<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>philosecurity</title>
	<atom:link href="http://philosecurity.org/feed" rel="self" type="application/rss+xml" />
	<link>http://philosecurity.org</link>
	<description></description>
	<lastBuildDate>Wed, 01 Jul 2009 22:07:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Chase Identity Theft FAIL</title>
		<link>http://philosecurity.org/2009/07/01/chase-identity-theft-fail</link>
		<comments>http://philosecurity.org/2009/07/01/chase-identity-theft-fail#comments</comments>
		<pubDate>Wed, 01 Jul 2009 22:07:33 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Credit Cards]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://philosecurity.org/?p=1898</guid>
		<description><![CDATA[This week I discovered that someone had opened up a new Chase card in my name. Scouring the Chase site for the appropriate number to report fraud, I stumbled onto their &#8220;Identity Protection&#8221; page and received this rather ironic pop-up. 
&#160;(Click to enlarge)



Sherri Davidoff


PGP-signed text: 2009-07-02 (current)








Did you like this article? Share it!


	
	
	
	
	


]]></description>
			<content:encoded><![CDATA[<p><!-- 2009-07-02 -->This week I discovered that someone had opened up a new Chase card in my name. Scouring the Chase site for the appropriate number to report fraud, I stumbled onto their &#8220;Identity Protection&#8221; page and received this rather ironic pop-up. <br />
&nbsp;<em>(Click to enlarge)</em></p>
<p><a href="http://philosecurity.org/wp-content/uploads/2009/07/chase-identitytheftfail3.png"><img src="http://philosecurity.org/wp-content/uploads/2009/07/chase-identitytheftfail3-1024x652.png" alt="chase-identitytheftfail3" title="chase-identitytheftfail3" width="480" height="306" class="center size-large wp-image-1899" /></a></p>
<table style="float: right">
<tr>
<td align=right><em>Sherri Davidoff</em></td>
</tr>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/pgp-archives/chase-identity-theft-fail-2009-07-02.asc">PGP-signed text: 2009-07-02 (current)</a></td>
</tr>
</table>
</td>
</tr>
</table>



Did you like this article? Share it!


	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F07%2F01%2Fchase-identity-theft-fail&amp;title=Chase%20Identity%20Theft%20FAIL" title="Digg"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://del.icio.us/post?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F07%2F01%2Fchase-identity-theft-fail&amp;title=Chase%20Identity%20Theft%20FAIL" title="del.icio.us"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F07%2F01%2Fchase-identity-theft-fail&amp;title=Chase%20Identity%20Theft%20FAIL" title="StumbleUpon"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F07%2F01%2Fchase-identity-theft-fail&amp;title=Chase%20Identity%20Theft%20FAIL" title="Reddit"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://slashdot.org/bookmark.pl?title=Chase%20Identity%20Theft%20FAIL&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F07%2F01%2Fchase-identity-theft-fail" title="Slashdot"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://philosecurity.org/2009/07/01/chase-identity-theft-fail/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Credit Cards == ID</title>
		<link>http://philosecurity.org/2009/06/30/credit-cards-id</link>
		<comments>http://philosecurity.org/2009/06/30/credit-cards-id#comments</comments>
		<pubDate>Tue, 30 Jun 2009 23:14:49 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Credit Cards]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Transit]]></category>

		<guid isPermaLink="false">http://philosecurity.org/?p=1884</guid>
		<description><![CDATA[Saw this sign in the Baltimore airport last week:

&#8220;Self-Service Check-In: You Will Need a Major Credit Card&#8221;
and then in small print:
&#8220;For Identification Only&#8221;
Yes, apparently American Airlines will only give boarding passes to individuals who have been thoroughly vetted according to the strict standards of American Express, Mastercard, or VISA (and perhaps Discover). 


Sherri Davidoff


PGP-signed text: [...]]]></description>
			<content:encoded><![CDATA[<p><!-- 2009-07-01-->Saw this sign in the Baltimore airport last week:<br />
<img src="http://philosecurity.org/wp-content/uploads/2009/06/credit-card-ids2-300x223.jpg" alt="credit-card-ids" title="credit-card-ids" width="300" height="223" class="right size-medium wp-image-1887" /></p>
<p>&#8220;Self-Service Check-In: You Will Need a Major Credit Card&#8221;<br />
and then in small print:<br />
&#8220;For Identification Only&#8221;</p>
<p>Yes, apparently American Airlines will only give boarding passes to individuals who have been thoroughly vetted according to the strict standards of <a href="https://www212.americanexpress.com/dsmlive/dsm/dom/us/en/feefreeservices/pages/identitytheftassistance_allccsg_shareddetails.do?vgnextoid=2952ce628310e010VgnVCM10000084b3ad94RCRD&#038;vgnextchannel=3c830da9846dd010VgnVCM10000084b3ad94RCRD&#038;name=identitytheftassistance_allccsg_shareddetails&#038;type=intbenefitdetail">American Express</a>, <a href="http://www.mastercard.com/us/personal/en/learningcenter/stayingsecure/fraudprevention.html">Mastercard</a>, or <a href="http://usa.visa.com/personal/security/visa_security_program/id_theft_assistance.html">VISA</a> (and perhaps <a href="http://www.discovercard.com/protection-solutions/identity-theft.html">Discover</>). </p>
<table style="float: right">
<tr>
<td align=right><em>Sherri Davidoff</em></td>
</tr>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/pgp-archives/credit-cards-equal-id-2009-07-01.asc">PGP-signed text: 2009-07-01 (current)</a></td>
</tr>
</table>
</td>
</tr>
</table>



Did you like this article? Share it!


	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F30%2Fcredit-cards-id&amp;title=Credit%20Cards%20%3D%3D%20ID" title="Digg"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://del.icio.us/post?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F30%2Fcredit-cards-id&amp;title=Credit%20Cards%20%3D%3D%20ID" title="del.icio.us"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F30%2Fcredit-cards-id&amp;title=Credit%20Cards%20%3D%3D%20ID" title="StumbleUpon"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F30%2Fcredit-cards-id&amp;title=Credit%20Cards%20%3D%3D%20ID" title="Reddit"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://slashdot.org/bookmark.pl?title=Credit%20Cards%20%3D%3D%20ID&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F30%2Fcredit-cards-id" title="Slashdot"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://philosecurity.org/2009/06/30/credit-cards-id/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>&#8220;Verizon&#8221; Store Security Update</title>
		<link>http://philosecurity.org/2009/06/29/verizon-store-security-update</link>
		<comments>http://philosecurity.org/2009/06/29/verizon-store-security-update#comments</comments>
		<pubDate>Mon, 29 Jun 2009 19:38:26 +0000</pubDate>
		<dc:creator>john_strand</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://philosecurity.org/?p=1846</guid>
		<description><![CDATA[The illustrious John Strand has an update for us regarding Verizon&#8217;s demo EVDO system security. This summer John is launching his new SANS class, Security Architecture for Systems Administrators.

Shortly after we posted the article about the openness of the Verizon EVDO demonstration terminals, we were contacted by Verizon.  After discussing the issue at length [...]]]></description>
			<content:encoded><![CDATA[<p><!-- 2009-06-30 --><em>The illustrious John Strand has an update for us regarding Verizon&#8217;s demo EVDO system security. This summer John is launching his new SANS class, <a href="http://www.sans.org/training/description.php?mid=1312">Security Architecture for Systems Administrators.</a><br />
</em><br />
Shortly after we posted the article about the <a href="http://philosecurity.org/2009/06/10/verizon-stores-pre-p0wned">openness of the Verizon EVDO demonstration terminals</a>, we were contacted by Verizon.  After discussing the issue at length they requested that we post the following comment:</p>
<blockquote><p>“The demo laptops in question are located in an independently owned/operated reseller location, and are not configured or maintained by Verizon Wireless. Verizon Wireless is committed to the security of its customers and is working with the reseller to resolve this issue.&#8221;
</p></blockquote>
<p>Usually when working with vendors, the company&#8217;s lawyers immediately respond to any potential problems with security systems.  Verizon did not respond this way. Instead, they began by asking a bunch of questions about the store locations and what security breaches were compromised.   Further, they said that they could understand the confusion because the third party resellers have huge Verizon signs on their store.  In short, they acknowledge that it can be very difficult to distinguish between the real Verizon stores and the resellers.</p>
<p>I was also very happy to see that they were interested in solving the issue. You see, even though the stores are not theirs, there is still damage that can be done if something hideous was to happen on one of the terminals. </p>
<p>I will keep you all posted on how the fix goes.   I am planning on hitting a few of the stores later today just to see.<br />
&nbsp;</p>
<table style="float: right">
<tr>
<td align=right><em>Philosecurity contributor John Strand</em></td>
</tr>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/pgp-archives/verizon-store-security-update-2009-06-30.asc">PGP-signed text: 2009-06-30 (current)</a></td>
</tr>
</table>
</td>
</tr>
</table>



Did you like this article? Share it!


	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F29%2Fverizon-store-security-update&amp;title=%22Verizon%22%20Store%20Security%20Update" title="Digg"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://del.icio.us/post?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F29%2Fverizon-store-security-update&amp;title=%22Verizon%22%20Store%20Security%20Update" title="del.icio.us"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F29%2Fverizon-store-security-update&amp;title=%22Verizon%22%20Store%20Security%20Update" title="StumbleUpon"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F29%2Fverizon-store-security-update&amp;title=%22Verizon%22%20Store%20Security%20Update" title="Reddit"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://slashdot.org/bookmark.pl?title=%22Verizon%22%20Store%20Security%20Update&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F29%2Fverizon-store-security-update" title="Slashdot"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://philosecurity.org/2009/06/29/verizon-store-security-update/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Verizon Stores Pre-p0wned</title>
		<link>http://philosecurity.org/2009/06/10/verizon-stores-pre-p0wned</link>
		<comments>http://philosecurity.org/2009/06/10/verizon-stores-pre-p0wned#comments</comments>
		<pubDate>Wed, 10 Jun 2009 08:56:55 +0000</pubDate>
		<dc:creator>john_strand</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://philosecurity.org/?p=1823</guid>
		<description><![CDATA[John Strand is the author of this week&#8217;s article. John is the owner of Black Hills Information Security and a  member of PaulDotCom Security Weekly. He is also a SANS Instructor and a regular presenter at various security conferences.
Last week I was plucking around at my  local Verizon Wireless store looking for a [...]]]></description>
			<content:encoded><![CDATA[<p><!-- 2009-06-10 --><em>John Strand is the author of this week&#8217;s article. John is the owner of Black Hills Information Security and a  member of <a href="www.pauldotcom.com">PaulDotCom Security Weekly</a>. He is also a SANS Instructor and a regular presenter at various security conferences.</em></p>
<p>Last week I was plucking around at my  local Verizon Wireless store looking for a power adapter for my i760. Apparently, this task is far harder then I thought it would be. The gentleman behind the counter said, &#8220;Whoa! That is a very old phone.&#8221;</p>
<p>I bought it last year.</p>
<p>Anyway, he disappeared into the back like he was hunting for the store&#8217;s last mogwai and left me, alone, in the store with their demo EVDO computer terminal.</p>
<p>So I started playing around with the Windows XP system they allow their customers to test the EVDO speed.   Which I think is a great idea.  However, there was a sign that said, &#8220;Please, check your email here!!&#8221;  I don&#8217;t think so.</p>
<p>So I got curious as to what kind of security they put on these systems.  I was hoping for at least a partially locked down terminal. At the very least, I was sure they would not leave an open system logged in with Administrator privileges for the whole world to use.</p>
<p><a href="http://philosecurity.org/wp-content/uploads/2009/06/verizon-smaller.jpg"><img src="http://philosecurity.org/wp-content/uploads/2009/06/verizon-smaller-300x189.jpg" alt="verizon-smaller" title="verizon-smaller" width="300" height="189" class="right size-medium wp-image-1829" /></a>I was wrong.</p>
<p>As you can see the system is logged in with an account that has Administrator Privileges.  There is no &#8220;hacking&#8221; this box&#8230;. You just walk up to it.</p>
<p>&nbsp;<br />When he returned, without the adapter I needed, he noticed that I had the command prompt up.  He asked me the basic questions like, &#8220;What the hell are you doing?&#8221;  Which I answered truthfully with the necessary mitigation steps.  You see, I am a pathetic, hopeless white hat.  I spent a few seconds re-explaining the problem to him while his eyes glassed over.  When I was done he said that he would need to take my name and a copy of my drivers license so he could run this &#8220;incident&#8221; by the management and possibly the police. It was my turn for my eyes to glass over and quickly leave the store. The irate store clerk was shocked that I would just walk away without complying with a perfectly sound and logical request to hand over my PII to a store that cannot secure a simple terminal.</p>
<p>To my horror, all of the Verizon stores in my area were set up the exact same way.</p>
<p>There are two issues here.  First, these terminals are insecure by design and replicated. Second, they encourage their potential customers to use these insecure systems to do potentially sensitive activities.</p>
<p>Why should Verizon care?  The single biggest thing I can think of is liability.  If you&#8217;re an attacker why would you keep your illegal files on your system?  It seems so much better to store them on a random Verizon demo system. Next, think about the consistency.   It is trivial to dump the password hashes from a system when you have Administrator access to the box.  Where else are those passwords used?</p>
<p>The point is that we need to start securing things even if you don&#8217;t think there is a need.  There are liability issues that come with having open systems so insecure. Further, it is just these types of things that can be catastrophic for an organization.  The sad part is many organizations would say they never saw it coming.</p>
<p>We can say it again and again, organizations need to be a bit more protective of their customers data.  Also, I think it would be a step in the right direction to not openly suggest that customers should check their email.</p>
<p>Until then&#8230; Buyer beware.</p>
<table style="float: right">
<tr>
<td align=right><em>Philosecurity contributor John Strand</em></td>
</tr>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/pgp-archives/verizon-stores-pre-p0wned-2009-06-10.asc">PGP-signed text: 2009-06-10 (current)</a></td>
</tr>
</table>
</td>
</tr>
</table>



Did you like this article? Share it!


