<?xml version='1.0' encoding='UTF-8'?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-25971470</atom:id><lastBuildDate>Mon, 18 May 2026 13:49:53 +0000</lastBuildDate><title>TRUST Security and Privacy Blog</title><description>Security and Privacy news items</description><link>http://trust-news.blogspot.com/</link><managingEditor>noreply@blogger.com (Christopher Brooks)</managingEditor><generator>Blogger</generator><openSearch:totalResults>392</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-1729907514994454422</guid><pubDate>Mon, 17 Dec 2012 19:39:00 +0000</pubDate><atom:updated>2012-12-17T11:39:35.584-08:00</atom:updated><title></title><description>&lt;h2&gt;
Please see the TRUST in the News blog&lt;/h2&gt;
Rather than having two blogs about TRUST, we&#39;ve decided to focus on one blog. Please see &lt;a href=&quot;http://trust-website-news.blogspot.com/&quot;&gt;TRUST in the News&lt;/a&gt;.</description><link>http://trust-news.blogspot.com/2012/12/please-see-trust-in-news-blog-rather.html</link><author>noreply@blogger.com (Christopher Brooks)</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-4862341621710507536</guid><pubDate>Thu, 03 May 2012 22:27:00 +0000</pubDate><atom:updated>2012-05-03T15:27:23.966-07:00</atom:updated><title>&quot;California Chosen as Home for Computing Institute&quot;</title><description>The May 1, 2012 NY Times article &quot;&lt;a href=&quot;http://www.nytimes.com/2012/05/01/science/simons-foundation-chooses-uc-berkeley-for-computing-center.html?smid=pl-share&quot;&gt;California Chosen as Home for Computing Institute&lt;/a&gt;&quot; covers the $60 million theoretical computing center to be hosted at UC Berkeley.  UCB College of Engineering Dean and TRUST PI S. Shankar Sastry is &lt;a href=&quot;http://www.dailycal.org/2012/05/02/uc/&quot;&gt;quoted elsewhere&lt;/a&gt; as saying that the goal of the institute will be to &quot;bring into the educational mainstream, the role of computing and theory of computational science.&quot;</description><link>http://trust-news.blogspot.com/2012/05/california-chosen-as-home-for-computing.html</link><author>noreply@blogger.com (Christopher Brooks)</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-7048453477442829573</guid><pubDate>Sun, 08 Apr 2012 00:31:00 +0000</pubDate><atom:updated>2012-04-07T17:55:09.371-07:00</atom:updated><title>New Mac malware epidemic exploits weaknesses in Apple ecosystem</title><description>For Mac owners, the nightmare scenario finally arrived. A piece of malware called Flashback, which has been in existence and steadily evolving for at least seven months, has infected more than 600,000 Macs worldwide, based on forensic analysis by a Russian antivirus company.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;What makes this outbreak especially disturbing is that the owners of infected Macs didn’t have to fall for social engineering, give away their administrative password, or do anything stupid. All they had to do was visit a web page using a Mac that had a current version of Java installed.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;Although Apple owners have been told for years that Macs don&#39;t get viruses. that&#39;s known to be untrue. Furthermore, Apple&#39;s casual approach to security updates makes them debatably more vulnerable. The Java flaw was reported in January and patched in February by Oracle.  Apple&#39;s version of Java didn&#39;t get a patch until early April.&lt;br /&gt;&lt;p&gt;&lt;br /&gt;Security expert &lt;a href=&quot;http://krebsonsecurity.com/2012/04/urgent-fix-for-zero-day-mac-java-flaw/&quot;&gt;Brian Krebs&lt;/a&gt; points out that this behavior by Apple is lamentably typical:&lt;br /&gt;&lt;blockquote&gt;Apple maintains its own version of Java, and as with this release, it has typically fallen unacceptably far behind Oracle in patching critical flaws in this heavily-targeted and cross-platform application. In 2009, I examined Apple’s patch delays on Java and found that the company patched Java flaws on average about six months after official releases were made available by then-Java maintainer Sun. The current custodian of Java – Oracle Corp. – first issued an update to plug this flaw and others back on Feb. 17. I suppose Apple’s performance on this front has improved, but its lackadaisical (and often plain puzzling) response to patching dangerous security holes perpetuates the harmful myth that Mac users don’t need to be concerned about malware attacks.&lt;/blockquote&gt;&lt;br /&gt;For complete article, see &lt;a href=&quot;http://www.zdnet.com/blog/bott/new-mac-malware-epidemic-exploits-weaknesses-in-apple-ecosystem/4726?tag=nl.e539&quot;&gt;ZDNet&lt;/a&gt;.</description><link>http://trust-news.blogspot.com/2012/04/new-mac-malware-epidemic-exploits.html</link><author>noreply@blogger.com (Mary Stewart)</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-8704184759931556940</guid><pubDate>Tue, 01 Feb 2011 00:57:00 +0000</pubDate><atom:updated>2011-01-31T17:24:05.297-08:00</atom:updated><title>DHS:  $40M To Research Next Big Thing in Cyber Security</title><description>The U.S. Department of Homeland Security announced a call for proposals this week in a $40 million program to encourage research and development in a wide range of topics related to cyber security.  In a Broad Agency Announcement (BAA) dated January 26th, the DHS said it was soliciting papers and proposals centered on 14 different areas, including topics in software assurance, enterprise security metrics, usable security, as well as challenges arising from insider threats.&lt;br /&gt;&lt;br /&gt;The Federal government has moved in recent ears to attract top security talent, while organization&#39;s like In-Q-Tel, the CIA&#39;s venture firm, have funded new, innovative ideas. But, as in the private sector, an overabundance of security products hasn&#39;t improved the security position of government networks.