<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2232301974213299528</id><updated>2011-11-27T18:40:46.856-05:00</updated><title type='text'>Security Rants</title><subtitle type='html'>My issues with the IT Security world and what's happening in it.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://securityrantsblog.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://securityrantsblog.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Mark Reinertson</name><uri>http://www.blogger.com/profile/08437218642927802667</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>12</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2232301974213299528.post-5029784226322449022</id><published>2008-02-07T18:20:00.000-05:00</published><updated>2008-02-07T19:47:46.429-05:00</updated><title type='text'>But, we've ALWAYS done it like this!</title><content type='html'>Tradition is no substitute for a good reason.&lt;br /&gt;&lt;br /&gt;Peter Tippett.&lt;br /&gt;&lt;br /&gt;Know who he is?&lt;br /&gt;&lt;br /&gt;Of course you don't.&lt;br /&gt;&lt;br /&gt;He's just the &lt;span&gt;&lt;span&gt;vice president of risk intelligence for Verizon Business, chief scientist at ICSA Labs, and the inventor of the program that became Norton AntiVirus.&lt;br /&gt;&lt;br /&gt;Not a bad resume.&lt;br /&gt;&lt;br /&gt;He had some very interesting points to make recently in an article with &lt;a href="http://www.darkreading.com/document.asp?doc_id=145224&amp;amp;WT.svl=news1_1"&gt;Dark Reading&lt;/a&gt;.&lt;br /&gt;Seriously, you should be reading &lt;a href="http://www.darkreading.com/default.asp"&gt;Dark Reading&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Meanwhile, back at the ranch... Peter Tippett said something that I have been trumpeting for years. (I'm so validated! GRIN)&lt;br /&gt;"&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;"Employee training sometimes gets a bad rap because it doesn't alter the behavior of every employee who takes it," he said. "But if I can reduce the number of security incidents by 30 percent through a $10,000 security awareness program, doesn't that make more sense than spending $1 million on an antivirus upgrade that only reduces incidents by 2 percent?""&lt;br /&gt;&lt;br /&gt;WOO HOO!!! Give the man a CIGAR!!!&lt;br /&gt;&lt;br /&gt;He makes other great points as well, but this one is GOLDEN!&lt;br /&gt;&lt;br /&gt;It's the human element that continues to be the weak point.&lt;br /&gt;Why waste time guessing passwords when I can ask someone to just give me theirs?&lt;br /&gt;Why pick a lock when someone will just open the door for me?&lt;br /&gt;&lt;br /&gt;So much of what we are doing as Security Practitioners is just a big waste of time.&lt;br /&gt;We're locking the barn door after the cows are down the road and in the slaughterhouse.&lt;br /&gt;&lt;br /&gt;Why do we have mandatory "Sensitivity Training" but we couldn't care less if Joe Schmo in the mail room opens his FluffyBunny.txt.exe attachment in his email and now the whole organization is boned.&lt;br /&gt;Boned, being a technical term.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;We're back to the Theater of Security.&lt;br /&gt;It doesn't actually do anything, but it looks great and gives us all kinds of expensive warm fuzzies.&lt;br /&gt;&lt;br /&gt;After all, it's not how you are, it's how you feel!&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2232301974213299528-5029784226322449022?l=securityrantsblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityrantsblog.blogspot.com/feeds/5029784226322449022/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2232301974213299528&amp;postID=5029784226322449022&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default/5029784226322449022'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default/5029784226322449022'/><link rel='alternate' type='text/html' href='http://securityrantsblog.blogspot.com/2008/02/but-weve-always-done-it-like-this.html' title='But, we&apos;ve ALWAYS done it like this!'/><author><name>Mark Reinertson</name><uri>http://www.blogger.com/profile/08437218642927802667</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2232301974213299528.post-7064075993325598000</id><published>2008-02-01T14:32:00.000-05:00</published><updated>2008-02-01T16:04:58.881-05:00</updated><title type='text'>Busting the GUI for fun and profit!!!</title><content type='html'>Ok.&lt;br /&gt;I admit it.&lt;br /&gt;I LOVE &lt;a href="http://dsc.discovery.com/fansites/mythbusters/mythbusters.html"&gt;MYTHBUSTERS&lt;/a&gt;!&lt;br /&gt;There, I said it.&lt;br /&gt;These guys are incredible. I absolutely love how they go in and tear apart all these pervasive myths about how and why things work or don't work.&lt;br /&gt;We need more of that.&lt;br /&gt;Worst offenders?&lt;br /&gt;Our own school system.&lt;br /&gt;But, I digress.&lt;br /&gt;&lt;br /&gt;Recently, &lt;span name="intelliTxt" id="intelliTXT"&gt;&lt;a href="http://en.wikipedia.org/wiki/Jamie_Hyneman"&gt;Jamie Hyneman&lt;/a&gt; of Mythbusters fame wrote a great article on what's wrong with current technology.&lt;br /&gt;I found it to be very well written and hits the nail on the head of an industry gone wrong.&lt;br /&gt;"..&lt;/span&gt;&lt;span name="intelliTxt" id="intelliTXT"&gt;As machines become more complicated, good interface design becomes more essential—you can't just keep adding buttons and menus."&lt;br /&gt;&lt;br /&gt;Modern design of just about everything in Tech is appalling.&lt;br /&gt;From the interface to the backend.&lt;br /&gt;To say nothing of the pointy haired bosses!