	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F10%2Fverizon-stores-pre-p0wned&amp;title=Verizon%20Stores%20Pre-p0wned" title="Digg"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://del.icio.us/post?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F10%2Fverizon-stores-pre-p0wned&amp;title=Verizon%20Stores%20Pre-p0wned" title="del.icio.us"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F10%2Fverizon-stores-pre-p0wned&amp;title=Verizon%20Stores%20Pre-p0wned" title="StumbleUpon"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F10%2Fverizon-stores-pre-p0wned&amp;title=Verizon%20Stores%20Pre-p0wned" title="Reddit"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://slashdot.org/bookmark.pl?title=Verizon%20Stores%20Pre-p0wned&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F06%2F10%2Fverizon-stores-pre-p0wned" title="Slashdot"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://philosecurity.org/2009/06/10/verizon-stores-pre-p0wned/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Doctors Require Photo ID for Treatment</title>
		<link>http://philosecurity.org/2009/05/28/doctors-require-photo-id-for-treatment</link>
		<comments>http://philosecurity.org/2009/05/28/doctors-require-photo-id-for-treatment#comments</comments>
		<pubDate>Thu, 28 May 2009 20:28:33 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://philosecurity.org/?p=1779</guid>
		<description><![CDATA[Walking into the doctor&#8217;s office, I was surprised to see a new sign in front of the receptionist, which read: 
&#8220;Red Flag Identity Theft Rule We are now required by law to ask for a Photo ID at the time of each visit. Please have your Photo ID ready for the receptionist to scan.&#8221;
As an [...]]]></description>
			<content:encoded><![CDATA[<p><!-- 2009-05-28 -->Walking into the doctor&#8217;s office, I was surprised to see a new sign in front of the receptionist, which read: </p>
<p><font color="red">&#8220;<u>Red Flag Identity Theft Rule</u></font> We are now required by law to ask for a <u>Photo ID</u> at the time of each visit. Please have your Photo ID ready for the receptionist to scan.&#8221;</p>
<p>As an avid bicyclist, I wasn&#8217;t carrying a driver&#8217;s license. </p>
<p>&#8220;I&#8217;m sorry, we&#8217;ll have to reschedule you,&#8221; said the receptionist. &#8220;We need to scan your ID before we can see you. It&#8217;s a new law.&#8221;</p>
<p><a href="http://philosecurity.org/wp-content/uploads/2009/05/eye-dr-sign-cropped-smaller.jpg"><img src="http://philosecurity.org/wp-content/uploads/2009/05/eye-dr-sign-cropped-smaller-300x222.jpg" alt="eye-dr-sign-cropped-smaller" title="eye-dr-sign-cropped-smaller" width="250" height="185" class="right size-medium wp-image-1782" /></a>&#8220;No, I really don&#8217;t have one. I bicycle everywhere. I don&#8217;t even know where my old license is any more.&#8221;</p>
<p>She looked me in the eye and said, &#8220;Sorry. I suggest you get a photo ID. You need to have one to be seen.&#8221;</p>
<p>&#8220;What if I&#8217;m paying for my own visit, and not using health insurance?&#8221;</p>
<p>&#8220;We need to scan your ID and have it in your file or we can&#8217;t see you.&#8221;</p>
<p>&#8220;I don&#8217;t think it&#8217;s right to deny care to patients who don&#8217;t have a Photo ID,&#8221; I said. </p>
<p>&#8220;Well, I can talk to my supervisor,&#8221; she said. &#8220;But I think you&#8217;re going to have to reschedule.&#8221;</p>
<p>As I waited, I watched the receptionist take another patient&#8217;s driver&#8217;s license and walk off into a back room. Apparently, in order to comply with the &#8220;Red Flag Identity Theft Rule,&#8221; the doctor&#8217;s office now scans a copy of every patient&#8217;s driver&#8217;s license and stores it in their computer systems. </p>
<p>How secure are my doctor&#8217;s computer systems? <em>Patients don&#8217;t have the right to know.</em> Doctor&#8217;s offices, hospitals and even health insurance companies get infected with viruses, worms and spyware all the time. These are generally not reported as patient data breaches, because they are far too common. </p>
<p>Just in the past few weeks, there have been <a href="http://www.foxnews.com/story/0,2933,519187,00.html">news</a> <a href="http://www.tribune-democrat.com/local/local_story_147235958.html">reports</a> of <a href="http://www.securityfocus.com/brief/960">patient data thefts</a> from UC Berkely Health Service, Virginia Prescription Monitoring Program and Memorial Medical Center. The vast majority of breaches never get reported or even detected, however, because tiny little health care clinics and hospitals all over the country have neither the resources nor the incentives to institute appropriate detection measures. </p>
<p>And now they want to store a high-resolution copy of my driver&#8217;s license on top of everything else? What is this &#8220;Red Flags Identity Theft Rule,&#8221; anyway?</p>
<p>The Red Flags Rules are a collection of new <a href="http://www.ftc.gov/bcp/edu/pubs/articles/art11.shtm">Federal Trade Commission</a> regulations aimed at reducing the risk of identity theft. The American Medical Association and dozens of other <a href="http://contemporaryobgyn.modernmedicine.com/obgyn/Modern+Medicine+Now/News-New-Red-Flags-Rule-focuses-on-medical-identit/ArticleStandard/Article/detail/597492">medical societies &#8220;have protested the FTC&#8217;s decision</a> to apply the Red Flags rule to medical practices and other health care providers.&#8221; </p>
<p><font size="+1">Why on earth does the Federal Trade Commission affect who my doctor treats? </font></p>
<p>According to the FTC, &#8220;Health care providers may be subject to the Rule if they are &#8216;creditors.&#8217; Although you may not think of your practice as a &#8216;creditor&#8217; in the traditional sense of a bank or mortgage company, the law defines &#8216;creditor&#8217; to include any entity that regularly defers payments for goods or services or arranges for the extension of credit. For example, <a href="http://www.ftc.gov/bcp/edu/pubs/articles/art11.shtm">you are a creditor if you regularly bill patients after the completion of services</a>, including for the remainder of medical fees not reimbursed by insurance.&#8221;</p>
<p>The FTC requires &#8220;each financial institution or creditor to develop and implement a written Identity Theft Prevention Program (Program) to detect, prevent, and mitigate identity theft in connection with the opening of certain accounts or certain existing accounts.&#8221; Although the Red Flags Rules do not explicitly require doctor&#8217;s offices to make copies of patient identification, they are often implemented this way. </p>
<p>Ironically, spreading more private information around&#8211; such as high-resolution copies of driver&#8217;s licenses- <em>increases</em> patients&#8217; risk of identity theft.  As a 2008 World Privacy Forum report explained:</p>
<p>&#8220;When patients are, for example, asked for a drivers’ license when checking in to hospitals for surgery, the license itself may be copied or scanned and added into the actual patient file. This can give hospital insiders with criminal tendencies access to a treasure trove of photographic, biometric, and other information that may have been unavailable to them before. <a href="http://www.worldprivacyforum.org/pdf/WPF_RedFlagReport_09242008fs.pdf">The result can be more identity theft (medical and otherwise).</a> </p>
<p>&#8220;&#8230;Just because customer identity proofing is commonplace in the financial sector does not mean that it has translated perfectly or even well to the health care sector. The two sectors have different regulatory requirements, approaches to access points, security, and information flows. Banks and health care providers also have different competencies, staffing capacities, training, and in many cases even procedures when it comes to reviewing and managing customer identification documents.&#8221;</p>
<p>Everyone should have access to medical care&#8211; not just people who have registered with the government and obtained a photo ID. Furthermore, patients should have the right to health care without being forced to give up control of our personal information.  As a patient, I don&#8217;t really want a copy of my Photo ID stored on a crappy unpatched Windows box at my doctor&#8217;s office.  Today&#8217;s patients do not even have the right to know how well doctor&#8217;s offices and hospitals are secured, even in the face of constant reports of medical data breaches. That&#8217;s sick.</p>
<table style="float: right">
<tr>
<td align=right><em>Sherri Davidoff</em></td>
</tr>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/pgp-archives/doctors-require-photo-id-for-treatment-2009-05-28.asc">PGP-signed text: 2009-05-28 (current)</a></td>
</tr>
</table>
</td>
</tr>
</table>



Did you like this article? Share it!


	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F05%2F28%2Fdoctors-require-photo-id-for-treatment&amp;title=Doctors%20Require%20Photo%20ID%20for%20Treatment" title="Digg"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://del.icio.us/post?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F05%2F28%2Fdoctors-require-photo-id-for-treatment&amp;title=Doctors%20Require%20Photo%20ID%20for%20Treatment" title="del.icio.us"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F05%2F28%2Fdoctors-require-photo-id-for-treatment&amp;title=Doctors%20Require%20Photo%20ID%20for%20Treatment" title="StumbleUpon"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F05%2F28%2Fdoctors-require-photo-id-for-treatment&amp;title=Doctors%20Require%20Photo%20ID%20for%20Treatment" title="Reddit"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://slashdot.org/bookmark.pl?title=Doctors%20Require%20Photo%20ID%20for%20Treatment&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F05%2F28%2Fdoctors-require-photo-id-for-treatment" title="Slashdot"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://philosecurity.org/2009/05/28/doctors-require-photo-id-for-treatment/feed</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>TSA &#8220;Secure Flight&#8221;</title>
		<link>http://philosecurity.org/2009/05/18/tsa-secure-flight</link>
		<comments>http://philosecurity.org/2009/05/18/tsa-secure-flight#comments</comments>
		<pubDate>Mon, 18 May 2009 02:22:05 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Transit]]></category>

		<guid isPermaLink="false">http://philosecurity.org/?p=1705</guid>
		<description><![CDATA[On May 15, the first phase of TSA&#8217;s Secure Flight program took effect after years of development. By the end of the year, when you book a flight, the airline will send your name (as specified on your government-issued ID), birthdate, gender, and itinerary to TSA&#8217;s centralized Secure Flight system, where you will be checked [...]]]></description>
			<content:encoded><![CDATA[<p><!-- 2009-05-17 -->On May 15, the first phase of <a href="http://www.tsa.gov/press/releases/2009/0512.shtm">TSA&#8217;s Secure Flight program</a> took effect after years of development. By the end of the year, when you book a flight, the airline will send your name (as specified on your government-issued ID), birthdate, gender, and itinerary to TSA&#8217;s centralized Secure Flight system, where you will be checked against government watch lists. In other words, before you ever set foot in the airport, your travel can be denied. </p>
<p>TSA has stated that Secure Flight record system is <a href="http://www.tsa.gov/assets/pdf/nprm_pae.pdf">exempt to multiple provisions of the Privacy Act</a>. In particular, it claims:</p>
<ul>
<li>&#8220;Exemption from the Access and Amendment Requirements&#8221; which &#8220;relate to an individual&#8217;s ability to request access to and correction of records&#8230;&#8221;</li>
<li>&#8220;Exemption from Requirement to Collect Only Relevant and Necessary Information&#8221;</li>
<li>&#8220;Exemption from the Requirement of Maintaining All Records Used by the Agency in Making a Determination about an Individual with Accuracy, Relevance, Timeliness and Completeness&#8221;</li>
<li>&#8220;Exemption from the Requirement of Judicial Review&#8221;</li>
</ul>
<p>TSA&#8217;s transportation security strategy appears to be based on the logic that by tracking civilians <i>en masse</i> and maintaining secret &#8220;watch lists&#8221; we can somehow identify all people with potentially malicious intent and prevent them from accessing public transportation systems.  (&#8221;Sorry sir, you&#8217;ve already committed three suicide bombings this year, so we can&#8217;t allow you on the plane.&#8221;)</p>
<p><img src="http://philosecurity.org/wp-content/uploads/2009/05/secureflight-cropped-better-300x101.png" alt="secureflight-cropped-better" title="secureflight-cropped-better" width="300" height="101" class="right size-medium wp-image-1766" />Of course, air travel is just a small part of the picture. TSA is also &#8220;responsible for security in <a href="http://www.tsa.gov/assets/pdf/Aviation_and_Transportation_Security_Act_ATSA_Public_Law_107_1771.pdf">all modes of transportation</a>.&#8221; This includes cars, buses, subway and rail.  According to their mandate, presumably even bicyclists would fall under TSA&#8217;s purview. Ground transportation is arguably even more important than aviation security, particularly because so many phone and network cables run along railways and highways. Although TSA has thus far focused their most draconian regulations on the air, they have been asserting increasing control over ground public transportation.</p>
<p>Last September, TSA flexed their ground-transportation muscles when they mobilized TSA and Amtrak security teams &#8220;from approximately 100 commuter rail, state, and local police agencies&#8230; for the largest joint, simultaneous Northeast rail security operation of its kind, involving 150 railway stations between Fredericksburg, Virginia, and Essex Junction, Vermont.&#8221;</p>
<p>What prompted this massive security exercise?</p>
<p><a href="http://www.tsa.gov/press/releases/2008/0923.shtm">&#8220;The morning rush-hour multi-force security deployment was NOT in response to any particular threat or incident</a>, but rather a demonstration of an ongoing collaborative effort to expand counter-terrorism and incident response capabilities up and down the Northeast Corridor railway system,&#8221; wrote TSA in a press release.</p>
<p>I see.</p>
<p>Let&#8217;s follow the TSA&#8217;s strategy to its logical conclusion. If we accept Secure Flight as a valid security strategy, then in order to effectively and fully &#8220;secure&#8221; our transportation infrastructure, we would need to:</p>
<ul>
<li>Track everyone traveling on a highway, subway, bus, train, or plane;</li>
<li>Track everyone in or near a transportation interchange;</li>
<li>Accurately identify every person (ultimately, using biometrics or similar);</li>
<li>Compare identification to meticulously-maintained &#8220;watch lists&#8221;; </li>
<li>Selectively deny travel based on secret information stored in government databases</li>
</ul>
<p>Even then, it only takes one sneaky attacker to dodge the system and cause havoc. Furthermore, tracking every citizen is an extremely high-impact, resource-intensive strategy, which will require deep, fundamental, rather frightening changes in our society. It requires the abolishment of free society, placing our freedom to travel in the hands of an un-auditable, un-elected elite. </p>
<p>By treating citizens as potential enemy combatants, we waste money and actually degrade our nation&#8217;s security.  This concept is summarized neatly in the Tao Te Ching: &#8220;<a href="http://www.shambhala.com/html/catalog/items/isbn/978-0-87773-452-9.cfm?selectedtext=EXCERPT_CHAPTER">do not use arms to coerce the world</a>, for these things tend to reverse&#8211; brambles grow where an army has been&#8230; Weapons are inauspicious instruments, not the tools of the enlightened.&#8221; <em>(Translation: Thomas Cleary)</em></p>
<p>What is a more effective strategy? The key is to examine incentives that lead up to attacks. Millions of people around the world, including American citizens, feel that they have been treated unfairly by United States corporations and the government. </p>
<p>Rather than feeding the fire by treating innocent civilians like potential enemy combatants, perhaps we should spend that money on 1) actually improving quality of life for civilians; 2) diplomatically resolving conflicts; 3) genuinely improving the resilience of our critical infrastructure; 4) non-proliferation and weapons-tracking efforts.</p>
<p>&#8220;When welfare and justice embrace the whole people, when public works are sufficient to meet national emergenices, when the policy of selection for office is satisfactory to the intelligent, when planning is sufficient to know strengths and weaknesses, that is the basis of certain victory.&#8221; <i>(Cleary, Translator&#8217;s Introduction to the <u>Art of War</u>)</i></p>
<table style="float: right">
<tr>
<td align=right><em>Sherri Davidoff</em></td>
</tr>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/pgp-archives/tsa-secure-flight-2009-05-17.asc">PGP-signed text: 2009-05-17 (current)</a></td>
</tr>
</table>
</td>
</tr>
</table>



Did you like this article? Share it!


	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F05%2F18%2Ftsa-secure-flight&amp;title=TSA%20%22Secure%20Flight%22" title="Digg"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://del.icio.us/post?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F05%2F18%2Ftsa-secure-flight&amp;title=TSA%20%22Secure%20Flight%22" title="del.icio.us"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F05%2F18%2Ftsa-secure-flight&amp;title=TSA%20%22Secure%20Flight%22" title="StumbleUpon"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F05%2F18%2Ftsa-secure-flight&amp;title=TSA%20%22Secure%20Flight%22" title="Reddit"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://slashdot.org/bookmark.pl?title=TSA%20%22Secure%20Flight%22&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F05%2F18%2Ftsa-secure-flight" title="Slashdot"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://philosecurity.org/2009/05/18/tsa-secure-flight/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Identity Thief&#8217;s Best Friend</title>
		<link>http://philosecurity.org/2009/05/11/identity-thiefs-best-friend</link>
		<comments>http://philosecurity.org/2009/05/11/identity-thiefs-best-friend#comments</comments>
		<pubDate>Mon, 11 May 2009 06:41:28 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Credit Cards]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://philosecurity.org/?p=1611</guid>
		<description><![CDATA[Today I got a charming letter in the mail from Citibank informing me that:

&#8220;A paper trail is an identity thief&#8217;s best friend. Sign up for paperless statements and you can rest easy knowing all your account information is locked away safely online.&#8221; 
Ahahahahaha!&#8230;ha&#8230; ha&#8230; When&#8217;s the last time you heard about millions of credit card [...]]]></description>
			<content:encoded><![CDATA[<p><!-- 2009-05-11 -->Today I got a charming letter in the mail from Citibank informing me that:</p>
<p><img src="http://philosecurity.org/wp-content/uploads/2009/05/paper_trail_bigger.jpg" alt="paper_trail_bigger" title="paper_trail_bigger" width="432" height="35" class="center size-full wp-image-1642" /></p>
<p><em>&#8220;A paper trail is an identity thief&#8217;s best friend. Sign up for paperless statements and you can rest easy knowing all your account information is locked away safely online.&#8221; </em></p>
<p>Ahahahahaha!&#8230;ha&#8230; ha&#8230; When&#8217;s the last time you heard about millions of credit card numbers being stolen from the <em>mail</em>? Somehow I don&#8217;t recall identity theft being such a big deal before online financial systems started taking off. In much the same way that the Bush administration linked Saddam Hussein to 9/11, credit card companies are now campaigning to link &#8220;identity theft&#8221; and&#8230; paper.</p>
<p>This brilliantly twisted marketing campaign:<br />
1) Fuels the &#8220;identity theft&#8221; fear-mongering, increasing identity theft protection sales.<br />
2) Reduces the number of individuals who will be able to independently verify and access statements down the road<br />
3) Saves Citibank money on paper (which also benefits the environment, but that isn&#8217;t Citibank&#8217;s motivation)<br />
4) Instills a false sense of security regarding the safety of web-based account management systems<br />
5) Increases customers&#8217; risk of identity theft by promoting the use of insecure, online web based account management systems (which will subsequently lead to more &#8220;identity theft protection&#8221; sales&#8230; yay!) </p>
<p><a href="http://philosecurity.org/wp-content/uploads/2009/05/citi_envelope.jpg"><img src="http://philosecurity.org/wp-content/uploads/2009/05/citi_envelope-300x156.jpg" alt="citi_envelope" title="citi_envelope" width="250" height="130" class="right size-medium wp-image-1649" /></a>I&#8217;d feel a lot safer if all of my account information were locked away in my own fireproof filing cabinet.  Unfortunately, it&#8217;s clearly not. Less than a month ago Citibank sent me a new card because one of <em>their</em> payment processors lost millions of people&#8217;s account information, including mine.</p>
<p>An identity thief&#8217;s friends are the vast legions of computers running Windows with Internet Explorer that people use to login to their online accounts (with re-used passwords such as &#8220;fluffy2009&#8243;). Identity thieves are also pretty chummy with payment processors such as Heartland, who recently lost over 100 million of credit card numbers. </p>
<p>Identity thieves&#8217; best friends in the <u>world</u> are the credit card companies themselves, who have created a system rife with holes, and subsequently profit from their own systematic failures through scams such as &#8220;identity theft protection&#8221; services. </p>
<p>What chutzpah.</p>
<table style="float: right">
<tr>
<td align=right><em>Sherri Davidoff</em></td>
</tr>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/pgp-archives/identity-thiefs-best-friend-2009-05-11b.asc">PGP-signed text: 2009-05-11 (current)</a></td>
</tr>
<tr>
<td align="right"><a href="http://philosecurity.org/wp-content/uploads/pgp-archives/identity-thiefs-best-friend-2009-05-11.asc">2009-05-11 (version 0)</a></td>
</tr>
</table>
</td>
</tr>
</table>



Did you like this article? Share it!


