;/p&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:d0a4a79e-f6b7-4dc9-ae3b-6eb0b0c2e878" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;LiveJournal tags: &lt;a href="http://www.livejournal.com/interests.bml?int=Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=MTM%20Technologies" rel="tag"&gt;MTM Technologies&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Rocky%20Mountain%20Ram" rel="tag"&gt;Rocky Mountain Ram&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Carahsoft%20Technology" rel="tag"&gt;Carahsoft Technology&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Spectrum%20Systems" rel="tag"&gt;Spectrum Systems&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=SafeNet" rel="tag"&gt;SafeNet&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Hi%20Tech%20Services" rel="tag"&gt;Hi Tech Services&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Autonomic%20Resources" rel="tag"&gt;Autonomic Resources&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=GovBuys" rel="tag"&gt;GovBuys&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Intelligent%20Decisions" rel="tag"&gt;Intelligent Decisions&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Merlin%20International" rel="tag"&gt;Merlin International&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Mobile%20Armor" rel="tag"&gt;Mobile Armor&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Data%20Armor" rel="tag"&gt;Data Armor&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Safeboot" rel="tag"&gt;Safeboot&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Safeboot%20Device%20Encryption" rel="tag"&gt;Safeboot Device Encryption&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Information%20Security%20Corp." rel="tag"&gt;Information Security Corp.&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Secret%20Agent" rel="tag"&gt;Secret Agent&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=SafeNet%20ProtectDrive" rel="tag"&gt;SafeNet ProtectDrive&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Encryption%20Solutions" rel="tag"&gt;Encryption Solutions&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=SkyLOCK%20At-Rest" rel="tag"&gt;SkyLOCK At-Rest&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=SPYRUS" rel="tag"&gt;SPYRUS&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Talisman/DS%20Data%20Security%20Suite" rel="tag"&gt;Talisman/DS Data Security Suite&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=WinMagic" rel="tag"&gt;WinMagic&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=SecureDoc" rel="tag"&gt;SecureDoc&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=CREDANT%20Technologies" rel="tag"&gt;CREDANT Technologies&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=CREDANTMobile%20Guardian" rel="tag"&gt;CREDANTMobile Guardian&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=GuardianEdge" rel="tag"&gt;GuardianEdge&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=DAR" rel="tag"&gt;DAR&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=GSA" rel="tag"&gt;GSA&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Enterprise%20Software%20Initiative" rel="tag"&gt;Enterprise Software Initiative&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=SmartBUY" rel="tag"&gt;SmartBUY&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Office%20of%20Management%20and%20Budget" rel="tag"&gt;Office of Management and Budget&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Defense%20Department" rel="tag"&gt;Defense Department&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=General%20Services%20Administration" rel="tag"&gt;General Services Administration&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=DARTT" rel="tag"&gt;DARTT&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Data-at-Rest%20Tiger%20Team" rel="tag"&gt;Data-at-Rest Tiger Team&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:e425539e-1980-4b3f-8de2-f18b8e44f8c5" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; float: none; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati tags: &lt;a href="http://technorati.com/tags/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://technorati.com/tags/MTM%20Technologies" rel="tag"&gt;MTM Technologies&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Rocky%20Mountain%20Ram" rel="tag"&gt;Rocky Mountain Ram&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Carahsoft%20Technology" rel="tag"&gt;Carahsoft Technology&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Spectrum%20Systems" rel="tag"&gt;Spectrum Systems&lt;/a&gt;, &lt;a href="http://technorati.com/tags/SafeNet" rel="tag"&gt;SafeNet&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Hi%20Tech%20Services" rel="tag"&gt;Hi Tech Services&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Autonomic%20Resources" rel="tag"&gt;Autonomic Resources&lt;/a&gt;, &lt;a href="http://technorati.com/tags/GovBuys" rel="tag"&gt;GovBuys&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Intelligent%20Decisions" rel="tag"&gt;Intelligent Decisions&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Merlin%20International" rel="tag"&gt;Merlin International&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Mobile%20Armor" rel="tag"&gt;Mobile Armor&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Data%20Armor" rel="tag"&gt;Data Armor&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Safeboot" rel="tag"&gt;Safeboot&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Safeboot%20Device%20Encryption" rel="tag"&gt;Safeboot Device Encryption&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Information%20Security%20Corp." rel="tag"&gt;Information Security Corp.&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Secret%20Agent" rel="tag"&gt;Secret Agent&lt;/a&gt;, &lt;a href="http://technorati.com/tags/SafeNet%20ProtectDrive" rel="tag"&gt;SafeNet ProtectDrive&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Encryption%20Solutions" rel="tag"&gt;Encryption Solutions&lt;/a&gt;, &lt;a href="http://technorati.com/tags/SkyLOCK%20At-Rest" rel="tag"&gt;SkyLOCK At-Rest&lt;/a&gt;, &lt;a href="http://technorati.com/tags/SPYRUS" rel="tag"&gt;SPYRUS&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Talisman/DS%20Data%20Security%20Suite" rel="tag"&gt;Talisman/DS Data Security Suite&lt;/a&gt;, &lt;a href="http://technorati.com/tags/WinMagic" rel="tag"&gt;WinMagic&lt;/a&gt;, &lt;a href="http://technorati.com/tags/SecureDoc" rel="tag"&gt;SecureDoc&lt;/a&gt;, &lt;a href="http://technorati.com/tags/CREDANT%20Technologies" rel="tag"&gt;CREDANT Technologies&lt;/a&gt;, &lt;a href="http://technorati.com/tags/CREDANTMobile%20Guardian" rel="tag"&gt;CREDANTMobile Guardian&lt;/a&gt;, &lt;a href="http://technorati.com/tags/GuardianEdge" rel="tag"&gt;GuardianEdge&lt;/a&gt;, &lt;a href="http://technorati.com/tags/DAR" rel="tag"&gt;DAR&lt;/a&gt;, &lt;a href="http://technorati.com/tags/GSA" rel="tag"&gt;GSA&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Enterprise%20Software%20Initiative" rel="tag"&gt;Enterprise Software Initiative&lt;/a&gt;, &lt;a href="http://technorati.com/tags/SmartBUY" rel="tag"&gt;SmartBUY&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Office%20of%20Management%20and%20Budget" rel="tag"&gt;Office of Management and Budget&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Defense%20Department" rel="tag"&gt;Defense Department&lt;/a&gt;, &lt;a href="http://technorati.com/tags/General%20Services%20Administration" rel="tag"&gt;General