<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:blogChannel="http://backend.userland.com/blogChannelModule" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:pingback="http://madskills.com/public/xml/rss/module/pingback/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
  <channel>
    <title>Blog</title>
    <description>Random musings,&lt;br/&gt;probably about you</description>
    <link>http://www.charlescorcoran.com/</link>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>BlogEngine.NET 1.4.0.0</generator>
<language>en-GB</language><blogChannel:blogRoll>http://www.charlescorcoran.com/opml.axd</blogChannel:blogRoll><blogChannel:blink>http://www.dotnetblogengine.net/syndication.axd</blogChannel:blink><dc:creator>Charles.Corcoran</dc:creator><dc:title>Blog</dc:title><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/charlescorcoran/PYjQ" type="application/rss+xml" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item><title>BLAM - Blog Spam</title><description>&lt;p&gt;
An interesting but annoying twist has Bloggers targeted for Spam. People found Google is indexing Blog posts. Posting your positive comment almost guarantees it will be included in the Blog (moderated) comments. The result is the links that are imbedded receive another inclusion in the URL indexer rating system. I have listed a post example below: 
&lt;/p&gt;
&lt;p&gt;
&amp;nbsp;
&lt;/p&gt;
&lt;p&gt;
&lt;img src="http://www.charlescorcoran.com/image.axd?picture=BLAM1.jpg" alt="" width="358" height="309" /&gt;
&lt;/p&gt;
&lt;p&gt;
Notice when I highlight KIM above, notice&amp;nbsp;what the URL is below &amp;quot;her&amp;quot; name. 
&lt;/p&gt;
&lt;p&gt;
This is another annoyance that moderators have to deal with. I will be implementing the CAPTCHA, or some other logic based system to make moderating a little easier. Some simple rules to get your negative post to show on my Blog you wonder? 
&lt;/p&gt;
&lt;p&gt;
1. Don&amp;#39;t link to other sites to increase your Google rating or sell your wares.&lt;br /&gt;
2. Don&amp;#39;t use profane language.&lt;br /&gt;
3. Expound on a compelling argument, don&amp;rsquo;t dis the Blogger for Blogging the issue.&lt;br /&gt;
4. No automated responses. 
&lt;/p&gt;
&lt;p&gt;
I would consider it a blessing to receive constructive criticism that is well thought out. I welcome all opinions. 
&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/charlescorcoran/PYjQ/~4/yxaLDKg3224" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/charlescorcoran/PYjQ/~3/yxaLDKg3224/post.aspx</link><author>SrChasJC.nospam@nospam.hotmail.com (Admin)</author><comments>http://www.charlescorcoran.com/post/2009/07/18/BLAM-Blog-Spam.aspx#comment</comments><guid isPermaLink="false">http://www.charlescorcoran.com/post.aspx?id=ddffc0bb-224b-466c-97e8-99e0fce39f66</guid><pubDate>Sat, 18 Jul 2009 05:44:00 -1100</pubDate><category>GrapeVine</category><category>Network Security</category><dc:publisher>Admin</dc:publisher><pingback:server>http://www.charlescorcoran.com/pingback.axd</pingback:server><pingback:target>http://www.charlescorcoran.com/post.aspx?id=ddffc0bb-224b-466c-97e8-99e0fce39f66</pingback:target><slash:comments>4</slash:comments><trackback:ping>http://www.charlescorcoran.com/trackback.axd?id=ddffc0bb-224b-466c-97e8-99e0fce39f66</trackback:ping><wfw:comment>http://www.charlescorcoran.com/post/2009/07/18/BLAM-Blog-Spam.aspx#comment</wfw:comment><wfw:commentRss>http://www.charlescorcoran.com/syndication.axd?post=ddffc0bb-224b-466c-97e8-99e0fce39f66</wfw:commentRss><feedburner:origLink>http://www.charlescorcoran.com/post.aspx?id=ddffc0bb-224b-466c-97e8-99e0fce39f66</feedburner:origLink></item><item><title>Make the problem part of the solution</title><description>&lt;p style="margin: 0in 0in 10pt" class="MsoNormal"&gt;
