<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Paranoid Prose &#187; best practices</title>
	<atom:link href="http://www.paranoidprose.com/category/best-practices/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.paranoidprose.com</link>
	<description>reading to keep you up at night</description>
	<lastBuildDate>Thu, 29 Jul 2010 13:10:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>playing in the sandbox for security</title>
		<link>http://www.paranoidprose.com/2010/07/20/playing-in-the-sandbox-for-security/</link>
		<comments>http://www.paranoidprose.com/2010/07/20/playing-in-the-sandbox-for-security/#comments</comments>
		<pubDate>Wed, 21 Jul 2010 02:26:23 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[best practices]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=428</guid>
		<description><![CDATA[Sounds like Adobe is planning to take action to make Reader a less attractive target for hackers.  According to a report out today, the maker of the ubiquitous document rendering software will release a new version of Reader which &#8220;sandboxes&#8221; PDF documents in a restricted environment while they are read.  This will mean that if [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="Sandbox" src="http://www.adair.k12.ky.us/ic/sandbox1.gif" alt="" width="292" height="293" />Sounds like Adobe is planning to take action to make Reader a less attractive target for hackers.  <a href="http://www.zdnet.com/blog/security/adobe-adding-sandbox-to-pdf-reader-to-ward-off-hacker-attacks/6886" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.zdnet.com/blog/security/adobe-adding-sandbox-to-pdf-reader-to-ward-off-hacker-attacks/6886?referer=');">According to a report out today</a>, the maker of the ubiquitous document rendering software will release a new version of Reader which &#8220;sandboxes&#8221; PDF documents in a restricted environment while they are read.  This will mean that if the file contains malicious code, that code will be trapped in a virtual jail and will be unable to access the underlying operating system for its nefarious purposes.  Similar technology is used in Google&#8217;s Chrome browser (my personal favorite) and Microsoft Office 2010.  The first version will just block writes to the host computer, but later versions will also control other operations from PDFs.  While this is not a cure-all, it sounds like a great step forward and will provide another layer of defense from evil PDFs.</p>
<p>In other sandbox news, Dell&#8217;s KACE systems management division released a <a href="http://www.kace.com/products/freetools/secure-browser/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.kace.com/products/freetools/secure-browser/?referer=');">free tool</a> which combines Mozilla Firefox browser with Adobe Flash and Acrobat Reader into a virtualized package which allows web browsing to take place within a sandbox isolated from the rest of the Windows environment.  They also offer a management appliance (not free) which will allow enterprises to deploy and manage Secure Browsers on hundreds or thousands of computers.  I have not yet had a chance to play with this tool, but it looks promising.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2010%2F07%2F20%2Fplaying-in-the-sandbox-for-security%2F&amp;linkname=playing%20in%20the%20sandbox%20for%20security" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2010_2F07_2F20_2Fplaying-in-the-sandbox-for-security_2F_amp_linkname=playing_20in_20the_20sandbox_20for_20security&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2010/07/20/playing-in-the-sandbox-for-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>russian spies with a distinctly capitalist bent</title>
		<link>http://www.paranoidprose.com/2010/07/14/russian-spies-with-a-distinctly-capitalist-bent/</link>
		<comments>http://www.paranoidprose.com/2010/07/14/russian-spies-with-a-distinctly-capitalist-bent/#comments</comments>
		<pubDate>Thu, 15 Jul 2010 02:38:31 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[best practices]]></category>
		<category><![CDATA[hacks]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=412</guid>
		<description><![CDATA[The Russian spy ring seems to be the gift that just keeps on giving in terms of blog fuel. First&#8230; if this story is to be believed, one of the spies set himself up as a consultant, talking to companies about their plans for a post oil economy (a subject of interest to fossil fuel [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 218px"><img src="http://wickeddelicious.com/blog/wp-content/uploads/2008/08/boris_natasha.jpg" alt="Oh hai!  We're in ur companies steeling ur sekretz" width="208" height="255" /><p class="wp-caption-text">Oh hai!  We&#39;re in ur companies steeling ur sekretz</p></div>