Services Administration&lt;/a&gt;, &lt;a href="http://technorati.com/tags/DARTT" rel="tag"&gt;DARTT&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Data-at-Rest%20Tiger%20Team" rel="tag"&gt;Data-at-Rest Tiger Team&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:73fbc8d4-911d-42fb-a7a3-d8ef76e9b67a" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;IceRocket tags: &lt;a href="http://blogs.icerocket.com/search?q=Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=MTM%20Technologies" rel="tag"&gt;MTM Technologies&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Rocky%20Mountain%20Ram" rel="tag"&gt;Rocky Mountain Ram&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Carahsoft%20Technology" rel="tag"&gt;Carahsoft Technology&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Spectrum%20Systems" rel="tag"&gt;Spectrum Systems&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=SafeNet" rel="tag"&gt;SafeNet&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Hi%20Tech%20Services" rel="tag"&gt;Hi Tech Services&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Autonomic%20Resources" rel="tag"&gt;Autonomic Resources&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=GovBuys" rel="tag"&gt;GovBuys&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Intelligent%20Decisions" rel="tag"&gt;Intelligent Decisions&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Merlin%20International" rel="tag"&gt;Merlin International&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Mobile%20Armor" rel="tag"&gt;Mobile Armor&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Data%20Armor" rel="tag"&gt;Data Armor&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Safeboot" rel="tag"&gt;Safeboot&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Safeboot%20Device%20Encryption" rel="tag"&gt;Safeboot Device Encryption&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Information%20Security%20Corp." rel="tag"&gt;Information Security Corp.&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Secret%20Agent" rel="tag"&gt;Secret Agent&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=SafeNet%20ProtectDrive" rel="tag"&gt;SafeNet ProtectDrive&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Encryption%20Solutions" rel="tag"&gt;Encryption Solutions&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=SkyLOCK%20At-Rest" rel="tag"&gt;SkyLOCK At-Rest&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=SPYRUS" rel="tag"&gt;SPYRUS&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Talisman/DS%20Data%20Security%20Suite" rel="tag"&gt;Talisman/DS Data Security Suite&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=WinMagic" rel="tag"&gt;WinMagic&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=SecureDoc" rel="tag"&gt;SecureDoc&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=CREDANT%20Technologies" rel="tag"&gt;CREDANT Technologies&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=CREDANTMobile%20Guardian" rel="tag"&gt;CREDANTMobile Guardian&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=GuardianEdge" rel="tag"&gt;GuardianEdge&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=DAR" rel="tag"&gt;DAR&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=GSA" rel="tag"&gt;GSA&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Enterprise%20Software%20Initiative" rel="tag"&gt;Enterprise Software Initiative&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=SmartBUY" rel="tag"&gt;SmartBUY&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Office%20of%20Management%20and%20Budget" rel="tag"&gt;Office of Management and Budget&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Defense%20Department" rel="tag"&gt;Defense Department&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=General%20Services%20Administration" rel="tag"&gt;General Services Administration&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=DARTT" rel="tag"&gt;DARTT&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Data-at-Rest%20Tiger%20Team" rel="tag"&gt;Data-at-Rest Tiger Team&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:2470d284-564a-4588-9c44-dbe353d0d078" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Flickr tags: &lt;a href="http://flickr.com/photos/tags/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/MTM%20Technologies" rel="tag"&gt;MTM Technologies&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Rocky%20Mountain%20Ram" rel="tag"&gt;Rocky Mountain Ram&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Carahsoft%20Technology" rel="tag"&gt;Carahsoft Technology&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Spectrum%20Systems" rel="tag"&gt;Spectrum Systems&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/SafeNet" rel="tag"&gt;SafeNet&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Hi%20Tech%20Services" rel="tag"&gt;Hi Tech Services&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Autonomic%20Resources" rel="tag"&gt;Autonomic Resources&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/GovBuys" rel="tag"&gt;GovBuys&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Intelligent%20Decisions" rel="tag"&gt;Intelligent Decisions&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Merlin%20International" rel="tag"&gt;Merlin International&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Mobile%20Armor" rel="tag"&gt;Mobile Armor&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Data%20Armor" rel="tag"&gt;Data Armor&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Safeboot" rel="tag"&gt;Safeboot&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Safeboot%20Device%20Encryption" rel="tag"&gt;Safeboot Device Encryption&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Information%20Security%20Corp." rel="tag"&gt;Information Security Corp.&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Secret%20Agent" rel="tag"&gt;Secret Agent&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/SafeNet%20ProtectDrive" rel="tag"&gt;SafeNet ProtectDrive&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Encryption%20Solutions" rel="tag"&gt;Encryption Solutions&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/SkyLOCK%20At-Rest" rel="tag"&gt;SkyLOCK At-Rest&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/SPYRUS" rel="tag"&gt;SPYRUS&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Talisman/DS%20Data%20Security%20Suite" rel="tag"&gt;Talisman/DS Data Security Suite&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/WinMagic" rel="tag"&gt;WinMagic&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/SecureDoc" rel="tag"&gt;SecureDoc&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/CREDANT%20Technologies" rel="tag"&gt;CREDANT Technologies&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/CREDANTMobile%20Guardian" rel="tag"&gt;CREDANTMobile Guardian&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/GuardianEdge" rel="tag"&gt;GuardianEdge&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/DAR" rel="tag"&gt;DAR&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/GSA" rel="tag"&gt;GSA&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Enterprise%20Software%20Initiative" rel="tag"&gt;Enterprise Software Initiative&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/SmartBUY" rel="tag"&gt;SmartBUY&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Office%20of%20Management%20and%20Budget" rel="tag"&gt;Office of