	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F05%2F11%2Fidentity-thiefs-best-friend&amp;title=Identity%20Thief%27s%20Best%20Friend" title="Digg"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://del.icio.us/post?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F05%2F11%2Fidentity-thiefs-best-friend&amp;title=Identity%20Thief%27s%20Best%20Friend" title="del.icio.us"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F05%2F11%2Fidentity-thiefs-best-friend&amp;title=Identity%20Thief%27s%20Best%20Friend" title="StumbleUpon"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F05%2F11%2Fidentity-thiefs-best-friend&amp;title=Identity%20Thief%27s%20Best%20Friend" title="Reddit"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://slashdot.org/bookmark.pl?title=Identity%20Thief%27s%20Best%20Friend&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F05%2F11%2Fidentity-thiefs-best-friend" title="Slashdot"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://philosecurity.org/2009/05/11/identity-thiefs-best-friend/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>If You See Something&#8230;</title>
		<link>http://philosecurity.org/2009/04/26/if-you-see-something</link>
		<comments>http://philosecurity.org/2009/04/26/if-you-see-something#comments</comments>
		<pubDate>Sun, 26 Apr 2009 18:21:44 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://philosecurity.org/?p=1558</guid>
		<description><![CDATA[













Sherri Davidoff


PGP-signed text: 2009-04-26 (current)





Last week, the evening before speaking at the RSA Conference in San Francisco, we saw a large black suitcase sitting by the main entrance of the Courtyard Marriott. It appeared to have been left behind by an unfortunate traveler.
We walked up to the front desk to let the hotel know. &#8220;Oh,&#8221; [...]]]></description>
			<content:encoded><![CDATA[<table align="right" cellspacing=0 cellpadding=0>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/2009/04/bench1_small.jpg"><img src="http://philosecurity.org/wp-content/uploads/2009/04/bench1_small-150x150.jpg" alt="bench1_small" title="bench1_small" width="150" height="150" class="right size-thumbnail wp-image-1572" /></a></td>
</tr>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/2009/04/front_desk_small.jpg"><img src="http://philosecurity.org/wp-content/uploads/2009/04/front_desk_small-150x150.jpg" alt="front_desk_small" title="front_desk_small" width="150" height="150" class="right" /></a></td>
</tr>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/2009/04/bench_2a.jpg"><img src="http://philosecurity.org/wp-content/uploads/2009/04/bench_2a-150x150.jpg" alt="bench_2a" title="bench_2a" width="150" height="150" class="right size-thumbnail wp-image-1591" /></a></td>
</tr>
<tr>
<td>
<table style="float: right">
<tr>
<td align=right><em>Sherri Davidoff</em></td>
</tr>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/pgp-archives/if-you-see-something-2009-04-26.asc">PGP-signed text: 2009-04-26 (current)</a></td>
</tr>
</table>
</td>
</tr>
</table>
<p><!--2009-04-26-->Last week, the evening before speaking at the RSA Conference in San Francisco, we saw a large black suitcase sitting by the main entrance of the Courtyard Marriott. It appeared to have been left behind by an unfortunate traveler.</p>
<p>We walked up to the front desk to let the hotel know. &#8220;Oh,&#8221; sighed the Marriott employee. &#8220;We get that all the time.&#8221;</p>
<p>Apparently, as part of the Marriott&#8217;s design theme, the hotel had installed realistic sculptures of unattended personal items all over the ground floor. </p>
<p>Out front there were two lonely suitcases, each left beside a different bench near the valet. Inside, there were a couple more suitcases, an outdated cell phone and a wallet on the bar. </p>
<p>Obviously a <a href="http://www.mta.info/mta/news/newsroom/images/high-res/seesomething2_hi.jpg">pre-9/11 design concept&#8230;</a></p>



Did you like this article? Share it!


	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F04%2F26%2Fif-you-see-something&amp;title=If%20You%20See%20Something..." title="Digg"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://del.icio.us/post?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F04%2F26%2Fif-you-see-something&amp;title=If%20You%20See%20Something..." title="del.icio.us"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F04%2F26%2Fif-you-see-something&amp;title=If%20You%20See%20Something..." title="StumbleUpon"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F04%2F26%2Fif-you-see-something&amp;title=If%20You%20See%20Something..." title="Reddit"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://slashdot.org/bookmark.pl?title=If%20You%20See%20Something...&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F04%2F26%2Fif-you-see-something" title="Slashdot"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://philosecurity.org/2009/04/26/if-you-see-something/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Squid Forensics</title>
		<link>http://philosecurity.org/2009/04/19/squid-forensics</link>
		<comments>http://philosecurity.org/2009/04/19/squid-forensics#comments</comments>
		<pubDate>Sun, 19 Apr 2009 02:22:52 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://philosecurity.org/?p=1429</guid>
		<description><![CDATA[Cephalopod autopsies? Nope, today&#8217;s article is about conducting forensics on a Squid web proxy/cache. Just as complicated, but less smelly.
Chances are pretty good that you&#8217;re reading this page through a web proxy right now, especially if you&#8217;re in an enterprise environment. Web proxying and caching have become increasingly popular, for both filtering traffic and speeding [...]]]></description>
			<content:encoded><![CDATA[<p><!-- 2009-04-18 -->Cephalopod autopsies? Nope, today&#8217;s article is about conducting forensics on a Squid web proxy/cache. Just as complicated, but less smelly.</p>
<p><img src="http://philosecurity.org/wp-content/uploads/2009/04/faroe_stamp_409_ten_armed_squid1-245x300.jpg" alt="faroe_stamp_409_ten_armed_squid1" title="faroe_stamp_409_ten_armed_squid1" width="245" height="300" class="right size-medium wp-image-1504" />Chances are pretty good that you&#8217;re reading this page through a web proxy right now, especially if you&#8217;re in an enterprise environment. Web proxying and caching have become increasingly popular, for both filtering traffic and speeding up requests. Even consumer ISPs have latched onto the idea (sometimes using similar techniques to <a href="http://blog.wired.com/27bstroke6/2007/12/canadian-isps-p.html">insert ads into pages</a> as they are downloaded).  That means your web surfing history is probably being recorded in a proxy log somewhere. </p>
<p>Web proxy and cache servers are untapped gold mines for forensic analysts. They often record the web browsing history for an entire organization, all rolled up into one directory. Web caching servers also contain copies of pages themselves, for a limited time.  </p>
<p>This is great for forensic analysts (and not so hot from a privacy perspective). Investigators can examine web browsing histories for everyone in an organization all at once. Moreover, it&#8217;s possible to reconstruct web pages from the cache. Right now, investigators often simply visit web sites in order to see what they are. This has some serious drawbacks: first, there is no guarantee you&#8217;re seeing what the end user saw earlier; and second, your surfing now appears in the server&#8217;s activity logs. If the owner of the server is an attacker or suspect, you may well have just tipped them off. It&#8217;s much better to first examine the web cache to see what you can find stored locally. </p>
<p>To learn more, I installed <a href="http://www.squid-cache.org/">Squid</a>, a popular web proxy/cache server, on my lab network and dissected it. There are a number of tools out there that will reconstruct client browsing history, based the access logs. I really liked <a href="http://www.rillion.net/squidview/">squidview</a> (which has a Kismet-style interface) and <a href="http://sarg.sourceforge.net/">sarg</a> (HTML clickable). </p>
<p>What I didn&#8217;t find was public information or tools for reconstructing pages from the web cache. It&#8217;s definitely possible. The proxy cache, by its very nature, stores the pages you view on its local hard drive and may later serve those pages to you or someone else. The precise pages it stores and the length of time they are retained vary depending on the specific server configuration and usage. </p>
<p>As a forensic analyst, I wanted to recover those cached pages. I figured, if Squid could do it, so could I.</p>
<p>By changing Squid&#8217;s configuration to &#8220;offline&#8221; mode, you can use <a href="http://www.gnu.org/software/wget/">wget</a> to extract some pages directly from the local cache. This is handy because it reconstructs the pages automatically, if they exist. However, I wanted to see what information was stored directly in the cache, and access associated headers and metadata.</p>
<p>Squid&#8217;s access log is straightforward: it&#8217;s essentially a text file which contains a list of client  IP addresses and pages accessed. If you correlate these with DHCP and central authentication logs, you can potentially match web surfing activity to a particular network card or user. </p>
<p>The cache directory is far more mysterious. If you simply list the directory contents, here is what you will see:</p>
<p><strong>$ ls<br />
00  01  02  03  04  05  06  07  08  09  0A  0B  0C  0D  0E  0F  swap.state<br />
</strong><br />
Daunting. That swap.state file is Squid&#8217;s database, which contains a record of every item in the cache. It&#8217;s a binary file. If you delete it while Squid isn&#8217;t running, Squid will actually re-create it the next time it starts up. (This is helpful if you&#8217;re trying to manually edit the Squid cache in order to create lab exercises for, oh, <a href="http://www.sans.org/training/description.php?mid=1227">a new class on network forensics</a>.)</p>
<p>Within each of those subdirectories are files such as these:<br />
<a href="http://philosecurity.org/wp-content/uploads/2009/04/squid-screenshot21.png"><img src="http://philosecurity.org/wp-content/uploads/2009/04/squid-screenshot21-300x114.png" alt="squid-screenshot21" title="squid-screenshot21" width="300" height="114" class="center size-medium wp-image-1517" /></a><br />
And each of <em>those</em> subdirectories contains files such as this:</p>
<p><a href="http://philosecurity.org/wp-content/uploads/2009/04/squid-file-list1.png"><img src="http://philosecurity.org/wp-content/uploads/2009/04/squid-file-list1-300x170.png" alt="squid-file-list1" title="squid-file-list1" width="300" height="170" class="alignright size-medium wp-image-1519" /></a><br />
Finally, each of those eight-character files contains- yes! &#8211; the pages actually cached by Squid. Here is an <a href="http://philosecurity.org/wp-content/uploads/2009/04/0000036A">example</a>. When you surf to a web page, Squid will add some metadata to the top, which includes the full URI and its MD5sum. Squid then stores this, along with the full HTTP reply (headers and body) as a file in one of these subdirectories. If the page is requested later, it can look it up in swap.state and fetch it.</p>
<p>Now let&#8217;s extract some content directly from the cache. </p>
<p>Let&#8217;s say we&#8217;re analyzing web traffic associated with 192.168.1.26. We come across the following entry in Squid&#8217;s access.log:</p>
<p><strong>1239739309.653    377 192.168.1.26 TCP_MISS/200 30348 GET http://finickypenguin.files.wordpress.com/2007/10/1161451564593.jpg &#8211; DIRECT/72.233.69.12 image/jpeg</strong></p>
<p>Interesting&#8230; What is this image? Let&#8217;s see if it&#8217;s in the cache. </p>
<p>We could analyze swap.state, but I created my own table of the URIs stored in Squid, along with their corresponding cache files. This was for two reasons: first, I didn&#8217;t have to rely on the accuracy of Squid&#8217;s database; and second, I&#8217;m a lazy bum and it&#8217;s pretty easy to do using a simple Bash script.  The URI is stored near the beginning of each cached page, just after the MD5sum of the URI. If you grep for strings beginning with &#8220;http&#8221; in the first few lines of each cache file, you&#8217;ll find it.  </p>
<p>Here&#8217;s that file we were looking for:<br />
<strong>./00/03/<a href="http://philosecurity.org/wp-content/uploads/2009/04/0000036A">0000036A</a> &nbsp;&nbsp; http://finickypenguin.files.wordpress.com/2007/10/1161451564593.jpg<br />
</strong><br />
Now let&#8217;s open up that cache file. Running strings on it, we see the following metadata and header info:<br />
<a href="http://philosecurity.org/wp-content/uploads/2009/04/endcat-strings-cropped.png"><img src="http://philosecurity.org/wp-content/uploads/2009/04/endcat-strings-cropped-300x150.png" alt="endcat-strings-cropped" title="endcat-strings-cropped" width="300" height="150" class="center size-medium wp-image-1481" /></a><br />
Lots of juicy info there. To extract the image itself, let&#8217;s open this up in a hex editor. I like to use &#8220;bless&#8221; on Ubuntu. JPEG images begin with &#8220;FFD8,&#8221; so extracting this content is fairly easy. Highlight everything before the magic number, click &#8220;Cut&#8221; and save as 0000036A-edited.jpg.<br />
<a href="http://philosecurity.org/wp-content/uploads/2009/04/bless-squid2-edited.png"><img src="http://philosecurity.org/wp-content/uploads/2009/04/bless-squid2-edited-300x177.png" alt="bless-squid2-edited" title="bless-squid2-edited" width="300" height="177" class="alignright size-medium wp-image-1484" /></a></p>
<p>A quick check with &#8220;file&#8221; confirms that we got it right:<br />
<strong>$ file 0000036A-edited.jpg<br />
0000036A-edited.jpg: JPEG image data, JFIF standard 1.01<br />
</strong><br />
Now let&#8217;s open it up:</p>
<p><a href="http://philosecurity.org/wp-content/uploads/2009/04/0000036a-edited.jpg"><img src="http://philosecurity.org/wp-content/uploads/2009/04/0000036a-edited-300x212.jpg" alt="0000036a-edited" title="0000036a-edited" width="300" height="212" class="center size-medium wp-image-1478" /></a></p>
<p>Looks pretty suspicious to me&#8230;<br />
&nbsp;</p>
<table style="float: right">
<tr>
<td align=right><em>Sherri Davidoff</em></td>
</tr>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/pgp-archives/squid-forensics-2009-04-18.asc">PGP-signed text: 2009-04-18 (current)</a></td>
</tr>
</table>



Did you like this article? Share it!


	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F04%2F19%2Fsquid-forensics&amp;title=Squid%20Forensics" title="Digg"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://del.icio.us/post?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F04%2F19%2Fsquid-forensics&amp;title=Squid%20Forensics" title="del.icio.us"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F04%2F19%2Fsquid-forensics&amp;title=Squid%20Forensics" title="StumbleUpon"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F04%2F19%2Fsquid-forensics&amp;title=Squid%20Forensics" title="Reddit"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://slashdot.org/bookmark.pl?title=Squid%20Forensics&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F04%2F19%2Fsquid-forensics" title="Slashdot"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://philosecurity.org/2009/04/19/squid-forensics/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Dirty Public Cell Phones</title>
		<link>http://philosecurity.org/2009/04/06/dirty-public-cell-phones</link>
		<comments>http://philosecurity.org/2009/04/06/dirty-public-cell-phones#comments</comments>
		<pubDate>Mon, 06 Apr 2009 03:44:13 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Transit]]></category>

		<guid isPermaLink="false">http://philosecurity.org/?p=1374</guid>
		<description><![CDATA[I love the Minneapolis airport. For an information security geek, it never fails to provide some interesting gem. 


Wandering through the airport this week I ran across a Delta &#8220;Helpline&#8221; kiosk (formerly Northwest&#8217;s Rebook Service Center).  Every time I walk through the airport I see these gray kiosks closed up and pushed aside in [...]]]></description>
			<content:encoded><![CDATA[<p><!-- 2009-04-05 -->I love the Minneapolis airport. For an information security geek, it never fails to provide some interesting gem. </p>
<table>
<tr>
<td>Wandering through the airport this week I ran across a Delta &#8220;Helpline&#8221; kiosk (formerly Northwest&#8217;s Rebook Service Center).  Every time I walk through the airport I see these gray kiosks closed up and pushed aside in some corner.
</td>
<td>
<img src="http://philosecurity.org/wp-content/uploads/2009/04/nwa_cart3-254x300.jpg" alt="nwa_cart3" title="nwa_cart3" width="190" height="225" class="right size-medium wp-image-1400" />
</td>
</tr>
<tr>
<td>As luck would have it, this one was open. There were several cell phones sitting on it, tethered to desks. A sign instructed users to contact a Northwest agent by picking up the phone and dialing &#8220;1692 #TALK.&#8221;
</td>
<td>
<img src="http://philosecurity.org/wp-content/uploads/2009/04/helpline-desk3-297x300.jpg" alt="helpline-desk3" title="helpline-desk3" width="168" height="168" class="right size-medium wp-image-1404" />
</td>
</tr>
<tr>
<td>
&#8220;The phone can only be used to access the Northwest Customer Service Rebook Hotline,&#8221; concluded the sign.</p>
<p>Apparently, that didn&#8217;t stop people from trying (and perhaps succeeding). The phone allowed full access to call history, revealing all outbound numbers that had been dialed, to both cell phones and land lines:
</td>
<td>
<img src="http://philosecurity.org/wp-content/uploads/2009/04/helpline_cell1-225x300.jpg" alt="helpline_cell1" title="helpline_cell1" width="168" height="225" class="right size-medium wp-image-1382" />
</td>
</tr>
<tr>
<td>
What&#8217;s more, the phone also allowed full access to configuration information, including Northwest&#8217;s Sprint user account name and associated phone IDs.
</td>
<td>
<img src="http://philosecurity.org/wp-content/uploads/2009/04/helpline_cell31-225x300.jpg" alt="helpline_cell31" title="helpline_cell31" width="168" height="225" class="right size-medium wp-image-1389" />
</td>
</tr>
<tr>
<td>
Funky. Reminds me of a public toilet that never gets cleaned.
</td>
<td>
<img src="http://philosecurity.org/wp-content/uploads/2009/04/helpline-kiosk-300x264.jpg" alt="helpline-kiosk" title="helpline-kiosk" width="168" height="148" class="right size-medium wp-image-1421" />
</td>
</tr>
</table>
<p>&nbsp;</p>
<table style="float: right">
<tr>
<td align=right><em>Sherri Davidoff</em></td>
</tr>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/pgp-archives/dirty-public-cell-phones-2009-04-05.asc">PGP-signed text: 2009-04-05 (current)</a></td>
</tr>
</table>



Did you like this article? Share it!


