<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>flyingpenguin</title>
	
	<link>http://www.flyingpenguin.com</link>
	<description>the poetry of information security</description>
	<lastBuildDate>Mon, 06 Sep 2010 00:09:01 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/flyingpenguin" /><feedburner:info uri="flyingpenguin" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><creativeCommons:license>http://creativecommons.org/licenses/by-sa/2.0/</creativeCommons:license><feedburner:emailServiceId>flyingpenguin</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item>
		<title>Water Filter In a Tea Bag</title>
		<link>http://feedproxy.google.com/~r/flyingpenguin/~3/MAS9ZiuU1EI/</link>
		<comments>http://www.flyingpenguin.com/?p=6861#comments</comments>
		<pubDate>Mon, 06 Sep 2010 00:01:07 +0000</pubDate>
		<dc:creator>Davi Ottenheimer</dc:creator>
				<category><![CDATA[Food]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.flyingpenguin.com/?p=6861</guid>
		<description><![CDATA[A researcher from Stellenbosch University in South Africa claims to have developed a water filter the size of a tea bag. It thus can be fitted under the cap of a bottle. This significantly reduces the cost and inconvenience of water quality, as reported by BBC News
&#8220;We cover the tea bag material with nano-structured fibres, [...]]]></description>
			<content:encoded><![CDATA[<p>A researcher from Stellenbosch University in South Africa claims to have developed a water filter the size of a tea bag. It thus can be fitted under the cap of a bottle. This significantly reduces the cost and inconvenience of water quality, <a href="http://www.bbc.co.uk/news/world-africa-11156031">as reported by BBC News</a></p>
<blockquote><p>&#8220;We cover the tea bag material with nano-structured fibres, and instead of tea inside the tea bag, we incorporate activated carbon.</p>
<p>&#8220;The function of the activated carbon is to remove most of the dangerous chemicals that you would find in water.&#8221;</p>
<p>He says that the function of the fibres is to create a filter where harmful bacteria is physically filtered out and killed.</p></blockquote>
<p>The BBC does not mention what quantity and speed of water can be filtered by a single bag. Those are the usual metrics but <a href="http://www.engineeringnews.co.za/article/stellenbosch-university-scientists-patent-tea-baglike-water-filter-2010-08-13">each bag is meant to be used only for a single serving</a> just like tea.</p>
<p>The inventor, &#8220;past executive vice-president of global network of water professionals the International Water Association and a member of Coca-Cola&#8217;s global panel of water experts&#8221;, emphasizes the importance of decentralized solutions to help those most in need of water security.</p>
<blockquote><p>A water security risk index of 165 nations, released by UK-based risk consultancy firm Maplecroft in June found that African and Asian nations had the most vulnerable water supplies, judged by factors such as availability of drinking water, demand per capita and dependence on rivers that flow through other countries. [Professor Eugene] Cloete adds that more than 90% of all cholera cases are reported in Africa, and 300-million people on the continent do not have access to safe drinking water.</p>
<p>&#8220;The &#8216;tea bag&#8217; filter can show the way forward, as it represents decentralised, point-of-use technology. &#8220;It can assist in meeting the needs of people who live or travel in remote areas, or people whose regular water supply is not treated to potable standards. &#8220;As it is impossible to build purification infrastructure at every polluted stream, we have to take the solution to the people,&#8221; he notes.</p></blockquote>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-enjoy">
<ul class="socials">
		<li class="shr-mail">
			<a href="mailto:?subject=%22Water%20Filter%20In%20a%20Tea%20Bag%22&amp;body=Link: http://www.flyingpenguin.com/?p=6861 (sent via shareaholic)%0D%0A%0D%0A----%0D%0A A%20researcher%20from%20Stellenbosch%20University%20in%20South%20Africa%20claims%20to%20have%20developed%20a%20water%20filter%20the%20size%20of%20a%20tea%20bag.%20It%20thus%20can%20be%20fitted%20under%20the%20cap%20of%20a%20bottle.%20This%20significantly%20reduces%20the%20cost%20and%20inconvenience%20of%20water%20quality%2C%20as%20reported%20by%20BBC%20News%0A%0A%22We%20cover%20the%20tea%20bag%20material%20wi" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.flyingpenguin.com/?p=6861&amp;feed=comments-rss2" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.flyingpenguin.com/?p=6861&amp;title=Water+Filter+In+a+Tea+Bag" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Water+Filter+In+a+Tea+Bag+-+http://b2l.me/apnhtd&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.flyingpenguin.com/?p=6861&amp;t=Water+Filter+In+a+Tea+Bag" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.flyingpenguin.com/?p=6861" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.flyingpenguin.com/?p=6861&amp;title=Water+Filter+In+a+Tea+Bag" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.flyingpenguin.com/?p=6861&amp;title=Water+Filter+In+a+Tea+Bag" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.flyingpenguin.com/?p=6861&amp;title=Water+Filter+In+a+Tea+Bag" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<img src="http://feeds.feedburner.com/~r/flyingpenguin/~4/MAS9ZiuU1EI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.flyingpenguin.com/?feed=rss2&amp;p=6861</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.flyingpenguin.com/?p=6861</feedburner:origLink></item>
		<item>
		<title>Padlock Gunshot Test</title>
		<link>http://feedproxy.google.com/~r/flyingpenguin/~3/dhY7DlXgrqc/</link>
		<comments>http://www.flyingpenguin.com/?p=6849#comments</comments>
		<pubDate>Sun, 05 Sep 2010 23:35:47 +0000</pubDate>
		<dc:creator>Davi Ottenheimer</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.flyingpenguin.com/?p=6849</guid>
		<description><![CDATA[Four padlocks were tested by Popular Mechanics using a rifle from 100 feet away. Can you find the winner?

They also ran tests using shock, bolt-cutters, tensile and salt-fog. 
The most expensive of the four locks did not win a single test.




		
			Email this to a friend?
		
		
			Subscribe to the comments for this post?
		
		
			Share this on Reddit
		
		
			Tweet This!
		
		
			Share [...]]]></description>
			<content:encoded><![CDATA[<p>Four padlocks <a href="http://www.popularmechanics.com/technology/gadgets/tests/can-your-padlock-withstand-a-bullet">were tested by Popular Mechanics</a> using a rifle from 100 feet away. Can you find the winner?</p>
<div class="youtube-video"><object height="283" width="460"><param name="movie" value="http://www.youtube.com/v/sWcKYJgjm08?fs=1&amp;hl=en_US&amp;rel=0"></param><param name="allowFullScreen" value="true"></param><param name="allowscriptaccess" value="always"></param><embed src="http://www.youtube.com/v/sWcKYJgjm08?fs=1&amp;hl=en_US&amp;rel=0" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" height="283" width="460"></embed></object></div>
<p>They also ran tests using shock, bolt-cutters, tensile and salt-fog. </p>
<p>The most expensive of the four locks did not win a single test.</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-enjoy">
<ul class="socials">
		<li class="shr-mail">
			<a href="mailto:?subject=%22Padlock%20Gunshot%20Test%22&amp;body=Link: http://www.flyingpenguin.com/?p=6849 (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Four%20padlocks%20were%20tested%20by%20Popular%20Mechanics%20using%20a%20rifle%20from%20100%20feet%20away.%20Can%20you%20find%20the%20winner%3F%0A%0A%20%20%20%20%20%20%0A%0A%0AThey%20also%20ran%20tests%20using%20shock%2C%20bolt-cutters%2C%20tensile%20and%20salt-fog.%20%0A%0AThe%20most%20expensive%20of%20the%20four%20locks%20did%20not%20win%20a%20single%20test." rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.flyingpenguin.com/?p=6849&amp;feed=comments-rss2" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.flyingpenguin.com/?p=6849&amp;title=Padlock+Gunshot+Test" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Padlock+Gunshot+Test+-+http://b2l.me/apnduw&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.flyingpenguin.com/?p=6849&amp;t=Padlock+Gunshot+Test" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.flyingpenguin.com/?p=6849" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.flyingpenguin.com/?p=6849&amp;title=Padlock+Gunshot+Test" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.flyingpenguin.com/?p=6849&amp;title=Padlock+Gunshot+Test" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.flyingpenguin.com/?p=6849&amp;title=Padlock+Gunshot+Test" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<img src="http://feeds.feedburner.com/~r/flyingpenguin/~4/dhY7DlXgrqc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.flyingpenguin.com/?feed=rss2&amp;p=6849</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.flyingpenguin.com/?p=6849</feedburner:origLink></item>
		<item>
		<title>CA Snow Helmet Law for Minors</title>
		<link>http://feedproxy.google.com/~r/flyingpenguin/~3/hhLxtjM4fHg/</link>
		<comments>http://www.flyingpenguin.com/?p=6847#comments</comments>
		<pubDate>Sun, 05 Sep 2010 21:03:29 +0000</pubDate>
		<dc:creator>Davi Ottenheimer</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.flyingpenguin.com/?p=6847</guid>
		<description><![CDATA[The Governor of California has until September to sign a bill into law that will require minors in California to wear a helmet when skiing or snowboarding.
The state Senate on Wednesday voted 21-11 to pass SB880, which requires helmets for snowboarders and skiers under 18.