&lt;br /&gt;Firewalls that are a pain to configure. Routers that need special voodoo to route. Anti-virus that is a huge resource hog and is too difficult for the average user to configure. Security ends up being theater and innovation is a labyrinth of incomprehensible menus and configurations.&lt;br /&gt;&lt;br /&gt;Does anyone wonder why so many WIFI routers are not configured with any security?&lt;br /&gt;It's because it's too stinkin' hard for most people to handle and they either believe (Falsely) that it's all been done for them or that it really doesn't matter anyway!&lt;br /&gt;"Hey, we bought some security. Now, you say we have to configure it? It should just know to secure us!"&lt;br /&gt;&lt;br /&gt;Even IT Professionals fail miserably at this basic task.&lt;br /&gt;If I had a nickel for every router, firewall, WIFI access point, server, etc that still had the default passwords on it, I'd be flippin' rich!&lt;br /&gt;&lt;br /&gt;We need better associative interoperability on all our devices.&lt;br /&gt;Devices should negotiate from the highest security settings they are capable of and move down by default. Currently, all too many devices start out with ZERO security turned on by default.&lt;br /&gt;Why can't my wireless router see devices in the area and let me pick which ones I want to be able to connect to it? Then let it auto-negotiate the security based on defaults or mandatory settings that I choose.&lt;br /&gt;Heck, why can't my router act as an intelligent and secure bridge to other networks in an easy to use fashion?&lt;br /&gt;&lt;br /&gt;The hardware is very capable, the ideas are all around us.&lt;br /&gt;Corporations and both greedy and very lazy.&lt;br /&gt;A dangerous combination.&lt;br /&gt;&lt;br /&gt;Don't believe me?&lt;br /&gt;Linksys is owned by Cisco. Arguably, the top dog in networking.&lt;br /&gt;They are the bee's knees in this field and you would think they would leap at the chance to make the absolute best and most affordable gear for the home market.&lt;br /&gt;Frankly, they could do a LOT better.&lt;br /&gt;&lt;br /&gt;Linksys firmware is still pretty primitive overall.&lt;br /&gt;A number of third party's have come up with better firmware and they GIVE IT AWAY!&lt;br /&gt;You heard me! FREE!!! NO COST!!!&lt;br /&gt;&lt;a href="http://en.wikipedia.org/wiki/Dd-wrt"&gt;DD-WRT&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Tomato_%28firmware%29"&gt;Tomato&lt;/a&gt;, and &lt;a href="http://en.wikipedia.org/wiki/OpenWrt"&gt;OpenWrt&lt;/a&gt; are just a few of many.&lt;br /&gt;(Brief opinion here, been running DD-WRT on a 20 dollar Linksys WRT54GS 2.0 for a few months now and I LOVE IT! Beats the brains out of my 75 dollar SMC!)&lt;br /&gt;&lt;br /&gt;Other problems are simple issues that no one seems to notice or care about that would make a HUGE impact.&lt;br /&gt;Email encryption. User education. IPv6 (There, I said it!)&lt;br /&gt;&lt;br /&gt;What does this have to do with the topic?&lt;br /&gt;VERY POOR INTERFACE DESIGN MEANS PEOPLE WON'T USE IT!&lt;br /&gt;&lt;br /&gt;We have devices with great features that go unused, great security that doesn't get configured or even turned on, great innovations that sit and rot because it's just too arcane.&lt;br /&gt;We get used to this nonsense and never demand any better.&lt;br /&gt;Why not?&lt;br /&gt;Because everyone just assumes that the next batch will be even more incomprehensible.&lt;br /&gt;&lt;br /&gt;All too often, they're right.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2232301974213299528-7064075993325598000?l=securityrantsblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityrantsblog.blogspot.com/feeds/7064075993325598000/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2232301974213299528&amp;postID=7064075993325598000&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default/7064075993325598000'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default/7064075993325598000'/><link rel='alternate' type='text/html' href='http://securityrantsblog.blogspot.com/2008/02/busting-gui-for-fun-and-profit.html' title='Busting the GUI for fun and profit!!!'/><author><name>Mark Reinertson</name><uri>http://www.blogger.com/profile/08437218642927802667</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2232301974213299528.post-5753344647542293649</id><published>2007-11-21T11:55:00.000-05:00</published><updated>2007-11-21T13:56:55.813-05:00</updated><title type='text'>How to owe money by doing NOTHING!!!</title><content type='html'>This one is just beyond the pale.&lt;br /&gt;Even for these vampire banks and credit card companies.&lt;br /&gt;I'm just amazed at the GALL they have, to say nothing of the outright FRAUD that is attempted.&lt;br /&gt;&lt;br /&gt;Just read a post from &lt;a href="http://12angrymen.wordpress.com/"&gt;The Twelve Angry Men &lt;/a&gt;blog.&lt;br /&gt;These guys are doing some terrific work, more power to them!&lt;br /&gt;&lt;br /&gt;Well, here's the link for the item that caught my interest.&lt;br /&gt;&lt;br /&gt;&lt;a title="Permanent Link: Force-Post, or Huh? I haven’t even activated the card!" href="http://12angrymen.wordpress.com/2007/11/16/force-post-or-huh-i-havent-even-activated-the-card/" rel="bookmark"&gt;Force-Post, or Huh? I haven’t even activated the card!&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Basically, it boils down to all this "Opt Out" nonsense.&lt;br /&gt;In other words, you have to tell them EXPLICITLY that you DON'T want something or they can go ahead and charge you for it!