<p>The <a href="http://topics.nytimes.com/top/reference/timestopics/subjects/r/russian_spy_ring_2010/index.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/topics.nytimes.com/top/reference/timestopics/subjects/r/russian_spy_ring_2010/index.html?referer=');">Russian spy ring </a>seems to be the gift that just keeps on giving in terms of blog fuel.</p>
<p>First&#8230; if <a href="http://www.washingtonian.com/blogarticles/16273.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.washingtonian.com/blogarticles/16273.html?referer=');">this story </a>is to be believed, one of the spies set himself up as a consultant, talking to companies about their plans for a post oil economy (a subject of interest to fossil fuel producers such as Russia) and pitching a software package to help companies model the effects of future events on their businesses.  Since this software would be installed on customer networks, it could be used as a vector to plant spyware on clients&#8217; computers.</p>
<p><a href="http://www.komonews.com/news/local/98370534.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.komonews.com/news/local/98370534.html?referer=');">Another report </a>reveals that a Russian man who may be linked to the spy ring and who was recently deported had worked at Microsoft as a software tester both as an intern and as a full time employee.  He worked in Redmond for less than a year, and Microsoft claims that no software was compromised.  Hmmm.  I hope the boys and girls are putting in some serious overtime looking at what this guy had access to.</p>
<p>If true, these stories point to a new face of state sponsored espionage &#8211; one focused on the private sector, which is much less prepared to protect the secrets which are important to their business as well as to the critical infrastructure.  Another good reason for security folks to <a href="http://www.infragard.net/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.infragard.net/?referer=');">join their local InfraGard chapter </a>and learn more about protecting their businesses (and their country) against corporate espionage.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2010%2F07%2F14%2Frussian-spies-with-a-distinctly-capitalist-bent%2F&amp;linkname=russian%20spies%20with%20a%20distinctly%20capitalist%20bent" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2010_2F07_2F14_2Frussian-spies-with-a-distinctly-capitalist-bent_2F_amp_linkname=russian_20spies_20with_20a_20distinctly_20capitalist_20bent&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2010/07/14/russian-spies-with-a-distinctly-capitalist-bent/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>enterprise risk management seminar in nyc 7/14</title>
		<link>http://www.paranoidprose.com/2010/07/10/enterprise-risk-management-seminar-in-nyc-714/</link>
		<comments>http://www.paranoidprose.com/2010/07/10/enterprise-risk-management-seminar-in-nyc-714/#comments</comments>
		<pubDate>Sun, 11 Jul 2010 01:17:06 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[best practices]]></category>
		<category><![CDATA[useful stuff]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=365</guid>
		<description><![CDATA[Interested in Enterprise Rights Management?  In the New York City metro area?  Free on July 14th?   New York Metro InfraGard is putting on an ERM seminar which looks really worthwhile.  I think that ERM is going to be a key tool for security professionals over the next year or two as new mobile devices, as [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 213px"><img title="infolock" src="http://www.yousecure.co.uk/sitebuildercontent/sitebuilderpictures/lock.jpg" alt="" width="203" height="120" /><p class="wp-caption-text">lock up those bits!</p></div>
<p>Interested in Enterprise Rights Management?  In the New York City metro area?  Free on July 14th?   New York Metro InfraGard is putting on an <a href="https://www.nym-infragard.us/cms/component/content/article/158" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.nym-infragard.us/cms/component/content/article/158?referer=');">ERM seminar </a>which looks really worthwhile.  I think that ERM is going to be a key tool for security professionals over the next year or two as new mobile devices, as well as devices owned by employees and business partners become more and more integrated with our businesses.  I&#8217;m planning to be there and look forward to meeting some readers!</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2010%2F07%2F10%2Fenterprise-risk-management-seminar-in-nyc-714%2F&amp;linkname=enterprise%20risk%20management%20seminar%20in%20nyc%207%2F14" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2010_2F07_2F10_2Fenterprise-risk-management-seminar-in-nyc-714_2F_amp_linkname=enterprise_20risk_20management_20seminar_20in_20nyc_207_2F14&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2010/07/10/enterprise-risk-management-seminar-in-nyc-714/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>robin sage ain&#8217;t your friend&#8230;</title>
