<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;A0ABQXY4eip7ImA9WxNbEEU.&quot;"><id>tag:blogger.com,1999:blog-7782260</id><updated>2009-11-13T08:52:30.832+03:30</updated><title>Vitalsecurity.org</title><subtitle type="html">A Revolution is the Solution</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://www.vitalsecurity.org/" /><link rel="hub" href="http://pubsubhubbub.appspot.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>paperghost</name><email>noreply@blogger.com</email></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>91</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><link rel="self" href="http://feeds.feedburner.com/Vitalsecurity-org" type="application/atom+xml" /><feedburner:browserFriendly>This is Vitalsecurity.org's XML content feed - the below articles do not show the full content of each item. It is intended to be viewed in a newsreader, or syndicated to another site if you would like to take advantage of our regularly updated news reports - reliable content with no hassle.</feedburner:browserFriendly><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><entry gd:etag="W/&quot;C0UCRH89fyp7ImA9WxNUFUk.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-4511987761998146418</id><published>2009-11-07T00:31:00.001+03:30</published><updated>2009-11-07T00:31:05.167+03:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-07T00:31:05.167+03:30</app:edited><title>Test post...</title><content type="html">Epic publishing / post loss fail, hopefully nothing to worry about...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-4511987761998146418?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/pDygwyEU1pA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/4511987761998146418/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=4511987761998146418&amp;isPopup=true" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/4511987761998146418?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/4511987761998146418?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/pDygwyEU1pA/test-post.html" title="Test post..." /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/11/test-post.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Dk4GRH84cCp7ImA9WxNUE0s.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-2236321590224251655</id><published>2009-11-04T20:10:00.013+03:30</published><updated>2009-11-04T23:32:05.138+03:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-04T23:32:05.138+03:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Lose/Lose" /><title>My thoughts on Lose / Lose</title><content type="html">There's a bit of a wing-ding at the moment concerning a game called "Lose / Lose" that deletes your files while you play it.&lt;br /&gt;
&lt;br /&gt;
The game has been around since at least September, and yet despite this I don't believe I've seen a single complaint about the program. &lt;a href="http://www.wired.co.uk/news/archive/2009-09/22/the-computer-game-that-destroys-your-files.aspx"&gt;Link&lt;/a&gt;:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Lose/Lose is a video-game with real life consequences. Each alien in the game is created based on a random file on the player's computer. If the player kills the alien, the file it is based on is deleted. If the player's ship is destroyed, the application itself is deleted."&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
&lt;/i&gt;&lt;br /&gt;
&lt;i&gt;"By way of exploring what it means to kill in a video-game, Lose/Lose broaches bigger questions," the game developers say. "As technology grows, our understanding of it diminishes, yet, at the same time, it becomes increasingly important in our lives. At what point does our virtual data become as important to us as physical possessions?"&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
I don't know about you, but I rather like the concept.&lt;br /&gt;
&lt;br /&gt;
Still, this game has been kicking around for a few months now with no fuss - and then all of a &lt;a href="http://www.itpro.co.uk/617143/new-mac-trojan-disguises-itself-like-space-invaders"&gt;sudden&lt;/a&gt;, Symantec are calling it a &lt;a href="http://www.symantec.com/connect/blogs/osxloosemaque-it-s-not-just-game-anymore"&gt;Trojan&lt;/a&gt; and sites abound with &lt;a href="http://news.google.com/news/more?pz=1&amp;amp;cf=all&amp;amp;cf=all&amp;amp;ncl=drEeHzt-IeomOCMSbuuO2REnssdjM"&gt;pitch forks and hand grenades&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
Some observations:&lt;br /&gt;
&lt;br /&gt;
&lt;object height="340" width="560"&gt;&lt;param name="movie" value="http://www.youtube.com/v/_AM6AN1hTCY&amp;hl=en&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/_AM6AN1hTCY&amp;hl=en&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="560" height="340"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;1)&lt;/b&gt; The above video is absolutely &lt;i&gt;ludicrous&lt;/i&gt;. They note that the game clearly warns you of what it will do if you run it (delete files) and then proceeds to show us the game....deleting files, as if this is somehow something to be shocked by.&lt;br /&gt;
&lt;br /&gt;
Well, duh.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;2)&lt;/b&gt; Many current references to the game are couched in dangerously obscure terms, as if to make it sound like the researchers talking about it hiked up a mountain, wrestled a bear or two then carried it down on their back for us to prod with a stick. From the Symantec blog:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;"Takashi Katsuki, one of our Tokyo engineers, came across just that today."&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
Came across? Came across where? The official site, that was ALL OVER THE INTERNET when the game was first revealed and &lt;i&gt;marketed&lt;/i&gt; as a &lt;i&gt;game that deletes your files should you run it&lt;/i&gt;?&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;"Researchers have discovered  a trojan"&lt;/i&gt; From &lt;a href="http://www.itpro.co.uk/617143/new-mac-trojan-disguises-itself-like-space-invaders"&gt;ITPro&lt;/a&gt;. "Discovered"? Man, that must have been hard work wading through such obscure sources as, er, &lt;a href="http://www.wired.co.uk/news/archive/2009-09/22/the-computer-game-that-destroys-your-files.aspx"&gt;Wired&lt;/a&gt;, &lt;a href="http://www.rockpapershotgun.com/2009/09/24/the-winner-takes-your-files-loselose/"&gt;Rock Paper Shotgun&lt;/a&gt;,&amp;nbsp; &lt;a href="http://www.escapistmagazine.com/news/view/94917-Lose-Lose-The-Game-That-Deletes-Your-Files"&gt;The Escapist&lt;/a&gt;, &lt;a href="http://www.joystiq.com/2009/09/30/lose-lose-game-deletes-files-as-you-play/"&gt;Joystiq&lt;/a&gt;, &lt;a href="http://www.techdirt.com/articles/20090924/1305596306.shtml"&gt;Techdirt&lt;/a&gt; and &lt;a href="http://gamerblips.dailyradar.com/story/stfj-art-2009-lose-lose/"&gt;half the online gaming press&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
As &lt;a href="http://twitter.com/helvetica/status/5423164647"&gt;noted&lt;/a&gt; by Lose/Lose creator Zach Gage, you now have the surreal situation where a site such as Softpedia simultaneously &lt;a href="http://mac.softpedia.com/get/Games/lose-lose.shtml"&gt;offers it as a download&lt;/a&gt; AND flags it as &lt;a href="http://news.softpedia.com/news/Mac-Trojan-Masked-as-Game-Deletes-a-File-for-Every-Alien-Killed-126023.shtml"&gt;Malware&lt;/a&gt;.&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_ZOjRj_3HrmA/SvGtMFiotuI/AAAAAAAAAT0/osNGwWHalz0/s1600-h/loselose.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;br /&gt;
&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;b&gt;3)&lt;/b&gt; Some justification for flagging this is as a Trojan is that &lt;i&gt;"There’s nothing stopping someone with more malicious intentions from modifying it slightly and then passing it on to unsuspecting computers, causing significant damage to a computer."&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
Firstly, couldn't you say that in relation to just about &lt;i&gt;any&lt;/i&gt; program? Seems like a bit of a weak reason for specifically marking it out. Are they also going to flag &lt;a href="http://www.cs.unm.edu/%7Edlchao/flake/doom/"&gt;psDooM &lt;/a&gt;, which has allowed you to - quite literally - blow away system processes since 1999 on the basis someone could "modify and do naughty things with it"? &lt;br /&gt;
&lt;br /&gt;
Get it now on &lt;a href="http://www.versiontracker.com/dyn/moreinfo/macosx/21327&amp;amp;vid=120587"&gt;Mac&lt;/a&gt;, kids! &lt;br /&gt;
&lt;br /&gt;
Second, the game ALREADY causes "significant damage" if you run it in its current state, which is nice enough to give you a &lt;i&gt;great big warning&lt;/i&gt; &lt;i&gt;when you run it&lt;/i&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/_ZOjRj_3HrmA/SvGtMFiotuI/AAAAAAAAAT0/osNGwWHalz0/s1600-h/loselose.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://4.bp.blogspot.com/_ZOjRj_3HrmA/SvGtMFiotuI/AAAAAAAAAT0/osNGwWHalz0/s320/loselose.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;/div&gt;&lt;br /&gt;