Management and Budget&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Defense%20Department" rel="tag"&gt;Defense Department&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/General%20Services%20Administration" rel="tag"&gt;General Services Administration&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/DARTT" rel="tag"&gt;DARTT&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Data-at-Rest%20Tiger%20Team" rel="tag"&gt;Data-at-Rest Tiger Team&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:fe357463-77ff-4eab-8052-e18d232a598f" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;del.icio.us tags: &lt;a href="http://del.icio.us/popular/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/MTM%20Technologies" rel="tag"&gt;MTM Technologies&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Rocky%20Mountain%20Ram" rel="tag"&gt;Rocky Mountain Ram&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Carahsoft%20Technology" rel="tag"&gt;Carahsoft Technology&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Spectrum%20Systems" rel="tag"&gt;Spectrum Systems&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/SafeNet" rel="tag"&gt;SafeNet&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Hi%20Tech%20Services" rel="tag"&gt;Hi Tech Services&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Autonomic%20Resources" rel="tag"&gt;Autonomic Resources&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/GovBuys" rel="tag"&gt;GovBuys&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Intelligent%20Decisions" rel="tag"&gt;Intelligent Decisions&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Merlin%20International" rel="tag"&gt;Merlin International&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Mobile%20Armor" rel="tag"&gt;Mobile Armor&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Data%20Armor" rel="tag"&gt;Data Armor&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Safeboot" rel="tag"&gt;Safeboot&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Safeboot%20Device%20Encryption" rel="tag"&gt;Safeboot Device Encryption&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Information%20Security%20Corp." rel="tag"&gt;Information Security Corp.&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Secret%20Agent" rel="tag"&gt;Secret Agent&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/SafeNet%20ProtectDrive" rel="tag"&gt;SafeNet ProtectDrive&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Encryption%20Solutions" rel="tag"&gt;Encryption Solutions&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/SkyLOCK%20At-Rest" rel="tag"&gt;SkyLOCK At-Rest&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/SPYRUS" rel="tag"&gt;SPYRUS&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Talisman/DS%20Data%20Security%20Suite" rel="tag"&gt;Talisman/DS Data Security Suite&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/WinMagic" rel="tag"&gt;WinMagic&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/SecureDoc" rel="tag"&gt;SecureDoc&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/CREDANT%20Technologies" rel="tag"&gt;CREDANT Technologies&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/CREDANTMobile%20Guardian" rel="tag"&gt;CREDANTMobile Guardian&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/GuardianEdge" rel="tag"&gt;GuardianEdge&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/DAR" rel="tag"&gt;DAR&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/GSA" rel="tag"&gt;GSA&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Enterprise%20Software%20Initiative" rel="tag"&gt;Enterprise Software Initiative&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/SmartBUY" rel="tag"&gt;SmartBUY&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Office%20of%20Management%20and%20Budget" rel="tag"&gt;Office of Management and Budget&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Defense%20Department" rel="tag"&gt;Defense Department&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/General%20Services%20Administration" rel="tag"&gt;General Services Administration&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/DARTT" rel="tag"&gt;DARTT&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Data-at-Rest%20Tiger%20Team" rel="tag"&gt;Data-at-Rest Tiger Team&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:7d92b6f1-464d-4dd3-b14a-2230111901d9" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;BuzzNet tags: &lt;a href="http://www.buzznet.com/tags/Michael%20Mongold/" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/MTM%20Technologies/" rel="tag"&gt;MTM Technologies&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Rocky%20Mountain%20Ram/" rel="tag"&gt;Rocky Mountain Ram&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Carahsoft%20Technology/" rel="tag"&gt;Carahsoft Technology&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Spectrum%20Systems/" rel="tag"&gt;Spectrum Systems&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/SafeNet/" rel="tag"&gt;SafeNet&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Hi%20Tech%20Services/" rel="tag"&gt;Hi Tech Services&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Autonomic%20Resources/" rel="tag"&gt;Autonomic Resources&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/GovBuys/" rel="tag"&gt;GovBuys&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Intelligent%20Decisions/" rel="tag"&gt;Intelligent Decisions&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Merlin%20International/" rel="tag"&gt;Merlin International&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Mobile%20Armor/" rel="tag"&gt;Mobile Armor&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Data%20Armor/" rel="tag"&gt;Data Armor&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Safeboot/" rel="tag"&gt;Safeboot&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Safeboot%20Device%20Encryption/" rel="tag"&gt;Safeboot Device Encryption&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Information%20Security%20Corp./" rel="tag"&gt;Information Security Corp.&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Secret%20Agent/" rel="tag"&gt;Secret Agent&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/SafeNet%20ProtectDrive/" rel="tag"&gt;SafeNet ProtectDrive&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Encryption%20Solutions/" rel="tag"&gt;Encryption Solutions&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/SkyLOCK%20At-Rest/" rel="tag"&gt;SkyLOCK At-Rest&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/SPYRUS/" rel="tag"&gt;SPYRUS&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Talisman/DS%20Data%20Security%20Suite/" rel="tag"&gt;Talisman/DS Data Security Suite&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/WinMagic/" rel="tag"&gt;WinMagic&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/SecureDoc/" rel="tag"&gt;SecureDoc&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/CREDANT%20Technologies/" rel="tag"&gt;CREDANT Technologies&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/CREDANTMobile%20Guardian/" rel="tag"&gt;CREDANTMobile Guardian&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/GuardianEdge/" rel="tag"&gt;GuardianEdge&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/DAR/" rel="tag"&gt;DAR&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/GSA/" rel="tag"&gt;GSA&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Enterprise%20Software%20Initiative/" rel="tag"&gt;Enterprise