tag:blogger.com,1999:blog-53580572359024862842009-03-05T13:41:59.741-06:00Security Karma"because no good deed goes unpunished..."Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.comBlogger60125tag:blogger.com,1999:blog-5358057235902486284.post-63348206359574115502009-03-05T13:41:00.001-06:002009-03-05T13:41:59.806-06:00Sometimes your security depends if you read from the bottom up or the top downI just noticed the following on my portal page and I thought it was funny so of course I'm sharing.<br /> <br /> <div class="separator" style="clear: both; text-align: center;"><a href="http://3.bp.blogspot.com/_YM_k6IgTR7E/SbApPbPTjNI/AAAAAAAAELM/20UlIiH_d2w/s1600-h/twitter-sec-lol.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_YM_k6IgTR7E/SbApPbPTjNI/AAAAAAAAELM/20UlIiH_d2w/s320/twitter-sec-lol.png" style="cursor: move;" /></a></div><br /> <br /> <div style="text-align: left;">As with everything else on the Internet, use <a href="http://twitter.com/">twitter</a> and <a href="http://twitpay.me/">twitpay </a>at your own risk... I use twitter and love it but wouldn't go near twitpay with someone else's money let alone mine.</div><blockquote></blockquote><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-6334820635957411550?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com0tag:blogger.com,1999:blog-5358057235902486284.post-60214331925921384982008-11-14T10:00:00.002-06:002008-11-14T10:07:51.906-06:00Internet thieves make big money stealing corporate infoSometimes I'm asked what keeps me up at night as an IT security professional... my answer is almost always "what I don't know." After I allow the confused look on their faces to pass I explain that in the realm of security we put very elaborate and expensive controls in place and then hope they never really get used. More quizzed looks ensue (you can probably tell I have fun with this) before I begin explaining myself.<br /> <br /> Antivirus, NIDPS, WAF, NAC, DLP, IP Firewalls, Web Proxies, etc. are all great controls and protect against most known and some unknown attack vectors and for the most part they work. What scares me and keeps me up at night are the -1 day attacks (less than zero) that will pass by all controls. <a href="http://www.usatoday.com/money/industries/technology/2008-11-11-thieves-cyber-corporate-data_N.htm">This story</a> in USA Today got me thinking about how easy it is for determined attackers to slip right by all my controls and begin pumping data out of my network. From the article:<br /> <blockquote>The virus swiftly located — and infected — some 300 other workstation PCs, silently copying the contents of each computer's MyDocuments folder. It transmitted the data across the Internet to a gang of thieves operating out of Turkey.</blockquote>They infected system zero by posting an innocent-looking link on a trusted employee-only message board. Reading articles and hearing horror stories from colleagues about the threats they didn't know about until after the damage was done is what keeps me up at night. The stuff I know about? I have lots of toys for that stuff. :)<br /> <br /> <span style="font-weight: bold;">Related Articles</span><br /> <ul><li><a href="http://www.boston.com/business/articles/2008/08/06/11_charged_with_massive_id_theft/">11 charged with massive ID theft</a></li> <li><a href="http://www.eweek.com/c/a/Security/Auto-Parts-Retailer-Notifies-Customers-of-Network-Breach/">Auto Parts Retailer Notifies Customers of Network Breach</a></li> <li><a href="http://www.networkworld.com/news/2008/111208-ufla.html?hpg1=bn">University of Florida discloses patient-record data breach</a></li> <li><a href="http://www.wnd.com/index.php?fa=PAGE.view&amp;pageId=80832">The most insidious IT security risk</a></li> <li><a href="http://draft.blogger.com/goog_1226676334347">A Huge Cache of Stolen Financial Data</a></li> <li><a href="http://money.cnn.com/news/newsfeeds/articles/djf500/200811111647DOWJONESDJONLINE000529_FORTUNE5.htm">Express Scripts Clients Receive Threats To Release Data</a></li> <li><a href="http://www.infoworld.com/news/feeds/08/05/07/5-ways-insiders-exploit-your-network.html">5 ways insiders exploit your network</a></li> </ul><blockquote></blockquote><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-6021433192592138498?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com1tag:blogger.com,1999:blog-5358057235902486284.post-69994180851134540192008-11-11T11:11:00.001-06:002008-11-11T12:28:59.951-06:00SANS lists the "coolest" infosec jobsI caught <a href="http://www.gcn.com/online/vol1_no1/47421-1.html?page=1">this article</a> over at <a href="http://www.gcn.com/">Government Computer News</a> that reported on a SANS Institute survey of the "coolest" information security jobs. Although the article is about the coolest ten public sector information security jobs it does also list the top ten coolest private sector infosec jobs.<br /> <br /> With further ado, for your reading pleasure, the ten coolest private sector infosec jobs:<br /> <blockquote>1. (tie) System, Network, and/or Web penetration tester<br /> 1. (tie) Information security crime investigator/forensics expert<br /> 3. Forensics analyst<br /> 4. Vulnerability researcher<br /> 5. Application penetration tester<br /> 6. Security architect<br /> 7. CISO/ISO or director of security<br /> 8. (tie) Incident response, incident handler<br /> 8. (tie) Sworn law enforcement officer specializing in information security crime<br /> 10. Security evangelist</blockquote>Since I didn't participate in the survey, and you didn't ask I thought I'd give you my top ten coolest infosec jobs:<br /> <blockquote>1. Security architect<br /> 2. Penetration tester (I don't differentiate between applications, networks, and systems)<br /> 3. (tie) Security analyst<br /> 3. (tie) Security evangelist<br /> 5. CISO or director of security<br /> 6. (tie) Vulnerability researcher<br /> 6. (tie) Forensic expert<br /> 8. Network security engineer<br /> 9. Vulnerability assessment analyst<br /> 10. Security auditor</blockquote>As you can tell I am at the crossroads between management and technology. It is my opinion that technical security controls without enterprise architecture and governance is a really good way to throw good money after bad... a topic that I will be visiting in a post in the near view.<br /> <blockquote></blockquote><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-6999418085113454019?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com1tag:blogger.com,1999:blog-5358057235902486284.post-62841763374055890632008-11-10T09:00:00.000-06:002008-11-10T09:00:01.019-06:00PING?<blockquote>PONG!</blockquote>I've been gone for a little while... over two months to be exact. TO say that I have been incredibly busy and distracted over the past two months would be an understatement. I've been busy with my HOA duties, building a nursery, and a work schedule that had me busy from dawn to dusk and completely wiped out by the time I would normally start writing. I have had to mark about 2,500 emails as read (sorry if your email got caught in the wash) and pretty much have disappeared from my digital life.<br /> <br /> I am going to attempt to dip my toe back into the tidal pool of infosec blogging (and the rest of my digital life) over the next few weeks. The past two months has placed me elbow-deep in project management, enterprise architecture &amp; strategy, as well as the day-to-day tactical obligations of my job. I will try to start writing some original posts regarding my thoughts and lessons learned in the areas of enterprise security architecture, security project management, budgeting for security, the difficulty in designing NAC and DLP solutions in an enormous and diverse environment... but for now I will say "welcome back" to myself and I look forward to writing again.<br /> <blockquote></blockquote><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-6284176337405589063?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com0tag:blogger.com,1999:blog-5358057235902486284.post-56817564885470370482008-09-03T09:30:00.000-05:002008-09-03T09:30:01.334-05:00IT pros name security top concern, security pros say huh?<p><a href="http://www.informationweek.com/news/security/management/showArticle.jhtml?articleID=210300074">Ahem</a>.</p> <blockquote> <p>The Computing Technology Industry Association (CompTIA) announced this week that its Web poll, conducted from June 3 through Aug. 25, showed that one-third of IT professionals believe that securing their networks and data is their biggest concern.</p> </blockquote> <p>I don't want to seem skeptical and perhaps the IT pros I have dealt with are the exceptions... but are these the same IT pros that push poor design, complain about preventative security measures, argue about how their app is different, tell me &quot;it's ok, really&quot;, and slash my budget? Not that I'm complaining... I'm just sayin'.</p> <p>But then again, security was the top concern of 33% of those surveyed; so perhaps I just deal with the other 66% 99% of the time. ;)</p> <div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-5681756488547037048?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com0tag:blogger.com,1999:blog-5358057235902486284.post-63349190240276033502008-09-01T09:30:00.001-05:002008-09-01T09:30:00.655-05:00Happy Labor Day<a href="http://lh3.ggpht.com/djglass/SLmPppI7q3I/AAAAAAAAD_U/_uij_Anj-88/s1600-h/LaborDay%5B5%5D.gif"><img align="left" alt="Labor Day" border="0" height="239" src="http://lh4.ggpht.com/djglass/SLmPqNZiQiI/AAAAAAAAD_Y/qU0csfAdSyk/LaborDay_thumb%5B3%5D.gif?imgmax=800" style="border-bottom: 0px; border-left: 0px; border-right: 0px; border-top: 0px;" title="Labor Day" width="244" /></a> Happy <a href="http://en.wikipedia.org/wiki/Labor_Day_(United_States)">Labor Day</a> weekend for all my American readers. For all my foreign readers, happy <a href="http://en.wikipedia.org/wiki/May_Day">May Day</a>… sorry I’m a four months late. Now get back to work.