	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F04%2F06%2Fdirty-public-cell-phones&amp;title=Dirty%20Public%20Cell%20Phones" title="Digg"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://del.icio.us/post?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F04%2F06%2Fdirty-public-cell-phones&amp;title=Dirty%20Public%20Cell%20Phones" title="del.icio.us"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F04%2F06%2Fdirty-public-cell-phones&amp;title=Dirty%20Public%20Cell%20Phones" title="StumbleUpon"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F04%2F06%2Fdirty-public-cell-phones&amp;title=Dirty%20Public%20Cell%20Phones" title="Reddit"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://slashdot.org/bookmark.pl?title=Dirty%20Public%20Cell%20Phones&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F04%2F06%2Fdirty-public-cell-phones" title="Slashdot"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://philosecurity.org/2009/04/06/dirty-public-cell-phones/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IBM’s Watchful Eye</title>
		<link>http://philosecurity.org/2009/04/02/ibm%e2%80%99s-watchful-eye</link>
		<comments>http://philosecurity.org/2009/04/02/ibm%e2%80%99s-watchful-eye#comments</comments>
		<pubDate>Thu, 02 Apr 2009 20:12:26 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://philosecurity.org/?p=1266</guid>
		<description><![CDATA[This week, IBM ran a full-page ad in the Wall Street Journal, which advertised that:
New York&#8217;s  &#8220;Real Time Crime Center can quickly query millions of pieces of information to uncover previously unknown data relationships and points of connection.&#8221;
In Poland &#8220;personal and vehicle IDs can be instantly checked in an EU-wide database.&#8221;
In Chicago:  city [...]]]></description>
			<content:encoded><![CDATA[<p><!-- 2009-04-02 -->This week, IBM ran a full-page ad in the <em>Wall Street Journal</em>, which advertised that:</p>
<p><a href="http://philosecurity.org/wp-content/uploads/2009/04/hollerith.jpg"><img src="http://philosecurity.org/wp-content/uploads/2009/04/hollerith-223x300.jpg" alt="Ad for Hollerith punch card machine" title="Ad for Hollerith punch card machine" width="223" height="300" class="right size-medium wp-image-1269" /></a>New York&#8217;s <em> &#8220;Real Time Crime Center can quickly query millions of pieces of information to uncover previously unknown data relationships and points of connection.&#8221;</em></p>
<p>In Poland <em>&#8220;personal and vehicle IDs can be instantly checked in an EU-wide database.&#8221;</em></p>
<p>In Chicago:  city staff <em>&#8220;have access to video from a multitude of cameras citywide, with advanced analytics built into the infrastructure, that are connected to a fiber/wireless network to assist the operator with potential &#8216;eyes-on-the-scene&#8217; in the vicinity of an incident.&#8221;</em></p>
<p>I&#8217;m all for fighting crime, but these vast, nascent public surveillance programs which have minimal public input and oversight are pretty frightening.  If you&#8217;re familiar with the <a href="http://www.amazon.com/IBM-Holocaust-Strategic-Alliance-Corporation/dp/0609808990">history of IBM</a>, their massive surveillance operations are especially creepy.  &#8220;IBM was founded in 1898 by German inventor Herman Hollerith as a census tabulating company. Census was its business,&#8221; wrote Edwin Black in his 2001 book, <em>IBM and the Holocaust</em>. </p>
<p>During the 1930s, IBM subsidiaries worked closely with the Nazis to develop and maintain the registration and tracking systems which were the foundation of their extermination operations. <a href="http://www.scrapbookpages.com/AuschwitzScrapbook/History/Articles/IBMpunchcards.html">&#8220;IBM&#8217;s custom-designed prisoner-tracking</a> Hollerith punch card equipment allowed the Nazis to efficiently manage the hundreds of concentration camps and sub-camps throughout Europe, as well as the millions who passed through them. Auschwitz&#8217; camp code in the IBM tabulation system was 001.&#8221; <em>(Black, 2002)</em></p>
<p>&#8220;The image of a tattooed number on the forearm of a death-camp survivor is one of the most recognized symbols of the Holocaust. Black shows that these numbers initially correlated to the <a href="http://www.allbusiness.com/buying_exiting_businesses/3580595-1.html">IBM Hollerith punch-card system</a>.&#8221; <em>(AllBusiness, 2002)</em></p>
<p>Of course, the level of surveillance that we are experiencing today far surpasses anything seen by those living in Nazi Germany. Between <a href="http://works.bepress.com/frederick_coolbroth/1/">GPS-tracked cell phones</a>, <a href="http://en.wikipedia.org/wiki/Automatic_number_plate_recognition">OCR license-plate readers</a>, and <a href="http://philosecurity.org/2008/12/21/watching-big-brother">full-fledged city video surveillance systems</a>, both corporations and law enforcement can track private citizens&#8217; moment-to-moment activities. </p>
<p>What&#8217;s happening with all this data? The answer is: we (the public) don&#8217;t know. From traffic cameras to full-scale city monitoring systems, mass surveillance programs are being put into place with very little publicized detail regarding information security or data management. Conversely, the implementers seem to have taken a &#8220;security through obscurity&#8221; approach, where public disclosure of surveillance IT management practices is seen as a threat to security itself.  </p>
<p><a href="http://philosecurity.org/wp-content/uploads/2009/04/newpaper_ibm.jpg"><img src="http://philosecurity.org/wp-content/uploads/2009/04/newpaper_ibm-150x150.jpg" alt="IBM&#039;s WSJ ad 4/1/2009" title="IBM&#039;s WSJ ad 4/1/2009" width="170" height="170" class="right size-medium wp-image-1328" /></a><em>&#8220;Billions of records, accessible in minutes,&#8221;</em> reads an IBM advertisement.<em> &#8220;At the heart of the Real Time Crime Center is IBM Crime Information Warehouse technology&#8230; Advanced data-mining technology provides investigators with access to billions of records.&#8221;<br />
</em> </p>
<p><u>Challenge: can you find any record of IT security audits of New York&#8217;s powerful public surveillance center, or even just indications that regular IT security audits occur?</u> I can&#8217;t. (If you do, post!) If these records exist, they sure aren&#8217;t easily accessible by the public. Don&#8217;t we deserve verifiable evidence that our personal information is being responsibly managed? </p>
<p>As anyone in the open-source or cryptographic community knows, security through obscurity doesn&#8217;t make a system more secure. In the case of mass surveillance and tracking systems, the public is being denied the ability to verify that our data is securely and appropriately managed.</p>
<p>Moreover, what exactly are government and contractors doing with all of this very personal data? Contractors such as IBM are collecting an enormous amount of personal data, yet the public receives very little detail about how long our information is kept, who has access, and precisely how our data managed or used &#8212; other than vague, unverified assurances that our information is managed in accordance with regulation. It is impossible for us to assess compliance with referenced privacy and information security regulations without any real data.</p>
<p>Mass surveillance is an extremely powerful tool which is here to stay. Electronic mass tracking systems essentially obviate the need for punch cards and tattooed numbers, while serving effectively the same purpose.  &#8220;It was the use of raw numbers, punch cards, statistical expertise, and identification cards that made [Nazi genocide] possible&#8230;&#8221; write Aly and Roth in their excellent book, <em>The Nazi Census</em>. <a href="http://www.google.com/books?id=U-GhQrKj9vQC&#038;dq=the+nazi+census&#038;printsec=frontcover&#038;source=bn#PPR8,M1">&#8220;Every act of extermination was preceded by an act of registration.&#8221;</a></p>
<p>In a free society, the public must have the ability to actively provide input and receive feedback regarding the collection, maintenance and use of our tracking information, surveillance photographs and videos.   If mass surveillance systems are not controlled by the population under surveillance, they will be (and have been) used for oppression. &#8220;Knowledge is power.&#8221;<br />
&nbsp;</p>
<table style="float: right">
<tr>
<td align=right><em>Sherri Davidoff</em></td>
</tr>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/pgp-archives/ibms-watchful-eye-2009-04-02.asc">PGP-signed text: 2009-04-02 (current)</a></td>
</tr>
</table>



Did you like this article? Share it!


	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F04%2F02%2Fibm%25e2%2580%2599s-watchful-eye&amp;title=IBM%E2%80%99s%20Watchful%20Eye" title="Digg"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://del.icio.us/post?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F04%2F02%2Fibm%25e2%2580%2599s-watchful-eye&amp;title=IBM%E2%80%99s%20Watchful%20Eye" title="del.icio.us"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F04%2F02%2Fibm%25e2%2580%2599s-watchful-eye&amp;title=IBM%E2%80%99s%20Watchful%20Eye" title="StumbleUpon"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F04%2F02%2Fibm%25e2%2580%2599s-watchful-eye&amp;title=IBM%E2%80%99s%20Watchful%20Eye" title="Reddit"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://slashdot.org/bookmark.pl?title=IBM%E2%80%99s%20Watchful%20Eye&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F04%2F02%2Fibm%25e2%2580%2599s-watchful-eye" title="Slashdot"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://philosecurity.org/2009/04/02/ibm%e2%80%99s-watchful-eye/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Pirates and Ninjas: Emacs or Vi?</title>
		<link>http://philosecurity.org/2009/03/23/pirates-and-ninjas-emacs-or-vi</link>
		<comments>http://philosecurity.org/2009/03/23/pirates-and-ninjas-emacs-or-vi#comments</comments>
		<pubDate>Mon, 23 Mar 2009 08:25:58 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://philosecurity.org/?p=1178</guid>
		<description><![CDATA[In the great debates of Pirates vs. Ninjas and Emacs vs. Vi, there is one overarching question:
Do Pirates and Ninjas use Emacs or Vi?
Philosecurity has conducted countless hours of research, interviewed real ninjas and pirates in their natural environs, and launched intensive laboratory studies involving monkeys in order to bring you, our readers, the scientifically [...]]]></description>
			<content:encoded><![CDATA[<p><!-- 2009-03-23 -->In the great debates of Pirates vs. Ninjas and Emacs vs. Vi, there is one overarching question:</p>
<h2>Do Pirates and Ninjas use Emacs or Vi?</h2>
<p>Philosecurity has conducted countless hours of research, interviewed real ninjas and pirates in their natural environs, and launched intensive laboratory studies involving monkeys in order to bring you, our readers, the scientifically proven answers you demand. </p>
<p>After thousands of hours and monkey brains, our scientists have reached the following conclusions:</p>
<ul>
<li>Pirates use Emacs
<li>
<li>Ninjas Use Vi</li>
</ul>
<p><a href="http://philosecurity.org/wp-content/uploads/2009/03/chart1.jpg">Laboratory results showed that 92% of ninjas preferred vi</a>, while fully <a href="http://philosecurity.org/wp-content/uploads/2009/03/chart2.jpg">96% of pirates used emacs.</a>  In the wild, <a href="http://philosecurity.org/wp-content/uploads/2009/03/chart3.png">these numbers were even higher</a> (94% and 97.5%, respectively). </p>
<p>Philosecurity&#8217;s expert team of scientists conducted an extensive genetic analysis and concluded that pirates were more genetically fit for the emacs programming environment, while ninjas were predisposed for survival in the vi environment. These genetic features can clearly be seen in the following photos of leading emacs and vi users:<br />
<center></p>
<table border=0 width=320>
<tr>
<td><center><strong>Ninja</strong></center></td>
<td><center><strong>Pirate</strong></center></td>
</tr>
<tr>
<td><img src="http://philosecurity.org/wp-content/uploads/2009/03/bill-joy1-150x150.jpg" alt="bill-joy1" title="bill-joy1" width="150" height="150" class="center size-thumbnail wp-image-1180" /></td>
<td><img src="http://philosecurity.org/wp-content/uploads/2009/03/richard-stallman-small-150x150.jpg" alt="richard-stallman-small" title="richard-stallman-small" width="150" height="150" class="center size-thumbnail wp-image-1181" /></td>
</tr>
<tr>
<td><center><strong>Bill Joy<br />Vi Creator</strong><br /><em>Hand placement conceals poison dart</em></center></td>
<td><center><strong>Richard Stallman<br />Emacs Creator</strong><br /><em>Note beard</em></center></td>
</tr>
</table>
<p></center></p>
<p>In order to better understand why, we gathered a team of anthropologists, programming experts, and behavioral psychiatrists to analyze the data. Our experts concluded that there are deep-seated psychological, cultural and evolutionary reasons that pirates use emacs and ninjas use vi. </p>
<h2>Why Ninjas Use Vi</h2>
<p>According to vi&#8217;s author Bill Joy, vi was designed to be usable over &#8220;a 300-baud modem,&#8221; on systems that could &#8220;just barely get the cursor off the bottom line.&#8221;  This was in contrast to Emacs, which &#8220;was written for systems with <a href="http://www.linux.com/feature/19661">blazing fiber-channel links and monster PDP-10&#8217;s.</a>&#8221; <em>(Jackson, Linux.com)</em> Ninjas, who emerged in 15th century feudal Japan, would no doubt have appreciated vi&#8217;s functionality even across limited communications facilities and on older equipment.</p>
<p>Vi is designed to allow &#8220;users of the QWERTY keyboard to keep their fingers on the home row, thus <a href="http://en.wikipedia.org/wiki/Editor_war">requiring less movement to edit</a>.&#8221; This would undoubtedly appeal to ninjas, who are &#8220;skilled in the art of stealth.&#8221; <em>(Wikipedia)</em></p>
<p>Vi was originally designed to do a few things well, and avoid feature bloat.  This also appealed to ninjas, who had to travel light. Over the centuries, ninja evolved increasingly specialized equipment, such as <em>shobo</em> rings to hit pressure points, <em>metsubushi</em> (small bombs) and poison <em>shuriken</em> (throwing weapons). &#8220;The assassination, espionage, and infiltration tasks of the ninja led to the development of <a href="http://en.wikipedia.org/wiki/Ninja">specialized technology in concealable weapons</a> and infiltration tools.&#8221;<em>(Wikpedia)</em> Similarly, over time vi has evolved offshoots such as vim with increasingly powerful features designed for the programming environment.</p>
<p>Vi has two modes:</p>
<ul>
<li>Command mode &#8211; Stealthily leap from line to line, over sentences, leaving no trace.</li>
<li>Insert mode &#8211; Text everywhere</li>
</ul>
<p>Ninjas have two modes: </p>
<ul>
<li>Stealth mode &#8211; Silently leap from tree to tree, over fences, leaving no trace</li>
<li>Battle mode &#8211; Bodies everywhere</li>
</ul>
<p>&nbsp;</p>
<h2>Why Pirates Use Emacs</h2>
<p><a href="http://philosecurity.org/wp-content/uploads/2009/03/screenshot-emacs41.png"><img src="http://philosecurity.org/wp-content/uploads/2009/03/screenshot-emacs41-300x246.png" alt="screenshot-emacs4" title="screenshot-emacs4" width="300" height="246" class="right size-medium wp-image-1200" /></a>Emacs was designed to be &#8220;highly customizable and includes a large number of <a href="http://en.wikipedia.org/wiki/Editor_war">bells and whistles</a>, as it is essentially a Lisp programming language execution environment&#8230;&#8221; <em>(Wikipedia)</em> </p>
<p>Pirates are highly concerned with customization. What they lack in speed they make up for in panache: swanky flags, matching shoulder parrots and even customized limbs with fancy hooks and pegs. Pirates work hard to customize their ships, their costumes, their appendages and their speech. Emacs is traditionally slower than vi, but that wouldn&#8217;t be much concern for pirates, who are usually drunk and missing limbs anyway.</p>
<p>Pirates place themselves along trade routes and routinely raid passing ships, which gives them access to the most modern equipment. One of their overarching professional goals is to accumulate lots of valuable stuff. In the course of daily raids they acquire the most modern technology, which they can then use to run a more resource-intensive programming editor such as Emacs.</p>
<h2>Conclusions</h2>
<p>Based on extensive laboratory research on monkeys, as well as detailed analysis of wild pirate/ninja habitats, Phillosecurity&#8217;s team of experts has uncovered clear evidence that pirates use Emacs and ninjas use vi. The team also identified several cultural and evolutionary factors which have contributed to this trend.</p>
<p>Still, open questions remain. According to leading programming expert Gary Longsine, &#8220;Vampires use vi with an emacs plugin.&#8221; What editors will robots and space aliens prefer? Only time will tell.<br />
&nbsp;</p>
<table style="float: right">
<tr>
<td align=right><em>Sherri Davidoff</em></td>
</tr>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/pgp-archives/pirates-and-ninjas-emacs-or-vi-2009-03-23.1.asc">PGP-signed text: 2009-03-23 (current)</a></td>
</tr>
<tr>
<td align=right><a href="http://philosecurity.org/wp-content/uploads/pgp-archives/pirates-and-ninjas-emacs-or-vi-2009-03-23.asc">2009-03-23 (version 0)</a></td>
</tr>
</table>



Did you like this article? Share it!


