<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Bag of Beans &#187; security</title>
	<atom:link href="http://bagofbeans.tsangal.org/archives/category/computers/security/feed" rel="self" type="application/rss+xml" />
	<link>http://bagofbeans.tsangal.org</link>
	<description>Caffeine not included.</description>
	<lastBuildDate>Sat, 21 Jan 2012 02:32:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Microsoft Dumps Partner For Fake Support Call Scam</title>
		<link>http://bagofbeans.tsangal.org/archives/7116</link>
		<comments>http://bagofbeans.tsangal.org/archives/7116#comments</comments>
		<pubDate>Wed, 21 Sep 2011 23:08:00 +0000</pubDate>
		<dc:creator>author-unknown</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[syndicated]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[An anonymous reader writes "Microsoft has broken its relationship with one of its Gold Partners, after it discovered that the partner was involved in a scam involving bogus tech support calls. India-based Comantra is said to have cold-called computer u... <a href="http://bagofbeans.tsangal.org/archives/7116">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p class="syndicated-attribution"><em>(via <a href="http://rss.slashdot.org/~r/Slashdot/slashdot/~3/gwcdXHKdV1c/Microsoft-Dumps-Partner-For-Fake-Support-Call-Scam">Slashdot</a>)</em></p>
An anonymous reader writes "Microsoft has broken its relationship with one of its Gold Partners, after it discovered that the partner was involved in a scam involving bogus tech support calls. India-based Comantra is said to have cold-called computer users in the UK, Australia, Canada and elsewhere, claiming to offer assistance in cleaning up virus infections. The calls used scare tactics to talk users into opening the Event Viewer on Windows, where a seemingly dangerous list of errors would be seen. This 'evidence' was used to trick innocent users into believing they had a malware infection, and for Comantra to gain the users' confidence. Duped users would then give permission for the support company to have remote access to their PC, and hand over their credit card details for a 'fix.' Security firm Sophos says that internet users have been complaining about Comantra's activities for over 18 months, and it has taken a long time for Microsoft to take action. Comantra's website still retains the Gold Certified Partner logo, although their details have been removed from Microsoft's database of approved partners."<p><a href="http://www.facebook.com/sharer.php?u=http://it.slashdot.org/story/11/09/21/2237207/Microsoft-Dumps-Partner-For-Fake-Support-Call-Scam?utm_source=slashdot&utm_medium=facebook" title="Share on Facebook"><img src="http://a.fsdn.com/sd/facebook_icon_large.png"></a>
   
      <a href="http://twitter.com/home?status=Microsoft+Dumps+Partner+For+Fake+Support+Call+Scam:+http://bit.ly/rlJUQm" title="Share on Twitter"><img src="http://a.fsdn.com/sd/twitter_icon_large.png"></a></p><p><a href="http://it.slashdot.org/story/11/09/21/2237207/Microsoft-Dumps-Partner-For-Fake-Support-Call-Scam?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p><iframe src="http://slashdot.org/slashdot-it.pl?op=discuss&amp;id=2439642&amp;smallembed=1" style="height:300px;width:100%;border:none"></iframe>
<p><a href="http://feedads.g.doubleclick.net/~at/PP7OpFykaTWcsHad2ri0UWMGFwY/0/da"><img src="http://feedads.g.doubleclick.net/~at/PP7OpFykaTWcsHad2ri0UWMGFwY/0/di" border="0" ismap></a><br>
<a href="http://feedads.g.doubleclick.net/~at/PP7OpFykaTWcsHad2ri0UWMGFwY/1/da"><img src="http://feedads.g.doubleclick.net/~at/PP7OpFykaTWcsHad2ri0UWMGFwY/1/di" border="0" ismap></a></p><img src="http://feeds.feedburner.com/~r/Slashdot/slashdot/~4/gwcdXHKdV1c" height="1" width="1">]]></content:encoded>
			<wfw:commentRss>http://bagofbeans.tsangal.org/archives/7116/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Protecting a Laptop From Sophisticated Attacks</title>
		<link>http://bagofbeans.tsangal.org/archives/6788</link>
		<comments>http://bagofbeans.tsangal.org/archives/6788#comments</comments>
		<pubDate>Fri, 26 Aug 2011 21:04:00 +0000</pubDate>
		<dc:creator>author-unknown</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[syndicated]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[mike_cardwell sends in a detailed writeup of how he went about protecting a Ubuntu laptop from attacks of varying levels of sophistication, covering disk encryption, defense against cold boot attacks, and even simple smash-and-grabs. (He also acknowled... <a href="http://bagofbeans.tsangal.org/archives/6788">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p class="syndicated-attribution"><em>(via <a href="http://rss.slashdot.org/~r/Slashdot/slashdot/~3/FP3lhzYOg9s/Protecting-a-Laptop-From-Sophisticated-Attacks">Slashdot</a>)</em></p>
mike_cardwell sends in a detailed writeup of how he went about protecting a Ubuntu laptop from attacks of varying levels of sophistication, covering disk encryption, defense against cold boot attacks, and even simple smash-and-grabs. (He also acknowledges that no defense is perfect, and the xkcd password extraction tool would still work.) Quoting:
"An attacker with access to the online machine could simply hard reboot the machine from a USB stick or CD containing msramdmp to grab a copy of the RAM. You could password protect the BIOS and disable booting from anything other than the hard drive, but that still doesn't protect you. An attacker could cool the RAM, remove it from the running machine, place it in a second machine and boot from that instead. The first defense I used against this attack is procedure based. I shut down the machine when it's not in use. My old Macbook was hardly ever shut down, and lived in suspend to RAM mode when not in use. The second defense I used is far more interesting. I use something called TRESOR. TRESOR is an implementation of AES as a cipher kernel module which stores the keys in the CPU debug registers, and which handles all of the crypto operations directly on the CPU, in a way which prevents the key from ever entering RAM. The laptop I purchased works perfectly with TRESOR as it contains a Core i5 processor which has the AES-NI instruction set."<p><a href="http://www.facebook.com/sharer.php?u=http://linux.slashdot.org/story/11/08/26/2033226/Protecting-a-Laptop-From-Sophisticated-Attacks?utm_source=slashdot&utm_medium=facebook" title="Share on Facebook"><img src="http://a.fsdn.com/sd/facebook_icon_large.png"></a>
   
      <a href="http://twitter.com/home?status=Protecting+a+Laptop+From+Sophisticated+Attacks:+http://bit.ly/oJhTGx" title="Share on Twitter"><img src="http://a.fsdn.com/sd/twitter_icon_large.png"></a></p><p><a href="http://linux.slashdot.org/story/11/08/26/2033226/Protecting-a-Laptop-From-Sophisticated-Attacks?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p><iframe src="http://slashdot.org/slashdot-it.pl?op=discuss&amp;id=2400152&amp;smallembed=1" style="height:300px;width:100%;border:none"></iframe><p><iframe src="http://feedads.g.doubleclick.net/~ah/f/lrqi37l1p7a6hqgtg7dfla1i4g/300/250?ca=1&amp;fh=280#http://linux.slashdot.org/story/11/08/26/2033226/Protecting-a-Laptop-From-Sophisticated-Attacks?utm_source=rss1.0mainlinkanon&utm_medium=feed" width="100%" height="280" frameborder="0" scrolling="no" marginwidth="0" marginheight="0"></iframe></p><img src="http://feeds.feedburner.com/~r/Slashdot/slashdot/~4/FP3lhzYOg9s" height="1" width="1">]]></content:encoded>
			<wfw:commentRss>http://bagofbeans.tsangal.org/archives/6788/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apache Warns Web Server Admins of DoS Attack Tool</title>
		<link>http://bagofbeans.tsangal.org/archives/6765</link>
		<comments>http://bagofbeans.tsangal.org/archives/6765#comments</comments>
		<pubDate>Wed, 24 Aug 2011 23:37:00 +0000</pubDate>
		<dc:creator>author-unknown</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[syndicated]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[CWmike writes "Developers of the Apache open-source project warned users of the Web server software on Wednesday that a denial-of-service (DoS) tool is circulating that exploits a bug in the program. 'Apache Killer' showed up last Friday in a post to t... <a href="http://bagofbeans.tsangal.org/archives/6765">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p class="syndicated-attribution"><em>(via <a href="http://rss.slashdot.org/~r/Slashdot/slashdot/~3/4wQSf8vnyGg/Apache-Warns-Web-Server-Admins-of-DoS-Attack-Tool">Slashdot</a>)</em></p>
CWmike writes "Developers of the Apache open-source project warned users of the Web server software on Wednesday that a denial-of-service (DoS) tool is circulating that exploits a bug in the program. 'Apache Killer' showed up last Friday in a post to the 'Full Disclosure' security mailing list. The Apache project said it would release a fix for Apache 2.0 and 2.2 in the next 48 hours. All versions in the 1.3 and 2.0 lines are said to be vulnerable to attack. The group no longer supports the older Apache 1.3. 'The attack can be done remotely and with a modest number of requests can cause very significant memory and CPU usage on the server,' Apache said in an advisory. The bug is not new. Michal Zalewski, a security engineer who works for Google, pointed out that he had brought up the DoS exploitability of Apache more than four-and-a-half years ago. In lieu of a fix, Apache offered steps administrators can take to defend their Web servers until a patch is available."<p><a href="http://www.facebook.com/sharer.php?u=http://apache.slashdot.org/story/11/08/24/2213201/Apache-Warns-Web-Server-Admins-of-DoS-Attack-Tool?utm_source=slashdot&utm_medium=facebook" title="Share on Facebook"><img src="http://a.fsdn.com/sd/facebook_icon_large.png"></a>
   