If you cannot understand the plain English warning, too bad. If you have kids who somehow manage to obtain the game, then run it on your Mac and you lose everything like &lt;a href="http://www.guardian.co.uk/technology/blog/2009/nov/04/mac-game-art-deletes-files"&gt;The Guardian&lt;/a&gt; suggests - maybe you shouldn't let your kids download whatever they feel like?&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;4)&lt;/b&gt; I'm concerned that the creator of a rather interesting art experiment is now forever to be known as "that guy who made a Mac Trojan, lol". This was someone who made something, fully disclosed what it did and made a credible creation borne out of his ideas and hey, it seemed to go down pretty well. Now? Trojan, lol.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;5)&lt;/b&gt; I also have an issue with the &lt;a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-110309-3638-99"&gt;writeup&lt;/a&gt; of the "threat" - at no point that I can see does it mention you have to download the game voluntarily, and that the game warns you in BIG RED LETTERS what it will do if you play it. I'm also faintly alarmed that this game is being called a "Trojan" when everything it does is &lt;i&gt;disclosed both on the &lt;a href="http://www.stfj.net/art/2009/loselose/"&gt;homepage&lt;/a&gt; and also in the program itself&lt;/i&gt;. Compare and contrast with &lt;a href="http://blog.spywareguide.com/2007/07/gta_hoodlife_virus_attack_is_a.html"&gt;this thing&lt;/a&gt;, which pretended to be a &lt;i&gt;safe&lt;/i&gt; game then went on to trash your computer via hidden infection files - with &lt;i&gt;no warning&lt;/i&gt;.&lt;br /&gt;
&lt;br /&gt;
Not so much a Wooden Horse as one made out of paper?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-2236321590224251655?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/WO9CExqGyHg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/2236321590224251655/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=2236321590224251655&amp;isPopup=true" title="7 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/2236321590224251655?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/2236321590224251655?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/WO9CExqGyHg/my-thoughts-on-lose-lose.html" title="My thoughts on Lose / Lose" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_ZOjRj_3HrmA/SvGtMFiotuI/AAAAAAAAAT0/osNGwWHalz0/s72-c/loselose.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">7</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/11/my-thoughts-on-lose-lose.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CE4FQ3g9fCp7ImA9WxNVFkk.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-4513609130875264280</id><published>2009-10-27T13:03:00.002+03:30</published><updated>2009-10-27T14:58:32.664+03:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-27T14:58:32.664+03:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="when poor marketing attacks" /><category scheme="http://www.blogger.com/atom/ns#" term="wtf" /><title>Marketing fail</title><content type="html">&lt;style type="text/css"&gt;
.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }
&lt;/style&gt;&lt;br /&gt;
&lt;div class="flickr-frame"&gt;&lt;a href="http://www.flickr.com/photos/paperghost/4048184270/" title="photo sharing"&gt;&lt;img alt="" class="flickr-photo" src="http://farm3.static.flickr.com/2800/4048184270_1e03ca6ae2.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.flickr.com/photos/paperghost/4048184270/"&gt;All your Facebook are belong to us!&lt;/a&gt;, originally uploaded by &lt;a href="http://www.flickr.com/people/paperghost/"&gt;Paperghost&lt;/a&gt;.&lt;br /&gt;
&lt;/div&gt;&lt;div class="flickr-yourcomment"&gt;&lt;br /&gt;
&lt;/div&gt;Here is your daily dose of &lt;a href="http://blog.spywareguide.com/2009/10/hacking-now-a-porn-marketing-t.html"&gt;plumbing the depths&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-4513609130875264280?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/HXgOPOKQkJA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/4513609130875264280/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=4513609130875264280&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/4513609130875264280?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/4513609130875264280?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/HXgOPOKQkJA/all-of-your-images-now-belong-to-us.html" title="Marketing fail" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/10/all-of-your-images-now-belong-to-us.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEIHSX49fip7ImA9WxNVFUg.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-6874485183105072280</id><published>2009-10-26T13:52:00.000+03:30</published><updated>2009-10-26T13:52:18.066+03:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-26T13:52:18.066+03:30</app:edited><title>Vkontakte Targeted By SMS Scammers</title><content type="html">&lt;style type="text/css"&gt;
.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }
&lt;/style&gt;&lt;br /&gt;
&lt;div class="flickr-frame"&gt;&lt;a href="http://www.flickr.com/photos/paperghost/4045516099/" title="photo sharing"&gt;&lt;img alt="" class="flickr-photo" src="http://farm3.static.flickr.com/2616/4045516099_3c501328aa.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.flickr.com/photos/paperghost/4045516099/"&gt;Vkontakte Graffiti Spam&lt;/a&gt;, originally uploaded by &lt;a href="http://www.flickr.com/people/paperghost/"&gt;Paperghost&lt;/a&gt;.&lt;br /&gt;
&lt;/div&gt;&lt;div class="flickr-yourcomment"&gt;&lt;br /&gt;
&lt;/div&gt;&lt;style type="text/css"&gt;
.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }
&lt;/style&gt;&lt;br /&gt;
&lt;style type="text/css"&gt;
.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }
&lt;/style&gt;&lt;br /&gt;
&lt;div class="flickr-frame"&gt;&lt;a href="http://www.flickr.com/photos/paperghost/4044902904/" title="photo sharing"&gt;&lt;img alt="" class="flickr-photo" src="http://farm3.static.flickr.com/2726/4044902904_87c9bb3d43.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;a href="http://www.flickr.com/photos/paperghost/4044902904/"&gt;Vkontakte Scam Windows SMS Hijack&lt;/a&gt;, originally uploaded by &lt;a href="http://www.flickr.com/people/paperghost/"&gt;Paperghost&lt;/a&gt;.&lt;br /&gt;
&lt;/div&gt;&lt;div class="flickr-yourcomment"&gt;&lt;br /&gt;
&lt;/div&gt;Popular Social Networking site &lt;a href="http://en.wikipedia.org/wiki/Vkontakte"&gt;Vkontakte.ru&lt;/a&gt; is currently under fire by a group of file dropping, password stealing, SMS moneygrabbing bad guys. More &lt;a href="http://blog.spywareguide.com/2009/10/vkontakte-targeted-by-sms-scam.html"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-6874485183105072280?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/biS7b5JE2zo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/6874485183105072280/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=6874485183105072280&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/6874485183105072280?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/6874485183105072280?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/biS7b5JE2zo/vkontakte-targeted-by-sms-scammers.html" title="Vkontakte Targeted By SMS Scammers" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/10/vkontakte-targeted-by-sms-scammers.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CU8AQX48cSp7ImA9WxNVFEU.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-2820179362558483796</id><published>2009-10-25T18:44:00.003+03:30</published><updated>2009-10-25T18:47:20.079+03:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-25T18:47:20.079+03:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Phishing" /><category scheme="http://www.blogger.com/atom/ns#" term="Epic Fail" /><title>When are you beyond all hope?</title><content type="html">&lt;i&gt;"I thought no way - I'm not falling for it, so just to be sure I tried it."&lt;/i&gt; &lt;br /&gt;
&lt;br /&gt;
When you say that. Phish victim of the week, bar none.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-2820179362558483796?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/O-74tuS2v1U" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/2820179362558483796/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=2820179362558483796&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/2820179362558483796?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/2820179362558483796?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/O-74tuS2v1U/when-are-you-beyond-all-hope.html" title="When are you beyond all hope?" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/10/when-are-you-beyond-all-hope.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEcMQHk9fip7ImA9WxNVEEo.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-7813559649122609416</id><published>2009-10-20T23:26:00.001+03:30</published><updated>2009-10-21T00:24:41.766+03:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-21T00:24:41.766+03:30</app:edited><title>More on that Kaspersky thing...</title><content type="html">...&lt;a href="http://threatpost.com/en_us/blogs/eugene-kaspersky-my-thoughts-internet-anonymity-102009"&gt;here&lt;/a&gt;. I've added a comment. For the record: I like their products, and use some of them myself. However, I think this is a bad idea and it makes me a sad panda.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-7813559649122609416?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/fJYvICh6NQY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/7813559649122609416/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=7813559649122609416&amp;isPopup=true" title="5 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/7813559649122609416?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/7813559649122609416?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/fJYvICh6NQY/more-on-that-kaspersky-thing.html" title="More on that Kaspersky thing..." /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">5</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/10/more-on-that-kaspersky-thing.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C04GQX08eyp7ImA9WxNVEE4.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-6720923250772112765</id><published>2009-10-20T12:50:00.006+03:30</published><updated>2009-10-20T13:15:20.373+03:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-20T13:15:20.373+03:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="nothankyou.jpg" /><category scheme="http://www.blogger.com/atom/ns#" term="identity" /><category scheme="http://www.blogger.com/atom/ns#" term="biometrics" /><category scheme="http://www.blogger.com/atom/ns#" term="government" /><title>Nothankyou.jpg</title><content type="html">Biometrics, identity cards and &lt;a href="http://www.vitalsecurity.org/2009/05/entrusting-your-data-to-boots-and.html"&gt;scanning your face in snappy snaps&lt;/a&gt; are all hot topics in the UK, if only because nobody seems to want them yet people who want to take money from you insist on jamming them down your throat anyway.&lt;br /&gt;