	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F03%2F23%2Fpirates-and-ninjas-emacs-or-vi&amp;title=Pirates%20and%20Ninjas%3A%20Emacs%20or%20Vi%3F" title="Digg"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://del.icio.us/post?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F03%2F23%2Fpirates-and-ninjas-emacs-or-vi&amp;title=Pirates%20and%20Ninjas%3A%20Emacs%20or%20Vi%3F" title="del.icio.us"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F03%2F23%2Fpirates-and-ninjas-emacs-or-vi&amp;title=Pirates%20and%20Ninjas%3A%20Emacs%20or%20Vi%3F" title="StumbleUpon"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F03%2F23%2Fpirates-and-ninjas-emacs-or-vi&amp;title=Pirates%20and%20Ninjas%3A%20Emacs%20or%20Vi%3F" title="Reddit"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://slashdot.org/bookmark.pl?title=Pirates%20and%20Ninjas%3A%20Emacs%20or%20Vi%3F&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F03%2F23%2Fpirates-and-ninjas-emacs-or-vi" title="Slashdot"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://philosecurity.org/2009/03/23/pirates-and-ninjas-emacs-or-vi/feed</wfw:commentRss>
		<slash:comments>23</slash:comments>
		</item>
		<item>
		<title>Beyond Hard Drive Forensics</title>
		<link>http://philosecurity.org/2009/03/16/beyond-hard-drive-forensics</link>
		<comments>http://philosecurity.org/2009/03/16/beyond-hard-drive-forensics#comments</comments>
		<pubDate>Mon, 16 Mar 2009 07:24:06 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://philosecurity.org/?p=1139</guid>
		<description><![CDATA[No matter where you go, your computer leaves footprints on the network. When you connect to the network, logon to your workstation, or surf the web, these activities leave trails throughout your employer or ISP&#8217;s network&#8211; even when the administrators are not deliberately trying to monitor your activity.  
Forensic analysts traditionally focus on hard [...]]]></description>
			<content:encoded><![CDATA[<p><!-- 2009-03-16 -->No matter where you go, your computer leaves footprints on the network. When you connect to the network, logon to your workstation, or surf the web, these activities leave trails throughout your employer or ISP&#8217;s network&#8211; even when the administrators are not deliberately trying to monitor your activity.  </p>
<p><img src="http://philosecurity.org/wp-content/uploads/2009/03/fingerprintonpaper.jpg" alt="Finger print" title="fingerprintonpaper" width="154" height="200" class="right wp-image-1140" />Forensic analysts traditionally focus on hard drive analysis, but hard drives are not always accessible, and they don&#8217;t tell the full story. Savvy investigators also include the network environment.  Recently I&#8217;ve been <a href="http://www.sans.org/training/description.php?mid=1227">co-authoring a class on Network Forensics (SANS Sec558)</a>, and I&#8217;ve been building lab networks, collecting evidence for the class exercises, and practicing network forensics in-depth. Here are a few ways that investigators reconstruct computer activity using network forensics.</p>
<p><strong>Web Surfing</strong>: Many organizations use web proxies to improve web surfing performance.  As it happens, web proxies maintain a log of web requests and even  copies of web pages (for a limited period of time). Forensic investigators can use graphical tools such as <a href="http://sarg.sourceforge.net/sarg.php">Sarg</a> to analyze web proxy logs and view a list of client&#8217;s browsing history. Investigators can even extract pages themselves from the web proxy cache with common tools such as <a href="http://www.gnu.org/software/wget/">wget</a>. </p>
<p>By analyzing web proxy logs, investigators can reconstruct browsing history, view downloads, recover social networking information, identify external email accounts, and even obtain usernames and passwords (which are sometimes included in URLs). Web proxies result in faster web browsing and help lower network congestion. As a side effect, they also accumulate logs which record your web browsing history.</p>
<p><strong>Laptop/Mobile Device Tracking</strong>: Investigators can identify a specific laptop even when its IP address changes, and even if it moves to a different network. The network card in your computer has a unique address assigned to it by the manufacturer called the Media Access Control (MAC) address. When you connect your laptop to a hotspot or company network, your network card broadcasts its unique MAC address, and the DHCP server then assigns an IP address to your network card. </p>
<p>Forensic analysts can use DHCP server logs to track which IP addresses belonged to which network cards at a given time. By default, your <a href="http://coffer.com/mac_find/">MAC address also reveals information about the manufacturer</a>, so forensic analysts can infer whether your laptop contains, for example, an Apple-manufactured network interface. </p>
<p>There&#8217;s a catch: <a href="http://www.tech-faq.com/change-mac-address.shtml">You can change your network card&#8217;s MAC address.</a> It&#8217;s actually fairly easy to do, even though most people don&#8217;t bother. A MAC address is really about as reliable as using hair color to describe a suspect. Much of the time, it&#8217;s accurate, and it takes conscious effort to change&#8211; but with a little effort it can be modified. You can even change the MAC address so that it looks as though your network card was made by a different manufacturer.  If someone purposefully changed their MAC address, that would make it harder to link network activity to their specific network card. </p>
<p><strong>Logon History</strong>: In order to comply with regulations such as HIPAA (as well as standard security best practices), organizations frequently configure workstations to send records of events to central logging servers, which collect and store logs from many workstations all in one place. Typically, central logging servers store login times, failed login attempts, and commands that are executed with administrative privileges (the specifics vary depending on the organization). The workstation must be preconfigured to send logs to the central logging server. My favorite log analysis tool is <a href="http://www.splunk.com/">Splunk</a>.  By analyzing a central logging server, forensic investigators can track when you logon (or when you mess up your password), when you run privileged commands, or take other noteworthy actions. </p>
<p><strong>Network traffic</strong>: Forensic investigators who are monitoring active connections can collect all network traffic to and from a specific computer, without the user ever knowing. There are many ways to monitor network traffic. If investigators have the support of network administrators, then the administrators can simply set up a <a href="http://en.wikipedia.org/wiki/Port_mirroring">SPAN port</a> on a router, mirror all traffic, and filter for interesting bits. Some companies do this all the time, filtering for malicious traffic, proprietary data, or even keywords that might indicate employees are angry. Wireless networks are even easier to analyze. Since wireless access points are hubs, every client can potentially capture traffic destined for any other system&#8211; or all systems. Tools such as <a href="http://www.wireshark.org/">Wireshark</a> and <a href="http://www.tcpdump.org/">tcpdump</a> are useful for capturing network traffic (investigators: if you use tcpdump, remember to set the snaplength to zero for full packet contents). </p>
<p>Here are a few things forensic investigators can do with raw traffic captures:</p>
<ul>
<li><em>File carving</em>: Investigators can actually carve files out of raw network traffic and reconstruct file transfers. If you upload a JPG to a web site, send an email attachment, or download an MP3, anyone who has captured your network traffic can reconstruct your file.  Tools such as <a href="http://tcpxtract.sourceforge.net/">tcpxtract</a> are helpful for this purpose. Investigators can also view images and other file formats in real time as they are transferred across the network, using tools like <a href="http://www.ex-parrot.com/~chris/driftnet/">driftnet</a>. </li>
<li><em>Instant message reconstruction</em>: If you&#8217;re not encrypting your instant messages, then they are quite easy to see as they travel across the network. One of my clients once half-jokingly said that he considered deploying a scrolling sign in the lunchroom which broadcast everybody&#8217;s IMs, in order to reduce the amount of IM usage.</li>
<li><em>Email reconstruction</em>: Emails are rarely encrypted as they traverse the network. Much like instant messages, the text is trivial to read. Investigators don&#8217;t even need to go to the trouble of reconstructing files: you can simply run <a href="http://sourceware.org/binutils/docs/binutils/strings.html">&#8220;strings&#8221;</a> on raw packet captures and dump the output to a file (I recommend always checking both ASCII and Unicode output).  If you&#8217;re feeling more interactive, you can also view the raw traffic in a <a href="http://en.wikipedia.org/wiki/Comparison_of_hex_editors">hex editor</a> and read the ASCII output. </li>
<li><em>Web surfing reconstruction</em>: Perhaps your organization doesn&#8217;t have a proxy server, or the forensic investigator doesn&#8217;t have access to it. With access to captured traffic from your computer, investigators can extract your web browsing activity, full page content, and form submissions. </li>
<p>Forensics and privacy are two sides of the same coin.  Both investigators and everyday citizens benefit from understanding the types of personal information that companies, hotspots and ISPs routinely store, and how activity can be tracked and reconstructed. </p>
<p>Check out our three-day class: <a href="http://www.sans.org/training/description.php?mid=1227">SANS Sec558: Network Forensics</a>, scheduled to run this June at SANSFIRE in Washington, DC. We&#8217;ll do lots of advanced, hands-on exercises in which we analyze a virtual network, and spend a full day working as investigative teams to solve a crime. Hope to see some of you there!</p>
<table style="float: right">
<tr>
<td align=right><em>Sherri Davidoff</em></td>
</tr>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/pgp-archives/beyond-hard-drive-forensics-2009-03-16.asc">PGP-signed text: 2009-03-16 (current)</a></td>
</tr>
</table>



Did you like this article? Share it!


	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F03%2F16%2Fbeyond-hard-drive-forensics&amp;title=Beyond%20Hard%20Drive%20Forensics" title="Digg"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://del.icio.us/post?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F03%2F16%2Fbeyond-hard-drive-forensics&amp;title=Beyond%20Hard%20Drive%20Forensics" title="del.icio.us"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F03%2F16%2Fbeyond-hard-drive-forensics&amp;title=Beyond%20Hard%20Drive%20Forensics" title="StumbleUpon"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F03%2F16%2Fbeyond-hard-drive-forensics&amp;title=Beyond%20Hard%20Drive%20Forensics" title="Reddit"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://slashdot.org/bookmark.pl?title=Beyond%20Hard%20Drive%20Forensics&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F03%2F16%2Fbeyond-hard-drive-forensics" title="Slashdot"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://philosecurity.org/2009/03/16/beyond-hard-drive-forensics/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Rogue Wireless Gets Sneakier</title>
		<link>http://philosecurity.org/2009/03/09/rogue-wireless-gets-sneakier</link>
		<comments>http://philosecurity.org/2009/03/09/rogue-wireless-gets-sneakier#comments</comments>
		<pubDate>Mon, 09 Mar 2009 07:41:26 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://philosecurity.org/?p=1113</guid>
		<description><![CDATA[For $40, anyone can purchase a cheap wireless AP and plug it into the company network. Often, employees do this simply for the sake of convenience, not realizing that it opens the company to attack. Criminals also deliberately plant wireless access points, which allow them to bypass the pesky firewall and remotely access the network [...]]]></description>
			<content:encoded><![CDATA[<p><!-- 2009-03-09 --><a href='http://philosecurity.org/wp-content/uploads/2009/03/rogue_vol_3.jpg'><img src="http://philosecurity.org/wp-content/uploads/2009/03/rogue_vol_3-213x300.jpg" alt="Rogue: X-Men" title="Rogue: X-Men" width="213" height="300" class="right size-medium wp-image-1115" /></a>For $40, anyone can purchase a cheap wireless AP and plug it into the company network. Often, employees do this simply for the sake of convenience, not realizing that it opens the company to attack. Criminals also deliberately plant wireless access points, which allow them to bypass the pesky firewall and remotely access the network later on. These days, disgruntled employees can easily hide an AP behind the file cabinet before cleaning out their desks, and then access the company network months later from the parking lot.</p>
<p>Many companies conduct regular &#8220;war-walking&#8221; scans to detect rogue access points (ie. using Kismet or Netstumbler), or invest in commercial Wireless Intrusion Detection Systems (WIDS). However, there are sneaky ways to bypass traditional war-walking and WIDS systems. Recently, I took <a href="http://www.sans.org/training/description.php?tid=2397">Josh Wright&#8217;s excellent &#8220;Wireless Ethical Hacking&#8221; SANS class</a>, and he touched on a number of tricks that attackers can use to foil your company&#8217;s rogue WAP detection efforts. Here are a few:</p>
<h2>1) Channel 14</h2>
<p>In the United States, the FCC has licensed 11 channels for 802.11b/g, which have center frequencies between 2.412 GHz to 2.462 GHz. However, most of Europe allows 13 channels (up to 2.472 GHz), and Japan allows 802.11b <a href="http://en.wikipedia.org/wiki/List_of_WLAN_channels">all the way up to channel 14, or 2.484 GHz.</a> </p>
<p>Cards manufactured for the United States often don&#8217;t support channel 14, since it&#8217;s illegal to transmit on that frequency. There&#8217;s overlap between the channels, but at 2.484 GHz, channel 14 is far enough away from channel 11 that network cards are unlikely to pick up much signal on channel 11. If an attacker were to configure an AP to illegally transmit on Channel 14 and export data at 2.484 GHz, security teams monitoring US channels would probably never detect it.</p>
<h2>2) 802.11n Green Field mode</h2>
<p>The IEEE has been hard at work on the 802.11n (<a href="http://en.wikipedia.org/wiki/Multiple-input_multiple-output">&#8220;MIMO&#8221;</a>-based) specification, which allows much greater throughput than 802.11a/b/g (100Mbps or more). The draft 802.11n standard specifies two modes:</p>
<ul>
<li>&#8220;Mixed-mode,&#8221; which allows it  to work with legacy 802.11a/b/g networks;</li>
<li>&#8220;Green Field&#8221; or &#8220;high-throughput only&#8221; mode, which takes full  advantage of the enhanced throughput but is not visible to 802.11a/b/g devices. Older devices will see GF-mode traffic only as noise.</li>
</ul>
<p>Not visible to 802.11a/b/g devices? That means if you&#8217;re war-walking with an 802.11a/b/g card, you can&#8217;t see 802.11n devices operating in Green Field (GF) mode. The specification hasn&#8217;t even been finalized, but 802.11n devices are already available for as little as $50&#8211; easy to buy, easy to plug into your company&#8217;s network. However, most companies have not yet purchased 802.11n-compatible equipment and hence can&#8217;t detect GF-mode 802.11n rogue APs.</p>
<p>Josh published a <a href="http://www.wirelessve.org/entries/show/WVE-2008-0005">vulnerability report explaining this</a>, in which he wrote: &#8220;With the inability to decode GF mode traffic, an attacker can position a malicious rogue AP on a victim network using the GF mode preamble. This would allow an attacker to evade wireless intrusion detection systems (WIDS) based on non-HT devices. This includes all WIDS devices based on 802.11a/b/g wireless cards.&#8221;</p>
<h2>3) Bluetooth Access Point</h2>
<p>If you&#8217;re like me, when you think about Bluetooth you envision your tiny little headset which crackles and hisses every time you walk too far away from your phone. That&#8217;s because your Bluetooth headset is designed for a Class 2 Bluetooth network, which is fairly low-power and has a maximum range of ~10M.</p>
<p>However, there&#8217;s more to Bluetooth than your rinky-dink headset. Bluetooth Class 1 devices are much more powerful, with ranges similar to 802.11b wireless APs. A Bluetooth Class 1 device can transmit up to 100mW, with a typical range of ~100M (or miles, if the receiver has a directional antenna).You can buy a Class 1 Bluetooth AP for $100-200.</p>
<p>Can you discover Bluetooth APs while war-walking? Not if you&#8217;re just using an 802.11 card. Even if you&#8217;re using a spectrum analyzer like <a href="http://www.metageek.net/">WiSpy</a>, you may not notice it. Bluetooth uses <a href="http://philosecurity.org/2008/07/28/off-the-grid">Frequency Hopping Spread Spectrum</a>, and hops 1600 times a second throughout the 2.402-2.480GHz band. Because it&#8217;s spread out across the spectrum, it can be hard to notice and easily mistaken for noise by the untrained eye. Most Wireless IDS systems and security teams simply don&#8217;t look for it (yet).</p>
<h2>4) Wireless Knocking</h2>
<p>This is my favorite. Remember port knocking? Instead of installing a backdoor to listen on a particular port (where it might be noticed), l33t h4&#215;0rs installed rootkits that would wait for a particular sequence of ports to be scanned, at which point the knocker&#8217;s IP address would be granted access. &#8220;A three-knock simple TCP sequence (e.g. port 1000, 2000, 3000) would require an attacker without prior knowledge of the sequence to test every combination of three ports in the range 1-65535, and then to scan each port in between to see if anything had opened&#8230; That equates to approximately 65535<sup>4</sup> packets in order to obtain and detect a single successful opening. That&#8217;s approximately 18,445,618,199,572,250,625 or <a href="http://en.wikipedia.org/wiki/Port_knocking">18 quintillion packets</a>.&#8221; <em>(Wikipedia)</em></p>
<p>With wireless knocking, a rogue AP sits on the network in monitor mode, listening for probe requests. When the rogue AP receives a packet (or sequence of packets) with the preconfigured SSID, it awakens and switches to master mode. The program &#8220;WKnock&#8221; is designed for this purpose, and it can be installed on any AP supported by the OpenWRT framework. During times when the rogue AP isn&#8217;t active, it is silent and can&#8217;t be detected using common wireless scanning tools.</p>
<p>Sneaky!</p>
<p><em>If you want to learn more about wireless attacks and defense, I definitely recommend Josh Wright&#8217;s class &#8211; <a href="http://www.sans.org/training/description.php?tid=2397">SANS 617</a>.</em></p>
<table style="float: right">
<tr>
<td align=right><em>Sherri Davidoff</em></td>
</tr>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/pgp-archives/rogue-wireless-gets-sneakier-2009-03-09.asc">PGP-signed text: 2009-03-09 (current)</a></td>
</tr>
</table>



Did you like this article? Share it!