      <a href="http://twitter.com/home?status=Apache+Warns+Web+Server+Admins+of+DoS+Attack+Tool:+http://bit.ly/qQBOuz" title="Share on Twitter"><img src="http://a.fsdn.com/sd/twitter_icon_large.png"></a></p><p><a href="http://apache.slashdot.org/story/11/08/24/2213201/Apache-Warns-Web-Server-Admins-of-DoS-Attack-Tool?utm_source=rss1.0&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p><iframe src="http://slashdot.org/slashdot-it.pl?op=discuss&amp;id=2396368&amp;smallembed=1" style="height:300px;width:100%;border:none"></iframe><p><iframe src="http://feedads.g.doubleclick.net/~ah/f/lrqi37l1p7a6hqgtg7dfla1i4g/300/250?ca=1&amp;fh=280#http://apache.slashdot.org/story/11/08/24/2213201/Apache-Warns-Web-Server-Admins-of-DoS-Attack-Tool?utm_source=rss1.0&utm_medium=feed" width="100%" height="280" frameborder="0" scrolling="no" marginwidth="0" marginheight="0"></iframe></p><img src="http://feeds.feedburner.com/~r/Slashdot/slashdot/~4/4wQSf8vnyGg" height="1" width="1">]]></content:encoded>
			<wfw:commentRss>http://bagofbeans.tsangal.org/archives/6765/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Research Cracks AES Keys 3-5x Faster</title>
		<link>http://bagofbeans.tsangal.org/archives/6693</link>
		<comments>http://bagofbeans.tsangal.org/archives/6693#comments</comments>
		<pubDate>Fri, 19 Aug 2011 00:53:00 +0000</pubDate>
		<dc:creator>author-unknown</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[syndicated]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Landing his first accepted submission, qpgmr writes "AES, generally thought to be the gold standard for encryption, is showing weaknesses. From Computerworld: 'Researchers from Microsoft and the [Belgian] Katholieke Universiteit Leuven have discovered ... <a href="http://bagofbeans.tsangal.org/archives/6693">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p class="syndicated-attribution"><em>(via <a href="http://rss.slashdot.org/~r/Slashdot/slashdot/~3/N0k_1FA8oiU/New-Research-Cracks-AES-Keys-3-5x-Faster">Slashdot</a>)</em></p>
Landing his first accepted submission, qpgmr writes "AES, generally thought to be the gold standard for encryption, is showing weaknesses. From Computerworld: 'Researchers from Microsoft and the [Belgian] Katholieke Universiteit Leuven have discovered a way to break the widely used Advanced Encryption Standard, the encryption algorithm used to secure most all online transactions and wireless communications.'"

The full paper has lots of details. Note that it would still take a few billion years with current computers to actually break anything, but there may be further vunerabilities yet to be discovered.<p><a href="http://www.facebook.com/sharer.php?u=http://it.slashdot.org/story/11/08/18/2338249/New-Research-Cracks-AES-Keys-3-5x-Faster?utm_source=slashdot&utm_medium=facebook" title="Share on Facebook"><img src="http://a.fsdn.com/sd/facebook_icon_large.png"></a>
   
      <a href="http://twitter.com/home?status=New+Research+Cracks+AES+Keys+3-5x+Faster:+http://bit.ly/pMRBrT" title="Share on Twitter"><img src="http://a.fsdn.com/sd/twitter_icon_large.png"></a></p><p><a href="http://it.slashdot.org/story/11/08/18/2338249/New-Research-Cracks-AES-Keys-3-5x-Faster?utm_source=rss1.0&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p><iframe src="http://slashdot.org/slashdot-it.pl?op=discuss&amp;id=2386868&amp;smallembed=1" style="height:300px;width:100%;border:none"></iframe><p><iframe src="http://feedads.g.doubleclick.net/~ah/f/lrqi37l1p7a6hqgtg7dfla1i4g/300/250?ca=1&amp;fh=280#http://it.slashdot.org/story/11/08/18/2338249/New-Research-Cracks-AES-Keys-3-5x-Faster?utm_source=rss1.0&utm_medium=feed" width="100%" height="280" frameborder="0" scrolling="no" marginwidth="0" marginheight="0"></iframe></p><img src="http://feeds.feedburner.com/~r/Slashdot/slashdot/~4/N0k_1FA8oiU" height="1" width="1">]]></content:encoded>
			<wfw:commentRss>http://bagofbeans.tsangal.org/archives/6693/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Safe Browsing Tool &#124; WOT (Web of Trust)</title>
		<link>http://bagofbeans.tsangal.org/archives/6031</link>
		<comments>http://bagofbeans.tsangal.org/archives/6031#comments</comments>
		<pubDate>Thu, 16 Jun 2011 19:28:41 +0000</pubDate>
		<dc:creator>Beanbag</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[syndicated]]></category>
		<category><![CDATA[bookmark]]></category>
		<category><![CDATA[extension]]></category>
		<category><![CDATA[Fraud]]></category>
		<category><![CDATA[Scams]]></category>
		<category><![CDATA[skepticism]]></category>

		<guid isPermaLink="false">http://www.delicious.com/url/5c8ee0d0562d372b5633e85d0d935fc1#tsangal</guid>
		<description><![CDATA["The WOT add-on shows you which websites you can trust based on millions of users' experiences.
Our safe surfing browser tool is easy-to-use, fast and completely free." <a href="http://bagofbeans.tsangal.org/archives/6031">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p class="syndicated-attribution"><em>(via <a href="http://www.mywot.com/">Delicious/tsangal</a>)</em></p>
"The WOT add-on shows you which websites you can trust based on millions of users' experiences.
Our safe surfing browser tool is easy-to-use, fast and completely free."]]></content:encoded>
			<wfw:commentRss>http://bagofbeans.tsangal.org/archives/6031/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Daily Sony Hacking Occurs On Schedule</title>
		<link>http://bagofbeans.tsangal.org/archives/5846</link>
		<comments>http://bagofbeans.tsangal.org/archives/5846#comments</comments>
		<pubDate>Mon, 06 Jun 2011 20:57:00 +0000</pubDate>
		<dc:creator>author-unknown</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[syndicated]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[jjp9999 writes "LulzSec was compromised and a member of the group, Robert Cavanaugh, was arrested by the FBI on June 6. Meanwhile, LulzSec hacked Sony again, this time leaking the Sony Developer Network source code through file sharing websites."
   
 ... <a href="http://bagofbeans.tsangal.org/archives/5846">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p class="syndicated-attribution"><em>(via <a href="http://rss.slashdot.org/~r/Slashdot/slashdot/~3/cKTIOFpTyEw/Daily-Sony-Hacking-Occurs-On-Schedule">Slashdot</a>)</em></p>
jjp9999 writes "LulzSec was compromised and a member of the group, Robert Cavanaugh, was arrested by the FBI on June 6. Meanwhile, LulzSec hacked Sony again, this time leaking the Sony Developer Network source code through file sharing websites."<p><a href="http://www.facebook.com/sharer.php?u=http://it.slashdot.org/story/11/06/06/2023204/Daily-Sony-Hacking-Occurs-On-Schedule?utm_source=slashdot&utm_medium=facebook" title="Share on Facebook"><img src="http://a.fsdn.com/sd/facebook_icon_large.png"></a>
   