<br /> In the US we use the day to catch up on napping, outdoor activities (it’s the last holiday of summer), American football, and eating. In much of the rest of the world May Day is a day of <a href="http://en.wikipedia.org/wiki/Taksim_Square_massacre">celebrating workers rights</a> and is often filled with protests, marches, speeches, and the <a href="http://en.wikipedia.org/wiki/Taksim_Square_massacre">occasional massacre</a>.<br /> That being said: enjoy the day, comrades!<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-6334919024027603350?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com0tag:blogger.com,1999:blog-5358057235902486284.post-46961966103866160362008-08-29T10:30:00.000-05:002008-08-29T10:30:00.552-05:00Password reset unsafe! Personal information easy to discover!Ok, I admit... the typical reader of <a href="http://www.sciam.com/">Scientific American</a> are probably not the most Internet-savvy folks out there and I actually loved Herbert H. Thompson's article "<a href="http://www.sciam.com/article.cfm?id=anatomy-of-a-social-hack&amp;print=true">How I Stole Someone's Identity</a>." Mr. Thompson does a good job explaining how to footprint a person online and begin compromising account after account of theirs simply by using the password reset feature and "security questions" that are used to validate identity.<br /> <blockquote>For many of us, the abundance of personal information we put online combined with the popular model of sending a password reset e-mail has our online security resting unsteadily on the shoulders of one or two e-mail accounts. In Kim's case some of that information came from a blog, but it could just as easily have come from a MySpace page, a sibling's blog (speaking of their birthday, mom's name, etcetera) or from any number of places online.</blockquote>To someone that has been around information security for a while now, none of this is news. This is actually a little old-school footprint and crack. The problem is: in the old days, the hacker would have to go through great lengths to investigate their marks. As this article shows, those days are gone and now with a simple web search we can find out almost everything about a person. All of our digital shadows are getting longer and keeping track of every account we've signed up for is getting more and more difficult.<br /> <blockquote>It's also critical to remember that once you put data online, it's almost impossible to delete it later. The more you blog about yourself, the more details you put in your social networking profiles, the more information about you is being archived, copied, backed up and analyzed almost immediately. Think first, post later.</blockquote>Great article and well worth the read.<br /> <br /> I'll be posting more about the new risk model in the 2.0 world soon.<br /> <blockquote></blockquote><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-4696196610386616036?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com0tag:blogger.com,1999:blog-5358057235902486284.post-58757932001008278712008-08-28T09:30:00.000-05:002008-08-28T09:30:00.450-05:00TSA takes security to the slopes, travelers run into treesMichael Chertoff must have gone skiing and thought of this little beauty. If you have flown through DFW and a handful of other airports across the country you may have noticed that there will soon be three lines to pass through airport security. Taking a queue from ski resorts travelers will now have to decide between black diamonds, blue squares, green dots, and purple horseshoes.<br /> <br /> <div class="separator" style="clear: both; text-align: center;"><a href="http://2.bp.blogspot.com/_YM_k6IgTR7E/SLYWDPv5jfI/AAAAAAAAD_A/yaqx78RSH4E/s1600-h/Picture+1.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" src="http://2.bp.blogspot.com/_YM_k6IgTR7E/SLYWDPv5jfI/AAAAAAAAD_A/Oh6j-3SfE1o/s400-R/Picture+1.png" /></a></div><br /> Now I won't chide the TSA too much for trying... but let's be honest for a second here. Like skiing, how many blue square travelers will think they're good enough to take on the black diamond line only to clog things up by forgetting their liter of water in the carry on and a pen knife in their pocket. What then? Blue square folks holding up the black diamond line, black diamond travelers in the green dot line because it's empty, and green dot travelers wondering where the lift is. So... basically... what we have now. Now go hit the slopes!<br /> <br /> More info about black diamond program <a href="http://www.tsa.gov/approach/black_diamond.shtm">here</a>.<br /> <br /> <blockquote></blockquote><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-5875793200100827871?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com2tag:blogger.com,1999:blog-5358057235902486284.post-22713878168489064942008-08-27T15:30:00.002-05:002008-08-27T21:23:44.391-05:0010 < 8,000,000<a href="http://www.bestwestern.com/">Best Western</a> has let it be known that the <a href="http://www.securitykarma.com/2008/08/over-8-million-best-western-records.html">compromise</a> <a href="http://www.sundayherald.com/news/heraldnews/display.var.2432225.0.revealed_8_million_victims_in_the_worlds_biggest_cyber_heist.php">that</a> <a href="http://www.dailymail.co.uk/news/worldnews/article-1048861/Eight-million-people-risk-ID-fraud-credit-card-details-stolen-hotel-chain-hackers.html">was</a>&nbsp;<a href="http://blogs.pcworld.com/staffblog/archives/007555.html">widely</a> <a href="http://www.telegraph.co.uk/news/uknews/2613095/Hackers-steal-details-of-millions-of-Best-Western-hotel-guests.html">reported</a>&nbsp;was contained to only 10 guests that stayed at one of the chain's many hotels in Germany.<br /> <blockquote>That's three fewer than the 13 customer records that Best Western International Inc. initially said had been exposed, and a far cry from the 8 million stolen records reported by the Glasgow Sunday Herald, a Scottish newspaper that broke the news of the breach on Sunday.</blockquote>So not so bad... this is great news (unless you are one of the ten people about to get letters and free credit monitoring).<br /> <h3>Original Story</h3><ul><li><a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9113499&amp;source=NLT_SEC&amp;nlid=38">Best Western says data breach even smaller than first thought</a><br /> </li> </ul><blockquote></blockquote><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-2271387816848906494?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com0tag:blogger.com,1999:blog-5358057235902486284.post-91634073756108203202008-08-27T10:00:00.001-05:002008-08-27T10:00:02.285-05:00The Internet is broken<div class="separator" style="clear: both; text-align: center;"><a href="http://3.bp.blogspot.com/_YM_k6IgTR7E/SLTJCGa8ffI/AAAAAAAAD-4/fewPlCgA8ck/s1600-h/gateway.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_YM_k6IgTR7E/SLTJCGa8ffI/AAAAAAAAD-4/F_P_uh01wTI/s200-R/gateway.jpg" /></a></div>This isn't exactly a "vulnerability" and has been around for years... but it is starting to get used more and more and is begging to get some press. <a href="http://blog.wired.com/27bstroke6/2008/08/revealed-the-in.html">Threat Level</a> over at <a href="http://www.wired.com/">Wired</a> has a nice summary and explanation of <a href="http://en.wikipedia.org/wiki/IP_hijacking">IP Hijacking</a> and how it's getting more play today and there isn't much anyone can do about it.<br /> <blockquote>That's what occurred earlier this year when Pakistan Telecom inadvertently hijacked YouTube traffic from around the world. The traffic hit a dead-end in Pakistan, so it was apparent to everyone trying to visit YouTube that something was amiss.<br /> <br /> Pilosov's innovation is to forward the intercepted data silently to the actual destination, so that no outage occurs.</blockquote>This hack is a symptom of a much bigger issue. The real problem is that the Internet is built and depends on protocols that were created in <a href="http://tools.ietf.org/html/rfc791">1980 (IPv4)</a>, <a href="http://tools.ietf.org/html/rfc821">1982 (SMTP)</a>, <a href="http://tools.ietf.org/html/rfc920">1984 (DNS)</a>, <a href="http://tools.ietf.org/html/rfc1771">1995 (BGP)</a>, etc. and we (the IT community) have been stacking more complexity on top of very simplistic and insecure infrastructure.<br /> <br /> Problems such as <a href="http://en.wikipedia.org/wiki/E-mail_spam">spam</a>, <a href="http://en.wikipedia.org/wiki/Ip_spoofing">IP spoofing</a>, <a href="http://en.wikipedia.org/wiki/DNS_cache_poisoning">DNS cache poisoning</a>, <a href="http://en.wikipedia.org/wiki/Arp_poisoning">ARP poisoning</a>, etc. are very effective and hard to detect or stop because the protocols themselves have little to no built-in security mechanisms. Why hasn't the industry fixed this? There is too much money in <span style="font-weight: bold;"><span style="font-size: medium;">not</span></span> fixing the problem. Network hardware vendors such as <a href="http://www.cisco.com/">Cisco</a>, <a href="http://www.juniper.net/">Juniper</a>, <a href="http://www.3com.com/">3Com</a>, <a href="http://www.nortel.com/">Nortel</a>, <a href="http://www.alcatel-lucent.com/">Lucent</a>, etc. have no incentive to fix the inherent problems since they make too much money on selling security devices, software, and services that slap band-aids on the problems, slowing down but never stopping attacks. Once the attacks pick up again or a new threat emerges the vendors are ready with more&nbsp;devices, software, and services... more band-aids.