		<link>http://www.paranoidprose.com/2010/07/08/robin-sage-aint-your-friend/</link>
		<comments>http://www.paranoidprose.com/2010/07/08/robin-sage-aint-your-friend/#comments</comments>
		<pubDate>Fri, 09 Jul 2010 00:57:06 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[best practices]]></category>
		<category><![CDATA[online security]]></category>
		<category><![CDATA[worst practices]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=346</guid>
		<description><![CDATA[You can never have too many friends &#8211; or CAN you?  (Hint: you can).   A recent social engineering experiment conducted by Thomas Martin of Provide Security showed the dangers of blindly accepting connection requests from people on social networks.  Martin set up multiple social network profiles for a fictitious person named Robin Sage who [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 83px"><img title="Robin Sage" src="http://a1.twimg.com/profile_images/593868778/Robin1_bigger.png" alt="" width="73" height="73" /><p class="wp-caption-text">Wanna be friends?</p></div>
<p>You can never have too many friends &#8211; or CAN you?  (Hint: you can).   A recent social engineering experiment conducted by Thomas Martin of Provide Security showed the dangers of blindly accepting connection requests from people on social networks.  Martin set up multiple social network profiles for a fictitious person named Robin Sage who supposedly worked in US military intelligence circles.  &#8220;Robin&#8221; then sent connection requests to a variety of people in the security and intel communities (people who should know better, in other words).  The result?  In <a href="http://www.csoonline.com/article/598906/the-robin-sage-experiment-fake-profile-fools-security-pros?page=1" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.csoonline.com/article/598906/the-robin-sage-experiment-fake-profile-fools-security-pros?page=1&amp;referer=');">an interview with CSO Magazine</a>, he stated that:</p>
<p style="padding-left: 30px;"><em>By the end of the 28-day experiment, Robin finished the month having  accumulated hundreds of connections through various social networking  sites. Contacts included executives at government entities such as the  NSA, DOD and Military Intelligence groups. Other friends came from  Global 500 corporations. Throughout the experiment Robin was offered  gifts, government and corporate jobs, and options to speak at a variety  of security conferences, said Ryan.</em></p>
<address style="padding-left: 30px;"> </address>
<address style="padding-left: 30px;"> </address>
<p>More alarmingly, according to an <a href="http://www.darkreading.com/insiderthreat/security/privacy/showArticle.jhtml?articleID=225702468" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.darkreading.com/insiderthreat/security/privacy/showArticle.jhtml?articleID=225702468&amp;referer=');">article from DarkReading</a>,</p>
<p style="padding-left: 30px;"><em>Robin actually duped an Army Ranger into  friending her. The Ranger then inadvertently exposed information about  his coordinates in Afghanistan to Robin with his uploaded photos from  the field that contained GeoIP data from the camera.</em></p>
<p>Can you spell &#8220;bad operational security?&#8221;</p>
<p>Martin will be revealing all of his findings from the Robin Sage experiment in a talk at Black Hat later this month &#8211; should be quite entertaining for most and deeply embarrassing for a few.</p>
<p>There are some lessons learned to be learned from this incident for those of us who are not part of the military:</p>
<p style="padding-left: 30px;"><strong>If you get a friend/connection request from someone you don&#8217;t know, don&#8217;t blindly accept it. </strong>When you bring someone into your online network, you are also granting them access to information about you (contact information, status updates, photos, etc.) as well as your organization (in the case of professional networking sites like LinkedIn)</p>
<p style="padding-left: 30px;"><strong>Just because a &#8220;new friend&#8221; is already connected to some of your current friends does not mean that you should connect to them.</strong> All it takes is one careless connection to start an &#8220;avalanche of (misplaced) trust&#8221; and give an evildoer lots of information about yourself and your organization.  Trust me &#8211; I have seen this happen.  You know who you are.</p>
<p style="padding-left: 30px;"><strong>Review the privacy settings for your social networking accounts and be sure that you are aware of and comfortable with the information that is shared with the public at large and with your &#8220;friends.&#8221; </strong> The privacy settings in Facebook and Linked In are rather complex.  I recommend using a privacy scanner tool to keep an eye on who can see what on your profiles&#8230; I really like one called <a href="http://apps.facebook.com/privacydefender" target="_blank" onclick="pageTracker._trackPageview('/outgoing/apps.facebook.com/privacydefender?referer=');">Privacy Defender for Facebook</a>, which allows you to easily see and modify who can and cannot see your info.  For LinkedIn, it seems like the only way to manage your privacy is manually via the Settings menu; it is sort of a pain, but the explanations provided by the site are pretty good.</p>