      <a href="http://twitter.com/home?status=Daily+Sony+Hacking+Occurs+On+Schedule:+http://bit.ly/mIl2Ju" title="Share on Twitter"><img src="http://a.fsdn.com/sd/twitter_icon_large.png"></a></p><p><a href="http://it.slashdot.org/story/11/06/06/2023204/Daily-Sony-Hacking-Occurs-On-Schedule?utm_source=rss1.0&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p><iframe src="http://slashdot.org/slashdot-it.pl?op=discuss&amp;id=2216562&amp;smallembed=1" style="height:300px;width:100%;border:none"></iframe><p><iframe src="http://feedads.g.doubleclick.net/~ah/f/lrqi37l1p7a6hqgtg7dfla1i4g/300/250?ca=1&amp;fh=280#http://it.slashdot.org/story/11/06/06/2023204/Daily-Sony-Hacking-Occurs-On-Schedule?utm_source=rss1.0&utm_medium=feed" width="100%" height="280" frameborder="0" scrolling="no" marginwidth="0" marginheight="0"></iframe></p><img src="http://feeds.feedburner.com/~r/Slashdot/slashdot/~4/cKTIOFpTyEw" height="1" width="1">]]></content:encoded>
			<wfw:commentRss>http://bagofbeans.tsangal.org/archives/5846/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RSA SecurID breach linked to hacker attack on Lockheed Martin; other US military contractors may be affected</title>
		<link>http://bagofbeans.tsangal.org/archives/5723</link>
		<comments>http://bagofbeans.tsangal.org/archives/5723#comments</comments>
		<pubDate>Sat, 28 May 2011 16:18:35 +0000</pubDate>
		<dc:creator>author-unknown</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[syndicated]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[war]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[
[F-35 Lightning II, also known as the Joint Strike Fighter (JSF), planes built by Lockheed Martin arrive at Edwards Air Force Base in California in this May 2010 photo. REUTERS/Tom Reynolds/Lockheed Martin]



This week, Lockheed Martin—the largest ... <a href="http://bagofbeans.tsangal.org/archives/5723">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p class="syndicated-attribution"><em>(via <a href="http://feedproxy.google.com/~r/boingboing/iBag/~3/aEBBcfRYZA4/attack-on-rsas-secur.html">Boing Boing</a>)</em></p>
<a href="http://www.boingboing.net/assets_c/2011/05/RTXSJA1-39823.html"><img src="http://www.boingboing.net/assets_c/2011/05/RTXSJA1-thumb-600x471-39823.jpg" width="600" alt="RTXSJA1.jpg" style="text-align:center;display:block;margin:0 auto 0px"></a><br>
<em><small>[F-35 Lightning II, also known as the Joint Strike Fighter (JSF), planes built by Lockheed Martin arrive at Edwards Air Force Base in California in this May 2010 photo. REUTERS/Tom Reynolds/Lockheed Martin]</small></em>

<p>

This week, <a href="http://www.lockheedmartin.com/">Lockheed Martin</a>—the largest U.S. military contractor—and several other defense contractors have reportedly experienced intrusions in their computer networks. Those intrusions may be connected to <a href="https://www.cs.columbia.edu/~smb/blog/2011-03/2011-03-18.html">a hacking attack</a> on <a href="http://www.rsa.com/">RSA</a>'s <a href="http://www.rsa.com/node.aspx?id=1156">SecurID</a> security token division, <a href="http://www.rsa.com/node.aspx?id=3872">disclosed back in March</a>. <p>
Hackers penetrating <a href="http://boingboing.net/2011/04/26/sony-psn-intruder-ma.html">Sony's Playstation network</a> or <a href="http://boingboing.net/2010/02/04/report-google-to-tea.html">Google</a>, affecting the data privacy of millions of users? Bad. Hackers penetrating the networks of the US military's largest weapons makers? Really, really, really bad.<p>
<a href="http://www.reuters.com/article/2011/05/28/usa-defense-hackers-idUSN2717936920110528">Reuters was first tonight with the news</a> of the intrusion at Lockheed, which the company is said to have first detected on Sunday.
<p>
<blockquote>They breached security systems designed to keep out intruders by creating duplicates to "SecurID" electronic keys from EMC Corp's RSA security division, said the person who was not authorized to publicly discuss the matter.

It was not immediately clear what kind of data, if any, was stolen by the hackers. But the networks of Lockheed and other military contractors contain sensitive data on future weapons systems as well as military technology currently used in battles in Iraq and Afghanistan.</blockquote>
<p>

A <a href="http://online.wsj.com/article/SB10001424052702303654804576350083016866022.html?mod=googlenews_wsj">Lockheed press statement, reprinted in part in the Wall Street Journal</a>,
<p>
<blockquote>[T]o counter any threats, we regularly take actions to increase the security of our systems and to protect our employee, customer and program data. We have policies and procedures in place to mitigate the cyber threats to our business, and we remain confident in the integrity of our robust, multilayered information systems security.
 </blockquote>
<p><a href="https://www.cs.columbia.edu/~smb/blog/2011-03/2011-03-18.html">
<img alt="securid.jpg" src="http://www.boingboing.net/2011/05/27/securid.jpg" width="600" style="text-align:center;display:block;margin:0 auto 20px"></a>

<p>
John Markoff and Christopher Drew <a href="http://www.nytimes.com/2011/05/28/business/28hack.html">in the <em>New York Times</em></a> link the Lockheed hack to the March RSA breach. While Lockheed's problems may be the first publicly known damage from that attack,  other firms may also be affected.<p>

<p>
<blockquote>

<p>"The issue is whether all of the security controls are compromised," said James A. Lewis, a senior fellow and a specialist in computer security issues at the Center for Strategic and International Studies, a policy group in Washington. "That's the assumption people are making."<br>
<p><br>
Neither RSA, which is based in Bedford, Mass., nor Lockheed would discuss the problems on Friday.<br>
<p><br>
Officials in the military industry, who spoke only on the condition of anonymity given the sensitivity of the matter, said Lockheed had detected an intruder trying to break into its networks last Sunday. It shut down much of its remote access and has been providing new tokens and passwords to many workers, company employees said. </p>

</p></p></blockquote><p>

<p></p>

<p><a href="http://www.raytheon.com/">Raytheon</a> published a statement today saying it took "immediate companywide actions" when the RSA breach became known back in March. <a href="http://www.generaldynamics.com/">General Dynamics</a> denied experiencing problems related to the RSA breach; <a href="http://www.northropgrumman.com/">Northrop Grumman</a> and <a href="http://www.boeing.com/">Boeing</a> <a href="http://www.nytimes.com/2011/05/28/business/28hack.html">declined to comment to the <em>Times</em></a>. <p><br>
<strong>Related reading</strong>: <br>
<br>• <a href="http://www.nytimes.com/2011/03/18/technology/18secure.html"><br>
SecurID Company Suffers a Breach of Data Security</a> <em>(NYT, March 17, 2011, John Markoff)</em> <br><br>
• <a href="https://www.cs.columbia.edu/~smb/blog/2011-03/2011-03-18.html">Columbia University computer science professor Steve Bellovin's take</a> on the RSA breach <em>(March, 2011)</em>.<br><br>
• And <a href="http://arstechnica.com/security/news/2011/04/spearphishing-0-day-rsa-hack-not-extremely-sophisticated.ars">Ars Technica's counterpoint to RSA's characterization of the breach</a> as "extremely sophisticated."</p><br style="clear:both">
<br style="clear:both">
<a href="http://ads.pheedo.com/click.phdo?s=9f744675d415d93ff3ead358b1a04734&amp;p=1"><img alt="" style="border:0" border="0" src="http://ads.pheedo.com/img.phdo?s=9f744675d415d93ff3ead358b1a04734&amp;p=1"></a>
<img alt="" height="0" width="0" border="0" src="http://segment-pixel.invitemedia.com/pixel?code=TechCons&amp;partnerID=167&amp;key=segment"><img alt="" height="0" width="0" border="0" src="http://pixel.quantserve.com/pixel/p-8bUhLiluj0fAw.gif?labels=pub.28925.rss.TechCons.7604,cat.TechCons.rss"><img alt="" height="0" width="0" border="0" src="http://amch.questionmarket.com/adsc/d887846/17/909940/adscout.php"><img src="http://feeds.feedburner.com/~r/boingboing/iBag/~4/aEBBcfRYZA4" height="1" width="1"></p></p></p></p></p></p></p></p></p></p></p></p>]]></content:encoded>
			<wfw:commentRss>http://bagofbeans.tsangal.org/archives/5723/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sony BMG Greece hacked, company&#8217;s security woes continue</title>
		<link>http://bagofbeans.tsangal.org/archives/5601</link>
		<comments>http://bagofbeans.tsangal.org/archives/5601#comments</comments>
		<pubDate>Mon, 23 May 2011 19:41:00 +0000</pubDate>
		<dc:creator>author-unknown</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[syndicated]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[customer data]]></category>
		<category><![CDATA[CustomerData]]></category>
		<category><![CDATA[greece]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[sony]]></category>
		<category><![CDATA[Sony BMG]]></category>
		<category><![CDATA[sony bmg greece]]></category>
		<category><![CDATA[SonyBmg]]></category>
		<category><![CDATA[SonyBmgGreece]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[
	