&lt;font face="Calibri" size="3"&gt;Protecting Personally Identifiable information (PII) has always been a concern but is required now in most states because almost every network is now connected to the Internet. It is easier than ever for a criminal to obtain your social security number and other information needed to &amp;ldquo;steal&amp;rdquo; your identity.&lt;/font&gt; 
&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt" class="MsoNormal"&gt;
&lt;font face="Calibri" size="3"&gt;Why is it so easy to steal a person&amp;rsquo;s identity once only a few things are known about a person, such as a social security number and place of birth? Because fake cards can be made with these numbers, and when taken to an agency to get a valid Driver&amp;rsquo;s license, or open a utility account, or obtain a Birth Certificate. &lt;span&gt;&amp;nbsp;&lt;/span&gt;Using these valid ID&amp;rsquo;s, other ID&amp;rsquo;s (Even the social security card that was issued based on the fake ID) can now be obtained.&lt;/font&gt; 
&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt" class="MsoNormal"&gt;
&lt;font face="Calibri" size="3"&gt;How do we &amp;ldquo;break the chain&amp;rdquo;? This is a battle that has been ongoing for some time; a &amp;ldquo;National ID Card&amp;rdquo; is constantly facing challenges by &amp;ldquo;rights&amp;rdquo; groups saying loss of personal anonymity would occur. (This is a good place to insert duh!) &lt;span&gt;&amp;nbsp;&lt;/span&gt;Either we can know and verify who you are or we can&amp;rsquo;t. So the challenge is great, but the solution can be simpler.&lt;/font&gt; 
&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt" class="MsoNormal"&gt;
&lt;font face="Calibri" size="3"&gt;SSN&amp;rsquo;s are guessable, according to a SANS report published last week. The Social Security Administration has issued a statement including: &amp;quot;There effectively is no way you can keep {SSNs} totally confidential.&amp;quot; &lt;/font&gt;
&lt;/p&gt;
&lt;p style="margin: 0in 0in 0pt" class="MsoNoSpacing"&gt;
&lt;a href="http://www.nytimes.com/2009/07/07/us/07numbers.html?_r=1"&gt;&lt;font face="Calibri" size="3"&gt;http://www.nytimes.com/2009/07/07/us/07numbers.html?_r=1&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt; &lt;/font&gt;
&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt" class="MsoNormal"&gt;
&lt;a href="http://www.theregister.co.uk/2009/07/07/ssn_guessing_algorithm/"&gt;&lt;font face="Calibri" size="3"&gt;http://www.theregister.co.uk/2009/07/07/ssn_guessing_algorithm/&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt; &lt;/font&gt;
&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt" class="MsoNormal"&gt;
&lt;font face="Calibri" size="3"&gt;We should be concentrating on how to mitigate the risks of disclosure, focusing on processes to prevent improper use. For instance, when a SSN is originally issued by the SSA, they require complete up to date information. Before a SSN can be used, similar to a credit card, the information could be checked electronically before an account is opened, job obtained, etc. &lt;/font&gt;
&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt" class="MsoNormal"&gt;
&lt;font face="Calibri" size="3"&gt;For instance;&lt;/font&gt; 
&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt" class="MsoNormal"&gt;
&lt;font face="Calibri" size="3"&gt;Employers use a system called &amp;ldquo;E-Verify&amp;rdquo; to help verify the validity of social security numbers. This system can be expanded to banks, utility companies, and loan companies to determine if the presented card is valid. So in any case, a federal agency would be the anchor point for any such system. It would be relatively easy to implement and fund. &lt;/font&gt;
&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt" class="MsoNormal"&gt;