&lt;br /&gt;&lt;br /&gt;Concurrently, spending on IT security continues to be criticized for waste of resources and a poor track record concerning learning from security incidents, e.g., the Wikileaks issue showcased the startling lack of security with sensitive data.  The new &lt;a href=&quot;https://www.fbo.gov/index?s=opportunity&amp;mode=form&amp;id=3c71c829bc28fcea61aef3a5e0f58ffe&amp;tab=core&amp;_cview=0&quot;&gt; DHS Proposal&lt;/a&gt; aims to address those issues as well.&lt;br /&gt;&lt;br /&gt;See article in &lt;a href=&quot;https://threatpost.com/en_us/blogs/dhs-40m-research-next-big-thing-cyber-security-012811&quot;&gt;threatpost&lt;/a&gt;.</description><link>http://trust-news.blogspot.com/2011/01/dhs-40m-to-research-next-big-thing-in.html</link><author>noreply@blogger.com (Mary Stewart)</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-8135786923328238065</guid><pubDate>Fri, 07 May 2010 22:09:00 +0000</pubDate><atom:updated>2010-05-07T15:43:34.411-07:00</atom:updated><title>Discarded Copiers Hold Sensitive Data on Hard Drives</title><description>&lt;a href=&quot;https://www.sans.org/newsletters/newsbites/newsbites.php?vol=12&amp;issue=32#sID307&quot;&gt; SANS Newsbites&lt;/a&gt; tells of a CBS news investigation that had found that the hard drives of four digital copy machines purchased second-hand contained vast amounts of personally identifiable information, including police files on domestic violence and sex crimes, copies of pay stubs and checks and sensitive medical information like test results, prescriptions and diagnoses. This would be a major coup for those in the identity theft business.&lt;br /&gt;&lt;blockquote&gt;&quot;You&#39;re talking about potentially ruining someone&#39;s life,&quot; said Ira Winkler, former analyst for the National Security Agency, &quot;where they could suffer serious social repercussions.&quot;&lt;/blockquote&gt;&lt;br /&gt;While some manufacturers say they offer security or encryption packages on their products, evidence keeps piling up in warehouses that many businesses are not willing to pay for such protection and the average American is oblivious to the dangers posed by digital copiers.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;For full story, see &lt;a href=&quot;http://www.cbsnews.com/stories/2010/04/19/eveningnews/main6412439.shtml&quot;&gt; CBS Evening News&lt;/a&gt;.</description><link>http://trust-news.blogspot.com/2010/05/discarded-copiers-hold-sensitive-data.html</link><author>noreply@blogger.com (Mary Stewart)</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-370960532987889410</guid><pubDate>Tue, 13 Apr 2010 16:29:00 +0000</pubDate><atom:updated>2010-04-13T10:09:32.029-07:00</atom:updated><title>Please do not change your password</title><description>Mark Pothier&#39;s Boston Globe article, &lt;a href=&quot;http://www.boston.com/bostonglobe/ideas/articles/2010/04/11/please_do_not_change_your_password/&quot;&gt;Please do not change your password&lt;/a&gt;,&quot; covers a paper by Microsoft Researcher &lt;a href=&quot;http://research.microsoft.com/en-us/people/cormac/&quot;&gt;Cormac Herley&lt;/a&gt;, &quot;&lt;a href=&quot;http://research.microsoft.com/users/cormac/papers/2009/SoLongAndNoThanks.pdf&quot;&gt;So Long, and No Thanks for the Externalities: the Rational Rejection of Security Advice by Users&lt;/a&gt;,&quot; from the 2009 &lt;a href=&quot;http://www.nspw.org/&quot;&gt;New Security Paradigms Workshop&lt;/a&gt;.  Herley argues &quot;that user&#39;s rejection of the security advice they receive is entirely rational from an economic perspective.&quot;  Herley discusses &quot;password rules,&quot; &quot;teaching users to recognized phishing sites by reading URLs&quot; and &quot;certificate errors&quot;.  Users obviously &lt;a href=&quot;http://it.slashdot.org/story/10/01/21/1313235/Analysis-of-32-Million-Breached-Passwords&quot;&gt;choose bad passwords&lt;/a&gt;, but does password aging actually help? There was some discussion on &lt;a href=&quot;http://blogs.techrepublic.com.com/security/?p=3275&quot;&gt;TechRepublic&lt;/a&gt; and &lt;a href=&quot;http://news.slashdot.org/story/10/03/16/1931214/Users-Rejecting-Security-Advice-Considered-Rational&quot;&gt;Slashdot&lt;/a&gt;.</description><link>http://trust-news.blogspot.com/2010/04/please-do-not-change-your-password.html</link><author>noreply@blogger.com (Christopher Brooks)</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-6145578758369346322</guid><pubDate>Sat, 13 Mar 2010 02:05:00 +0000</pubDate><atom:updated>2010-03-12T18:13:18.129-08:00</atom:updated><title>&quot;Privacy Protection Needed as Smart Grid Arrives&quot;</title><description>A press release from UC Berkeley&#39;s Law School, &quot;&lt;a href=&quot;http://www.law.berkeley.edu/7966.htm&quot;&gt;Privacy Protection Needed as Smart Grid Arrives&lt;/a&gt;&quot; points out privacy concerns with PG&amp;E&#39;s &lt;a href=&quot;http://www.pge.com/smartmeter/&quot;&gt;Smart Meter&lt;/a&gt; project.  In particular:&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&quot;Smart meters being installed now in California will collect 750 to 3,000 data points a month per household. This detailed energy usage data can indicate whether someone is at home or out, entertaining guests, or using particular appliances.&quot;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;See &quot;&lt;a href=&quot;http://www.sfgate.com/cgi-bin/blogs/scavenger/detail?entry_id=59017&quot;&gt;PG&amp;E customer refuses to take smart meter, locks up old meter&lt;/a&gt;&quot; for some of the controversy surrounding privacy and the accuracy of the meters.</description><link>http://trust-news.blogspot.com/2010/03/privacy-protection-needed-as-smart-grid.html</link><author>noreply@blogger.com (Christopher Brooks)</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-4036802287224671055</guid><pubDate>Thu, 25 Feb 2010 00:09:00 +0000</pubDate><atom:updated>2010-02-24T16:41:59.880-08:00</atom:updated><title>Judge Hears Arguments on Google Book Settlement</title><description>Federal judge &lt;a href=&quot;http://topics.nytimes.com/topics/reference/timestopics/people/c/denny_chin/index.html?inline=nyt-per&quot;&gt; Denny Chin&lt;/a&gt; heard more than four hours of testimony in a packed courtroom this week about the hotly contested class-action lawsuit filed against Google.