It's the security nightmare that just won't end, and right now there's got to be plenty of Sony executives beginning to wish someone would pinch them already. After taking quite a PR and financial beating over the PSN breach, now the Greek site of S... <a href="http://bagofbeans.tsangal.org/archives/5601">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p class="syndicated-attribution"><em>(via <a href="http://www.engadget.com/2011/05/23/sony-bmg-greece-hacked-companys-security-woes-continue/">Engadget</a>)</em></p>
<div style="text-align:center">
	<a href="http://www.engadget.com/2011/05/23/sony-bmg-greece-hacked-companys-security-woes-continue/"><img alt="SonyBMG.gr Hacked" src="http://www.blogcdn.com/www.engadget.com/media/2011/05/5-22-2011sonybmggreecehack.jpg" style="border-width:0px;border-style:solid;margin:4px"></a></div>
It's the <a href="http://www.engadget.com/2011/05/18/psn-logins-exploited-again-sony-takes-sign-in-pages-offline/">security</a> <a href="http://www.engadget.com/2011/05/04/sony-responds-to-congress-all-77-million-psn-accounts-compromis/">nightmare</a> that just won't end, and right now there's got to be plenty of Sony executives beginning to wish someone would pinch them already. After taking quite a <a href="http://www.engadget.com/2011/05/16/japan-wont-allow-sony-to-turn-psn-back-on-until-its-assured-it/">PR</a> and <a href="http://www.engadget.com/2011/05/23/sony-estimates-3-2b-loss-this-year-171-million-cost-for-psn-b/">financial</a> beating over the PSN breach, now the Greek site of Sony BMG has been hacked and the account info of thousands of users has been posted online. According to the Sophos blog <span style="font-style:italic">Naked Security</span>, the attack does not appear to have been particularly sophisticated and was carried out using an automated SQL injection tool that demands more patience than skill. While the data dump reveals the usernames, real names, and email addresses of registered SonyMusic.gr customers, other fields (including passwords and telephone numbers) are either empty or contain fake data -- suggesting the hack was not entirely successful. Here's hoping Sony takes this as an opportunity to seriously baton down those security hatches.<p style="padding:5px;background:#ddd;border:1px solid #ccc;clear:both"><a href="http://www.engadget.com/2011/05/23/sony-bmg-greece-hacked-companys-security-woes-continue/">Sony BMG Greece hacked, company's security woes continue</a> originally appeared on <a href="http://www.engadget.com">Engadget</a> on Mon, 23 May 2011 15:41:00 EDT.  Please see our <a href="http://www.weblogsinc.com/feed-terms/">terms for use of feeds</a>.</p><h6 style="clear:both;padding:8px 0 0 0;height:2px;font-size:1px;border:0;margin:0;padding:0"></h6><a href="http://www.engadget.com/2011/05/23/sony-bmg-greece-hacked-companys-security-woes-continue/" rel="bookmark" title="Permanent link to this entry">Permalink</a>   |  <img src="http://www.blogsmithmedia.com/www.engadget.com/media/post_label_source.gif" alt="source"><span><a href="http://nakedsecurity.sophos.com/2011/05/22/sony-bmg-greece-the-latest-hacked-sony-site/">Naked Security</a></span>  | <a href="http://www.engadget.com/forward/19947500/" title="Send this entry to a friend via email">Email this</a> | <a href="http://www.engadget.com/2011/05/23/sony-bmg-greece-hacked-companys-security-woes-continue/#comments" title="View reader comments on this entry">Comments</a>]]></content:encoded>
			<wfw:commentRss>http://bagofbeans.tsangal.org/archives/5601/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sony hacked again, used to host phishing site</title>
		<link>http://bagofbeans.tsangal.org/archives/5497</link>
		<comments>http://bagofbeans.tsangal.org/archives/5497#comments</comments>
		<pubDate>Fri, 20 May 2011 14:35:00 +0000</pubDate>
		<dc:creator>author-unknown</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[syndicated]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[sony]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[
  
  

		        
    With Anonymous Denial of Service attacks and then the twin hacks of PlayStation Network and Sony Online Entertainment, Sony&#039;s online infrastructure has been taking a battering over the last few weeks—and it&#039;s not over y... <a href="http://bagofbeans.tsangal.org/archives/5497">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p class="syndicated-attribution"><em>(via <a href="http://feeds.arstechnica.com/~r/arstechnica/index/~3/IG_aabwwHzo/sony-hacked-again-used-to-host-phishing-site.ars">Ars Technica</a>)</em></p>
<a href="http://arstechnica.com/security/news/2011/05/sony-hacked-again-used-to-host-phishing-site.ars?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=rss">
  <img vspace="4" hspace="4" border="0" align="right" width="230" height="129" src="http://static.arstechnica.net/brief_icons/generic-brief.png">
  </a>

		        
    <p>With <a href="http://arstechnica.com/tech-policy/news/2011/04/anonymous-attacks-sony-to-protest-ps3-hacker-lawsuit.ars">Anonymous Denial of Service</a> attacks and then the twin hacks of <a href="http://arstechnica.com/gaming/news/2011/04/sonys-black-eye-is-a-pr-problem-not-a-legal-one.ars">PlayStation Network</a> and Sony Online Entertainment, Sony&#39;s online infrastructure has been taking a battering over the last few weeks—and it&#39;s not over yet. Another successful hack against the company <a href="http://www.f-secure.com/weblog/archives/00002160.html">is being reported</a> by security firm F-Secure. A Web server used to host Sony's Thai site has been broken into, and is now being used to host a phishing site that targets customers of an Italian credit card company.</p>

<p>Unlike the PSN and SOE break-ins, this hack is not likely to have any serious consequences; it should be restricted to a relatively unimportant Web server that has no access to sensitive customer information. Still, it shows that Sony&#39;s online troubles aren&#39;t over yet—and that the entire company needs to take online security more seriously.</p>    
        
    


      <p><a href="http://arstechnica.com/security/news/2011/05/sony-hacked-again-used-to-host-phishing-site.ars?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=rss&amp;comments=1#comments-bar">Read the comments on this post</a></p><p><iframe src="http://feedads.g.doubleclick.net/~ah/f/99b8ti6rhu084de2qordu91eqc/300/250?ca=1&amp;fh=280#http://arstechnica.com/security/news/2011/05/sony-hacked-again-used-to-host-phishing-site.ars?utm_source=rss&utm_medium=rss&utm_campaign=rss" width="100%" height="280" frameborder="0" scrolling="no" marginwidth="0" marginheight="0"></iframe></p><div>
<a href="http://feeds.arstechnica.com/~ff/arstechnica/index?a=IG_aabwwHzo:nuTw8Ee4MUQ:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/arstechnica/index?i=IG_aabwwHzo:nuTw8Ee4MUQ:V_sGLiPBpWU" border="0"></a> <a href="http://feeds.arstechnica.com/~ff/arstechnica/index?a=IG_aabwwHzo:nuTw8Ee4MUQ:F7zBnMyn0Lo"><img src="http://feeds.feedburner.com/~ff/arstechnica/index?i=IG_aabwwHzo:nuTw8Ee4MUQ:F7zBnMyn0Lo" border="0"></a> <a href="http://feeds.arstechnica.com/~ff/arstechnica/index?a=IG_aabwwHzo:nuTw8Ee4MUQ:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/arstechnica/index?d=qj6IDK7rITs" border="0"></a> <a href="http://feeds.arstechnica.com/~ff/arstechnica/index?a=IG_aabwwHzo:nuTw8Ee4MUQ:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/arstechnica/index?d=yIl2AUoC8zA" border="0"></a>
</div><img src="http://feeds.feedburner.com/~r/arstechnica/index/~4/IG_aabwwHzo" height="1" width="1">]]></content:encoded>
			<wfw:commentRss>http://bagofbeans.tsangal.org/archives/5497/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>France to require unhashed password storage</title>
		<link>http://bagofbeans.tsangal.org/archives/4843</link>
		<comments>http://bagofbeans.tsangal.org/archives/4843#comments</comments>
		<pubDate>Tue, 12 Apr 2011 09:02:38 +0000</pubDate>
		<dc:creator>author-unknown</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[syndicated]]></category>
		<category><![CDATA[france]]></category>
		<category><![CDATA[law]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[surveillance]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[France's new data retention law requires online service providers to retain databases of their users' addresses, real names and passwords, and to supply these to police on demand. Leaving aside the risk of retaining all this personal information (ident... <a href="http://bagofbeans.tsangal.org/archives/4843">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p class="syndicated-attribution"><em>(via <a href="http://feedproxy.google.com/~r/boingboing/iBag/~3/2CnbWbUBV8U/france-to-require-cl.html">Boing Boing</a>)</em></p>
France's new data retention law requires online service providers to retain databases of their users' addresses, real names and passwords, and to supply these to police on demand. Leaving aside the risk of retaining all this personal information (identity thieves, stalkers, etc -- that which isn't stored can't be stolen and leaked), there's the risk of requiring providers to store <s>plaintext</s> <b>unhashed</b> passwords, as <a href="http://www.schneier.com/blog/archives/2011/04/new_french_law.html">Bruce Schneier points out</a>. 
<p>
Well-designed systems don't store passwords; rather, they take the password you supply and run it through a cryptographic hashing algorithm that turns it into another string (in theory, this string can't be turned back into the password). When you re-visit the website and supply your password, it is run through the algorithm again, and then the result is compared to the stored version. That way, no one -- not even the provider -- knows your password (except you). Again, that which isn't stored can't be leaked. Requiring French online services to keep a record of <b>unhashed</b> passwords is a reversal of decades of best practices in security.