<p>And Robin Sage ain&#8217;t your friend.</p>
<p>PS &#8211; &#8220;Robin Sage&#8221; is the code name for the <a href="http://www.globalsecurity.org/military/ops/robin-sage.htm" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.globalsecurity.org/military/ops/robin-sage.htm?referer=');">last training exercise that Army Rangers must complete before they are truly &#8220;Green Berets&#8221;</a> &#8211; and none of the military folks (including at least one Ranger) caught on.  Sigh&#8230;</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2010%2F07%2F08%2Frobin-sage-aint-your-friend%2F&amp;linkname=robin%20sage%20ain%26%238217%3Bt%20your%20friend%26%238230%3B" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2010_2F07_2F08_2Frobin-sage-aint-your-friend_2F_amp_linkname=robin_20sage_20ain_26_238217_3Bt_20your_20friend_26_238230_3B&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2010/07/08/robin-sage-aint-your-friend/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>porn and malware redux</title>
		<link>http://www.paranoidprose.com/2010/07/05/porn-and-malware-redux/</link>
		<comments>http://www.paranoidprose.com/2010/07/05/porn-and-malware-redux/#comments</comments>
		<pubDate>Mon, 05 Jul 2010 23:04:45 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[best practices]]></category>
		<category><![CDATA[online security]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=343</guid>
		<description><![CDATA[A few weeks back, I blogged about some research on the economics and potential malware risks posed by Internet pornography.  Well, a *new* study from Avast Software finds that non pornographic sites serving up malware outnumber pornographic sites serving malware by a factor of almost 100 to one.  Furthermore, Avast contends that there are more malware infected [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_344" class="wp-caption alignleft" style="width: 309px"><a href="http://www.paranoidprose.com/wp-content/uploads/2010/07/NewYorkSocietyForTheSuppressionOfVice.jpg"><img class="size-medium wp-image-344" title="NewYorkSocietyForTheSuppressionOfVice" src="http://www.paranoidprose.com/wp-content/uploads/2010/07/NewYorkSocietyForTheSuppressionOfVice-299x300.jpg" alt="" width="299" height="300" /></a><p class="wp-caption-text">Did they have it all wrong?</p></div>
<p>A few weeks back, I <a href="http://www.paranoidprose.com/2010/06/13/porn-economics-and-security-but-mostly-porn/" target="_blank">blogged</a> about some research on the economics and potential malware risks posed by Internet pornography.  Well, <a href="http://www.avast.com/pr-legitimate-websites-outscore-the-adult" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.avast.com/pr-legitimate-websites-outscore-the-adult?referer=');">a *new* study from Avast Software</a> finds that non pornographic sites serving up malware outnumber pornographic sites serving malware by a factor of almost 100 to one.  Furthermore, Avast contends that there are more malware infected domains containing the word &#8220;London&#8221; than there are containing the word &#8220;sex.&#8221;  Not sure what this says about London.  I guess the morals of the story are:  for every study claiming fact x, there will be one claiming fact y and that the internet is as dangerous a place for the vituous as it is for the naughty.  Have<strong> you</strong> updated your antivirus and <a href="http://www.mozilla.com/en-US/plugincheck/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.mozilla.com/en-US/plugincheck/?referer=');">plugins</a> lately?</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2010%2F07%2F05%2Fporn-and-malware-redux%2F&amp;linkname=porn%20and%20malware%20redux" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2010_2F07_2F05_2Fporn-and-malware-redux_2F_amp_linkname=porn_20and_20malware_20redux&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2010/07/05/porn-and-malware-redux/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>photo kiosks dispense prints and extra bonus virii</title>
		<link>http://www.paranoidprose.com/2010/07/05/photo-kiosks-dispense-prints-and-extra-bonus-virii/</link>
		<comments>http://www.paranoidprose.com/2010/07/05/photo-kiosks-dispense-prints-and-extra-bonus-virii/#comments</comments>
		<pubDate>Mon, 05 Jul 2010 22:50:44 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[best practices]]></category>
		<category><![CDATA[worst practices]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=341</guid>
