<?xml version="1.0"?>
<!-- RSS generated by Radio UserLand v8.0.7 on Sun, 22 Dec 2002 08:21:38 GMT -->
<rss version="2.0">
	<channel>
		<title>Al Macintyre: Security</title>
		<link>http://radio.weblogs.com/0107846/categories/security/</link>
		<description>Computer Security, Homeland Security, other kinds of Security that Al Macintyre has opinions on.</description>
		<language>en-us</language>
		<copyright>Copyright 2002 Al Macintyre</copyright>
		<lastBuildDate>Sun, 22 Dec 2002 08:21:38 GMT</lastBuildDate>
		<docs>http://backend.userland.com/rss</docs>
		<generator>Radio UserLand v8.0.7</generator>
		<managingEditor>macwheel99@sigecom.net</managingEditor>
		<webMaster>macwheel99@sigecom.net</webMaster>
		<category domain="http://www.weblogs.com/rssUpdates/changes.xml">rssUpdates</category> 
		<skipHours>
			<hour>7</hour>
			<hour>8</hour>
			<hour>5</hour>
			<hour>6</hour>
			<hour>4</hour>
			<hour>9</hour>
			<hour>19</hour>
			<hour>20</hour>
			</skipHours>
		<cloud domain="radio.xmlstoragesystem.com" port="80" path="/RPC2" registerProcedure="xmlStorageSystem.rssPleaseNotify" protocol="xml-rpc"/>
		<ttl>60</ttl>
		<item>
			<description>&lt;P&gt;From [&lt;A href=&quot;http://boingboing.net/&quot;&gt;Boing Boing Blog&lt;/A&gt;]&lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://boingboing.net/#90078481&quot;&gt;Copy of report referred to in NYT story re: Total Internet Monitoring plan&lt;/A&gt;. &lt;IMG align=left border=1 hspace=10 src=&quot;http://www.xeni.net/images/boingboing/securecyberspace.jpg&quot; vspace=10&gt; This link to a September, 2002 draft of &quot;The National Strategy to Secure Cyberspace&quot; appears to be an earlier copy of the report mentioned in &lt;A href=&quot;http://www.nytimes.com/2002/12/20/technology/20MONI.html&quot;&gt;today&apos;s NYT story&lt;/A&gt; about Bush administration plans for centralized monitoring of the Internet. &lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://www.whitehouse.gov/pcipb/cyberstrategy-draft.html&quot;&gt;Link&lt;/A&gt; &lt;A href=&quot;http://www.quicktopic.com/18/H/yLKjbWvRiWG&quot;&gt;Discuss&lt;/A&gt; (&lt;I&gt;Thanks, &lt;A href=&quot;http://www.memestreams.net/&quot;&gt;Tom&lt;/A&gt;!&lt;/I&gt;)&lt;BR clear=all&gt;From [&lt;A href=&quot;http://boingboing.net/&quot;&gt;Boing Boing Blog&lt;/A&gt;]&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/12/22.html#a496</guid>
			<pubDate>Sun, 22 Dec 2002 08:21:38 GMT</pubDate>
			<source url="http://boingboing.net/rss.xml">Boing Boing Blog</source>
			</item>
		<item>
			<description>I started post here today with my idea for &lt;A href=&quot;http://radio.weblogs.com/0107846/stories/2002/12/16/eBountyHunt.html&quot;&gt;e Bounty Hunting&lt;/A&gt; of spammers, virus creators, and other e-unwanteds.</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/12/16.html#a494</guid>
			<pubDate>Mon, 16 Dec 2002 08:09:43 GMT</pubDate>
			</item>
		<item>
			<description>&lt;P&gt;&lt;A href=&quot;http://c.moreover.com/click/here.pl?r54026039&quot;&gt;Court to rule on software that copies &apos;protected&apos; DVDs&lt;/A&gt;. New Scientist Dec 7 2002 7:05AM ET [&lt;A href=&quot;http://www.moreover.com&quot;&gt;Moreover - Science news&lt;/A&gt;]&lt;/P&gt;
&lt;P&gt;Interesting case here&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The really interesting arguement here is that the copy protection scheme has a humogous loophole or design flaw ... the backups of movies are made at a point in the process when the copy protection scheme is non-functional, so nothing in fact is being spoofed.&amp;nbsp; The courts will have to rule on whether or not it is legal to exploit the stupidity of your adversaries.&lt;/LI&gt;
&lt;LI&gt;I thought copyright law made it legal for us to backup software, but did not make it a right, so that software companies were free to offer stuff that is impossible to backup.&lt;/LI&gt;
&lt;LI&gt;I thought copyright law with respect to software backups allowed multiple backups, but basically ruled that only one copy could actually be running ON THE COMPUTER with ONLY ONE USER per software license.&lt;/LI&gt;
&lt;LI&gt;This article implies that I thought wrong about that, and that we are back to the interpretation that loading software from CD Rom or diskette or Internet download is a violation of copyright law because we are COPYING it from the purchase media into our computer.&lt;/LI&gt;
&lt;LI&gt;I thought copyright law was a bit different for different kinds of media ... software, printed literature, music&lt;/LI&gt;&lt;/UL&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/12/07.html#a489</guid>
			<pubDate>Sat, 07 Dec 2002 19:05:51 GMT</pubDate>
			<source url="http://p.moreover.com/cgi-local/page?c=Science%20news&amp;o=rss">Moreover - Science news</source>
			</item>
		<item>
			<description>&lt;P&gt;[&lt;A href=&quot;http://radio.weblogs.com/0110120/&quot;&gt;David Fletcher&apos;s Government and Technology&lt;/A&gt;] has many links of Security Interest: QUOTE&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The &lt;A href=&quot;http://www.cdt.org/&quot;&gt;Center for Democracy and Technology&lt;/A&gt; released statements regarding the &lt;A href=&quot;http://www.cdt.org/wiretap/021119homelandsecurity.shtml&quot;&gt;passage of the Homeland Security act&lt;/A&gt; and the &lt;A href=&quot;http://www.cdt.org/security/critinfra/021118nssc.shtml&quot;&gt;draft National Strategy for Securing Cyberspace&lt;/A&gt;. 
&lt;LI&gt;
&lt;P&gt;&lt;A href=&quot;http://www.fbi.gov/ucr/01cius.htm&quot;&gt;FBI&apos;s annual crime&lt;/A&gt; report.&lt;/P&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href=&quot;http://www.securityfocus.com/&quot;&gt;Security Focus&lt;/A&gt;&amp;nbsp;headline: &lt;SPAN class=maintitle&gt;&lt;EM&gt;&lt;A href=&quot;http://online.securityfocus.com/news/1666&quot;&gt;US gov&apos;s &apos;ultimate database&apos; run by a felon&lt;/A&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;LI&gt;
&lt;P&gt;ITAA and the US Attorney&apos;s Office, District of Utah sponsored a &lt;A href=&quot;http://www.itaa.org/events/event.cfm?EventID=554&quot;&gt;Regional Forum on Combating e-Crime and Cyberterrorism&lt;/A&gt;.&lt;BR&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/11/24.html#a481</guid>
			<pubDate>Sun, 24 Nov 2002 08:35:24 GMT</pubDate>
			</item>
		<item>
			<description>&lt;P&gt;[&lt;A href=&quot;http://radio.weblogs.com/0104634/&quot;&gt;Ernie the Attorney&lt;/A&gt;] QUOTE - I was at &lt;A href=&quot;http://www.ochsner.org/&quot;&gt;&lt;FONT color=blue&gt;Ochsner hospital&lt;/FONT&gt;&lt;/A&gt; today (&lt;EM&gt;my teenage daughter was having a benign tumor removed, and everything turned out okay&lt;/EM&gt;).&amp;nbsp; When she was in the pre-op area I noticed the laptop in the room that was on a rolling cart.&amp;nbsp; It was a Dell laptop with a Wi-Fi antenna and, though the power socket was plugged in, the cart was designed to move around from place to place (&lt;EM&gt;obviously after unplugging the power cord&lt;/EM&gt;).&lt;/P&gt;
&lt;P&gt;I asked&amp;nbsp;one of the&amp;nbsp;nurses about the wireless system.&amp;nbsp; She told me that the mobile laptops have been used in the surgery area for about two years, and were now&amp;nbsp;being&amp;nbsp;used throughout the hospital.&amp;nbsp; The wireless laptop has&amp;nbsp;access to the Internet, but the laptop is configured with special software that the hospital uses (and other hospitals use as well)&amp;nbsp;for immediate&amp;nbsp;entry of patient information directly into a central database.&amp;nbsp; This allows the hospital to have the patient&apos;s information updated on the computer system in real time.&lt;/P&gt;
&lt;P&gt;I asked her what she thought about the system.&amp;nbsp; She said that it had taken her awhile to get used to it.&amp;nbsp; The hospital apparently only sent about four &quot;power users&quot; to be trained and then they trained everyone else. But now that the system was running she said it was very good and only had a few problems.&amp;nbsp; She agreed that it was overall a good thing and would lead to better information about patients and less reliance on paper.&amp;nbsp; But she complained that she still had paper forms to fill out and, in fact, had even &lt;EM&gt;more&lt;/EM&gt; paper forms to fill out because of the new system.&amp;nbsp; She said it this was bourne out of an obsession for &quot;backup.&quot;&amp;nbsp; I don&apos;t think she really knows what the real reason is, but I wouldn&apos;t be surprised if she was right.&amp;nbsp; Hospital administrators live in dread fear of mishandling patient records, or at least&amp;nbsp;of being &lt;EM&gt;accused&lt;/EM&gt; of doing so.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;But I digress from the more important point: wireless in hospitals.&lt;/P&gt;
&lt;P&gt;I knew that Oschner had started to implement a wireless network because one of our firm&apos;s outside computer consultants used to work there and had told me about their initiative. I understand that it is a difficult proposition for a hospital to try something like this, and I&apos;m glad to see that Ochsner is giving it a try.&amp;nbsp; I don&apos;t know how they&apos;ve got their system set up, but I will say this: I booted up my laptop in the patient waiting area (which is admitedly far away from the surgery area, i.e.&amp;nbsp;+500 feet) and didn&apos;t pick up any signal.&amp;nbsp; Obviously, in terms of network security, that&apos;s a good thing.&lt;/P&gt;UNQUOTE [&lt;A href=&quot;http://radio.weblogs.com/0104634/&quot;&gt;Ernie the Attorney&lt;/A&gt;]</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/11/21.html#a467</guid>
			<pubDate>Fri, 22 Nov 2002 04:53:51 GMT</pubDate>
			<source url="http://radio.weblogs.com/0104634/rss.xml">Ernie the Attorney</source>
			</item>
		<item>
			<description>I started a story on &lt;A href=&quot;http://radio.weblogs.com/0107846/stories/2002/11/19/identityProtection.html&quot;&gt;Identity Protection&lt;/A&gt;, which collects various ideas on what to do to minimize our risk of someone stealing our credit, and what should be done after an incident, beyond the standard advice.</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/11/19.html#a459</guid>
			<pubDate>Tue, 19 Nov 2002 20:08:39 GMT</pubDate>
			</item>
		<item>
			<description>&lt;P&gt;&lt;A href=&quot;http://www.netcrimes.net&quot;&gt;www.netcrimes.net&lt;/A&gt; and Misdemeanors is the latest book I have taken a look at.&amp;nbsp; It is written great!&amp;nbsp; Each chapter is a mixture of stories of real problems for real people, showing us what it is to be a victim of out-of-control: &lt;STRONG&gt;&lt;FONT color=red&gt;cyber-stalking &lt;/FONT&gt;&lt;/STRONG&gt;(get help via &lt;A href=&quot;http://www.haltabuse.org&quot;&gt;www.haltabuse.org&lt;/A&gt; if you a victim of this); &lt;STRONG&gt;&lt;FONT color=red&gt;identity-theft &lt;/FONT&gt;&lt;/STRONG&gt;(more kinds than I knew about, which means I need to say more in &lt;A href=&quot;http://radio.weblogs.com/0107846/stories/2002/11/19/identityProtection.html&quot;&gt;Identity Protection&lt;/A&gt; than what was implied by &lt;A href=&quot;http://radio.weblogs.com/0107846/stories/2002/11/14/stopIdentityTheft.html&quot;&gt;Stop Identity Theft&lt;/A&gt;&amp;nbsp;because my &lt;A href=&quot;http://radio.weblogs.com/0107846/stories/2002/08/31/bankingStories.html&quot;&gt;Banking Stories&lt;/A&gt; may have distorted my vision as to where the greatest threats come from,&amp;nbsp;&lt;A href=&quot;http://www.cybersnitch.net&quot;&gt;www.cybersnitch.net&lt;/A&gt;&amp;nbsp;has advice how &lt;STRONG&gt;&lt;FONT color=red&gt;not &lt;/FONT&gt;&lt;/STRONG&gt;to become the next such statistic); hostile people out there posting stuff that pretends to be from you; spam; hoaxes; all sorts of frauds; &lt;STRONG&gt;&lt;FONT color=red&gt;what you ought to do about it&lt;/FONT&gt;&lt;/STRONG&gt;, with tons of useful links.&amp;nbsp; Some of these connections will be making their way onto my web site in future postings.&amp;nbsp; Some have already come here, although with a somewhat different spin than that of&amp;nbsp;&lt;A href=&quot;http://www.jahitchcock.com&quot;&gt;www.jahitchcock.com&lt;/A&gt;&amp;nbsp;J. A. Hitchcock.&amp;nbsp; Here are some wonderful starting points.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href=&quot;http://www.trf.k12.mn.us/lhs/shutthedoor.html&quot;&gt;www.trf.k12.mn.us/lhs/shutthedoor.html&lt;/A&gt; = safety brochure to help schools and law enforcement understand about anonymous e-harrassment and what can be done about it 
&lt;LI&gt;If you&amp;nbsp;&lt;FONT color=red size=4&gt;&lt;STRONG&gt;want &lt;/STRONG&gt;&lt;/FONT&gt;spam&amp;nbsp;or want more than you already getting, then sign up at &lt;A href=&quot;http://www.iwantspam.com&quot;&gt;www.iwantspam.com&lt;/A&gt; 