&lt;font face="Calibri" size="3"&gt;Forcing companies to use this system and obtain a valid &amp;ldquo;authorization code&amp;rdquo; would prevent - almost stop all identity thefts in their tracks. When an identity is stolen, it will be very easy to catch as the credit reporting agencies should also be required to verify their information before publishing it. Any red flags would cause everyone in the chain to receive change notification. &lt;/font&gt;
&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt" class="MsoNormal"&gt;
&lt;font face="Calibri" size="3"&gt;Fraud involving a valid authorization code will spring a federal agency into action to reverse the wrong actions, challenge the information, utilize intelligence and enforce Title 18 laws on a national level.&lt;/font&gt; 
&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt" class="MsoNormal"&gt;
&lt;font face="Calibri" size="3"&gt;The banking system is a large part of the problem. The day of walking into a bank to open a credit card account has been replaced by just a signature on a pre-approved form in the mailbox. &lt;span&gt;&amp;nbsp;&lt;/span&gt;But the banks would welcome an automated way to verify a SSN and other PII; this would help cut down on their losses. We know the track record of credit reporting agencies (mainly who they rely on today), and the stories about people&amp;rsquo;s dogs obtaining credit. The job of the &amp;ldquo;Feds&amp;rdquo; would be to provide a vehicle for real verification.&lt;/font&gt; 
&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt" class="MsoNormal"&gt;
&lt;font face="Calibri" size="3"&gt;We may never eliminate fraud, but finding ways to make obtaining the information ineffectual will greatly reduce identity theft.&lt;/font&gt; 
&lt;/p&gt;
&lt;font face="Calibri" size="3"&gt;&amp;nbsp;&lt;/font&gt;&lt;img src="http://feeds.feedburner.com/~r/charlescorcoran/PYjQ/~4/XcQkPXJY370" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/charlescorcoran/PYjQ/~3/XcQkPXJY370/post.aspx</link><author>SrChasJC.nospam@nospam.hotmail.com (SrChasJC)</author><comments>http://www.charlescorcoran.com/post/2009/07/12/Make-SSN-number-of-no-value.aspx#comment</comments><guid isPermaLink="false">http://www.charlescorcoran.com/post.aspx?id=2d5bf7ee-e0fe-4a21-ae05-c69662d11ab6</guid><pubDate>Sun, 12 Jul 2009 14:06:00 -1100</pubDate><category>Identity Theft</category><category>Network Security</category><category>political</category><dc:publisher>SrChasJC</dc:publisher><pingback:server>http://www.charlescorcoran.com/pingback.axd</pingback:server><pingback:target>http://www.charlescorcoran.com/post.aspx?id=2d5bf7ee-e0fe-4a21-ae05-c69662d11ab6</pingback:target><slash:comments>3</slash:comments><trackback:ping>http://www.charlescorcoran.com/trackback.axd?id=2d5bf7ee-e0fe-4a21-ae05-c69662d11ab6</trackback:ping><wfw:comment>http://www.charlescorcoran.com/post/2009/07/12/Make-SSN-number-of-no-value.aspx#comment</wfw:comment><wfw:commentRss>http://www.charlescorcoran.com/syndication.axd?post=2d5bf7ee-e0fe-4a21-ae05-c69662d11ab6</wfw:commentRss><feedburner:origLink>http://www.charlescorcoran.com/post.aspx?id=2d5bf7ee-e0fe-4a21-ae05-c69662d11ab6</feedburner:origLink></item><item><title>Security is becoming your responsibility</title><description>&lt;p&gt;
&lt;span style="font-size: 12pt; line-height: 115%"&gt;&lt;font face="Calibri"&gt;We&amp;rsquo;re upset every time we hear about a security breach involving thousands of names and social security numbers or credit cards. In many cases we have no choice to give the information to doctors, etc. I was recently at a medical clinic (ERLANGER PEDIATRICS OF DALTON) on January 22nd, and saw a young lady surfing her MySpace account on the same computer my information was entered. I had a sick feeling in my stomach. In short order I expect my personal information to be on the Internet for sale to the highest bidder. It might fetch up to $50.