		<description><![CDATA[From Risky.Biz&#8230; Customers at some convenience stores got a bit more than they bargained for when they used photo printing kiosks.  It seems that some kiosks at &#8220;Big W&#8221; stores run Windows.  And they don&#8217;t run anti virus.  And everyone and their brother brings their USB sticks (some infected with virii) to the stores to [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 162px"><a href="null"><img title="Thumb drive" src="http://savasplace.com/wp-content/uploads/2009/09/thumb-usb-thumb-drive.jpg" alt="" width="152" height="97" /></a><p class="wp-caption-text">Watch where you stick your thumb (drive)</p></div>
<p>From Risky.Biz&#8230; Customers at some convenience <a href="http://risky.biz/big-wirus" target="_blank" onclick="pageTracker._trackPageview('/outgoing/risky.biz/big-wirus?referer=');">stores got a bit more than they bargained for </a>when they used photo printing kiosks.  It seems that some kiosks at &#8220;Big W&#8221; stores run Windows.  And they don&#8217;t run anti virus.  And everyone and their brother brings their USB sticks (some infected with virii) to the stores to print.  You can see where this is going&#8230; the infected Fuji kiosks have been dispensing viruses to the USB sticks of customers.   The company is aware of the issue and is &#8220;currently testing&#8221; installing anti virus on the kiosks.  Hel-ll0 &#8211; the 1980s called and asked for their security policy back!</p>
<p>If you are partaking of the photo printing goodness of any of such kiosks, or sticking your USB drive into strange ports (I don&#8217;t judge&#8230;), make sure that you are running the very latest anti malware software on any of your own computers where you use said storage peripheral.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2010%2F07%2F05%2Fphoto-kiosks-dispense-prints-and-extra-bonus-virii%2F&amp;linkname=photo%20kiosks%20dispense%20prints%20and%20extra%20bonus%20virii" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2010_2F07_2F05_2Fphoto-kiosks-dispense-prints-and-extra-bonus-virii_2F_amp_linkname=photo_20kiosks_20dispense_20prints_20and_20extra_20bonus_20virii&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2010/07/05/photo-kiosks-dispense-prints-and-extra-bonus-virii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>truecrypt (and good passwords) 1, fbi 0</title>
		<link>http://www.paranoidprose.com/2010/06/30/truecrypt-and-good-passwords-1-fbi-0/</link>
		<comments>http://www.paranoidprose.com/2010/06/30/truecrypt-and-good-passwords-1-fbi-0/#comments</comments>
		<pubDate>Wed, 30 Jun 2010 21:51:18 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[Paranoid Peeps]]></category>
		<category><![CDATA[best practices]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[useful stuff]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=337</guid>
		<description><![CDATA[Looks like open source disk encryption software TrueCrypt has shown its mettle in a cybercrime case out of Brazil.   The Brazilian police seized 500 TrueCrypt protected drives from the apartment of Daniel Dantas, a Rio banker accused of financial crimes.  In Brazil, there is no law compelling defendants to reveal passwords to encrypted evidence, so the Brazilian [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_339" class="wp-caption alignleft" style="width: 310px"><a href="http://www.paranoidprose.com/wp-content/uploads/2010/06/locked-door-sign.jpg"><img class="size-medium wp-image-339" title="locked-door-sign" src="http://www.paranoidprose.com/wp-content/uploads/2010/06/locked-door-sign-300x201.jpg" alt="" width="300" height="201" /></a><p class="wp-caption-text">Daniel Dantas did...</p></div>
<p>Looks like open source disk encryption software <a href="http://www.truecrypt.org/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.truecrypt.org/?referer=');">TrueCrypt</a> has shown its mettle in a<a href="http://g1.globo.com/English/noticia/2010/06/not-even-fbi-can-de-crypt-files-daniel-dantas.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/g1.globo.com/English/noticia/2010/06/not-even-fbi-can-de-crypt-files-daniel-dantas.html?referer=');"> cybercrime case </a>out of Brazil.   The Brazilian police <a href="http://www.theregister.co.uk/2010/06/28/brazil_banker_crypto_lock_out/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.theregister.co.uk/2010/06/28/brazil_banker_crypto_lock_out/?referer=');">seized 500 TrueCrypt protected drives from the apartment of Daniel Dantas, a Rio banker accused of financial crimes</a>.  In Brazil, there is no law compelling defendants to reveal passwords to encrypted evidence, so the Brazilian crime lab attempted to break the encryption for five months with no success.  They then turned to the US FBI, who ran dictionary attacks against the encryption for another year.  No joy.  As a result of the banker&#8217;s good password practices, the 500 drives with potential evidence were reduced to really ugly paperweights.</p>