&lt;br /&gt;&lt;br /&gt;The result of such insanity, you ask?&lt;br /&gt;&lt;br /&gt;"In the particular case I am speaking of, customers had run up balances of $1500 or more having never activated their card. Not to mention royally screwing their credit histories at the bureaus.&lt;br /&gt;A regular merchant could never post a settlement against an unactivated card as this is a principle barrier against merchant fraud. But the issuing bank, who usually also runs either an enhancement business unit, or contracts for one, OWNS the cardholder masterfile. By masking out the activation character position in the master file by means of a COBOL program,they can run the enhancement sales orders against the master file and ‘force post’ the enhancement product sale. The pretense is that this is valid and legal because the customer indicated a desire to purchase the enhancement, even though the product is an enhancement against a non-active account."&lt;br /&gt;&lt;br /&gt;And people wonder why I go with a Credit Union???&lt;br /&gt;&lt;br /&gt;What a business prospect!&lt;br /&gt;Charge people for something they never asked for. In doing so it puts a big time hurt on them but not enough to be forced to get a lawyer.&lt;br /&gt;Everyone BUT you profits!&lt;br /&gt;For almost ZERO COST!!!&lt;br /&gt;&lt;br /&gt;Educate yourselves.&lt;br /&gt;Write letters to Congress and the Senate.&lt;br /&gt;Write to the &lt;a href="http://www.ftc.gov/index.shtml"&gt;FTC&lt;/a&gt;.&lt;br /&gt;Write letters to the Editor of your local paper.&lt;br /&gt;&lt;br /&gt;STOP TAKING THIS LYING DOWN!!!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2232301974213299528-5753344647542293649?l=securityrantsblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityrantsblog.blogspot.com/feeds/5753344647542293649/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2232301974213299528&amp;postID=5753344647542293649&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default/5753344647542293649'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default/5753344647542293649'/><link rel='alternate' type='text/html' href='http://securityrantsblog.blogspot.com/2007/11/how-to-owe-money-by-doing-nothing.html' title='How to owe money by doing NOTHING!!!'/><author><name>Mark Reinertson</name><uri>http://www.blogger.com/profile/08437218642927802667</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2232301974213299528.post-15537081338473223</id><published>2007-11-03T14:15:00.000-05:00</published><updated>2007-11-21T13:59:39.196-05:00</updated><title type='text'>Do you need to have permission to have rights???</title><content type='html'>I just read an outrageous article and opinion by a Detroit News Writer. A Mr. Chris McCosky.&lt;br /&gt;I fully credit him and since I am a Detroit resident, I would LOVE to take him up on his challenge,&lt;br /&gt;"We actually talk to, in person, the people we write about. If we rip somebody in an article, you best be sure most of us will confront that person the next day and take whatever medicine we need to take."&lt;br /&gt;&lt;br /&gt;Please! Contact me at your earliest convenience regarding this. I will happily meet with you to discuss this.&lt;br /&gt;&lt;br /&gt;The article as posted.&lt;br /&gt;&lt;a href="http://detnews.com/apps/pbcs.dll/article?AID=/20071103/OPINION03/711030306"&gt;http://detnews.com/apps/pbcs.dll/article?AID=/20071103/OPINION03/711030306&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Bloggers most certainly ARE journalists.&lt;br /&gt;&lt;br /&gt;You state (and I credit you with), "It's actually getting to the point now where some (too many) of the bloggers are using cyberspace to discredit the legitimate media. "&lt;br /&gt;What makes media legitimate?&lt;br /&gt;The scandals? The yellow journalism? The favoritisms? The backdoor deals? The lack of ethics? Being beholden to advertisers? Endorsing popular opinions over the truth?&lt;br /&gt;They deserve to be discredited when they are wrong. At every opportunity! THAT is freedom! The freedom to question, to dig, to examine, to hold up something or someone to the harsh light of the truth.&lt;br /&gt;No one is above scrutiny!&lt;br /&gt;Not even you.&lt;br /&gt;The dictionary describes journalism as "Written material of current interest or wide popular appeal".&lt;br /&gt;I would say bloggers are engaged in journalism by definition.&lt;br /&gt;Since when are the rights of freedom of the press only granted to a favored few?&lt;br /&gt;That is an outrage to even suggest that!&lt;br /&gt;Who is to say what is legitimate media?&lt;br /&gt;Who mandates that? No one does and no one should ever!&lt;br /&gt;The act of writing creates the journalist and it's resulting product is journalism. It doesn't matter if you like it or not.&lt;br /&gt;We are born with these inalienable rights. NOT granted them by a university or by being hired onto a staff.&lt;br /&gt;Freedom of the press is universal. From the kids printing up thier own 'zines to the New York Times.&lt;br /&gt;To be a journalist is simply to exercise ones rights that cannot ever be taken away.&lt;br /&gt;I WILL exercise my rights that I was born with.&lt;br /&gt;You CANNOT take them away.&lt;br /&gt;I AM a journalist!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2232301974213299528-15537081338473223?l=securityrantsblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityrantsblog.blogspot.com/feeds/15537081338473223/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2232301974213299528&amp;postID=15537081338473223&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default/15537081338473223'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default/15537081338473223'/><link rel='alternate' type='text/html' href='http://securityrantsblog.blogspot.com/2007/11/do-you-need-to-have-permission-to-have.html' title='Do you need to have permission to have rights???'