&lt;/font&gt;&lt;/span&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;span style="font-size: 12pt; line-height: 115%"&gt;&lt;/span&gt;&lt;span style="font-size: 12pt; line-height: 115%"&gt;&lt;font face="Calibri"&gt;Part of the problem is there isn&amp;#39;t an understanding of WHAT needs to be done to protect data and fight cyber crime. Law enforcement is helping there, but they can go overboard, case in point the new federal laws being presented that would require all Internet providers and operators of millions of Wi-Fi access points to keep logs for two years. That means you, the homeowner, the businessman, the coffee shop, hotels, etc etc. &lt;/font&gt;&lt;/span&gt;&lt;span style="font-size: 12pt; line-height: 115%"&gt;&lt;font face="Calibri"&gt;&lt;a href="http://www.cnn.com/2009/TECH/02/20/internet.records.bill/index.html?eref=rss_tech"&gt;&lt;font size="2"&gt;http://www.cnn.com/2009/TECH/02/20/internet.records.bill/index.html?eref=rss_tech&lt;/font&gt;&lt;/a&gt; &lt;/font&gt;&lt;/span&gt;
&lt;/p&gt;
&lt;p&gt;
&lt;span style="font-size: 12pt; line-height: 115%"&gt;&lt;font face="Calibri"&gt;Most of you have never seen a log, now you will have to preserve them. When that guy pulls up to your neighbor&amp;#39;s house and surfs YOUR unprotected access point he/she may be downloading child porn, and it will be up to you to assist law enforcement to catch them.&lt;/font&gt;&lt;/span&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;span style="font-size: 12pt; line-height: 115%"&gt;&lt;/span&gt;&lt;span style="font-size: 12pt; line-height: 115%"&gt;&lt;font face="Calibri"&gt;So yes, YOU will be responsible for maintaining logs if this law is passed. It&amp;#39;s not that it is a bad law, there are many good components. But like I said, there isn&amp;#39;t an understanding of WHAT needs to be done, let&amp;#39;s start there.&lt;/font&gt;&lt;/span&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;span style="font-size: 12pt; line-height: 115%"&gt;&lt;/span&gt;&lt;span style="font-size: 12pt; line-height: 115%"&gt;&lt;font face="Calibri"&gt;First, secure your access point. Force manufacturers to enforce encryption and authentication on their products. Second, know who you&amp;#39;re giving access to. Third, place the burden on the ISP to maintain the logs for you as part of their service (Another law). THEY should know WHO is on their network at all times. I can hear the shouting now, rights issues. But let&amp;#39;s face it, it&amp;#39;s out of control. Who needs to hide when there are open access points all over the world. Fourth, let&amp;#39;s get real, these things will stop an amateur, but it&amp;#39;s the pro&amp;#39;s committing the big crimes. Let&amp;rsquo;s give government the flexibility they need to catch these &amp;quot;pro&amp;#39;s&amp;quot;. Fifth - ask the government to create real standards and hold business AND government agencies accountable, punishable by law. (Please don&amp;#39;t let people surf the Internet on the same network as my SSN)&lt;/font&gt;&lt;/span&gt; 
&lt;/p&gt;
&lt;p&gt;
&lt;span style="font-size: 12pt; line-height: 115%"&gt;&lt;/span&gt;&lt;span style="font-size: 12pt; line-height: 115%"&gt;&lt;font face="Calibri"&gt;There is no magic bullet. But it will be up to us, WE THE PEOPLE, not business, not government, but a collaboration, starting with us requiring our government and business to work toward a common goal: Securing our networks.&lt;/font&gt;&lt;/span&gt;&lt;span style="font-size: 12pt; line-height: 115%"&gt;&lt;font face="Calibri"&gt;&amp;nbsp;&lt;/font&gt;&lt;/span&gt; 