&lt;br /&gt;&lt;br /&gt;Supporters of a deal that would allow Google to create an extensive digital library and bookstore included the president of the National Federation of the Blind, a librarian at the University of Michigan, and a lawyer for Sony Electronics stated that the agreement would make millions of hard-to-find books available to an enormous audience.&lt;br /&gt;&lt;br /&gt;A much larger group of opponents cited many concerns related to competition, privacy, violation of copyright and abuse of class-action processes. Law Professor at the University of California, Berkeley, &lt;b&gt;Pamela Samuelson&lt;/b&gt; says that her academic colleagues would prefer to have their books available via open access, and also supported open access to orphan works. She said &quot;the authors Guild has not fairly represented academic authors.&quot; &lt;blockquote&gt;“We think orphan works is a public policy issue to be decided by Congress,” she said. She mentioned that she had asked for “meaningful constraints” on pricing subscriptions. And, while not responding directly to University of Michigan Librarian Courant, she offered a contrasting perspective: “for plaintiffs, books are commodities. For academics, books are a slow form of social dialog.&quot;&lt;/blockquote&gt;&lt;br /&gt;See more in &lt;a href=&quot;http://www.nytimes.com/2010/02/19/technology/19google.html&quot;&gt; The New York Times&lt;/a&gt; and a February 12th &lt;a href=&quot;http://people.ischool.berkeley.edu/~pam/GBSBrussels.pdf&quot;&gt; presentation &lt;/a&gt;, &quot;How Fair is the Google Book Search Settlement&quot; by Berkeley law professor &lt;b&gt;Pamela Samuelson&lt;/b&gt;.</description><link>http://trust-news.blogspot.com/2010/02/judge-hears-arguments-on-google-book.html</link><author>noreply@blogger.com (Mary Stewart)</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-208528999984818855</guid><pubDate>Sat, 20 Feb 2010 01:23:00 +0000</pubDate><atom:updated>2010-02-19T17:44:43.782-08:00</atom:updated><title>Adobe Download Manager Installing Software Without Consent</title><description>&lt;a href=&quot;http://yro.slashdot.org/story/10/02/19/223211/Adobe-Download-Manager-Installing-Software-Without-Consent&quot;&gt; Slashdot&lt;/a&gt; is running an article about a problem in the Adobe Download Manager (ADM) found by Researcher Aviv Raff. The net effect of the problem is that a user can be tricked into downloading and installing software without actual consent.&lt;br /&gt;&lt;br /&gt;In a related article in &lt;i&gt;PCMAG.COM&lt;/i&gt;, Raff&#39;s list of the following software can be downloaded and installed for users that have ADM installed by merely following a link to Adobe&#39;s site, including Adobe Flash 10, Adobe Reader 9.3, Adobe Reader 8.2,  Google Toolbar6.3, McAfee Security Scan Plus and a half dozen more.  &lt;br /&gt;&lt;br /&gt;The ADM FAQ explains that ADM is installed when needed and removed when the system reboots. However, this ignores the fact that Adobe downloads don&#39;t tyically require a reboot and users might go a long time between them.&lt;br /&gt;&lt;br /&gt;Raff also announced that he had found a remote code execution bug in ADM, increasing the danger of remote compromise by an order of magnitude or two. &lt;br /&gt;&lt;br /&gt;See more at &lt;a href=&quot;http://blogs.pcmag.com/securitywatch/2010/02/unauthorized_downloads_through.php&quot;&gt; Security Watch&lt;/a&gt;.</description><link>http://trust-news.blogspot.com/2010/02/adobe-download-manager-installing.html</link><author>noreply@blogger.com (Mary Stewart)</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-5718681072431990207</guid><pubDate>Thu, 18 Feb 2010 23:59:00 +0000</pubDate><atom:updated>2010-02-18T16:07:01.241-08:00</atom:updated><title>NY Times: &quot;Critics Say Google Invades Privacy With New Service&quot;</title><description>TRUST faculty member &lt;a href=&quot;http://www.truststc.org/people/directory/dkm&quot;&gt;Deirdre Mulligan&lt;/a&gt; is quoted in the Feburary 12, 2010 NY Times article &lt;a href=&quot;http://www.nytimes.com/2010/02/13/technology/internet/13google.html&quot;&gt;Critics Say Google Invades Privacy With New Service&lt;/a&gt;.  The article discusses privacy issues in Google&#39;s &lt;a href=&quot;http://buzz.google.com&quot;&gt;Buzz&lt;/a&gt; product where users may unintentionally publicly share the names of their contacts.  Apparently, Google has made it difficult to make the contacts list private. Professor Mulligan is quoted as saying “You want to have a simple rollback mechanism, so once things are not what you expected them to be, you can get out quickly and not have to play a game of Whack-a-Mole.”</description><link>http://trust-news.blogspot.com/2010/02/ny-times-critics-say-google-invades.html</link><author>noreply@blogger.com (Christopher Brooks)</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-1339516767284717505</guid><pubDate>Fri, 15 Jan 2010 23:45:00 +0000</pubDate><atom:updated>2010-01-15T17:14:05.058-08:00</atom:updated><title>US preps cyber outfit to protect national electric grid</title><description>The Department of Energy has said it would spend $8.5 million to create a &lt;a href=&quot;http://www.oe.energy.gov/controlsecurity.htm&quot;&gt; National Energy Sector Cyber Organization&lt;/a&gt; that would help protect the nation&#39;s electric power grid, incorporating smart grid technology.&lt;br /&gt;&lt;br /&gt;The intent is to create an independent national energy sector cyber security organization that would accelerate research, development and deployment priorities, including policies and protocols, according to the DOE.