The helmet law would be the country&#8217;s most restrictive if Gov. [...]]]></description>
			<content:encoded><![CDATA[<p>The Governor of California has until September to sign a bill into law that will require minors in <a href="http://www.insidebayarea.com/ci_15914023?source=most_emailed">California to wear a helmet when skiing or snowboarding</a>.</p>
<blockquote><p>The state Senate on Wednesday voted 21-11 to pass SB880, which requires helmets for snowboarders and skiers under 18.</p>
<p>The helmet law would be the country&#8217;s most restrictive if Gov. Arnold Schwarzenegger signs the legislation. The fine, however, would top out at $25.</p>
<p>The bill would require resorts to post signs about the law on trail maps, websites and other locations throughout the property.</p></blockquote>
<p>There already is a <a href="http://www.dmv.ca.gov/pubs/vctop/d11/vc21212.htm">bicycle, skate and skateboard helmet law for minors</a> in California and a <a href="http://www.bhsi.org/negativs.htm">wealth of information</a> on <a href="http://www.bhsi.org/mandator.htm">bike helmet laws</a> at the Bike Helmet Safety Institute.</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-enjoy">
<ul class="socials">
		<li class="shr-mail">
			<a href="mailto:?subject=%22CA%20Snow%20Helmet%20Law%20for%20Minors%22&amp;body=Link: http://www.flyingpenguin.com/?p=6847 (sent via shareaholic)%0D%0A%0D%0A----%0D%0A The%20Governor%20of%20California%20has%20until%20September%20to%20sign%20a%20bill%20into%20law%20that%20will%20require%20minors%20in%20California%20to%20wear%20a%20helmet%20when%20skiing%20or%20snowboarding.%0A%0AThe%20state%20Senate%20on%20Wednesday%20voted%2021-11%20to%20pass%20SB880%2C%20which%20requires%20helmets%20for%20snowboarders%20and%20skiers%20under%2018.%0A%0AThe%20helmet%20law%20would%20be%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.flyingpenguin.com/?p=6847&amp;feed=comments-rss2" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.flyingpenguin.com/?p=6847&amp;title=CA+Snow+Helmet+Law+for+Minors" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=CA+Snow+Helmet+Law+for+Minors+-+http://b2l.me/apmkcf&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.flyingpenguin.com/?p=6847&amp;t=CA+Snow+Helmet+Law+for+Minors" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.flyingpenguin.com/?p=6847" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.flyingpenguin.com/?p=6847&amp;title=CA+Snow+Helmet+Law+for+Minors" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.flyingpenguin.com/?p=6847&amp;title=CA+Snow+Helmet+Law+for+Minors" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.flyingpenguin.com/?p=6847&amp;title=CA+Snow+Helmet+Law+for+Minors" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<img src="http://feeds.feedburner.com/~r/flyingpenguin/~4/hhLxtjM4fHg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.flyingpenguin.com/?feed=rss2&amp;p=6847</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.flyingpenguin.com/?p=6847</feedburner:origLink></item>
		<item>
		<title>How much should UK phone hacker’s boss be paid?</title>
		<link>http://feedproxy.google.com/~r/flyingpenguin/~3/9rcESsM_P9w/</link>
		<comments>http://www.flyingpenguin.com/?p=6840#comments</comments>
		<pubDate>Sat, 04 Sep 2010 15:32:19 +0000</pubDate>
		<dc:creator>Davi Ottenheimer</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.flyingpenguin.com/?p=6840</guid>
		<description><![CDATA[I have been trying to maintain interest in the controversy regarding Andy Coulson, home secretary in the UK. Was he involved in authorization of &#8220;phone hacking&#8221; when he was editor of a paper? Very little technical detail is being discussed; it appears to be devolving into a political mud campaign. A good example is the [...]]]></description>
			<content:encoded><![CDATA[<p>I have been trying to maintain interest in the controversy regarding Andy Coulson, home secretary in the UK. Was he involved in authorization of &#8220;phone hacking&#8221; when he was editor of a paper? Very little technical detail is being discussed; it appears to be devolving into a political mud campaign. A good example is the BBC news that <a href="http://www.bbc.co.uk/news/uk-politics-11188459">Ed Balls demands statement on &#8216;phone hacking&#8217; claims</a></p>
<blockquote><p>Leadership hopeful Ed Balls said David Cameron should ask Theresa May to assure MPs that the allegations would be properly investigated. [...] &#8220;But look, we cannot have somebody being paid over £140,000 a year to run the government&#8217;s communications when there are questions about whether he misled Parliament or not, and whether or not he was systematically involved in illegally bugging the telephones of members of Parliament and wider citizens.&#8221;</p></blockquote>
<p>Apparently it takes Balls to ask Cameron to ask Theresa to make a statement. </p>
<p>Sorry, couldn&#8217;t resist that line. Seriously, though, what does a salary have to do with anything? Balls appears to be trying to use it as a wedge to drive resentment against Cameron, or against Coulson, or both.</p>
<p>The issue I see first is whether or not Coulson was involved and second to what level. It would be nice to see a third part describing details of the incident. Tessa Jowell, for example, claimed 28 individual hacks on her phone. How were those counted as individual &#8220;hacks&#8221;? Many of the hacks seem to be just sloppy impersonations that left behind obvious indicators like messages being flagged as read before the mobile owner had read them &#8212; a PIN code was stolen once and then used repeatedly.</p>
<p>The New York Times suggested that Rupert Murdoch’s <a href="http://www.nytimes.com/2010/09/05/magazine/05hacking-t.html?_r=3&amp;pagewanted=all">tabloid practice of privacy breaches and surveillance was widespread in the industry</a>. </p>
<blockquote><p>Scotland Yard collected evidence indicating that reporters at News of the World might have hacked the phone messages of hundreds of celebrities, government officials, soccer stars — anyone whose personal secrets could be tabloid fodder. Only now, more than four years later, are most of them beginning to find out. [...] Andy Coulson, the top editor at the time, had imposed a hypercompetitive ethos, even by tabloid standards. One former reporter called it a &#8220;do whatever it takes&#8221; mentality. The reporter was one of two people who said Coulson was present during discussions about phone hacking. Coulson ultimately resigned but denied any knowledge of hacking. </p></blockquote>
<p>Coulson is being pinned with raising the stakes in the game. Maybe that is why his salary as home secretary is being tossed out in debate even though it does not really belong in any of the three parts I mentioned. It does seem to fit into a &#8220;do whatever it takes&#8221; competitive culture. </p>
<p>I say it will be hard to isolate fault in tabloids for digging in and bringing everything to the front page when the same style of sensationalism is used by leaders in British Parliament. Coulson&#8217;s salary is perhaps public information, which would clearly differentiate it from details of his private communications, but the context still illustrates what might motivate tabloid surveillance. The fights get dirty.</p>
<p>The politics and arguments between those trying diligently to preserve privacy and those working to expose information hopefully will evolve into another story; how industry and mobile owners can detect and report surveillance regardless of source. Will the UK government, in other words, move now towards support of privacy that counters private industry surveillance, given that those same skills and tools will probably interfere with their infamous government-led surveillance?</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-enjoy">
<ul class="socials">
		<li class="shr-mail">
			<a href="mailto:?subject=%22How%20much%20should%20UK%20phone%20hacker%27s%20boss%20be%20paid%3F%22&amp;body=Link: http://www.flyingpenguin.com/?p=6840 (sent via shareaholic)%0D%0A%0D%0A----%0D%0A I%20have%20been%20trying%20to%20maintain%20interest%20in%20the%20controversy%20regarding%20Andy%20Coulson%2C%20home%20secretary%20in%20the%20UK.%20Was%20he%20involved%20in%20authorization%20of%20%22phone%20hacking%22%20when%20he%20was%20editor%20of%20a%20paper%3F%20Very%20little%20technical%20detail%20is%20being%20discussed%3B%20it%20appears%20to%20be%20devolving%20into%20a%20political%20mud%20campaign.%20A" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.flyingpenguin.com/?p=6840&amp;feed=comments-rss2" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.flyingpenguin.com/?p=6840&amp;title=How+much+should+UK+phone+hacker%27s+boss+be+paid%3F" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=How+much+should+UK+phone+hacker%27s+boss+be+paid%3F+-+http://b2l.me/apcstd&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.flyingpenguin.com/?p=6840&amp;t=How+much+should+UK+phone+hacker%27s+boss+be+paid%3F" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.flyingpenguin.com/?p=6840" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.flyingpenguin.com/?p=6840&amp;title=How+much+should+UK+phone+hacker%27s+boss+be+paid%3F" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.flyingpenguin.com/?p=6840&amp;title=How+much+should+UK+phone+hacker%27s+boss+be+paid%3F" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.flyingpenguin.com/?p=6840&amp;title=How+much+should+UK+phone+hacker%27s+boss+be+paid%3F" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<img src="http://feeds.feedburner.com/~r/flyingpenguin/~4/9rcESsM_P9w" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.flyingpenguin.com/?feed=rss2&amp;p=6840</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.flyingpenguin.com/?p=6840</feedburner:origLink></item>
		<item>
		<title>Chimps outwit hunters</title>
		<link>http://feedproxy.google.com/~r/flyingpenguin/~3/48-AGHBeDvs/</link>
		<comments>http://www.flyingpenguin.com/?p=6835#comments</comments>
		<pubDate>Sat, 04 Sep 2010 02:38:41 +0000</pubDate>
		<dc:creator>Davi Ottenheimer</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.flyingpenguin.com/?p=6835</guid>
		<description><![CDATA[The BBC says wild chimps have learned to detect and avoid traps set by human hunters
Across Africa, people often lay snare traps to catch bushmeat, killing or injuring chimps and other wildlife.
But a few chimps living in the rainforests of Guinea have learnt to recognise these snare traps laid by human hunters, researchers have found.
More [...]]]></description>
			<content:encoded><![CDATA[<p>The BBC says <a href="http://news.bbc.co.uk/earth/hi/earth_news/newsid_8962000/8962747.stm">wild chimps have learned to detect and avoid traps set by human hunters</a></p>
<blockquote><p>Across Africa, people often lay snare traps to catch bushmeat, killing or injuring chimps and other wildlife.</p>
<p>But a few chimps living in the rainforests of Guinea have learnt to recognise these snare traps laid by human hunters, researchers have found.</p>
<p>More astonishing, the chimps actively seek out and intentionally deactivate the traps, setting them off without being harmed. </p></blockquote>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-enjoy">
<ul class="socials">
		<li class="shr-mail">
			<a href="mailto:?subject=%22Chimps%20outwit%20hunters%22&amp;body=Link: http://www.flyingpenguin.com/?p=6835 (sent via shareaholic)%0D%0A%0D%0A----%0D%0A The%20BBC%20says%20wild%20chimps%20have%20learned%20to%20detect%20and%20avoid%20traps%20set%20by%20human%20hunters%0A%0AAcross%20Africa%2C%20people%20often%20lay%20snare%20traps%20to%20catch%20bushmeat%2C%20killing%20or%20injuring%20chimps%20and%20other%20wildlife.%0A%0ABut%20a%20few%20chimps%20living%20in%20the%20rainforests%20of%20Guinea%20have%20learnt%20to%20recognise%20these%20snare%20traps%20laid%20by" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.flyingpenguin.com/?p=6835&amp;feed=comments-rss2" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.flyingpenguin.com/?p=6835&amp;title=Chimps+outwit+hunters" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Chimps+outwit+hunters+-+http://b2l.me/apbm5f&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.flyingpenguin.com/?p=6835&amp;t=Chimps+outwit+hunters" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.flyingpenguin.com/?p=6835" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.flyingpenguin.com/?p=6835&amp;title=Chimps+outwit+hunters" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.flyingpenguin.com/?p=6835&amp;title=Chimps+outwit+hunters" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.flyingpenguin.com/?p=6835&amp;title=Chimps+outwit+hunters" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<img src="http://feeds.feedburner.com/~r/flyingpenguin/~4/48-AGHBeDvs" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.flyingpenguin.com/?feed=rss2&amp;p=6835</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.flyingpenguin.com/?p=6835</feedburner:origLink></item>