<blockquote>
The law obliges a range of e-commerce sites, video and music services and webmail providers to keep a host of data on customers.
<p>
This includes users' full names, postal addresses, telephone numbers and passwords. The data must be handed over to the authorities if demanded.
<p>
Police, the fraud office, customs, tax and social security bodies will all have the right of access.
</p></p></blockquote>

<a href="http://www.bbc.co.uk/news/technology-12983734">Net giants challenge French data law</a>

<br style="clear:both">
<br style="clear:both">
<a href="http://ads.pheedo.com/click.phdo?s=6203d7e32b5f2a6115dce956db8b1c9d&amp;p=1"><img alt="" style="border:0" border="0" src="http://ads.pheedo.com/img.phdo?s=6203d7e32b5f2a6115dce956db8b1c9d&amp;p=1"></a>
<img alt="" height="0" width="0" border="0" src="http://segment-pixel.invitemedia.com/pixel?code=TechCons&amp;partnerID=167&amp;key=segment"><img alt="" height="0" width="0" border="0" src="http://pixel.quantserve.com/pixel/p-8bUhLiluj0fAw.gif?labels=pub.28925.rss.TechCons.7604,cat.TechCons.rss"><img src="http://feeds.feedburner.com/~r/boingboing/iBag/~4/2CnbWbUBV8U" height="1" width="1"></p>]]></content:encoded>
			<wfw:commentRss>http://bagofbeans.tsangal.org/archives/4843/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SSL certificate authorities put us all at risk by handing out certs for &#8220;mail&#8221; &#8220;webmail&#8221; and other unqualified domains</title>
		<link>http://bagofbeans.tsangal.org/archives/4793</link>
		<comments>http://bagofbeans.tsangal.org/archives/4793#comments</comments>
		<pubDate>Wed, 06 Apr 2011 10:35:03 +0000</pubDate>
		<dc:creator>author-unknown</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[syndicated]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[Action]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[eff]]></category>
		<category><![CDATA[ssl]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[In the wake of the revelation that a major SSL certificate provider suffered a serious breach, Chris Palmer from the Electronic Frontier Foundation has analysis of the common practice of issuing certificates for unqualified domain names, such as "mail"... <a href="http://bagofbeans.tsangal.org/archives/4793">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p class="syndicated-attribution"><em>(via <a href="http://feedproxy.google.com/~r/boingboing/iBag/~3/_oVTITAmbeA/ssl-certificate-auth.html">Boing Boing</a>)</em></p>
In the wake of the revelation that <a href="http://www.boingboing.net/2011/03/24/understanding-the-ss.html">a major SSL certificate provider suffered a serious breach</a>, Chris Palmer from the Electronic Frontier Foundation has analysis of the common practice of issuing certificates for unqualified domain names, such as "mail" and "www" and "localhost" (an unqualified domain is one that consists of a single word, without a top- and second-level domain, e.g., "www" instead of "www.boingboing.net"). These unqualified names should <em>never</em> be issued certificates, as doing so leaves anyone who makes a practice of using them within a company network vulnerable to man-in-the-middle attacks. Palmer found tens of thousands of these certificates, and sounds the alarm that if you're not using fully qualified domains for secure connections, you're very vulnerable.

<blockquote>
<img src="http://craphound.com/images/unqualedcerts.jpeg" align="right">
Although signing "localhost" is humorous, CAs create real risk when they sign other unqualified names. What if an attacker were able to receive a CA-signed certificate for names like "mail" or "webmail"? Such an attacker would be able to perfectly forge the identity of your organization's webmail server in a "man-in-the-middle" attack! Everything would look normal: your browser would use HTTPS, it would show a the lock icon that indicates HTTPS is working properly, it would show that a real CA validated the HTTPS certificate, and it would raise no security warnings. And yet, you would be giving your password and your email contents to the attacker.
<p>
To test the prevalence of the validated, unqualified names problem, I queried the Observatory database for unqualified names similar to "exchange". (Microsoft Exchange is an extremely popular email server, and servers that run it commonly have "exchange" or "exch" in their names. Likely examples include "exchange.example.net" and "exch-01.example.com".) My results show that unqualified "exchange"-like names are the most popular type of name, overall, that CAs are happy to sign.
</p></blockquote>

<a href="https://www.eff.org/deeplinks/2011/04/unqualified-names-ssl-observatory">Unqualified Names in the SSL Observatory</a>

<div>
<em> </em><ul><li><a href="http://www.boingboing.net/2011/03/24/understanding-the-ss.html#previouspost">Understanding the SSL security breach, preparing for the next one ...</a></li>
<li><a href="http://www.boingboing.net/2011/01/03/how-to-stay-safe-at.html#previouspost">How to stay safe at public WiFi spots - Boing Boing</a></li>
<li><a href="http://www.boingboing.net/2010/10/27/sheep.html#previouspost">Liar, Liar, Sheep on Fire - Boing Boing</a></li>
<li><a href="http://boingboing.net/2008/11/26/passwords-suck.html#previouspost">Passwords suck - Boing Boing</a></li>
</ul>
</div>

<br style="clear:both">
<br style="clear:both">
<a href="http://ads.pheedo.com/click.phdo?s=e480a4962449d8212876fd548d917546&amp;p=1"><img alt="" style="border:0" border="0" src="http://ads.pheedo.com/img.phdo?s=e480a4962449d8212876fd548d917546&amp;p=1"></a>
<img alt="" height="0" width="0" border="0" src="http://segment-pixel.invitemedia.com/pixel?code=TechCons&amp;partnerID=167&amp;key=segment"><img alt="" height="0" width="0" border="0" src="http://pixel.quantserve.com/pixel/p-8bUhLiluj0fAw.gif?labels=pub.28925.rss.TechCons.7604,cat.TechCons.rss"><img src="http://feeds.feedburner.com/~r/boingboing/iBag/~4/_oVTITAmbeA" height="1" width="1">]]></content:encoded>
			<wfw:commentRss>http://bagofbeans.tsangal.org/archives/4793/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>World&#8217;s largest spam botnet goes down (for now?)</title>
		<link>http://bagofbeans.tsangal.org/archives/4560</link>
		<comments>http://bagofbeans.tsangal.org/archives/4560#comments</comments>
		<pubDate>Thu, 17 Mar 2011 11:25:06 +0000</pubDate>
		<dc:creator>author-unknown</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[syndicated]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[Action]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Brian Krebs reports on the takedown of the command-and-control servers for Rustock, the largest and most successful spam botnet. The botnet's output has fallen from thousands of spams per second to one or two spams per second: 



It may yet be too soo... <a href="http://bagofbeans.tsangal.org/archives/4560">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p class="syndicated-attribution"><em>(via <a href="http://feedproxy.google.com/~r/boingboing/iBag/~3/6xWrBDKLbaM/worlds-largest-spam.html">Boing Boing</a>)</em></p>
Brian Krebs reports on the takedown of the command-and-control servers for Rustock, the largest and most successful spam botnet. The botnet's output has fallen from thousands of spams per second to one or two spams per second: 

<blockquote>
<img src="http://craphound.com/images/155554663_89beb0ac63_z.jpg" align="right">
It may yet be too soon to celebrate the takedown of the world's largest spam botnet. For one thing, PCs that were infected with Rustock prior to this action remain infected, only they are now somewhat lost, like sheep without a shepherd. In previous takedowns, such as those executed against the Srizbi botnet, the botmasters have been able to regain control over their herds of infected PCs using a complex algorithm built into the malware that generates a random but unique Web site domain name that the bots would be instructed to check for new instructions and software updates from its authors. Using such a system, the botmaster needs only to register one of these Web site names in order to resume sending updates to and controlling the herd of infected computers.
<p>
Stewart said that whoever is responsible for this takedown clearly has done their homework, and that the backup domains hard-coded into Rustock appear to also have been taken offline. But, he said, Rustock also appears to have a mechanism for randomly generating and seeking out new Web site names that could be registered by the botmaster to regain control over the pool of still-infected PCs. Stewart said Rustock-infected machines routinely reach out to a variety of popular Web sites, such as Wikipedia, Mozilla, Slashdot, MSN and others, and that it is possible that Rustock may be configured to use the news headlines or other topical information from these sites as the random seed for generating new command and control domains.
</p></blockquote>