&lt;LI&gt;If you sent $ in the mail to some place to buy something that was communicated to you via the Internet, and you now think you have been cheated, prompt contact with postal inspectors can put a scammer in the slammer &lt;A href=&quot;http://www.usps.gov/websites/depart/inspect&quot;&gt;www.usps.gov/websites/depart/inspect&lt;/A&gt; 
&lt;LI&gt;Got questions about computers and the Internet? Check out &lt;A href=&quot;http://whatis.techtarget.com&quot;&gt;&lt;a href=&quot;http://whatis.techtarget.com&quot;&gt;http://whatis.techtarget.com&lt;/a&gt;&lt;/A&gt; and &lt;A href=&quot;http://www.askanexpert.com&quot;&gt;www.askanexpert.com&lt;/A&gt; 
&lt;LI&gt;Do you suspect that there are programs hiding on your computer that should not be there?&amp;nbsp; I not talking viruses &amp;amp; trojans but spyware.&amp;nbsp; Check out &lt;A href=&quot;http://www.cexx.org/problem.htm&quot;&gt;www.cexx.org/problem.htm&lt;/A&gt; and &lt;A href=&quot;http://www.lavasoftusa.com&quot;&gt;www.lavasoftusa.com&lt;/A&gt; 
&lt;LI&gt;Let&apos;s suppose someone might be impersonating you and behaving in a disreputable manner, you can keep track of yourself online by submitting your first &amp;amp; last name, or your e-mail address to &lt;A href=&quot;http://www.tracerlock.com&quot;&gt;www.tracerlock.com&lt;/A&gt; and they will e-mail you when it finds a match (I know I am in a LOT of places legitimately)&lt;/LI&gt;&lt;/UL&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/11/18.html#a451</guid>
			<pubDate>Mon, 18 Nov 2002 08:19:18 GMT</pubDate>
			</item>
		<item>
			<description>&lt;P&gt;&lt;FONT color=purple&gt;&lt;U&gt;&lt;STRONG&gt;[&lt;/STRONG&gt;&lt;/U&gt;&lt;A href=&quot;http://radio.weblogs.com/0104634/&quot;&gt;&lt;STRONG&gt;Ernie the Attorney&lt;/STRONG&gt;&lt;/A&gt;&lt;EM&gt;&lt;U&gt;]&amp;nbsp;&lt;/U&gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;FONT color=black&gt;&amp;nbsp;QUOTE &lt;/FONT&gt;&lt;FONT color=purple&gt;&lt;STRONG&gt;&lt;FONT color=red&gt;Oops!&amp;nbsp; Honey, I forgot to redact the document&lt;/FONT&gt;&lt;U&gt;!&lt;/U&gt;&lt;/STRONG&gt;&lt;/FONT&gt; - giving your opponent a document with sensitive information exposed is not a good idea.&amp;nbsp; That&apos;s why people use black markers.&amp;nbsp; But what about electronic documents?&amp;nbsp; Anyone ever hear of &quot;meta-data&quot;?&amp;nbsp; Please, people.&amp;nbsp; Let&apos;s be careful out there.&amp;nbsp; If you are an attorney and don&apos;t know what I&apos;m talking about (especially if you use Microsoft Word) &lt;A href=&quot;http://www.law.com/jsp/article.jsp?id=1036630382605&quot;&gt;&lt;FONT color=blue&gt;read this&lt;/FONT&gt;&lt;/A&gt;. UNQUOTE [&lt;A href=&quot;http://radio.weblogs.com/0104634/&quot;&gt;Ernie the Attorney&lt;/A&gt;]&lt;/P&gt;
&lt;P&gt;In earlier posts I have shared how Word documents can contain all sorts of stuff you not want to share, and how unscrupulous people can send you what seems like an innocent document, but it really contains software that acts like a virus to do Industrial Espionage.&amp;nbsp; That is a great link by Ernie to an article on &lt;A href=&quot;http://www.law.com&quot;&gt;www.law.com&lt;/A&gt; about electronic documents in general.&amp;nbsp; It is not just Microsoft stuff you have to manage.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/11/15.html#a442</guid>
			<pubDate>Fri, 15 Nov 2002 21:10:08 GMT</pubDate>
			<source url="http://radio.weblogs.com/0104634/rss.xml">Ernie the Attorney</source>
			</item>
		<item>
			<description>I have added &lt;A href=&quot;http://radio.weblogs.com/0107846/stories/2002/11/14/stopIdentityTheft.html&quot;&gt;Stop Identity Theft&lt;/A&gt; which has my proposed solution to a problem that causes grief to far too many people today.</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/11/14.html#a439</guid>
			<pubDate>Thu, 14 Nov 2002 18:45:57 GMT</pubDate>
			</item>
		<item>
			<description>&lt;P&gt;&lt;A href=&quot;http://www.eweek.com/article2/0,3959,693751,00.asp&quot;&gt;&lt;STRONG&gt;&lt;FONT size=5&gt;e Week&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/A&gt; has a big story on where the jobs are in the USA for computer people.&lt;/P&gt;
&lt;P&gt;There are a lot of us who are somewhat depressed about the economy, large layoffs all over the place, dot com melt down etc.&amp;nbsp; We can forget that while the economy may be bad overall, there are always places with growth and stability.&amp;nbsp; They move around the country as geography and technology evolves.&amp;nbsp; Some industries have not suffered in the current economy, such as biotechnology, health care, defense spending, which has led to growth in computer jobs some places.&amp;nbsp; e-Week analysed data from the federal Bureau of Labor Statistics and other sources, and concluded that the best areas of the country to relocate to, if you want to be where the computer jobs are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;FONT color=red size=4&gt;&lt;STRONG&gt;New York&apos;s Capital Region&lt;/STRONG&gt;&lt;/FONT&gt; 
&lt;UL&gt;
&lt;LI&gt;Thanks to IBM, Eastman Kodak, Bausch &amp;amp; Lomb, Corning, and other companies, this area was a tech center long before the dot com boom.&amp;nbsp; In 1999, NY ranked 4th in the nation for attracting venture capital, and 3rd for R&amp;amp;D spending.&amp;nbsp; This seven county region, consisting of Albany, Troy and other cities, continues to have a strong economy for growth in computer jobs.&amp;nbsp; One of the newest companies here is looking for experts in bioinformatics, such as analysis of DNA sequences for nanotechnology.&amp;nbsp; Check out &lt;A href=&quot;http://www.hightechNY.com&quot;&gt;www.hightechNY.com&lt;/A&gt; for current job openings.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;&lt;FONT color=red size=4&gt;&lt;STRONG&gt;Northern Virginia Beltway&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;Defense Contractors are booming with approx 5,000 IT jobs going unfilled.&amp;nbsp; Background checks for a good security clearance can take 18 months.&amp;nbsp; Biomedical also has great prospects.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;&lt;FONT color=red size=4&gt;&lt;STRONG&gt;Southern California&apos;s Inland Empire&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;East of Los Angeles created 29,700 new IT jobs in July and 26,000 in August, the highest rate in the nation, because it has become a major center for distribution, thanks to inexpensive land, a diverse industrial base, including industries that are today&apos;s drivers of tomorrow&apos;s economic growth.&lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;
&lt;P&gt;There&apos;s an article of tips for relocating, and one on the methodology they used to determine the three top areas.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/11/13.html#a438</guid>
			<pubDate>Thu, 14 Nov 2002 04:33:05 GMT</pubDate>
			</item>
		<item>
			<description>&lt;P&gt;[&lt;A href=&quot;http://boingboing.net/&quot;&gt;Boing Boing Blog&lt;/A&gt;] QUOTE&lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://boingboing.net/#85659616&quot;&gt;Open spectrum explained for the laity&lt;/A&gt;. Seattle Times has run a great story on the group of &quot;lawyers, engineers and telecommunications analysts&quot; who are lobbying the FCC for cognitive radio and open spectrum. &lt;/P&gt;
&lt;BLOCKQUOTE&gt;In an ideal world, the FCC would treat the airwaves like a highway system nobody owns and enforce rules governing how people use its lanes without crashing into each other, the group says. And in cases where this isn&apos;t possible, the FCC would allow people to drive across other people&apos;s &quot;property&quot; as long as they keep a low profile and don&apos;t do any damage. 
&lt;P&gt;Given this freedom, inventors and entrepreneurs would invent new vehicles and new ways of using the highway, the thinking goes. Consumers would finance the development of the airwaves by buying the devices that suit them best and abiding by the rules of the road that prevent nasty accidents. 
&lt;P&gt;But to make this vision a reality, the devices need a slice of the spectrum that would form a virtual park or an airwaves commons where equipment makers and others could experiment. In addition, common protocols &amp;#151; industry standards that allow devices to understand each others&apos; communications &amp;#151; and rules are needed to prevent accidents and to make sure everyone gets a fair shake. &lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;A href=&quot;http://seattletimes.nwsource.com/html/businesstechnology/134564261_btspectrum28.html&quot;&gt;Link&lt;/A&gt; &lt;A href=&quot;http://www.quicktopic.com/boing/H/qFzSAfXjKiEb&quot;&gt;Discuss&lt;/A&gt; (&lt;I&gt;Thanks, &lt;A href=&quot;http://www.smartmobs.com&quot;&gt;Howard&lt;/A&gt;!&lt;/I&gt;) [&lt;A href=&quot;http://boingboing.net/&quot;&gt;Boing Boing Blog&lt;/A&gt;]&lt;/P&gt;
&lt;P&gt;Let&apos;s hope the FBI crew that&apos;s checking up on War Chalkers, also reads this perspective.&amp;nbsp; I also think there may need to be some standards to avoid &lt;STRONG&gt;&lt;FONT color=red&gt;electronic smog&lt;/FONT&gt;&lt;/STRONG&gt;, where equipment is controlled by signals delivered by wireless, but the wireless can also pick up signals from unrelated activity that is sharing the same spectrum.&amp;nbsp; If the controller cannot tell the difference between the authorzed control signals and the unrelated traffic, then something can crash, which can be very dangerous if that something is robotoic, transportation, medical, public services, etc.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/11/11.html#a435</guid>
			<pubDate>Mon, 11 Nov 2002 18:00:46 GMT</pubDate>
			<source url="http://boingboing.net/rss.xml">Boing Boing Blog</source>
			</item>
		<item>
			<description>Risk Management tips in &lt;A href=&quot;http://www.sysmod.com/praxis/prax0210.htm&quot;&gt;Oct 2002 Praxis&lt;/A&gt; includes ways to hide your e-mail address from spammers, yet still make the obvious to real people (see in my &lt;A href=&quot;http://radio.weblogs.com/0107846/stories/2002/09/29/searchEngineTips.html&quot;&gt;Search Engine Tips&lt;/A&gt; the many ways to get at people&apos;s e-identity), also what viruses trojans worms etc. threats and Microsoft Vulnerabilities are going around and what you can do to protect yourself.</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/11/01.html#a421</guid>
			<pubDate>Fri, 01 Nov 2002 17:19:12 GMT</pubDate>
			</item>
		<item>
			<description>The Economist: &lt;A href=&quot;http://www.economist.com/printedition/displayStory.cfm?Story_ID=1389553&quot;&gt;The weakest link&lt;/A&gt;. Human failings, in other words, can undermine even the cleverest security measures. In one survey, carried out by PentaSafe Security, two-thirds of commuters at London&apos;s Victoria Station were happy to reveal their computer password in return for a ballpoint pen. [&lt;A href=&quot;http://www.tomalak.org/&quot;&gt;Tomalak&apos;s Realm&lt;/A&gt;]</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/10/29.html#a419</guid>
			<pubDate>Tue, 29 Oct 2002 18:50:12 GMT</pubDate>
			<source url="http://static.userland.com/tomalak/links2.xml">Tomalak&apos;s Realm</source>
			</item>
		<item>
			<description>&lt;P&gt;What I personally fear the most about &lt;FONT color=red size=4&gt;&lt;STRONG&gt;embedded chips &lt;/STRONG&gt;&lt;/FONT&gt;is that &lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;If having this chip makes it easier to find someone who has been kidnapped, then at the same time, having this chip makes it easy for would-be kidnappers to find their victims, chop out the chip from the body, and leave it with a ransom note, so that when the rescuers zoom in on the chip, they find what the kidnappers want them to find.&amp;nbsp; Also kidnappers can browse info about people in a crowd, to match up someone easy to seize with someone who is worth seizing, on the basis of what the embedded chip tells them, when they look up the code number.
&lt;LI&gt;Some institutions will begin to require that their employees or customers have this embedded chip as part of their security system. 
&lt;LI&gt;Potential crooks will think the embedded chip is the only thing they need for access to the facility. 
&lt;LI&gt;&lt;A href=&quot;http://www.vortex.com/privacy.html&quot;&gt;Humans will be assaulted for the purpose of chopping off whatever part of their anatomy is thought to contain the chip&lt;/A&gt;, so that the crook can then use a human arm with an embedded chip as the key to try to unlock access to whatever facility they want to break into. 