<p>While this was a loss for the good guys, it does provide security professionals with some valuable information.  First, choosing a strong (long non dictionary word with special characters, numbers and the like) password is still an integral part of good basic meat and potatos security practice.  Second, if the FBI is unable to crack a TrueCrypt protected drive without the user having chosen a boneheaded password, it seems like the program  is a good and cost effective choice for protecting personal data as well as in small business environments.  The only thing missing for bigger business is some sort of key management and recovery scheme&#8230; sounds like an opportunity for an entrepeneurial crypto programmer.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2010%2F06%2F30%2Ftruecrypt-and-good-passwords-1-fbi-0%2F&amp;linkname=truecrypt%20%28and%20good%20passwords%29%201%2C%20fbi%200" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2010_2F06_2F30_2Ftruecrypt-and-good-passwords-1-fbi-0_2F_amp_linkname=truecrypt_20_28and_20good_20passwords_29_201_2C_20fbi_200&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2010/06/30/truecrypt-and-good-passwords-1-fbi-0/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>it&#8217;s (not always) nice to share&#8230;</title>
		<link>http://www.paranoidprose.com/2010/05/20/its-not-always-nice-to-share/</link>
		<comments>http://www.paranoidprose.com/2010/05/20/its-not-always-nice-to-share/#comments</comments>
		<pubDate>Fri, 21 May 2010 02:26:40 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[best practices]]></category>
		<category><![CDATA[online security]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=277</guid>
		<description><![CDATA[Now that Facebook has made their privacy settings just a bit less complex than, say, the US Tax Code or particle physics, now would be a really good time to check your privacy settings and make sure that you are not sharing more personal information with the world (or at least to the Internet connected [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="Facebook2 " src="http://www.omcareers.org/blog/wp-content/uploads/2009/08/facebook-small-logo-thumb-360x360-75537-thumb-300x300-78195.png" alt="" width="240" height="240" />Now that Facebook has made their privacy settings just a bit less complex than, say, the US Tax Code or particle physics, now would be a really good time to check your privacy settings and make sure that you are not sharing more personal information with the world (or at least to the Internet connected portion thereof)  than you intended to.</p>
<p>The new settings default to sharing quite a bit of information &#8211; you may be (unpleasantly) surprised about what Facebook is telling the world about you.</p>
<p><a href="http://www.reclaimprivacy.org/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.reclaimprivacy.org/?referer=');">This website </a>provides a browser bookmarklet which will scan your <a href="http://www.nytimes.com/interactive/2010/05/12/business/facebook-privacy.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.nytimes.com/interactive/2010/05/12/business/facebook-privacy.html?referer=');">privacy settings</a> and let you know what you might want to change.   Take five minutes to protect your online privacy&#8230;</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2010%2F05%2F20%2Fits-not-always-nice-to-share%2F&amp;linkname=it%26%238217%3Bs%20%28not%20always%29%20nice%20to%20share%26%238230%3B" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2010_2F05_2F20_2Fits-not-always-nice-to-share_2F_amp_linkname=it_26_238217_3Bs_20_28not_20always_29_20nice_20to_20share_26_238230_3B&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2010/05/20/its-not-always-nice-to-share/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>i&#8217;m invincible! (you&#8217;re a looney!)</title>
		<link>http://www.paranoidprose.com/2010/05/13/im-invincible-youre-a-looney/</link>
		<comments>http://www.paranoidprose.com/2010/05/13/im-invincible-youre-a-looney/#comments</comments>
		<pubDate>Thu, 13 May 2010 21:13:05 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[best practices]]></category>
		<category><![CDATA[online security]]></category>
		<category><![CDATA[worst practices]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=267</guid>
		<description><![CDATA[We security professionals tend to underestimate our own vulnerability to threats like phishing. Here is a really good article by Cory Doctorow, who is most definitely not an Internet novice explaining how all of the wrong stars came into alignment to make him fall for a phishing attempt. Worth reading, especially if you think you [...]]]></description>