Software Initiative&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/SmartBUY/" rel="tag"&gt;SmartBUY&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Office%20of%20Management%20and%20Budget/" rel="tag"&gt;Office of Management and Budget&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Defense%20Department/" rel="tag"&gt;Defense Department&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/General%20Services%20Administration/" rel="tag"&gt;General Services Administration&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/DARTT/" rel="tag"&gt;DARTT&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Data-at-Rest%20Tiger%20Team/" rel="tag"&gt;Data-at-Rest Tiger Team&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:8e1e41a6-7c54-45be-8be9-aebb43f79092" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;43 Things tags: &lt;a href="http://www.43things.com/tag/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/MTM%20Technologies" rel="tag"&gt;MTM Technologies&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Rocky%20Mountain%20Ram" rel="tag"&gt;Rocky Mountain Ram&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Carahsoft%20Technology" rel="tag"&gt;Carahsoft Technology&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Spectrum%20Systems" rel="tag"&gt;Spectrum Systems&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/SafeNet" rel="tag"&gt;SafeNet&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Hi%20Tech%20Services" rel="tag"&gt;Hi Tech Services&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Autonomic%20Resources" rel="tag"&gt;Autonomic Resources&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/GovBuys" rel="tag"&gt;GovBuys&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Intelligent%20Decisions" rel="tag"&gt;Intelligent Decisions&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Merlin%20International" rel="tag"&gt;Merlin International&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Mobile%20Armor" rel="tag"&gt;Mobile Armor&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Data%20Armor" rel="tag"&gt;Data Armor&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Safeboot" rel="tag"&gt;Safeboot&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Safeboot%20Device%20Encryption" rel="tag"&gt;Safeboot Device Encryption&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Information%20Security%20Corp." rel="tag"&gt;Information Security Corp.&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Secret%20Agent" rel="tag"&gt;Secret Agent&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/SafeNet%20ProtectDrive" rel="tag"&gt;SafeNet ProtectDrive&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Encryption%20Solutions" rel="tag"&gt;Encryption Solutions&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/SkyLOCK%20At-Rest" rel="tag"&gt;SkyLOCK At-Rest&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/SPYRUS" rel="tag"&gt;SPYRUS&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Talisman/DS%20Data%20Security%20Suite" rel="tag"&gt;Talisman/DS Data Security Suite&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/WinMagic" rel="tag"&gt;WinMagic&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/SecureDoc" rel="tag"&gt;SecureDoc&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/CREDANT%20Technologies" rel="tag"&gt;CREDANT Technologies&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/CREDANTMobile%20Guardian" rel="tag"&gt;CREDANTMobile Guardian&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/GuardianEdge" rel="tag"&gt;GuardianEdge&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/DAR" rel="tag"&gt;DAR&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/GSA" rel="tag"&gt;GSA&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Enterprise%20Software%20Initiative" rel="tag"&gt;Enterprise Software Initiative&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/SmartBUY" rel="tag"&gt;SmartBUY&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Office%20of%20Management%20and%20Budget" rel="tag"&gt;Office of Management and Budget&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Defense%20Department" rel="tag"&gt;Defense Department&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/General%20Services%20Administration" rel="tag"&gt;General Services Administration&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/DARTT" rel="tag"&gt;DARTT&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Data-at-Rest%20Tiger%20Team" rel="tag"&gt;Data-at-Rest Tiger Team&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=Cc6dMqYTXmU:-Zm1A9LHMIU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=Cc6dMqYTXmU:-Zm1A9LHMIU:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=Cc6dMqYTXmU:-Zm1A9LHMIU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=Cc6dMqYTXmU:-Zm1A9LHMIU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=Cc6dMqYTXmU:-Zm1A9LHMIU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=Cc6dMqYTXmU:-Zm1A9LHMIU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=Cc6dMqYTXmU:-Zm1A9LHMIU:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=Cc6dMqYTXmU:-Zm1A9LHMIU:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=Cc6dMqYTXmU:-Zm1A9LHMIU:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=Cc6dMqYTXmU:-Zm1A9LHMIU:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=Cc6dMqYTXmU:-Zm1A9LHMIU:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2007/06/government_buys.html</feedburner:origLink></entry>
    <entry>
        <title>Ohio mess could have been prevented...</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/n-08JZnfKLE/ohio_mess_could.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2007/06/ohio_mess_could.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-35537714</id>
        <published>2007-06-19T14:54:58-05:00</published>
        <updated>2007-06-19T14:54:58-05:00</updated>
        <summary type="html">This may hard to believe, but experts are saying that IF the data stolen from Ohio would have been encrypted it would have prevented the worries they are going through now. Uh, yea. No kidding. Oh, well. More fodder for...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">
&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&lt;font size="3"&gt;This may hard to believe, but experts are saying that &lt;strong&gt;IF&lt;/strong&gt; the data stolen from Ohio would have been encrypted it would have prevented the worries they are going through now. &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Uh, yea. No kidding. Oh, well. More fodder for the bloggers and newsies to write about. There certainly seems to be no shortage of it. &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;The plus side of this is that these big, very public losses are helping divert attention from the smaller losses that are occurring everyday. So, if your company has any data theft that it needs to report, try to time it around another data theft that is a lot larger. Most likely the&amp;nbsp;news outlets will only run one story on data theft that day and choose to run the other company's screw up. Bonus points if you report this late on a Friday.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;I should be a political spin-meister.