&lt;UL&gt;
&lt;LI&gt;At one college, it is your &lt;A href=&quot;http://www.wired.com/news/privacy/0,1848,53912,00.html&quot;&gt;thumb&lt;/A&gt; that the thieves will want to chop off.&amp;nbsp; &lt;A href=&quot;http://www.wired.com/news/privacy/0,1848,53912,00.html&quot;&gt;&lt;a href=&quot;http://www.wired.com/news/privacy/0,1848,53912,00.html&quot;&gt;http://www.wired.com/news/privacy/0,1848,53912,00.html&lt;/a&gt;&lt;/A&gt;&amp;nbsp;&lt;A href=&quot;http://www.vortex.com/privacy.html&quot;&gt;&lt;a href=&quot;http://www.vortex.com/privacy.html&quot;&gt;http://www.vortex.com/privacy.html&lt;/a&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;It is bad enough now that crooks want to steal my wallet, or break into my home and steal property from me, or steal my identity, but with this technology, future crooks will want to chop off part of my body.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;A href=&quot;http://www.wired.com/news/privacy/0,1848,55999,00.html&quot;&gt;Wired Articles&lt;/A&gt;&amp;nbsp;on &lt;A href=&quot;http://www.wired.com/news/privacy&quot;&gt;Privacy&lt;/A&gt;: &lt;BR&gt;&lt;A href=&quot;http://www.wired.com/news/privacy&quot;&gt;&lt;a href=&quot;http://www.wired.com/news/privacy&quot;&gt;http://www.wired.com/news/privacy&lt;/a&gt;&lt;/A&gt;&lt;/P&gt;
&lt;DIV&gt;&lt;A href=&quot;http://www.wired.com/news/privacy/0,1848,55999,00.html&quot; EUDORA=&quot;AUTOURL&quot;&gt;&lt;a href=&quot;http://www.wired.com/news/privacy/0,1848,55999,00.html&quot;&gt;http://www.wired.com/news/privacy/0,1848,55999,00.html&lt;/a&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;The initial version of the &lt;A href=&quot;http://www.adsx.com/prodservpart/verichip.html&quot;&gt;VeriChipID&lt;/A&gt; is the size of a grain of rice.&amp;nbsp; &lt;A href=&quot;http://www.adsx.com/prodservpart/verichip.html&quot;&gt;&lt;a href=&quot;http://www.adsx.com/prodservpart/verichip.html&quot;&gt;http://www.adsx.com/prodservpart/verichip.html&lt;/a&gt;&lt;/A&gt;&amp;nbsp;It needs to be activated by a scanner.&amp;nbsp; It gives a code number, that when looked up in&amp;nbsp;a data base, gives whatever info the wearer has decided will be in that data base.&amp;nbsp; However, much more advanced versions are in the pipeline, such as &lt;A href=&quot;http://www.digitalangel.net/&quot;&gt;Digital Angel&lt;/A&gt;, which combines Global Positioning (GPS) system and monitoring service, to help keep track of people with certain medical conditions, &lt;A href=&quot;http://www.wired.com/news/school/0,1383,54604,00.html&quot;&gt;school children&lt;/A&gt;, where &lt;A href=&quot;http://www.wired.com/news/privacy/0,1848,55740,00.html&quot;&gt;the legal system needs to keep track of them&lt;/A&gt;, and potential kidnap victims.&amp;nbsp; &lt;A href=&quot;http://www.wired.com/news/business/0,1367,53075,00.html&quot;&gt;Sex Offenders&lt;/A&gt; are branded for life in some states, but not yet with this chip.&amp;nbsp; Perhaps some Catholic Priests need to have the &lt;A href=&quot;http://www.tldm.org/News4/MarkoftheBeast.htm&quot;&gt;Mark of the Beast&lt;/A&gt;&amp;nbsp;added to their anatomy, so parents can scan child care providers before entrusting their children to their care.&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href=&quot;http://www.wired.com/news/business/0,1367,50004,00.html&quot;&gt;&lt;a href=&quot;http://www.wired.com/news/business/0,1367,50004,00.html&quot;&gt;http://www.wired.com/news/business/0,1367,50004,00.html&lt;/a&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href=&quot;http://www.wired.com/news/privacy/0,1848,55740,00.html&quot;&gt;&lt;a href=&quot;http://www.wired.com/news/privacy/0,1848,55740,00.html&quot;&gt;http://www.wired.com/news/privacy/0,1848,55740,00.html&lt;/a&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href=&quot;http://www.wired.com/news/school/0,1383,54604,00.html&quot;&gt;&lt;a href=&quot;http://www.wired.com/news/school/0,1383,54604,00.html&quot;&gt;http://www.wired.com/news/school/0,1383,54604,00.html&lt;/a&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href=&quot;http://www.wired.com/news/business/0,1367,53075,00.html&quot;&gt;&lt;a href=&quot;http://www.wired.com/news/business/0,1367,53075,00.html&quot;&gt;http://www.wired.com/news/business/0,1367,53075,00.html&lt;/a&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Remember &lt;A href=&quot;http://www.lojack.com/&quot;&gt;Lojack&lt;/A&gt;?&amp;nbsp; &lt;A href=&quot;http://www.lojack.com/&quot;&gt;&lt;a href=&quot;http://www.lojack.com/&quot;&gt;http://www.lojack.com/&lt;/a&gt;&lt;/A&gt;&amp;nbsp;This is a system used to help the police locate stolen vehicles, that have had &lt;A href=&quot;http://www.lojack.com/&quot;&gt;Lojack&lt;/A&gt; installed in advance.&amp;nbsp; Depending on how large &lt;A href=&quot;http://www.lojack.com/&quot;&gt;Lojack&lt;/A&gt; is, and how obvious it is to thieves who might want to remove it during the theft, before the theft is discovered, some people might want this installed on other products of value ... would it interfere with the operation of a computer for example?&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Well what we are talking about here is a similar concept embedded in human bodies.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;A similar chip has been embedded into &lt;A href=&quot;http://www.gcn.com/archives/sl/1997/November/desk.htm&quot;&gt;pets&lt;/A&gt; so animal shelters can identify the owners.&amp;nbsp; Three different companies market these devices.&amp;nbsp; There is some controversy over whether the technology works as advertised.&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href=&quot;http://www.gcn.com/archives/sl/1997/November/desk.htm&quot;&gt;&lt;a href=&quot;http://www.gcn.com/archives/sl/1997/November/desk.htm&quot;&gt;http://www.gcn.com/archives/sl/1997/November/desk.htm&lt;/a&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Several versions of this product, from several companies, are being marketed in Latin America with an GPS that keeps track of where the person is, who has the chip.&amp;nbsp; This can &lt;A href=&quot;http://www.wired.com/news/business/0,1367,50004,00.html&quot;&gt;help locate people who have been kidnapped&lt;/A&gt;, before the kidnappers remove the chip from their bodies, and it can also be used by kidnappers to help them find their kidnap victims.&amp;nbsp; Kidnapping is big business in South America, and the &lt;A href=&quot;http://travel.state.gov/colombia_warning.html&quot;&gt;US State Dept has a travel warning on Columbia due to this&lt;/A&gt;.&amp;nbsp; A &lt;A href=&quot;http://www.wired.com/news/technology/0,1282,50435,00.html&quot;&gt;politician in Brazil&lt;/A&gt; has volunteered to be chipped, to demonstrate how safe it is to the people.&amp;nbsp; The capital of Brazil is also the kidnapping capital of Brazil.&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href=&quot;http://www.wired.com/news/business/0,1367,52253,00.html&quot;&gt;&lt;a href=&quot;http://www.wired.com/news/business/0,1367,52253,00.html&quot;&gt;http://www.wired.com/news/business/0,1367,52253,00.html&lt;/a&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href=&quot;http://www.wired.com/news/business/0,1367,50004,00.html&quot;&gt;&lt;a href=&quot;http://www.wired.com/news/business/0,1367,50004,00.html&quot;&gt;http://www.wired.com/news/business/0,1367,50004,00.html&lt;/a&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href=&quot;http://travel.state.gov/colombia_warning.html&quot;&gt;&lt;a href=&quot;http://travel.state.gov/colombia_warning.html&quot;&gt;http://travel.state.gov/colombia_warning.html&lt;/a&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href=&quot;http://www.wired.com/news/technology/0,1282,50435,00.html&quot;&gt;&lt;a href=&quot;http://www.wired.com/news/technology/0,1282,50435,00.html&quot;&gt;http://www.wired.com/news/technology/0,1282,50435,00.html&lt;/a&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href=&quot;http://www.wherifywireless.com/corp_home.htm&quot;&gt;Wherify&lt;/A&gt; makes a bracelet that parents can lock onto children wrists, to allegedly track their physical movement, and their Internet travels, to allegedly keep the children safe, until a kidnapper removes the bracelet. &lt;A href=&quot;http://www.wherifywireless.com/corp_home.htm&quot;&gt;&lt;a href=&quot;http://www.wherifywireless.com/corp_home.htm&quot;&gt;http://www.wherifywireless.com/corp_home.htm&lt;/a&gt;&lt;/A&gt;&amp;nbsp; If the child strays, does not report in when supposed to, the parents can use the internet to identify the child GPS signal on the map.&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href=&quot;http://www.wired.com/news/school/0,1383,54604,00.html&quot;&gt;&lt;a href=&quot;http://www.wired.com/news/school/0,1383,54604,00.html&quot;&gt;http://www.wired.com/news/school/0,1383,54604,00.html&lt;/a&gt;&lt;/A&gt;&amp;nbsp; If the child encounters a situation he or she has been trained to deal with, like a stranger making certain claims, the child can punch a 911 button to send an alert to the police that is GPS linked.&amp;nbsp; The device can also send out a police alarm if someone tries to forceably remove it, so obviously the criminals have a bit of work cut out for them to jam the signal before they do the removal. &lt;A href=&quot;http://www.wired.com/news/business/0,1367,55731,00.html&quot;&gt;&lt;a href=&quot;http://www.wired.com/news/business/0,1367,55731,00.html&quot;&gt;http://www.wired.com/news/business/0,1367,55731,00.html&lt;/a&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;However, the technology exists such that the parents could have software continuously checking on where the child is in transit, to make a little map of all the places the children have been to, and the speed of transition (implying when in a vehicle in excess of speed limit).&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;There is a&amp;nbsp;big controversy over what&amp;nbsp;the &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt;&amp;nbsp;has to say on the subject, with representatives of &lt;A href=&quot;http://www.adsx.com/&quot;&gt;Applied Digital Solutions&lt;/A&gt; site/ad &lt;A href=&quot;http://www.adsx.com/&quot;&gt;&lt;a href=&quot;http://www.adsx.com/&quot;&gt;http://www.adsx.com/&lt;/a&gt;&lt;/A&gt;&amp;nbsp;mentioned in the article, claiming that different &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt;&amp;nbsp;have been telling them contradictory stories.&amp;nbsp; &lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;I have a hard time believing that the &lt;A href=&quot;http://www.adsx.com/&quot;&gt;Applied Digital Solutions&lt;/A&gt;&amp;nbsp;chip was accurately depicted to &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt;&amp;nbsp;personnel who told &lt;A href=&quot;http://www.adsx.com/&quot;&gt;Applied Digital Solutions&lt;/A&gt;&amp;nbsp;that this chip did not need&amp;nbsp;&lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt;&amp;nbsp;approval, if the company proceeded in a certain way in their advertising claims and statements to the media, because&amp;nbsp;&lt;A href=&quot;http://www.fda.gov/opacom/laws/fdcact/fdcact1.htm&quot;&gt;Section 201&lt;/A&gt; of the &lt;A href=&quot;http://www.fda.gov/opacom/laws/fdcact/fdctoc.htm&quot;&gt;Federal Food, Drug, and Cosmetic Act&lt;/A&gt;, implants and other devices that &quot;affect the structure or any function of the body of man or other animals&quot; require government approval.&amp;nbsp; &lt;A href=&quot;http://www.fda.gov/opacom/laws/fdcact/fdctoc.htm&quot;&gt;&lt;a href=&quot;http://www.fda.gov/opacom/laws/fdcact/fdctoc.htm&quot;&gt;http://www.fda.gov/opacom/laws/fdcact/fdctoc.htm&lt;/a&gt;&lt;/A&gt;&amp;nbsp;Any foreign object inside human body, for any length of time, has the potential to impact that human&apos;s well being, and thus must have FDA approval.&amp;nbsp; Many implants, that have no medical purpose, come under FDA regulation.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;However, it is clear from news reports that someone at the &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt;&amp;nbsp;did in fact &lt;A href=&quot;http://www.wired.com/news/politics/0,1283,55952,00.html&quot;&gt;approve&lt;/A&gt; the &lt;A href=&quot;http://www.adsx.com/&quot;&gt;Applied Digital Solutions&lt;/A&gt;&amp;nbsp;chip, but not 100%. &lt;A href=&quot;http://www.wired.com/news/politics/0,1283,55952,00.html&quot;&gt;&lt;a href=&quot;http://www.wired.com/news/politics/0,1283,55952,00.html&quot;&gt;http://www.wired.com/news/politics/0,1283,55952,00.html&lt;/a&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Perhaps we want to invest in &lt;A href=&quot;http://www.adsx.com/&quot;&gt;Applied Digital Solutions&lt;/A&gt;, as there are sure to be lots of people who will want to buy the product, without taking the risks seriously, but suppose there is law suit thanks to major abuse?&amp;nbsp; Be ready to sell the stock real fast.&amp;nbsp;&amp;nbsp;&lt;A href=&quot;http://www.adsx.com/&quot;&gt;Applied Digital Solutions&lt;/A&gt;&amp;nbsp;is also in the news because of conflicts with their auditors, which puts them at risk of being in violation of their restructured loan with IBM Global Credit.&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href=&quot;http://www.wired.com/news/ipo/0,1350,52499,00.html&quot;&gt;&lt;a href=&quot;http://www.wired.com/news/ipo/0,1350,52499,00.html&quot;&gt;http://www.wired.com/news/ipo/0,1350,52499,00.html&lt;/a&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt; = &lt;A href=&quot;http://www.fda.gov/&quot;&gt;&lt;a href=&quot;http://www.fda.gov/&quot;&gt;http://www.fda.gov/&lt;/a&gt;&lt;/A&gt;&amp;nbsp;= &lt;A href=&quot;http://www.fda.gov/&quot;&gt;Food and Drug Administration&lt;/A&gt;&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI&gt;Hearing Aids, Contact Lenses, Tattoos, surely are less intrusive on our bodies than embedded chips, but they are in fact covered by &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt; regulations.&amp;nbsp; Something does not compute here. 
&lt;LI&gt;Anything we eat is covered by &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt; regulations, with a large chunk of the food chain from agriculture also covered, and packaging of Halloween candy to give to kids 
&lt;LI&gt;Any medicine we take is covered by &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt; regulations 
&lt;LI&gt;Vitamin Pills and alternative medicine covered by &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt; regulations 
&lt;LI&gt;Medical tools in the home like thermometer or blood pressure measure or know if pregnant are covered by &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt; 
&lt;LI&gt;Chemicals placed on our bodies, like cosmetics, ointments, anti-mosquito repellant, sun tan, you name it, is covered by &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt; 
&lt;LI&gt;Products that emit radiation, are covered by &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt; regulations, such as Cell Phones, Lasers, Microwave Ovens, Personal Computers ... but somehow this embedded chip in our bodies which is connected by radio to GPS to track who we are and where we are, is to be exempted from &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA &lt;/A&gt;regulations.&amp;nbsp; I have a hard time believing this story. 