&lt;br /&gt;&lt;br /&gt;DOE Acting Assistant Secretary Patricia Hoffman states: &lt;blockquote&gt;&quot;The scope and nature of security threats and their potential impact on our national security require the ability to act quickly to protect the bulk power system and to protect sensitive information from public disclosure. At the same time, we must continue to build long-term programs that improve information sharing and awareness between the public and private energy sector.&lt;br /&gt;&lt;br /&gt;&quot;The electric system is not the Internet. It is a carefully tended and balanced system that is critical to the Nation and the people. We must continue to strive towards an electric system that can survive an intentional cyber assault with no loss of critical functions,&quot; she said. &lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;See complete article at &lt;a href=&quot;http://www.networkworld.com/community/node/54820&quot;&gt; NETWORK WORLD&lt;/a&gt;.</description><link>http://trust-news.blogspot.com/2010/01/us-preps-cyber-outfit-to-protect.html</link><author>noreply@blogger.com (Mary Stewart)</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-6846313027423665219</guid><pubDate>Tue, 15 Sep 2009 17:45:00 +0000</pubDate><atom:updated>2009-09-15T10:50:56.647-07:00</atom:updated><title>Nonprofit for collecting info on SCADA &amp; PCS security incidents</title><description>The &lt;a href=&quot;http://catless.ncl.ac.uk/Risks/25.78.html#subj10&quot;&gt;Risks Digest&lt;/a&gt; has an item that refers to &lt;a href=&quot;http://www.managingautomation.com/maonline/news/read/NonProfit_Targets_CyberSecurity_in_Plants_33037&quot;&gt;Stephanie Neil&#39;s article in &quot;Managing Automation&quot;, 12 Sep 2009&lt;/a&gt; that discusses the &lt;a href=&quot;http://www.securityincidents.org/&quot;&gt;http://www.securityincidents.org&lt;/a&gt;, &quot;a newly formed non-profit group that provides public access to its Repository of Industrial Security Incidents (RISI)&quot;.  This group is targeted towards SCADA and process control security incidents.</description><link>http://trust-news.blogspot.com/2009/09/nonprofit-for-collecting-info-on-scada.html</link><author>noreply@blogger.com (Christopher Brooks)</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-5439012117588354673</guid><pubDate>Thu, 10 Sep 2009 23:52:00 +0000</pubDate><atom:updated>2009-09-10T17:10:25.551-07:00</atom:updated><title>How much are you worth on the black market?</title><description>&lt;a href=&quot;http://yro.slashdot.org/story/09/09/10/1837233/How-Much-Is-Your-Online-Identity-Worth&quot;&gt; &lt;i&gt;Slashdot&lt;/i&gt;&lt;/a&gt; reports a new tool being developed by Symantec intended to raise consumer awareness about cybercrime.  By answering a few questions about personal Internet use, the tool calculates your net worth on the black market calculations in three areas: how much your online assets are worth, how much your online identity would sell for on the black market, and your risk of becoming a victim of identity theft.  &lt;br /&gt;&lt;br /&gt;Norton&#39;s Online Risk Calculator is not intended to promote software or instill fear but to raise awareness about cybercrime, according to Marian Merritt, Internet security advocate for Symantec.  Merritt pointed out that cybercrime is now larger than the international drug trade. Nearly 10 million people have reported identity theft in United States in the past 12 months and one in four households have already been victimized, she said.&lt;br /&gt;&lt;br /&gt;Cybercrime is well reported in the IT space, but the message doesn&#39;t often reach the general public, according to Merritt. &quot;You turn on the news and they are talking about capturing drug dealers going across the border, but they rarely show a hacker in handcuffs,&quot; she said.&lt;br /&gt;&lt;br /&gt;See more in &lt;a href=&quot;http://www.itworld.com/software/77238/how-much-are-you-worth-black-market&quot;&gt; IT WORLD&lt;/a&gt;.</description><link>http://trust-news.blogspot.com/2009/09/how-much-are-you-worth-on-black-market.html</link><author>noreply@blogger.com (Mary Stewart)</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-3874023067047524178</guid><pubDate>Sun, 16 Aug 2009 23:24:00 +0000</pubDate><atom:updated>2009-08-16T16:32:31.722-07:00</atom:updated><title>NIST Releases Security Standards for Federal Systems</title><description>The &lt;a href=&quot;http://www.nist.gov/index.html&quot;&gt;National Institute of Standards and Technology&lt;/a&gt; (NIST) released &lt;a href=&quot;http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final.pdf&quot;&gt;Special Publication 800-53&lt;/a&gt;, titled &lt;i&gt;Recommended Security Controls for Federal Information Systems and Organizations&lt;/i&gt;.  This document addresses information security standards and guidelines, including minimum requirements for federal information systems.  Released as part of NIST’s statutory responsibilities under the Federal Information Security Management Act (FISMA), this publication is geared toward information system and information security professionals who develop, implement, operate, manage, or assess/monitor federal information systems.</description><link>http://trust-news.blogspot.com/2009/08/nist-releases-security-standards-for.html</link><author>noreply@blogger.com (Larry Rohrbough)</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-1173282041917509306</guid><pubDate>Thu, 23 Jul 2009 23:46:00 +0000</pubDate><atom:updated>2009-07-23T17:44:57.465-07:00</atom:updated><title>Adobe Vulnerability Targeted in Drive-by Attacks</title><description>eWEEK.COM is running a story about a new zero-day vulnerability affecting Adobe&#39;s Flash Player software that is being exploited by attackers via drive-by downloads.&lt;br /&gt;&lt;br /&gt;Adobe first warned about the vulnerability July 21, then issued an updated advisory the next night.  The issue affects current versions of Flash Player on Windows, Mac and Linux platforms.