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Of note, is Gov. Strickland's stance that Ohio "&lt;em&gt;&lt;strong&gt;maybe should&lt;/strong&gt;&lt;/em&gt; &lt;em&gt;&lt;strong&gt;have&lt;/strong&gt;&lt;/em&gt; considered encrypting the data". Regardless, he believes the data is still safe because it &lt;em&gt;&lt;strong&gt;should be&lt;/strong&gt;&lt;/em&gt; difficult to use the data on the hard drive.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;I hope the Ohio voting populace feels better about their&amp;nbsp;tech-savvy governor telling us how it is. &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Perhaps&amp;nbsp;the car that the data was &lt;strong&gt;&lt;em&gt;stored&lt;/em&gt; &lt;/strong&gt;in &lt;em&gt;&lt;strong&gt;maybe should have&lt;/strong&gt;&lt;/em&gt; been harder to break into as well.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Michael Mongold&lt;/font&gt;&lt;/p&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:1618c091-a031-4e6f-9080-8e356270c9b6" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati tags: &lt;a href="http://technorati.com/tags/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Ohio" rel="tag"&gt;Ohio&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Data%20theft" rel="tag"&gt;Data theft&lt;/a&gt;, &lt;a href="http://technorati.com/tags/data%20encryption" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://technorati.com/tags/technology%20security" rel="tag"&gt;technology security&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:88eb4602-463a-4ebe-ba2c-6f2af3158a62" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;LiveJournal tags: &lt;a href="http://www.livejournal.com/interests.bml?int=Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Ohio" rel="tag"&gt;Ohio&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Data%20theft" rel="tag"&gt;Data theft&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=data%20encryption" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=technology%20security" rel="tag"&gt;technology security&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:cc2ac2fe-ad44-47e3-b5e4-7a34b65ac3fc" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;IceRocket tags: &lt;a href="http://blogs.icerocket.com/search?q=Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Ohio" rel="tag"&gt;Ohio&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Data%20theft" rel="tag"&gt;Data theft&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=data%20encryption" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=technology%20security" rel="tag"&gt;technology security&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:7245fa97-0ada-4857-b753-91eb3b9959a7" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Flickr tags: &lt;a href="http://flickr.com/photos/tags/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Ohio" rel="tag"&gt;Ohio&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Data%20theft" rel="tag"&gt;Data theft&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/data%20encryption" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/technology%20security" rel="tag"&gt;technology security&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:9d543304-6150-4911-bbe2-586250f9eccd" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;del.icio.us tags: &lt;a href="http://del.icio.us/popular/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Ohio" rel="tag"&gt;Ohio&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Data%20theft" rel="tag"&gt;Data theft&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/data%20encryption" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/technology%20security" rel="tag"&gt;technology security&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:8245a692-95dd-4c0c-b4c0-642e95e883db" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;BuzzNet tags: &lt;a href="http://www.buzznet.com/tags/Michael%20Mongold/" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Ohio/" rel="tag"&gt;Ohio&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Data%20theft/" rel="tag"&gt;Data theft&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/data%20encryption/" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/technology%20security/" rel="tag"&gt;technology security&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:e9dc6728-9dd3-4918-af03-237ddfb87189" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;43 Things tags: &lt;a href="http://www.43things.com/tag/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Ohio" rel="tag"&gt;Ohio&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Data%20theft" rel="tag"&gt;Data theft&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/data%20encryption" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/technology%20security" rel="tag"&gt;technology security&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=n-08JZnfKLE:yZhHN1SnAPc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=n-08JZnfKLE:yZhHN1SnAPc:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=n-08JZnfKLE:yZhHN1SnAPc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=n-08JZnfKLE:yZhHN1SnAPc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=n-08JZnfKLE:yZhHN1SnAPc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=n-08JZnfKLE:yZhHN1SnAPc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=n-08JZnfKLE:yZhHN1SnAPc:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=n-08JZnfKLE:yZhHN1SnAPc:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=n-08JZnfKLE:yZhHN1SnAPc:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=n-08JZnfKLE:yZhHN1SnAPc:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=n-08JZnfKLE:yZhHN1SnAPc:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2007/06/ohio_mess_could.html</feedburner:origLink></entry>
    <entry>
        <title>Find the Phish</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/SgS7aQDlfXY/find_the_phish.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2007/06/find_the_phish.html" thr:count="2" thr:updated="2007-06-29T14:44:10-05:00" />
        <id>tag:typepad.com,2003:post-35477386</id>
        <published>2007-06-18T11:19:53-05:00</published>
        <updated>2007-06-18T11:19:53-05:00</updated>
        <summary type="html">My fiancee forwarded an e-mail she received today from a bank that she does not use. The e-mail stated that the bank had locked her online access and needed some information from her. Here is the gist of it: "Dear...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">
&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&lt;font size="3"&gt;My fiancee forwarded an e-mail she received today from a bank that she does not use. The e-mail stated&amp;nbsp;that the bank&amp;nbsp;had locked her online access and needed some information from her.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Here is the gist of it:&lt;/font&gt;&lt;/p&gt; &lt;p&gt;"Dear customer, &lt;/p&gt; &lt;p&gt;Your access to Online Services has been suspended. Due to a miss-match access code between your Site key information. To enable you continue accessing your online account it will only take you few minutes to re-activate your account. Click on the link below and you will be taken straight to where you can activate your account." &lt;p&gt;&lt;font size="3"&gt;It goes on to provide a link to the bank, which if investigated shows that it actually points to a link at MISIONCRISTIANAELIMHN.com. Performing a quick check at dnsstuff.com shows that it is registered to Solucion Logica in San Pedro Sula, Cortez, Honduras with Julius Barber as the technical contact. Continuing along this path, I visited Solucion Logica's website at &lt;a href="http://www.slogica.net"&gt;www.slogica.net&lt;/a&gt; and found that they are currently having problems with their mail because one of their servers is being used for Spam. &lt;/font&gt; &lt;p&gt;&lt;font size="3"&gt;Of course, they say that they are investigating who the culprit is and once that account has been discovered, it will be suspended. Also you are welcome to call 9982-8141 if you have any questions, but you better be fluent in Spanish.