&lt;br /&gt;
Well, I saw &lt;a href="http://www.itpro.co.uk/616432/uk-ready-and-willing-for-biometric-fingerprinting"&gt;this&lt;/a&gt; earlier today and could feel at least seven or eight brain cells fry in a rage of rageyness.&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;"UK Ready and willing for biometric fingerprinting".&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;More than half (56 per cent) of Britons are now willing to give their biometric data to retailers and financial institutions to prove their identity, according to new research from Unisys.&lt;br /&gt;
&lt;br /&gt;
Nearly everyone (95 per cent) was willing to give their fingerprints, while 90 per cent would use iris recognition.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
You know, if you're going to put up something that sounds identical to a press release - at LEAST disclose what the people who provided the survey do, because it may well be somewhat relevant to the idea or issue being promoted. Not everybody has the time to go Googling for things in relation to random articles that proclaim biometrics "the best thing ever".&lt;br /&gt;
&lt;br /&gt;
Many will see that piece, assume Unisys are some kind of survey company, or PR firm, or etc etc etc and go about their daily business thinking "Oh well, if everyone else thinks they're awesome these biometrics / ID cards / databases can't be all bad, then".&lt;br /&gt;
&lt;br /&gt;
But even if you &lt;i&gt;don't&lt;/i&gt; know who they are, one quick search gives you &lt;a href="http://www.thirdfactor.com/2009/10/14/unisys-receives-contract-extension-from-australian%20government"&gt;this&lt;/a&gt;:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Unisys, a developer of biometric and security solutions, has announced it has received an extension on its existing contract with the Australian Department of Immigration and Citizenship covering desktop support and biometric services.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
And &lt;a href="http://www9.unisys.com/public_sector/us__federal/federal__contracts/dhs__eagle/experience.htm"&gt;this&lt;/a&gt;:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Unisys has worked with the Department of Homeland Security from the start.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
And &lt;a href="http://www9.unisys.com/public_sector/solutions/national__defense_a_domestic__security/citizen__identity__management.htm"&gt;this&lt;/a&gt;.&lt;br /&gt;
&lt;i&gt;&lt;br /&gt;
Unisys provides national ID card management and other biometric security systems.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
That's right everyone, the UK is ready and willing for biometrics, says someone WHO MAKES BIOMETRIC TECHNOLOGY AND WORKS WITH GOVERNMENTS.&lt;br /&gt;
&lt;br /&gt;
While this might not be news to people working in tech related fields, not everybody knows who Unysis are (and the article certainly doesn't point out this somewhat important bit of information).&lt;br /&gt;
&lt;br /&gt;
Meanwhile, the Government are &lt;a href="http://www.theregister.co.uk/2009/10/19/dna_dando/"&gt;rethinking DNA data retention&lt;/a&gt;, pocket change is being hurled at &lt;a href="http://www.theregister.co.uk/2009/10/16/id_card_promo_spend/"&gt;ID card promotion&lt;/a&gt;, the Tories say they'll bin cards and databases should they get into power and only &lt;a href="http://www.theregister.co.uk/2009/10/19/manchester_id_trial/"&gt;2,000 Mancunians&lt;/a&gt; picked up a voluntary ID card which almost makes up for years of annoying people with that bloody football team.&lt;br /&gt;
&lt;br /&gt;
I can't point you to a big pile of people jumping up and down yelling hooray for biometrics and ID cards; however, I &lt;i&gt;can&lt;/i&gt; point you to &lt;a href="http://www.leavethemkidsalone.com/index.htm"&gt;groups&lt;/a&gt; who object to &lt;a href="http://www.leavethemkidsalone.com/index.htm"&gt;biometrics in schools&lt;/a&gt;, and larger entities who pretty much object to the &lt;a href="http://www.no2id.net/"&gt;whole shebang&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
In conclusion, not only am I not "ready and willing" for Biometrics, I'm hard pressed to point to anybody else I know who doesn't think the whole thing is an excercise in security theatre and a great way for Governments to coin in some extra bling while hooking their grubby paws into every aspect of the daily lives of its wage slaves.&lt;br /&gt;
&lt;br /&gt;
Sorry, "citizens".&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-6720923250772112765?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/cykB1-Fsrrw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/6720923250772112765/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=6720923250772112765&amp;isPopup=true" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/6720923250772112765?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/6720923250772112765?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/cykB1-Fsrrw/nothankyoujpg.html" title="Nothankyou.jpg" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">3</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/10/nothankyoujpg.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0cARno5eip7ImA9WxNWF04.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-3272409126178776030</id><published>2009-10-17T01:40:00.000+03:30</published><updated>2009-10-17T01:40:47.422+03:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-17T01:40:47.422+03:30</app:edited><title>Uh, how about "no".</title><content type="html">Ladies and gentlemen, a &lt;a href="http://www.theregister.co.uk/2009/10/16/kaspersky_rebukes_net_anonymity/"&gt;terrible idea&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-3272409126178776030?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/wRWx5tD6QZs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/3272409126178776030/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=3272409126178776030&amp;isPopup=true" title="6 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/3272409126178776030?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/3272409126178776030?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/wRWx5tD6QZs/uh-how-about-no.html" title="Uh, how about &quot;no&quot;." /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">6</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/10/uh-how-about-no.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEAGQX45fSp7ImA9WxNTFkk.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-7310235110802974779</id><published>2009-08-19T00:37:00.004+04:30</published><updated>2009-08-19T05:15:20.025+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-08-19T05:15:20.025+04:30</app:edited><title>ID Cards And Poor Excuses</title><content type="html">You know what sucks? ID cards and poor excuses.&lt;br /&gt;&lt;br /&gt;Yes, the clue was in the title.&lt;br /&gt;&lt;br /&gt;Something that bugs me about the gradual creep, creep, creep of ID cards is that you just know eventually, they'll tie those stupid bits of plastic to essential services that you simply cannot do without. Sure, they'll be "optional" - if you want to live like a stinky hobo.&lt;br /&gt;&lt;br /&gt;You don't, do you?&lt;br /&gt;&lt;br /&gt;Well there you go, then. "Optional" is a joke when used in relation to these cards. I've been saying it for a while, and sure enough &lt;a href="http://www.theregister.co.uk/2009/08/17/hillingdon_id_card/"&gt;this&lt;/a&gt; popped up on The Register the other day, in relation to a local council offering up a "voluntary" ID card that local people can use to get discounts on numerous services - meanwhile, pesky outsiders get charged a higher price to do stuff...&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;"There is no obligation on local residents to use this card. However, some services, such as access to the local library or the Household Waste facilities, will only be made available on production of a card."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Naysayers will point to the closing comments of the piece in relation to how the above is a load of rubbish:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;In this case, the initiative appears to have less to do with the drive towards a database state, and far more to do with Hillingdon Council finding new ways to fund their services via stealth taxes. Their stated aim is for this scheme to cost nothing overall, as the price of local services will be fixed for residents – but increased for anyone coming in to Hillingdon from outside the Borough.