/><author><name>Mark Reinertson</name><uri>http://www.blogger.com/profile/08437218642927802667</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2232301974213299528.post-2773737408188255856</id><published>2007-11-01T12:01:00.000-05:00</published><updated>2007-11-01T12:42:10.360-05:00</updated><title type='text'>If you're not one of US, then you MUST be one of THEM!</title><content type='html'>Bruce Schneier is fast becoming my favorite voice of reason in the wilderness.&lt;br /&gt;He just wrote a tremendous article on the irrational concepts of the Citizens Reporting Atypical Practices. In short, C.R.A.P!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.schneier.com/blog/archives/2007/11/the_war_on_the.html"&gt;http://www.schneier.com/blog/archives/2007/11/the_war_on_the.html&lt;/a&gt;&lt;br /&gt;"We've opened up a new front on the war on terror. It's an attack on the unique, the unorthodox, the unexpected; it's a war on different. If you act different, you might find yourself investigated, questioned, and even arrested — even if you did nothing wrong, and had no intention of doing anything wrong. The problem is a combination of citizen informants and a CYA attitude among police that results in a knee-jerk escalation of reported threats... After someone reports a 'terrorist threat,' the whole system is biased towards escalation and CYA instead of a more realistic threat assessment... If you ask amateurs to act as front-line security personnel, you shouldn't be surprised when you get amateur security."&lt;br /&gt;&lt;br /&gt;This will, of course, result in his immediate investiation for Journalists Investigating Internal Government Operations.&lt;br /&gt;Jingo!&lt;br /&gt;&lt;a href="http://en.wikipedia.org/wiki/Jingoism"&gt;http://en.wikipedia.org/wiki/Jingoism&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Ok, all kidding aside. The new witch hunts are here.&lt;br /&gt;I see no reason to believe that these will turn out any differently from the past ones.&lt;br /&gt;We already have descended to this hysteria,&lt;br /&gt;&lt;a href="http://www.bloggernews.net/18108"&gt;http://www.bloggernews.net/18108&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I found the best quote regarding this on SlashDot,&lt;br /&gt;"The war on Terror is a war against an emotion... Anything which can cause fear is therefore subject to the war. In that way it's the perfect war for politicians."&lt;br /&gt;&lt;br /&gt;Who makes money off this war on (insert today's fear response here)?&lt;br /&gt;Who gets more rights then you do?&lt;br /&gt;They, are your enemy.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2232301974213299528-2773737408188255856?l=securityrantsblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityrantsblog.blogspot.com/feeds/2773737408188255856/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2232301974213299528&amp;postID=2773737408188255856&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default/2773737408188255856'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default/2773737408188255856'/><link rel='alternate' type='text/html' href='http://securityrantsblog.blogspot.com/2007/11/if-youre-not-one-of-us-then-you-must-be.html' title='If you&apos;re not one of US, then you MUST be one of THEM!'/><author><name>Mark Reinertson</name><uri>http://www.blogger.com/profile/08437218642927802667</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2232301974213299528.post-8059198405359913850</id><published>2007-07-07T11:37:00.000-05:00</published><updated>2007-07-07T11:56:45.896-05:00</updated><title type='text'>If the product is so great, why not stand behind it?</title><content type='html'>Just had a very inspiring read from Charles Cooper at Cnet's News.com&lt;br /&gt;&lt;br /&gt;&lt;a href="http://news.com.com/8301-10784_3-9740409-7.html?part=rss&amp;subj=news&amp;amp;tag=2547-1_3-0-5"&gt;http://news.com.com/8301-10784_3-9740409-7.html?part=rss&amp;subj=news&amp;amp;tag=2547-1_3-0-5&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The simple question at the heart of it is, Why don't companies warranty their product for a reasonable time anymore?&lt;br /&gt;Sure, you can BUY an extended warranty. Corporation LOVE the profit margins on those!&lt;br /&gt;But, why not a reasonable warranty?&lt;br /&gt;&lt;br /&gt;Case in point,&lt;br /&gt;Sooner or later, shoddy quality is going to bite you.&lt;br /&gt;HARD!&lt;br /&gt;When it does, it costs big.&lt;br /&gt;About a BILLION DOLLARS big.&lt;br /&gt;&lt;a href="http://games.slashdot.org/games/07/07/06/1330228.shtml"&gt;http://games.slashdot.org/games/07/07/06/1330228.shtml&lt;/a&gt;&lt;br /&gt;Demand more, demand better!&lt;br /&gt;Write to your congressional representative.&lt;br /&gt;I even made it really easy right here on the website!&lt;br /&gt;Nothing will get fixed if we don't start demanding something be done!&lt;br /&gt;&lt;br /&gt;But, at least they're saving money, off-shoring your job!