&lt;LI&gt;Safety of nation&apos;s blood supplies, from say West Nile or AIDS, is covered by &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt; 
&lt;LI&gt;On-line medicine and imported treatments covered by &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt; 
&lt;LI&gt;Bioterrorism information from &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA web site&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;DIV&gt;&lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt; Investigator&apos;s &lt;A href=&quot;http://www.wired.com/news/business/0,1367,55626,00.html&quot;&gt;Concern&lt;/A&gt; about potential health risks to humans from having this chip embedded in their bodies:&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href=&quot;http://www.wired.com/news/business/0,1367,55626,00.html&quot;&gt;&lt;a href=&quot;http://www.wired.com/news/business/0,1367,55626,00.html&quot;&gt;http://www.wired.com/news/business/0,1367,55626,00.html&lt;/a&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;The &lt;A href=&quot;http://www.techtv.com/news/culture/story/0,24195,3372523,00.html&quot;&gt;Jacobs family in Florida&lt;/A&gt; got a lot of publicity when they got chipped, &lt;/DIV&gt;
&lt;DIV&gt;&lt;A href=&quot;http://www.techtv.com/news/culture/story/0,24195,3372523,00.html&quot;&gt;&lt;a href=&quot;http://www.techtv.com/news/culture/story/0,24195,3372523,00.html&quot;&gt;http://www.techtv.com/news/culture/story/0,24195,3372523,00.html&lt;/a&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;then a week later &lt;A href=&quot;http://www.techtv.com/news/culture/story/0,24195,3384927,00.html&quot;&gt;the FDA announced that it was investigating the company&lt;/A&gt;, and as a result NASDAQ temporarily put trading of&amp;nbsp;&lt;A href=&quot;http://www.adsx.com/&quot;&gt;Applied Digital Solutions&lt;/A&gt; on hold.&amp;nbsp; &lt;/DIV&gt;
&lt;DIV&gt;&lt;A href=&quot;http://www.techtv.com/news/culture/story/0,24195,3384927,00.html&quot;&gt;&lt;a href=&quot;http://www.techtv.com/news/culture/story/0,24195,3384927,00.html&quot;&gt;http://www.techtv.com/news/culture/story/0,24195,3384927,00.html&lt;/a&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Apparently, during a press briefing of the implications of what had happened with the &lt;A href=&quot;http://www.techtv.com/news/culture/story/0,24195,3372523,00.html&quot;&gt;Jacobs family in Florida&lt;/A&gt;,&amp;nbsp;&lt;A href=&quot;http://www.adsx.com/&quot;&gt;Applied Digital Solutions&lt;/A&gt;&amp;nbsp;representatives spoke of the chip being linked to&amp;nbsp;&lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt;&amp;nbsp;compliant medical data base.&amp;nbsp; The &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt;&amp;nbsp;says it is illegal to use the &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt;&amp;nbsp;name in such a way that it sounds to be an endorsement of any product.&amp;nbsp; &lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Any company, that is marketing products that &lt;FONT color=red&gt;&lt;STRONG&gt;might &lt;/STRONG&gt;&lt;/FONT&gt;have government approval implications for some aspects of their products, ought to have its marketing department briefed by appropriate lawyers with respect to what you can say and what you ought not say.&amp;nbsp; It sure sounds like&amp;nbsp;&lt;A href=&quot;http://www.adsx.com/&quot;&gt;Applied Digital Solutions&lt;/A&gt; is not following that safety protocol, which so far has resulted in a whole series of foot in mouth incidents that will probably eventually cost the company millions of dollars in fines, lawsuits, and lost business.&amp;nbsp; I can only conclude that either &lt;A href=&quot;http://www.adsx.com/&quot;&gt;Applied Digital Solutions&lt;/A&gt; management is extremely inexperienced, or deliberately taking serious chances because they think the publicity and scandals will help them much more than any damage.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href=&quot;http://www.techtv.com/news/culture/story/0,24195,3384209,00.html&quot;&gt;Additional&lt;/A&gt; &lt;A href=&quot;http://www.techtv.com/news/culture/story/0,24195,3384016,00.html&quot;&gt;Links&lt;/A&gt; to &lt;A href=&quot;http://www.wired.com/news/privacy/0,1848,50187,00.html&quot;&gt;stories&lt;/A&gt; about the Jacobs family.&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href=&quot;http://www.techtv.com/news/culture/story/0,24195,3384209,00.html&quot;&gt;&lt;a href=&quot;http://www.techtv.com/news/culture/story/0,24195,3384209,00.html&quot;&gt;http://www.techtv.com/news/culture/story/0,24195,3384209,00.html&lt;/a&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href=&quot;http://www.techtv.com/news/culture/story/0,24195,3384016,00.html&quot;&gt;&lt;a href=&quot;http://www.techtv.com/news/culture/story/0,24195,3384016,00.html&quot;&gt;http://www.techtv.com/news/culture/story/0,24195,3384016,00.html&lt;/a&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href=&quot;http://www.wired.com/news/privacy/0,1848,50187,00.html&quot;&gt;&lt;a href=&quot;http://www.wired.com/news/privacy/0,1848,50187,00.html&quot;&gt;http://www.wired.com/news/privacy/0,1848,50187,00.html&lt;/a&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;I&amp;nbsp;have not been following this story in detail, so it is not clear to me what the precise sequence of events are.&amp;nbsp; The news media seems to be implying that of &lt;A href=&quot;http://www.adsx.com/&quot;&gt;Applied Digital Solutions&lt;/A&gt;&amp;nbsp;tried to put something over on the &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt;, and the &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt;&amp;nbsp;either fell for some of it, or we are already seeing abuses.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Remember &lt;A href=&quot;http://radio.weblogs.com/0107846/2002/09/27.html&quot;&gt;Lindows&lt;/A&gt;, where &lt;A href=&quot;http://radio.weblogs.com/0107846/categories/myFriends/2002/09/30.html#a332&quot;&gt;that company&lt;/A&gt; clicked &lt;FONT color=red&gt;&lt;STRONG&gt;I agree&lt;/STRONG&gt;&lt;/FONT&gt; that everyone has to click to get a product, then in their advertising claimed a relationship that the&amp;nbsp;&lt;FONT color=red&gt;&lt;STRONG&gt;I agree&lt;/STRONG&gt;&lt;/FONT&gt;&amp;nbsp;vendor felt was excessive and sued to have them stop saying that?&amp;nbsp; Well the &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt;&amp;nbsp;has a similar gripe, and they are not the only place with gripes.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Allegedly&amp;nbsp;&lt;A href=&quot;http://www.adsx.com/&quot;&gt;Applied Digital Solutions&lt;/A&gt;&amp;nbsp;asked the &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt; what they had to do to avoid needing &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt;&amp;nbsp;approval, then after &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt; told them, they both violated that understanding, and advertised that they had government approval to market the thing.&amp;nbsp; Here is another example of where &lt;A href=&quot;http://www.adsx.com/&quot;&gt;Applied Digital Solutions&lt;/A&gt;&amp;nbsp;actions have triggered a storm of media controversy ... was it deliberate or by mistake?&lt;/DIV&gt;
&lt;DIV&gt;It sounds to me that if the &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt; told them what they had to do to avoid needing &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt; approval for the device, and if they complied with those conditions, then they did in fact have government approval from the &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA,&lt;/A&gt; and the only problem would be with how they phrased it.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Allegedly&amp;nbsp;&lt;A href=&quot;http://www.adsx.com/&quot;&gt;Applied Digital Solutions&lt;/A&gt;&amp;nbsp;asked various hospitals if they would be willing to provide this chip as a service.&amp;nbsp; 12 hospitals said they interested in exploring what&apos;s involved.&amp;nbsp; Allegedly&amp;nbsp;&lt;A href=&quot;http://www.adsx.com/&quot;&gt;Applied Digital Solutions&lt;/A&gt;&amp;nbsp;then &lt;A href=&quot;http://www.techtv.com/news/culture/story/0,24195,3384209,00.html&quot;&gt;claimed &lt;/A&gt;the 12 hospitals were now offering the service.&amp;nbsp; &lt;A href=&quot;http://www.techtv.com/news/culture/story/0,24195,3384209,00.html&quot;&gt;&lt;a href=&quot;http://www.techtv.com/news/culture/story/0,24195,3384209,00.html&quot;&gt;http://www.techtv.com/news/culture/story/0,24195,3384209,00.html&lt;/a&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;This sounds to me to be very sloppy business practice, or outright attempt at fraud,&amp;nbsp;another example of where &lt;A href=&quot;http://www.adsx.com/&quot;&gt;Applied Digital Solutions&lt;/A&gt;&amp;nbsp;actions&amp;nbsp;triggered a storm of media controversy ... was it deliberate or by mistake?&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt; Spokesperson &lt;A href=&quot;http://www.newsday.com/ny-fdachip0406.story?coll=ny-homepage-more-breaking-news&quot;&gt;Claim&lt;/A&gt; that so long as no medical information is involved in this tracking of human beings, it is not subject to &lt;A href=&quot;http://www.fda.gov/&quot;&gt;FDA&lt;/A&gt; regulation.&amp;nbsp; It is Ok to have it connected to a medical data base, and it is Ok for people to use it to save them in medical emergencies, but so long as the device itself is not gathering medical information about the person it is embedded in, it is not subject to FDA approval.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href=&quot;http://www.newsday.com/ny-fdachip0406.story?coll=ny-homepage-more-breaking-news&quot;&gt;&lt;a href=&quot;http://www.newsday.com/ny-fdachip0406.story?coll=ny-homepage-more-breaking-news&quot;&gt;http://www.newsday.com/ny-fdachip0406.story?coll=ny-homepage-more-breaking-news&lt;/a&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;The Executive Director of the New York ACLU says that this has enormous potential for benefits at the same time as enormous potential for abuse.&amp;nbsp; I agree with both.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Potential benefit and abuse at the same time&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href=&quot;http://www.techtv.com/tlkbck/comment/0,24009,3372523-573942,00.html?netsection_id=2100118&quot;&gt;National Identity&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;Potential benefits&lt;/DIV&gt;
&lt;UL&gt;
&lt;LI&gt;Similar to medical alert bracelet ... you wheeled into hospital unconscious, and this thing tells medical professionals what you would have told them had you been conscious, about your medical allergies for example. 
&lt;LI&gt;Your child is kidnapped, and assuming the kidnappers don&apos;t have one of these scanners to locate and destroy the chip and injure your child in the process, the police use GPS to find your child. 
&lt;LI&gt;Alzheimer&apos;s patients who may get lost. 
&lt;LI&gt;Some felon is supposed to report to authorities regularly, out on bond, or &lt;A href=&quot;http://www.ptm.com/&quot;&gt;on parole&lt;/A&gt;, but of course this only works for criminals who lack the desire to cut up their own bodies to remove the thing. &lt;A href=&quot;http://www.ptm.com/&quot;&gt;&lt;a href=&quot;http://www.ptm.com/&quot;&gt;http://www.ptm.com/&lt;/a&gt;&lt;/A&gt; 
&lt;LI&gt;&lt;A href=&quot;http://www.techtv.com/siliconspin/features/story/0,23008,3375490,00.html&quot;&gt;Article&lt;/A&gt; listing benefits and claiming no risk to privacy.&amp;nbsp; I do not believe the latter claim.&amp;nbsp;&amp;nbsp; &lt;A href=&quot;http://www.techtv.com/siliconspin/features/story/0,23008,3375490,00.html&quot;&gt;&lt;a href=&quot;http://www.techtv.com/siliconspin/features/story/0,23008,3375490,00.html&quot;&gt;http://www.techtv.com/siliconspin/features/story/0,23008,3375490,00.html&lt;/a&gt;&lt;/A&gt;&amp;nbsp; The article claims that the data bases will be protected using the full state of art, but I know from past experience and education that the state of art is full of holes.&amp;nbsp; Plus, there are various risks I talk about elsewhere in this post.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;Potential abuses&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Many concerns stated above, such as the risk to having our arm chopped off if the chip is used for something really critical access, such as security key to get into a facility that terrorists or criminals desire to get into. 
&lt;LI&gt;You walking, minding your own business.&amp;nbsp; Someone scans you, gets your code #s, looks up the data base, and pretty soon there is in your face advertising, tailored to the contents of your data base. 
&lt;LI&gt;Suppose you win the lottery.&amp;nbsp; A kidnapper could use the chip to locate your child.&amp;nbsp; Start off by searching the internet for info about you, to determine what kids you have and what the code numbers are of any chips in them, then use portable scanners to look at kids in your neighborhood to see which one has the chip for the parent that just got wealthy. 
&lt;LI&gt;Go through airport security - it sets off some kind of alarm - special legislation needed to say that people with this are allowed to use the nation&apos;s airlines.&amp;nbsp; Ok now the homicide bombers seek to manufacture pieces of weapons that can masquerade as this stuff, then a terrorist team takes turns using the privacy of the airplane toilet to dig the pieces out of themselves to assemble their weapon.&amp;nbsp; The initial version is about the size of a grain of rice and needs to be activated by a scanner.&amp;nbsp; It does not have the GPS feature. 
&lt;LI&gt;&lt;A href=&quot;http://www.adsx.com/&quot;&gt;Applied Digital Solutions&lt;/A&gt;&amp;nbsp;CEO Richard Sullivan said, in &lt;A href=&quot;http://www.wired.com/news/privacy/0,1848,50187-2,00.html&quot;&gt;an interview&lt;/A&gt;, that this could be used to track foreigners in the USA.&amp;nbsp; 
&lt;UL&gt;
&lt;LI&gt;You show up as a tourist, student, business person, or whatever, and have to have this injected into your body, as a condition of being in the country, then you would be treated as a suspected criminal until you leave.&amp;nbsp; Those of us already here might have to show up to some government office to be injected.&amp;nbsp; This way only the real criminals who smuggle themselves into the country and do not voluntarily go to the government offices would not have them.&amp;nbsp; 
&lt;LI&gt;I also expect that some criminals would indulge in identity theft and have injected into themselves one of these gadgets with a forged code number that agrees with the person whose identity they are stealing.&amp;nbsp; I wonder how difficult it would be to change the code number so that on different days the criminal will be masquerading as different people. 