<br /> <blockquote>ISPs... have been holding their breath, "hoping that people don’t discover (this) and exploit it."</blockquote>How do we fix this? We need the users of these products big and small to start demanding fixes to the fundamental security issues. Without monetary incentive these companies will continue to push their "fixes" upon us and leave the core infrastructure of the Internet vulnerable to attack. Until then? Keep buying band-aids, check DNS and eBGP periodically to ensure proper resolution and routing and cross your fingers.<br /> <blockquote></blockquote><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-9163407375610820320?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com0tag:blogger.com,1999:blog-5358057235902486284.post-34892705982429647282008-08-26T13:00:00.003-05:002008-08-27T11:26:01.253-05:00Seriously now, we're starting to spoil them<div class="separator" style="clear: both; text-align: center;"><a href="http://2.bp.blogspot.com/_YM_k6IgTR7E/SLRGQdhmHfI/AAAAAAAAD-w/nSIBodL-gt0/s1600-h/hard-drive.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"><img border="0" src="http://2.bp.blogspot.com/_YM_k6IgTR7E/SLRGQdhmHfI/AAAAAAAAD-w/wVMydr4KJzg/s200-R/hard-drive.jpg" /></a></div><a href="http://www.theregister.co.uk/2008/08/26/more_details_lost/">Hackers are going to get lazy at this rate in Britain</a>.<br /> <span class="Apple-style-span" style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; border-collapse: collapse; font-family: Helvetica;"><blockquote>A computer hard disc containing one million sets of bank details was bought on eBay for just £35.<br /> <br /> The secondhand PC contained details of customers from American Express, NatWest and Royal Bank of Scotland. The files included names, addresses, sort codes, account numbers, credit card numbers, mobile phone numbers, mothers' maiden names and even scans of signatures - more than enough for an identity thief.<br /> </blockquote></span><br /> <blockquote></blockquote><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-3489270598242964728?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com0tag:blogger.com,1999:blog-5358057235902486284.post-77190088694852790212008-08-26T10:30:00.002-05:002008-08-26T10:30:00.919-05:00Why Red Hat should be ashamed<div class="separator" style="clear: both; text-align: center;"><a href="http://1.bp.blogspot.com/_YM_k6IgTR7E/SLDQngiEopI/AAAAAAAAD9o/z6eOw1i7Khc/s1600-h/log-in_corner_shadowman.gif" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"><img border="0" src="http://1.bp.blogspot.com/_YM_k6IgTR7E/SLDQngiEopI/AAAAAAAAD9o/cLd07KrtZmY/s200-R/log-in_corner_shadowman.gif" /></a></div>This is big. Real big. As a former <a class="zem_slink" href="http://www.redhat.com/" rel="homepage" title="Red Hat">Red Hat</a> Enterprise <a class="zem_slink" href="http://en.wikipedia.org/wiki/Linux" rel="wikipedia" title="Linux">Linux</a> (RHEL) admin and dabbler in things <a class="zem_slink" href="http://fedoraproject.org/" rel="homepage" title="Fedora (operating system)">Fedora</a> I find this news very disturbing. I'm not upset that servers at RH got compromised... that happens. What shouldn't happen is a breach of the infrastructure servers that manage your package signing. When trust is a key part of your business model (who is going to purchase an OS let alone download and install packages they can't trust?) keeping encryption management servers protected as much if not more than your financial databases.<br /> <br /> Certificate Authority (CA) servers, key management systems, and certificate management systems should among be the most difficult systems on your network to access, no exception. They shouldn't run web servers or the public Internet (or your Intranet for that matter). The NIDS/NIPS systems should be cranked up and watching for the baddies and your firewalls should be blocking all inbound and outbound communication other than only what is absolutely needed to function in the environment. Many businesses keep these servers off the grid (no network connectivity) in a secured room and all package signing is done via sneakernet (carrying data to be signed on physical media into the room). <br /> <br /> <div class="separator" style="clear: both; text-align: center;"><a href="http://1.bp.blogspot.com/_YM_k6IgTR7E/SLDQtyAvdFI/AAAAAAAAD9w/QzFsM675Eig/s1600-h/fedora.jpg" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://1.bp.blogspot.com/_YM_k6IgTR7E/SLDQtyAvdFI/AAAAAAAAD9w/WnJMKRMX9T8/s200-R/fedora.jpg" /></a></div>Red Hat has recreated the keys for Fedora packages but there was no mention if they are creating new RHEL keys. If I were running RHEL servers I would be compiling <a class="zem_slink" href="http://en.wikipedia.org/wiki/OpenSSH" rel="wikipedia" title="OpenSSH">OpenSSH</a> from source at this point. This is coming from someone who doesn't typically fall into the "Henny-Penny" category of infosec professionals. I like to temper my paranoia with a healthy dose of reality. However, on this one I think I am upset that Red Hat's infrastructure is architected in such a way as to let this happen and can't trust they aren't still rooted in some way. I have a feeling many security-conscience system administrators will be looking sideways at any and all new packages from Red Hat and Fedora for the next few months.<br /> <br /> I am harsh because I love. I have run Red Hat since 1998 (5.2) and still run a Fedora laptop at home and use my RHEL 4 VM a few times a week at work. I have fought long and hard to get management sign-off at various jobs to bring Linux into the datacenter and hate when the community gives Microsoft ammunition for white papers.<br /> <br /> <h3>Related Articles</h3><a href="http://www.infoworld.com/article/08/08/22/Red_Hat_admits_breach_of_its_servers_Fedora_1.html?source=rss&amp;url=http://www.infoworld.com/article/08/08/22/Red_Hat_admits_breach_of_its_servers_Fedora_1.html">Red Hat admits breach of its servers, Fedora</a><br /> <a href="http://www.hackaday.com/2008/08/23/red-hat-confirms-security-breach/">Red Hat confirms security breach</a><br /> <a href="http://news.cnet.com/8301-1009_3-10023565-83.html?hhTest=1&amp;part=rss&amp;subj=news">Red Hat, Fedora servers compromised</a><br /> <a href="http://www.theregister.co.uk/2008/08/22/red_hat_systems_hacked/">Red Hat hack prompts critical OpenSSH update</a><br /> <blockquote></blockquote><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-7719008869485279021?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com2tag:blogger.com,1999:blog-5358057235902486284.post-24753760501407514782008-08-25T15:30:00.001-05:002008-08-25T15:39:07.783-05:00Best Western refutes breach claims<a href="http://2.bp.blogspot.com/_YM_k6IgTR7E/SLMYI5LFRvI/AAAAAAAAD-Q/tJoCgbRcjq0/s1600-h/oops.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"><img border="0" src="http://2.bp.blogspot.com/_YM_k6IgTR7E/SLMYI5LFRvI/AAAAAAAAD-Q/ij2Wr3h0m9U/s200-R/oops.jpg" /></a>As a follow up to my post yesterday "<a href="http://www.securitykarma.com/2008/08/over-8-million-best-western-records.html">Over 8 million Best Western records stolen and sold to Russian mob</a>,"&nbsp;<a href="http://www.bestwestern.com/">Best Western</a>&nbsp;is&nbsp;reporting that only 13 records (not 8,000,000) may have been exposed. A company spokesman states:<br /> <blockquote>There was one instance of suspicious activity at a single hotel with respect to 13 guests, who are being notified. We are working with the FBI and international authorities to investigate the source of the other claims, which were never presented to us for investigation prior to publication of the Herald story. We have found no suspicious activity to support them.</blockquote>Best Western points to their compliance with the PCI DSS as further proof that the allegations aren't true. Now everything they are saying may be true, only one hotel was involved in the breach, and only 13 records were compromised, and that they are fully PCI DSS compliant. However, with statements such as<br /> <blockquote>... our most recent internal review was conducted in August 2008, as was our most recent external test and review. Both evaluations showed Best Western to be compliant with PCI DSS.&nbsp;</blockquote>... it sounds as if they are relying on the fact they are PCI compliant as proof that such an audacious hack (the 8 million, not 13) can not happen. It can. Hannaford was "compliant" with the DSS but there were 4.2 million credit card numbers involved in that breach.&nbsp;That brings up the larger topic of compliance vs. best practices... which will have to wait for a different post.<br /> <br /> In the end,&nbsp;&nbsp;I hope BW is correct in their investigation and the reports were wrong. I've stayed at numerous BW hotels over the past few years myself so I'm a stakeholder of sorts in all this.<br /> <br /> <h3>Related Articles</h3><ul><li><a href="http://www.marketwatch.com/news/story/best-western-responds-sunday-herald/story.aspx?guid={A87F9682-AC67-4803-A135-B6ACF42C0956}&amp;dist=hppr">Best Western Responds to Sunday Herald Story Claiming Security Breach</a></li> <li><a href="http://computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=security&amp;articleId=9113402&amp;taxonomyId=17&amp;intsrc=kc_top">Best Western refutes story claiming 8 million customer records were breached</a><br /> </li> <li><a href="http://www.informationweek.com/news/security/attacks/showArticle.jhtml?articleID=210200550">8 Million-Record Data Breach Claim 'Grossly Unsubstantiated,' Says Best Western </a><br /> </li> <li><a href="http://www.securitypronews.com/insiderreports/insider/spn-49-20080825BestWesternHackWorstExaggerationInHistory.html">Best Western Hack Worst Exaggeration In History?