		<item>
		<title>Linguistic Email Analysis Catches Fraud</title>
		<link>http://feedproxy.google.com/~r/flyingpenguin/~3/Uy5XlTKZC0I/</link>
		<comments>http://www.flyingpenguin.com/?p=6827#comments</comments>
		<pubDate>Fri, 03 Sep 2010 19:33:35 +0000</pubDate>
		<dc:creator>Davi Ottenheimer</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.flyingpenguin.com/?p=6827</guid>
		<description><![CDATA[At the RSA 2010 Conference in San Francisco last March I gave a presentation with linguistic anthropologist Harriet Ottenheimer. We explained how linguistic analysis of email can catch fraud and we gave the example of 419 scams, also known as advanced fee fraud (AFF). A pattern of &#8220;bad&#8221; language stands out. This is a concept [...]]]></description>
			<content:encoded><![CDATA[<p>At the <a href="http://www.emc.com/microsites/rsa-conference/2010/usa/">RSA 2010 Conference in San Francisco last March</a> I gave a presentation with linguistic anthropologist Harriet Ottenheimer. We explained how linguistic analysis of email can catch fraud and we gave the example of 419 scams, also known as advanced fee fraud (AFF). A pattern of &#8220;bad&#8221; language stands out. This is a concept we have <a href="?page_id=40">developed and presented over several years</a>.</p>
<p>The question we often are asked is whether this could be applied to email systems with automation. The answer is of course yes. Just as malware can be caught by looking for bad code, fraud can be caught by looking for a pattern of &#8220;bad&#8221; language.</p>
<p>I will present an update to our research at the <a href="http://www.htciaconference.org/">International High Technology Crime Investigation Association Conference</a> this month in Atlanta, Georgia. </p>
<p><a href="http://www.securecomputing.net.au/News/230855,subconscious-language-leads-to-sales-fraud.aspx">SC Magazine reports today that Blare Sutton of Ernst and Young has found success with fraud investigations by manually applying our technique in the field</a>.</p>
<blockquote><p>Words that showed &#8220;subconscious&#8221; tendencies included problem, concern, revise, discount, correct, miss, Figure out, It&#8217;s OK, find it, complex. And when regulators such as the Australian Securities and Investments Commission were breathing down a company&#8217;s neck, Sutton&#8217;s team looked for incidences of their mentions in emails. </p>
<p>&#8220;It&#8217;s basic language,&#8221; he said. &#8220;There was nothing about the fraud [in the emails], it was subconscious language that led to an anomaly from which we could do a traditional investigation.&#8221; </p></blockquote>
<p>Yes, just like a virus will masquerade as something else fraud language is not obvious, but calling it &#8220;subconscious&#8221; language is inaccurate. The story indicates Sutton is trying to statistically show correlation so the question now becomes whether we could predict fraud in advance or actually block fraud messages pro-actively. We are moving towards a warning system or prevention technique. Simply classifying language after the fact, which appears to be Sutton&#8217;s story, is interesting but not an ideal use case &#8212; his application comes across as &#8220;once we know there is fraud we can find indicators of it&#8221;. </p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-enjoy">
<ul class="socials">
		<li class="shr-mail">
			<a href="mailto:?subject=%22Linguistic%20Email%20Analysis%20Catches%20Fraud%22&amp;body=Link: http://www.flyingpenguin.com/?p=6827 (sent via shareaholic)%0D%0A%0D%0A----%0D%0A At%20the%20RSA%202010%20Conference%20in%20San%20Francisco%20last%20March%20I%20gave%20a%20presentation%20with%20linguistic%20anthropologist%20Harriet%20Ottenheimer.%20We%20explained%20how%20linguistic%20analysis%20of%20email%20can%20catch%20fraud%20and%20we%20gave%20the%20example%20of%20419%20scams%2C%20also%20known%20as%20advanced%20fee%20fraud%20%28AFF%29.%20A%20pattern%20of%20%22bad%22%20language%20sta" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.flyingpenguin.com/?p=6827&amp;feed=comments-rss2" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.flyingpenguin.com/?p=6827&amp;title=Linguistic+Email+Analysis+Catches+Fraud" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Linguistic+Email+Analysis+Catches+Fraud+-+http://b2l.me/an9q9y&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.flyingpenguin.com/?p=6827&amp;t=Linguistic+Email+Analysis+Catches+Fraud" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.flyingpenguin.com/?p=6827" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.flyingpenguin.com/?p=6827&amp;title=Linguistic+Email+Analysis+Catches+Fraud" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.flyingpenguin.com/?p=6827&amp;title=Linguistic+Email+Analysis+Catches+Fraud" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.flyingpenguin.com/?p=6827&amp;title=Linguistic+Email+Analysis+Catches+Fraud" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<img src="http://feeds.feedburner.com/~r/flyingpenguin/~4/Uy5XlTKZC0I" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.flyingpenguin.com/?feed=rss2&amp;p=6827</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.flyingpenguin.com/?p=6827</feedburner:origLink></item>
		<item>
		<title>Malware gang nets $30 million in one month</title>
		<link>http://feedproxy.google.com/~r/flyingpenguin/~3/eMD5aqil69A/</link>
		<comments>http://www.flyingpenguin.com/?p=6807#comments</comments>
		<pubDate>Fri, 03 Sep 2010 18:40:07 +0000</pubDate>
		<dc:creator>Davi Ottenheimer</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.flyingpenguin.com/?p=6807</guid>
		<description><![CDATA[RT has posted a story from Moscow titled Police bust hacker gang who made $30 million in one month.
Operatives of the city police directorate for fighting economic crimes have told journalists that the suspects created a computer virus that blocked all programs on the users&#8217; computers and put a pornographic picture on the screen together [...]]]></description>
			<content:encoded><![CDATA[<p>RT has posted a story from Moscow titled <a href="http://rt.com/Top_News/2010-08-31/hackers-gang-russian-bust.html">Police bust hacker gang who made $30 million in one month</a>.</p>
<blockquote><p>Operatives of the city police directorate for fighting economic crimes have told journalists that the suspects created a computer virus that blocked all programs on the users&#8217; computers and put a pornographic picture on the screen together with a demand to send an SMS to a certain number to receive a code that would supposedly unblock the computer. For the SMS the victims were billed about 300 roubles or $10. However, sending the SMS never led to any results and some users have sent it repeatedly.</p></blockquote>
<p>I detect hyperbole. Let me count the ways I find this story hard to follow. </p>
<ol>
<li>Even if users hit the SMS repeated times there still were over a million users affected. I searched the source lifenews.ru and found no mention of the malware incident. My Russian is not great but a million people with inoperable computers seems like it should be a headline story long before the police report catching the people responsible. The software in this case is not named but it probably is related to <a href="http://forum.sysinternals.com/trojan-ransom-winlock-lockscreen_topic22054.html">WinLock and LockScreen</a></li>
<li>Malware that tries to lock a system and demand payment is nothing new. <a href="http://www.sophos.com/security/analyses/viruses-and-spyware/trojransoma.html">Ransomware-A</a> by name alone made it pretty clear in 2006 that you should not give in to demands for money. Are so many users in Russia really unaware of this class of malware and attack vector? Do they not realize <a href="http://www.symantec.com/business/security_response/writeup.jsp?docid=2009-041607-1924-99">they could use a free tool to get the unlock code</a> or just <a href="http://www.symantec.com/connect/blogs/sms-ransomware-threat">figure out the unlock code themselves</a>?</li>
<li>Russians are said to be familiar with or even seasoned by news of fraud and crime linked to blackmail. Why did they forgo all the other options and instead believe in a ransom note &#8212; give their money to someone without any guarantee of getting an unlock code in return?</li>
<li>The Telecom companies facilitated the crime. They must have detected something amiss when that many SMS messages flooded their system for so long and so much in revenue. Is there no fraud detection? No early-warning system in operation? Did they send a giant check to the gang as a prize, like a lottery winner, or did they just freeze the account and refuse payment? Perhaps I should ask this a different way. Do infrastructure operators in Russia have any incentive to detect and block this kind of obvious criminal activity or are they just taking a cut of the profits (apparently 50%) and walking away clean even after the criminals are caught?</li>
</ol>
<p>The failure of the fraud detection system and the awareness of users is the real story I see in this report. Two or three days after the attack started it could have been shut down completely. Nothing glamorous or clever about it, and very easy to stop/prevent, which makes it so hard to believe it could have been as successful as claimed just as malware. I therefore think this amount of money must only be possible with the cooperation of those who could stop the attack.</p>
<p>An <a href="http://www.itar-tass.com/eng/level2.html?NewsID=15445927&amp;PageNum=1">ITAR-TASS report</a> gives a very different estimate of harm over a much longer period of time.</p>
<blockquote><p>According to preliminary calculations, more than 3,000 Internet users fell victims of fraudsters in April alone, including in CIS countries. According to police data, the annual profit of law-breakers topped one billion roubles.</p></blockquote>
<p>Perhaps something is being lost in translation with the first report. The same amount over a year is far more believable, but still begs the question of corruption and presence of simple controls.</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-enjoy">
<ul class="socials">
		<li class="shr-mail">
			<a href="mailto:?subject=%22Malware%20gang%20nets%20%2430%20million%20in%20one%20month%22&amp;body=Link: http://www.flyingpenguin.com/?p=6807 (sent via shareaholic)%0D%0A%0D%0A----%0D%0A RT%20has%20posted%20a%20story%20from%20Moscow%20titled%20Police%20bust%20hacker%20gang%20who%20made%20%2430%20million%20in%20one%20month.%0A%0AOperatives%20of%20the%20city%20police%20directorate%20for%20fighting%20economic%20crimes%20have%20told%20journalists%20that%20the%20suspects%20created%20a%20computer%20virus%20that%20blocked%20all%20programs%20on%20the%20users%27%20computers%20and%20put%20a%20por" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.flyingpenguin.com/?p=6807&amp;feed=comments-rss2" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.flyingpenguin.com/?p=6807&amp;title=Malware+gang+nets+%2430+million+in+one+month" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Malware+gang+nets+%2430+million+in+one+month+-+http://b2l.me/an9ewh&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.flyingpenguin.com/?p=6807&amp;t=Malware+gang+nets+%2430+million+in+one+month" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.flyingpenguin.com/?p=6807" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.flyingpenguin.com/?p=6807&amp;title=Malware+gang+nets+%2430+million+in+one+month" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.flyingpenguin.com/?p=6807&amp;title=Malware+gang+nets+%2430+million+in+one+month" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.flyingpenguin.com/?p=6807&amp;title=Malware+gang+nets+%2430+million+in+one+month" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<img src="http://feeds.feedburner.com/~r/flyingpenguin/~4/eMD5aqil69A" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.flyingpenguin.com/?feed=rss2&amp;p=6807</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.flyingpenguin.com/?p=6807</feedburner:origLink></item>
		<item>
		<title>Two Wheel EV Recumbant: Zerotracer</title>
		<link>http://feedproxy.google.com/~r/flyingpenguin/~3/fCQ9T4PYhmA/</link>
		<comments>http://www.flyingpenguin.com/?p=6803#comments</comments>
		<pubDate>Thu, 02 Sep 2010 20:39:14 +0000</pubDate>
		<dc:creator>Davi Ottenheimer</dc:creator>
				<category><![CDATA[Energy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.flyingpenguin.com/?p=6803</guid>
		<description><![CDATA[Wired says the Two-Wheeled Zerotracer EV Is a Wild Ride
We&#8217;re jealous of the folks who get to drive the Zerotracer. It&#8217;s a sporty two-seat enclosed motorcycle that weighs less than 1,400 lbs, can do 0-100 km/hr (62 mph) in less than 4.5 seconds and has a top speed of 150 mph.