<a href="http://krebsonsecurity.com/2011/03/rustock-botnet-flatlined-spam-volumes-plummet/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed:+KrebsOnSecurity+(Krebs+on+Security)">Rustock Botnet Flatlined, Spam Volumes Plummet</a>
<p>
(<i>Image: <a href="http://www.flickr.com/photos/63056612@N00/155554663/">Spam wall</a>, a Creative Commons <a href="http://creativecommons.org/licenses/by-sa/2.0/deed.en">Attribution Share-Alike (2.0)</a> image from 63056612@N00's photostream</i>)

<div>
<em> </em><ul><li><a href="http://boingboing.net/2010/01/25/fighting-spam-with-c.html#previouspost">Fighting spam with captured botnet hosts - Boing Boing</a></li>
<li><a href="http://boingboing.net/2009/06/13/have-botnet-prices-c.html#previouspost">Have botnet prices crashed? - Boing Boing</a></li>
<li><a href="http://boingboing.net/2007/09/07/economics-of-malware.html#previouspost">Economics of Malware - Boing Boing</a></li>
<li><a href="http://gadgets.boingboing.net/2008/11/13/colo-shutdown-takes.html#previouspost">Colo shutdown takes a big bite out of spam traffic - Boing Boing</a></li>
<li><a href="http://boingboing.net/2009/12/21/botnet-runners-start.html#previouspost">Botnet runners start their own ISPs - Boing Boing</a></li>
<li><a href="http://www.boingboing.net/2010/11/05/botmasters-include-f.html#previouspost">Botmasters include fake control interface to ensnare security ...</a></li>
</ul>
</div>
<br style="clear:both">
<br style="clear:both">
<a href="http://ads.pheedo.com/click.phdo?s=70b5e12e387ac6efda681417d7e54184&amp;p=1"><img alt="" style="border:0" border="0" src="http://ads.pheedo.com/img.phdo?s=70b5e12e387ac6efda681417d7e54184&amp;p=1"></a>
<img alt="" height="0" width="0" border="0" src="http://segment-pixel.invitemedia.com/pixel?code=TechCons&amp;partnerID=167&amp;key=segment"><img alt="" height="0" width="0" border="0" src="http://pixel.quantserve.com/pixel/p-8bUhLiluj0fAw.gif?labels=pub.28925.rss.TechCons.7604,cat.TechCons.rss"><img src="http://feeds.feedburner.com/~r/boingboing/iBag/~4/6xWrBDKLbaM" height="1" width="1"></p>]]></content:encoded>
			<wfw:commentRss>http://bagofbeans.tsangal.org/archives/4560/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Amazon Security Flaw May Make Your Old Password Easy to Crack [Security]</title>
		<link>http://bagofbeans.tsangal.org/archives/3870</link>
		<comments>http://bagofbeans.tsangal.org/archives/3870#comments</comments>
		<pubDate>Thu, 27 Jan 2011 12:15:00 +0000</pubDate>
		<dc:creator>author-unknown</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[syndicated]]></category>
		<category><![CDATA[Amazon]]></category>
		<category><![CDATA[in brief]]></category>
		<category><![CDATA[Passwords]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[
										
					
						
											
									
				It seems that if you haven't changed your Amazon.com password in awhile and it's more than eight characters, anything after the first eight characters doesn't matter so much.  For example, if your pass... <a href="http://bagofbeans.tsangal.org/archives/3870">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p class="syndicated-attribution"><em>(via <a href="http://lifehacker.com/5744577/amazon-security-flaw-may-make-your-old-password-easy-to-crack">Lifehacker</a>)</em></p>
<div style="float:left;padding-right:10px">
										
					<div><a title="Click here to read Amazon Security Flaw May Make Your Old Password Easy to Crack" href="http://lifehacker.com/5744577/amazon-security-flaw-may-make-your-old-password-easy-to-crack">
						<img style="border-color:#B3B3B3;border-width:0 1px 1px;border-style:none solid solid" height="120" width="160" title="Click here to read Amazon Security Flaw May Make Your Old Password Easy to Crack" alt="Click here to read Amazon Security Flaw May Make Your Old Password Easy to Crack" src="http://cache-01.gawkerassets.com/assets/images/17/2011/01/160x120_amazon_crave.jpg">
											</a></div>
									</div>
				It seems that if you haven't changed your Amazon.com password in awhile and it's more than eight characters, anything after the first eight characters doesn't matter so much.  For example, if your password was <b>password1234567890</b>, someone could enter <b>passwordpizza</b> and get into your account all the same.  It seems this problem is only with passwords that are a couple of years old and it can easily be fixed by just setting a new password.<br>				<a href="http://lifehacker.com/5744577/amazon-security-flaw-may-make-your-old-password-easy-to-crack" title="Click here to read more about Amazon Security Flaw May Make Your Old Password Easy to Crack [Security]">More »</a>
				<br style="clear:both"><div>
<a href="http://feeds.gawker.com/~ff/lifehacker/excerpts?a=VbASl0_jzW8:OzJQNJIjWkY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/lifehacker/excerpts?d=yIl2AUoC8zA" border="0"></a> <a href="http://feeds.gawker.com/~ff/lifehacker/excerpts?a=VbASl0_jzW8:OzJQNJIjWkY:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/lifehacker/excerpts?i=VbASl0_jzW8:OzJQNJIjWkY:D7DqB2pKExk" border="0"></a> <a href="http://feeds.gawker.com/~ff/lifehacker/excerpts?a=VbASl0_jzW8:OzJQNJIjWkY:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/lifehacker/excerpts?i=VbASl0_jzW8:OzJQNJIjWkY:V_sGLiPBpWU" border="0"></a> <a href="http://feeds.gawker.com/~ff/lifehacker/excerpts?a=VbASl0_jzW8:OzJQNJIjWkY:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/lifehacker/excerpts?d=qj6IDK7rITs" border="0"></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://bagofbeans.tsangal.org/archives/3870/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Secunia Personal Software Inspector (PSI)</title>
		<link>http://bagofbeans.tsangal.org/archives/3574</link>
		<comments>http://bagofbeans.tsangal.org/archives/3574#comments</comments>
		<pubDate>Fri, 14 Jan 2011 00:20:38 +0000</pubDate>
		<dc:creator>Beanbag</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[syndicated]]></category>
		<category><![CDATA[bookmark]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.delicious.com/url/2b13f351481c8884cfd264faf27214c6#tsangal</guid>
		<description><![CDATA[The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. <a href="http://bagofbeans.tsangal.org/archives/3574">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p class="syndicated-attribution"><em>(via <a href="http://secunia.com/vulnerability_scanning/personal">Delicious/tsangal</a>)</em></p>
The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks.]]></content:encoded>
			<wfw:commentRss>http://bagofbeans.tsangal.org/archives/3574/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Amazon EC2 Enables Cheap Brute-Force Attacks</title>
		<link>http://bagofbeans.tsangal.org/archives/3571</link>
		<comments>http://bagofbeans.tsangal.org/archives/3571#comments</comments>
		<pubDate>Thu, 13 Jan 2011 21:50:00 +0000</pubDate>
		<dc:creator>author-unknown</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[syndicated]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[snydeq writes &#34;German white-hat hacker Thomas Roth claims he can crack WPA-PSK-protected networks in six minutes using Amazon EC2 compute power — an attack that would cost him $1.68. The key? Amazon&#39;s new cluster GPU instances. &#39;GPUs are... <a href="http://bagofbeans.tsangal.org/archives/3571">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p class="syndicated-attribution"><em>(via <a href="http://rss.slashdot.org/~r/Slashdot/slashdot/~3/h7nACB8CH-Y/story01.htm">Slashdot</a>)</em></p>
snydeq writes &quot;German white-hat hacker Thomas Roth claims he can crack WPA-PSK-protected networks in six minutes using Amazon EC2 compute power — an attack that would cost him $1.68. The key? Amazon&#39;s new cluster GPU instances. &#39;GPUs are (depending on the algorithm and the implementation) some hundred times faster compared to standard quad-core CPUs when it comes to brute forcing SHA-1 and MD,&#39; Roth explained. GPU-assisted servers were previously available only in supercomputers and not to the public at large, according to Roth; that&#39;s changed with EC2. Among the questions Roth&#39;s research raises is, what role should Amazon and other public-cloud service providers play in preventing customers from using their services to commit crimes?&quot;<p><a href="http://www.facebook.com/sharer.php?u=http://it.slashdot.org/story/11/01/13/2024237/Amazon-EC2-Enables-Cheap-Brute-Force-Attacks?from=fb" title="Share on Facebook"><img src="http://a.fsdn.com/sd/facebook_icon_large.png"></a> <a href="http://twitter.com/home?status=Amazon+EC2+Enables+Cheap+Brute-Force+Attacks:+http://bit.ly/hTrZd7" title="Share on Twitter"><img src="http://a.fsdn.com/sd/twitter_icon_large.png"></a></p><p><a href="http://it.slashdot.org/story/11/01/13/2024237/Amazon-EC2-Enables-Cheap-Brute-Force-Attacks?from=rss">Read more of this story</a> at Slashdot.</p><iframe src="http://slashdot.org/slashdot-it.pl?op=discuss&amp;id=1949748&amp;smallembed=1" style="height:300px;width:100%;border:none"></iframe><img width="1" height="1" src="http://slashdot.feedsportal.com/c/32909/f/530758/s/119c00b7/mf.gif" border="0"><br><br><a href="http://da.feedsportal.com/r/91702655271/u/49/f/530758/c/32909/s/119c00b7/a2.htm"><img src="http://da.feedsportal.com/r/91702655271/u/49/f/530758/c/32909/s/119c00b7/a2.img" border="0"></a><p><iframe src="http://feedads.g.doubleclick.net/~ah/f/lrqi37l1p7a6hqgtg7dfla1i4g/300/250?ca=1&amp;fh=280#http://slashdot.feedsportal.com/c/32909/f/530758/s/119c00b7/l/0Lit0Bslashdot0Borg0Cstory0C110C0A10C130C20A242370CAmazon0EEC20EEnables0ECheap0EBrute0EForce0EAttacks0Dfrom0Frss/story01.htm" width="100%" height="280" frameborder="0" scrolling="no" marginwidth="0" marginheight="0"></iframe></p><img src="http://feeds.feedburner.com/~r/Slashdot/slashdot/~4/h7nACB8CH-Y" height="1" width="1">]]></content:encoded>
			<wfw:commentRss>http://bagofbeans.tsangal.org/archives/3571/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Car immobilizers cracked due to crappy proprietary crypto</title>
		<link>http://bagofbeans.tsangal.org/archives/3378</link>
		<comments>http://bagofbeans.tsangal.org/archives/3378#comments</comments>
		<pubDate>Sat, 18 Dec 2010 11:13:11 +0000</pubDate>
		<dc:creator>author-unknown</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[syndicated]]></category>
		<category><![CDATA[technology]]></category>
		<category><![CDATA[automotive]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[copyfight]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Karsten Nohl of Security Research Labs, a white-hat hacker, believes that a recent spike in car theft is due to a break in the car immobilizer security systems; thieves are able to re-mobilize the immobilized vehicles. My question is: how long until so... <a href="http://bagofbeans.tsangal.org/archives/3378">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p class="syndicated-attribution"><em>(via <a href="http://feedproxy.google.com/~r/boingboing/iBag/~3/BbiqNAbXmIY/car-immobilizers-cra.html">Boing Boing</a>)</em></p>
Karsten Nohl of Security Research Labs, a white-hat hacker, believes that a recent spike in car theft is due to a break in the car immobilizer security systems; thieves are able to re-mobilize the immobilized vehicles. My question is: how long until someone builds a TV-B-Gone for car engines that lets you stop cars with the click of a button?