	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F03%2F09%2Frogue-wireless-gets-sneakier&amp;title=Rogue%20Wireless%20Gets%20Sneakier" title="Digg"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://del.icio.us/post?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F03%2F09%2Frogue-wireless-gets-sneakier&amp;title=Rogue%20Wireless%20Gets%20Sneakier" title="del.icio.us"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F03%2F09%2Frogue-wireless-gets-sneakier&amp;title=Rogue%20Wireless%20Gets%20Sneakier" title="StumbleUpon"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F03%2F09%2Frogue-wireless-gets-sneakier&amp;title=Rogue%20Wireless%20Gets%20Sneakier" title="Reddit"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://slashdot.org/bookmark.pl?title=Rogue%20Wireless%20Gets%20Sneakier&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F03%2F09%2Frogue-wireless-gets-sneakier" title="Slashdot"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://philosecurity.org/2009/03/09/rogue-wireless-gets-sneakier/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>National Drug Intelligence Center Keeps Hash(es)</title>
		<link>http://philosecurity.org/2009/03/02/national-drug-intelligence-center-keeps-hashes</link>
		<comments>http://philosecurity.org/2009/03/02/national-drug-intelligence-center-keeps-hashes#comments</comments>
		<pubDate>Mon, 02 Mar 2009 05:20:27 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://philosecurity.org/?p=1087</guid>
		<description><![CDATA[The National Drug Intelligence Center has developed software called (ahem) &#8220;HashKeeper&#8221; &#8220;as its principal tool to expedite the analysis of electronic media.&#8221;
Hahahaha&#8230;.. 
Apparently, &#8220;HashKeeper is available free of charge.&#8221; Contact the National Drug Intelligence Center for more information.
National Drug Intelligence Center
c/o Mr. Steve Gironda
Telephone: 814-532-4987
E-mail:  ndic.domex.request@usdoj.gov

Hat tip to John Masterson.


Sherri Davidoff


PGP-signed text: 2009-03-01 (current)





Did [...]]]></description>
			<content:encoded><![CDATA[<p><!-- 2009-03-01 --><img src="http://philosecurity.org/wp-content/uploads/2009/03/us-nationaldrugintelligencecenter-seal-smaller-300x300.jpg" alt="us-nationaldrugintelligencecenter-seal-smaller" title="us-nationaldrugintelligencecenter-seal-smaller" width="200" height="200" class="right size-medium wp-image-1094" />The National Drug Intelligence Center has developed software called (<em>ahem</em>) <a href="http://www.usdoj.gov/ndic/domex/hashkeeper.htm#Top">&#8220;HashKeeper&#8221;</a> &#8220;as its principal tool to expedite the analysis of electronic media.&#8221;</p>
<p>Hahahaha&#8230;.. </p>
<p>Apparently, &#8220;<a href="http://www.usdoj.gov/ndic/domex/hashkeeper.htm#Top">HashKeeper</a> is available free of charge.&#8221; Contact the National Drug Intelligence Center for more information.</p>
<p><a href="http://www.usdoj.gov/ndic">National Drug Intelligence Center</a><br />
c/o Mr. Steve Gironda<br />
Telephone: 814-532-4987<br />
E-mail:  ndic.domex.request@usdoj.gov<br />
<br />
<em>Hat tip to <a href="http://montananorml.org/">John Masterson</a>.</em></p>
<table style="float: right">
<tr>
<td align=right><em>Sherri Davidoff</em></td>
</tr>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/pgp-archives/national-drug-intellegence-keeps-hashes-2009-03-01.asc">PGP-signed text: 2009-03-01 (current)</a></td>
</tr>
</table>



Did you like this article? Share it!


	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F03%2F02%2Fnational-drug-intelligence-center-keeps-hashes&amp;title=National%20Drug%20Intelligence%20Center%20Keeps%20Hash%28es%29" title="Digg"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://del.icio.us/post?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F03%2F02%2Fnational-drug-intelligence-center-keeps-hashes&amp;title=National%20Drug%20Intelligence%20Center%20Keeps%20Hash%28es%29" title="del.icio.us"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F03%2F02%2Fnational-drug-intelligence-center-keeps-hashes&amp;title=National%20Drug%20Intelligence%20Center%20Keeps%20Hash%28es%29" title="StumbleUpon"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F03%2F02%2Fnational-drug-intelligence-center-keeps-hashes&amp;title=National%20Drug%20Intelligence%20Center%20Keeps%20Hash%28es%29" title="Reddit"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://slashdot.org/bookmark.pl?title=National%20Drug%20Intelligence%20Center%20Keeps%20Hash%28es%29&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F03%2F02%2Fnational-drug-intelligence-center-keeps-hashes" title="Slashdot"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://philosecurity.org/2009/03/02/national-drug-intelligence-center-keeps-hashes/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>DTV Coupons: Personal Tracking</title>
		<link>http://philosecurity.org/2009/02/23/dtv-coupons-personal-tracking</link>
		<comments>http://philosecurity.org/2009/02/23/dtv-coupons-personal-tracking#comments</comments>
		<pubDate>Mon, 23 Feb 2009 11:43:10 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Economics]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[Memory]]></category>
		<category><![CDATA[Politics]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Transit]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://philosecurity.org/?p=983</guid>
		<description><![CDATA[Last week marked the original official deadline for the Digital Television Transition, after which analog television broadcasts would be terminated. (The official deadline was recently extended to June 12, 2009.) To ease the transition, the US government launched the TV Converter Box Coupon Program, which &#8220;allows U.S. households to obtain up to two coupons, each [...]]]></description>
			<content:encoded><![CDATA[<p><!-- 2009-02-23 -->Last week marked the original official deadline for the Digital Television Transition, after which analog television broadcasts would be terminated. (The official deadline was recently extended to June 12, 2009.) To ease the transition, the US government launched the TV Converter Box Coupon Program, which &#8220;allows U.S. households to obtain up to <a href="https://www.dtv2009.gov/FAQ.aspx">two coupons</a>, each worth $40, that can be applied toward the cost of eligible converter boxes.&#8221; <em>(TV converter coupon program site)</em></p>
<p><a href="http://philosecurity.org/wp-content/uploads/2009/02/coupon-front-private-small.jpg"><img src="http://philosecurity.org/wp-content/uploads/2009/02/coupon-front-private-small-150x150.jpg" alt="coupon-front-private-small" title="coupon-front-private-small" width="150" height="150" class="right size-thumbnail wp-image-1047" /></a>The coupon is similar to a credit card, with a serial number and expiration date printed on the front (as well as a nifty hologram that reads &#8220;Security&#8221;).  It also has a magnetic stripe. Curious, I borrowed a coupon and swiped it through my <a href="http://www.amazon.com/MiniMag-Magnetic-Strip-Reader-3-Track/dp/B0015EP3E8">trusty mag-stripe reader</a>. The output was as follows (name/number have been changed for privacy):</p>
<p>%B5897320630985200^<strong>SMITH/FRANK </strong>            ^0903121000000000000000798000000?<br />
;5897320630985200=09031210000079800000?</p>
<p><a href="http://philosecurity.org/wp-content/uploads/2009/02/coupon-back-private-small.jpg"><img src="http://philosecurity.org/wp-content/uploads/2009/02/coupon-back-private-small-150x150.jpg" alt="coupon-back-private-small" title="coupon-back-private-small" width="150" height="150" class="right size-thumbnail wp-image-1055" /></a>Much to my surprise, the applicant&#8217;s name was encoded on the coupon, in addition to the serial number and expiration date. </p>
<p>Consumers are clearly not aware that their names are encoded on the cards. Although National Telecommunications and Information Administration (NTIA) documents refer to &#8220;<a href="http://www.ntia.doc.gov/otiahome/dtv/comments/dtvcoupon_comment0080.htm">identifying serial numbers</a>,&#8221; <em>(NTIA 2006)</em> there is no mention of the fact that names themselves are encoded on the cards. Since the name is not printed on the face of the card itself, there&#8217;s no way for recipients to tell it is there without special card-reader equipment. </p>
<p>As a result, over 24 million Americans have now unknowingly submitted their names into the tracking systems of nationwide corporate retailers such as Wal-Mart and Best Buy. &#8220;There are federal privacy laws that say what the government can do with your information, but once that information is given to private industry, it&#8217;s theirs,&#8221; commented senior security consultant <a href="http://jhamcorp.com">Jonathan Ham</a>. </p>
<p>What&#8217;s more, the NTIA itself tracks the location, date and time of each purchase. Retailers are required to &#8220;provide NTIA electronically with redemption information and payment receipts related to coupons used in the purchase of converter boxes, <a href="https://www.ntiadtv.gov/">specifically tracking each serialized coupon</a> by number with a corresponding [certified converter box] purchase.&#8221; <em>(NTIA retailer site.)</em> Each week, the <a href="https://www.ntiadtv.gov/coupon_stats.cfm">NTIA publishes statistics</a> indicating the number of cards used in each zip code.</p>
<p>Consumers are not explicitly informed of the coupon tracking on the TV Converter Coupon Program web site or application. Buried in the NTIA&#8217;s web site is the statement that &#8220;to keep track of the number of coupons issued, used and redeemed, as well as to minimize fraud and counterfeiting, NTIA intends to place <a href="http://www.ntia.doc.gov/otiahome/dtv/comments/dtvcoupon_comment0080.htm">identifying serial numbers</a> on the coupons.&#8221; <em>(NTIA 2006)</em></p>
<p>I went to Best Buy to get a retailer&#8217;s perspective on the TV Converter Coupon Program. Like most retailers, Best Buy likes to track their customers. With cash or check, this is difficult, but with credit cards and similar systems (such as the DTV coupons), customers can be automatically added to their database.</p>
<p>Rob Hooper, the helpful manager on duty, explained, &#8220;[The DTV coupon] would probably have their name, a number, and they probably have to put in their phone number for us to ring out the remainder of the transaction. As soon as that number gets rung through a Best Buy retailer or a Wal-Mart retailer or anywhere else, [NTIA can] probably break it down underneath the ID of the retailer, and then also the ID of the individual who applied for that particular card number. Not only do they have demographics, they also have geographics&#8211; where each card is used.&#8221;</p>
<p><img src="http://philosecurity.org/wp-content/uploads/2009/02/mom-quote-transparent-small.png" alt="mom-quote-transparent-small" title="mom-quote-transparent-small" width="170" height="178" class="right size-full wp-image-1060" />In other words, the government receives detailed information about precisely where and when each card is used, and each card is explicitly linked to a name. What&#8217;s more, since the names are stored on the coupon&#8217;s magnetic stripe itself, the retailer also receives and can store personal information about the consumer. The consumer may never even be aware that his or her name has been given to the retailer.</p>
<p>My mother, who applied for the program by phone, was shocked to learn that her name was encoded on the card and her purchases were tracked. &#8220;The government should have made me aware of the information they would be collecting about me if I used the card,&#8221; she said. &#8220;They&#8217;re taking away my freedom. If they decide they need to collect information, they should do so with the people they are collecting the information from <em>volunteering</em> to give it, not being forced.&#8221;</p>
<p>Presumably the names encoded on the coupon&#8217;s magnetic stripe can be used to prevent fraud, but in practice this has not been occurring.  Even if the name on the coupon doesn&#8217;t match the consumer, retailers still accept the coupons.</p>
<p><a href="http://philosecurity.org/wp-content/uploads/2009/02/bestbuy.jpg"><img src="http://philosecurity.org/wp-content/uploads/2009/02/bestbuy-225x300.jpg" alt="bestbuy-stacks-of-converters" title="bestbuy-stacks-of-converters" width="225" height="300" class="left size-medium wp-image-1047" /></a>&#8220;We generally don&#8217;t check IDs against the card,&#8221; said Rob. &#8220;If someone&#8217;s out there stealing digital converter box cards and they&#8217;re just hoarding boxes of those cards, that&#8217;s not on the top priority list for Best Buy&#8217;s loss prevention.&#8221; </p>
<p>&#8220;We haven&#8217;t really seen too much fraud whatsoever with these coupon cards,&#8221; he added. &#8220;It would be a really interesting thing to try to steal $40 converter box cards, because you&#8217;re basically getting paid off in technology that will be antiquated.&#8221;<br />
&nbsp;<br />
Millions of Americans using the DTV converter coupons have unknowingly had their shopping habits tracked and names given to third parties such as Best Buy and Wal-Mart.  What is the value of our privacy? Is watered-down &#8220;fraud protection&#8221; really worth giving away millions of American&#8217;s names to retailers? Would my mother really want her shopping habits recorded in an obscure government database, even to save $40? </p>
<p>&#8220;I like to shop for a product without Big Brother watching over me,&#8221; said Mom.</p>
<p>&nbsp;</p>
<table style="float: right">
<tr>
<td align=right><em>Sherri Davidoff</em></td>
</tr>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/pgp-archives/dtv-coupons-personal-tracking-2009-02-23.asc">PGP-signed text: 2009-02-23 (current)</a></td>
</tr>
</table>



Did you like this article? Share it!