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt; If other Councils buy in to this approach, then over the long term it might encourage individuals to make greater use of local services, as the price of out of area services becomes relatively more expensive.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Unfortunately, I'm going to have to call shenanigans on this one.&lt;br /&gt;&lt;br /&gt;With specific regards to &lt;span style="font-style: italic;"&gt;Council&lt;/span&gt; services - which are highlighted in the article - how many people go to &lt;i&gt;another council borough&lt;/i&gt; to visit a library instead of the &lt;span style="font-style: italic;"&gt;one on their doorstep&lt;/span&gt;, or use another councils household waste facilities (one county council alone has eleven of the things - is there really a council &lt;span style="font-style: italic;"&gt;anywhere&lt;/span&gt; in England that doesn't have &lt;i&gt;one&lt;/i&gt; such facility?) - or any &lt;span style="font-style: italic;"&gt;other&lt;/span&gt; number of council services that their own council would &lt;i&gt;logically provide&lt;/i&gt;?&lt;br /&gt;&lt;br /&gt;Perhaps you &lt;i&gt;might&lt;/i&gt; conceivably travel to another council district if you were looking for an obscure copy of Fly Fishing by JR Hartley or something, but if "stealth taxes" on council services for "outsiders" using council services like waste disposal are the overall objective I can't see them pulling in much money from it.&lt;br /&gt;&lt;br /&gt;Speaking of which, some 400 businesses have apparently signed up for this scheme. Is this an idiot tax on people unfortunate enough to have to commute to (or through) Hillingdon? Because it doesn't take a genius to work out that people being charged more for being outsiders will simply start taking their business - and businesses - elsewhere.&lt;br /&gt;&lt;br /&gt;In essence, Hillingdon just became an inbred shotgun waving outpost of fail. The logical extension of this scheme - if rolled out to everybody - says "Stay in your council area, and never go outside" which seems to be at odds with the rest of the worlds need to, you know, do stuff outside of your own little patch of land.&lt;br /&gt;&lt;br /&gt;Oh, and as a final rebuke to the claims of this card being a way to ward off evil outsiders from using council services - here's a &lt;a href="http://en.wikipedia.org/wiki/Greater_London#Local_government"&gt;map&lt;/a&gt; of the London Borough. Harrow, Ealing and Hounslow are next to Hillingdon - and all of those councils are full of "libraries and waste disposal services", two of the services mentioned by Captain Council Flunky.&lt;br /&gt;&lt;br /&gt;I'd imagine they all have the &lt;span style="font-style: italic;"&gt;rest&lt;/span&gt; of the services that the glorious Hillingdon provides too, so what exactly &lt;span style="font-style: italic;"&gt;are&lt;/span&gt; people going to come into Hillingdon to use that they can't get from their own area? Swimming pools? Pest control? Crackpipes?&lt;br /&gt;&lt;br /&gt;Beats me.&lt;br /&gt;&lt;br /&gt;"Voluntary" cards that are actually &lt;i&gt;required&lt;/i&gt; unless you want to be excluded from what will no doubt be an ever growing list of basic services. Didn't see that one coming, did you.&lt;br /&gt;&lt;br /&gt;Wait, you &lt;span style="font-style: italic;"&gt;did&lt;/span&gt;? Ah...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-7310235110802974779?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/Ec9cB5wQnYg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/7310235110802974779/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=7310235110802974779&amp;isPopup=true" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/7310235110802974779?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/7310235110802974779?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/Ec9cB5wQnYg/id-cards-and-poor-excuses.html" title="ID Cards And Poor Excuses" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/08/id-cards-and-poor-excuses.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEAGRX09eyp7ImA9WxJbFkU.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-279454382732324934</id><published>2009-07-27T13:51:00.003+04:30</published><updated>2009-07-27T13:55:24.363+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-07-27T13:55:24.363+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Videogames" /><title>Gamerscore hacking</title><content type="html">&lt;style type="text/css"&gt;.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }&lt;/style&gt;&lt;div class="flickr-frame"&gt; &lt;a href="http://www.flickr.com/photos/paperghost/3758268801/" title="photo sharing"&gt;&lt;img src="http://farm3.static.flickr.com/2479/3758268801_260993d062.jpg" class="flickr-photo" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span class="flickr-caption"&gt;&lt;a href="http://www.flickr.com/photos/paperghost/3758268801/"&gt;XBox Profile Editing Progam&lt;/a&gt;, originally uploaded by &lt;a href="http://www.flickr.com/people/paperghost/"&gt;Paperghost&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;    &lt;p class="flickr-yourcomment"&gt; &lt;/p&gt;Lots of people are indulging in a little leet hax action where XBox360 profile are concerned, artificially inflating Gamerscores then selling on the accounts to suckers.&lt;br /&gt;&lt;br /&gt;Read about how these dubious deeds relate to the underground economy (and how you can pick up stolen accounts with credit cards attached for as little as $4) &lt;a href="http://blog.spywareguide.com/2009/07/xbox-gamerscore-hacking-and-th.html"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-279454382732324934?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/mchojlZlgi4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/279454382732324934/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=279454382732324934&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/279454382732324934?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/279454382732324934?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/mchojlZlgi4/gamerscore-hacking.html" title="Gamerscore hacking" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/07/gamerscore-hacking.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUIERng4fyp7ImA9WxJUFko.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-249149506059266945</id><published>2009-07-15T21:32:00.002+04:30</published><updated>2009-07-15T21:35:07.637+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-07-15T21:35:07.637+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="EBay fail" /><title>Write about phishing, get threatened with the FBI</title><content type="html">Some awesome work by Ebay / Paypal yesterday, assuming "writing to someones webhost with lots of threats related to copyright infringement and then running to the FBI all because someone put up a screenshot of a phishing mail with your brand on it" means "awesome" nowadays.&lt;br /&gt;&lt;br /&gt;Which is doesn't.&lt;br /&gt;&lt;br /&gt;Gigantic amounts of fail can be yours for the taking &lt;a href="http://www.ghettowebmaster.com/legal/ebay-paypal-reported-me-to-the-fbi/"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-249149506059266945?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/O0nFxIhedKM" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/249149506059266945/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=249149506059266945&amp;isPopup=true" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/249149506059266945?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/249149506059266945?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/O0nFxIhedKM/write-about-phishing-get-threatened.html" title="Write about phishing, get threatened with the FBI" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">3</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/07/write-about-phishing-get-threatened.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUICQ3Y7eyp7ImA9WxJUFUs.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-7018710806683910571</id><published>2009-07-14T13:55:00.002+04:30</published><updated>2009-07-14T13:56:02.803+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-07-14T13:56:02.803+04:30</app:edited><title>Some downtime scheduled...</title><content type="html">I'll be messing with things behind the scenes later today, so don't be massively surprised if the site is AWOL for a while. It might even come back online too - bonus...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-7018710806683910571?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/PVzFWSi_R14" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/7018710806683910571/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=7018710806683910571&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/7018710806683910571?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/7018710806683910571?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/PVzFWSi_R14/some-downtime-scheduled.html" title="Some downtime scheduled..." /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/07/some-downtime-scheduled.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUMHRXwyeip7ImA9WxJUEk8.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-3144067839516420949</id><published>2009-07-10T16:17:00.002+04:30</published><updated>2009-07-10T16:33:54.292+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-07-10T16:33:54.292+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Epic Fail" /><category scheme="http://www.blogger.com/atom/ns#" term="wtf" /><title>Smacktalk Fail</title><content type="html">&lt;a href="https://www.blogger.com/comment.g?blogID=7782260&amp;amp;postID=3555679640887843836&amp;amp;isPopup=true"&gt;Oh dear&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-3144067839516420949?