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2232301974213299528-8059198405359913850?l=securityrantsblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityrantsblog.blogspot.com/feeds/8059198405359913850/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2232301974213299528&amp;postID=8059198405359913850&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default/8059198405359913850'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default/8059198405359913850'/><link rel='alternate' type='text/html' href='http://securityrantsblog.blogspot.com/2007/07/if-product-is-so-great-why-not-stand.html' title='If the product is so great, why not stand behind it?'/><author><name>Mark Reinertson</name><uri>http://www.blogger.com/profile/08437218642927802667</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2232301974213299528.post-4398995493702419205</id><published>2007-07-02T19:35:00.000-05:00</published><updated>2007-07-02T19:44:36.001-05:00</updated><title type='text'>Better security, eh? Sure it is!</title><content type='html'>Oh great!&lt;br /&gt;Microsoft is at it again.&lt;br /&gt;More reporting back to the mothership of your data.&lt;br /&gt;&lt;br /&gt;From the article, &lt;a href="http://news.softpedia.com/news/Forget-about-the-WGA-20-Windows-Vista-Features-and-Services-Harvest-User-Data-for-Microsoft-58752.shtml"&gt;http://news.softpedia.com/news/Forget-about-the-WGA-20-Windows-Vista-Features-and-Services-Harvest-User-Data-for-Microsoft-58752.shtml&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;"The Redmond company emphasized numerous times the fact that all information collected is not used to identify or contact users. But could it? Oh yes! All you have to know is that Microsoft could come knocking on your door as soon as you boot Windows Vista for the first time if you consider the system’s computer information harvested. Microsoft will get your "Internet protocol address, the type of operating system, browser and name and version of the &lt;a class="iAs" style="FONT-WEIGHT: normal; PADDING-BOTTOM: 1px; COLOR: #0066cc; BORDER-BOTTOM: 0.1em solid; BACKGROUND-COLOR: transparent; TEXT-DECORATION: underline" href="http://news.softpedia.com/news/Forget-about-the-WGA-20-Windows-Vista-Features-and-Services-Harvest-User-Data-for-Microsoft-58752.shtml#" target="_blank" itxtdid="2930972"&gt;software&lt;/a&gt; you are using, and the language code of the device where you installed the software." But all they really need is your IP address. "&lt;br /&gt;&lt;br /&gt;When is this going to end?&lt;br /&gt;When are the consumers, especially the corporation, going to stand up and refuse this type of spyware?&lt;br /&gt;&lt;br /&gt;One simple solution?&lt;br /&gt;Go Open Source.&lt;br /&gt;Frankly, I'm seeing less and less reason to not switch to Linux.&lt;br /&gt;&lt;br /&gt;It's YOUR computer, YOUR data, YOUR security.&lt;br /&gt;You deserve better!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2232301974213299528-4398995493702419205?l=securityrantsblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityrantsblog.blogspot.com/feeds/4398995493702419205/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2232301974213299528&amp;postID=4398995493702419205&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default/4398995493702419205'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default/4398995493702419205'/><link rel='alternate' type='text/html' href='http://securityrantsblog.blogspot.com/2007/07/better-security-eh-sure-it-is.html' title='Better security, eh? Sure it is!'/><author><name>Mark Reinertson</name><uri>http://www.blogger.com/profile/08437218642927802667</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2232301974213299528.post-1070071743549511091</id><published>2007-04-12T13:33:00.000-05:00</published><updated>2007-04-12T13:50:56.401-05:00</updated><title type='text'></title><content type='html'>Just got done reading a VERY interesting paper by Richard Clayton.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.lightbluetouchpaper.org/2007/04/03/there-arent-that-many-serious-spammers-any-more/"&gt;http://www.lightbluetouchpaper.org/2007/04/03/there-arent-that-many-serious-spammers-any-more/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I was made aware of it from Bruce Schneier's Blog. (A must read btw, GO BRUCE!)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.schneier.com/blog/"&gt;http://www.schneier.com/blog/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;It appears that just a few spammers may be responsible for the majority of spam out there.&lt;br /&gt;Could Alan Ralsky from the Metro Detroit area be one of them?&lt;br /&gt;&lt;br /&gt;&lt;a href="http://en.wikipedia.org/wiki/Alan_Ralsky"&gt;http://en.wikipedia.org/wiki/Alan_Ralsky&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Could Sandford Wallace be back in action?&lt;br /&gt;&lt;br /&gt;&lt;a href="http://en.wikipedia.org/wiki/Sanford_Wallace"&gt;http://en.wikipedia.org/wiki/Sanford_Wallace&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Only the Shadow knows.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://en.wikipedia.org/wiki/The_Shadow"&gt;http://en.wikipedia.org/wiki/The_Shadow&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Now seriously folks, this really is important.&lt;br /&gt;If this is the case, we really have a chance at nailing a good bit of the problem.&lt;br /&gt;5 or 10 people versus tens of thousands?&lt;br /&gt;&lt;br /&gt;You may be asking, "Why is he interested in Spam?"&lt;br /&gt;&lt;br /&gt;&lt;a href="http://news.com.com/Spam+law+a+matter+of+fax/2100-1028_3-994076.html"&gt;http://news.com.com/Spam+law+a+matter+of+fax/2100-1028_3-994076.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;As you can see, I am not a fan of spam in the least.