&lt;/font&gt; &lt;p&gt;&lt;font size="3"&gt;I guess where I'm going with this is the fact that&amp;nbsp;this should not be happening. Organizations which allow people to spam from their servers should be held liable for any damage that it does.&amp;nbsp;And let's face it, this is not just&amp;nbsp;spam but an attempt to illegally&amp;nbsp;gain someone's banking information. &lt;/font&gt; &lt;p&gt;&lt;font size="3"&gt;No&amp;nbsp;less than an outright attempt to steal money from someone and it should not be tolerated.&lt;/font&gt; &lt;p&gt;&lt;font size="3"&gt;I am a strong proponent of what the Electronic Frontiers Foundation represents and I believe an open Internet allows for the most advances. However, allowing people to attempt such flagrant scams should not be tolerated. And yes, there are other things that occur over the Internet that are even more disturbing but our law enforcement&amp;nbsp;personnel are already&amp;nbsp;pursuing those individuals. &lt;/font&gt; &lt;p&gt;&lt;font size="3"&gt;I guess I find it hard to believe that in this day and age, someone can feel so brazen as to attempt something like a phishing scam and not be concerned about the repercussions.&lt;/font&gt; &lt;p&gt;&lt;font size="3"&gt;Let us&amp;nbsp;hope that someone will put into effect a mechanism to block those that attempt scams such as these. &lt;/font&gt; &lt;p&gt;&lt;font size="3"&gt;Here's a thought: If a government body ran a DDOS, after judicial approval similar to a wiretap proceeding, against one of these creeps, it would force ISPs to be much more diligent about the junk they allow&amp;nbsp;through their networks. &lt;/font&gt; &lt;p&gt;&lt;font size="3"&gt;Of course, the ISP would need to be given prior knowledge and a chance to work the issue out themselves, but at least we would have some recourse.&lt;/font&gt; &lt;p&gt;&lt;font size="3"&gt;Right now, we solely place the burden of protecting yourself on the end user which is sounds like money to a phisher.&lt;/font&gt; &lt;p&gt;&lt;font size="3"&gt;What do you think?&lt;/font&gt; &lt;p&gt;&lt;font size="3"&gt;Michael Mongold&lt;/font&gt;&lt;/p&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:4882fe96-3aff-40c5-96f6-e3df04382475" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;43 Things tags: &lt;a href="http://www.43things.com/tag/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Phishing" rel="tag"&gt;Phishing&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Phish" rel="tag"&gt;Phish&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/MISIONCRISTIANAELIMHN.com" rel="tag"&gt;MISIONCRISTIANAELIMHN.com&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/San%20Pedro%20Sula" rel="tag"&gt;San Pedro Sula&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Cortez" rel="tag"&gt;Cortez&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Honduras" rel="tag"&gt;Honduras&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Solucion%20Logica" rel="tag"&gt;Solucion Logica&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/www.slogica.net" rel="tag"&gt;www.slogica.net&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/DDOS" rel="tag"&gt;DDOS&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:0a456126-b305-4d75-b7a8-883fedadf876" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;BuzzNet tags: &lt;a href="http://www.buzznet.com/tags/Michael%20Mongold/" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Phishing/" rel="tag"&gt;Phishing&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Phish/" rel="tag"&gt;Phish&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/MISIONCRISTIANAELIMHN.com/" rel="tag"&gt;MISIONCRISTIANAELIMHN.com&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/San%20Pedro%20Sula/" rel="tag"&gt;San Pedro Sula&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Cortez/" rel="tag"&gt;Cortez&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Honduras/" rel="tag"&gt;Honduras&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Solucion%20Logica/" rel="tag"&gt;Solucion Logica&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/www.slogica.net/" rel="tag"&gt;www.slogica.net&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/DDOS/" rel="tag"&gt;DDOS&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:c1815908-4942-48b3-aa70-c41d3c9d1b22" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;del.icio.us tags: &lt;a href="http://del.icio.us/popular/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Phishing" rel="tag"&gt;Phishing&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Phish" rel="tag"&gt;Phish&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/MISIONCRISTIANAELIMHN.com" rel="tag"&gt;MISIONCRISTIANAELIMHN.com&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/San%20Pedro%20Sula" rel="tag"&gt;San Pedro Sula&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Cortez" rel="tag"&gt;Cortez&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Honduras" rel="tag"&gt;Honduras&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Solucion%20Logica" rel="tag"&gt;Solucion Logica&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/www.slogica.net" rel="tag"&gt;www.slogica.net&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/DDOS" rel="tag"&gt;DDOS&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:c7c942ac-c7d1-4ccb-a48c-2f30fe6e919a" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Flickr tags: &lt;a href="http://flickr.com/photos/tags/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Phishing" rel="tag"&gt;Phishing&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Phish" rel="tag"&gt;Phish&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/MISIONCRISTIANAELIMHN.com" rel="tag"&gt;MISIONCRISTIANAELIMHN.com&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/San%20Pedro%20Sula" rel="tag"&gt;San Pedro Sula&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Cortez" rel="tag"&gt;Cortez&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Honduras" rel="tag"&gt;Honduras&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Solucion%20Logica" rel="tag"&gt;Solucion Logica&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/www.slogica.net" rel="tag"&gt;www.slogica.net&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/DDOS" rel="tag"&gt;DDOS&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:93b81fa5-f106-42c4-b9d5-7cb927842455" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;IceRocket tags: &lt;a href="http://blogs.icerocket.com/search?q=Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Phishing" rel="tag"&gt;Phishing&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Phish" rel="tag"&gt;Phish&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=MISIONCRISTIANAELIMHN.com" rel="tag"&gt;MISIONCRISTIANAELIMHN.com&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=San%20Pedro%20Sula" rel="tag"&gt;San Pedro