The first thing that comes [...]]]></description>
			<content:encoded><![CDATA[<p>Wired says the <a href="http://www.wired.com/autopia/2010/09/oerlikon-solar-zerotracer/">Two-Wheeled Zerotracer EV Is a Wild Ride</a></p>
<blockquote><p>We&#8217;re jealous of the folks who get to drive the Zerotracer. It&#8217;s a sporty two-seat enclosed motorcycle that weighs less than 1,400 lbs, can do 0-100 km/hr (62 mph) in less than 4.5 seconds and has a top speed of 150 mph.</p></blockquote>
<p><img src="http://www.wired.com/images_blogs/autopia/2010/09/Oerlikon-Solar-Zerotracer-01.jpg" width="330" height="242" /></p>
<p>The first thing that comes to mind, if I remember correctly, is that this looks to be a very close copy of a vehicle in the 1991 movie &#8220;Until the End of the World&#8221; by Wim Wenders. Rent the movie and see how the landing wheels work; to be fair the concept was developed by a pilot and Wenders seemed to just throw it as a credibility prop.</p>
<p>The movie also had some amusing concepts of Internet search engines and computer navigation in cars. The search engine, for example, had a big Russian bear mascot that would say &#8220;I&#8217;m searching, I&#8217;m searching&#8221; while it generated results.</p>
<p>My first work with GPS navigation was in 1994, about the same time I saw the movie. It seemed back then uncanny how accurate Wenders was in his vision. The Wired article suggests to me it might be time to see it again and see what else was predicted or may still come true.</p>
<p><img src="http://davi.poetry.org/blog/wp-content/uploads/2010/09/until-the-end-of-the-world-cover-3.jpg" /></p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-enjoy">
<ul class="socials">
		<li class="shr-mail">
			<a href="mailto:?subject=%22Two%20Wheel%20EV%20Recumbant%3A%20Zerotracer%22&amp;body=Link: http://www.flyingpenguin.com/?p=6803 (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Wired%20says%20the%20Two-Wheeled%20Zerotracer%20EV%20Is%20a%20Wild%20Ride%0A%0AWe%27re%20jealous%20of%20the%20folks%20who%20get%20to%20drive%20the%20Zerotracer.%20It%27s%20a%20sporty%20two-seat%20enclosed%20motorcycle%20that%20weighs%20less%20than%201%2C400%20lbs%2C%20can%20do%200-100%20km%2Fhr%20%2862%20mph%29%20in%20less%20than%204.5%20seconds%20and%20has%20a%20top%20speed%20of%20150%20mph.%0A%0A%0A%0AThe%20first%20thing%20tha" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.flyingpenguin.com/?p=6803&amp;feed=comments-rss2" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.flyingpenguin.com/?p=6803&amp;title=Two+Wheel+EV+Recumbant%3A+Zerotracer" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Two+Wheel+EV+Recumbant%3A+Zerotracer+-+http://b2l.me/anz5ek&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.flyingpenguin.com/?p=6803&amp;t=Two+Wheel+EV+Recumbant%3A+Zerotracer" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.flyingpenguin.com/?p=6803" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.flyingpenguin.com/?p=6803&amp;title=Two+Wheel+EV+Recumbant%3A+Zerotracer" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.flyingpenguin.com/?p=6803&amp;title=Two+Wheel+EV+Recumbant%3A+Zerotracer" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.flyingpenguin.com/?p=6803&amp;title=Two+Wheel+EV+Recumbant%3A+Zerotracer" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<img src="http://feeds.feedburner.com/~r/flyingpenguin/~4/fCQ9T4PYhmA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.flyingpenguin.com/?feed=rss2&amp;p=6803</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.flyingpenguin.com/?p=6803</feedburner:origLink></item>
		<item>
		<title>Credit Bureau Compliance with EI3PA</title>
		<link>http://feedproxy.google.com/~r/flyingpenguin/~3/2TkZZUcePCo/</link>
		<comments>http://www.flyingpenguin.com/?p=6800#comments</comments>
		<pubDate>Wed, 01 Sep 2010 07:30:29 +0000</pubDate>
		<dc:creator>Davi Ottenheimer</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.flyingpenguin.com/?p=6800</guid>
		<description><![CDATA[The Credit Bureaus are moving towards a new standard to protect personal identity information in credit reports. 
Experian has adapted the PCI-DSS and renamed it Experian Independent Third Party Assessment (EI3PA). Trans Union and Equifax are expected to follow suit. 
The EI3PA is an annual assessment of a reseller&#8217;s ability to protect the Experian-provided personal [...]]]></description>
			<content:encoded><![CDATA[<p>The Credit Bureaus are moving towards a new standard to protect personal identity information in credit reports. </p>
<p>Experian has adapted the PCI-DSS and renamed it Experian Independent Third Party Assessment (EI3PA). Trans Union and Equifax are expected to follow suit. </p>
<p>The EI3PA is an annual assessment of a reseller&#8217;s ability to protect the Experian-provided personal sensitive information. It also has quarterly scans for network vulnerabilities. Although similar to the PCI DSS, and QSAs will be doing the assessments, approval comes from Experian only, not from a card issuer or issuing bank.</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-enjoy">
<ul class="socials">
		<li class="shr-mail">
			<a href="mailto:?subject=%22Credit%20Bureau%20Compliance%20with%20EI3PA%22&amp;body=Link: http://www.flyingpenguin.com/?p=6800 (sent via shareaholic)%0D%0A%0D%0A----%0D%0A The%20Credit%20Bureaus%20are%20moving%20towards%20a%20new%20standard%20to%20protect%20personal%20identity%20information%20in%20credit%20reports.%20%0A%0AExperian%20has%20adapted%20the%20PCI-DSS%20and%20renamed%20it%20Experian%20Independent%20Third%20Party%20Assessment%20%28EI3PA%29.%20Trans%20Union%20and%20Equifax%20are%20expected%20to%20follow%20suit.%20%0A%0AThe%20EI3PA%20is%20an%20annual%20assess" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.flyingpenguin.com/?p=6800&amp;feed=comments-rss2" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.flyingpenguin.com/?p=6800&amp;title=Credit+Bureau+Compliance+with+EI3PA" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Credit+Bureau+Compliance+with+EI3PA+-+http://b2l.me/ank76j&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.flyingpenguin.com/?p=6800&amp;t=Credit+Bureau+Compliance+with+EI3PA" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.flyingpenguin.com/?p=6800" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.flyingpenguin.com/?p=6800&amp;title=Credit+Bureau+Compliance+with+EI3PA" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.flyingpenguin.com/?p=6800&amp;title=Credit+Bureau+Compliance+with+EI3PA" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.flyingpenguin.com/?p=6800&amp;title=Credit+Bureau+Compliance+with+EI3PA" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<img src="http://feeds.feedburner.com/~r/flyingpenguin/~4/2TkZZUcePCo" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.flyingpenguin.com/?feed=rss2&amp;p=6800</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.flyingpenguin.com/?p=6800</feedburner:origLink></item>
		<item>
		<title>“Give Me 3″ passing rule in CA</title>
		<link>http://feedproxy.google.com/~r/flyingpenguin/~3/m0UoxN8vSRQ/</link>
		<comments>http://www.flyingpenguin.com/?p=6798#comments</comments>
		<pubDate>Tue, 31 Aug 2010 17:53:48 +0000</pubDate>
		<dc:creator>Davi Ottenheimer</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.flyingpenguin.com/?p=6798</guid>
		<description><![CDATA[LA Mayor Villaraigosa has unveiled a &#8220;Give Me 3&#8243; Bike Safety Poster
The Mayor also announced that he would like to &#8220;make the 3 Foot Passing Rule a 3 Foot Passing Law&#8221; in California. He will be introducing the bill, going to Sacramento and working with the bicycling community to ensure that this becomes a reality. [...]]]></description>
			<content:encoded><![CDATA[<p>LA Mayor Villaraigosa has unveiled a <a href="http://lacbc.wordpress.com/2010/08/24/give-me-3-bike-safety-posters-unveiled-by-mayor-villaraigosa/">&#8220;Give Me 3&#8243; Bike Safety Poster</a></p>
<blockquote><p>The Mayor also announced that he would like to &#8220;make the 3 Foot Passing Rule a 3 Foot Passing Law&#8221; in California. He will be introducing the bill, going to Sacramento and working with the bicycling community to ensure that this becomes a reality. &#8220;We&#8217;ll keep at it until it becomes part of the California Vehicle Code.&#8221;</p></blockquote>
<p>LA has to be one of the most bike unfriendly cities anywhere. When I lived there many years ago it was common for bike lanes to end abruptly at the intersection with eight lanes of freeway, and no way to get across. Apparently the very first <a href="http://la.streetsblog.org/2010/08/17/helmets-ready-mayor-hosts-first-bike-summit/">LA Bicycle Summit</a> was just held this year. Excellent to see them take (three?) steps to at least make bicycling safer.</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-enjoy">
<ul class="socials">
		<li class="shr-mail">
			<a href="mailto:?subject=%22%22Give%20Me%203%22%20passing%20rule%20in%20CA%22&amp;body=Link: http://www.flyingpenguin.com/?p=6798 (sent via shareaholic)%0D%0A%0D%0A----%0D%0A LA%20Mayor%20Villaraigosa%20has%20unveiled%20a%20%22Give%20Me%203%22%20Bike%20Safety%20Poster%0A%0AThe%20Mayor%20also%20announced%20that%20he%20would%20like%20to%20%22make%20the%203%20Foot%20Passing%20Rule%20a%203%20Foot%20Passing%20Law%22%20in%20California.%20He%20will%20be%20introducing%20the%20bill%2C%20going%20to%20Sacramento%20and%20working%20with%20the%20bicycling%20community%20to%20ensure%20that%20this%20bec" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.flyingpenguin.com/?p=6798&amp;feed=comments-rss2" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.flyingpenguin.com/?p=6798&amp;title=%22Give+Me+3%22+passing+rule+in+CA" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=%22Give+Me+3%22+passing+rule+in+CA+-+http://b2l.me/anfxgp&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.flyingpenguin.com/?p=6798&amp;t=%22Give+Me+3%22+passing+rule+in+CA" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.flyingpenguin.com/?p=6798" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.flyingpenguin.com/?p=6798&amp;title=%22Give+Me+3%22+passing+rule+in+CA" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.flyingpenguin.com/?p=6798&amp;title=%22Give+Me+3%22+passing+rule+in+CA" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.flyingpenguin.com/?p=6798&amp;title=%22Give+Me+3%22+passing+rule+in+CA" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<img src="http://feeds.feedburner.com/~r/flyingpenguin/~4/m0UoxN8vSRQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.flyingpenguin.com/?feed=rss2&amp;p=6798</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.flyingpenguin.com/?p=6798</feedburner:origLink></item>
		<item>
		<title>SmartMeters Run Into Santa Cruz Resistance</title>
		<link>http://feedproxy.google.com/~r/flyingpenguin/~3/V9JByO9hGEY/</link>
		<comments>http://www.flyingpenguin.com/?p=6788#comments</comments>
		<pubDate>Tue, 31 Aug 2010 07:00:06 +0000</pubDate>
		<dc:creator>Davi Ottenheimer</dc:creator>
				<category><![CDATA[Energy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.flyingpenguin.com/?p=6788</guid>
		<description><![CDATA[The Indybay says Protesters Halt Smart Meter Installation in Santa Cruz County
Heidi Bazzano, one of the protesters at 38th and Portola this morning, said, &#8220;there are so many problems with &#8217;smart&#8217; meters. PG&#38;E, the government, and any hacker worth his salt will know when you wake up, what appliances you use, when you go on [...]]]></description>
			<content:encoded><![CDATA[<p>The Indybay says <a href="http://www.indybay.org/newsitems/2010/08/26/18656872.php">Protesters Halt Smart Meter Installation in Santa Cruz County</a></p>
<blockquote><p>Heidi Bazzano, one of the protesters at 38th and Portola this morning, said, &#8220;there are so many problems with &#8217;smart&#8217; meters. PG&amp;E, the government, and any hacker worth his salt will know when you wake up, what appliances you use, when you go on vacation. The meters overcharge people, increase carbon emissions, expose us to EMF which is a confirmed carcinogen, and worst of all, we&#8217;re paying for them through hikes in our electric rates!&#8221;</p></blockquote>