&lt;br /&gt;It's essentially the same as telemarketing using collect calls.&lt;br /&gt;&lt;br /&gt;Are you sick of 90% of your Inbox being spam?&lt;br /&gt;Get off your duffs and get ahold of your Congressman!&lt;br /&gt;&lt;a href="http://www.rallycongress.com/letter2congress/698/?gclid=CNXehdXtvYsCFRgXEAodY1blyQ"&gt;http://www.rallycongress.com/letter2congress/698/?gclid=CNXehdXtvYsCFRgXEAodY1blyQ&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Remember, we're all in this together.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2232301974213299528-1070071743549511091?l=securityrantsblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityrantsblog.blogspot.com/feeds/1070071743549511091/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2232301974213299528&amp;postID=1070071743549511091&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default/1070071743549511091'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default/1070071743549511091'/><link rel='alternate' type='text/html' href='http://securityrantsblog.blogspot.com/2007/04/just-got-done-reading-very-interesting.html' title=''/><author><name>Mark Reinertson</name><uri>http://www.blogger.com/profile/08437218642927802667</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2232301974213299528.post-1371961196895680051</id><published>2007-04-12T09:41:00.000-05:00</published><updated>2007-04-12T10:08:11.326-05:00</updated><title type='text'>When you dont challenge a myth, it becomes a religion.</title><content type='html'>Paul Ohm wrote a surprisingly refreshing and sobering piece on the myth on the superhacker.&lt;br /&gt;&lt;br /&gt;Guess what? Another Slashdot.org link!&lt;br /&gt;&lt;a href="http://it.slashdot.org/article.pl?sid=07/04/11/1952247"&gt;http://it.slashdot.org/article.pl?sid=07/04/11/1952247&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;One part that I think was really on the point was,&lt;br /&gt;"First, some statements of Superuser harm are so hyperbolic as to be self-disproving. For example, as Cybersecurity Czar under the Clinton and second Bush administrations, Richard Clarke was fond of saying, “digital Pearl Harbors are happening every day.” I’m not sure what meaning Clarke was giving to the phrase, digital Pearl Harbor: he may have meant attacks with the psychologically damaging effect, horrific loss of life, terrifying surprise, size of invading force, or historical impact of the December 7, 1941 attack; no matter which of these he meant, the claim is a horribly exaggerated overstatement."&lt;br /&gt;&lt;br /&gt;Now, I'll be the first one to dust off the old aluminum foil fedora for a nice tiptoe through the tulips. But, this is just beyond the pale.&lt;br /&gt;All this "the sky is falling" just deadens us to actual threats, and boy are there plenty of those.&lt;br /&gt;&lt;br /&gt;This leads us handily to the next part.&lt;br /&gt;The response to the boogey man on the Internet!&lt;br /&gt;&lt;br /&gt;"The CFAA’s (Computer Fraud and Abuse Act) prohibitions cover an expansive laundry list of activity. You might be a felon under the CFAA’s broad “hacking” provisions if you: &lt;a href="http://papers.ssrn.com/sol3/papers.cfm?abstract_id=399740"&gt;breach a contract&lt;/a&gt;; &lt;a href="http://emlawcenter.bna.com/pic2/em.nsf/id/BNAP-6MYNRX?OpenDocument"&gt;“transmit” a program&lt;/a&gt; from a floppy to your employer-issued laptop; or &lt;a href="http://writ.news.findlaw.com/commentary/20030925_sprigman.html"&gt;send a lot of e-mail messages&lt;/a&gt;. And even if the FBI decides not to prosecute you for these transgressions, the broad CFAA gives it the right to investigate you, to read your e-mail messages and maybe even wiretap your phones and Internet connections."&lt;br /&gt;&lt;br /&gt;Well, if you aren't guilty of anything, you should have no problems with any of this!&lt;br /&gt;"Officer Jellydonut, hand me my rubber gloves. Just going to have a little look-see!"&lt;br /&gt;&lt;br /&gt;I think that covered infringement of civil liberties pretty well, don't you?&lt;br /&gt;&lt;br /&gt;The next exhibit in our Alleyway of Fear, Uncertainty and Dread would be the end result and failures of our industry and it's so called "experts".&lt;br /&gt;&lt;br /&gt;"Finally, too many experts consider online risk assessment to be somebody else’s concern. Computer security experts often conclude simply that all computer software is flawed, and that malicious attackers can and will exploit those flaws if they are sufficiently motivated. The question isn’t a technology question at all, they contend, but it is about means, motive, and opportunity, which are questions for criminologists, not engineers. "&lt;br /&gt;&lt;br /&gt;Nothing like the classic "somebody else's problem".&lt;br /&gt;But, it's everyone's problem.&lt;br /&gt;Seriously, it affects and impacts you, me, Grandma, the schools, the job market, the stock market. (Boy, I'm starting to sound a bit paranoid here, eh?) (I can say eh, I live 20 minutes from the Canadian border!) (Michigan joke)&lt;br /&gt;&lt;br /&gt;We desperately need greater information sharing and peer review.&lt;br /&gt;We need empirical evidence and the harsh light of day.&lt;br /&gt;We need to stop buying the lie!&lt;br /&gt;&lt;br /&gt;We must demand that at the very least, best practices that are recognized by the IT Security industry are in place and enforced.&lt;br /&gt;&lt;br /&gt;IT needs to be a democracy, but not at the expense of the true data owners.&lt;br /&gt;Mr. and Mrs. America.