</a><br /> </li> </ul><blockquote></blockquote><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-2475376050140751478?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com0tag:blogger.com,1999:blog-5358057235902486284.post-42819875489069678482008-08-25T10:00:00.004-05:002008-08-25T10:05:03.476-05:00Congress to DHS - Terror Watch List needs major overall<div xmlns="http://www.w3.org/1999/xhtml">Interesting story in <a class="zem_slink" href="http://www.wsj.com/" rel="homepage" title="The Wall Street Journal">the Wall Street Journal</a> regarding a Congressional report finding that the TWL is:<br /> <blockquote>...hobbled by technology challenges, and the $500 million program designed to upgrade it is on the verge of collapse, according to a preliminary congressional investigation.</blockquote>Interesting fact I didn't know... the TWL DB was built by <a class="zem_slink" href="http://www.lockheedmartin.com/" rel="homepage" title="Lockheed Martin">Lockheed Martin</a> (I know when I think database I think Lockheed... WTF?) back in 2001 and is unable to do keyword searches... they have a person build a query. I'm not kidding. I'll repeat. The <a class="zem_slink" href="http://en.wikipedia.org/wiki/United_States_Department_of_Homeland_Security" rel="wikipedia" title="United States Department of Homeland Security">Department of Homeland Security</a> builds the <a class="zem_slink" href="http://en.wikipedia.org/wiki/No_Fly_List" rel="wikipedia" title="No Fly List">Terror Watch List</a> by running a friggin' query.<br /> <br /> <h3>Related Articles</h3><ul><li><a href="http://online.wsj.com/article/SB121937117186362585.html?mod=googlenews_wsj">Flaws Found In Watch List For Terrorists - Wall Street Journal</a></li> <li><a href="http://www.securitymanagement.com/news/congress-finds-critical-failures-affecting-terror-watch-list-004511">Congress Finds Critical Failures Affecting Terror Watch List - Securty Management </a><br /> </li> <li><a href="http://science.house.gov/press/PRArticle.aspx?NewsID=2289">Technical Flaws Hinder Terrorist Watch List; Congress Calls for Investigation - House Science and Technology Committee</a></li> <li><a href="http://democrats.science.house.gov/Media/File/AdminLetters/bm_InspectorGeneralMaquire_terrorwatchlist_8.21.08.pdf">Miller letter to Inspector General Maquire Regarding Technical Flaws in Terrorist Watch List [pdf]</a></li> <li><a href="http://democrats.science.house.gov/Media/File/Commdocs/Staff_Memo_toBM_terror_watch_8.21.08.pdf">Memo to Subcommittee Chairman Miller [pdf]</a><br /> </li> </ul><span id="ArticleDetailsCtrl_LongVersionLabel"></span><a href="http://democrats.science.house.gov/Media/File/Commdocs/Staff_Memo_toBM_terror_watch_8.21.08.pdf"></a><br /> <blockquote></blockquote></div><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-4281987548906967848?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com0tag:blogger.com,1999:blog-5358057235902486284.post-22312225537648459242008-08-24T19:30:00.003-05:002008-08-24T20:11:10.957-05:00Over 8 million Best Western records stolen and sold to Russian mob<div class="separator" style="clear: both; text-align: center;"><a href="http://3.bp.blogspot.com/_YM_k6IgTR7E/SLIEbTQ1JXI/AAAAAAAAD-I/I3WZc0TMtf4/s1600-h/best_western_logo.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_YM_k6IgTR7E/SLIEbTQ1JXI/AAAAAAAAD-I/_SlFEUnrpqk/s200-R/best_western_logo.gif" /></a></div>Looks like this one is going to be up there with the <a href="http://www.tjx.com/">TJX</a> and <a href="http://www.hannaford.com/">Hannaford</a> breaches. The <a href="http://www.telegraph.co.uk/">London Telegraph</a> is <a href="http://www.telegraph.co.uk/news/uknews/2613095/Hackers-steal-details-of-millions-of-Best-Western-hotel-guests.html">reporting</a> that over 8 million customer accounts have been stolen from <a href="http://www.bestwestern.com/">Best Western</a> and sold to the Russian mafia. This story is still breaking but from the article:<br /> <blockquote>It is believed an Indian hacker succeeded in bypassing the security software and placing a Trojan virus on one of the firm's machines used for reservations.<br /> <br /> The next time a staff member logged in, his or her username and password were collected, stored then put up for sale on a website operated by a branch of the Russian mafia.<br /> <br /> The stolen data includes a range of private information such as home addresses, telephone numbers, credit card details and place of employment.<br /> <br /> Best Western fixed the security breach on Friday after being alerted by a Sunday newspaper, which had discovered the crime.</blockquote><br /> A Sunday newspaper discovered the crime? Jeez. I'm sure there will be much, much more to come about this one.<br /> <br /> Original Story:&nbsp;<a href="http://www.telegraph.co.uk/news/uknews/2613095/Hackers-steal-details-of-millions-of-Best-Western-hotel-guests.html">Hackers steal details of millions of Best Western hotel guests</a><br /> <blockquote></blockquote><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-2231222553764845924?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com0tag:blogger.com,1999:blog-5358057235902486284.post-57621361311084591072008-08-24T11:30:00.007-05:002008-08-25T10:06:11.783-05:00They have the technology, but no security<a href="http://4.bp.blogspot.com/_YM_k6IgTR7E/SLGTDvnOjTI/AAAAAAAAD-A/09b5T_MdptE/s1600-h/mod_logo.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"><img border="0" src="http://4.bp.blogspot.com/_YM_k6IgTR7E/SLGTDvnOjTI/AAAAAAAAD-A/dPCmV6ILyZA/s200-R/mod_logo.jpg" /></a>Great article in the London Times this morning entitled "<a href="http://www.timesonline.co.uk/tol/comment/columnists/guest_contributors/article4592322.ece">We have the technology, but no security</a>." Author <a class="zem_slink" href="http://en.wikipedia.org/wiki/Simon_Davies_%28privacy_advocate%29" rel="wikipedia" title="Simon Davies (privacy advocate)">Simon Davies</a> goes through the laundry list of compromises that have hit the British government over the past year and correctly comes to the conclusion that it is a lack of standards, policy, and understanding about data security that lead to a culture of carelessness.<br /> <br /> Hackers in Britain don't need to scan servers for vulnerabilities nor do they have to prepare "spear phishing" attacks to compromise desktops within the government... they just need to walk around the street and look for discarded DVDs and USB key drives. &nbsp;&nbsp;Their problems are definitely on the people and process side of the security triad (people, process, technology).<br /> <br /> I hope someone in the British government takes control of the situation and institutes an educational program coupled with a strong encryption and data access policies with the necessary technical controls to help enforcement.<br /> <br /> <h3>Related Articles</h3><ul><li><a href="http://politics.guardian.co.uk/homeaffairs/story/0,,2233519,00.html?gusrc=rss">Britain 'worst in Europe for privacy'</a></li> <li><a href="http://www.iwr.co.uk/information-world-review/news/2224554/information-thousands-prisoners">Information on thousands of prisoners missing</a></li> <li><a href="http://www.boingboing.net/2008/08/22/uk-govt-loses-4-mill.html">UK gov't loses 4 million citizens' personal info</a></li> <li><a href="http://www.guardian.co.uk/technology/2008/aug/23/security.justice?gusrc=rss">Pitfalls of miniaturisation as PA Consultancy loses prisoners' details</a></li> <li><a href="http://www.pcworld.com/businesscenter/article/150219/uk_government_spills_personal_data_of_millions.html">UK Government Spills Personal Data of Millions</a>&nbsp;</li> <li><a href="http://www.telegraph.co.uk/news/newstopics/politics/2608805/Thousands-of-personal-records-lost-each-month.html">Thousands of personal records lost each month</a>&nbsp;</li> <li><a href="http://www.guardian.co.uk/politics/2008/aug/24/justice.conservatives">Tories call for data loss prosecutions</a></li> <li><a href="http://www.computerworld.com.au/index.php/id;50110485">UK gov't loses personal data on 4M people in one year</a><br /> </li> </ul><blockquote></blockquote><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-5762136131108459107?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com1tag:blogger.com,1999:blog-5358057235902486284.post-53657864909512814962008-08-23T22:00:00.004-05:002008-08-24T13:49:44.433-05:00a wii haiku<div class="mobile-photo"></div><div style="font-family: Helvetica; font-size-adjust: none; font-size: 12px; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; margin: 0px;"><div style="text-align: center;"><span style="font-size: x-large;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="color: #666666;">a cord pulled too hard<br /> </span></span></span></div></div><div style="font-family: Helvetica; font-size-adjust: none; font-size: 12px; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; margin: 0px;"><div style="text-align: center;"><span style="font-size: x-large;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="color: #666666;">the wii falls down </span></span></span><span style="font-size: x-large;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="color: #666666;"> crashes breaks </span></span></span></div></div><div style="font-family: Helvetica; font-size-adjust: none; font-size: 12px; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; margin: 0px;"><div style="text-align: center;"><span style="font-size: x-large;"><span style="font-family: 'Trebuchet MS', sans-serif;"><span style="color: #666666;">my heart sinks to floor</span></span></span></div><div style="text-align: center;"></div></div><div style="font-family: Helvetica; font-size-adjust: none; font-size: 12px; font-stretch: normal; font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; margin: 0px;"></div><br /> <div class="mobile-photo"><div style="text-align: center;"><a href="http://1.bp.blogspot.com/_YM_k6IgTR7E/SLAxu2-jnxI/AAAAAAAAD9U/PxAVv05WLTQ/s1600-h/photo-719552.jpg"><img alt="" border="0" id="BLOGGER_PHOTO_ID_5237741047733526290" src="http://1.bp.blogspot.com/_YM_k6IgTR7E/SLAxu2-jnxI/AAAAAAAAD9U/PxAVv05WLTQ/s400/photo-719552.jpg" /></a></div></div><div style="text-align: center;"></div><br /> <blockquote></blockquote><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-5365786490951281496?