<p>&#8220;One of the protesters&#8221; is not exactly a qualified opinion. And their description of a hacker sounds a lot like the bogeyman or Santa Claus rather than a real threat. Watch out, he knows when you have been bad or good&#8230;this makes the protester sound uninformed. Confirmed carcinogen? Confirmed where? </p>
<blockquote><p>Those who are electrically sensitive have reported that the intense bursts of radiation from &#8217;smart&#8217; meters are amongst the worst they have ever experienced. People throughout the state have been reporting headaches, nausea, dizziness, sleep disruption and other health impacts after smart meters are installed. PG&amp;E has declined to remove the new meters even though they are causing adverse health impacts, leading some local residents to flee the state and stay with relatives. Some have even been forced into homelessness, living in their cars with the hope that their smart meter will be removed.</p></blockquote>
<p>The health risks still all sound theoretical. Some might correlate smart meters to general health issues but where are the audits, studies or tests that prove causation? A placebo test or control group study would be interesting. I can understand an opposition to meters after billing mistakes are caught by auditors. This problem was <a href="http://www.zdnet.co.uk/news/systems-management/2010/05/11/smart-meter-flaws-led-to-inaccurate-billing-40088905/">documented and proven</a>. I do not understand the vague health argument.</p>
<p>Indybay does not offer insights. They link instead to <a href="http://stopsmartmeters.wordpress.com/">StopSmartMeters</a>, which gives only more vague references, laced with heavy-handed sarcasm.</p>
<blockquote><p>PG&amp;ESE:  &#8220;A SmartMeter device transmits relatively weak radio signals, resembling those of many other devices we use every day, like cell phones and baby monitors. A major radio station, by contrast, usually transmits with 50,000 times as much power.&#8221;</p>
<p>English Translation:  &#8220;A DumbMeter device transmits relatively weak radio signals compared with your microwave oven (which we initially asked the FCC for permission to install but we realized that humans who are cooked like hot dogs have trouble authorizing a debit account).  We&#8217;ll conveniently neglect to mention that cell phone and baby monitor wireless technologies have been implicated in brain tumors and other nasty lethal ailments, trusting that the public&#8217;s ignorance of wireless impacts will hold out long enough for us to finish installation.&#8221;</p></blockquote>
<p>First, this is a counter-point to the entire argument. It says the SmartMeter company is motivated to do no harm because they need consumers to be healthy enough to pay bills. That could be the end of their protest right there.</p>
<p>Second, the style reads to me like a story from The Onion. I might think the site is a hoax except for links to real news stories about <a href="http://www.santacruzsentinel.com/business/ci_15886141">City Councils considering whether to block installation</a>. </p>
<p>Are Councils and local government driven by fear more than any evidence of risk? An <a href="http://articles.sfgate.com/2010-08-24/business/22232109_1_smart-meter-electricity-and-gas-meters-pg-e">article in SFGate</a> says this is very likely. </p>
<blockquote><p>Of all the complaints filed with PG&amp;E, 16 percent came from customers who did not yet have a smart meter, Burt said. In other words, they couldn&#8217;t be reacting to a mechanical problem with the meter.</p>
<p>Another bit of evidence suggests that fears rather than malfunctions drive at least some of the complaints. The Sacramento Municipal Utility District gets more customer complaints about its own smart meters following newspaper or television stories about PG&amp;E&#8217;s meters. That includes stories about the meters&#8217; accuracy as well as complaints that the wireless devices could pose a health risk &#8211; an idea that PG&amp;E strenuously rejects.</p>
<p>&#8220;Whenever we see a spike in stories about PG&amp;E&#8217;s smart meters, we see a spike in complaints,&#8221; said SMUD spokesman Chris Capra. </p></blockquote>
<p>What happens when there is a spike in stories about stories about PG&amp;E smart meters?</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-enjoy">
<ul class="socials">
		<li class="shr-mail">
			<a href="mailto:?subject=%22SmartMeters%20Run%20Into%20Santa%20Cruz%20Resistance%22&amp;body=Link: http://www.flyingpenguin.com/?p=6788 (sent via shareaholic)%0D%0A%0D%0A----%0D%0A The%20Indybay%20says%20Protesters%20Halt%20Smart%20Meter%20Installation%20in%20Santa%20Cruz%20County%0D%0A%0D%0AHeidi%20Bazzano%2C%20one%20of%20the%20protesters%20at%2038th%20and%20Portola%20this%20morning%2C%20said%2C%20%22there%20are%20so%20many%20problems%20with%20%27smart%27%20meters.%20PG%26amp%3BE%2C%20the%20government%2C%20and%20any%20hacker%20worth%20his%20salt%20will%20know%20when%20you%20wake%20up%2C%20what%20app" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.flyingpenguin.com/?p=6788&amp;feed=comments-rss2" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.flyingpenguin.com/?p=6788&amp;title=SmartMeters+Run+Into+Santa+Cruz+Resistance" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=SmartMeters+Run+Into+Santa+Cruz+Resistance+-+http://b2l.me/anb7yv&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.flyingpenguin.com/?p=6788&amp;t=SmartMeters+Run+Into+Santa+Cruz+Resistance" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.flyingpenguin.com/?p=6788" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.flyingpenguin.com/?p=6788&amp;title=SmartMeters+Run+Into+Santa+Cruz+Resistance" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.flyingpenguin.com/?p=6788&amp;title=SmartMeters+Run+Into+Santa+Cruz+Resistance" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.flyingpenguin.com/?p=6788&amp;title=SmartMeters+Run+Into+Santa+Cruz+Resistance" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<img src="http://feeds.feedburner.com/~r/flyingpenguin/~4/V9JByO9hGEY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.flyingpenguin.com/?feed=rss2&amp;p=6788</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.flyingpenguin.com/?p=6788</feedburner:origLink></item>
		<item>
		<title>Google Blames Vulnerability Report Error on Compilers</title>
		<link>http://feedproxy.google.com/~r/flyingpenguin/~3/l9ELH1vti8A/</link>
		<comments>http://www.flyingpenguin.com/?p=6784#comments</comments>
		<pubDate>Tue, 31 Aug 2010 00:18:48 +0000</pubDate>
		<dc:creator>Davi Ottenheimer</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.flyingpenguin.com/?p=6784</guid>
		<description><![CDATA[The Google Online Security Blog has posted an interesting update in response to an IBM 2010 Risk Report. 
&#8230;we were confused by a claim that 33% of critical and high-risk bugs uncovered in our services in the first half of 2010 were left unpatched. We learned after investigating that the 33% figure referred to a [...]]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://googleonlinesecurity.blogspot.com/2010/08/vulnerability-trends-how-are-companies.html">Google Online Security Blog</a> has posted an interesting update in response to an IBM 2010 Risk Report. </p>
<blockquote><p>&#8230;we were confused by a claim that 33% of critical and high-risk bugs uncovered in our services in the first half of 2010 were left unpatched. We learned after investigating that the 33% figure referred to a single unpatched vulnerability out of a total of three &#8212; and importantly, the one item that was considered unpatched was only mistakenly considered a security vulnerability due to a terminology mix-up. As a result, the true unpatched rate for these high-risk bugs is 0 out of 2, or 0%.</p></blockquote>
<p>IBM has an <a href="http://blogs.iss.net/archive/midyear2010chartupda.html">updated chart now</a>. Although one can see how Google might take such a sensitive and defensive position when confronted with vulnerability data, their analysis comes across as shockingly one-sided. </p>
<p>They first highlight four &#8220;factors working against [vulnerability databases]&#8220;. All have a clear tone of &#8220;don&#8217;t trust those databases&#8221; but only one says the vendors have an important role &#8212; disclosure in consistent formats. The finger-pointing then goes a step further with two suggestions:</p>
<blockquote><p>To make these databases more useful for the industry and less likely to spread misinformation, we feel there must be more frequent collaboration between vendors and compilers. As a first step, database compilers should reach out to vendors they plan to cover in order to devise a sustainable solution for both parties that will allow for a more consistent flow of information. Another big improvement would be increased transparency on the part of the compilers &#8212; for example, the inclusion of more hard data, the methodology behind the data gathering, and caveat language acknowledging the limitations of the presented data.</p></blockquote>
<p>I think calling the report misinformation is a bit harsh. Their post only says databases are not to be trusted because the &#8220;compilers&#8221; do not reach out and are not transparent enough. That should be a two-way commentary. There is no need to place all blame on database researchers and none on vendors like Google. Google could publish more patch information and transparency with regard to its recorded vulnerabilities. They could lead by example, of course, and fix their their <a href="?p=6361">security communication and management issues, especially around consistency</a>. That might be the third, but most important, step to make these databases more useful.</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-enjoy">
<ul class="socials">
		<li class="shr-mail">
			<a href="mailto:?subject=%22Google%20Blames%20Vulnerability%20Report%20Error%20on%20Compilers%22&amp;body=Link: http://www.flyingpenguin.com/?p=6784 (sent via shareaholic)%0D%0A%0D%0A----%0D%0A The%20Google%20Online%20Security%20Blog%20has%20posted%20an%20interesting%20update%20in%20response%20to%20an%20IBM%202010%20Risk%20Report.%20%0A%20%0A...we%20were%20confused%20by%20a%20claim%20that%2033%25%20of%20critical%20and%20high-risk%20bugs%20uncovered%20in%20our%20services%20in%20the%20first%20half%20of%202010%20were%20left%20unpatched.%20We%20learned%20after%20investigating%20that%20the%2033%25%20figu" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.flyingpenguin.com/?p=6784&amp;feed=comments-rss2" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.flyingpenguin.com/?p=6784&amp;title=Google+Blames+Vulnerability+Report+Error+on+Compilers" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Google+Blames+Vulnerability+Report+Error+on+Compilers+-+http://b2l.me/am993t&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.flyingpenguin.com/?p=6784&amp;t=Google+Blames+Vulnerability+Report+Error+on+Compilers" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.flyingpenguin.com/?p=6784" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.flyingpenguin.com/?p=6784&amp;title=Google+Blames+Vulnerability+Report+Error+on+Compilers" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.flyingpenguin.com/?p=6784&amp;title=Google+Blames+Vulnerability+Report+Error+on+Compilers" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.flyingpenguin.com/?p=6784&amp;title=Google+Blames+Vulnerability+Report+Error+on+Compilers" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<img src="http://feeds.feedburner.com/~r/flyingpenguin/~4/l9ELH1vti8A" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.flyingpenguin.com/?feed=rss2&amp;p=6784</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.flyingpenguin.com/?p=6784</feedburner:origLink></item>
		<item>
		<title>Social Networks Fool InfoSec Pros</title>
		<link>http://feedproxy.google.com/~r/flyingpenguin/~3/FPxto78ab5o/</link>
		<comments>http://www.flyingpenguin.com/?p=6774#comments</comments>
		<pubDate>Fri, 27 Aug 2010 17:11:00 +0000</pubDate>
		<dc:creator>Davi Ottenheimer</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.flyingpenguin.com/?p=6774</guid>
		<description><![CDATA[BitDefender says they have a survey that shows over 30% of users who accepted a friendship with a bogus profile are in the IT Security industry. 