&lt;LI&gt;Although the company is now downplaying their CEO&apos;s remarks, there has allegedly been &lt;A href=&quot;http://www.tldm.org/News4/MarkoftheBeast.htm&quot;&gt;an effort in the UN&lt;/A&gt; to mandate this for keeping track of refugees and other stateless persons.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;&lt;A href=&quot;http://www.eff.org/&quot;&gt;Electronic Frontier Foundation&lt;/A&gt; Attorney speaks out about &lt;A href=&quot;http://www.techtv.com/siliconspin/features/story/0,23008,3375488,00.html&quot;&gt;Issues and Concerns&lt;/A&gt; with the VeriChip in &lt;A href=&quot;http://www.techtv.com/siliconspin/features/story/0,23008,3375488,00.html&quot;&gt;&lt;a href=&quot;http://www.techtv.com/siliconspin/features/story/0,23008,3375488,00.html&quot;&gt;http://www.techtv.com/siliconspin/features/story/0,23008,3375488,00.html&lt;/a&gt;&lt;/A&gt; 
&lt;LI&gt;Gary Wohlscheid,&amp;nbsp;President of &lt;A href=&quot;http://www.tldm.org/&quot;&gt;Last Days Ministries&lt;/A&gt;&amp;nbsp;&lt;A href=&quot;http://www.tldm.org/&quot;&gt;&lt;a href=&quot;http://www.tldm.org/&quot;&gt;http://www.tldm.org/&lt;/a&gt;&lt;/A&gt;, is comparing this chip to the Biblical &lt;A href=&quot;http://www.tldm.org/News4/MarkoftheBeast.htm&quot;&gt;Mark of the Beast&lt;/A&gt;. &lt;A href=&quot;http://www.tldm.org/News4/MarkoftheBeast.htm&quot;&gt;&lt;a href=&quot;http://www.tldm.org/News4/MarkoftheBeast.htm&quot;&gt;http://www.tldm.org/News4/MarkoftheBeast.htm&lt;/a&gt;&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;DIV&gt;Thanks to V. of TYR for bringing these links to Al attention. Discuss this at &lt;A href=&quot;http://www.techtv.com/news/culture/story/0,24195,3372523,00.html&quot;&gt;Tech TV&lt;/A&gt; also &lt;A href=&quot;http://www.techtv.com/news/culture/story/0,24195,3384927,00.html&quot;&gt;here&lt;/A&gt;&amp;nbsp;and &lt;A href=&quot;http://www.techtv.com/news/culture/story/0,24195,3384016,00.html&quot;&gt;here&lt;/A&gt; and &lt;A href=&quot;http://www.techtv.com/news/culture/story/0,24195,3384209,00.html&quot;&gt;here&lt;/A&gt;.&amp;nbsp; I may have lost track ... many of the Tech TV articles have at the very bottom, links to other articles that are related, then below that there is an area where people have been commenting on these stories.&amp;nbsp; Some of the &lt;A href=&quot;http://www.wired.com/news/business/0,1367,50004,00.html&quot;&gt;Wired&lt;/A&gt; &lt;A href=&quot;http://www.wired.com/news/technology/0,1282,50435,00.html&quot;&gt;articles&lt;/A&gt; also have &lt;A href=&quot;http://www.wired.com/news/privacy/0,1848,55740,00.html&quot;&gt;space&lt;/A&gt; at the bottom for commenting on them.&lt;/DIV&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/10/26.html#a413</guid>
			<pubDate>Sat, 26 Oct 2002 18:04:52 GMT</pubDate>
			</item>
		<item>
			<description>&lt;P&gt;Anyone stop to consider &lt;A href=&quot;http://www.guardian.co.uk/usguns/Story/0,2763,817370,00.html?=rss&quot;&gt;this guy&lt;/A&gt; might be a cop? [&lt;A href=&quot;http://live.curry.com/&quot;&gt;Adam Curry: Adam Curry&apos;s Weblog&lt;/A&gt;]&lt;/P&gt;
&lt;P&gt;Well now that he has been arrested we know he really is ex-military, All American deadbeat family abuser.&amp;nbsp; I thought he might be media.&amp;nbsp; The trick was not in getting to the attack site, but in being non-suspicious after an attack.&amp;nbsp; What profession can legitimately be in any community at any time, without anyone questioning them?&amp;nbsp; A news media person.&lt;/P&gt;
&lt;P&gt;Stick around, wait for the police to descend on the scene.&amp;nbsp; Show up and try to interview them.&lt;/P&gt;
&lt;P&gt;But now we know the sniper team was driving around in a personal attack vehicle disguised as an ordinary auto, so when stopped at a road block, the weapon hidden below the trap door.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/10/25.html#a412</guid>
			<pubDate>Fri, 25 Oct 2002 07:56:30 GMT</pubDate>
			<source url="http://cloud.datashed.net/users/adam@curry.com/curryCom.xml">Adam Curry: Adam Curry&apos;s Weblog</source>
			</item>
		<item>
			<description>&lt;P&gt;I have worked with various different kinds of computer security over the years, but I am no expert at it.&lt;/P&gt;
&lt;P&gt;Al Rule # 1 = You cannot padlock a tent or house of cards.&amp;nbsp; Security needs to be built into the foundation of the computer system, preferably via a rock solid operating system.&lt;/P&gt;
&lt;P&gt;Al Rule # 2 = Computer data can be accessed by a variety of tools, software hardware and tapping into the flow of data.&amp;nbsp; Just because the software you using cannot see the passwords or unencrypt the data flow does not mean that some other person software cannot do so.&lt;/P&gt;
&lt;P&gt;Al Rule # 3 = It is not unusual for purchased computer systems and software to come with back doors left there by developers.&amp;nbsp; You have to do business with reputable firms that do not condone such behavior.&lt;/P&gt;
&lt;P&gt;[&lt;A href=&quot;http://radio.weblogs.com/0111198/&quot;&gt;BlogFish&lt;/A&gt;] found insight in [&lt;A href=&quot;http://weblog.infoworld.com/udell/&quot;&gt;Jon&apos;s Radio&lt;/A&gt;]&lt;/P&gt;
&lt;P&gt;Use Private Keys, no - Use Public Keys, no - .... &lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://weblog.infoworld.com/udell/&quot;&gt;Jon Udell&lt;/A&gt; is &lt;A href=&quot;http://weblog.infoworld.com/udell/2002/10/13.html#a465&quot;&gt;opening a can of worms&lt;/A&gt;, I must not look... &lt;/P&gt;
&lt;P&gt;I always knew there were ways to encrypt information and I accepted that. Then I was assigned the task of revamping our software licensing process. This required me to choose an encryption method. Choosing an encryption method required me to justify my selection against its alternatives. Justifying my selection required me to understand both my selection and the alternatives that I did not choose. &lt;/P&gt;
&lt;P&gt;So I did some reading, and once I understood the difference between Private Key Encryption and Public Key Encryption, I changed my mind. Public Key Encryption surely seemed like the better choice. &lt;/P&gt;
&lt;P&gt;&lt;FONT color=red&gt;&lt;STRONG&gt;If some rogue ex-employee were to take the private key and issue passwords for a discounted price, we could throw out the old key pair and replace it with two new keys&lt;/STRONG&gt;&lt;/FONT&gt;. Because one of the keys of the pair is public, we could simply distribute it along with the encrypted information. No need to hard-code the private key in the software, right? No need to require customers to reinstall existing software, right? No need to maintain legacy password generation programs, right? (Anyone who has done this before, please comment...please throw me a clue...) &lt;/P&gt;
&lt;P&gt;Yes, I thought I finally had&amp;nbsp;gotten it. Public Key Encryption provides more&amp;nbsp;convenience, more security, more robustness&amp;nbsp;than&amp;nbsp;Private Key Encryption. &lt;/P&gt;
&lt;P&gt;I am trying to resist looking at Jon Udell&apos;s post. He is questioning his long-held assumption that Public Keys were the way to go.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;&lt;A href=&quot;http://weblog.infoworld.com/udell/2002/10/13.html#a465&quot;&gt;Remind me why I need a public key&lt;/A&gt;. Dick Hardt, founder and now CTO of &lt;A href=&quot;http://www.activestate.com/&quot;&gt;ActiveState&lt;/A&gt;, was prowling around the digital ID conference asking a deceptively simple question: &quot;Why do I need a key pair?&quot; &lt;B&gt;...&lt;/B&gt; &lt;/BLOCKQUOTE&gt;[&lt;A href=&quot;http://weblog.infoworld.com/udell/&quot;&gt;Jon&apos;s Radio&lt;/A&gt;]&lt;/BLOCKQUOTE&gt;[&lt;A href=&quot;http://radio.weblogs.com/0111198/&quot;&gt;BlogFish&lt;/A&gt;]</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/10/15.html#a401</guid>
			<pubDate>Tue, 15 Oct 2002 09:37:48 GMT</pubDate>
			<source url="http://radio.weblogs.com/0111198/rss.xml">BlogFish</source>
			</item>
		<item>
			<description>&lt;P&gt;&lt;FONT color=red size=4&gt;&lt;STRONG&gt;Avoiding the Sniper&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://radio.weblogs.com/0107233/&quot;&gt;Dog News&lt;/A&gt; lives in the target zone so I been sending her various thoughts.&amp;nbsp; Here below are some of what I think were my brighter ideas.&amp;nbsp; Some of my ideas may be a bit dumb, but I hope on balance I have shared ideas that Y&quot;all will find worthwhile thinking about.&amp;nbsp; I have updated this mini-essay several times, most recently&amp;nbsp; mid-day Thursday Oct 17.&amp;nbsp; If you want to print it out, figure&amp;nbsp;5 pages.&lt;/P&gt;
&lt;P&gt;She told me about a friend seeing a vehicle that looked exactly what the police were watching the public to be on the look out for, but all the police phone lines were busy, so I suggested calling that into the news media.&amp;nbsp; Have them tail the suspect vehicles until the police clear them.&amp;nbsp; The friend was not able to leave her job, at the time of the witnessing.&amp;nbsp; Another thought is to have standard forms, downloadable from police web site, for witnesses to fill out when something fresh in their mind but access to the police not practical.&amp;nbsp; At the time of the anthrax scare, and at times of bomb threats, we have had similar forms from the police that spell out what should be done when an incident occurs.&lt;/P&gt;
&lt;P&gt;Put in perspective that while the sniper has killed 11 people in 11 days, in the same time period there have been 14 unrelated homicides in 5 of the 6 communities where the sniper has been active, while even more people die in traffic accidents (68 a year in DC, 660 in Maryland, 935 in Virginia).&amp;nbsp; This is not really as bad as people in other countries have to put up with all the time.&amp;nbsp; Get a pen pal in another country to understand what it is like for them and see that we might be over-reacting to this latest crime spree.&lt;/P&gt;
&lt;P&gt;Is this a good time of year to visit Disneyland?&amp;nbsp; Get away from the daily worries and have a good time somewhere else?&amp;nbsp; Your auto club can probably print out maps of driving routes that take you to interesting places that are not on the sniper past visitations or even close.&lt;/P&gt;
&lt;P&gt;If you want to get away for a while, consider that while you have a good job, there are hundreds of thousands of people around the country who are out of work.&amp;nbsp; Perhaps you can organize a trade.&amp;nbsp; You get away and live in someone else community for a while, and someone else take over your job and income until you ready to come home.&amp;nbsp; In academia this is called taking a sabattical.&amp;nbsp; Some Professor and family trade homes and jobs with some other Professor and family&amp;nbsp;in some other city.&amp;nbsp; The University has teacher all the time.&amp;nbsp; Professor and family have nice place to live.&amp;nbsp; Basically they trust each other, something like exchange students.&lt;/P&gt;
&lt;P&gt;Say, how about exchange students your kids go live in some other city until DC is safer place again?&amp;nbsp; Travel broadens the mind, so it is educational also.&lt;/P&gt;
&lt;P&gt;The sniper is not neccessarily someone with police or military training, because so far all the victims have been people who were easy targets for someone who is a good shot, and desires to continue killing random victims.&amp;nbsp; Ask someone who does have relevant training to suggest to you how to avoid being an easy target.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;I think that right now, many people in the communities, that the sniper is preying on, could use a police briefing, not on the kind of stuff that the media is demanding, regarding progress or lack of progress finding this serial killer, because past criminals of this nature have gone on killing sprees that have lasted months or years before they got caught.&amp;nbsp; Rather, what I think the people need is community policing meetings briefing the people on how to minimize risk of becoming a next target, and which of these various ideas are most constructive.&lt;/P&gt;
&lt;P&gt;I have in the past suggested that Homeland Security Professionals could benefit from a seminar series put on by professionals from other walks of life - health and computer auditors for example.&amp;nbsp; For other posts by me on security topics see my &lt;A href=&quot;http://radio.weblogs.com/0107846/Categories/security/&quot;&gt;security category&lt;/A&gt;, or ask for copies of one of my Word documents on security issues.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Your pooch pals need to be able to run outside while you remain indoors.&amp;nbsp; I can send you attached to e-mail, some of my joke collections that will have you ROFL so much that you won&apos;t care about the real world until this is over. 
&lt;UL&gt;
&lt;LI&gt;If you not have much in the way of a back yard for the dog, where you could have a long cable with the leash to it so dog can run back and forth, find a wooded area where you can walk out of sight of the highways.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;When you have to be outside, in the role of a pedestrian, do not remain stationary.&amp;nbsp; Walk briskly, not in a straight line, but zig zag.&amp;nbsp; Wear dark clothing, stay in dark shadowed areas, so that you are not an easy target. 
&lt;UL&gt;
&lt;LI&gt;This is directly opposite to the kind of advice I would ordinarily give a bicyclist.&amp;nbsp; Living in Evansville Indiana, where the crime rate is almost zero, so that we have the privilege of laws like it being illegal to play radio so loud in auto that it is annoying to adjacent cars in traffic, a lot of young people seem to be extremely careless about personal safety.&amp;nbsp; I find pre-schoolers in middle of side streets with no look outs for traffic, wearing dark clothing at night.&amp;nbsp; I see college age kids on bicycles, with no lights, just tiny reflectors, no safety helmet, dark clothing, on limited access highways at night, where the speed of the motorists like 50 mph.&amp;nbsp; These kids are accidents looking for an auto to hit them. 
&lt;LI&gt;But when a sniper is around, a person needs to emulate these kids.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;Perhaps people going about their business in groups, so you guarantee that if a member of the group gets struck, survivors will have some clues to share.&amp;nbsp; Think group of friends, neighbors, co-workers traveling together like a military expedition, with multiple lookouts in all directions, so if you fired upon, there&apos;s someone else looking in every direction.&amp;nbsp;&amp;nbsp;Have the group carry a camera to capture clues to share with the police. 
&lt;LI&gt;So far the sniper has shot at people outdoors, loading car in parking lot of strip mall retail outlets, waiting at a bus stop, mowing yard, at a gas station.&amp;nbsp; So, you need to patronize establishments that have parking garages attached to where ever it is you want to go.&amp;nbsp; Doesn&apos;t downtown have an underground garage?&amp;nbsp; Don&apos;t some shopping centers have attached parking garages, where you can walk between car and shopping, and be hidden from sniper view at all times?&amp;nbsp; Is there a safe subway system where you can go from indoors to indoors? 
&lt;UL&gt;
&lt;LI&gt;The 10th incident, Monday nite, sounded like it was in the bottom level of an open air split level parking structure, not a real enclosed garage.&amp;nbsp; When I say to park in a garage, I mean one that when you get out of your car, you are not visible outside the garage to some sniper.&amp;nbsp; For the sniper to get you, also have to be inside the garage. 
&lt;LI&gt;In answer to one of my questions, dog news has informed me that several shoppers, inside the split level partially covered parking garage, witnessed a man standing behind his Astro Van, quickly taking the shot, and then getting into the van and leaving.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;The 4 gas stations were MOBILE SHELL SUNOCO EXXON&lt;BR&gt;You want to patronize one of those brand names on the assumption the next gas station will be a 5th brand name. 
&lt;LI&gt;MICHAELS CRAFT STORE was location of FOUR of the shootings, either right there, or in a shopping area that had one.&lt;BR&gt;Look up in Yellow pages where they all located.&lt;BR&gt;Mark on a map.&lt;BR&gt;Do not go anywhere close to any other such store. 
&lt;UL&gt;
&lt;LI&gt;After the sniper is apprehended, use that map to assist in deliberately shopping near Michaels Craft Stores so as to undermine whatever economic purpose was why the sniper was frequenting those areas. 