&lt;br /&gt;&lt;br /&gt;According to the U.S. Computer Emergency Response Team (US-CERT), an attacker can trigger an overflow by luring a user into opening a malicious Flash (SWF) file that is either hosted or embedded on a Web page or contained in a PDF file.  Then the attacker could either trigger a system crash or take full control of a vulnerable system.&lt;br /&gt;&lt;blockquote&gt;“There are reports that this vulnerability is being actively exploited in the wild via limited, targeted attacks against Adobe Reader v9 on Windows,” according to a post on the Adobe Product Security Incident Response Team blog. “We are in the process of developing a fix for the issue, and expect to provide an update for Flash Player v9 and v10 for Windows, Macintosh, and Linux by July 30, 2009(the date for Flash Player v9 and v10 for Solaris is still pending). We expect to provide an update for Adobe Reader and Acrobat v9.1.2 for Windows, Macintosh, and UNIX by July 31, 2009.” &lt;/blockquote&gt;&lt;blockquote&gt;“At the moment there (are) a low number of malicious sites serving the exploit, but we confirmed that the links have been injected in legitimate Websites to create a drive-by attack, as expected,” according to SANS Internet Storm Center. &lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;See full article at &lt;a href=&quot;http://www.eweek.com/c/a/Security/Adobe-Vulnerability-Targeted-in-Driveby-Attacks-695016/&quot;&gt; eWEEK.COM&lt;/a&gt;.</description><link>http://trust-news.blogspot.com/2009/07/adobe-vulnerability-targeted-in-drive.html</link><author>noreply@blogger.com (Mary Stewart)</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-3682772571256217996</guid><pubDate>Wed, 08 Jul 2009 00:51:00 +0000</pubDate><atom:updated>2009-07-07T18:03:39.563-07:00</atom:updated><title>Google Book Search Settlement Inquiry Announced</title><description>ISEDB&#39;s article &quot;&lt;a href=&quot;http://www.isedb.com/db/articles/2090/1/Google-Book-Search-Settlement-Inquiry-Announced/Page1.html&quot;&gt;Google Book Search Settlement Inquiry Announced&lt;/a&gt;&quot; includes a link to &lt;a href=&quot;http://www.truststc.org/people/directory/pam&quot;&gt;Pam Samuelson&#39;s&lt;/a&gt; talk &lt;a href=&quot;http://bit.ly/yxjs3&quot;&gt;Reflections on the Google Book Search Settlement&lt;/a&gt;.  See also her 4/17/09 guest blog &quot;&lt;a href=&quot;http://radar.oreilly.com/2009/04/legally-speaking-the-dead-soul.html&quot;&gt;Legally Speaking: The Dead Souls of the Google Booksearch Settlement&lt;/a&gt;&quot;, where she says:&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&quot;In the short run, the Google Book Search settlement will unquestionably bring about greater access to books collected by major research libraries over the years. But it is very worrisome that this agreement, which was negotiated in secret by Google and a few lawyers working for the Authors Guild and AAP (who will, by the way, get up to $45.5 million in fees for their work on the settlement—more than all of the authors combined!), will create two complementary monopolies with exclusive rights over a research corpus of this magnitude. Monopolies are prone to engage in many abuses.&quot;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&quot;The Book Search agreement is not really a settlement of a dispute over whether scanning books to index them is fair use. It is a major restructuring of the book industry’s future without meaningful government oversight. The market for digitized orphan books could be competitive, but will not be if this settlement is approved as is.&quot;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Professor Samuelson points out that &quot;nothing in the settlement agreement speaks about privacy interests of users&quot; and that this is very different than how libraries operate.</description><link>http://trust-news.blogspot.com/2009/07/google-book-search-settlement-inquiry.html</link><author>noreply@blogger.com (Christopher Brooks)</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-3349911122813588261</guid><pubDate>Tue, 26 May 2009 23:34:00 +0000</pubDate><atom:updated>2009-05-27T09:41:06.827-07:00</atom:updated><title>Announcement:  2nd Annual Privacy Law Scholar Conference, June 4-5 2009</title><description>The 2nd Annual Privacy Law Scholars Conference (PLSC) will be held at the Claremont Resort in Berkeley, CA, on June 4-5.  PLSC is an academic paper workshop, and there are no panels of boring talking heads.  Instead, we have two days of intense discussion about privacy issues.&lt;br /&gt;&lt;br /&gt;If you have students who are interested in working in the privacy field, I strongly encourage you to pass on info about the event.  It&#39;s free, and about 100 privacy academics (predominately law, but also econ and some computer science, including Peter Neumann, Chris Soghoian, and Jeff Jonas, the inventor of NORA) participate, as well as 50 leading legal practitioners.  It&#39;s a wonderful opportunity to network, share ideas,etc.&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://docs.law.gwu.edu/facweb/dsolove/PLSC/&quot;&gt;  &lt;i&gt;Schedule and information&lt;/i&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The password to all papers is &lt;code&gt;plsc2009&lt;/code&gt;.&lt;br /&gt;&lt;br /&gt;Send email to choofnagle at law.berkeley.edu if you would like to participate.</description><link>http://trust-news.blogspot.com/2009/05/announcement-2nd-annual-privacy-law.html</link><author>noreply@blogger.com (Mary Stewart)</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-5588579183945191038</guid><pubDate>Thu, 14 May 2009 16:23:00 +0000</pubDate><atom:updated>2009-05-14T09:41:14.930-07:00</atom:updated><title>Mathematical Advances Strengthen IT Security</title><description>&lt;a href=&quot;http://technews.acm.org/&quot;&gt; ACM TechNews&lt;/a&gt; is running an article about a new cryptography approach based on the mathematical theory of elliptic curves, a leading candidate to replace the widely used RSA public key security system.