&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/charlescorcoran/PYjQ/~4/V6qpd4EFO_o" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/charlescorcoran/PYjQ/~3/V6qpd4EFO_o/post.aspx</link><author>SrChasJC.nospam@nospam.hotmail.com (SrChasJC)</author><comments>http://www.charlescorcoran.com/post/2009/02/20/Wireless-Access.aspx#comment</comments><guid isPermaLink="false">http://www.charlescorcoran.com/post.aspx?id=d248502b-0865-4ce2-9274-2b3135d72571</guid><pubDate>Fri, 20 Feb 2009 10:35:00 -1100</pubDate><category>GrapeVine</category><category>Network Security</category><category>political</category><dc:publisher>SrChasJC</dc:publisher><pingback:server>http://www.charlescorcoran.com/pingback.axd</pingback:server><pingback:target>http://www.charlescorcoran.com/post.aspx?id=d248502b-0865-4ce2-9274-2b3135d72571</pingback:target><slash:comments>17</slash:comments><trackback:ping>http://www.charlescorcoran.com/trackback.axd?id=d248502b-0865-4ce2-9274-2b3135d72571</trackback:ping><wfw:comment>http://www.charlescorcoran.com/post/2009/02/20/Wireless-Access.aspx#comment</wfw:comment><wfw:commentRss>http://www.charlescorcoran.com/syndication.axd?post=d248502b-0865-4ce2-9274-2b3135d72571</wfw:commentRss><feedburner:origLink>http://www.charlescorcoran.com/post.aspx?id=d248502b-0865-4ce2-9274-2b3135d72571</feedburner:origLink></item><item><title>What’s important to you?</title><description>&lt;p&gt;
&lt;span style="font-size: 11pt; font-family: 'Calibri','sans-serif'"&gt;Ask the question, see what answers you get. Money issues always rates top, next family, work, and then the answers are varied. What if you ask a two year old? (Mine said puppies, toys, going to see Bubba (favorite uncle), Anna, (a next store neighbor) You see their perspective is quite different. How about a teen? (I have three awesome boys, two are teens) Yes, different even still, girls, muscles, time off of school, money, food.&lt;/span&gt;&lt;span style="font-size: 11pt; font-family: 'Calibri','sans-serif'"&gt;What do I consider important? God, family, work. But even that changes depending on the day. Last week my wife and I took my two year old daughter to Disney. When things go well, seems there is not a care in the world. When something bad happens, nothing else matters. When my two year old slipped and went under water (I was very close by) my heart stopped, I grabbed her and got her up out of the water in a split second. She coughed, but was ok. What do you think went through my mind? She was the most important thing in the world to me. I hugged her tight and you can bet the water was a little saltier from my tears that day.&lt;/span&gt; 
&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt" class="MsoNormal"&gt;
&lt;font face="Calibri" size="3"&gt;My daughter saw new things, experienced new things, smells, tastes and sounds. I noticed in many pictures it seemed she wasn&amp;rsquo;t smiling, but she was taking it all in, and when she wasn&amp;rsquo;t laughing, she was struck with awe. I asked her several times after the trip what she liked the most about Disney, I was surprised, meeting Mickey and Mini Mouse rated top. We don&amp;rsquo;t watch much TV, although we do read Disney books to her often, I guessed I was a little surprised that meeting the characters stood out. Riding on the Dumbo ride was her response once. Recently, I&amp;rsquo;ve noticed she has been asking to read stories about Flick, a character in the Bugs Life. I&amp;rsquo;m sure it&amp;rsquo;s because she met (the character) Flick in person. What stands out about that is before we went, she was bitten by several ants in our yard, and when we told her that Flick was an ant, at first she wouldn&amp;rsquo;t get near him. After a little coaxing explaining he didn&amp;rsquo;t bite, she gave him five and we got a couple of pictures. And I appreciate Flick apologizing to her from the whole ant population. Pictures at &lt;/font&gt;&lt;a href="http://www.middleton-howington.com/Photos.aspx?AlbumID=6"&gt;&lt;font face="Calibri" size="3" color="#800080"&gt;http://www.middleton-howington.com/Photos.aspx?AlbumID=6&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt; &lt;/font&gt;