&lt;LI&gt;You can hope that the police have all the Michaels Craft Store shopping areas staked out, and are running simulations what to do if this one is the next place the sniper raids.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;If you have a vehicle anything close to the description the police looking for, ask them to move it to police impound lot or other place of their choosing, so as to get similar vehicles off the streets and make it easier to find the one and only one left.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;STRONG&gt;Suppose you are a retail commercial store&amp;nbsp;and you want to protect shoppers visiting your establishment&lt;/STRONG&gt;.&amp;nbsp; Did you see the police putting a sheet like on a clothes line to protect the crime scene and victim?&amp;nbsp; A shopping center could put something like that up to protect their parking lot patrons from visibility from the highways.&amp;nbsp; Not a permanent structure, but temporary curtains on a split level parking lot.&amp;nbsp; Put stuff in windows of stores like you batten down the hatches to protect against a storm or a riot, so the customers can be inside, not seen through the windows, and thus safe from sniper, while inside.&lt;/P&gt;
&lt;P&gt;Shoppers need to be able to have their cars loaded in an enclosed area as they leave the store.&amp;nbsp; It could be like a tent up against the building.&amp;nbsp; Car drives into the tent, gets loaded, drives out.&amp;nbsp; Someone to move the cars who should be wearing bullet proof vest and heavy plastic helmet like riot police, so that they can see where they going, but their head protected from bullet.&lt;/P&gt;
&lt;P&gt;Customers arrive.&amp;nbsp; Stop in tent covered area, give car keys to person in the plastic helmet, at which point there is a receipt that identifies car description and who drove it here, helmeted person moves it to parking area, turns in copy of receipt and the keys to person near cashier desk, with identification of parking space added.&amp;nbsp; Customers ready to leave.&amp;nbsp; Identify selves.&amp;nbsp; One of the helmeted workers gets corresponding car keys, with paper saying which parking space that car located, goes to get it, drives it into tent covered area.&amp;nbsp; It gets loaded.&amp;nbsp; Customer leaves.&lt;/P&gt;
&lt;P&gt;Customer is never exposed to sniper, except through windows of car, in the scenario that I have described.&amp;nbsp; The only people exposed to sniper are helmeted people who are wearing bullet proof clothing.&amp;nbsp; The cost for this would be minimal.&amp;nbsp; What do curtains, or tent cost, or block up the windows of a store?&amp;nbsp; The cost is the labor for the people wearing the bullet proof clothing.&amp;nbsp; Hey, the economy could use some more people with jobs.&amp;nbsp; Would shoppers be willing to make a donation to a fund for this kind of protection, so they have places they can go with this added peace of mind?&lt;/P&gt;
&lt;P&gt;Do you have a drive in garage at your home that is large enough to accomodate a visiting vehicle?&amp;nbsp; If so, use the Internet to order groceries, alternatives to Pizza, other stuff.&amp;nbsp; Each neighborhood could have a weblog category that announces new businesses that have setup e-business services for their community, then webloggers can subscribe to that announcement category, and use it to link to the new announcements.&amp;nbsp; (See Al&apos;s &lt;A href=&quot;http://radio.weblogs.com/0107846/stories/2002/08/17/understandRadioNewsAggregation.html&quot;&gt;Understand Radio News Aggregation &lt;/A&gt;if you unfamiliar with this concept.)&amp;nbsp; Sign up as a customer, specify wants, give directions to get to your home - store phones you before making a delivery to make sure someone ready to accept delivery and make payment.&amp;nbsp; Then when this is all over, e-business has had a boost in your area.&amp;nbsp;&amp;nbsp; If sniper not caught any time soon, you have now setup infrastructure that can be used for Christmas shopping.&lt;/P&gt;
&lt;P&gt;Business district organizations need to study how to get people from enclosed parking areas to retail establishments, without becoming exposed to the sniper.&lt;/P&gt;
&lt;P&gt;Transit systems like buses and taxis need to review where their people wait for them, and find ways for the people to be enclosed, while at same time the drivers able to see when someone is waiting for them.&lt;/P&gt;
&lt;P&gt;Do we need an Amber for Cops? ... someone calls in some alert, and a signal is sent to all police, irrespective of which agency, informing them of where some event occurred, then they react according to their stations relative to that location and type of event.&lt;/P&gt;
&lt;P&gt;Employers need to think about this also.&amp;nbsp; Do your employees drive to work and have their cars in a parking lot visible from the street?&amp;nbsp; Do your people arrive and leave at predictable times?&amp;nbsp; What can you do to make your employees less at risk?&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT size=4&gt;Has Halloween been canceled?&amp;nbsp; &lt;/FONT&gt;&lt;/STRONG&gt;What does this do for the kids fun, and the economy of the stores that cater to their business?&lt;/P&gt;
&lt;P&gt;Think gift certificates, substitute events,&amp;nbsp;e-halloween, and contests in safe areas with top prize being like trip to Disneyland (something kids want, and also get you out of town for a great trip).&lt;/P&gt;
&lt;P&gt;Ask Amtrak for a special evening or weekend trip.&amp;nbsp; Kids from the neighborhood are driven to an enclosed railway station and board a train that will go on a special trip out of town, perhaps with a different return route.&amp;nbsp; Many of the cars will be like neighborhood block parties for groups of people who cannot do outdoor stuff while this scare is going on.&amp;nbsp; Kids visit with the various neighborhoods on the Amtrak trip.&amp;nbsp; Can older kids be connected to the Internet from this?&lt;/P&gt;
&lt;P&gt;Stores with web sites combine visitor # onto their web site with a program to print e-gift certificates that can be cashed in after the sniper is caught, in one of several special kids party weekends.&lt;/P&gt;
&lt;P&gt;Have some quality time parents and children at home on grand tour of kids friendly web sites.&amp;nbsp; Familes vote which is best in several categories (different, wild, fun, educational) and send them (the kids friendly website organizers) e-gift certificates from the local stores, that can be cashed in at national chains that have outlets in your community.&lt;/P&gt;
&lt;P&gt;Result - local commercial economy does not get hurt, parents and kids have quality time, internet innovation is stimulated.&lt;/P&gt;
&lt;P&gt;Assuming there is a shopping mall where people can drive into an enclosed garage, and there is some security like I been talking about, a shopping mall could have a Halloween weekend, in which extra security is put on for the weekend.&amp;nbsp; Down the middle of the mall have little shoppes selling halloween related stuff, and each of the main stores provide gift certificate discount coupons, in which the kids have something to cash in when the sniper is no longer an impediment to going shopping.&amp;nbsp; Stores know what to do - buy one get one free coupons.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Have a treasure hunt in the mall ... each store may contribute a clue that is related to the stuff they sell.&amp;nbsp; The first 25 kids per hour to come in with the right answer receive a gift certificate discount coupon or something even better.&lt;/P&gt;
&lt;P&gt;Are you annoyed by the Gun control people trying to take advantage of the big scare?&amp;nbsp; The pro-2nd amendment crowd can fight back with a Neighborhood NRA watch ... people who have gun permits, and have had appropriate weapons training, could escort their neighbors on errands, prepared to shoot back at the sniper.&amp;nbsp; Have a web site where people can sign up to have the Neighborhood NRA watch provide them with an armed escort.&amp;nbsp; The police would be asked to swear in these people as temporary deputies with special badges showing that they have been checked out and are trusted to be traveling the city with weapons ready to fight the sniper.&lt;/P&gt;
&lt;P&gt;[&lt;A href=&quot;http://www.dws.us/weblog/&quot;&gt;dws.&lt;/A&gt;] Asks QUOTE &lt;A href=&quot;http://www.google.com/search?as_q=beltway+sniper&amp;amp;num=30&amp;amp;hl=en&amp;amp;ie=ISO-8859-1&amp;amp;btnG=Google+Search&amp;amp;as_epq=&amp;amp;as_oq=&amp;amp;as_eq=&amp;amp;lr=&amp;amp;as_ft=i&amp;amp;as_filetype=&amp;amp;as_qdr=all&amp;amp;as_occt=any&amp;amp;as_dt=i&amp;amp;as_sitesearch=&amp;amp;safe=images&quot;&gt;To: Anyone who publishes material related to the sniper in DC&lt;/A&gt;, Please do not give the idiot (sniper) in Washington a title that feeds his/her ego. &quot;The Beltway Sniper&quot; is too glamorous. Refer to him/her with a title that is more fitting, and less likely to be bragged about in prison, such as &quot;The Murdering Coward&quot;. UNQUOTE [&lt;A href=&quot;http://www.dws.us/weblog/&quot;&gt;dws.&lt;/A&gt;]&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/10/14.html#a400</guid>
			<pubDate>Mon, 14 Oct 2002 08:50:57 GMT</pubDate>
			</item>
		<item>
			<description>&lt;P&gt;What we have here are some links inspired by me visiting places that are&amp;nbsp;visited by people who also visit my site, showing some interests that we have in common.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href=&quot;http://www.religioustolerance.org/chr_cul.htm&quot;&gt;Christian stories&lt;/A&gt; that never happened. 
&lt;UL&gt;
&lt;LI&gt;I&apos;d like to see something similar on other Religions, because those of us who are not believers can sometimes have a hard time distinguishing truth vs. distortion.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;&lt;A href=&quot;http://www.vmyths.com/&quot;&gt;Computer Virus Myths&lt;/A&gt; - how to spot them. 
&lt;UL&gt;
&lt;LI&gt;Warning - that site disables the back button.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;&lt;A href=&quot;http://www.darwinawards.com/legends/&quot;&gt;Darwin Awards&lt;/A&gt; for people who have found incredible ways to remove themselves from the gene pool.&amp;nbsp; These are true stories, that someone could easily think were made up. 
&lt;LI&gt;&lt;A href=&quot;http://urbanlegends.miningco.com/&quot;&gt;Discuss Urban Legends&lt;/A&gt;.
&lt;LI&gt;&lt;A href=&quot;http://www.wdog.com/legends/&quot;&gt;Electronic tour of artistic renditions of Urban Legends&lt;/A&gt;. 
&lt;UL&gt;
&lt;LI&gt;I was not impressed with what I sampled, but different strokes for different folks.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;&lt;A href=&quot;http://hoaxbusters.ciac.org/&quot;&gt;Hoax Identification Education&lt;/A&gt;
&lt;LI&gt;&lt;A href=&quot;http://www.hoaxkill.com/&quot;&gt;Hoax Kill Service&lt;/A&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;Once you find out if a message is a hoax you can send it to a designated email address and their software will then extract the addresses of all previous recipients from the message and inform them all that the message is a hoax.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;&lt;A href=&quot;http://www.tourbus.com/warning.txt&quot;&gt;Humor about Hoaxes&lt;/A&gt;.
&lt;LI&gt;Latest &lt;A href=&quot;http://www.urbanlegends.com/&quot;&gt;Urban Legends&lt;/A&gt;. 
&lt;LI&gt;&lt;A href=&quot;http://www.hoaxkill.com/urbanlegends.html&quot;&gt;Net Lore and Urban Legends&lt;/A&gt;. 
&lt;LI&gt;&lt;A href=&quot;http://www.symantec.com/avcenter/hoax.html&quot;&gt;Norton Symantec&lt;/A&gt; Security Response Directory of e-mail Hoaxes.
&lt;LI&gt;Researching &lt;A href=&quot;http://www.ulrc.com.au/&quot;&gt;Urban Legends&lt;/A&gt;.&amp;nbsp; 
&lt;UL&gt;
&lt;LI&gt;This might be where my sister got the idea that the volume of visitors to a website, translated into extra charges for bandwidth.&amp;nbsp; Oh! that Is a true story for this site.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;&lt;A href=&quot;http://www.scambusters.org/legends.html&quot;&gt;Scam Busters&lt;/A&gt; list e-mail chain nonsense and &lt;A href=&quot;http://www.scambusters.org/scamcheck.html&quot;&gt;other scams&lt;/A&gt;, tips on fighting spam, lots of good links, also including links to info on real computer viruses.
&lt;LI&gt;Scope of &lt;A href=&quot;http://www.snopes.com/index.htm&quot;&gt;Urban Legends&lt;/A&gt;. 
&lt;LI&gt;&lt;FONT face=Symbol&gt;&lt;X-TAB&gt;&lt;/X-TAB&gt;&lt;/FONT&gt;Many people think something is a hoax when it is not. See my&amp;nbsp;&lt;FONT face=Symbol&gt;&amp;nbsp;&lt;/X-TAB&gt;&lt;/FONT&gt;&lt;FONT color=#0000ff&gt;&lt;U&gt;Sep 20&lt;/U&gt;&lt;/FONT&gt; post about the plight of a Nigerian woman, sentenced to be stoned to death for the crime of being jilted by the husband of her child, in which I got a flood of referers due to people searching Gooble and other engines for information on the hoax details on this story, so their only hits were on sites that both talked about this real life situation, and some unrelated hoaxes.&lt;BR&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/10/13.html#a399</guid>
			<pubDate>Sun, 13 Oct 2002 21:07:23 GMT</pubDate>
			</item>
		<item>
			<description>[&lt;A href=&quot;http://www.suntimes.com/output/news/cst-nws-social09.html&quot;&gt;Chicago Sun Times&lt;/A&gt;] reports&amp;nbsp;insider identity theft of 5,000 employees of the state of Illinois in which crooks in Indiana, and other states, opened credit card accounts in the names of the victims, then stuck them with the bills for what was purchased on those accounts.&amp;nbsp;  </description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/10/10.html#a390</guid>
			<pubDate>Thu, 10 Oct 2002 20:20:23 GMT</pubDate>
			</item>
		<item>
			<description>&lt;P&gt;&lt;A href=&quot;http://www.woodyswatch.com/office/archives.asp&quot;&gt;W-O-O-D-Y-S--O-F-F-I-C-E--W-A-T-C-H&lt;/A&gt; &lt;A href=&quot;http://www.woodyswatch.com/office/archtemplate.asp?v7-n47&quot;&gt;Volume 7 Issue 47&lt;/A&gt; is really annoyed with Microsoft.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://www.woodyswatch.com/office/archives.asp&quot;&gt;W-O-O-D-Y-S--O-F-F-I-C-E--W-A-T-C-H&lt;/A&gt; describes QUOTE &lt;STRONG&gt;&lt;FONT color=red&gt;security holes in&lt;/FONT&gt;&lt;/STRONG&gt;&amp;nbsp;&lt;FONT color=red&gt;&lt;STRONG&gt;Word so big they defy description&lt;/STRONG&gt;&lt;/FONT&gt;. UNQUOTE Subscribe to&amp;nbsp;&lt;A href=&quot;http://www.woodyswatch.com/office/archives.asp&quot;&gt;W-O-O-D-Y-S--O-F-F-I-C-E--W-A-T-C-H&lt;/A&gt; for the low down on understanding that &lt;STRONG&gt;&lt;FONT color=red size=4&gt;Microsoft Security is an Oxymoron&lt;/FONT&gt;&lt;/STRONG&gt;.&amp;nbsp; There is a wealth of information in this regular e-newsletter.&lt;/P&gt;
&lt;P&gt;Scenario:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Bob has access to a file. 
&lt;LI&gt;Alice wants it. 
&lt;LI&gt;Alice sends Bob a document, innocently asking Bob to edit it and return it to her. 
&lt;LI&gt;When it comes back, it contains the file that Alice wanted, and Bob is none the wiser.&amp;nbsp; Bob cannot block this with anti-virus or any of the usual PC security because this is the way Microsoft Word is supposed to work. 
&lt;LI&gt;or, Word can &quot;phone home&quot; to Alice web site, delivering&amp;nbsp;what she wants.&amp;nbsp; Bob does not need to send the document back to Alice and she can still get copy of the file she wants.&amp;nbsp; 
&lt;UL&gt;
&lt;LI&gt;Woody showed Microsoft step by step exactly how that could be done, Sep 17, and the latest Microsoft press release is still pretending that this capability is not in their software. 