Although it would be cool to jump into this statistic, I do not see any analysis or data on the users that proves they were not faking their own [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://news.bitdefender.com/NW1700-en--BitDefender-Finds-IT-Security-Employees-Likely-to-Disclose-Sensitive-Information-on-Social-Networks.html">BitDefender says they have a survey</a> that shows over 30% of users who accepted a friendship with a bogus profile are in the IT Security industry. </p>
<p>Although it would be cool to jump into this statistic, I do not see any analysis or data on the users that proves they were not faking their own profile. </p>
<p><img src="http://www.barcelonafootballblog.com/wp-content/uploads/2009/09/spy-vs-spy.png" /></p>
<p>Turnabout is fair play, no? How much of this information that BitDefender collected is real?</p>
<blockquote><p>The study sample group included 2,000 users from all over the world registered on one of the most popular social networks. These users were randomly chosen in order to cover different aspects: sex (1,000 females, 1,000 males), age (the sample ranged from 17 to 65 years with a mean age of 27.3 years), professional affiliation, interests etc. In the first step, the users were only requested to add the unknown test profile as their friend, while in the second step several conversations with randomly selected users aimed to determine what kind of details they would disclose.</p></blockquote>
<p>Ironic that they would assume it can be trusted. Or did they verify? The <a href="http://www.bitdefender.com/files/News/file/Social_Networking_and_the_Illusion_of_Anonimity_BT.pdf">complete 400K report</a> does not give any verification of the survey group, so maybe we can assume they also could have been duped while they were trying to dupe others. The closest thing I found was this note:</p>
<blockquote><p>These outcomes were tested against the motivation of IT security industry users to become friends with the blonde girl, in order to ensure that they didn&#8217;t accept the friendship request just to have &#8220;study material&#8221; for their own research.</p></blockquote>
<p>That means they asked the person they were trying to befriend for their motivation; 53% said &#8220;a lovely face&#8221; was their reason to accept the girl. Was this a game response or sincere? I don&#8217;t see it as validation.</p>
<blockquote><p>The experiment revealed that the most vulnerable users appeared to be those that worked in the IT industry: after a half an hour conversation, 10% of them disclosed to &#8220;the blonde face&#8221; personal sensitive information such as: address, phone number, mother&#8217;s and father&#8217;s name, etc &#8212; information usually used in recovery passwords questions. In addition to that, after a 2 hour conversation, 73% revealed what appears to be confidential information from their work place, such as future strategies, plans, and unreleased technologies/software.</p></blockquote>
<p>Two hour conversation with a fake profile. That&#8217;s impressive but I still would like to see validation results. I mean what percentage of those claiming to work in IT were proven/verified to actually work in IT. Did they divulge real or fake information? When a study begins with a premise that you can easily fool people online, it would seem logical to then proceed with caution and not believe everything a new contact might say.</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-enjoy">
<ul class="socials">
		<li class="shr-mail">
			<a href="mailto:?subject=%22Social%20Networks%20Fool%20InfoSec%20Pros%22&amp;body=Link: http://www.flyingpenguin.com/?p=6774 (sent via shareaholic)%0D%0A%0D%0A----%0D%0A BitDefender%20says%20they%20have%20a%20survey%20that%20shows%20over%2030%25%20of%20users%20who%20accepted%20a%20friendship%20with%20a%20bogus%20profile%20are%20in%20the%20IT%20Security%20industry.%20%0A%0AAlthough%20it%20would%20be%20cool%20to%20jump%20into%20this%20statistic%2C%20I%20do%20not%20see%20any%20analysis%20or%20data%20on%20the%20users%20that%20proves%20they%20were%20not%20faking%20their%20own%20profile." rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.flyingpenguin.com/?p=6774&amp;feed=comments-rss2" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.flyingpenguin.com/?p=6774&amp;title=Social+Networks+Fool+InfoSec+Pros" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Social+Networks+Fool+InfoSec+Pros+-+http://b2l.me/amgayj&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.flyingpenguin.com/?p=6774&amp;t=Social+Networks+Fool+InfoSec+Pros" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.flyingpenguin.com/?p=6774" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.flyingpenguin.com/?p=6774&amp;title=Social+Networks+Fool+InfoSec+Pros" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.flyingpenguin.com/?p=6774&amp;title=Social+Networks+Fool+InfoSec+Pros" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.flyingpenguin.com/?p=6774&amp;title=Social+Networks+Fool+InfoSec+Pros" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<img src="http://feeds.feedburner.com/~r/flyingpenguin/~4/FPxto78ab5o" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.flyingpenguin.com/?feed=rss2&amp;p=6774</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.flyingpenguin.com/?p=6774</feedburner:origLink></item>
		<item>
		<title>PCI Level 1 Compliance Deadline Coming</title>
		<link>http://feedproxy.google.com/~r/flyingpenguin/~3/nLnOnFVzbeQ/</link>
		<comments>http://www.flyingpenguin.com/?p=6772#comments</comments>
		<pubDate>Thu, 26 Aug 2010 20:34:28 +0000</pubDate>
		<dc:creator>Davi Ottenheimer</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.flyingpenguin.com/?p=6772</guid>
		<description><![CDATA[Quick reminder to acquirers &#8212; just one month remains until the deadline.
Visa warned in 2008 that to avoid &#8220;appropriate risk controls, up to and including fines&#8221; you must provide them a PCI DSS Attestation of Compliance for all Level 1 merchants by the end of September 2010.




		
			Email this to a friend?
		
		
			Subscribe to the comments for [...]]]></description>
			<content:encoded><![CDATA[<p>Quick reminder to acquirers &#8212; just one month remains until the deadline.</p>
<p><a href="http://usa.visa.com/download/merchants/cisp-bulletin-visa-pci-dss-framework-111808.pdf">Visa warned in 2008</a> that to avoid &#8220;appropriate risk controls, up to and including fines&#8221; you must provide them a PCI DSS Attestation of Compliance for all Level 1 merchants by the end of September 2010.</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-enjoy">
<ul class="socials">
		<li class="shr-mail">
			<a href="mailto:?subject=%22PCI%20Level%201%20Compliance%20Deadline%20Coming%22&amp;body=Link: http://www.flyingpenguin.com/?p=6772 (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Quick%20reminder%20to%20acquirers%20--%20just%20one%20month%20remains%20until%20the%20deadline.%0D%0A%0D%0AVisa%20warned%20in%202008%20that%20to%20avoid%20%22appropriate%20risk%20controls%2C%20up%20to%20and%20including%20fines%22%20you%20must%20provide%20them%20a%20PCI%20DSS%20Attestation%20of%20Compliance%20for%20all%20Level%201%20merchants%20by%20the%20end%20of%20September%202010." rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.flyingpenguin.com/?p=6772&amp;feed=comments-rss2" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.flyingpenguin.com/?p=6772&amp;title=PCI+Level+1+Compliance+Deadline+Coming" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=PCI+Level+1+Compliance+Deadline+Coming+-+http://b2l.me/ak9kkx&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.flyingpenguin.com/?p=6772&amp;t=PCI+Level+1+Compliance+Deadline+Coming" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.flyingpenguin.com/?p=6772" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.flyingpenguin.com/?p=6772&amp;title=PCI+Level+1+Compliance+Deadline+Coming" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.flyingpenguin.com/?p=6772&amp;title=PCI+Level+1+Compliance+Deadline+Coming" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.flyingpenguin.com/?p=6772&amp;title=PCI+Level+1+Compliance+Deadline+Coming" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<img src="http://feeds.feedburner.com/~r/flyingpenguin/~4/nLnOnFVzbeQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.flyingpenguin.com/?feed=rss2&amp;p=6772</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.flyingpenguin.com/?p=6772</feedburner:origLink></item>
		<item>
		<title>Cracking Encrypted HDDs</title>
		<link>http://feedproxy.google.com/~r/flyingpenguin/~3/AbqY6E7P2vs/</link>
		<comments>http://www.flyingpenguin.com/?p=6770#comments</comments>
		<pubDate>Thu, 26 Aug 2010 19:40:30 +0000</pubDate>
		<dc:creator>Davi Ottenheimer</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.flyingpenguin.com/?p=6770</guid>
		<description><![CDATA[Sprites mods has a very nice in-depth hardware security review of the Disk Genie hard drive. The first problem seems to be how easily the device is opened. The next failure comes from how it indicates failures to the attacker. Spoiler alert: here are the conclusions.
If you&#8217;re just a generic Joe Blow who wants to [...]]]></description>
			<content:encoded><![CDATA[<p>Sprites mods has a <a href="http://spritesmods.com/?art=diskgenie&amp;page=8">very nice in-depth hardware security review</a> of the Disk Genie hard drive. The first problem seems to be how easily the device is opened. The next failure comes from how it indicates failures to the attacker. Spoiler alert: here are the conclusions.</p>
<blockquote><p>If you&#8217;re just a generic Joe Blow who wants to make sure your private  pictures don&#8217;t get viewed by your collegues or kids, you&#8217;re golden. The fact that the there&#8217;s no way a software-only attack can get the pincode means that some hardware-experience is needed to start hacking the device, and that will deter casual onlookers enough to make the device completely safe for curious neighbours or collegues, even if they are smart enough to, for example, install a keylogger on your PC.</p>
<p>If you&#8217;re a business-person with actual info to hide, info that could  financially benefit other parties&#8230; you can still use this, but make sure to pick a strong pincode. More than 11 digits should do, depending on how  badly others want the data.</p>
<p>If you&#8217;re, say, the president of a nuclear country and want to use this to carry around the launch codes of your nukes, I wouldn&#8217;t recommend this device. While the thing is safe for a casual hacker like me, someone with  money or the resources to de-cap chips can probably get to the data fairly  easy: the PIC which contains the keys to the HD is not a secure device and when decapped under a microscope in a laboratory can probably be made to give up that key fairly easily.</p></blockquote>
<p>Is that a qualified hint to the Pentagon or just an example?</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-enjoy">
<ul class="socials">
		<li class="shr-mail">
			<a href="mailto:?subject=%22Cracking%20Encrypted%20HDDs%22&amp;body=Link: http://www.flyingpenguin.com/?p=6770 (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Sprites%20mods%20has%20a%20very%20nice%20in-depth%20hardware%20security%20review%20of%20the%20Disk%20Genie%20hard%20drive.%20The%20first%20problem%20seems%20to%20be%20how%20easily%20the%20device%20is%20opened.%20The%20next%20failure%20comes%20from%20how%20it%20indicates%20failures%20to%20the%20attacker.%20Spoiler%20alert%3A%20here%20are%20the%20conclusions.%0D%0A%0D%0AIf%20you%27re%20just%20a%20generic%20Joe%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.flyingpenguin.com/?p=6770&amp;feed=comments-rss2" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.flyingpenguin.com/?p=6770&amp;title=Cracking+Encrypted+HDDs" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Cracking+Encrypted+HDDs+-+http://b2l.me/ak89y4&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.flyingpenguin.com/?p=6770&amp;t=Cracking+Encrypted+HDDs" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.flyingpenguin.com/?p=6770" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.flyingpenguin.com/?p=6770&amp;title=Cracking+Encrypted+HDDs" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.flyingpenguin.com/?p=6770&amp;title=Cracking+Encrypted+HDDs" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.flyingpenguin.com/?p=6770&amp;title=Cracking+Encrypted+HDDs" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<img src="http://feeds.feedburner.com/~r/flyingpenguin/~4/AbqY6E7P2vs" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.flyingpenguin.com/?feed=rss2&amp;p=6770</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.flyingpenguin.com/?p=6770</feedburner:origLink></item>
		<item>
		<title>Auditors catch E-waste fraud in CA</title>
		<link>http://feedproxy.google.com/~r/flyingpenguin/~3/dKvJJYULQKM/</link>
		<comments>http://www.flyingpenguin.com/?p=6766#comments</comments>
		<pubDate>Thu, 26 Aug 2010 17:14:49 +0000</pubDate>