	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F02%2F23%2Fdtv-coupons-personal-tracking&amp;title=DTV%20Coupons%3A%20Personal%20Tracking" title="Digg"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://del.icio.us/post?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F02%2F23%2Fdtv-coupons-personal-tracking&amp;title=DTV%20Coupons%3A%20Personal%20Tracking" title="del.icio.us"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F02%2F23%2Fdtv-coupons-personal-tracking&amp;title=DTV%20Coupons%3A%20Personal%20Tracking" title="StumbleUpon"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F02%2F23%2Fdtv-coupons-personal-tracking&amp;title=DTV%20Coupons%3A%20Personal%20Tracking" title="Reddit"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://slashdot.org/bookmark.pl?title=DTV%20Coupons%3A%20Personal%20Tracking&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F02%2F23%2Fdtv-coupons-personal-tracking" title="Slashdot"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://philosecurity.org/2009/02/23/dtv-coupons-personal-tracking/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>White-Collar Looting</title>
		<link>http://philosecurity.org/2009/02/17/white-collar-looting</link>
		<comments>http://philosecurity.org/2009/02/17/white-collar-looting#comments</comments>
		<pubDate>Tue, 17 Feb 2009 05:54:28 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Economics]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://philosecurity.org/?p=920</guid>
		<description><![CDATA[One midsummer night in 1977, the power went out in New York City. &#8220;Thousands of people took to the streets and smashed store windows looking for TVs, furniture, or clothing&#8230; The police made 3,776 arrests, although&#8230;many thousands escaped before being caught. 1,037 fires burned throughout the City&#8230;&#8221; (Blackout History Project)
The troublemakers weren&#8217;t faceless terrorists but [...]]]></description>
			<content:encoded><![CDATA[<p><!--2009-02-16 -->One midsummer night in 1977, the power went out in New York City. &#8220;Thousands of people <a href="http://www.blackout.gmu.edu/events/tl1977.html">took to the streets and smashed store windows</a> looking for TVs, furniture, or clothing&#8230; The police made 3,776 arrests, although&#8230;many thousands escaped before being caught. 1,037 fires burned throughout the City&#8230;&#8221; (<em>Blackout History Project</em>)</p>
<p><a href="http://philosecurity.org/wp-content/uploads/2009/02/time_new_york_blackout1.png"><img src="http://philosecurity.org/wp-content/uploads/2009/02/time_new_york_blackout1.png" alt="Cover of July 25, 1977 Time Magazine showing the New York City blackout of 1977 (Wikipedia)" title="Cover of July 25, 1977 Time Magazine showing the New York City blackout of 1977 (Wikipedia)" width="190" height="250" class="right size-full wp-image-961" /></a>The troublemakers weren&#8217;t faceless terrorists but local youth and ultimately, mainstream moms and dads. The most notable shift in the demographic of the looters occurred between the hours of 11:00 P.M. and midnight when stable, normally law-abiding citizens began to participate in the scavenging and mayhem.</p>
<p>The massive extent of the looting, especially compared with the few disruptions that occurred during the 1965 blackout, was partly <a href="http://www.time.com/time/magazine/article/0,9171,919090,00.html">due to the economic downturn</a>. By 1977 the unemployment amongst young blacks in New York City had reached 40%, compared to roughly 20% in 1965.    Many people were out of work and the standard of living had decreased; however, television and media constantly reminded people of the material goods which they could not possess. (<em>Time, 1977</em>)</p>
<p>It&#8217;s no wonder that in the current economic downturn, companies are <a href="http://www.itbusinessedge.com/cm/community/features/articles/blog/turbulent-economy-adds-to-risk-of-insider-threat/?cs=23208">starting</a> to <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&#038;articleId=9117138">worry</a> more about the &#8220;insider threat&#8221; and white-collar looting. &#8220;Information security experts are bracing for the law of unintended consequences to swing into action in 2009 as <a href="http://whitepapers.zdnet.com/abstract.aspx?docid=908841">layoffs, downsizing and low morale bring the worst out of trusted insiders</a> looking to profit off of proprietary intellectual property, customer contact lists, trade secrets and any other sensitive information. &#8230;[L]ast December the majority of participants in a survey reported that if they were fired tomorrow they would definitely take company data with them to their next employer.&#8221; (<em>Lumension, 2009</em>)</p>
<p>Today, as downsizing becomes rampant, there are increasing numbers of disgruntled former employees, who sometimes have deep knowledge of an organization&#8217;s IT infrastructure.  There are also more disgruntled current employees, as downsizing places greater burden and stresses on staff that remain. As scholar Ho Yanxi quoted, &#8220;The one who treats me well is my leader, the one who treats me <a href="http://www.amazon.com/Art-War-Sun-Tzu/dp/0877734526">cruelly is my enemy</a>.&#8217;&#8221; (<em>Cleary, Art of War</em>).</p>
<p>Exacerbating the situation, fewer staff means less people to monitor and maintain already out-of-control networks. This increases the risk of security vulnerabilities and lowers the risk that a theft will be noticed, proportionally increasing the likelihood of exploitation. Cutting already overworked IT staff leads to a downward spiral of network disrepair, security incidents and stressed IT workers.</p>
<p>The risk-vs-reward calculations are illustrated in this interview with one of the first blackout looters:</p>
<p><em>Interviewer: “What kind of money would you need to stop you from [looting]?”<br />
J: Oh, it wouldn’t just have to be money. It would have to be my position in life. Like if I was to go to law school, and have a nice paying job, and be established in a firm or something&#8230; I wouldn’t take the risk of getting busted and havin to go to jail and blowin’ my schooling. It’s not worth the risk.</em> (<a href="http://www.amazon.com/Blackout-Looting-Robert-Curvin/dp/0470266694/ref=sr_1_1?ie=UTF8&#038;s=books&#038;qid=1234827675&#038;sr=8-1"><em>Blackout Looting!</a>, p.176</em>)</p>
<p>As white-collar workers feel increasingly disenfranchised, the risk of insider data theft proportionally rises.</p>
<h2>Who are &#8220;we,&#8221; anyway?</h2>
<p>The &#8220;insider threat&#8221; is even more serious when a large percentage of workers are contractors, who have even less incentive to ensure long-term organizational stability.  The war in Iraq nicely illustrates this phenomenon. Last week the GAO released a very interesting <a href="http://www.gao.gov/new.items/d09380t.pdf">report on US operations management in Iraq and Afghanistan</a>, in which they stated, &#8220;As of July 2008, there were approximately 162,400 DOD contractors and, as of December 1, 2008, approximately 148,500 U.S. troops in Iraq.&#8221; This enormous ratio of contractors to military staff proved overwhelming. &#8220;Lack of adequate numbers of contract oversight personnel,&#8221; was cited as a serious issue. &#8220;[T]oo few contract oversight personnel  limited DOD’s ability to identify savings, monitor contractor  performance, or resolve contractor performance issues.&#8221; (<em>GAO, 2/2009</em>)</p>
<p>Lacking oversight, training and incentives, contractors took enormous advantage of their situation. &#8220;KBR employees who were contracted to perform construction duties inside palaces and municipal buildings were looting,&#8221; said Linda Warren, a contracted laundry foreman, during Senate hearings. &#8220;Not only were they looting, but they had a system in place to get contraband out of the country so it could be sold on eBay. They <a href="http://democrats.senate.gov/dpc/hearings/hearing42/warren.pdf">stole artwork, rugs, crystal, and even melted down gold</a> to make spurs for cowboy boots.&#8221; (The transcript of her testimony is definitely worth reading.)</p>
<p><a href="http://www.nytimes.com/2009/02/15/world/middleeast/15iraq.html">Even contracting <em>officers</em> took advantage.</a> Yesterday the New York Times released a front-page exposee, in which they reported, &#8220;Maj. John L. Cockerham of the Army pleaded guilty to accepting nearly $10 million in bribes as a contracting officer for the Iraq war and other military efforts from 2004 to 2007, when he was arrested. Major Cockerham’s wife has also pleaded guilty, as have several other contracting officers&#8230;. Former American officials describe payments to local contractors from huge sums of cash dumped onto tables and stuffed into sacks as if it were Halloween candy. “You had no oversight, chaos and breathtaking sums of money,” said Senator Claire McCaskill.&#8221;(<em>NYTimes, 2/15/2009</em>)</p>
<p>Iraq is an extreme, but informative, example. Given these recent graphic illustrations of the results of contractor mismanagement, it&#8217;s worth examining the current situation in the IT sector, where contractor jobs are rising even as general employment falls.</p>
<p><a href="http://news.cnet.com/8301-1001_3-10162879-92.html">&#8220;Contract work fuels rise in tech job postings&#8221;</a> reported CNET news last week. &#8220;Tech job listings rose to 57,337 as of February 2&#8230;But if you&#8217;re looking for full-time work with health benefits, you may not find the new data to be especially good news: Helping to drive that modest increase was a 7.3 percent gain in the number of contractor positions&#8230; &#8216;In uncertain times, companies are looking for flexibility in their payrolls to continue with critical projects,&#8221; said Tom Silver.. [of] Dice.com. Those critical projects often involve improvements to a company&#8217;s infrastructure&#8230; &#8216;For the last year or so, contractor jobs have accounted for 38 to 40 percent of the positions, but I expect that increase,&#8217; Silver said. He noted he wouldn&#8217;t be surprised if the percentage for contractor job postings eventually reached to 50 percent later this year.&#8221; (<em>Kawamoto, 2/2009</em>)</p>
<p>In other words, the people being hired to work on &#8220;critical&#8221; infrastructure projects are increasingly those that do not receive health benefits and have little invested in the long-term survival of the company. Furthermore, as the ratio of full-time to contractor staff shrinks, there are fewer full-time employees to provide oversight.</p>
<h2>Solutions: Maintaining Security in a Weakening Economy</h2>
<p>The blackout of 1977 and the Iraq war illustrated two important factors which ultimately led to widespread security failures and looting:</p>
<ol>
<li>Reduced incentives for large numbers of individuals to support the current system;</li>
<li>Limited oversight and low perceived risk of personal repercussions.</li>
</ol>
<p>These two factors are increasingly present in the IT sector today, where a growing percentage of disgruntled employees and contractors have access to critical IT infrastructure, and where companies do not have the staffing or technical resources to monitor access and lock systems down.</p>
<p>How can we correct these fundamental problems that lead to the &#8220;insider threat?</p>
<ol>
<li> Help workers to feel invested in the current system;</li>
<li>Increase the perception of oversight and perceived likelihood of repercussions.</li>
</ol>
<p>Any time there is a fundamental disconnect between the incentives of the people versus the organization, there is naturally internal conflict and greater risk of people undermining the status quo. When workers do not feel invested in the system, security incidents abound. Conversely, organizations can reduce the risk of insider attack by giving people a stake in the company&#8217;s success. A favorite of the security industry, ancient military strategist Sun Tsu wrote about the importance of &#8220;inducing the people to have the same aim as the leadership.&#8221;</p>
<p><a href="http://philosecurity.org/wp-content/uploads/2009/02/wwiip60.jpg"><img class="right size-medium" title="" src="http://philosecurity.org/wp-content/uploads/2009/02/wwiip601-289x300.jpg" alt="World War II poster" width="200" height="207" /></a>Even on a tight budget, organizations can still foster worker loyalty. As demonstrated during World War II, it is possible to maintain&#8211; and even grow&#8211; a dedicated workforce during tough times. The WWII propaganda effort was implemented as a massive postering campaign on an unprecedented scale. During a period where civilians re-used scraps of paper because supplies were so limited, the US Office of War Information sought to &#8220;[ poster ] America every night,&#8221; and <a href="http://www.amazon.com/Design-Victory-World-Poster-American/dp/1568981406">treated posters &#8220;as real war ammunition.&#8221;</a> <em>(Design for Victory, p. 11-12)</em> The investment paid for itself hundredfold.</p>
<p>Without resources for appropriate staffing and equipment, a high-return security investment for many companies might be a simple PR campaign, designed to motivate employee loyalty. Similarly, even organizations that lack the resources to install and maintain proper monitoring capabilities can still at least create the <em>perception</em> of oversight, which can dramatically reduce incidents.  Physical security professionals have long utilized this tactic, for example by installing $30 dummy cameras and warning signs which advertise that the premises is actively monitored.</p>
<p>I often say that &#8220;humans are unreliable components,&#8221; but that&#8217;s not really true. Humans are unreliable when placed in unstable situations and given conflicting incentives. Much like transistors in a circuit, humans within organizations tend to act predictably based on perceived incentives and risk.</p>
<p>In today&#8217;s downward economy, companies are dramatically reducing incentives for workers and expanding the ratio of IT contractors to employees, even while IT oversight and monitoring capabilities are already very limited.  As with New York&#8217;s 1977 blackout and the Iraqi occupation, workers find themselves with conflicted incentives, and some will invariably decide to serve their own well-being rather than the larger organization. How can organizations lower the risk of &#8220;white-collar looting&#8221;? Advertise incentives for workers to support the organization, and instill at least the perception (and better, the actuality) of oversight and monitoring.</p>
<table style="float: right">
<tr>
<td align=right><em>Sherri Davidoff</em></td>
</tr>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/pgp-archives/white-collar-looting-2009-02-16.asc">PGP-signed text: 2009-02-16 (current)</a></td>
</tr>
</table>



Did you like this article? Share it!


	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F02%2F17%2Fwhite-collar-looting&amp;title=White-Collar%20Looting" title="Digg"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://del.icio.us/post?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F02%2F17%2Fwhite-collar-looting&amp;title=White-Collar%20Looting" title="del.icio.us"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F02%2F17%2Fwhite-collar-looting&amp;title=White-Collar%20Looting" title="StumbleUpon"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F02%2F17%2Fwhite-collar-looting&amp;title=White-Collar%20Looting" title="Reddit"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://slashdot.org/bookmark.pl?title=White-Collar%20Looting&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F02%2F17%2Fwhite-collar-looting" title="Slashdot"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://philosecurity.org/2009/02/17/white-collar-looting/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Airport Internet Kiosk Phishing</title>
		<link>http://philosecurity.org/2009/02/09/airport-internet-kiosk-phishing</link>
		<comments>http://philosecurity.org/2009/02/09/airport-internet-kiosk-phishing#comments</comments>
		<pubDate>Mon, 09 Feb 2009 06:03:40 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://philosecurity.org/?p=814</guid>
		<description><![CDATA[Walking through the Minneapolis airport, a friend and I came across something&#8230; not right.








Apparently, the &#8220;New and Improved&#8221; Internet Access GateStation kiosk had rebooted, and hung with the BIOS displayed.

We laughed and walked closer to get a good look.







Interesting. It was configured to boot off a USB floppy drive. There couldn&#8217;t be a USB port [...]]]></description>
			<content:encoded><![CDATA[<p><!-- 2009-02-08 -->Walking through the Minneapolis airport, a friend and I came across something&#8230; not right.</p>
<table>
<tr>
<td>
<a href="http://philosecurity.org/wp-content/uploads/2009/02/broken-kiosk-internet-access.jpg"><img class="left size-medium" title="" src="http://philosecurity.org/wp-content/uploads/2009/02/broken-kiosk-internet-access-300x61.jpg" alt="" width="235" height="48" /></a><br />
<a href="http://philosecurity.org/wp-content/uploads/2009/02/broken-kiosk-enhanced.jpg"><img class="left size-medium" title="" src="http://philosecurity.org/wp-content/uploads/2009/02/broken-kiosk-enhanced-299x60.jpg" alt="" width="235" height="47" /></a><br />
<a href="http://philosecurity.org/wp-content/uploads/2009/02/broken-kiosk1.jpg"><img class="left size-medium" title="" src="http://philosecurity.org/wp-content/uploads/2009/02/broken-kiosk1-235x300.jpg" alt="" width="235" height="300" /></a>
</td>
<td>
Apparently, the &#8220;New and Improved&#8221; Internet Access GateStation kiosk had rebooted, and hung with the BIOS displayed.<br />
<br />
We laughed and walked closer to get a good look.
</td>
</tr>
<tr>
<td>
<a href="http://philosecurity.org/wp-content/uploads/2009/02/broken-kiosk-screen3.jpg"><img class="left size-medium" title="" src="http://philosecurity.org/wp-content/uploads/2009/02/broken-kiosk-screen3-300x190.jpg" alt="" width="300" height="190" /></a>
</td>
<td>
Interesting. It was configured to boot off a USB floppy drive. There couldn&#8217;t be a USB port accessible&#8230; could there?
</td>
</tr>
<tr>
<td>
<a href="http://philosecurity.org/wp-content/uploads/2009/02/broken-usb-port4.jpg"><img class="left size-medium" title="" src="http://philosecurity.org/wp-content/uploads/2009/02/broken-usb-port4-300x179.jpg" alt="" width="300" height="179" /></a>
</td>
<td>
Turned out there was a USB port&#8230;
</td>
</tr>
<tr>
<td>
<a href="http://philosecurity.org/wp-content/uploads/2009/02/broken-kiosk-keyboard.jpg"><img class="left size-medium" title="" src="http://philosecurity.org/wp-content/uploads/2009/02/broken-kiosk-keyboard-300x100.jpg" alt="" width="300" height="100" /></a>
</td>
<td>
&#8230;Right next to the keyboard. Hmmm.
</td>
</tr>
<tr>
<td>
<a href="http://philosecurity.org/wp-content/uploads/2009/02/broken-kiosk-j3.jpg"><img class="left size-medium" title="" src="http://philosecurity.org/wp-content/uploads/2009/02/broken-kiosk-j3-173x300.jpg" alt="" width="173" height="300" /></a>
</td>
<td>
That keyboard couldn&#8217;t possibly control the BIOS screen, though.
</td>
</tr>
<tr>
<td>
<a href="http://philosecurity.org/wp-content/uploads/2009/02/broken-kiosk-screen-switched2.jpg"><img class="left size-medium" title="" src="http://philosecurity.org/wp-content/uploads/2009/02/broken-kiosk-screen-switched2-300x188.jpg" alt="" width="300" height="188" /></a>
</td>
<td>
Oh, wait. It did. We had inadvertently switched the boot device from &#8220;USB FDD&#8221; to &#8220;USB ZIP/Flash.&#8221;<br />
<br />
We could probably boot the kiosk off our own USB thumb drive if we wanted.
</td>
</tr>
<tr>
<td>
<a href="http://philosecurity.org/wp-content/uploads/2009/02/broken-kiosk-screenshot2.jpg"><img class="left size-medium" title="" src="http://philosecurity.org/wp-content/uploads/2009/02/broken-kiosk-screenshot2-300x194.jpg" alt="" width="300" height="194" /></a>
</td>
<td>
The kiosk had two terminals. One screen was dead and the keyboard was connected to the BIOS display. The other screen appeared to be fully functional. The functional terminal advertised &#8220;Go to Web&#8221; &#8220;Get Email&#8221; and &#8220;Flight Info.&#8221;
</td>
</tr>
<tr>
<td>
<a href="http://philosecurity.org/wp-content/uploads/2009/02/broken-kiosk-payment-screen-partial.jpg"><img class="left size-medium" title="" src="http://philosecurity.org/wp-content/uploads/2009/02/broken-kiosk-payment-screen-partial-300x207.jpg" alt="" width="300" height="207" /></a>
</td>
<td>
Clicking on the &#8220;Get Email&#8221; link brought up a payment screen.
</td>
</tr>
<tr>
<td>
<a href="http://philosecurity.org/wp-content/uploads/2009/02/broken-kiosk-credit-card2.jpg"><img class="left size-medium" title="" src="http://philosecurity.org/wp-content/uploads/2009/02/broken-kiosk-credit-card2-300x278.jpg" alt="" width="300" height="278" /></a>
</td>
<td>
The kiosk accepted cash and credit cards.</td>
</tr>
<tr>
<td>
<a href="http://philosecurity.org/wp-content/uploads/2009/02/broken-kiosk-use-anyway.jpg"><img class="left size-medium" title="" src="http://philosecurity.org/wp-content/uploads/2009/02/broken-kiosk-use-anyway-300x291.jpg" alt="" width="300" height="291" /></a>
</td>
<td>
Even though there was clearly a very strange technical problem, people lined up to use the working terminal of the kiosk. Here is a photograph of one person who swiped his credit card and used the kiosk while we stood there, loudly discussing the potential security implications.
</td>
</tr>
</table>
<p></p>
<h2>Airport kiosk phishing, anyone?</h2>
<p>Let&#8217;s review:</p>
<ol>
<li>The kiosk had a live keyboard connected to the BIOS setup</li>
<li>A USB port was easily accessible and listed as a boot option</li>
<li>The kiosk routinely processed highly valuable (and regulated) personal information, such as credit card numbers and email passwords</li>
<li>Despite the fact that the kiosk had a super sketchy software error displayed on a screen 4&#8242; high, people lined up to swipe their credit cards and type in their email passwords anyway.	</li>
<li>The BIOS was displayed and accessible the entire time we were at the airport (a few hours). Airport security staff sat in little carts right next to the kiosk, and didn&#8217;t seem interested in reporting the error to anyone. For all we knew, it could have been like that for days. </li>
</ol>
<p>When a kiosk is bootable from an easily accessible USB port, this opens it up to a variety of attacks. If we were Evil, we could have created a bootable USB thumb drive with our own &#8220;New and Improved&#8221; Internet Access software (ie. a simple customized Linux distribution) and booted the kiosk off of that. The software could record credit card numbers and password, which would always run before any of the normal software, and store them on the thumb drive which we could later snatch. Given that people didn&#8217;t seem at all phased by glaring software glitches, our Evil software probably wouldn&#8217;t even have to be very good to successfully snag valuable financial and account information.</p>
<p>Even worse, if the internal hard drive was writable, we could have modified GateStation&#8217;s operating system and inserted our malicious code into the legitimate software. If we were really sneaky and willing to put in the effort, we might have been able to flash the Award BIOS and insert our own low-level malware, which would be extremely difficult to detect. This would be a sophisticated attack, but given the high payoff, criminals might consider it worthwhile.<br />
<br />
The value of information entered into airport kiosks is very high, but often the level of security is not commensurate. </p>
<table style="float: right">
<tr>
<td align=right><em>Sherri Davidoff</em></td>
</tr>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/pgp-archives/airport-internet-kiosk-phishing-2009-02-08.asc">PGP-signed text: 2009-02-08 (current)</a></td>
</tr>
</table>



Did you like this article? Share it!