&lt;br /&gt;&lt;br /&gt;Elliptic curves are equasions with two variables, e.g., x and y, including terms where both x and y are raised to powers of two or more. The possibilities for elliptic curves and other modern mathematical techniques were discussed at a recent workshop organized by the European Science Foundation (ESF).&lt;blockquote&gt;“The impact of the elliptic curve method for integer factorisation (developed by my PhD advisor Hendrik Lenstra) has played a role in introducing elliptic curves to cryptographers, albeit for attacking the underlying problem on which RSA is based (the difficulty of factoring integers),” said David Kohel, convenor of the ESF workshop, from the Institut de Mathematiques de Luminy in Marseille, France. &lt;/blockquote&gt;&lt;br /&gt;Kohel describes the advantage of elliptic curve cryptography as its immunity to the specialized attacks that have degraded the strength of RSA (smaller keys can be used to provide the same levels of protection).&lt;blockquote&gt;&quot;In general, the cryptographer has the benefit over the cryptanalyst (the person attacking the cryptosystem) as he or she can select the key size for any desired level of security, provided everyone has the same base of knowledge of best attacks on the underlying cryptosystem,&quot; he says.&lt;/blockquote&gt;&lt;br /&gt;See details in &lt;a href=&quot;http://www.esf.org/activities/exploratory-workshops/news/ext-news-singleview/article/mathematical-advances-strengthen-it-security-579.html&quot;&gt; &lt;i&gt;European Science Foundation&lt;/i&gt;&lt;/a&gt;.</description><link>http://trust-news.blogspot.com/2009/05/acm-technews-is-running-article-about.html</link><author>noreply@blogger.com (Mary Stewart)</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-1640038329239099580</guid><pubDate>Tue, 28 Apr 2009 16:21:00 +0000</pubDate><atom:updated>2009-04-28T09:43:35.928-07:00</atom:updated><title>Chinese Hackers Targeting NYPD Computers</title><description>&lt;a href=&quot;http://news.slashdot.org/article.pl?sid=09/04/23/2025243&quot;&gt; Slashdot&lt;/a&gt; prints an article about a network of mystery hackers, mostly based in China, making 70,000 attempts a day to break into the NYPD&#39;s sytem, according to Commissioner Raymond Kelly.  He said he suspects that his department is being targeted by foreign hackers because it has beefed up operations in the international arena since the 9/11 attacks.&lt;blockquote&gt;&quot;We are constantly studying events worldwide and assessing their implications for New York,&quot; said Kelly, adding that the NYPD now has officers stationed in Abu Dhabi, Jordan, Great Britain, France, Spain, Canada and the Dominican Republic.&lt;/blockquote&gt; Kelly also said senior police officers have been attending lectures by foreign affairs and terrorism experts. The Commissioner&#39;s surprising revelations closely followed a Canadian report exposing a China-based electronic spy network that has invaded at least 1295 computers in 103 countries.&lt;br /&gt;&lt;br /&gt;Dubbed &quot;GhostNet&quot;, the group of hackers have targeted embassies, foreign ministries and the Dalai Lama&#39;s offices in India, Brussels, London and New York. &lt;br /&gt;&lt;br /&gt;Toronto University&#39;s 10-month study suggests that the GhostNet is linked to Chinese government espionage agencies, which Chinese government officials deny.&lt;br /&gt;&lt;br /&gt;See complete article in the &lt;a href=&quot;http://www.nydailynews.com/news/2009/04/22/2009-04-22_international_hackers_lauching_attack_against_nypd_computers.html&quot;&gt; New York Daily News&lt;/a&gt;.</description><link>http://trust-news.blogspot.com/2009/04/chinese-hackers-targeting-nypd.html</link><author>noreply@blogger.com (Mary Stewart)</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-9171616822814009867</guid><pubDate>Thu, 23 Apr 2009 00:33:00 +0000</pubDate><atom:updated>2009-04-22T17:57:07.987-07:00</atom:updated><title>Most electronic voting isn&#39;t secure, CIA expert says</title><description>&lt;a href=&quot;http://catless.ncl.ac.uk/Risks/25.64.html#subj6&quot;&gt; The Risks Digest&lt;/a&gt; points to an article about a CIA agent testifying before the Election Assistance Commission.  His position is that electronic votes are not secure and can be altered and further, are being altered already in some locales.&lt;br /&gt;&lt;br /&gt;The CIA agent, a cybersecurity expert, suggested that Venezuelan President Hugo Chavez and his allies fixed a 2004 election recount, a pronouncement that could further agitate U.S. relations with the Latin leader.&lt;br /&gt;&lt;br /&gt;In a presentation that could provide foreboding lessons for the United States, where electronic voting is becoming preeminent, Steve Stigall summarized what he described as attempts to use computers to undermine democratic elections in developing nations.  Stigall told the Election Assistance Commission that computerized electoral systems can be manipulated at five stages, from altering voter registration lists to posting results.&lt;blockquote&gt;&quot;You heard the old adage &#39;follow the money,&#39; &quot; Stigall said, according to a transcript of his hour-long presentation that McClatchy obtained. &quot;I follow the vote. And wherever the vote becomes an electron and touches a computer, that&#39;s an opportunity for a malicious actor potentially to . . . make bad things happen.&quot;&lt;/blockquote&gt;&lt;br /&gt;Stigall said that some countries had taken extraordinary steps that improved security.  For example, he said internet systems that encrypt vote results so they&#39;re unrecognizable during transmission &quot;greatly complicates malicious corruption.&quot;&lt;br /&gt;&lt;br /&gt;After reviewing the agent&#39;s remarks, director of election reform for the citizens&#39; lobby &#39;Common Cause, Susannah Goodman says they showed &lt;blockquote&gt;&quot;we can no longer ignore the fact that all of these risks are present right here at home . . . and must secure our election system by requiring every voter to have his or her vote recorded on a paper ballot.