&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt" class="MsoNormal"&gt;
&lt;font face="Calibri" size="3"&gt;When I spend time with my boys little else matters. They don&amp;rsquo;t live with me, so I greatly cherish the time with them. My oldest has a drumming video that showed up on a Google rating higher than my sites (&lt;/font&gt;&lt;a href="http://www.theslapstik.com/videos/Charles-Corcoran.html"&gt;&lt;font face="Calibri" size="3" color="#800080"&gt;http://www.theslapstik.com/videos/Charles-Corcoran.html&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt;) today, of course I&amp;rsquo;m proud. My middle son is focused on IT in High School, winning awards for most improved student, hard to be more proud of him, and that he has direction. And my youngest son is simply known as the wiz, with a wit I wouldn&amp;rsquo;t dare contend with, again, it makes me sing inside with pride. All three of my boys are very sharp and I love them with all my heart.&lt;/font&gt; 
&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt" class="MsoNormal"&gt;
&lt;font face="Calibri" size="3"&gt;As I think about what&amp;rsquo;s important to me, showing my children there is a purpose in life and an internal need for dedication to a lifelong goal. And in whatever direction they choose, be the best they can be at it, I&amp;rsquo;m behind you 100%. Again, what&amp;rsquo;s important is dependent on the day, and right now, mowing the lawn is way up there. Who you were will be measured by the impact you have made today. Now, I&amp;rsquo;m off to impress the neighbors.&lt;/font&gt; 
&lt;/p&gt;
&lt;img src="http://www.charlescorcoran.com/image.axd?picture=flick.bmp" alt="" width="421" height="600" /&gt;&lt;img src="http://feeds.feedburner.com/~r/charlescorcoran/PYjQ/~4/v8I-10pR_Bs" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/charlescorcoran/PYjQ/~3/v8I-10pR_Bs/post.aspx</link><author>SrChasJC.nospam@nospam.hotmail.com (SrChasJC)</author><comments>http://www.charlescorcoran.com/post/2008/10/05/Whate28099s-important-to-you.aspx#comment</comments><guid isPermaLink="false">http://www.charlescorcoran.com/post.aspx?id=168686b5-6383-4d85-9e6d-caac026d0fc0</guid><pubDate>Sun, 05 Oct 2008 11:19:00 -1100</pubDate><category>Family</category><category>Corcoran</category><dc:publisher>SrChasJC</dc:publisher><pingback:server>http://www.charlescorcoran.com/pingback.axd</pingback:server><pingback:target>http://www.charlescorcoran.com/post.aspx?id=168686b5-6383-4d85-9e6d-caac026d0fc0</pingback:target><slash:comments>11</slash:comments><trackback:ping>http://www.charlescorcoran.com/trackback.axd?id=168686b5-6383-4d85-9e6d-caac026d0fc0</trackback:ping><wfw:comment>http://www.charlescorcoran.com/post/2008/10/05/Whate28099s-important-to-you.aspx#comment</wfw:comment><wfw:commentRss>http://www.charlescorcoran.com/syndication.axd?post=168686b5-6383-4d85-9e6d-caac026d0fc0</wfw:commentRss><feedburner:origLink>http://www.charlescorcoran.com/post.aspx?id=168686b5-6383-4d85-9e6d-caac026d0fc0</feedburner:origLink></item><item><title>A one man army - defeated by business - everyone loses</title><description>&lt;p style="margin: 0in 0in 10pt" class="MsoNormal"&gt;
&lt;font face="Calibri" size="3"&gt;It&amp;rsquo;s a disappointing day for the security information professionals. When a man elected by the people sides with business concerns, we all lose. According to &lt;/font&gt;&lt;a href="http://idtheftcenter.org/workplace_facts.html"&gt;&lt;font face="Calibri" size="3" color="#800080"&gt;http://idtheftcenter.org/workplace_facts.html&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt; claims &amp;ldquo;One study said that identity theft cost U.S. businesses and consumers $56.6 billion in 2005&amp;rdquo; and &amp;ldquo;According to the U.S.&lt;span&gt;&amp;nbsp; &lt;/span&gt;Department of Justice Statistics, identity theft is now passing up drug trafficking as the number one crime in the nation&amp;rdquo;.&lt;/font&gt; 