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/Vj5rq8CovPo" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/3144067839516420949/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=3144067839516420949&amp;isPopup=true" title="4 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/3144067839516420949?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/3144067839516420949?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/Vj5rq8CovPo/smacktalk-fail.html" title="Smacktalk Fail" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">4</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/07/smacktalk-fail.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUMFRXY4cSp7ImA9WxJVE0s.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-2381613962846893651</id><published>2009-06-30T16:22:00.005+04:30</published><updated>2009-06-30T16:33:34.839+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-06-30T16:33:34.839+04:30</app:edited><title>GMail and IP Addresses</title><content type="html">My pals over at Sunbelt have written about a &lt;a href="http://sunbeltblog.blogspot.com/2009/06/useful-gmail-security-feature.html"&gt;feature&lt;/a&gt; of GMail I didn't know existed:&lt;br /&gt;&lt;p&gt;&lt;span style="font-style: italic;"&gt;"Click “Details” and you get an overview of your accounts activity, including whether it’s from POP, a browser, or a mobile phone"&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;It also gives you IP addresses. Now I'm of the opinion that grabbing the IP address of someone who has hijacked your GMail is an interesting prospect - however, this also means that anybody able to hijack your GMail account has &lt;span style="font-style: italic;"&gt;your&lt;/span&gt; IP address too, and they'll have yours before you have theirs. To be honest, I think the potentially tiny benefit of having an attackers (potentially fake) IP is greatly outweighed by them having &lt;span style="font-style: italic;"&gt;your&lt;/span&gt; IP.&lt;br /&gt;&lt;br /&gt;Call me paranoid, but is it time to break out proxies and VPNs for GMail now? Perhaps there's a way for Google to implement some kind of password protection that's required to be able to access this information - but of course, if that password is tied to GMail itself then presumably the attacker would have access to that too - so how would you do it?&lt;br /&gt;&lt;br /&gt;Suggestions on a postcard to Google, please...&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-2381613962846893651?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/6V-wcjurFgg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/2381613962846893651/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=2381613962846893651&amp;isPopup=true" title="4 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/2381613962846893651?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/2381613962846893651?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/6V-wcjurFgg/gmail-and-ip-addresses.html" title="GMail and IP Addresses" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">4</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/06/gmail-and-ip-addresses.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkQBQXo-fSp7ImA9WxJVE0k.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-3555679640887843836</id><published>2009-06-30T11:06:00.002+04:30</published><updated>2009-06-30T11:15:50.455+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-06-30T11:15:50.455+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="wtf" /><title>Hackers Target Neopets Users</title><content type="html">&lt;style type="text/css"&gt;.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }&lt;/style&gt;&lt;div class="flickr-frame"&gt; &lt;a href="http://www.flickr.com/photos/paperghost/3674703868/" title="photo sharing"&gt;&lt;img src="http://farm3.static.flickr.com/2621/3674703868_4492894f74.jpg" class="flickr-photo" alt="" /&gt;&lt;/a&gt;&lt;br /&gt; &lt;span class="flickr-caption"&gt;&lt;a href="http://www.flickr.com/photos/paperghost/3674703868/"&gt;Neopets Scam&lt;/a&gt;, originally uploaded by &lt;a href="http://www.flickr.com/people/paperghost/"&gt;Paperghost&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;    &lt;p class="flickr-yourcomment"&gt; &lt;/p&gt;Targeting 12 year old kids with keyloggers?&lt;br /&gt;&lt;br /&gt;Oh Lordy. More &lt;a href="http://blog.spywareguide.com/2009/06/hackers-target-neopets-users.html"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-3555679640887843836?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/dUaQVVUeScQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/3555679640887843836/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=3555679640887843836&amp;isPopup=true" title="21 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/3555679640887843836?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/3555679640887843836?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/dUaQVVUeScQ/hackers-target-neopets-users.html" title="Hackers Target Neopets Users" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">21</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/06/hackers-target-neopets-users.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0ABSXs9fCp7ImA9WxJVEE8.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-3463808343949429021</id><published>2009-06-26T17:16:00.009+04:30</published><updated>2009-06-26T17:39:18.564+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-06-26T17:39:18.564+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="wtf" /><title>Save us from these idiots</title><content type="html">So some old guy who clearly knows nothing about computers - or how many internets you can fit into them - is &lt;a href="http://news.bbc.co.uk/1/hi/uk_politics/8118729.stm"&gt;seriously rubbing me up the wrong way&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;“You need youngsters who are deep into this stuff… If they have been slightly naughty boys, very often they really enjoy stopping other naughty boys,” he said.”&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Wait, what?&lt;br /&gt;&lt;br /&gt;Look out, clueless guy ahoy.&lt;br /&gt;&lt;br /&gt;Apart from the fact that there's something distinctly pervy sounding about calling them "naughty boys" and "enjoyment" at them "getting caught" - we're not in some sort of boarding school here - this is the biggest heap of crap I've heard since the last time some old guy who knows nothing about computers talked a load of old crap.&lt;br /&gt;&lt;br /&gt;Let's go out and hire (nay, REWARD) a bunch of  talentless, idiotic script kiddies who haven't done very much of note to defend a country? Oh yeah, that's genius, that is.&lt;br /&gt;&lt;br /&gt;Except that they&lt;br /&gt;&lt;br /&gt;a) have little to no technical knowledge&lt;br /&gt;b) enjoy cutting and pasting other peoples work (due to the whole lack of knowledge thing) and&lt;br /&gt;c) are idiots, who leave their entire life across ten social networking sites then wonder how come you're waiting outside their house with a baseball bat and a length of cheesewire.&lt;br /&gt;&lt;br /&gt;Last time I checked, the SAS was not full of morons. Nor are the SEALs, or any number of dedicated anti-whatever teams. Why should UK cyber security rather predictably be given the bastard children of a thousand leftover takeaway meals to defend it?&lt;br /&gt;&lt;br /&gt;Idiots commanding idiots, I love it. I'm going to go out and phish six hundred XBox Live accounts, I might be in Whitehall within six months. Let me tell Old Man McGinty something - I have waded through a crapload of script kiddies, and every now and then even convinced them to do the right thing(TM).&lt;br /&gt;&lt;br /&gt;But you know what? In order to get them to do the right thing, more often than not I had to THREATEN THEM WITH HORRIBLE AND EMBARRASSING THINGS. It took time. It took effort. It took pictures of them cavorting with their rather large and thuggish best mates girlfriend. Sometimes &lt;span style="font-style: italic;"&gt;I&lt;/span&gt; did the cavorting.&lt;br /&gt;&lt;br /&gt;It took all of these things and &lt;span style="font-style: italic;"&gt;more&lt;/span&gt;, to get a TINY percentage of people to stop being morons and play good guy for a while - and &lt;span style="font-style: italic;"&gt;only&lt;/span&gt; for a while. Where are these magical script kiddies - who really, &lt;span style="font-style: italic;"&gt;really&lt;/span&gt; want to be good, honest they do - Old Man McGinty is talking about? Can we have some of them to play with?&lt;br /&gt;&lt;br /&gt;Oh, right. Didn't think so.&lt;br /&gt;&lt;br /&gt;I've said it before, and I'll say it again - UK law enforcement tackling cybercrime is like Stevie Wonder playing Dance Dance Revolution. And all these ancient Government type guys who are older than the telephone need to get out of the way and stop talking about computers, technology and (most of all) script kiddies.&lt;br /&gt;&lt;br /&gt;Because they have absolutely no idea what they are talking about.&lt;br /&gt;&lt;br /&gt;Oh, the rage.&lt;br /&gt;&lt;br /&gt;Also: More sensible takes on this &lt;a href="http://countermeasures.trendmicro.eu/would-the-real-cybersecurity-minister-please-stand-up/"&gt;here&lt;/a&gt; and &lt;a href="http://www.sophos.com/blogs/gc/g/2009/06/26/uk-attack-countries-cyberspace/"&gt;here&lt;/a&gt;. I'll just stick with the ranting and cheap insults, for those are my boomsticks and I'm happy to deploy them.