&lt;LI&gt;Oct 5 Woody sent Microsoft a demonstration Word document that when opened, sends Woody the first 230 characters of any file on your PC that he cares to name, to anywhere he cares to send it.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;Contrary to&amp;nbsp;Microsoft public statement, Alice does not need to know the absolute path to Bob&apos;s&amp;nbsp;file.&amp;nbsp; The person doing the pilfering can use just the name of the file without knowing what directory it is in. 
&lt;LI&gt;You can go after just about any file, such as the&amp;nbsp;passwords file, so long as you know how Windows organizes these things. 
&lt;LI&gt;The ability to do this stuff is what Microsoft calls a feature, so obviously, to Microsoft, this is not something they have any commitment to fixing.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;A href=&quot;http://www.woodyswatch.com/office/archives.asp&quot;&gt;W-O-O-D-Y-S--O-F-F-I-C-E--W-A-T-C-H&lt;/A&gt;&amp;nbsp;QUOTE&lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://www.woodyswatch.com/office/archtemplate.asp?v7-n47&quot;&gt;LIES, DAMN LIES, AND MICROSOFT&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Man, am I ticked off.&lt;/P&gt;
&lt;DIV&gt;&amp;nbsp; On October 8 - yesterday - I received a copy of Microsoft&apos;s&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; Inside Office Newsletter. Under the headline &quot;Answers to&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; Concerns About Security in Word&quot; there&apos;s a link to&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; &lt;A href=&quot;http://www.microsoft.com/technet/security/topics/secword.asp&quot; EUDORA=&quot;AUTOURL&quot;&gt;&lt;a href=&quot;http://www.microsoft.com/technet/security/topics/secword.asp&quot;&gt;http://www.microsoft.com/technet/security/topics/secword.asp&lt;/a&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; , where you&apos;ll find the same press release Microsoft posted&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; a month ago about the &quot;confusion and speculation&quot;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; surrounding the huge security holes in all versions of&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; Word. This is the first time Microsoft has notified its&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; customers about Alex&apos;s Document Collaboration Spy problem,&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; as far as I can tell, and instead of telling something&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; resembling the truth, all we get is more obfuscation.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; Recycled obfuscation at that.&lt;/DIV&gt;
&lt;DIV&gt;&lt;BR&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; Only Microsoft would have the unmitigated gall to lie so&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; blatantly, at this late date, and expect their customers to&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; swallow it.&amp;nbsp; I use the term lie quite deliberately,&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; Microsoft is still making statements that it knew then and&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; knows now are totally false.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; YODA tore the press release apart in Woody&apos;s Windows Watch&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; a couple of weeks ago&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;(&amp;lt;&lt;A href=&quot;http://www.woodyswatch.com/windows/archtemplate.asp?5-18&quot;&gt;&lt;a href=&quot;http://www.woodyswatch.com/windows/archtemplate.asp?5-18&quot;&gt;http://www.woodyswatch.com/windows/archtemplate.asp?5-18&lt;/a&gt;&lt;/A&gt;&amp;gt;).&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&amp;nbsp; But YODA only knew part of the story: he didn&apos;t know&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; about the security holes I&apos;ve been feeding to Microsoft,&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; and he hasn&apos;t seen the gaping exposures other folks have&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; encountered. The truth is far more devastating than&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; anything YODA could imagine.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; In this issue of Woody&apos;s Office Watch, I&apos;m going to show&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; you specifically how Microsoft is lying to you.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;UNQUOTE &lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;and Woody does so, with ample examples.&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;BACKGROUND&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;On August 26&lt;SUP&gt;th&lt;/SUP&gt; Alex Gantman released to a small community of fellow anti-virus analysts details of a&amp;nbsp;new type of security breach in Word, which has many variations and consequences.&amp;nbsp; He didn&amp;#146;t misuse his discovery but told other computer security specialists through an avenue that Microsoft closely watches.&amp;nbsp; Therefore Alex did notify Microsoft, at the same time as others.&amp;nbsp; Microsoft objects to anyone else being told about security problems with Microsoft products, preferring to be the sole clearing house for information and arbiter of what their customers should know.&amp;nbsp; It was only after Woody published some details in Woody&amp;#146;s OFFICE Watch on September 6th that the mainstream press got a hold of the story.&amp;nbsp; &lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;If you like the no-nonsense straight scoop of&amp;nbsp;&lt;A href=&quot;http://www.woodyswatch.com/office/archives.asp&quot;&gt;W-O-O-D-Y-S--O-F-F-I-C-E--W-A-T-C-H,&lt;/A&gt; assuming I have done an adequate job of translating / reviewing the latest news on this &lt;FONT color=red size=4&gt;&lt;STRONG&gt;Microsoft Security is an Oxymoron &lt;/STRONG&gt;&lt;/FONT&gt;front, here are some books to look out for from Woody (Al advertisement for Woody here in appreciation for the great education Al gets from Woddy).&lt;/DIV&gt;
&lt;P&gt;Windows XP All-In-One Desk Reference For Dummies&quot;, Hungry Minds&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href=&quot;http://www.woodyswatch.com/l.asp?0764515489&quot; EUDORA=&quot;AUTOURL&quot;&gt;&lt;a href=&quot;http://www.woodyswatch.com/l.asp?0764515489&quot;&gt;http://www.woodyswatch.com/l.asp?0764515489&lt;/a&gt;&lt;/A&gt;&lt;/P&gt;
&lt;DIV&gt;&amp;nbsp; &quot;Special Edition Using Microsoft Office XP&quot; with Ed Bott, Que&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href=&quot;http://www.woodyswatch.com/l.asp?0789725134&quot; EUDORA=&quot;AUTOURL&quot;&gt;&lt;a href=&quot;http://www.woodyswatch.com/l.asp?0789725134&quot;&gt;http://www.woodyswatch.com/l.asp?0789725134&lt;/a&gt;&lt;/A&gt;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp; &quot;Special Edition Using Microsoft Office 2000&quot; with Ed Bott, Que&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href=&quot;http://www.woodyswatch.com/l.asp?0789718421&quot; EUDORA=&quot;AUTOURL&quot;&gt;&lt;a href=&quot;http://www.woodyswatch.com/l.asp?0789718421&quot;&gt;http://www.woodyswatch.com/l.asp?0789718421&lt;/a&gt;&lt;/A&gt;&lt;/P&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp; &quot;Woody Leonhard Teaches Office 2000&quot;, Que&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href=&quot;http://www.woodyswatch.com/l.asp?0789718715&quot; EUDORA=&quot;AUTOURL&quot;&gt;&lt;a href=&quot;http://www.woodyswatch.com/l.asp?0789718715&quot;&gt;http://www.woodyswatch.com/l.asp?0789718715&lt;/a&gt;&lt;/A&gt;&lt;BR&gt;&lt;/DIV&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/10/09.html#a389</guid>
			<pubDate>Wed, 09 Oct 2002 22:13:49 GMT</pubDate>
			</item>
		<item>
			<description>&lt;H4&gt;[&lt;A href=&quot;http://radio.weblogs.com/0001285/&quot;&gt;Eclecticity: Dan Shafer&apos;s Web Log&lt;/A&gt;] QUOTE&lt;/H4&gt;
&lt;H4&gt;The Problems With Word on OS X Are Worse Than I Imagined&lt;/H4&gt;Word has become, for me at least, almost unusable since my upgrade to Jaguar. Here&apos;s what &lt;A href=&quot;http://www.mvps.org/word/FAQs/WordMac/WordXTroubleshooting.htm&quot;&gt;Microsoft&apos;s MVP support team&lt;/A&gt; has to say on the subject: 
&lt;BLOCKQUOTE&gt;&lt;I&gt;Unfortunately, Word is not going to work properly under Jaguar unless Microsoft releases a patch for Microsoft Office. The problems have now been analyzed, and the experts have found that Word v.X is not fully compatible with Jaguar, and there is nothing you can do to make it so. &lt;/I&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;What incredible garbage. Now what am I supposed to do? I have a publisher waiting for a book. They use Word. Their feedback to me is in Word comments, which are &lt;B&gt;frigging broken&lt;/B&gt; in Word on Jaguar. Arrogance screws the little guy once again. &lt;/P&gt;
&lt;P&gt;UNQUOTE [&lt;A href=&quot;http://radio.weblogs.com/0001285/&quot;&gt;Eclecticity: Dan Shafer&apos;s Web Log&lt;/A&gt;]&lt;/P&gt;
&lt;P&gt;Well here is a candidate for a souped up &lt;A href=&quot;http://radio.weblogs.com/0107846/categories/myFriends/2002/09/30.html#a332&quot;&gt;Lindows&lt;/A&gt;, since Word works on that Linux package.&amp;nbsp; Do your word processing on Star Office for Linux and output the document as RTF standard which Word will accept.&amp;nbsp; Just use Lindows to make the file acceptable to your publishers, and to get at their comments, while you do your real work on the computer of your choice.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/10/09.html#a383</guid>
			<pubDate>Wed, 09 Oct 2002 06:15:09 GMT</pubDate>
			<source url="http://radio.weblogs.com/0001285/rss.xml">Eclecticity: Dan Shafer&apos;s Web Log</source>
			</item>
		<item>
			<description>&lt;P&gt;[&lt;A href=&quot;http://www.suntimes.com/output/quicktakes/cst-nws-qt25.html&quot;&gt;Chicago Sun Times&lt;/A&gt;] shares a couple stories about Zero Tolerance of Modern School Administrators:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;A Nebraska 7th grader found some marijuana in his classroom and turned it into to the office.&amp;nbsp; He was suspended because, the act of picking it up and carrying it to the authorities constituted possession of marijuana. 
&lt;LI&gt;A Florida sophomore honor student saw a bag of pills on school grounds and did not follow the example of the Nebraska student because she was afraid of getting in trouble for possession of the contraband in the short distance of carrying it to the authorities.&amp;nbsp; She has been told she will be expelled for failure to do so.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;This reminds me of in Illinois where youngsters are encouraged to clean up the environment, but it is illegal for them to remove beer cans and alcohol bottles from the road side, because that means that those empty containers inside their garbage bags constitutes possession of those containers by a minor.&lt;/P&gt;
&lt;P&gt;The lesson for these kids is to &lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Do not touch the illegal substance - drugs, guns, whatever. 
&lt;LI&gt;Carefully write up a statement of where you saw this illegal substance, in a report to the authorities. 
&lt;LI&gt;Make sure your report is addressed to the authorities before you leave the scene, so that if an undercover officer sees you seeing the illegal whatever and not picking it up, your statement is part of your defense. 
&lt;LI&gt;Make a copy of your statement before you turn it in, so that if you later get hassled, you can take your statement to a lawyer, the news media, or &lt;A href=&quot;http://www.chillingeffects.org/fanfic/&quot;&gt;where ever&lt;/A&gt; your parents think will most embarrass the school authorities into backing down.&lt;/LI&gt;&lt;/UL&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/09/26.html#a323</guid>
			<pubDate>Thu, 26 Sep 2002 21:45:52 GMT</pubDate>
			</item>
		<item>
			<description>&lt;P&gt;&lt;A href=&quot;http://c.moreover.com/click/here.pl?r48099544&quot;&gt;Safety of Nuclear Power Plants Again Questioned&lt;/A&gt;. VOA Sep 24 2002 9:33PM ET [&lt;A href=&quot;http://www.moreover.com&quot;&gt;Moreover - Science news&lt;/A&gt;]&amp;nbsp; &lt;/P&gt;
&lt;P&gt;We are living in a different world today.&amp;nbsp; In recent years it made sense to&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Build a nuclear power plant right next to a major city, because nothing serious likely to go wrong, but now power plants are potential terrorist targets, so we do not want them right next to major cities. 
&lt;LI&gt;Build an airport in the middle of a major interstate interchange so easy to bring passengers real close to check in counters, but now a truck bomb can take out an airport, so we need a different kind of transportation infrastructure to unload the passengers from ground transport further away from the air tranport, and run everyone through screening suitably distant from buildings that might be major targets of terrorists.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&lt;FONT color=red&gt;&lt;STRONG&gt;VOA = Voice of America &lt;/STRONG&gt;&lt;/FONT&gt;... there&apos;s links here to what headlines VOA is sharing in various places in the world ... an interesting site worth revisiting occasionally.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href=&quot;http://www.voanews.com/category_browse.cfm?catOID=45C9C789-88AD-11D4-A57200A0CC5EE46C&amp;amp;title=Africa&quot;&gt;Africa&lt;/A&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;Amnesty International protests torture of child prisoners in Burundi
&lt;LI&gt;Intervention in Ivory Coast &lt;/LI&gt;
&lt;LI&gt;&lt;A href=&quot;http://www.voanews.com/article.cfm?objectID=78B988D9-E846-4AF7-89A6C518B15AECEB&amp;amp;title=African%20Uranium%20Security%20Raises%20Concern&amp;amp;catOID=45C9C789-88AD-11D4-A57200A0CC5EE46C&amp;amp;categoryname=Africa&quot;&gt;Uranium Security in Africa&lt;/A&gt; - is that an Oxymoron?&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;&lt;A href=&quot;http://www.voanews.com/category_browse.cfm?catOID=45C9C78B-88AD-11D4-A57200A0CC5EE46C&amp;amp;title=Asia%20Pacific&quot;&gt;Asia - Pacific&lt;/A&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;China ultimatim to Iraq
&lt;LI&gt;North Korea gets special envoy from Pres Bush 
&lt;LI&gt;a lot of stories I had not seen on local national news&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;&lt;A href=&quot;http://www.voanews.com/category_browse.cfm?catOID=45C9C78B-88AD-11D4-A57200A0CC5EE46C&amp;amp;title=Asia%20Pacific&quot;&gt;Asia - South and Central&lt;/A&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;US Troops in Afghanistan discover &lt;A href=&quot;http://www.voanews.com/article.cfm?objectID=59082FB7-DAA0-4FCF-88E9348779F22EDE&amp;amp;title=US%20Troops%20Uncover%20al%2DQaida%20Weapons%2C%20Model%20of%20757%20Airplane&amp;amp;catOID=45C9C78E-88AD-11D4-A57200A0CC5EE46C&amp;amp;categoryname=South%20%26%20Central%20Asia&quot;&gt;another chilling al Quaida site&lt;/A&gt;.
&lt;LI&gt;Dutch and Germans to take over NATO command in Afghanistan when Turkey time runs out.
&lt;LI&gt;Iran nervous about US troops near their border with Afghanistan
&lt;LI&gt;Suicide terrorists seized an Indian temple, leading to another gunfight.