<blockquote>
<img src="http://craphound.com/images/carimmobilizer.jpeg" align="right">
Juels says that these cracks were possible because the proprietary algorithms that the firms use to encode the cryptographic keys shared between the immobiliser and receiver, and receiver and engine do not match the security offered by openly published versions such as the Advanced Encryption Standard (AES) adopted by the US government to encrypt classified information. Furthermore, in both cases the encryption key was way too short, says Nohl. Most cars still use either a 40 or 48-bit key, but the 128-bit AES - which would take too long to crack for car thieves to bother trying - is now considered by security professionals to be a minimum standard. It is used by only a handful of car-makers...
<p>
What's more, one manufacturer was even found to use the vehicle ID number as the supposedly secret key for this internal network. The VIN, a unique serial number used to identify individual vehicles, is usually printed on the car. "It doesn't get any weaker than that," Nohl says.
</p></blockquote>

<a href="http://www.newscientist.com/article/mg20827894.500-criminals-find-the-key-to-car-immobilisers.html">Criminals find the key to car immobilisers </a>

(<i>via <a href="http://www.schneier.com/">Schneier</a></i>)
<p>
(<i>Image: <a href="http://www.flickr.com/photos/dittaeva/194631956/">Invalidka - Soviet car for disabled people</a>, a Creative Commons <a href="http://creativecommons.org/licenses/by/2.0/deed.en">Attribution (2.0)</a> image from dittaeva's photostream</i>)
<div>
<em> </em><ul><li><a href="http://boingboing.net/2010/09/14/adobe-issues-securit.html#previouspost">Adobe issues security advisory for Flash Player, plans fix &quot;during ...</a></li>
<li><a href="http://boingboing.net/2010/09/16/wash-dc-transit-auth.html#previouspost">Wash., DC transit authority uses proprietary RFID system, gets ...</a></li>
<li><a href="http://www.boingboing.net/2010/07/22/can-you-audit-the-so.html#previouspost">Can you audit the software that goes in your body? - Boing Boing</a></li>
<li><a href="http://www.boingboing.net/2010/11/11/if-other-industries.html#previouspost">If other industries were as evil as the record companies - Boing Boing</a></li>
</ul>
</div>
<br style="clear:both">
<br style="clear:both">
<a href="http://ads.pheedo.com/click.phdo?s=c45d7f3cbfcb9e09e14759d842e54310&amp;p=1"><img alt="" style="border:0" border="0" src="http://ads.pheedo.com/img.phdo?s=c45d7f3cbfcb9e09e14759d842e54310&amp;p=1"></a>
<img alt="" height="0" width="0" border="0" src="http://segment-pixel.invitemedia.com/pixel?code=TechCons&amp;partnerID=167&amp;key=segment"><img alt="" height="0" width="0" border="0" src="http://pixel.quantserve.com/pixel/p-8bUhLiluj0fAw.gif?labels=pub.28925.rss.TechCons.7604,cat.TechCons.rss"><img alt="" height="0" width="0" border="0" src="http://haku.vizu.com/a.gif?cid=1361;adid=300x250;siteid=pheedo;"><img src="http://feeds.feedburner.com/~r/boingboing/iBag/~4/BbiqNAbXmIY" height="1" width="1"></p>]]></content:encoded>
			<wfw:commentRss>http://bagofbeans.tsangal.org/archives/3378/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Tiny Watcher: keep your Windows clean</title>
		<link>http://bagofbeans.tsangal.org/archives/2998</link>
		<comments>http://bagofbeans.tsangal.org/archives/2998#comments</comments>
		<pubDate>Wed, 24 Nov 2010 00:28:32 +0000</pubDate>
		<dc:creator>Beanbag</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[syndicated]]></category>
		<category><![CDATA[bookmark]]></category>
		<category><![CDATA[freeware]]></category>
		<category><![CDATA[monitoring]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[System]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.delicious.com/url/82aef6061e37c77678724e7def5d42a1#tsangal</guid>
		<description><![CDATA[The way Tiny Watcher works is pretty simple: basically, it starts by taking a snapshot of important parts of your Windows system; then it tracks changes (every time you log in, or whenever you want to). When a change is detected, you are notified. <a href="http://bagofbeans.tsangal.org/archives/2998">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p class="syndicated-attribution"><em>(via <a href="http://kubicle.dcmembers.com/watcher/">Delicious/tsangal</a>)</em></p>
The way Tiny Watcher works is pretty simple: basically, it starts by taking a snapshot of important parts of your Windows system; then it tracks changes (every time you log in, or whenever you want to). When a change is detected, you are notified.]]></content:encoded>
			<wfw:commentRss>http://bagofbeans.tsangal.org/archives/2998/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spammers Using Soft Hyphen To Hide Malicious URLs</title>
		<link>http://bagofbeans.tsangal.org/archives/2383</link>
		<comments>http://bagofbeans.tsangal.org/archives/2383#comments</comments>
		<pubDate>Thu, 07 Oct 2010 21:32:00 +0000</pubDate>
		<dc:creator>author-unknown</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[syndicated]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Trailrunner7 writes with this excerpt from ThreatPost illustrating the ongoing Spy-vs.-Spy battle between spammers and the rest of us: "Spammers have jumped on the little-used soft hyphen (or SHY character) to fool URL filtering devices. According to r... <a href="http://bagofbeans.tsangal.org/archives/2383">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p class="syndicated-attribution"><em>(via <a href="http://rss.slashdot.org/~r/Slashdot/slashdot/~3/p2BhY3Qo20I/story01.htm">Slashdot</a>)</em></p>
Trailrunner7 writes with this excerpt from ThreatPost illustrating the ongoing Spy-vs.-Spy battle between spammers and the rest of us: "Spammers have jumped on the little-used soft hyphen (or SHY character) to fool URL filtering devices. According to researchers, spammers are larding up URLs for sites they promote with the soft hyphen character, which many browsers ignore. Spammers aren't shy about jumping humans flexible cognitive abilities to slip past the notice of spam filters (H3rb41 V14gr4, anyone?). ... The latest trend involves the use of an obscure character called the soft hyphen or 'SHY' character to obscure malicious URLs in spam messages. Writing on the Symantec Connect blog, researcher Samir Patil said that the company has seen recent spam messages that insert the HTML symbol for the soft hyphen to obfuscate URLs for Web pages promoted by the spammers."<p><a href="http://www.facebook.com/sharer.php?u=http://it.slashdot.org/story/10/10/07/2127241/Spammers-Using-Soft-Hyphen-To-Hide-Malicious-URLs?from=fb" title="Share on Facebook"><img src="http://a.fsdn.com/sd/facebook_icon_large.png"></a> <a href="http://twitter.com/home?status=Spammers+Using+Soft+Hyphen+To+Hide+Malicious+URLs:+http://bit.ly/d2Vw9B" title="Share on Twitter"><img src="http://a.fsdn.com/sd/twitter_icon_large.png"></a></p><p><a href="http://it.slashdot.org/story/10/10/07/2127241/Spammers-Using-Soft-Hyphen-To-Hide-Malicious-URLs?from=rss">Read more of this story</a> at Slashdot.</p><iframe src="http://slashdot.org/slashdot-it.pl?op=discuss&amp;id=1812746&amp;smallembed=1" style="height:300px;width:100%;border:none"></iframe><img width="1" height="1" src="http://slashdot.feedsportal.com/c/32909/f/530758/s/e833a5b/mf.gif" border="0"><br><br><a href="http://da.feedsportal.com/r/83962745356/u/49/f/530758/c/32909/s/e833a5b/a2.htm"><img src="http://da.feedsportal.com/r/83962745356/u/49/f/530758/c/32909/s/e833a5b/a2.img" border="0"></a><p><iframe src="http://feedads.g.doubleclick.net/~ah/f/lrqi37l1p7a6hqgtg7dfla1i4g/300/250?ca=1&amp;fh=280#http://slashdot.feedsportal.com/c/32909/f/530758/s/e833a5b/l/0Lit0Bslashdot0Borg0Cstory0C10A0C10A0C0A70C21272410CSpammers0EUsing0ESoft0EHyphen0ETo0EHide0EMalicious0EURLs0Dfrom0Frss/story01.htm" width="100%" height="280" frameborder="0" scrolling="no" marginwidth="0" marginheight="0"></iframe></p><img src="http://feeds.feedburner.com/~r/Slashdot/slashdot/~4/p2BhY3Qo20I" height="1" width="1">]]></content:encoded>