Sula&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Cortez" rel="tag"&gt;Cortez&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Honduras" rel="tag"&gt;Honduras&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Solucion%20Logica" rel="tag"&gt;Solucion Logica&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=www.slogica.net" rel="tag"&gt;www.slogica.net&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=DDOS" rel="tag"&gt;DDOS&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:ca47a892-be37-4ea7-8e78-d6182ff8676f" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;LiveJournal tags: &lt;a href="http://www.livejournal.com/interests.bml?int=Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Phishing" rel="tag"&gt;Phishing&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Phish" rel="tag"&gt;Phish&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=MISIONCRISTIANAELIMHN.com" rel="tag"&gt;MISIONCRISTIANAELIMHN.com&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=San%20Pedro%20Sula" rel="tag"&gt;San Pedro Sula&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Cortez" rel="tag"&gt;Cortez&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Honduras" rel="tag"&gt;Honduras&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Solucion%20Logica" rel="tag"&gt;Solucion Logica&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=www.slogica.net" rel="tag"&gt;www.slogica.net&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=DDOS" rel="tag"&gt;DDOS&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:32f79bcc-594f-4109-a4de-360950a02e3f" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati tags: &lt;a href="http://technorati.com/tags/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Phishing" rel="tag"&gt;Phishing&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Phish" rel="tag"&gt;Phish&lt;/a&gt;, &lt;a href="http://technorati.com/tags/MISIONCRISTIANAELIMHN.com" rel="tag"&gt;MISIONCRISTIANAELIMHN.com&lt;/a&gt;, &lt;a href="http://technorati.com/tags/San%20Pedro%20Sula" rel="tag"&gt;San Pedro Sula&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Cortez" rel="tag"&gt;Cortez&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Honduras" rel="tag"&gt;Honduras&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Solucion%20Logica" rel="tag"&gt;Solucion Logica&lt;/a&gt;, &lt;a href="http://technorati.com/tags/www.slogica.net" rel="tag"&gt;www.slogica.net&lt;/a&gt;, &lt;a href="http://technorati.com/tags/DDOS" rel="tag"&gt;DDOS&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=SgS7aQDlfXY:c1qPUAsF708:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=SgS7aQDlfXY:c1qPUAsF708:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=SgS7aQDlfXY:c1qPUAsF708:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=SgS7aQDlfXY:c1qPUAsF708:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=SgS7aQDlfXY:c1qPUAsF708:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=SgS7aQDlfXY:c1qPUAsF708:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=SgS7aQDlfXY:c1qPUAsF708:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=SgS7aQDlfXY:c1qPUAsF708:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=SgS7aQDlfXY:c1qPUAsF708:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=SgS7aQDlfXY:c1qPUAsF708:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=SgS7aQDlfXY:c1qPUAsF708:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2007/06/find_the_phish.html</feedburner:origLink></entry>
    <entry>
        <title>Ohio State Employees Show It All</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/TechnologySecurity/~3/ZfliK4q78Tw/ohio_state_empl.html" />
        <link rel="replies" type="text/html" href="http://securityblog.typepad.com/technology_security/2007/06/ohio_state_empl.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-35374452</id>
        <published>2007-06-15T14:09:11-05:00</published>
        <updated>2007-06-15T14:09:11-05:00</updated>
        <summary type="html">An employee for the state of Ohio lost a cd containing the Social Security numbers and "other" personal information for ALL 64,000 Ohio state employees. Now Governor Ted Strickland has stepped in and issued an executive order to change the...</summary>
        <author>
            <name>Michael Mongold</name>
        </author>
        
        
<content type="html" xml:lang="en-US" xml:base="http://securityblog.typepad.com/technology_security/">
&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&lt;font size="3"&gt;An employee for the state of Ohio lost a cd containing the Social Security numbers and "other" personal information for ALL 64,000 Ohio state employees. &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Now Governor Ted Strickland has stepped in and issued an executive order to change the way data is handled.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;I did a quick search to look at who had picked up this release. It was on the top of MSNBC's website under the heading "Also Making Headlines". ABC, the Boston Herald, Baltimore Sun, Forbes, Houston Chronicle, and over 130 other news outlets decided that this was important enough to announce. Not the kind of headlines you want to make.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;So please take a moment and &lt;a title="Opens a seperate web page to Ohio.gov" href="http://www.ohio.gov/ohioportalnews.stm#061507" target="_blank"&gt;visit this site&lt;/a&gt;. It is the Governor office's announcement and a copy of his executive order. I believe they are handling this very well and I completely approve of the steps they are taking and the immediacy they are giving this issue. &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Among the steps,&amp;nbsp;is a change in their completely BONE-HEAD methodology of storing this data off-site. That alone should get someone fired. Storing this kind of information at some employee's apartment? Are you kidding me? Folks, if any of you are doing this then count yourself lucky that you are still employed and hire someone today that can securely and legitimately store the data.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Next, the assessment is so important.&amp;nbsp;They need to know what data is important to secure and what data is not. They need to&amp;nbsp;insure all&amp;nbsp;points where the data is handled is done so properly.&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Lastly, the push to have this occur within seventy-five days is extremely aggressive for any&amp;nbsp;government body so I'll cut them some slack on the timeframe.&lt;/font&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Also, I like the fact that they have setup a &lt;a title="Opens a seperate web page to Ohio.gov" href="http://www.ohio.gov/idprotect/" target="_blank"&gt;website&lt;/a&gt; so the state employees can have a place to get the latest info on the breach. &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Of course, credit monitoring (and the associated costs with that)&amp;nbsp;is &lt;em&gt;de rigeur&lt;/em&gt; at this point. &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;It is unfortunate that the disc&amp;nbsp;(or device depending on where&amp;nbsp;you get your information)&amp;nbsp;was "contained on a specialized medium" and that "it is highly unlikely that the data could be accessed by someone without the knowledge of how to do so." &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;I say unfortunate because it doesn't really mean squat in this situation. They are still being run through the ringer because they can't say authoritatively that they disc is encrypted and completely worthless to anyone that doesn't have the key. &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;So take a good look at how Ohio is addressing this problem. They are doing a great job of trying to clean up a mess they could have prevented in the first place. &lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;In fact, I would just keep this site handy in case you don't have your own ducks in a row. Ohio might become a good template for your company. And on that sarcastic note, I sincerely wish you a fun and safe weekend!