&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt" class="MsoNormal"&gt;
&lt;font face="Calibri" size="3"&gt;On October 5&lt;sup&gt;th&lt;/sup&gt;, 2008 I read a report from SANS that detailed how&amp;nbsp;California Governor Arnold Schwarzenegger vetoed the Consumer Data Protection Act again on October the 2&lt;sup&gt;nd&lt;/sup&gt;. His comments regarding his reasoning included &amp;quot;by requiring notification even where no information was obtained improperly, this bill would likely result in significant costs to businesses and to the state.&amp;quot;&lt;/font&gt; 
&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt" class="MsoNormal"&gt;
&lt;font face="Calibri" size="3"&gt;Identity theft is life changing. Imagine for a moment, opening your credit card bills one month and seeing that all the interest rates raised to 24%, and the payments doubling. If you are trying to finance a home, forget about it because your ratio will change significantly, and your credit rating will be in the toilet. After you pull a credit report, you realize someone has opened a credit card account in your name, charged $20K, and to boot, they are late on the payment! Correction, YOU are late on the payment! That is why all of your credit card companies have revised their terms with you. Even if you get the card company convinced it wasn&amp;rsquo;t you and the charges are removed from your credit file, you are responsible for the increased payments on all the other cards, and getting the terms revised, well, ask anyone who is in that position, you can pretty much forget it. &lt;/font&gt;
&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt" class="MsoNormal"&gt;
&lt;font face="Calibri" size="3"&gt;Three months later, you&amp;rsquo;re considering bankruptcy, you&amp;rsquo;re savings account depleted, and you are considering cashing out your 401K to pay off the credit cards. You have no budget because you can&amp;rsquo;t meet the payments as they are. Now all it takes is a car repair, an increase in gas price, well, you get the picture. The most the &amp;ldquo;company&amp;rdquo; responsible&amp;nbsp;is going to offer you is a free credit report.&lt;/font&gt; 
&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt" class="MsoNormal"&gt;
&lt;font face="Calibri" size="3"&gt;According to &lt;/font&gt;&lt;a href="http://ag.ca.gov/idtheft/"&gt;&lt;font face="Calibri" size="3" color="#800080"&gt;http://ag.ca.gov/idtheft/&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt; there were 45,175 victims reported from California in 2005. This will increase. As a security specialist I have a few observations. Businesses as a rule are lazy, doing only what they have to. (This is not a reflection of any company I have worked for who hired me to improve their security.) If only the businesses treated the personal information like how they HAVE to treat VISA credit card information (That still doesn&amp;rsquo;t mean they will, case in point TJX), we would be much better off. The credit card industry has come together and produced a simple list of requirements; (&lt;/font&gt;&lt;a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml"&gt;&lt;font face="Calibri" size="3" color="#800080"&gt;https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml&lt;/font&gt;&lt;/a&gt;&lt;font face="Calibri" size="3"&gt;), the first of which is &amp;ldquo;Build and Maintain a Secure Network&amp;rdquo;. Wait, you mean this is a requirement? Wouldn&amp;rsquo;t you think that is a given? Don&amp;rsquo;t fool yourself. If you have ever found a company that took credit cards but doesn&amp;rsquo;t take VISA credit, think again about doing business with them because most likely they can&amp;rsquo;t (or won&amp;rsquo;t ) meet these simple standards.&lt;/font&gt; 