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2232301974213299528-1371961196895680051?l=securityrantsblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityrantsblog.blogspot.com/feeds/1371961196895680051/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2232301974213299528&amp;postID=1371961196895680051&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default/1371961196895680051'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default/1371961196895680051'/><link rel='alternate' type='text/html' href='http://securityrantsblog.blogspot.com/2007/04/when-you-dont-challenge-myth-it-becomes.html' title='When you dont challenge a myth, it becomes a religion.'/><author><name>Mark Reinertson</name><uri>http://www.blogger.com/profile/08437218642927802667</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2232301974213299528.post-7162872990108951549</id><published>2007-04-03T09:43:00.000-05:00</published><updated>2007-04-08T14:10:05.067-05:00</updated><title type='text'>The long arm of the lawyer!</title><content type='html'>&lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_0"&gt;OK&lt;/span&gt;,&lt;br /&gt;I'm all for full disclosure.&lt;br /&gt;But!&lt;br /&gt;&lt;br /&gt;When the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;RIAA's&lt;/span&gt; lawyers start fishing expeditions like this, it's just too far reaching!&lt;br /&gt;As was reported on &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_2"&gt;Slashdot&lt;/span&gt;.org, &lt;a href="http://yro.slashdot.org/article.pl?sid=07/04/02/0516242"&gt;http://yro.slashdot.org/article.pl?sid=07/04/02/0516242&lt;/a&gt;&lt;br /&gt;""The &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;RIAA's&lt;/span&gt; &lt;a href="http://yro.slashdot.org/article.pl?sid=06/11/28/1549242&amp;amp;tid=141"&gt;attempt to get Ms. &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;Lindor's&lt;/span&gt; son's desktop computer&lt;/a&gt; in &lt;a href="http://recordingindustryvspeople.blogspot.com/#UMG_v_Lindor"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;UMG&lt;/span&gt; v. &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;Lindor&lt;/span&gt;&lt;/a&gt; has been &lt;a href="http://recordingindustryvspeople.blogspot.com/2007/03/judge-denies-riaa-motion-to-compel-ms.html"&gt;rejected by the Magistrate Judge&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The judge said that the &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;RIAA&lt;/span&gt; 'offered little more than speculation to support their request for an inspection of Mr. Raymond's desktop computer, based on ... his family relationship to the defendant, the proximity of his house to the defendant's house, and his determined defense of his mother in this case. That is not enough. On the record before me, plaintiffs have provided scant basis to authorize an inspection of Mr. Raymond's desktop computer.'"&lt;br /&gt;&lt;br /&gt;This amounts to an attempt to get free shots at just about &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;anyone's&lt;/span&gt; computer based on the arguments of relationship, proximity, and the fact that they are against just this sort of strong arming in the first place!&lt;br /&gt;&lt;br /&gt;"You don't agree with us, so you MUST be guilty too!"&lt;br /&gt;&lt;br /&gt;Oh yeah, THAT fills me with warm, fuzzy feelings.&lt;br /&gt;&lt;br /&gt;I'm amazed how a group that can be behind consumer rights restricting &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;DRM&lt;/span&gt;, installing &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;RootKits&lt;/span&gt; on customers machine, unfair and monopolistic practices and such self serving legal wrangling and can STILL survive.&lt;br /&gt;&lt;br /&gt;It's not about the music, it's about the profit margins!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2232301974213299528-7162872990108951549?l=securityrantsblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityrantsblog.blogspot.com/feeds/7162872990108951549/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2232301974213299528&amp;postID=7162872990108951549&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default/7162872990108951549'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default/7162872990108951549'/><link rel='alternate' type='text/html' href='http://securityrantsblog.blogspot.com/2007/04/long-arm-of-lawyer.html' title='The long arm of the lawyer!'/><author><name>Mark Reinertson</name><uri>http://www.blogger.com/profile/08437218642927802667</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2232301974213299528.post-2337068382890211436</id><published>2007-02-21T19:56:00.000-05:00</published><updated>2007-02-21T20:14:29.275-05:00</updated><title type='text'>Ignorance of merchants and what it's costing you!</title><content type='html'>A new article on Slashdot.&lt;br /&gt;BTW, if you aren't reading Slashdot, you need to.&lt;br /&gt;&lt;br /&gt;"A &lt;a href="http://www.boston.com/business/globe/articles/2007/02/19/stop__shop_reports_credit_data_was_stolen/"&gt;scheme to steal customers' credit and debit card information&lt;/a&gt; at a New England supermarket chain highlights a little-understood fact about credit card security: &lt;a href="http://www.computerworld.com/blogs/node/5018"&gt;Customers still think that the credit-card companies have to eat fraudulent charges&lt;/a&gt;, but since the &lt;a href="https://www.pcisecuritystandards.org/tech/"&gt;PCI DSS standards&lt;/a&gt; were adopted, it's actually the &lt;a href="http://www.computerworld.com/blogs/node/5026"&gt;merchant banks and merchants who have to pay up&lt;/a&gt;. And, according to the blogger writing in the latter article, it's a good thing." "The main reason PCI exists is that there are tens of thousands of merchants who don't understand the basics of information security and weren't even taking the very minimum steps to secure their networks and the credit card information they stored... PCI pushes that burden downstream and forces merchants to... put in a properly configured firewall, encrypt sensitive information and maintain a minimum security stance or be fined by their merchant banks... [T]he credit card companies have taken the bulk of the financial burden off of themselves and placed it on the merchants, which is where much of it belongs...'"