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com0tag:blogger.com,1999:blog-5358057235902486284.post-76205610452696506852008-08-22T09:30:00.003-05:002008-08-24T13:57:06.116-05:00TSA ninja strikes, renders nine planes helpless.<div xmlns="http://www.w3.org/1999/xhtml"><div style="text-align: center;"></div><div style="text-align: center;"></div><div style="text-align: center;"></div><div style="text-align: center;"><a href="http://3.bp.blogspot.com/_YM_k6IgTR7E/SK428N7KsmI/AAAAAAAAD9I/E2ITvAp4XBE/s1600-h/TSA-NINJA.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"><img border="0" src="http://3.bp.blogspot.com/_YM_k6IgTR7E/SK428N7KsmI/AAAAAAAAD9I/xTnP3CiS-XQ/s400-R/TSA-NINJA.png" /></a></div><div class="separator" style="clear: both; text-align: left;"></div><div style="text-align: left;">From the National Security Ninjas Desk:</div><a href="http://www.abcnews.go.com/Blotter/story?id=5624381&amp;page=1">ABC News: TSA Fires Back: Blames Airline for 'Security Violation'</a><br /> <br /> I'll start with a summary from the article:<br /> <blockquote>A TSA inspector, as part of a spot security check, used a sensitive aircraft probe as a handhold to gain access to parked <a class="zem_slink" href="http://www.aa.com/content/footer/eagleOverview.jhtml" rel="homepage" title="American Eagle Airlines">American Eagle</a> planes at <a class="zem_slink" href="http://flychicago.com/Ohare/OhareHomepage.shtm" rel="homepage" title="O'Hare International Airport">Chicago's O'Hare airport</a>.</blockquote>The TSA ninja caused AE to ground nine Eagle commuter jets, causing 40 flights to be delayed, maintenance costs to repair the broken parts (they ain't cheap folks), and loads of pissed passengers.<br /> <br /> To top it off:<br /> <blockquote>TSA, however, strongly defended its inspector's actions, noting in a<br /> statement that he was able to gain interior access to seven of the nine<br /> aircraft he inspected, which was an "apparent violation of the<br /> airline's security program."</blockquote>The kicker is that the TSA is considering fining AE for the "violations." I'd like to deconstruct the argument that AE was in "violation of the airline's security program." Airplanes aren't cars and the airport tarmac isn't a Wal-Mart parking lot, in order to get onto the tarmac you must pass through... you guessed it, TSA security check-points.<br /> <br /> Furthermore, you need specialized badges, passcards, and need to be recognized by sight to get into the secured areas. Trust me... it ain't easy. So if you look like you belong, you're a familiar face, and you are out on the tarmac, most likely people will let you go on with your day because the airport is a busy, busy place and they all have things to do.<br /> <br /> I can understand if the guy bribed an Eagle shift worker for a uniform, knocked out a sleeping American Eagle security henchman standing guard outside the plane, and got inside the plane without breaking anything. Where exactly did the TSA agent gain unauthorized access in "apparent violation of the airline's security?" What they did do was walk through security checkpoints, walk into areas they are allowed to go, broke several planes so they couldn't take off, and wasted the time of a lot of hard working people.<br /> <br /> If you are reading this blog you most likely understand that insider threats are one of the largest problems facing information security today. But seriously, this is like the IT security guy complaining that he was able to hit a server with a hammer when he has badge access to the datacenter and keys to the cage and rack where the server was located... it's just not a fair assessment.<br /> <br /> The TSA should stick to what it's best at: <a href="http://www.flickr.com/photos/cjd/1418632004/">frisking nuns</a>, <a href="http://consumerist.com/5039530/tsa-martinet-claims-her-unpublished-rules-trump-real-ones">making up rules as they go along</a>, <a href="http://www.tsa.gov/blog/2008/05/you-asked-for-ityou-got-it-millimeter.html">peeking straight through our clothing</a>, and <a href="http://www.boingboing.net/2008/01/09/tsa-searches-detains.html">detaining five year old children</a>. </div><br /> <fieldset class="zemanta-related"><br /> <legend class="zemanta-related-title">Related Articles</legend><br /> <ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a href="http://www.gadling.com/2008/08/20/tsa-inspector-damages-planes-and-causes-major-flight-delays/">TSA inspector damages planes and causes major flight delays</a></li> <li class="zemanta-article-ul-li"><a href="http://www.cnn.com/2008/TRAVEL/08/21/TSA.american.eagle/index.html?eref=rss_latest">TSA investigating possible violations by American Eagle</a></li> <li class="zemanta-article-ul-li"><a href="http://www.cnn.com/2008/TRAVEL/08/21/TSA.american.eagle/index.html?eref=rss_travel">TSA investigating American Eagle at O'Hare</a></li> <li class="zemanta-article-ul-li"><a href="http://abcnews.go.com/Blotter/story?id=5619046&amp;page=1">Pilots Outraged Over TSA's Botched Security Check</a></li> <li class="zemanta-article-ul-li"><a href="http://www.cnn.com/2008/TRAVEL/08/20/grounded.jets/index.html?eref=rss_us">Inspector's method grounds 9 aircraft, TSA says</a></li> <li class="zemanta-article-ul-li"><a href="http://www.cnn.com/2008/TRAVEL/08/20/grounded.jets/index.html?eref=rss_latest">Jets grounded after inspector grabs sensitive equipment</a></li> <li class="zemanta-article-ul-li"><a href="http://www.cnn.com/2008/TRAVEL/08/20/grounded.jets/index.html?eref=rss_travel">Jets grounded after inspector grabs instrument</a></li> <li class="zemanta-article-ul-li"><a href="http://abcnews.go.com/Blotter/story?id=5613502&amp;page=1">TSA Snafu Damages Nine Planes at O'Hare Field</a></li> <li class="zemanta-article-ul-li"><a href="http://www.schneier.com/blog/archives/2008/08/tsa_follies.html">TSA Follies</a></li> <li class="zemanta-article-ul-li"><a href="http://www.boingboing.net/2008/08/20/tsa-inspector-breaks.html">TSA inspector breaks airplanes by climbing on them using instruments as handholds</a></li> </ul></fieldset><blockquote></blockquote><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-7620561045269650685?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com0tag:blogger.com,1999:blog-5358057235902486284.post-43988956510599998972008-08-21T10:00:00.001-05:002008-08-24T14:24:27.799-05:00To cert, or not to cert, that is the Question:<div xmlns="http://www.w3.org/1999/xhtml"><a href="http://abovesecuritytraining.com/resources/Certification.gif" imageanchor="1" style="clear: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img border="0" height="35" src="http://abovesecuritytraining.com/resources/Certification.gif" width="200" /></a>Mike Rothman wrote an interesting article titled "<a href="http://searchsecurity.techtarget.com/tip/0,289483,sid14_gci1323863,00.html?track=NL-430&amp;ad=654062&amp;asrc=EM_NLT_4270974&amp;uid=7868131">Security certifications: Are they worth the trouble?</a>" at <a href="http://searchsecurity.techtarget.com/home/0,289692,sid14,00.html">SearchSecurity.com</a>. His take was pretty close to the one I have and his expierence is in line with what I have experienced in my years within the IT field. From the article:<br /> <blockquote>I've never really been a fan of certifications for two reasons: some of the smartest security folks I know don't have any, and some of the least capable do.</blockquote>I don't have a <a class="zem_slink" href="http://en.wikipedia.org/wiki/Certified_Information_Systems_Security_Professional" rel="wikipedia" title="Certified Information Systems Security Professional">CISSP</a>, nor have I earned a <a class="zem_slink" href="http://en.wikipedia.org/wiki/Certified_Ethical_Hacker" rel="wikipedia" title="Certified Ethical Hacker">CEH</a>, <a class="zem_slink" href="http://en.wikipedia.org/wiki/Certified_Information_System_Auditor" rel="wikipedia" title="Certified Information System Auditor">CISA</a>, Security+, etc. Quite honestly I am too busy to study for any of them. I have found a few types of "certified" folks out there:<br /> <ul><li>Smart, dedicated professional looking to expand knowledge and become an expert in their chosen field spending hours studying texts, reading white papers, etc.<br /> </li> <li>Smart, dedicated professional that went to training and took the exam at the end because... "why not?" <br /> </li> <li>Poor soul sent to a boot camp training course to take on new technology / responsibility that they have no experience in, took the test on Friday afternoon after getting their free travel mug and polo shirt.<br /> </li> <li>Sales engineers and the ilk that need certifications to "prove" expertise... I still remember the CISSP, CEH, LMNOP vendor dude that didn't understand basic routing issues and insisted that eBGP could NOT be run on an internal network.