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-3463808343949429021?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/mabuj3Z2siA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/3463808343949429021/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=3463808343949429021&amp;isPopup=true" title="7 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/3463808343949429021?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/3463808343949429021?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/mabuj3Z2siA/save-us-from-these-idiots.html" title="Save us from these idiots" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">7</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/06/save-us-from-these-idiots.html</feedburner:origLink></entry><entry gd:etag="W/&quot;Ck8FRX0_eip7ImA9WxJWEUk.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-2081818526169369160</id><published>2009-06-16T12:44:00.004+04:30</published><updated>2009-06-16T12:56:54.342+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-06-16T12:56:54.342+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Spam" /><category scheme="http://www.blogger.com/atom/ns#" term="wtf" /><title>Spam of the day</title><content type="html">&lt;style type="text/css"&gt;.flickr-photo { border: solid 2px #000000; }.flickr-yourcomment { }.flickr-frame { text-align: left; padding: 3px; }.flickr-caption { font-size: 0.8em; margin-top: 0px; }&lt;/style&gt;&lt;div class="flickr-frame"&gt; &lt;a href="http://www.flickr.com/photos/paperghost/3631275791/" title="photo sharing"&gt;&lt;img src="http://farm4.static.flickr.com/3384/3631275791_faec617e30_o.jpg" class="flickr-photo" alt="" /&gt;&lt;/a&gt;&lt;br /&gt; &lt;span class="flickr-caption"&gt;&lt;a href="http://www.flickr.com/photos/paperghost/3631275791/"&gt;Rohan Crones&lt;/a&gt;, originally uploaded by &lt;a href="http://www.flickr.com/people/paperghost/"&gt;Paperghost&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;    &lt;p class="flickr-yourcomment"&gt; &lt;/p&gt;...Rohan Crones? Are they old women from Lord of the Rings? If so, I'll have two of those and a Russian bride to go, please.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-2081818526169369160?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/Q0NfiFkA4gk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/2081818526169369160/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=2081818526169369160&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/2081818526169369160?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/2081818526169369160?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/Q0NfiFkA4gk/spam-of-day.html" title="Spam of the day" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/06/spam-of-day.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkcAQXs5eCp7ImA9WxJWEUk.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-457920311528392949</id><published>2009-06-16T12:41:00.002+04:30</published><updated>2009-06-16T12:44:00.520+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-06-16T12:44:00.520+04:30</app:edited><title>Remember kids, people lie on the Internet</title><content type="html">&lt;a href="http://forums.xbox.com/27664245/ShowPost.aspx"&gt;Oh dear&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Ten asshole points awarded to the social engineer for decimating an entire gaming clan, I guess.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-457920311528392949?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/i-Eu6PZTcac" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/457920311528392949/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=457920311528392949&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/457920311528392949?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/457920311528392949?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/i-Eu6PZTcac/remember-kids-people-lie-on-internet.html" title="Remember kids, people lie on the Internet" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/06/remember-kids-people-lie-on-internet.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0QGRXg7cCp7ImA9WxJWEEg.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-7495530514674797803</id><published>2009-06-15T14:16:00.002+04:30</published><updated>2009-06-15T14:18:44.608+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-06-15T14:18:44.608+04:30</app:edited><title>Pastebins and Botnets</title><content type="html">I loves me some Pastebin action, and I loves me some Botnet action too. If someone were to combine the two and toss around an idea where Pastebins could be used to issue commands to Botnets, would I be interested in taking a look?&lt;br /&gt;&lt;br /&gt;&lt;a href="http://blog.spywareguide.com/2009/06/pastebin-botnets.html"&gt;You bet&lt;/a&gt;. One of the more interesting things I've come across recently.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-7495530514674797803?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/U_JXL7fLL7Q" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/7495530514674797803/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=7495530514674797803&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/7495530514674797803?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/7495530514674797803?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/U_JXL7fLL7Q/pastebins-and-botnets.html" title="Pastebins and Botnets" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/06/pastebins-and-botnets.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0ECQXgzfyp7ImA9WxJXF00.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-8697680657837871083</id><published>2009-06-11T10:53:00.003+04:30</published><updated>2009-06-11T10:57:40.687+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-06-11T10:57:40.687+04:30</app:edited><title>When will they learn?</title><content type="html">Honestly, when someone waves their arms around in the air and goes "hack me", you can bet someone will turn up minutes later and say "okay".&lt;br /&gt;&lt;br /&gt;So it went with the recent Strongwebmail competition, where Lance James pulled a few &lt;a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;amp;articleId=9133976"&gt;A Team moves&lt;/a&gt; and pocketed a cool $10,000 in return for pwning their supposedly unpwnable CEO email account.&lt;br /&gt;&lt;br /&gt;I really don't know why companies offer themselves up for a public gutting where competitions such as this are concerned, but whatever. You can read an interview with Lance &lt;a href="http://www.fireblog.com/exclusive-interview-with-strongwebmails-10000-hacker/"&gt;here&lt;/a&gt;, although he doesn't say if he's Mr T or Hannibal which is a bit of a letdown.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-8697680657837871083?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/SJlWaZvJubQ" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/8697680657837871083/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=8697680657837871083&amp;isPopup=true" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/8697680657837871083?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/8697680657837871083?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/SJlWaZvJubQ/when-will-they-learn.html" title="When will they learn?" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/06/when-will-they-learn.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEUMRH89cSp7ImA9WxJXEk4.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-5162855620310507224</id><published>2009-06-05T23:53:00.007+04:30</published><updated>2009-06-06T00:34:45.169+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-06-06T00:34:45.169+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="JetKing" /><title>JetKing: They came, they saw, they rocked</title><content type="html">At the height of the "Myspace band hacks" back in &lt;a href="http://www.time.com/time/business/article/0,8599,1683361,00.html"&gt;2007&lt;/a&gt;, I have to confess to being somewhat underwhelmed by reaction to the problems facing the bands on that social networking site. It seemed most bands were puzzled at best and disinterested at worst by the mass hack attempts on their pages.&lt;br /&gt;&lt;br /&gt;However - one band actually took an interest in it, and had been fighting the good fight for some time while I was only just starting to dig into the problem. That band would be &lt;a href="http://www.jetking.info/"&gt;JetKing&lt;/a&gt;, and they really flew the flag for bands that were getting it in the neck from all the phishing &amp;amp; malware spewing that was going on at the time.&lt;br /&gt;&lt;br /&gt;We've kept in touch to this day, and I was flattered when they sent me a copy of their debut album a week or so ago.  I'm happy to report that the album is bloody good and well worth investigating (I've had "Smoke and Mirrors" lodged in my brain for a few days now). It's an interesting mix of guitars and electronica, but what caught my eye (ear?) was that neither element was overloaded or overdone - there's a nice bit of breathing space to the tracks and that appeals to me as a one time orchestral bod. And hey, you can rock out to it so +1 for that.&lt;br /&gt;&lt;br /&gt;You can check out a few of the songs on their &lt;a href="http://www.myspace.com/jetkinguk"&gt;Myspace page&lt;/a&gt;  and there's a review &lt;a href="http://indiemusicuniverse.com/albumreviews/album-review-jetkings-theories-suit-facts/"&gt;here&lt;/a&gt; that pretty much says what I was thinking about the album myself. Cheers for that, album reviewer guy.