&lt;br /&gt;&lt;br /&gt;Amazing!&lt;br /&gt;The small to medium business's are just RIPE for enterprising security practitioners to do work for and it's really quite an untapped market!&lt;br /&gt;Then again, I hear time and again. "No one wants to hack us! We're the little guys! They only want the huge companies!"&lt;br /&gt;Remember those words. As a security practitioner you will hear them often and loud.&lt;br /&gt;They simply don't want to spend a nickel preventing what they don't see as a problem, until it happens to them.&lt;br /&gt;Why isn't the IT Security industry targeting them with an educational campaign?&lt;br /&gt;&lt;br /&gt;The problem is, yes, the credit card companies are shifting the financial burdens to the merchants. But, this protects them with only the byproduct of protecting us. Not the intention at all. Merely a benefit.&lt;br /&gt;I really have yet to see where we are being implicitly protected.&lt;br /&gt;Why aren't we?&lt;br /&gt;Because there isn't a profit margin in doing so and the lawmakers aren't interested in creating real protections for consumers.&lt;br /&gt;So again, here we are in the leaky rowboat.&lt;br /&gt;But again, the end of the month figures look great!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2232301974213299528-2337068382890211436?l=securityrantsblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://securityrantsblog.blogspot.com/feeds/2337068382890211436/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2232301974213299528&amp;postID=2337068382890211436&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default/2337068382890211436'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default/2337068382890211436'/><link rel='alternate' type='text/html' href='http://securityrantsblog.blogspot.com/2007/02/ignorance-of-merchants-and-what-its.html' title='Ignorance of merchants and what it&apos;s costing you!'/><author><name>Mark Reinertson</name><uri>http://www.blogger.com/profile/08437218642927802667</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2232301974213299528.post-4453551796267582785</id><published>2007-02-19T08:58:00.000-05:00</published><updated>2007-02-19T09:38:05.526-05:00</updated><title type='text'>The myth of security.</title><content type='html'>First post!&lt;br /&gt;Finally, what I couldn't do on Slashdot. :)&lt;br /&gt;&lt;br /&gt;So, with that out of the way...&lt;br /&gt;&lt;br /&gt;My name is Mark &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;Reinertson&lt;/span&gt;. I'm an IT Security practitioner in the Metro Detroit area.&lt;br /&gt;How dull, right?&lt;br /&gt;&lt;br /&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;Ok&lt;/span&gt;, on with the rants. This is called Security Rants for a reason.&lt;br /&gt;Here we go.&lt;br /&gt;&lt;br /&gt;At &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;Defcon&lt;/span&gt; 14, just this past summer in &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;Las&lt;/span&gt; Vegas, I got to ask the "Meet the Feds" panel a very important question.&lt;br /&gt;What is the government doing or going to do to &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_4"&gt;safeguard&lt;/span&gt; our personal financial data when it is being sent overseas? Bearing in mind that, we the people, are the data owners. The corporations are merely the data stewards.&lt;br /&gt;The reply you ask?&lt;br /&gt;I was told "We don't tell corporations what to do".&lt;br /&gt;WHAT??? Wait just one second there! Since when does the federal government NOT tell corporate &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_5"&gt;America&lt;/span&gt; what they can and cant do???&lt;br /&gt;Last time I checked, it was government of the people, for the people, by the people!&lt;br /&gt;NOT, of a few people on a board of directors, by a few people on a board of directors, and for a few people on a board of directors!&lt;br /&gt;The idea of our personal financial data being sent overseas with virtually zero &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_6"&gt;safeguards&lt;/span&gt; scares me to death! What is going to prevent mass identity theft?&lt;br /&gt;This has the potential for disaster that makes 9/11 look like a drop in the bucket!&lt;br /&gt;But, the month end figures look great!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2232301974213299528-4453551796267582785?l=securityrantsblog.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default/4453551796267582785'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2232301974213299528/posts/default/4453551796267582785'/><link rel='alternate' type='text/html' href='http://securityrantsblog.blogspot.com/2007/02/myth-of-security.html' title='The myth of security.'/><author><name>Mark Reinertson</name><uri>http://www.blogger.com/profile/08437218642927802667</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry></feed>