</li> </ul>I am, of course, taking a light-hearted job at my certified security bretheren out there. Seriously though, I have not impressed with some of the <a class="zem_slink" href="http://en.wikipedia.org/wiki/Cisco_Career_Certifications" rel="wikipedia" title="Cisco Career Certifications">CCIE</a> (I helped one write an ACL on a <a class="zem_slink" href="http://en.wikipedia.org/wiki/Cisco_PIX" rel="wikipedia" title="Cisco PIX">PIX firewall</a> once... no joke), CISSP, CEH, etc. that I have been meeting and interviewing lately.<br /> <br /> I think what is beginning to happen with security certifications is what has happened with <a class="zem_slink" href="http://en.wikipedia.org/wiki/Cisco_Career_Certifications" rel="wikipedia" title="Cisco Career Certifications">Cisco certifications</a> and college degrees... so many unqualified, uninterested, and incompetent people have been attaining the high level certs that they are becoming almost worthless as a selection criteria of value or knowledge.<br /> <br /> That being said, I would actually consider a <a class="zem_slink" href="http://en.wikipedia.org/wiki/Certification" rel="wikipedia" title="Certification">certification</a> that still meant something like the CISSP (but that is changing by the day) or a newer, lesser known <a class="zem_slink" href="http://en.wikipedia.org/wiki/SANS_Institute" rel="wikipedia" title="SANS Institute">SANS</a> certification (management or technical tracks... I still haven't decided which direction I want my career to go). Of course that would put me in the first type of certified professional I listed above ;)<br /> <blockquote></blockquote></div><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-4398895651059999897?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com0tag:blogger.com,1999:blog-5358057235902486284.post-48068356318132784062008-08-20T22:45:00.001-05:002008-08-24T13:40:24.165-05:00Squirtle: squirting browser-based NTLM site on your intranet<div class="separator" style="clear: both; text-align: center;"><a href="http://1.bp.blogspot.com/_YM_k6IgTR7E/SKzpeJmu26I/AAAAAAAAD9A/SsoybPVwA0I/s1600-h/squirtle.gif" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"><img border="0" src="http://1.bp.blogspot.com/_YM_k6IgTR7E/SKzpeJmu26I/AAAAAAAAD9A/aylXYQ3XJwg/s200-R/squirtle.gif" /></a></div>Just a quick note about something interesting I ran across out at <a class="zem_slink" href="http://code.google.com/" rel="homepage" title="Google Code">Google Code</a>. <a href="http://code.google.com/p/squirtle/">Squirtle</a> uses <a class="zem_slink" href="http://en.wikipedia.org/wiki/Internet_Explorer" rel="wikipedia" title="Internet Explorer">Internet Explorer's</a> use of trusted zones and grabs <a class="zem_slink" href="http://en.wikipedia.org/wiki/NTLM" rel="wikipedia" title="NTLM">NTLM</a> hashes when a user browses to a site that is running squirtle. No muss, no fuss, just pure Windows credential hashes. After glancing through the code I honestly can't imagine why it took so long for this to come along. Personally, I think <a href="http://en.wikipedia.org/wiki/Cross-site_scripting">XSS</a> and <a href="http://en.wikipedia.org/wiki/Social_engineering_%28security%29">social engineering</a> are your most likely attack vector and that deploying squirtle is dead simple... and NTLM is just dead (FD: I have never liked nor thought NTLM was effective and was a MS lock-in trick to make people feel better... but not make them more secure (like SMB signing). More info <a href="http://grutz.jingojango.net/exploits/pokehashball.html">here</a> and <a href="http://oss.coresecurity.com/projects/pshtoolkit.htm">here</a>.<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-4806835631813278406?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com1tag:blogger.com,1999:blog-5358057235902486284.post-6547009474326335572008-08-20T09:30:00.001-05:002008-08-24T13:57:06.118-05:00Continental expands paperless boarding pass effort<a href="http://upload.wikimedia.org/wikipedia/commons/thumb/6/67/Continental.airlines.b757-200.takeoff.arp.jpg/800px-Continental.airlines.b757-200.takeoff.arp.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"><img border="0" height="139" src="http://upload.wikimedia.org/wikipedia/commons/thumb/6/67/Continental.airlines.b757-200.takeoff.arp.jpg/800px-Continental.airlines.b757-200.takeoff.arp.jpg" width="200" /></a><br /> <div xmlns="http://www.w3.org/1999/xhtml">Continental has expanded their pilot program for paperless ticketing as <a href="http://www.kxan.com/Global/story.asp?S=8865017&amp;nav=menu73_2">reported on KXAN</a> (Austin, TX NBC affiliate). The program allows passengers pass through airport "security" and board planes with electronic <a class="zem_slink" href="http://en.wikipedia.org/wiki/Boarding_pass" rel="wikipedia" title="Boarding pass">boarding pass</a> barcodes that are sent to the passengers and can be downloaded and viewed on devices such as <a class="zem_slink" href="http://en.wikipedia.org/wiki/Mobile_phone" rel="wikipedia" title="Mobile phone">cell phones</a>. The <a class="zem_slink" href="http://www.tsa.gov/" rel="homepage" title="Transportation Security Administration">TSA</a> will have scanners at checkpoints that can scan the <a class="zem_slink" href="http://en.wikipedia.org/wiki/Barcode" rel="wikipedia" title="Barcode">barcode</a> on the device, eliminating the need for paper. I can't comment in too much detail since I have been involved in the architecture of this program for my employer. I will post about this again as the more information becomes public regarding the security of the program. For now, I will list a few articles that give more details regarding the program. You can piece together a good amount of information regarding the program by reading them (Be warned... some of them are re-posts and article amplifications and don't offer much anything new... sort of like this post :) ).<br /> <blockquote></blockquote></div><fieldset class="zemanta-related"><br /> <br /> <legend class="zemanta-related-title">Related articles </legend><br /> <ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a href="http://www.cbsnews.com/stories/2007/12/04/travel/main3573858.shtml?source=RSS&amp;attr=_3573858">TSA Greenlights Paperless Boarding Passes</a></li> <li class="zemanta-article-ul-li"><a href="http://www.msnbc.msn.com/id/22100817/">TSA, Continental initiate paperless boarding</a></li> <li class="zemanta-article-ul-li"><a href="http://mobilecrunch.com/2008/06/04/continental-airlines-offers-mobile-boarding-passes/">Continental Airlines offers Mobile Boarding Passes</a></li> <li class="zemanta-article-ul-li"><a href="http://www10.nytimes.com/2008/03/18/technology/18check.html?_r=5&amp;ex=1363579200&amp;en=706a3325091fa7f8&amp;ei=5088&amp;partner=rssnyt&amp;emc=rss&amp;oref=slogin&amp;oref=slogin&amp;oref=slogin&amp;oref=slogin">Itineraries: Paper Is Out, Cellphones Are In</a></li> <li class="zemanta-article-ul-li"><a href="http://gizmodo.com/gadgets/cellphones/paperless-boarding-passes-coming-to-cellphones-330178.php">Paperless Boarding Passes Coming To Cellphones [Cellphones]</a></li> <li class="zemanta-article-ul-li"><a href="http://www.news.com/8301-10784_3-9896859-7.html?part=rss&amp;subj=news">Cell phone as boarding pass</a></li> <li class="zemanta-article-ul-li"><a href="http://venturebeat.com/2008/07/14/sojern-gives-airlines-a-new-way-to-make-money-your-boarding-pass/">Sojern gives airlines a new way to make money - your boarding pass</a></li> <li class="zemanta-article-ul-li"><a href="http://www.informationweek.com/news/mobility/showArticle.jhtml?articleID=204701111">Paperless Boarding Pass Program Kicks Off</a><br /> </li> <li class="zemanta-article-ul-li"><a href="http://www.news.com/8301-10784_3-9931866-7.html?part=rss&amp;subj=news">iPhone as electronic airplane boarding pass</a></li> </ul></fieldset><blockquote></blockquote><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-654700947432633557?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com0tag:blogger.com,1999:blog-5358057235902486284.post-7850004085561981042008-08-19T16:25:00.004-05:002008-08-24T14:25:04.576-05:00PCI DSS update (1.2) pre-released and boy howdy it's about time!<div xmlns="http://www.w3.org/1999/xhtml"><a href="http://2.bp.blogspot.com/_YM_k6IgTR7E/SKs_wwjZoqI/AAAAAAAAD8Y/_kmm2wltwuE/s1600-h/credit_card_alternative.jpg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"><img border="0" src="http://2.bp.blogspot.com/_YM_k6IgTR7E/SKs_wwjZoqI/AAAAAAAAD8Y/PMI66mQwyY8/s200-R/credit_card_alternative.jpg" /></a>The <a href="http://www.pcisecuritystandards.org/">Payment Card Institute</a> (PCI) Security Standards Council has <a href="http://www.pcisecuritystandards.org/pdfs/pci_dss_summary_of_changes_v1-2.pdf">pre-released</a> it's highly anticipated <a href="http://www.pcisecuritystandards.org/security_standards/pci_dss.shtml">Data Security Standards</a> (DSS) version 1.2. The standard is due to be officially released in October of this year (2008) but the PCI wanted to give businesses a chance to examine the changes and begin re-architecting half the stuff they hurriedly put in place this year in order to meet the June 30 deadline for 1.1. Enough of my babbling, onto the good stuff:<br /> <br /> <ul><li>Relaxed firewall configuration review from three months to six.</li> <li>Language changes to include routers into the fold (not just firewalls).</li> <li>Clarified the requirement applies to wireless environments “attached to cardholder environment or transmitting cardholder data.” </li> <li>Got rid of WEP language... long live WEP! (just kidding of course)</li> <li>Finally got rid of the silly SSID hiding requirement... I got in some very intense arguements here about the futality of hiding the SSID... so that's a big ITYS to my colleagues (except you Ryan).