		<dc:creator>Davi Ottenheimer</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.flyingpenguin.com/?p=6766</guid>
		<description><![CDATA[The California Attorney Jerry Brown has filed charges against e-waste recycler&#8217;s execs
In late 2008, CalRecycle auditors contacted investigators at the California Department of Toxic Substances Control after noticing discrepancies in the claims submitted by Tung Tai and the records kept by Golden State Records and Recycling, a company that collected and transferred materials to Tung [...]]]></description>
			<content:encoded><![CDATA[<p>The California Attorney Jerry Brown has filed <a href="http://www.computerworld.com/s/article/9182060/California_files_charges_against_e_waste_recycler_s_execs?source=rss_news">charges against e-waste recycler&#8217;s execs</a></p>
<blockquote><p>In late 2008, CalRecycle auditors contacted investigators at the California Department of Toxic Substances Control after noticing discrepancies in the claims submitted by Tung Tai and the records kept by Golden State Records and Recycling, a company that collected and transferred materials to Tung Tai, Brown said in the release.</p>
<p>In July 2009, state agents searched the Tung Tai facility and discovered two separate sets of records, Brown said. Those records showed that Tung Tai had significantly inflated the pounds of recycled material it submitted for reimbursement to CalRecycle between January and September 2008, Brown&#8217;s office said.</p></blockquote>
<p>Two separate sets of records? That is pretty bold.</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-enjoy">
<ul class="socials">
		<li class="shr-mail">
			<a href="mailto:?subject=%22Auditors%20catch%20E-waste%20fraud%20in%20CA%22&amp;body=Link: http://www.flyingpenguin.com/?p=6766 (sent via shareaholic)%0D%0A%0D%0A----%0D%0A The%20California%20Attorney%20Jerry%20Brown%20has%20filed%20charges%20against%20e-waste%20recycler%27s%20execs%0D%0A%0D%0AIn%20late%202008%2C%20CalRecycle%20auditors%20contacted%20investigators%20at%20the%20California%20Department%20of%20Toxic%20Substances%20Control%20after%20noticing%20discrepancies%20in%20the%20claims%20submitted%20by%20Tung%20Tai%20and%20the%20records%20kept%20by%20Golden" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.flyingpenguin.com/?p=6766&amp;feed=comments-rss2" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.flyingpenguin.com/?p=6766&amp;title=Auditors+catch+E-waste+fraud+in+CA" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Auditors+catch+E-waste+fraud+in+CA+-+http://b2l.me/ak8bv7&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.flyingpenguin.com/?p=6766&amp;t=Auditors+catch+E-waste+fraud+in+CA" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.flyingpenguin.com/?p=6766" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.flyingpenguin.com/?p=6766&amp;title=Auditors+catch+E-waste+fraud+in+CA" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.flyingpenguin.com/?p=6766&amp;title=Auditors+catch+E-waste+fraud+in+CA" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.flyingpenguin.com/?p=6766&amp;title=Auditors+catch+E-waste+fraud+in+CA" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<img src="http://feeds.feedburner.com/~r/flyingpenguin/~4/dKvJJYULQKM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.flyingpenguin.com/?feed=rss2&amp;p=6766</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.flyingpenguin.com/?p=6766</feedburner:origLink></item>
		<item>
		<title>Cathode Tube Watch – Design Process</title>
		<link>http://feedproxy.google.com/~r/flyingpenguin/~3/971ERadCNsg/</link>
		<comments>http://www.flyingpenguin.com/?p=6762#comments</comments>
		<pubDate>Thu, 26 Aug 2010 14:49:59 +0000</pubDate>
		<dc:creator>Davi Ottenheimer</dc:creator>
				<category><![CDATA[Energy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.flyingpenguin.com/?p=6762</guid>
		<description><![CDATA[The Cathode Corner site has a nice writeup of the design considerations for the Nixie Watch
As I pondered the perplexing problem of what to do with the back of the  watch, I decided to study the mechanical watches I had lying around. They  all seemed to have the same general design &#8211; a [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.cathodecorner.com/nixiewatch/nwrd-viewing-tn.jpg" alt="Nixie Watch" align=right />The Cathode Corner site has a nice writeup of the design considerations for the <a href="http://www.cathodecorner.com/nixiewatch/watchhist/watchhist4.html">Nixie Watch</a></p>
<blockquote><p>As I pondered the perplexing problem of what to do with the back of the  watch, I decided to study the mechanical watches I had lying around. They  all seemed to have the same general design &#8211; a big turning with the strap  lugs formed by punching out the material between them and from the sides  of the watch. I had to approach it a bit differently, since I had an  o-ring seal to get in the way of milling away material from the front. So  I had the material milled from the rear. But I used the idea of turning  the strap lugs, which is what gives it that watch-like look.</p></blockquote>
<p>Although they figured out how to seal the case and make it attractive, battery life is still far below the paltry one-year that was planned. Hello, solar? What is that other wrist for anyway? Ironically it has a sensor built-in to save battery life by only displaying the time when viewed from a certain angle. Why not also generate energy from movement? This becomes a great example of how dependent a system is on energy, yet how little engineering is spent on solving the problem of input versus aesthetics.</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-enjoy">
<ul class="socials">
		<li class="shr-mail">
			<a href="mailto:?subject=%22Cathode%20Tube%20Watch%20-%20Design%20Process%22&amp;body=Link: http://www.flyingpenguin.com/?p=6762 (sent via shareaholic)%0D%0A%0D%0A----%0D%0A The%20Cathode%20Corner%20site%20has%20a%20nice%20writeup%20of%20the%20design%20considerations%20for%20the%20Nixie%20Watch%0D%0AAs%20I%20pondered%20the%20perplexing%20problem%20of%20what%20to%20do%20with%20the%20back%20of%20the%20%20watch%2C%20I%20decided%20to%20study%20the%20mechanical%20watches%20I%20had%20lying%20around.%20They%20%20all%20seemed%20to%20have%20the%20same%20general%20design%20-%20a%20big%20turning%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.flyingpenguin.com/?p=6762&amp;feed=comments-rss2" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.flyingpenguin.com/?p=6762&amp;title=Cathode+Tube+Watch+-+Design+Process" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Cathode+Tube+Watch+-+Design+Process+-+http://b2l.me/ak7fjb&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.flyingpenguin.com/?p=6762&amp;t=Cathode+Tube+Watch+-+Design+Process" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.flyingpenguin.com/?p=6762" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.flyingpenguin.com/?p=6762&amp;title=Cathode+Tube+Watch+-+Design+Process" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.flyingpenguin.com/?p=6762&amp;title=Cathode+Tube+Watch+-+Design+Process" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.flyingpenguin.com/?p=6762&amp;title=Cathode+Tube+Watch+-+Design+Process" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<img src="http://feeds.feedburner.com/~r/flyingpenguin/~4/971ERadCNsg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.flyingpenguin.com/?feed=rss2&amp;p=6762</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.flyingpenguin.com/?p=6762</feedburner:origLink></item>
		<item>
		<title>Qualys scan changes forced by PCI Council</title>
		<link>http://feedproxy.google.com/~r/flyingpenguin/~3/H9LkcmPeTwg/</link>
		<comments>http://www.flyingpenguin.com/?p=6759#comments</comments>
		<pubDate>Thu, 26 Aug 2010 14:22:02 +0000</pubDate>
		<dc:creator>Davi Ottenheimer</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.flyingpenguin.com/?p=6759</guid>
		<description><![CDATA[Qualys has sent out a notice of change to how their QualysGuard provides reports for PCI
Within the QualysGuard Consultant interface,  you will still be able to run PCI specific scans using the PCI Option  Profile. You will also still be able to run PCI pass/fail reports;  however, these reports will now be [...]]]></description>
			<content:encoded><![CDATA[<p>Qualys has sent out a notice of change to how their QualysGuard provides reports for PCI</p>
<blockquote><p>Within the QualysGuard Consultant interface,  you will still be able to run PCI specific scans using the PCI Option  Profile. You will also still be able to run PCI pass/fail reports;  however, these reports will now be flagged as <strong><em>non-certified reports</em></strong> and cannot be submitted to your clients&rsquo; acquiring banks to pass PCI Compliance. </p>
</blockquote>
<p>Approved Scanning Vendors (ASV) using QualysGuard are not affected if they are already using the ASV Portal. The portal gives only a Pay Per Host license with unlimited external scans instead of the Pay Per Scan. Internal scans for requirement 11.2 have to be done with another tool or a different account. </p>
<p>Those who are not an ASV will no longer be able to own the scanning license and can not submit reports to the PCI council for certification on behalf of a client. </p>
<p>Qualys says the changes are related to the <a href="http://notifications.qualys.com/content/QWEB_PCI_8-31-2010">new PCI Council guidelines on ASV from last March</a>. The following differences will be seen after their new product launch next week, on August 31. </p>
<blockquote><p># Attestations: Customers are required to confirm on a quarterly basis that reports adhere to PCI DSS requirements for scoping, false positive documentation, and scan completeness.  ASVs must then review these submissions and provide their own attestation.  QualysGuard PCI will provide simple workflows to assist scan customers in providing and tracking the status these attestations.<br />
# Report Content Changes: The ASV Scan Report must use a new format that includes additional content, revised scoring terminology (High, Medium, and Low), and sections for attestations.  QualysGuard PCI reports will incorporate all required changes.<br />
# False Positives: Approved false positive requests must be resubmitted by the customer to the ASV for review on a quarterly basis.  QualysGuard PCI workflows will provide scan customers an easy-to-use interface for viewing and resubmitting false positives.<br />
# Scoring Changes:  As a result of clarifications concerning CVSS scoring, certain QIDs have changed their compliance posture and will now cause components to fail PCI certification.  The complete list of QIDs is detailed in the FAQ referenced below.</p></blockquote>
<p>Scoring changes can be found in an appendix of their FAQ. <a href="http://img.en25.com/Web/Qualys/PCI_FAQ_20100805-03.pdf?elq=00000000000000000000000000000000">A long list of exploits</a> (QID in Qualys terms) will now have CVSS v2 scores of 4.0 or higher. </p>
<p>Their most recent notice does not mention this but instead focuses on who is an ASV and the services provided &#8212; a company can not compete directly with an ASV just by using the same software and running the same reports. The PCI Council <a href="https://www.pcisecuritystandards.org/qsa_asv/become_asv.shtml">charges a fee to become an ASV</a> and be listed as an ASV. The change thus seems to have come from a combination of licensing issues and  <a href="https://www.pcisecuritystandards.org/pdfs/qsa_validation_requirements.pdf">quality control</a>.</p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-enjoy">
<ul class="socials">
		<li class="shr-mail">
			<a href="mailto:?subject=%22Qualys%20scan%20changes%20forced%20by%20PCI%20Council%22&amp;body=Link: http://www.flyingpenguin.com/?p=6759 (sent via shareaholic)%0D%0A%0D%0A----%0D%0A Qualys%20has%20sent%20out%20a%20notice%20of%20change%20to%20how%20their%20QualysGuard%20provides%20reports%20for%20PCI%0D%0AWithin%20the%20QualysGuard%20Consultant%20interface%2C%20%20you%20will%20still%20be%20able%20to%20run%20PCI%20specific%20scans%20using%20the%20PCI%20Option%20%20Profile.%20You%20will%20also%20still%20be%20able%20to%20run%20PCI%20pass%2Ffail%20reports%3B%20%20however%2C%20these%20reports%20wi" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.flyingpenguin.com/?p=6759&amp;feed=comments-rss2" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.flyingpenguin.com/?p=6759&amp;title=Qualys+scan+changes+forced+by+PCI+Council" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Qualys+scan+changes+forced+by+PCI+Council+-+http://b2l.me/ak7akb&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.flyingpenguin.com/?p=6759&amp;t=Qualys+scan+changes+forced+by+PCI+Council" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.flyingpenguin.com/?p=6759" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.flyingpenguin.com/?p=6759&amp;title=Qualys+scan+changes+forced+by+PCI+Council" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.flyingpenguin.com/?p=6759&amp;title=Qualys+scan+changes+forced+by+PCI+Council" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.flyingpenguin.com/?p=6759&amp;title=Qualys+scan+changes+forced+by+PCI+Council" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<img src="http://feeds.feedburner.com/~r/flyingpenguin/~4/H9LkcmPeTwg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.flyingpenguin.com/?feed=rss2&amp;p=6759</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.flyingpenguin.com/?p=6759</feedburner:origLink></item>