&quot;&lt;/blockquote&gt;&lt;br /&gt;See complete article in &lt;a href=&quot;http://www.mcclatchydc.com/226/story/64711.html&quot;&gt; McClatchy Newspapers&lt;/a&gt;.</description><link>http://trust-news.blogspot.com/2009/04/most-electronic-voting-isnt-secure-cia.html</link><author>noreply@blogger.com (Mary Stewart)</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-5029753258141183022</guid><pubDate>Mon, 26 Jan 2009 16:43:00 +0000</pubDate><atom:updated>2009-01-26T09:15:05.995-08:00</atom:updated><title>Obama Sides With Bush In Spy Case</title><description>&lt;a href=&quot;http://news.slashdot.org/article.pl?sid=09/01/23/1744250&quot;&gt; Slashdot &lt;/a&gt; picked up a story in &lt;span style=&quot;font-style:italic;&quot;&gt;Wired&lt;/span&gt; about the Obama administration siding with the Bush administration when it urged a federal judge to set aside a ruling in a closely watched case examining whether a U.S. president may bypass Congress and establish warrantless wiretapping programs designed to spy on American citizens.&lt;br /&gt;&lt;br /&gt;With just hours left in office, President George W. Bush asked U.S. District Judge Vaughn Walker late Monday to stay enforcement of a Jan.5 ruling admitting key evidence into the case.  On Thursday, the Obama administration said in its filing with the court&lt;blockquote&gt;&quot;The Government&#39;s position remains that this case should be stayed&quot; &lt;/blockquote&gt;marking the first time it was clear that the new president was in agreement with the Bush administration&#39;s reasoning in this case.&lt;br /&gt;&lt;br /&gt;The legal hubbub concerns Walker&#39;s decision to admit a classified document as evidence that allegedly shows that two American lawyers for a now-defunct Saudi charity were electronically eavesdropped on without warrants in 2004.&lt;br /&gt;&lt;br /&gt;The Obama administration is in agreement with the previous administration in its legal defense of July legislation that immunizes the nation&#39;s  telecommunications companies from lawsuits accusing them of complicity in Bush&#39;s eavesdropping program, according to testimony last week by incoming Attorney General Eric Holder.&lt;br /&gt;&lt;br /&gt;A separate case requiring a decision on the constitutionality of the immunity legislation (which Obama voted for as a U.S. Senator from Illinois) brought by the Electronic Frontier Foundation is pending before Judge Walker.&lt;br /&gt;&lt;br /&gt;See details in &lt;a href=&quot;http://blog.wired.com/27bstroke6/2009/01/obama-sides-wit.html&quot;&gt; Wired&lt;/a&gt;.</description><link>http://trust-news.blogspot.com/2009/01/obama-sides-with-bush-in-spy-case.html</link><author>noreply@blogger.com (Mary Stewart)</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-6387826707999041088</guid><pubDate>Wed, 21 Jan 2009 23:50:00 +0000</pubDate><atom:updated>2009-01-21T16:09:31.848-08:00</atom:updated><title>Privacy Groups Want Strong Security Measures for Electronic Health Records</title><description>&lt;a href=&quot;https://www.sans.org/newsletters/newsbites/newsbites.php?vol=11&amp;issue=5#sID201&quot;&gt; SANS Institute&lt;/a&gt;  summarizes an article about US privacy rights and civil liberties advocacy groups writing legislators and asking them to ensure that any adoption of electronic health records include substantial security measures. Such letters from the American Civil Liberties Union, the National Association of Social Workers and Patient Privacy rights request that patients have control over how their medical records are used and that they be protected from organizations that share and sell medical information. &lt;blockquote&gt;&quot;We all want to innovate and improve health care, but without privacy our system will crash as any system with a persistent and chronic virus will,&quot; Patient Privacy Rights executive director Ashley Katz said at a Capitol Hill briefing.&lt;/blockquote&gt; Chairman of Senate Health, Education, Labor and Pensions, Edward Kennedy and ranking member Michael Enzi submitted a bill in the 110th Congress and have worked with Judiciary Chairman Patrick Leahy to beef up its privacy provisions. However, Senate Small Business ranking member Olympia Snowe does not believe the measure went far enough, and together with Rep. Edward Markey, D-Mass., and Rep. Lloyd Doggett, D-Texas, offered letters of support for the privacy groups&#39; call to action.&lt;blockquote&gt;&quot;Without robust safeguards, the health IT systems we are planning for today could turn the dream of integrated, seamless electronic health networks into a nightmare for consumers,&quot; Markey said in a statement.&lt;/blockquote&gt;&lt;br /&gt;For complete article, see &lt;a href=&quot;http://www.nextgov.com/nextgov/ng_20090115_7415.php&quot;&gt; nextgov&lt;/a&gt;.</description><link>http://trust-news.blogspot.com/2009/01/privacy-groups-want-strong-security.html</link><author>noreply@blogger.com (Mary Stewart)</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-7283395495007876960</guid><pubDate>Tue, 13 Jan 2009 17:10:00 +0000</pubDate><atom:updated>2009-01-13T09:55:18.669-08:00</atom:updated><title>CWE/SANS TOP 25 Most Dangerous Programming Errors</title><description>Yesterday, the SysAdmin, Audit, Network, Security (&lt;span style=&quot;font-style:italic;&quot;&gt;SANS&lt;/span&gt;) Institute announced that in Washington D.C., experts from more than 30 U.S. and international cyber security organizations jointly released a list of the 25 most dangerous programming errors that bring about security bugs permitting cyber espionage and cyber crime. The project is a significant component of an overall national security initiative. &lt;br /&gt;&lt;br /&gt;The impact of such errors is extensive, where just two errors led to more than 1.5 million web site security breaches in 2008.  Those breaches then cascaded onto the computers of people who visited those websites.