	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F02%2F09%2Fairport-internet-kiosk-phishing&amp;title=Airport%20Internet%20Kiosk%20Phishing" title="Digg"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://del.icio.us/post?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F02%2F09%2Fairport-internet-kiosk-phishing&amp;title=Airport%20Internet%20Kiosk%20Phishing" title="del.icio.us"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F02%2F09%2Fairport-internet-kiosk-phishing&amp;title=Airport%20Internet%20Kiosk%20Phishing" title="StumbleUpon"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F02%2F09%2Fairport-internet-kiosk-phishing&amp;title=Airport%20Internet%20Kiosk%20Phishing" title="Reddit"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://slashdot.org/bookmark.pl?title=Airport%20Internet%20Kiosk%20Phishing&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F02%2F09%2Fairport-internet-kiosk-phishing" title="Slashdot"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://philosecurity.org/2009/02/09/airport-internet-kiosk-phishing/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Identity Protection Racket</title>
		<link>http://philosecurity.org/2009/02/02/identity-protection-racket</link>
		<comments>http://philosecurity.org/2009/02/02/identity-protection-racket#comments</comments>
		<pubDate>Mon, 02 Feb 2009 12:21:56 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Credit Cards]]></category>
		<category><![CDATA[Economics]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://philosecurity.org/?p=703</guid>
		<description><![CDATA[Credit bureaus and credit card companies have direct control over the risk of identity theft. They control the systems for granting and rescinding credit, including fundamental mediums for communication and related security features. Oddly, that doesn&#8217;t stop them from trying to profit when things go wrong. Credit companies strongly push their identity theft &#8220;protection&#8221; services, [...]]]></description>
			<content:encoded><![CDATA[<p><!-- 2009-02-02 -->Credit bureaus and credit card companies have direct control over the risk of identity theft. They control the systems for granting and rescinding credit, including fundamental mediums for communication and related security features. Oddly, that doesn&#8217;t stop them from trying to profit when things go wrong. Credit companies strongly push their identity theft &#8220;protection&#8221; services, especially now that identity theft is on the rise. For example, Equifax offers &#8220;ID Patrol&#8221; and Discover offers &#8220;Identity Theft Protection.&#8221; These services appear to be effectively glorified credit monitoring services offered at $10-20 a month.</p>
<p><a href="http://philosecurity.org/wp-content/uploads/2009/02/twogangstas.jpg"><img class="left size-medium" title="The Perils of Superman - Gangsters running a protection racket" src="http://philosecurity.org/wp-content/uploads/2009/02/twogangstas-261x300.jpg" alt="The Perils of Superman - Gangsters running a protection racket" width="174" height="200" /></a>Sounds like a protection racket to me. &#8220;<a href="http://en.wikipedia.org/wiki/Protection_racket">A protection racket is an extortion scheme</a> whereby a powerful entity or individual coerces other less powerful entities or individuals to pay protection money which allegedly serves to purchase protection services against various external threats. Those who do not buy into the protection plan are often targeted by criminals&#8230;&#8221; <em>(Wikipedia)</em><br />
<br />
Equifax&#8217;s scare tactics include: &#8220;<a href="http://www.equifax.com/newsletter_archive/jul2008/"><em>Don&#8217;t become a statistic.</a> Every year, millions of people fall victim to identity theft.</em>&#8221;  Experian writes, &#8220;<a href="http://www.experian.com/whitepapers/precise_id_whitepaper.pdf"><em>Specialized criminal gangs</a> increasingly work outside of the United States to gain access to account information. They then perpetrate crimes online&#8230;</em>&#8221; Discover advertises &#8220;<a href="http://www.discovercard.com/protection-solutions/identity-theft.html"><em>Identity theft occurs every 79 seconds</a> and affected 8.4 million people last year.</em>&#8221;</p>
<p>Funny&#8211; at the same time, the Big Three lobbyists have been trying to convince Washington that &#8220;<a href="http://www.usatoday.com/money/perfi/credit/2007-06-25-credit-freeze-usat_N.htm">identity theft isn&#8217;t as big a threat as people think.</a>&#8221; Represented by the Consumer Data Industry Association (CDIA), these very same companies lobbied intensely against laws &#8220;empowering consumers to freeze access to their credit histories to prevent identity theft.&#8221;  <em>(USA Today, 2007)</em> Credit companies also routinely sell consumers&#8217; financial and contact information, subjecting people to solicitations including bait-and-switch loan swindles or identity theft scams. </p>
<p>Credit bureaus have fought against widespread use of fraud alerts and similar techniques which require that they proactively verify consumer identities before, say, new accounts are opened in consumers&#8217; names. Last year Experian sued identity theft protection firm, LifeLock, for activating fraud alerts on behalf of hundreds of thousands of clients. Experian &#8220;claimed that alerts should be entered only when people have already been victimized by identity theft or have legitimate reasons to believe that they are at <a href="http://www.networkworld.com/news/2008/022108-credit-reporting-firm-sues-lifelock.html?page=1">imminent risk.</a>&#8221; <em>(Network World, 2008.)</em>  I&#8217;ve heard that &#8220;<em>identity theft occurs every 79 seconds</em>.&#8221; Does that count?</p>
<p>Having put himself through MIT on a credit card, <a href="http://www.infinitydayweekend.com/">Blake Brasher, author of &#8220;Infinity Day Weekend,&#8221;</a> knows more than anyone I&#8217;ve ever met about how to wrangle with the credit industry. The <a href="http://www.infinitydayweekend.com/about/">roboticist-turned-painter</a> writes, &#8220;I had an obnoxious encounter with Discover card a month ago.  I called to negotiate a special APR and they tried to get me to sign up for their identity theft protection service. The guy wouldn&#8217;t take no for an answer, and very nearly tricked me into signing up.</p>
<p>&#8220;I finally said, &#8216;Actually, I want to close this account. You&#8217;ve convinced me that using this card is not safe and to protect myself from identity theft I want to close the account.&#8217; So he transferred me to someone in the accounts department. </p>
<p>&#8220;The woman who answered&#8230; explained to me that actually, my Discover card account has built in, free fraud protection, and that if someone tried to commit a fraud with my account I would not be liable at all. They scare you into thinking you need this extra service, but if they scare you too much and you threaten to close your account to keep it safe they go ahead and let you know that you don&#8217;t actually need it.&#8221;</p>
<p>There are obvious steps that credit companies could take which really would reduce the risk of identity theft&#8211; such as taking further measures to verify identity, reducing sales of personal data, using PINs, etc. However, credit companies won&#8217;t support measures which reduce their own profits.  &#8220;Identity theft could be made as obsolete a crime as cattle rustling or high-seas piracy,&#8221; reported MONEY Magazine several years ago. &#8220;&#8230;[It's] now possible to request a freeze on your credit report, stopping anyone from granting new credit without your approval. <a href="http://money.cnn.com/2005/06/07/pf/security_stoptheft_0507/index.htm">Why isn&#8217;t this brutally simple and effective solution more widespread?</a> Simply put, it disrupts the free flow of credit information on which consumer lenders and data sellers depend.&#8221;</p>
<p>When credit companies play both sides of the game, there are reduced incentives for them to build secure systems. Rather, they have found a way to profit from crime. By fighting consumer protection measures and selling personal data, credit companies increase consumers&#8217; risk of identity theft. As long as credit companies can scare enough people into paying them for &#8220;protection,&#8221; they can actually make money from the results of their own recklessness&#8211; thus passing the costs of identity theft on to consumers or merchants, and reducing or even eliminating financial incentives for genuine, systematic improvements.</p>
<table style="float: right">
<tr>
<td align=right><em>Sherri Davidoff</em></td>
</tr>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/pgp-archives/identity-protection-racket-2009-02-02.asc">PGP-signed text: 2009-02-02 (current)</a></td>
</tr>
</table>



Did you like this article? Share it!


	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F02%2F02%2Fidentity-protection-racket&amp;title=Identity%20Protection%20Racket" title="Digg"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://del.icio.us/post?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F02%2F02%2Fidentity-protection-racket&amp;title=Identity%20Protection%20Racket" title="del.icio.us"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F02%2F02%2Fidentity-protection-racket&amp;title=Identity%20Protection%20Racket" title="StumbleUpon"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F02%2F02%2Fidentity-protection-racket&amp;title=Identity%20Protection%20Racket" title="Reddit"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://slashdot.org/bookmark.pl?title=Identity%20Protection%20Racket&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F02%2F02%2Fidentity-protection-racket" title="Slashdot"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://philosecurity.org/2009/02/02/identity-protection-racket/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>&#8220;Mind Your Business&#8221;</title>
		<link>http://philosecurity.org/2009/01/26/mind-your-business</link>
		<comments>http://philosecurity.org/2009/01/26/mind-your-business#comments</comments>
		<pubDate>Mon, 26 Jan 2009 08:07:53 +0000</pubDate>
		<dc:creator>sherri</dc:creator>
				<category><![CDATA[Economics]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://philosecurity.org/?p=660</guid>
		<description><![CDATA[The motto on the very first official United States coin was &#8220;Mind Your Business.&#8221;  Designed by Benjamin Franklin in 1787, the front of the coin also bore a picture of the sundial with with word Fugio (Latin, &#8220;I fly&#8221;). Franklin was fond of aphorisms, and the design has been taken to mean, &#8220;Time Flies, Mind [...]]]></description>
			<content:encoded><![CDATA[<p><!-- 2009-01-26 -->The motto on the <a href="http://en.wikipedia.org/wiki/Fugio_Cent">very first official United States coin</a> was &#8220;Mind Your Business.&#8221;  Designed by Benjamin Franklin in 1787, the front of the coin also bore a picture of the sundial with with word <em>Fugio</em> (Latin, &#8220;I fly&#8221;). Franklin was fond of <a href="http://books.google.com/books?id=ZgfIMio7RwgC&amp;printsec=frontcover">aphorisms</a>, and the design has been taken to mean, &#8220;Time Flies, Mind your Business.&#8221;  Franklin&#8217;s message was at once sound economic advice and an assertion of privacy.</p>
<p><a href="http://philosecurity.org/wp-content/uploads/2009/01/fugio_cent.jpg"><img class="right size-medium" title="First official United States coin, known as the Fugio cent" src="http://philosecurity.org/wp-content/uploads/2009/01/fugio_cent-300x297.jpg" alt="First official United States coin, known as the Fugio cent" width="230" height="229" /></a>My, how time flies. A little over two hundred years later, it&#8217;s difficult to conduct business privately.  &#8220;American Express knows everywhere I go, how long I stay, where I eat, how much I pay,&#8221; said security consultant <a href="http://www.jhamcorp.com">Jonathan Ham</a>. &#8220;They could reconstruct my activity on a day-to-day basis.&#8221;</p>
<p>Our entire system for conducting financial transactions has changed&#8211; and the collection, trade and analysis of detailed personal information is now an enormous component of everyday payment processing.  During 2006, there were <a href="http://www.frbservices.org/files/communications/pdf/research/2007_payments_study.pdf">93.3 billion non-cash payments in the United States</a>, meaning third parties were involved in transactions 93.3 billion times.  Non-cash payments have increased an average of 4.6% each year since 2006. <em>(Federal Reserve, 2007)</em> There&#8217;s no direct way to measure the number of cash transactions, but estimates indicate that <a href="http://www.clevelandfed.org/research/Commentary/2007/100107.cfm">the usage of cash in the US is decreasing.</a></p>
<p>Due to the extreme importance of credit scores, Americans are strongly pressured to use credit cards and build up credit, at the cost of our privacy. Without a credit score, it&#8217;s very difficult to buy a house or car, and companies charge far more for insurance. Personal credit checks are now standard for renting apartments, buying houses and many other basic needs.  &#8220;They are using FICO scores to evaluate job applicants!&#8221;  wrote <a href="http://www.taxattorneycpa.com/media/index.html">my father</a> recently.</p>
<p>Personal transaction monitoring goes far beyond credit reports. Financial institutions routinely track and profile customers&#8217; daily habits. A few months ago, I drove cross-country and found myself using my credit card a lot for gas purchases. In the middle of South Dakota, the card suddenly stopped working. I called up the card company.</p>
<p>&#8220;Well, you need to notify us if you&#8217;re going to be traveling,&#8221; admonished the American Express representative.</p>
<p><em>Like hell</em>, I thought. Notify American Express every time I want to travel? Who do they think they are, my nanny?</p>
<p>Of course, American Express has an undeniable business interest in rabidly tracking card use. The system (which they have created) is ripe for abuse and fraud. As <a href="http://philosecurity.org/2009/01/12/interview-with-an-adware-author">Matt Knox said</a>, &#8220;When I use a credit card, the security model is the same as that of handing you my wallet and saying, &#8216;Take out whatever money you think you want, and then give it back.&#8217;&#8221;</p>
<p>To compensate for security weaknesses in their own system, financial institutions conduct extremely detailed, real-time monitoring of customer purchases and locations.</p>
<p>Financial institutions also profit from selling and trading personal payment histories. For example, credit card companies sell detailed personal purchasing records for the purposes of marketing. &#8220;Privacy restrictions&#8230; would require businesses to send <a href="http://www.privacyalliance.org/resources/turner.pdf">significantly more catalogs to obtain the same response rates</a>, and the resulting increase in cost would be passed along to consumer.&#8221; <em>(Turner, 2001)</em> Credit card companies routinely profit from selling personal consumer information to third parties, who use the data for targeted advertising.</p>
<p>If financial institutions were not able to reap financial gains from selling personal information, and if they were forced to compensate for systematic security weaknesses out of their own pockets, there would be economic incentives for them to create electronic payment systems that are genuinely more secure and require less monitoring.</p>
<p>Personal financial histories held by private companies are also routinely accessed by the government. Many people are concerned that this access has been abused. &#8220;Bipartisan groups in Congress are pressing to place new controls on <a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/04/14/AR2008041402664.html">the FBI&#8217;s ability to demand troves of sensitive personal information</a> from telephone providers and credit card companies, over the opposition of agency officials who say they deserve more time to clean up past abuses.&#8221;  <em>(Johnson, Washington Post, 2008)</em></p>
<p>What would Franklin have thought of our modern third-party payment and credit systems?</p>
<p>As it happens, the fledgling United States was completely ripped off by the manufacturer of the first official penny. At the time, the United States didn&#8217;t yet have a national Mint, so they outsourced currency production to James Jarvis of Connecticut, who had bribed the head of the Treasury board with $10,000 for the contract. Jarvis was supposed to produce 300 tons of pennies, but ultimately only produced four tons of slightly underweight coins. Furthermore, a congressional report stated that &#8220;Jarvis had received a large quantity of federal copper but had <a href="http://www.coins.nd.edu/ColCoin/ColCoinIntros/Fugio.intro.html">only paid for a small portion</a>.&#8221; <em>(Louis Jordan, University of Notre Dame)</em></p>
<p>Would tighter financial monitoring have ensured that the original contract was awarded based on merit rather than a bribe? Would a credit check have helped our fledgling nation avoid making a bad loan? Quite possibly.</p>
<p>Then again, payment is deeply tied with freedom to travel and other fundamental liberties. Anyone who has had their credit card frozen while traveling understands the power that global payment processing companies hold over individuals. Due to the extreme importance of a credit score, Americans today are strongly pressured into using credit cards, which result in the intimate details of our daily purchasing habits being sold and exploited. Fundamentally, we are being forced to choose between our privacy and essential needs such as a house.</p>
<p>Our founding fathers never experienced loss of personal privacy at the scale that we see today, and probably could not imagine a system in which even their daily grocery purchases were tracked and analyzed. If they had, they might have pointed out that privacy is fundamental to freedom, and freedom comes at a price. Sometimes the price of freedom is blood, sometimes it&#8217;s money, and sometimes it&#8217;s the convenience of &#8220;instant credit.&#8221;</p>
<table style="float: right">
<tr>
<td align=right><em>Sherri Davidoff</em></td>
</tr>
<tr>
<td><a href="http://philosecurity.org/wp-content/uploads/pgp-archives/mind-your-business-2009-01-26.asc">PGP-signed text: 2009-01-26 (current)</a></td>
</tr>
</table>



Did you like this article? Share it!


	<a rel="nofollow" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F01%2F26%2Fmind-your-business&amp;title=%22Mind%20Your%20Business%22" title="Digg"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://del.icio.us/post?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F01%2F26%2Fmind-your-business&amp;title=%22Mind%20Your%20Business%22" title="del.icio.us"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F01%2F26%2Fmind-your-business&amp;title=%22Mind%20Your%20Business%22" title="StumbleUpon"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://reddit.com/submit?url=http%3A%2F%2Fphilosecurity.org%2F2009%2F01%2F26%2Fmind-your-business&amp;title=%22Mind%20Your%20Business%22" title="Reddit"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a>
	<a rel="nofollow" href="http://slashdot.org/bookmark.pl?title=%22Mind%20Your%20Business%22&amp;url=http%3A%2F%2Fphilosecurity.org%2F2009%2F01%2F26%2Fmind-your-business" title="Slashdot"><img src="http://philosecurity.org/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a>


<br/><br/>]]></content:encoded>
			<wfw:commentRss>http://philosecurity.org/2009/01/26/mind-your-business/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