</li> <li>Clarified the local user accounts databases need to be encrypted but the DB in my secure data center sitting behind eight layers of security devices need not go through the hassle... not that they shouldn't be encrypted... maybe I won't share that new requirement with management ;)</li> <li>Wireless networks must follow industry best standards (whatever that means... more ambiguity!) for encryption, AAA, and transmission.</li> <li>New WEP projects must be implemented by the end of March 2009 (hear that PM's... better hurry) and all WEP must die by June 30, 2010</li> <li>AV is now required to all operating systems and must be updated and protect against <span style="font-style: italic;">known</span> attacks</li> <li>Thankfully loosened patching requirements to allow a risk-based prioritization of patches.</li> <li>6.6 is mandatory! All Internet facing websites have to either be behind a WAF or have vulnerability assessment tools pointed their direction or a rubber-glove code review</li> <li>You have to test and verify that passwords must be unreadable both at rest and in motion.</li> <li>They did something surrounding the 2FA requirement for access but I guess we'll have to wait to get the actual requirement (bummer)</li> <li>Passphrases join passwords as acceptable forms of authentication (another ITYS)</li> <li>Must visit all off-site storage facilities at least once a year. (Ugh!)<br /> </li> <li>Added some flexibility surrounding cameras to allow other access control types.</li> <li>Finally clarified what "secure media" meant. It applies to electronic AND paper media and how to destroy it.<br /> </li> <li>Logs for external devices must send logs to <span style="font-style: italic;">internal</span> logging servers (well DUH!)</li> <li>Relaxed audit trail requirements to three months and that they can be archived but quickly restored.</li> <li>More guidance surrounding wireless analyzers and WIDS/WIPS, ASVs must be used in quarterly external scans and internal and external pen tests but you don't have to use a QSA or ASV for those!</li> <li>This one I don't get: 'Expanded list of examples of critical employee-facing technologies to include “remote access technologies, wireless technologies, removable electronic media, email usage, internet usage, laptops, and Personal Data Assistants (PDAs)”' (Big WTF?!?!?!)<br /> </li> <li>Security policy must be reviewed by all employees annually.</li> <li>Cleared up language regarding service provider account access and hygiene.</li> <li>Generally cleaned up language for consistency and clarity (we'll see about that!)</li> </ul>All-in-all I am glad to see some of the clarifications and new requirements but there is still enough ambiguity and confusing language in the "clarifications" to keep security professionals busy and QSA's well employed over the next few years.</div><blockquote></blockquote><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-785000408556198104?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com0tag:blogger.com,1999:blog-5358057235902486284.post-55758919292168769552008-08-18T20:41:00.005-05:002008-08-24T13:37:59.332-05:00Hack the Vote<span style="display: block; float: right; margin-bottom: 1em; margin-left: 1em; margin-right: 1em; margin-top: 1em;"><a href="http://1.bp.blogspot.com/_YM_k6IgTR7E/SKoolHlAdoI/AAAAAAAAD8Q/R5AJsTmawlQ/s1600-h/2766529482_81992de053.jpg"><img border="0" src="http://1.bp.blogspot.com/_YM_k6IgTR7E/SKoolHlAdoI/AAAAAAAAD8Q/gU1PKVM8mhw/s200-R/2766529482_81992de053.jpg" /></a><span style="display: block; font-size: xx-small; margin-bottom: 0pt; margin-left: 0pt; margin-right: 0pt; margin-top: 1em;">Image by <a href="http://www.flickr.com/photos/theamarand/">Amarand Agasi</a> via <a href="http://www.flickr.com/">Flickr</a> </span></span><br /> <div xmlns="http://www.w3.org/1999/xhtml">Christopher Beam wrote a short article for Salon last week with an attention-getting title: <a href="http://www.slate.com/id/2197502/">Hack the Vote - Five ways hackers could tamper with the 2008 elections</a> over at <a href="http://www.slate.com/id/2197502/" target="_blank">Slate</a>. After wasting five minutes of my time reading the article I thought I would waste another five minutes of my time writing a short summary of how "hackers" can "tamper" with the elections this fall. Please note that Mr. Beam has the word "hackers" in his title but consistently refers to them as "tricksters." Mr. Beam's short list of ways hacker-tricksters (hicksters?) can sabotage the vote are:<br /> <ol><li><span style="font-weight: bold;">Fake e-mails.</span> Seems that some hicksters (I'm starting to like it... I'm slapping a trademark on it) are actually politically-savvy phishers. He offers defending against phishers with "rapid response" getting the word out about the scam to the people most likely to get duped. I do love this little bit of genius from the article: "...Obama's <a href="https://donate.barackobama.com/page/contribute/2millionD?source=20080813_2M_ND_R" target="_blank">donation page</a> has a security seal at the bottom designating it an "authentic site." Notice, also, that you can easily copy the seal and post it on your own site." I actually did LOL when I read the last sentence.</li> <li><span style="font-weight: bold;">Dummy Web sites.</span> I'm not sure how this one made it in but Mr. Beam spends a good amount of screen real estate rambling about: <a href="http://www.wired.com/politics/onlinerights/news/2007/11/spoof_forums">fake content</a>, <a href="http://www.misspelledtraffic.com/index.htm">misspelled domain names</a>, the <a href="http://blogs.zdnet.com/security/?p=1042">Obama-Clinton XSS incident</a>, the <a href="http://www.securityfocus.com/news/11526">recent DNS flaw</a>, and finally <a href="http://en.wikipedia.org/wiki/SQL_injection">SQLi</a>. His solution? Well, not much since every security professional I know is struggling with the exact same issues day-in day-out... but I'll give Mr. Beam credit for bringing some of these vulnerabilities to the general public's attention.</li> <li><span style="font-weight: bold;">Social networking.</span> I see this potentially being an issue for Obamanics but for McCainites? Not so much. Unless you count the golf course or barbershop.</li> <li><span style="font-weight: bold;">Robo-calling.</span> Um. Yeah, weren't they cold calling my parents to sling some serious mud back when it was Nixon vs. McGovern? <br /> </li> <li><b>Search-engine deoptimization.</b> Potentially could be a problem if the hicksters are very very motivated and very very organized but his scenarios are too localized to be effective (buying ads to mislead people where to vote?). <a href="http://www.google.com/" target="_blank">Google</a> (and the other search engines) have gotten much better about rooting out "<a href="http://en.wikipedia.org/wiki/Google_bomb">google bombing</a>" and other <a href="http://en.wikipedia.org/wiki/Search_engine_optimization">SEO</a> tricks and hacks (hicks?). <br /> </li> </ol>Ultimately the article closes out with the statements that it should have started with: <br /> <blockquote>That's not to say these Internet tricks will upset the election—or even dent it. There are <a href="http://www.nytimes.com/2008/08/03/magazine/03trolls-t.html" target="_blank">plenty of bright mischief-makers</a> out there, but how many of them want to screw up elections? (Elect John McCain for the <a href="http://en.wikipedia.org/wiki/LOL" target="_blank">lulz</a>!) And it may turn out that traditional methods of voter manipulation—such as, say, <a href="http://www.washingtonpost.com/wp-dyn/content/article/2006/11/07/AR2006110700740.html" target="_blank">paying busloads of homeless people to pass out inaccurate sample ballots</a>—will prove more effective. Plus, one <a href="http://my.barackobama.com/page/content/fightthesmearshome" target="_blank">smear campaign</a> probably equals a thousand polling-place misinformation campaigns.</blockquote><blockquote></blockquote></div><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-5575891929216876955?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com2tag:blogger.com,1999:blog-5358057235902486284.post-79421037343118840492008-08-09T10:17:00.012-05:002008-08-24T14:32:11.829-05:00Using credit cards at airport kiosks is as safe using them anywhere else... which isn't saying much.<span style="display: block; float: right; margin-bottom: 1em; margin-left: 1em; margin-right: 1em; margin-top: 1em;"><a href="http://commons.wikipedia.org/wiki/Image:International_airport_toronto_pearson.jpg"><img alt="The Terminal 3 Grand Hall" src="http://upload.wikimedia.org/wikipedia/commons/thumb/7/77/International_airport_toronto_pearson.jpg/202px-International_airport_toronto_pearson.jpg" style="border: medium none; display: block;" /></a><span style="display: block; margin-bottom: 0pt; margin-left: 0pt; margin-right: 0pt; margin-top: 1em;">Image via <a href="http://commons.wikipedia.org/wiki/Image:International_airport_toronto_pearson.jpg">Wikipedia</a></span></span><br /> <div xmlns="http://www.w3.org/1999/xhtml">Bob Sullivan wrote a post titled "<a href="http://redtape.msnbc.com/2008/07/airline-travele.html">Are airline kiosks safe?