&lt;br /&gt;&lt;br /&gt;The people and organizations that provided input to the project are among the most respected security experts, coming from an extensive range of leading organizations such as Symantec, Microsoft, DHS&#39;s National Cyber Security Division, and NSA&#39;s Information Assurance Division to the Japaneses IPA, to the University of California at Davis and Purdue University.&lt;br /&gt;&lt;br /&gt;Remarkably, all the experts quickly came to agreement, despite some intense discussion.&lt;blockquote&gt;&quot;There appears to be broad agreement on the programming errors,&quot; says SANS Director, Mason Brown, &quot;Now it is time to fix them. First we need to make sure every programmer knows how to write code that is free of the Top 25 errors, and then we need to make sure every programming team has processes in place to find, fix, or avoid these problems and has the tools needed to verify their code is as free of these errors as automated tools can verify.&quot;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;See complete Announcement in &lt;a href=&quot;http://www.sans.org/top25errors//&quot;&gt; SANS&lt;/a&gt;.</description><link>http://trust-news.blogspot.com/2009/01/cwesans-top-25-most-dangerous.html</link><author>noreply@blogger.com (Mary Stewart)</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-1773273683455907471</guid><pubDate>Fri, 09 Jan 2009 00:03:00 +0000</pubDate><atom:updated>2009-01-08T16:22:49.871-08:00</atom:updated><title>State Secrets Defense Rejected in Wiretapping Case</title><description>&lt;a href=&quot;http://yro.slashdot.org/article.pl?sid=09/01/06/2056249&quot;&gt; Slashdot&lt;/a&gt; references a report in Ars Technica of a federal judge ruling that a lawsuit filed by an Islamic charity alleging illegal wiretapping by the National Security Agency may proceed.&lt;br /&gt;&lt;br /&gt;The case, &lt;i&gt;Al Haramain v. Bush&lt;/i&gt;, stands out in that unlike the Electronic Frontier&#39;s more widely publicized suits agains the NSA and cooperating telecoms, the plaintiffs here know that the directors of the charity were specifically subjected to warrantless surveillance, thanks to a government faux pas that put a classified memo in the hands of the charity&#39;s lawyers.&lt;br /&gt;&lt;br /&gt;Judge Vaughn Walker, who has been handling a raft of suits concerning the NSA&#39;s super-secret &lt;i&gt;Stellar Wind&lt;/i&gt; program decided that the charity could seek to show they&#39;d been spied upon using public evidence.&lt;blockquote&gt;&quot;Without a doubt,&quot; he wrote, plaintiffs have alleged enough to plead &#39;aggrieved persons&#39; status so as to proceed to the next step in proceedings.&quot;&lt;/blockquote&gt;The Justice Department repeatedly tried to try to block the suit by invoking national security concerns.  At one point, Walker described the government&#39;s argument &quot;without merit&quot; and characterized another argument as &quot;circular&quot;.&lt;br /&gt;&lt;br /&gt;See complete report at &lt;a href=&quot;http://arstechnica.com/news.ars/post/20090106-judge-doesnt-buy-state-secrets-privilege-oks-wiretap-suit.html&quot;&gt; Ars Technica&lt;/a&gt;.</description><link>http://trust-news.blogspot.com/2009/01/state-secrets-defense-rejected-in.html</link><author>noreply@blogger.com (Mary Stewart)</author></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-25971470.post-3842431770750733063</guid><pubDate>Wed, 24 Dec 2008 18:58:00 +0000</pubDate><atom:updated>2008-12-24T11:48:06.402-08:00</atom:updated><title>Congress in the Cyber-Crosshairs</title><description>&lt;a href=&quot;http://technews.acm.org/#391938&quot;&gt; ACM TechNews&lt;/a&gt; points out the cover story of National Journal about what it will take to keep the next invader out of Congressional computers.&lt;br /&gt;&lt;br /&gt;Two years ago, 15 House panels and members&#39; offices were invaded by malware whose nature suggest the intrusions originated in China. One target, the office of House Representative Frank Wolf (R-Va) argued before the House that the fear of admitting vulnerability might be a reason underlying U.S. intelligence and national security&#39;s reluctance ro publicize the breaches sooner.&lt;blockquote&gt;&quot;I strongly believe that the appropriate officials, including those from the Department of Homeland Security and the FBI, should brief all members of Congress in a closed session regarding threats from China and other countries against the security of House technology, including our computers, BlackBerry devices, and phones,&quot; he said.&lt;/blockquote&gt;While it appears that there is little interest from members of Congress in discussing cyber vulnerabilities, it is likely because they have little understanding of them.  Former director the DHS&#39; Cyber Security Division Amit Yoran says &lt;blockquote&gt;&quot;As a member of Congress, you have so many issues competing for your attention and, historically, cyber-security hasn&#39;t been one that&#39;s won out. It&#39;s not an issue that is particularly well tracked by their constituents.&quot;&lt;/blockquote&gt;In a recent study prepared by the Center for Strategic and International Studies concluded for President-elect Barack Obama that Congress is unsuited for managing executive-branch cybersecurity due to the inconsistency and fragmentation of its oversight. The study group recommended that Obama take charge of cybersecurity and establish a new office for cyberspace in the Executive Office of the President that would collaborate closely with the National Security Council, &quot;managing the many aspects of securing our national networks while protecting privacy and civil liberties.&quot;&lt;br /&gt;&lt;br /&gt;See complete article at &lt;a href=&quot;http://www.nationaljournal.com/njmagazine/cs_20081220_6787.php&quot;&gt; National Journal Magazine&lt;/a&gt;.</description><link>http://trust-news.blogspot.com/2008/12/congress-in-cyber-crosshairs.html</link><author>noreply@blogger.com (Mary Stewart)</author></item></channel></rss>