			<wfw:commentRss>http://bagofbeans.tsangal.org/archives/2383/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Searching For Backdoors From Rogue IT Staff</title>
		<link>http://bagofbeans.tsangal.org/archives/1868</link>
		<comments>http://bagofbeans.tsangal.org/archives/1868#comments</comments>
		<pubDate>Tue, 24 Aug 2010 21:43:00 +0000</pubDate>
		<dc:creator>author-unknown</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[syndicated]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[WHiTe VaMPiRe writes "When IT staff are terminated under duress, there is often justification for a complete infrastructure audit to reduce future risk to a company. Here is an exploration of the steps necessary to maintain security." Of course the fir... <a href="http://bagofbeans.tsangal.org/archives/1868">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p class="syndicated-attribution"><em>(via <a href="http://rss.slashdot.org/~r/Slashdot/slashdot/~3/sd73cWTgcOE/story01.htm">Slashdot</a>)</em></p>
WHiTe VaMPiRe writes "When IT staff are terminated under duress, there is often justification for a complete infrastructure audit to reduce future risk to a company. Here is an exploration of the steps necessary to maintain security." Of course the first piece of advice is to basically assume you've been rooted. Ouch.<p><a href="http://www.facebook.com/sharer.php?u=http://it.slashdot.org/story/10/08/24/2014256/Searching-For-Backdoors-From-Rogue-IT-Staff" title="Share on Facebook"><img src="http://a.fsdn.com/sd/facebook_icon_large.png"></a> <a href="http://twitter.com/home?status=Searching+For+Backdoors+From+Rogue+IT+Staff:+http://bit.ly/drlEMI" title="Share on Twitter"><img src="http://a.fsdn.com/sd/twitter_icon_large.png"></a></p><p><a href="http://it.slashdot.org/story/10/08/24/2014256/Searching-For-Backdoors-From-Rogue-IT-Staff?from=rss">Read more of this story</a> at Slashdot.</p><iframe src="http://slashdot.org/slashdot-it.pl?op=discuss&amp;id=1764944&amp;smallembed=1" style="height:300px;width:100%;border:none"></iframe><img width="1" height="1" src="http://slashdot.feedsportal.com/c/32909/f/530758/s/d152e7c/mf.gif" border="0"><p><iframe src="http://feedads.g.doubleclick.net/~ah/f/lrqi37l1p7a6hqgtg7dfla1i4g/468/60#http://slashdot.feedsportal.com/c/32909/f/530758/s/d152e7c/l/0Lit0Bslashdot0Borg0Cstory0C10A0C0A80C240C20A142560CSearching0EFor0EBackdoors0EFrom0ERogue0EIT0EStaff0Dfrom0Frss/story01.htm" width="100%" height="60" frameborder="0" scrolling="no" marginwidth="0" marginheight="0"></iframe></p><img src="http://feeds.feedburner.com/~r/Slashdot/slashdot/~4/sd73cWTgcOE" height="1" width="1">]]></content:encoded>
			<wfw:commentRss>http://bagofbeans.tsangal.org/archives/1868/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Your Password Should Be At Least 12 Random Characters Long to Be Safe [Security]</title>
		<link>http://bagofbeans.tsangal.org/archives/1860</link>
		<comments>http://bagofbeans.tsangal.org/archives/1860#comments</comments>
		<pubDate>Thu, 19 Aug 2010 19:15:00 +0000</pubDate>
		<dc:creator>author-unknown</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[syndicated]]></category>
		<category><![CDATA[in brief]]></category>
		<category><![CDATA[Passwords]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[
									
				According to a study at Georgia Tech Research Institute, your password should be at least 12 random characters long (and include letters, numbers, and symbols) if you want to consider yourself safe from brute force password hacks. From M... <a href="http://bagofbeans.tsangal.org/archives/1860">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p class="syndicated-attribution"><em>(via <a href="http://lifehacker.com/5617074/your-password-should-be-at-least-12-random-characters-long-to-be-safe">Lifehacker</a>)</em></p>
<div style="float:left;padding-right:10px">
									</div>
				According to a study at Georgia Tech Research Institute, your password should be at least 12 random characters long (and include letters, numbers, and symbols) if you want to consider yourself safe from brute force password hacks. From MSNBC: "'Eight-character passwords are inadequate now ... If eight characters is all you use, and if you restrict your characters to only alphabetic letters, it can be cracked in minutes,' said Richard Boyd, a senior researcher at GTRI." We've highlighted <a href="http://lifehacker.com/5505400/how-id-hack-your-weak-passwords">how easily common passwords can be hacked</a>, but even if you've got a system auto-generating your passwords, you may want to make sure you're going for at least 12. It may seem like a lot to remember (because it is), but that's where <a href="http://lifehacker.com/5483119/the-easy-any+browser-any+os-password-solution">a great password management solution</a> comes in handy. [<a href="http://www.msnbc.msn.com/id/38771772/ns/technology_and_science-security/?ocid=twitter">MSNBC</a> via <a href="http://twitter.com/wjrothman/statuses/21600738597">@wjrothman</a>]				<a href="http://lifehacker.com/5617074/your-password-should-be-at-least-12-random-characters-long-to-be-safe" title="Click here to read more about Your Password Should Be At Least 12 Random Characters Long to Be Safe [Security]">More »</a>
				<br style="clear:both"><div>
<a href="http://feeds.gawker.com/~ff/lifehacker/excerpts?a=ogv9ll7OBoU:HaccLZhaaAw:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/lifehacker/excerpts?d=yIl2AUoC8zA" border="0"></a> <a href="http://feeds.gawker.com/~ff/lifehacker/excerpts?a=ogv9ll7OBoU:HaccLZhaaAw:D7DqB2pKExk"><img src="http://feeds.feedburner.com/~ff/lifehacker/excerpts?i=ogv9ll7OBoU:HaccLZhaaAw:D7DqB2pKExk" border="0"></a> <a href="http://feeds.gawker.com/~ff/lifehacker/excerpts?a=ogv9ll7OBoU:HaccLZhaaAw:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/lifehacker/excerpts?i=ogv9ll7OBoU:HaccLZhaaAw:V_sGLiPBpWU" border="0"></a> <a href="http://feeds.gawker.com/~ff/lifehacker/excerpts?a=ogv9ll7OBoU:HaccLZhaaAw:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/lifehacker/excerpts?d=qj6IDK7rITs" border="0"></a>
</div>]]></content:encoded>
			<wfw:commentRss>http://bagofbeans.tsangal.org/archives/1860/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