</a>" for <a href="http://redtape.msnbc.com/">The Red Tape Chronicles</a> at <a href="http://www.msnbc.msn.com/">msnbc.com</a> last week that made me frown when I first read it. (Note: I'll give Bob Sullivan credit... at least he tried to be balanced, read on). On July 24th the <a href="http://www.thestar.com/News/Canada/article/467012">The Toronto Star</a> broke a story titled "<a href="http://www.thestar.com/News/Canada/article/467012">Airports a natural target for credit card fraud: Expert</a>." Ok, airports are a target... so are <a href="http://www.washingtonpost.com/wp-dyn/content/article/2007/02/21/AR2007022100940_pf.html">discount retail chains</a> and<a href="http://www.nytimes.com/2008/03/23/us/23credit.html"> grocery stores</a>... what's with the title? It turns out that <a class="zem_slink" href="http://www.visa.com/" rel="homepage" title="Visa Inc.">Visa</a> was investigating "isolated fraud incidents" that were occurring when people used the cards to check in to their flights and get their boarding passes. What drives me nuts is that the article spends almost 500 words scaring the bejeebus out of people when right in the middle of the article there is this gem of a quote:<br /> <blockquote>"<a class="zem_slink" href="http://www.westjet.com/" rel="homepage" title="WestJet">WestJet</a> has cautioned against pinning the blame solely on the kiosks until the investigation is complete."</blockquote>Eh? They didn't really know where the fraud was originating from, the banks (which do not usually have detailed information regarding POS (<a class="zem_slink" href="http://en.wikipedia.org/wiki/Point_of_sale" rel="wikipedia" title="Point of sale">Point of Sale</a>) location or IT infrastructure of organizations) were guessing that the kiosks was a logical place to start looking. Makes sense to me. But then the <a href="http://www.upi.com/">UPI</a> picked up on the story with the albeit better title "<a href="http://www.upi.com/Top_News/2008/07/24/Toronto_airport_credit_card_scam_probed/UPI-94451216909711/" title="">Toronto airport credit card scam probed</a>." Unfortunately, this article also takes the tact that it's better to scare people about swiping your card than emphasize that the banks were investigating whether there was something to investigate.<br /> <br /> Well, not long after the UPI story came out the security and travel blogosphere grabbed the ball and ran. With titles like these who wouldn't be scared about checking in at a kiosk?<br /> <blockquote><ul><li><a href="http://www.usatoday.com/travel/flights/item.aspx?type=blog&amp;ak=53166670.blog">Does using your credit card to check-in expose you to fraud?</a></li> <li><a href="http://www.networkworld.com/community/node/30360">Airport kiosks may be stealing your credit card info</a></li> <li><a href="http://www.tripso.com/today/beware-of-credit-card-fraud-at-torontos-airport-ticket-kiosks/"> Beware of credit card fraud at Toronto’s airport ticket kiosks</a></li> <li><a href="http://www.doubledeckerbuses.org/nuttinbut/index.php/2008/07/26/credit_card_fraud_at_the_airport">Credit Card Fraud At The Airport</a> (with authority FTW!)</li> </ul></blockquote><ul></ul>Ok, ok, I know what you're thinking, it's better to spread the word about possible fraud than to keep it quiet and let people continue to be at risk. Fine. I agree... although I think by upping the hyperbole you spread FUD (<a class="zem_slink" href="http://en.wikipedia.org/wiki/Fear%2C_uncertainty_and_doubt" rel="wikipedia" title="Fear, uncertainty and doubt">Fear, Uncertainty, Doubt</a>) and damage the airports, the kiosk owners, and the airlines. Let's stick to the facts and leave the outrageous headlines out (except for the last one I listed above... if a reader of "Nuttin' But Pimp" takes anything on that site seriously... well then send me an email because do I have some offers for you!<br /> <br /> Why am I picking on this particular news item? Well, just a few days after the initial story broke (five (5) days to be exact) <a href="http://www.cbc.ca/">cbc news</a> reported that "<a href="http://www.cbc.ca/consumer/story/2008/07/29/airport-kiosks.html">No fraud linked to Toronto Pearson airport kiosks</a>." Yes, that's right... they did an audit and found that there are "no confirmed cases of fraud currently at [Pearson] airport kiosks."<br /> <br /> I scoured the blogosphere for follow-up articles giving the "all clear" to let people use credit cards in addition to their passports or PNR numbers to check into their flight. I could only find a few stories in the Canadian press about it. At least there will be one article out there spreading the good news. Swiping your <a class="zem_slink" href="http://en.wikipedia.org/wiki/Credit_card" rel="wikipedia" title="Credit card">credit card</a> (CC) at an airport kiosks is just as dangerous as storing your CC information online, swiping it at the <a class="zem_slink" href="http://en.wikipedia.org/wiki/Grocery_store" rel="wikipedia" title="Grocery store">grocery store</a>, handing it to a waiter at a resteraunt, etc. In other words, not really all that safe at all but convenient.<br /> <br /> Shout out to Howard for sending me the msnbc post.</div><br /> Related Articles<br /> <ul><li><a href="http://www.thestar.com/article/466406">Airport's self-serve kiosks tied to fraud</a></li> <li><a href="http://www.nationalpost.com/nationalpost/story.html?id=675085">WestJet to pull credit card readers at check-in kiosks</a></li> <li><a href="http://www.canada.com/topics/news/national/story.html?id=a6818ae8-bad6-4ac2-914b-87bf5efef244">WestJet shutters credit card kiosks</a></li> <li><a href="http://www.canada.com/calgaryherald/news/story.html?id=a6818ae8-bad6-4ac2-914b-87bf5efef244">Stop that card</a></li> <li><a href="http://www.canada.com/topics/news/national/story.html?id=2d4dc8ef-4ea1-4b5c-b0bc-8a9e4e091b0d">No fraud at Pearson kiosks: Ottawa</a></li> <li><a href="http://www.ctv.ca/servlet/ArticleNews/story/CTVNews/20080727/airport_kiosks_080727/20080727?hub=QPeriod">Ottawa preparing report on Pearson airport kiosks</a></li> <li><a href="http://www.thestar.com/article/468256">Ottawa to probe possible airport kiosk fraud</a></li> <li><a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9110642&amp;source=rss_topic82">Credit card firms investigate fraud at Canadian airport kiosks</a></li> <li><a href="http://www.thestar.com/article/466225">WestJet suspends credit-card check-in amid fraud fears</a></li> <li><a href="http://www.ctv.ca/servlet/ArticleNews/story/CTVNews/20080724/pearson_probe_080724/20080724?hub=Canada">Expert warns travellers in wake of Pearson probe</a></li> <li><a href="http://www.cbc.ca/consumer/story/2008/07/29/airport-kiosks.html?ref=rss">No fraud linked to Toronto Pearson airport kiosks</a></li> <li><a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9110642&amp;source=rss_topic82">Credit card firms investigate fraud at Canadian airport kiosks</a></li> </ul><span style="font-size: x-small;">Edit: Fixed some spelling and cleaned up the language a bit. </span><br /> <blockquote></blockquote><div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-7942103734311884049?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com0tag:blogger.com,1999:blog-5358057235902486284.post-12318785047678119692008-07-29T12:58:00.002-05:002008-08-24T13:57:06.123-05:00Airlines warn customers of infected ticket invoices<div class="separator" style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none; clear: both; text-align: center;"><a href="http://farm2.static.flickr.com/1194/542145956_efae4854b1.jpg?v=0" imageanchor="1" style="background-color: transparent; border-bottom: 0px; border-left: 0px; border-right: 0px; border-top: 0px; clear: left; cssfloat: left; float: left; margin-bottom: 1em; margin-right: 1em;"><img height="133" src="http://farm2.static.flickr.com/1194/542145956_efae4854b1.jpg?v=0" style="border-bottom: 0px; border-left: 0px; border-right: 0px; border-top: 0px;" wc="true" width="200" /></a></div><div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;">I haven't blogged in a while because work has been unbelievably busy lately but I wanted to pass on an <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9110883&amp;source=NLT_VVR&amp;nlid=37">article</a> on <a href="http://www.computerworld.com/">Computerworld</a> that falls right into my wheelhouse: information security and airlines. <a href="http://www.delta.com/">Delta</a> and <a href="http://www.nwa.com/">Northwest</a> have put out warnings regarding malicious ticket invoices that are being emailed to unsuspecting people. The malicious email contains a trojan-packed zip file and instructs the reader&nbsp;to&nbsp;open the zip in order to see the invoice for a $400 ticket. From the article:</div><div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"></div><div style="border-bottom: medium none; border-left: medium none; border-right: medium none; border-top: medium none;"><span style="font-size: xx-small;">Photo by Flickr user: caribb</span> </div><blockquote>However, the .zip file format attachment is a Trojan horse that steals information, including keystrokes, from the infected Windows PC and transmits that data to a server hosted in Russia, according to McAfee threat researcher Craig Schmugar. McAfee has pegged the malware as "Spy-Agent.bw," but other security firms have given it different names. For example, Symantec Corp. has labeled the same Trojan horse as "Infostealer.Monstres."</blockquote>It doesn't appear that the message hasn't been directed at <a href="http://www.aa.com/">American Airlines</a> yet but I wouldn't bet against seeing them withing a day or two if the spam campain is successful. I'll update this blog if more details become available.<div class="blogger-post-footer"><img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/5358057235902486284-1231878504767811969?l=www.securitykarma.com'/></div>Dan Glasshttp://www.blogger.com/profile/05184514838073792623noreply@blogger.com0