			<content:encoded><![CDATA[<p>We security professionals tend to underestimate our own vulnerability to threats like phishing.  <a href="http://www.locusmag.com/Perspectives/2010/05/cory-doctorow-persistence-pays-parasites/" onclick="pageTracker._trackPageview('/outgoing/www.locusmag.com/Perspectives/2010/05/cory-doctorow-persistence-pays-parasites/?referer=');">Here</a> is a really good article by Cory Doctorow, who is most definitely not an Internet novice explaining how all of the wrong stars came into alignment to make him fall for a phishing attempt.  Worth reading, especially if you think you are &#8220;smart enough&#8221; to recognize and avoid phishers&#8217; bait.</p>
<p>- Posted using BlogPress from my iPad</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2010%2F05%2F13%2Fim-invincible-youre-a-looney%2F&amp;linkname=i%26%238217%3Bm%20invincible%21%20%28you%26%238217%3Bre%20a%20looney%21%29" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2010_2F05_2F13_2Fim-invincible-youre-a-looney_2F_amp_linkname=i_26_238217_3Bm_20invincible_21_20_28you_26_238217_3Bre_20a_20looney_21_29&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2010/05/13/im-invincible-youre-a-looney/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>massachusetts kicks data protection butt!</title>
		<link>http://www.paranoidprose.com/2010/05/02/massachusetts-kicks-data-protection-butt/</link>
		<comments>http://www.paranoidprose.com/2010/05/02/massachusetts-kicks-data-protection-butt/#comments</comments>
		<pubDate>Sun, 02 May 2010 18:59:46 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[CSO]]></category>
		<category><![CDATA[best practices]]></category>
		<category><![CDATA[online security]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=248</guid>
		<description><![CDATA[Now I have two things which I really like about Massachussets &#8211; The Friendly Toast in Cambridge (mmm&#8230; Caribbean waffles) and their new data protection law.  As of March 1, any organization which holds personnally identifiable information (PII) about residents of the Commonwealth must attest that they have a written information security plan designed to [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 177px"><img title="Minuteman" src="http://www.pf-militarygallery.com/images/troiani/Minute-Man-lg.jpg" alt="" width="167" height="279" /><p class="wp-caption-text">Data protection... Massachusetts style</p></div>
<p>Now I have two things which I really like about Massachussets &#8211; <a href="http://www.thefriendlytoast.net/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.thefriendlytoast.net/?referer=');">The Friendly Toast </a>in Cambridge (mmm&#8230; Caribbean waffles) and their <a href="http://www.informationweek.com/news/security/government/showArticle.jhtml?articleID=224400426&amp;queryText=massachusetts%20cmr" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.informationweek.com/news/security/government/showArticle.jhtml?articleID=224400426_amp_queryText=massachusetts_20cmr&amp;referer=');">new data protection law</a>.  As of March 1, any organization which holds personnally identifiable information (PII) about residents of the Commonwealth must attest that they have a written information security plan designed to protect that information.  And that PII maust be encrypted both when it travels over the wire and when it is stored in systems.  Penalties for violation are quite hefty &#8211; $5,000 per violation and per record lost.</p>
<p>The law also requires businesses handling MA residents&#8217; PII to take a number of steps that they should already be doing &#8211; having someone responsible for the infosec program, identifying risks, training personnel, preventing terminated employees from accessing the PII, secure authentication and the like.    You can read the entire text of the law <a href="http://www.mass.gov/Eoca/docs/idtheft/201CMR1700reg.pdf" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.mass.gov/Eoca/docs/idtheft/201CMR1700reg.pdf?referer=');">here&#8230;</a></p>
<p>It is about time and I hope that other states (and the federal government &#8211; call me a socialist) follow Massachusetts&#8217; lead.  Requiring businesses to take some very basic and inexpensive steps to protect our information from unauthorized access is quite reasonable.    It seems to me that complying with the encryption requirements can be accomplished via an SSL cert, laptop encryption software (such as BitLocker, included with Windows 7 or FileVault on Macs), and use of database encryption features are just common sense, as is having an information security plan.</p>
<p>Bravo, MA!</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2010%2F05%2F02%2Fmassachusetts-kicks-data-protection-butt%2F&amp;linkname=massachusetts%20kicks%20data%20protection%20butt%21" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2010_2F05_2F02_2Fmassachusetts-kicks-data-protection-butt_2F_amp_linkname=massachusetts_20kicks_20data_20protection_20butt_21&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2010/05/02/massachusetts-kicks-data-protection-butt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