		<item>
		<title>Civilians giving away too much control of US CyberSecurity?</title>
		<link>http://feedproxy.google.com/~r/flyingpenguin/~3/OGEas2y9vNQ/</link>
		<comments>http://www.flyingpenguin.com/?p=6755#comments</comments>
		<pubDate>Thu, 26 Aug 2010 03:30:26 +0000</pubDate>
		<dc:creator>Davi Ottenheimer</dc:creator>
				<category><![CDATA[History]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.flyingpenguin.com/?p=6755</guid>
		<description><![CDATA[I wrote earlier about Deputy Defense Secretary William Lynn&#8217;s political posturing for influence or control of CyberCommand in the US. I was brought back to this thought after I read an excellent opinion article in The Daily Star called &#8220;An obsession with cybersecurity is not what the US needs&#8220;
Lynn&#8217;s proposals are provocative. But the  [...]]]></description>
			<content:encoded><![CDATA[<p>I <a href="?p=6744">wrote earlier about Deputy Defense Secretary William Lynn&#8217;s political posturing </a>for influence or control of CyberCommand in the US. I was brought back to this thought after I read an excellent opinion article in The Daily Star called <a href="http://www.dailystar.com.lb/article.asp?edition_id=1&amp;categ_id=5&amp;article_id=118631">&#8220;An obsession with cybersecurity is not what the US needs</a>&#8220;</p>
<blockquote><p><span class="snap_noshots">Lynn&rsquo;s proposals are provocative. But the  strategy could be costly and perhaps cumbersome, and it involves threats  that aren&rsquo;t well understood by the public &ndash; even by many of the  companies that could be targets of attacks. </span></p>
<p>Talking with Lynn, I was struck by the gap between the way defense experts see cyberspace &ndash; as a source of potentially crippling assault &ndash; and the public&rsquo;s view of an internet that is a generally benign companion. Although Lynn speaks of cyberspace as a &ldquo;domain&rdquo; that can be protected, such as airspace, it may be closer to the oxygen we breathe.</p>
</blockquote>
<p>Anyone who has been in a country ruled by a military junta knows the downsides. A perfect example of this was when I was walking down a quiet street one day and noticed a little building surrounded by plants next to a river. It was an interesting scene and I pulled out my camera to take a picture.</p>
<p>No more than a brief moment after my finger pressed on the shutter control three heavily armed men in camoflage emerged from the bushes yelling at me in a foreign language. I stepped back into the pedestrian traffic behind me but I very quickly noticed they were headed right for me, guns now in their hands at their waist. Fortunately the crowd surrounded me and a yelling match ensued with the civilians telling the three men to stay back.</p>
<p>The soldiers saw me as a threat perhaps in the same way that Lynn is going to train his staff and tell everyone about the threats facing America. I was using digital equipment so I showed the photo to the soldiers. I did not let go of my camera. They at first said they would have to confiscate my camera and worse but the crowd and I managed to convince them that there was no harm, no threat and no need to waste any more time arguing in the street, blocking everyone&#8217;s day. Resolution came when I deleted the photo so the soldiers could see they had made their influence felt. They walked away with guns back over their shoulders and the crowd dispersed.</p>
<p>My experience in this country was overshadowed by the fact that they had been through several military coups. Power was influenced heavily by the presence of domestic and foreign military, both of whom had used force to instate control over the political landscape.</p>
<p>This is just one of many examples you will find that show a disparity can easily form between perceptions of risk by civilians and the military. This is not to discount the value of a military presence but rather to say it needs to be something in perspective, especially given the recent record of US military threat analysis. I agree completely with the writer in the Daily Star when he says this.</p>
<blockquote><p><span class="snap_noshots">In the debate about cyberstrategy, I hope  officials will recognize the dangers of militarizing the global highway  for commerce and communication. </span></p>
</blockquote>
<p><span class="snap_noshots">All that being said, I also remember when I crossed the border from Mexico into the United States. It was a small town border on a dustry stretch of desert. I sauntered through a small gate with my camera out in front of me. A yellow school bus was parked along a line of yellow posts in the distance. I raised the camera and pressed the button&#8230;a second later I had a U.S. Border Patrol officer jump out of a box fifty feet ahead and yell that I was breaking a Federal law of 1920 that prohibits blah, blah, blah.&nbsp; </span></p>
<p><span class="snap_noshots">I was familiar enough with US laws, unlike the example above, to know this was nonsense and I had done nothing wrong. Nonetheless, here was a man with a gun again telling me that my tourist photo was a clear and present threat to national security. I showed the photo but did not offer to delete it. He said delete it or he was going to seize the camera, which indicated to me this was a kind of process for him. Perhaps it was how he passed the time. I hope you can see where the story goes. This is not the mentality the US needs in an office meant to protect the country from harm. Real threats should be handled. False positives can do more harm than good. Where is the emphasis to prevent false positives?<br />
</span></p>
<p><span class="snap_noshots">A secure network is one that operates without interruption, just like a secure neighborhood is one that has no need for military roadblocks. It is possible that the US military will consider civilian values of efficiency and freedom when they work on their new domain of &#8220;potential warfare&#8221; but so far I have seen little evidence. Instead I see a lot of military speakers being given open forums to scare civilian crowds with threats (bad guys are at the door, don&#8217;t you want to hand over control to the military now?) and Lynn has fit the rule not the exception.<br />
</span></p>
<p>The <a href="http://www.wired.com/dangerroom/tag/operation-buckshot-yankee/">Wired report</a> on Operation Buckshot Yankee supports <a href="?p=6744">my earlier assertion</a> that it is more hype about threat than reality. No clear harm, no clear link to a clear threat; just a vulnerability &#8212; apparently weak security controls in the US military.</p>
<blockquote><p>But exactly how much (if any) information was compromised because of agent.btz remains unclear. And members of the military involved in Operation Buckshot Yankee are reluctant to call agent.btz the work of a hostile government — despite ongoing talk that the Russians were behind it.</p></blockquote>
<p><span class="snap_noshots">Although I remain wary, at the very least I have to thank Lynn and the State Department for giving me excellent and somewhat contradictory material to add to my Top Ten Breaches presentation this October at the <a href="http://www.emc.com/microsites/rsa-conference/2010/europe/index.htm">RSA Conference in Europe</a>. The analysis feels very similar to my history studies when I had to make sense of the UK Foreign Office, Colonial Office and War Office fighting for control of resources at the end of WWII.<br />
</span></p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-enjoy">
<ul class="socials">
		<li class="shr-mail">
			<a href="mailto:?subject=%22Civilians%20giving%20away%20too%20much%20control%20of%20US%20CyberSecurity%3F%22&amp;body=Link: http://www.flyingpenguin.com/?p=6755 (sent via shareaholic)%0D%0A%0D%0A----%0D%0A I%20wrote%20earlier%20about%20Deputy%20Defense%20Secretary%20William%20Lynn%27s%20political%20posturing%20for%20influence%20or%20control%20of%20CyberCommand%20in%20the%20US.%20I%20was%20brought%20back%20to%20this%20thought%20after%20I%20read%20an%20excellent%20opinion%20article%20in%20The%20Daily%20Star%20called%20%22An%20obsession%20with%20cybersecurity%20is%20not%20what%20the%20US%20needs%22Lynn%26r" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.flyingpenguin.com/?p=6755&amp;feed=comments-rss2" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.flyingpenguin.com/?p=6755&amp;title=Civilians+giving+away+too+much+control+of+US+CyberSecurity%3F" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Civilians+giving+away+too+much+control+of+US+CyberSecurity%3F+-+http://b2l.me/ak3fth&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.flyingpenguin.com/?p=6755&amp;t=Civilians+giving+away+too+much+control+of+US+CyberSecurity%3F" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.flyingpenguin.com/?p=6755" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.flyingpenguin.com/?p=6755&amp;title=Civilians+giving+away+too+much+control+of+US+CyberSecurity%3F" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.flyingpenguin.com/?p=6755&amp;title=Civilians+giving+away+too+much+control+of+US+CyberSecurity%3F" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.flyingpenguin.com/?p=6755&amp;title=Civilians+giving+away+too+much+control+of+US+CyberSecurity%3F" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<img src="http://feeds.feedburner.com/~r/flyingpenguin/~4/OGEas2y9vNQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.flyingpenguin.com/?feed=rss2&amp;p=6755</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.flyingpenguin.com/?p=6755</feedburner:origLink></item>
		<item>
		<title>NYC Subway 80s Photos</title>
		<link>http://feedproxy.google.com/~r/flyingpenguin/~3/kx2hHpWjdOU/</link>
		<comments>http://www.flyingpenguin.com/?p=6753#comments</comments>
		<pubDate>Wed, 25 Aug 2010 18:34:23 +0000</pubDate>
		<dc:creator>Davi Ottenheimer</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.flyingpenguin.com/?p=6753</guid>
		<description><![CDATA[A photo-essay on the NYC Subway can be found here. It really highlights the change in safety and security that is felt now. I frequently rode the subway in the 1970s and 80s and today&#8217;s experience is radically different. These photos really capture it.





		
			Email this to a friend?
		
		
			Subscribe to the comments for this post?
		
		
			Share this [...]]]></description>
			<content:encoded><![CDATA[<p>A photo-essay on the NYC Subway can be found <a href="http://24flinching.com/word/headline/subway-lifeblood/">here</a>. It really highlights the change in safety and security that is felt now. I frequently rode the subway in the 1970s and 80s and today&#8217;s experience is radically different. <a href="http://24flinching.com/word/headline/subway-lifeblood/">These photos</a> really capture it.</p>
<p><img src="http://24flinching.com/word/wp-content/uploads/2010/08/tumblr_l702n6I4fF1qa64sm.png" alt="" /></p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-enjoy">
<ul class="socials">
		<li class="shr-mail">
			<a href="mailto:?subject=%22NYC%20Subway%2080s%20Photos%22&amp;body=Link: http://www.flyingpenguin.com/?p=6753 (sent via shareaholic)%0D%0A%0D%0A----%0D%0A A%20photo-essay%20on%20the%20NYC%20Subway%20can%20be%20found%20here.%20It%20really%20highlights%20the%20change%20in%20safety%20and%20security%20that%20is%20felt%20now.%20I%20frequently%20rode%20the%20subway%20in%20the%201970s%20and%2080s%20and%20today%27s%20experience%20is%20radically%20different.%20These%20photos%20really%20capture%20it.%0A%0A" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.flyingpenguin.com/?p=6753&amp;feed=comments-rss2" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.flyingpenguin.com/?p=6753&amp;title=NYC+Subway+80s+Photos" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=NYC+Subway+80s+Photos+-+http://b2l.me/akywe6&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.flyingpenguin.com/?p=6753&amp;t=NYC+Subway+80s+Photos" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.flyingpenguin.com/?p=6753" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.flyingpenguin.com/?p=6753&amp;title=NYC+Subway+80s+Photos" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://www.flyingpenguin.com/?p=6753&amp;title=NYC+Subway+80s+Photos" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.flyingpenguin.com/?p=6753&amp;title=NYC+Subway+80s+Photos" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

<img src="http://feeds.feedburner.com/~r/flyingpenguin/~4/kx2hHpWjdOU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.flyingpenguin.com/?feed=rss2&amp;p=6753</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.flyingpenguin.com/?p=6753</feedburner:origLink></item>
	</channel>
</rss>