&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt" class="MsoNormal"&gt;
&lt;font face="Calibri" size="3"&gt;Unless business HAS to meet certain standards (AND IS AUDITED BY A THIRD PARTY), your data is in jeopardy. You would be very surprised what I have seen as a security professional.&lt;/font&gt; 
&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt" class="MsoNormal"&gt;
&lt;font face="Calibri" size="3"&gt;So back to Arnold. He is in a position to make change to affect people&amp;rsquo;s lives, not only in California, but possibly worldwide. Many states follow California, and let&amp;rsquo;s face it, many countries follow the US. I have always seen Arnold as the underdog, man against the bad world. My favorite movie of all time is Total Recall, where he saves the planet Mars. If I could speak to him, I would only say I wished you could see the blatant disregard of personal data I have seen, not with the companies I was/am with, but the companies they do business with, and shared information from other security professionals. &lt;/font&gt;
&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt" class="MsoNormal"&gt;
&lt;font face="Calibri" size="3"&gt;Laws don&amp;rsquo;t fix everything, but they do cause change. It would be a shame to think that every company would have to make the headlines before they made the changes required to secure personal information. Without laws, this is what will happen. Meanwhile, your information is not only in your state, but in every home office of every company you do business with. A little multiplication, and the 45K people for just one state for one year, now think of the odds of your information being exposed. If you do business on the Internet, use a credit card in a restaurant or retailer, your odds are not good. Someone will use that card, your information, or otherwise get at the data because of the fact there are weak controls, or for the smaller companies, no controls in place since they won&amp;rsquo;t fall under any of the other control standards such as SOX, HIPPA, or PCI. That&amp;#39;s where a law comes in to play. It gives security professionals like myself the grease to make internal changes.&lt;/font&gt; 
&lt;/p&gt;
&lt;p style="margin: 0in 0in 10pt" class="MsoNormal"&gt;
&lt;font face="Calibri" size="3"&gt;Arnold, you have shown us that the sword is mightier than the pen.&lt;/font&gt; 
&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/charlescorcoran/PYjQ/~4/7l3vP0It0-A" height="1" width="1"/&gt;</description><link>http://feedproxy.google.com/~r/charlescorcoran/PYjQ/~3/7l3vP0It0-A/post.aspx</link><author>SrChasJC.nospam@nospam.hotmail.com (SrChasJC)</author><comments>http://www.charlescorcoran.com/post/2008/10/05/A-one-man-army-defeated-by-business-everyone-loses.aspx#comment</comments><guid isPermaLink="false">http://www.charlescorcoran.com/post.aspx?id=f0839794-32e3-4c11-9d6f-5cd7216333d6</guid><pubDate>Sun, 05 Oct 2008 05:08:00 -1100</pubDate><category>GrapeVine</category><category>Identity Theft</category><category>Network Security</category><category>political</category><dc:publisher>SrChasJC</dc:publisher><pingback:server>http://www.charlescorcoran.com/pingback.axd</pingback:server><pingback:target>http://www.charlescorcoran.com/post.aspx?id=f0839794-32e3-4c11-9d6f-5cd7216333d6</pingback:target><slash:comments>56</slash:comments><trackback:ping>http://www.charlescorcoran.com/trackback.axd?id=f0839794-32e3-4c11-9d6f-5cd7216333d6</trackback:ping><wfw:comment>http://www.charlescorcoran.com/post/2008/10/05/A-one-man-army-defeated-by-business-everyone-loses.aspx#comment</wfw:comment><wfw:commentRss>http://www.charlescorcoran.com/syndication.axd?post=f0839794-32e3-4c11-9d6f-5cd7216333d6</wfw:commentRss><feedburner:origLink>http://www.charlescorcoran.com/post.aspx?id=f0839794-32e3-4c11-9d6f-5cd7216333d6</feedburner:origLink></item></channel>
</rss>