&lt;br /&gt;&lt;br /&gt;JetKing: flying the flag for music &lt;span style="font-style: italic;"&gt;and&lt;/span&gt; security.&lt;br /&gt;&lt;br /&gt;That's always a good thing, isn't it? Good luck with the album Vaughn, and thanks for being interested in the whole security thing at a time when so many others affected by the same problem weren't. It made a difference :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-5162855620310507224?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/wavy4ehdr7c" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/5162855620310507224/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=5162855620310507224&amp;isPopup=true" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/5162855620310507224?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/5162855620310507224?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/wavy4ehdr7c/jetking-they-came-they-saw-they-rocked.html" title="JetKing: They came, they saw, they rocked" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">3</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/06/jetking-they-came-they-saw-they-rocked.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0UFQX4_cCp7ImA9WxJQFk0.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-6702623778581232865</id><published>2009-05-29T19:10:00.004+04:30</published><updated>2009-05-29T19:30:10.048+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-29T19:30:10.048+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Epic Fail" /><title>If it's not for you, just move on</title><content type="html">It's an unspoken rule of security that anytime a story about something that isn't THE END OF THE WORLD appears, a guy will show up and loudly deride the story / the author / why it isn't important or "newsworthy" or something else he feels like complaining about.&lt;br /&gt;&lt;br /&gt;Case in point, a week or so ago people were coming to me worried that their Playstation consoles were "infected with viruses". I looked into it, saw there was nothing to worry about and wrote about it on &lt;a href="http://www.techradar.com/news/gaming/consoles/guest-column-don-t-fall-for-ps3-virus-alerts-602168"&gt;TechRadar&lt;/a&gt;. Sure enough, the very first comment posted was this:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;"I'm sorry but anyone who is fooled by this is a complete moron. A picture of XP My Computer and a reference to ‘your PC’, I suppose he thinks those lovely ladies he speaks to on those ‘Hot Babes’ hotlines are real people and really live just a few blocks away. It certainly isn’t newsworthy for a site dedicated to technology. People have been duped by this stuff for years and will continue to be till the end of the net. It’s dumb enough for a PC user to be duped yet understandable as the messages do, quite successfully at times, simulate the user’s day-to-day PC environment. It’s not virus he should be scared of, its woodworm eating away at his head."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Love it. Wannabe holier-than-thou atttitude where security is concerned, combined with derisive scorn at the people who might actually be worried by something regarding hardware that cost them a lot of money.&lt;br /&gt;&lt;br /&gt;Thank God for angry security commentators, eh? I mean, I would mention stones in glass houses when a quick check for him on twitter reveals his face, his name (hello, Toby) and what's probably his lovely lady &lt;a href="http://twitter.com/tholmewood"&gt;here&lt;/a&gt;, or how his &lt;a href="http://www.facebook.com/people/Toby-Holmewood/277004130"&gt;Facebook page&lt;/a&gt; reveals his location and opens his visible friends up to "fake friend" trolling antics, or how what looks like his &lt;a href="http://myworld.ebay.co.uk/tholmewood/"&gt;EBay page&lt;/a&gt; under the same username used for contemptuous and insulting comments leaves him perilously open to aggrieved parties stalking him by buying an item from him, then returning it with an excuse to grab his home address.&lt;br /&gt;&lt;br /&gt;But hey, people worried by Playstation virus warnings are idiots. Right?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-6702623778581232865?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/Hj9vlS4ZlTA" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/6702623778581232865/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=6702623778581232865&amp;isPopup=true" title="8 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/6702623778581232865?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/6702623778581232865?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/Hj9vlS4ZlTA/if-its-not-for-you-just-move-on.html" title="If it's not for you, just move on" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">8</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/05/if-its-not-for-you-just-move-on.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CE8FR3s9eSp7ImA9WxJQFk0.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-8813629428275757235</id><published>2009-05-29T16:58:00.005+04:30</published><updated>2009-05-29T17:43:36.561+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-29T17:43:36.561+04:30</app:edited><title>Look out, it's Angry Apple Guy</title><content type="html">I love a bit of blog rage, but sadly I haven't seen any for a while. As it turns out, you need to simply question the veracity of an Apple Mac advert, retreat to a safe distance and wait for some guy to start going RAAAAARGH RAGE RAGE RAGE all over the place.&lt;br /&gt;&lt;br /&gt;Which he is. Cheap shots, contrived logic, ad hominem attacks and a complete lack of understanding with regards how writing a blog that serves the needs of those with a technical bent, computer savvy reporters, those who have no clue whatsoever about IT but want to stay safe and non technical journos who want to learn more about "the whole security thing" operates on a day to day basis can be yours for the taking &lt;a href="http://countermeasures.trendmicro.eu/apple-macs-no-crashes-or-viruses/comment-page-1/"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;All because someone said the word "virus", apparently.&lt;br /&gt;&lt;br /&gt;Also, here's a stupid song I just made up.&lt;br /&gt;&lt;br /&gt;ANGRY APPLE GUY! WOO-OOOO-OOOOO!&lt;br /&gt;HE SAYS A LOT OF STUFF BECAUSE HE'S "IN THE KNOW"!&lt;br /&gt;ANGRY APPLE GUY! WOO-OOOO-OOOOO!&lt;br /&gt;PUTS CANDLES AT YOUR FEET, 'CAUSE WINDOZE BLOWS!&lt;br /&gt;&lt;br /&gt;ANGRY APPLE GUY! WOO-OOOO-OOOOO!&lt;br /&gt;WANTS TO GIVE YOU A CLASSIFICATION TEST!&lt;br /&gt;ANGRY APPLE GUY! WOO-OOOO-OOOOO!&lt;br /&gt;HAS A NERD RAGE ABOUT MAC OS X!&lt;br /&gt;&lt;br /&gt;/ GUITAR SOLO&lt;br /&gt;&lt;br /&gt;OH YES, HE'LL PROVE YOU WRONG!&lt;br /&gt;UNLESS YOU MAKE YOUR COMMENTS &lt;span style="font-weight: bold;"&gt;TWICE&lt;/span&gt; AS LONG!&lt;br /&gt;WATCH OUT FOR HIS MICROSOFT CHEERLEADER BARBS!&lt;br /&gt;CAUSE I'M MARRIED TO BILL GATES, GOD BLESS HIS HEART!&lt;br /&gt;&lt;br /&gt;/ SLOW SECTION&lt;br /&gt;&lt;br /&gt;I ADDED NOTHING TO THE DISCUSSION!&lt;br /&gt;&lt;br /&gt;/ POWER CHORD&lt;br /&gt;&lt;br /&gt;EXCEPT A SAD ATTEMPT AT DIVERSION!&lt;br /&gt;&lt;br /&gt;(Yes, I am using your own words as the basis for my song. Enjoy)&lt;br /&gt;&lt;br /&gt;DOESN'T WANT TO GIVE ME A HUG!&lt;br /&gt;&lt;br /&gt;/ POWER CHORD&lt;br /&gt;&lt;br /&gt;EVEN THOUGH I OFFERED HIM A FREE WINDOWS MUG!&lt;br /&gt;&lt;br /&gt;/ LEATHER PANTS THRUSTING&lt;br /&gt;&lt;br /&gt;ANGRY APPLE GUY! WOO-OOOO-OOOOO!&lt;br /&gt;HAS A BIG THING FOR BLOGGERS AND JOURNALISTS!&lt;br /&gt;ANGRY APPLE GUY! WOO-OOOO-OOOOO!&lt;br /&gt;HE PROBABLY SEES NOW I'M TAKING THE PI -&lt;br /&gt;&lt;br /&gt;.....is this mike still on?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-8813629428275757235?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/yegoPBtvjIs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/8813629428275757235/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=8813629428275757235&amp;isPopup=true" title="10 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/8813629428275757235?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/8813629428275757235?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/yegoPBtvjIs/look-out-its-angry-apple-guy.html" title="Look out, it's Angry Apple Guy" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">10</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/05/look-out-its-angry-apple-guy.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkYBQ3Y_fip7ImA9WxJQFU8.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-5332224759685650927</id><published>2009-05-28T15:19:00.005+04:30</published><updated>2009-05-28T20:59:12.846+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-28T20:59:12.846+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Twitter" /><title>Location-based information on Twitter</title><content type="html">From &lt;a href="http://www.readwriteweb.com/archives/twitter_might_start_adding_comments_location-based_info.php"&gt;Readwriteweb&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;"Twitter might soon add location-based information to every tweet. Currently, users can set a location on their profile, but individual tweets are not geo-coded in any way. If Twitter did indeed add a geo-references to every tweet, then that would open up the door to a wealth of new possibilities for developers."