&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="3"&gt;Michael Mongold&lt;/font&gt;&lt;/p&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:13e3d1bb-4281-4ad1-97c0-218cb3598cd3" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Technorati tags: &lt;a href="http://technorati.com/tags/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Ohio" rel="tag"&gt;Ohio&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Ted%20Strickland" rel="tag"&gt;Ted Strickland&lt;/a&gt;, &lt;a href="http://technorati.com/tags/device%20lost" rel="tag"&gt;device lost&lt;/a&gt;, &lt;a href="http://technorati.com/tags/data%20theft" rel="tag"&gt;data theft&lt;/a&gt;, &lt;a href="http://technorati.com/tags/data%20encryption" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://technorati.com/tags/Ohio%20State" rel="tag"&gt;Ohio State&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:7937879e-3a9f-4c26-8c74-c16423e39202" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;LiveJournal tags: &lt;a href="http://www.livejournal.com/interests.bml?int=Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Ohio" rel="tag"&gt;Ohio&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Ted%20Strickland" rel="tag"&gt;Ted Strickland&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=device%20lost" rel="tag"&gt;device lost&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=data%20theft" rel="tag"&gt;data theft&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=data%20encryption" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://www.livejournal.com/interests.bml?int=Ohio%20State" rel="tag"&gt;Ohio State&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:394af4d9-79ca-4d6b-97a9-3ff6578c68fe" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;IceRocket tags: &lt;a href="http://blogs.icerocket.com/search?q=Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Ohio" rel="tag"&gt;Ohio&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Ted%20Strickland" rel="tag"&gt;Ted Strickland&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=device%20lost" rel="tag"&gt;device lost&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=data%20theft" rel="tag"&gt;data theft&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=data%20encryption" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://blogs.icerocket.com/search?q=Ohio%20State" rel="tag"&gt;Ohio State&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:f6b137ed-98cf-448b-97d5-27ecbc73bd73" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;Flickr tags: &lt;a href="http://flickr.com/photos/tags/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Ohio" rel="tag"&gt;Ohio&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Ted%20Strickland" rel="tag"&gt;Ted Strickland&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/device%20lost" rel="tag"&gt;device lost&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/data%20theft" rel="tag"&gt;data theft&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/data%20encryption" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://flickr.com/photos/tags/Ohio%20State" rel="tag"&gt;Ohio State&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:089dd5ce-af8d-4adb-a3b9-15f71a9f5dd3" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;del.icio.us tags: &lt;a href="http://del.icio.us/popular/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Ohio" rel="tag"&gt;Ohio&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Ted%20Strickland" rel="tag"&gt;Ted Strickland&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/device%20lost" rel="tag"&gt;device lost&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/data%20theft" rel="tag"&gt;data theft&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/data%20encryption" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://del.icio.us/popular/Ohio%20State" rel="tag"&gt;Ohio State&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:b291e6a2-aabb-44c4-9af6-f7ccfd03fa4a" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;BuzzNet tags: &lt;a href="http://www.buzznet.com/tags/Michael%20Mongold/" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Ohio/" rel="tag"&gt;Ohio&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Ted%20Strickland/" rel="tag"&gt;Ted Strickland&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/device%20lost/" rel="tag"&gt;device lost&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/data%20theft/" rel="tag"&gt;data theft&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/data%20encryption/" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://www.buzznet.com/tags/Ohio%20State/" rel="tag"&gt;Ohio State&lt;/a&gt;&lt;/div&gt; &lt;div class="wlWriterSmartContent" id="0767317B-992E-4b12-91E0-4F059A8CECA8:a21c5c77-6fd2-408f-b537-698dedfb42de" contenteditable="false" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px"&gt;43 Things tags: &lt;a href="http://www.43things.com/tag/Michael%20Mongold" rel="tag"&gt;Michael Mongold&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Ohio" rel="tag"&gt;Ohio&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Ted%20Strickland" rel="tag"&gt;Ted Strickland&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/device%20lost" rel="tag"&gt;device lost&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/data%20theft" rel="tag"&gt;data theft&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/data%20encryption" rel="tag"&gt;data encryption&lt;/a&gt;, &lt;a href="http://www.43things.com/tag/Ohio%20State" rel="tag"&gt;Ohio State&lt;/a&gt;&lt;/div&gt; &lt;p&gt;&lt;font size="3"&gt;&lt;/font&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=ZfliK4q78Tw:1jEqHQBPbZ8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=ZfliK4q78Tw:1jEqHQBPbZ8:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=ZfliK4q78Tw:1jEqHQBPbZ8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=ZfliK4q78Tw:1jEqHQBPbZ8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=ZfliK4q78Tw:1jEqHQBPbZ8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=ZfliK4q78Tw:1jEqHQBPbZ8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=ZfliK4q78Tw:1jEqHQBPbZ8:wF9xT3WuBAs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=ZfliK4q78Tw:1jEqHQBPbZ8:wF9xT3WuBAs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=ZfliK4q78Tw:1jEqHQBPbZ8:KwTdNBX3Jqk"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?i=ZfliK4q78Tw:1jEqHQBPbZ8:KwTdNBX3Jqk" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TechnologySecurity?a=ZfliK4q78Tw:1jEqHQBPbZ8:5lVTG1FW49M"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TechnologySecurity?d=5lVTG1FW49M" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;</content>


    <feedburner:origLink>http://securityblog.typepad.com/technology_security/2007/06/ohio_state_empl.html</feedburner:origLink></entry>
 
</feed><!-- ph=1 --><!-- nhm:dynamic-ssi -->