&lt;br /&gt;&lt;br /&gt;Well, screw the developers. All I want to know is&lt;br /&gt;&lt;br /&gt;1) Will there be an opt-out and&lt;br /&gt;2) If there IS an opt-out planned, will they apply geolocational technology to all the messages previously posted to Twitter before you get a chance to hit the "opt-out" button? Of course, in an ideal world opt-out would be selected by default (thus making it an opt-in, but it's all getting a bit confusing now so let's just say we don't want it in the first place and take it from there).&lt;br /&gt;&lt;br /&gt;I asked the co-founder and the main Twitter account on, uh, Twitter &lt;a href="http://twitter.com/paperghost/status/1939311795"&gt;here&lt;/a&gt;, but amazingly enough I haven't had a reply back. Hopefully the answer will be what we want to hear, or else I predict an epic security / privacy fail.&lt;br /&gt;&lt;br /&gt;/ Edit - More from Graham Cluley &lt;a href="http://www.sophos.com/blogs/gc/g/2009/05/28/locationbased-twitter-bad-security/"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-5332224759685650927?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/xQ9v_XBZfJw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/5332224759685650927/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=5332224759685650927&amp;isPopup=true" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/5332224759685650927?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/5332224759685650927?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/xQ9v_XBZfJw/location-based-information-on-twitter.html" title="Location-based information on Twitter" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/05/location-based-information-on-twitter.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0ACRngzcSp7ImA9WxJQE0s.&quot;"><id>tag:blogger.com,1999:blog-7782260.post-3813418744828814535</id><published>2009-05-26T23:09:00.007+04:30</published><updated>2009-05-26T23:52:47.689+04:30</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-05-26T23:52:47.689+04:30</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Wake up" /><category scheme="http://www.blogger.com/atom/ns#" term="NO2ID" /><title>If you've nothing to hide, you've everything to fear</title><content type="html">&lt;span style="font-style: italic;"&gt;"The government will have a few more records on me, so what?"&lt;/span&gt; Some guy on a forum&lt;br /&gt;&lt;br /&gt;You know, I'm still amazed when I see statements like that one regarding the massive boner the UK Government has for compiling a gigantic set of databases on everything you could imagine. It's clearly a "nothing to hide, nothing to fear" way of thinking.&lt;br /&gt;&lt;br /&gt;The problem is that it doesn't freaking &lt;span style="font-style: italic;"&gt;work&lt;/span&gt; like that.&lt;br /&gt;&lt;br /&gt;There are two &lt;span style="font-style: italic;"&gt;huge&lt;/span&gt; problems with "nothing to hide, nothing to fear".&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;1)&lt;/span&gt; It assumes the people in charge (along with the people who have access to the data currently stored on the 11 or so databases with parts of your whole existence stored on them) are all whiter than white.&lt;br /&gt;&lt;br /&gt;They're not, as it &lt;a href="http://www.cnn.com/2009/WORLD/europe/05/11/oakley.uk.mps.expenses/"&gt;turns out&lt;/a&gt;. They're just like you and me, and just &lt;span style="font-style: italic;"&gt;like&lt;/span&gt; you and me, they get up to things they don't want everybody to know about. Fancy that.&lt;br /&gt;&lt;br /&gt;And the more people you open the data up to, the bigger the risk of idiocy taking place. The &lt;a href="http://www.theregister.co.uk/2009/05/17/contactpoint_follow_up/"&gt;ContactPoint database&lt;/a&gt; is a perfect example - 300,000+ people from police, to charities(!) to random boobs in councils and God knows where else, and NONE of those people will try to track a kid down for their mate with an estranged spouse or other such shenanigans?&lt;br /&gt;&lt;br /&gt;Huh, good luck with &lt;span style="font-style: italic;"&gt;that&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;As the desire for databases combining their information grows - and ContactPoint is a big step towards that - so the risk increases for huge chunks of data to be lost and used in horrible and as of yet unthought of ways.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2)&lt;/span&gt; Put down the groundwork for a "Let's watch everybody" State, and its the easiest thing in the world for a party to come in afterwards and use that system to abuse whoever they feel like. It should certainly give pause for thought when considering how many pieces of your life are constantly being stacked up inside ever growing databases. I can tell you this much - whoever gets into power after the current shower of thugs are fired into the heart of the Sun, it will be the &lt;span style="font-style: italic;"&gt;hardest thing in the World&lt;/span&gt; for them to kill off some of these databases and monitoring tactics.&lt;br /&gt;&lt;br /&gt;It'll be like that guy who really, really wants to keep his terabyte of porno on his external HD but doesn't want the wife to find out. Seriously. They will &lt;span style="font-style: italic;"&gt;agonise&lt;/span&gt; over it.&lt;br /&gt;&lt;br /&gt;Oh, and let's not forget the very people constantly telling us how &lt;span style="font-style: italic;"&gt;wonderful&lt;/span&gt; these databases will be, and how you can soon go into Snappy Snaps and "Have your face scanned and fingerprints taken" while &lt;a href="http://news.bbc.co.uk/1/hi/uk_politics/8036536.stm"&gt;shopping&lt;/a&gt; are the very same shower of idiots who've done their level best to &lt;a href="http://www.guardian.co.uk/politics/blog/2009/jan/15/freedomofinformation-houseofcommons"&gt;prevent the public&lt;/a&gt; from seeing how much they've been &lt;a href="http://www.telegraph.co.uk/news/newstopics/mps-expenses/"&gt;screwing over the expenses system&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;It seems like everyone, everywhere is constantly being told to watch people, and report them, for anything and everything. If it's not kids as young as eight trained in the ways of &lt;a href="http://www.telegraph.co.uk/news/uknews/2689996/Children-aged-eight-enlisted-as-council-snoopers.html"&gt;reporting&lt;/a&gt;&lt;a href="http://www.telegraph.co.uk/news/uknews/2689996/Children-aged-eight-enlisted-as-council-snoopers.html"&gt; their neighbours&lt;/a&gt;, its the growing army of "&lt;a href="http://www.guardian.co.uk/politics/2008/aug/27/police.conservatives"&gt;Accredited Persons&lt;/a&gt;", or photography of police becoming &lt;a href="http://www.guardian.co.uk/commentisfree/2009/feb/16/protest-police-liberty-central"&gt;illegal&lt;/a&gt;, or those &lt;a href="http://enduringamerica.com/tag/anti-terrorism/"&gt;stupid posters&lt;/a&gt; issued by the "anti terror hotline" begging you to report anyone and everyone lest they &lt;a href="http://boingboing.net/2009/03/24/london-cops-reach-ne.html"&gt;blow something up&lt;/a&gt;, or tourists stopped in London and having their &lt;a href="http://www.guardian.co.uk/uk/2009/apr/16/police-delete-tourist-photos"&gt;photos deleted&lt;/a&gt; in case they're "terrorists", or schoolchildren having their &lt;a href="http://www.leavethemkidsalone.com/"&gt;biometrics taken at school&lt;/a&gt; without parents permission, or the police posters asking you to report people who wear "&lt;a href="http://www.dailymail.co.uk/news/article-1180911/Polices-latest-brainwave-Report-people-wear-bling-Crimestoppers.html"&gt;too much bling&lt;/a&gt;", or the desire for &lt;a href="http://www.geek.com/articles/news/uk-government-plans-increase-in-remote-computer-searches-2009016/"&gt;State approved spyware&lt;/a&gt;, and on it goes.&lt;br /&gt;&lt;br /&gt;I can say with conviction there is something fundamentally broken with this idea that huge reams of data being piled high magically solves everything. It's clear the Government intends to plough on with as many of these idiotic schemes as possible making it that much more difficult to remove the structure should someone else get into power.&lt;br /&gt;&lt;br /&gt;But hey, you'll be able to get your face scanned and fingerprints taken at &lt;a href="http://news.bbc.co.uk/1/hi/uk_politics/8036536.stm"&gt;Boots and Snappy Snaps&lt;/a&gt;. Great.&lt;br /&gt;&lt;br /&gt;How did we even &lt;span style="font-style: italic;"&gt;reach&lt;/span&gt; the point where people could be going around thinking this is remotely normal?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7782260-3813418744828814535?l=www.vitalsecurity.org'/&gt;&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/Vitalsecurity-org/~4/0Q1a8cV5AKc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://www.vitalsecurity.org/feeds/3813418744828814535/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="https://www.blogger.com/comment.g?blogID=7782260&amp;postID=3813418744828814535&amp;isPopup=true" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/3813418744828814535?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/7782260/posts/default/3813418744828814535?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/Vitalsecurity-org/~3/0Q1a8cV5AKc/if-youve-nothing-to-hide-youve.html" title="If you've nothing to hide, you've everything to fear" /><author><name>paperghost</name><email>noreply@blogger.com</email><gd:extendedProperty name="OpenSocialUserId" value="14589969791524625011" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">3</thr:total><feedburner:origLink>http://www.vitalsecurity.org/2009/05/if-youve-nothing-to-hide-youve.html</feedburner:origLink></entry></feed>