&lt;LI&gt;Terrorists attack a Christian Charity.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;&lt;A href=&quot;http://www.voanews.com/category_browse.cfm?catOID=45C9C78E-88AD-11D4-A57200A0CC5EE46C&amp;amp;title=South%20%26%20Central%20Asia&quot;&gt;Americas&lt;/A&gt;&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;Argentina and Brazil economies still in bad shape
&lt;LI&gt;Chilean Appeals court throws out 7 cases against Pinochet
&lt;LI&gt;Colombian President visits USA President 
&lt;LI&gt;Mexican Banker gets record bail
&lt;LI&gt;That storm in the Carribean &lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;&lt;A href=&quot;http://www.voanews.com/category_browse.cfm?catOID=45C9C78D-88AD-11D4-A57200A0CC5EE46C&amp;amp;title=Mideast&quot;&gt;Middle East &lt;/A&gt;
&lt;UL&gt;
&lt;LI&gt;Britain and Iraq 
&lt;LI&gt;China and Iraq 
&lt;LI&gt;Kuwait hosts USA military exercises 
&lt;LI&gt;Lebanon scandal with Israel 
&lt;LI&gt;Palestinians 
&lt;LI&gt;USA politics and Iraq 
&lt;LI&gt;USA and Pakistan cooperation&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;&lt;A href=&quot;http://www.voanews.com/category_browse.cfm?catOID=45C9C78F-88AD-11D4-A57200A0CC5EE46C&amp;amp;title=USA&quot;&gt;USA&lt;/A&gt; 
&lt;UL&gt;
&lt;LI&gt;Brushfire in Western USA 
&lt;LI&gt;Iraq and Partisan Politics 
&lt;LI&gt;Various legislation&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/09/26.html#a318</guid>
			<pubDate>Thu, 26 Sep 2002 06:49:28 GMT</pubDate>
			<source url="http://p.moreover.com/cgi-local/page?c=Science%20news&amp;o=rss">Moreover - Science news</source>
			</item>
		<item>
			<description>I added a small reference directory of &quot;e Discussion Groups&quot;: e-commerce; computer security; etc.</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/09/24.html#a313</guid>
			<pubDate>Tue, 24 Sep 2002 09:10:42 GMT</pubDate>
			</item>
		<item>
			<description>[&lt;A href=&quot;http://radio.weblogs.com/0100530/categories/security/&quot;&gt;Scott Granneman&apos;s Security Category&lt;/A&gt;] covers topics of e-law; human stupidity; Microsoft gotchas.</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/09/24.html#a305</guid>
			<pubDate>Tue, 24 Sep 2002 07:20:48 GMT</pubDate>
			</item>
		<item>
			<description>&lt;P&gt;FROM [&lt;A href=&quot;http://www.ozzie.net/blog/&quot;&gt;Ray Ozzie&apos;s Weblog&lt;/A&gt;]&lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://www.ozzie.net/blog/stories/2002/09/10/tyrannyTerrorAndTechnology.html&quot;&gt;Tyranny, Terror, and Technology&lt;/A&gt;.&amp;nbsp; Some thoughts about the intersection between the challenges confronting business, and those confronting government and society. UNQUOTE &lt;A href=&quot;http://www.ozzie.net/blog/&quot;&gt;Ray Ozzie&apos;s Weblog&lt;/A&gt;]&lt;/P&gt;
&lt;P&gt;This is a dynamite thought provoking essay - I highly recommend it - my words of wisdom pale in comparison.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;I believe that beaurocracy, and inter-communications within an organization, is like &lt;FONT color=red&gt;&lt;STRONG&gt;glue&lt;/STRONG&gt;&lt;/FONT&gt;. 
&lt;UL&gt;
&lt;LI&gt;Too much and the enterprise is all gummed up with rules that get in the way of doing the job. 
&lt;LI&gt;Too little and everyone is flying off in different directions, counter productive. 
&lt;LI&gt;The challenge is to get it just right, so that you have an agile team effort. 
&lt;UL&gt;
&lt;LI&gt;This is further complicated by the organization fluctuating in size, so you need different strategies for different scales of operation.&amp;nbsp; Also there is a spread of individual skills of participants in the organization, so until you get everyone up to speed on something, there has to be another way of getting the job done.&amp;nbsp; Any time things are changed, there will be transitional confusion.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;Organizations can be too large and unwieldy. 
&lt;UL&gt;
&lt;LI&gt;Remember the book &lt;A href=&quot;http://www.yourdon.com/books/coolbooks/notes/brooks.html&quot;&gt;The Mythical Man Month&lt;/A&gt;, which I consider to be one of the classics on software engineering? 
&lt;LI&gt;Basically the permutations of all the different people who need to intercommunicate can bog down some things so that nothing can get done. 
&lt;LI&gt;Thus it is essential to organize focus teams and have a hierarchy such that there is no wasted baggage in your structure that gets in the way of a lean and mean team.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;An excess of organizations focused on different tasks is good in business. 
&lt;UL&gt;
&lt;LI&gt;Competition leads to better Quality, Features, Economies.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;An excess of organizations with overlapping responsibilities is bad in government. 
&lt;UL&gt;
&lt;LI&gt;They can have turf wars that get in the way of them doing what they are supposed to be doing.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/09/10.html#a250</guid>
			<pubDate>Tue, 10 Sep 2002 19:38:32 GMT</pubDate>
			<source url="http://www.ozzie.net/blog/rss.xml">Ray Ozzie&apos;s Weblog</source>
			</item>
		<item>
			<description>&lt;P&gt;&lt;A href=&quot;http://www.newsisfree.com/click/-2,7714967,1843/&quot;&gt;FBI warns of potential threats&lt;/A&gt; [&lt;A href=&quot;http://www.usatoday.com/&quot;&gt;USA Today : Front Page&lt;/A&gt;]&lt;/P&gt;
&lt;P&gt;As usual, nothing specific ... if they had something specific they could stop it from happening ... except right before 9/11 both CIA and FBI were independently tailing 2 of the hijackers because of their involvement in a prior terrorist attack on USA and&amp;nbsp;GOV was trying to identify all the conspirators, and what they up to, and build court case, but the 2 hijackers gave their tails the slip and the rest is history.&amp;nbsp; There is a hard balance there to achieve between ability to get a court conviction, round up evidence what going on, (correlate the masses of clues that they get, many of which might be misleading or erroneous), and actually prevent something bad from happening.&lt;/P&gt;
&lt;P&gt;Unconfirmed reports of AlQ targeting oil tankers, add that to laundry list of other things identified in past like nuclear power plants, and shipping containers.&lt;/P&gt;
&lt;P&gt;Question detainees - risk they will share every fantasy whacko scheme any alQ group ever dreamed up, but was abandoned as impractical.&lt;/P&gt;
&lt;P&gt;I sure hope GOV and MIL doing war game simulations into what might go wrong, and keep secret results until they have plugged holes that the simulations uncover. &lt;/P&gt;
&lt;P&gt;Historical patterns logic ... &lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Our enemies hate what West stands for, and international western institutions, so they may target meetings of UN or World Bank. 
&lt;LI&gt;Pearl Harbor was on a Sunday when Amercian Air Defense at Peace and high religious ethic what do on a Sunday. 
&lt;LI&gt;Oklahoma City was on the anniversary of Waco because some whacko with no relationship to Waco wanted to do something on that anniversary date. 
&lt;LI&gt;Well, people who hate us are inspired by bin Laden example, people with no contact with alQ. 
&lt;UL&gt;
&lt;LI&gt;I sure hope long term Foreign Policy goals can include addressing why these people hate us so much, and do something about turning the tide of recruitments into ranks of our enemies, so that potential enemies do not go down that path.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/09/10.html#a249</guid>
			<pubDate>Tue, 10 Sep 2002 19:18:17 GMT</pubDate>
			<source url="http://www.newsisfree.com/HPE/xml/feeds/43/1843.xml">USA Today : Front Page</source>
			</item>
		<item>
			<description>&lt;P&gt;[&lt;A href=&quot;http://live.curry.com/&quot;&gt;Adam Curry: Adam Curry&apos;s Weblog&lt;/A&gt;] QUOTE&lt;/P&gt;
&lt;P&gt;I found out via an email exchange that one of the founders of the [newly relaunched] &lt;A href=&quot;http://electronicIntifada.net/&quot;&gt;electronic intifada&lt;/A&gt; website is Dutch. Arjan El Fassed also posted several &lt;A href=&quot;http://rcs.blognewsnetwork.com/comments/comments?u=1014&amp;amp;p=2256&amp;amp;link=http%3A%2F%2Flive.curry.com%2F2002%2F09%2F08.html%23a2256&quot;&gt;comments&lt;/A&gt; to &lt;A href=&quot;http://live.curry.com/2002/09/08.html#a2256&quot;&gt;yesterday&apos;s posting&lt;/A&gt;. Of course there are counter posts now as well that is forming a lively conversation. &lt;/P&gt;
&lt;P&gt;My advice to Arjan is to re-re-launch electronicintifada as a weblog. Perhaps a multi-user weblog for multiple authors. Currently the site appears to emulate a BigPub and imho detracts from their mission. 
&lt;P&gt;As with all aspects of war, be careful not to become what you are fighting against. UNQUOTE [&lt;A href=&quot;http://live.curry.com/&quot;&gt;Adam Curry: Adam Curry&apos;s Weblog&lt;/A&gt;] 
&lt;P&gt;This is also like the &lt;FONT color=red&gt;&lt;STRONG&gt;appearance &lt;/STRONG&gt;&lt;/FONT&gt;of impropriety.&amp;nbsp; The enemies are not clearly understood by government intelligence, let alone anyone else.&amp;nbsp; When any group of people discuss something, the odds are that several are police spies, journalists trying to ferret out a story, pure innocents trying to figure out what is going on, and it may be that none of the participants are any of the bad guys, but in a war, the rules of innocent until proven guilty are sometimes altered into round up suspects before someone pulls another 9/11.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/09/09.html#a234</guid>
			<pubDate>Mon, 09 Sep 2002 19:15:31 GMT</pubDate>
			<source url="http://cloud.datashed.net/users/adam@curry.com/curryCom.xml">Adam Curry: Adam Curry&apos;s Weblog</source>
			</item>
		<item>
			<description>&lt;P&gt;[&lt;A href=&quot;http://live.curry.com/&quot;&gt;Adam Curry: Adam Curry&apos;s Weblog&lt;/A&gt;] QUOTE&lt;/P&gt;
&lt;P&gt;All dutch helicopter companies, &lt;A href=&quot;http://geengemopper.nl/&quot;&gt;including ours&lt;/A&gt;,&amp;nbsp;received a fax from the authorities this morning, warning of &apos;journalists&apos; that will attempt to proove our natuional security is flawed, by staging an &apos;air assault&apos; over the country on sept. 11th.&lt;/P&gt;
&lt;P&gt;Geez guys, get a life already. I&apos;ve posted the fax on my &lt;A href=&quot;http://live.curry.com/dutch/2002/09/09.html#a2262&quot;&gt;dutch weblog&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;UNQUOTE [&lt;A href=&quot;http://live.curry.com/&quot;&gt;Adam Curry: Adam Curry&apos;s Weblog&lt;/A&gt;]&lt;/P&gt;
&lt;P&gt;I think the threat to National Security is more from Journalists than from Air Companies, from the perspective of doing something stupid.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Many people, who work in Air Companies learned their trade, as military pilots, or have around them people of that patriotic perspective that can provide a sense of balance.&lt;/P&gt;
&lt;P&gt;The risk from Air Companies is that in the management of costs, there will be a trade off that sacrifices safety and security.&lt;/P&gt;
&lt;P&gt;It is self evident to anyone, who lives in a democracy, that various national monuments and institutions can be seriously hit by something like the Oklahoma City Bombing, if the perpetrators do not care if they get caught, and the only way to protect ourselves is to become a police state.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;If you doubt this, show me your credentials (such as a policeman badge) that you have need to know my theories on how bad guys could hit the very stuff that is sacred to our democracy, such as various government buildings and important places to the infrastructure of our economy, and I will tell you how, but not via a public forum.&lt;/P&gt;
&lt;P&gt;Now some commentators seem to have an attitude that parallels that of Juvenile Computer Crackers ... hey, here is a weakness not properly protected ... broadcasting it daring someone to find a solution, and meanwhile the bad guys have been delivered of an idea that perhaps they might not have dreamed up for a while, so the article has just made the job of Homeland Security that much more difficult to get done.&lt;/P&gt;
&lt;P&gt;This is reminiscent of past wars where journalists pretended to be impartial.&amp;nbsp; Remember Saddam&apos;s troops shooting up various air conditioning ducts in downtown Kuwait?&amp;nbsp; Why did they do that?&amp;nbsp; Well some refugees crossing the border to freedom were surrounded by journalists to cover their story, and among other things they said they hid in air conditioning ducts of some office buildings.&amp;nbsp; Saddam&apos;s military intelligence was watching Western media and picked up on that information, and other clues about how people were escaping, and some refugees did not make it out safely, thanks to many journalists not understanding that &lt;FONT color=red&gt;&lt;STRONG&gt;loose lips sink ships&lt;/STRONG&gt;&lt;/FONT&gt;.&lt;/P&gt;
&lt;P&gt;What we need are private briefings in executive session to Legislators and Homeland Security agency workers, to make sure that they are aware of things that people in other professions can see.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Architectural Design Professionals 
&lt;LI&gt;Computer Professionals 
&lt;LI&gt;Journalism Professionals 
&lt;LI&gt;Public Health Professionals 
&lt;LI&gt;Security Professionals 
&lt;LI&gt;Transportation Professionals&lt;/LI&gt;&lt;/UL&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/09/09.html#a233</guid>
			<pubDate>Mon, 09 Sep 2002 19:08:41 GMT</pubDate>
			<source url="http://cloud.datashed.net/users/adam@curry.com/curryCom.xml">Adam Curry: Adam Curry&apos;s Weblog</source>
			</item>
		<item>
			<description>&lt;P&gt;On a thread in the &lt;A href=&quot;http://groups.yahoo.com/group/e-com-sec/&quot;&gt;e-com-sec discussion group&lt;/A&gt;, I asked what are we supposed to do when we get spam from known criminals such as the Nigerian Scam.&amp;nbsp; We have a moral obligation to report criminals to the government, but police seem to be ill equipped to deal with individual internet solicitations of criminal activity.&amp;nbsp; The tip lines are so overwhelmed as it is with more serious issues, that GOV has a serious need for a software magnet to find the key needle clues in their information haystack.&lt;/P&gt;
&lt;P&gt;I was basically told that we should treat any spam as spam, forget about trying to deal with criminals the same way as is done in the real world outside of the Internet, and given an interesting link to a &lt;A href=&quot;http://www.sysmod.com/praxis/prax0206.htm&quot;&gt;back issue of Sysmod&apos;s Praxis&lt;/A&gt;, which I have previously mentioned on my weblog.&amp;nbsp; It included the following stimulating topics:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Europe&apos;s anti-spam legislation. 
&lt;LI&gt;Microsoft IE patch 
&lt;LI&gt;The &lt;FONT color=red&gt;&lt;STRONG&gt;person &lt;/STRONG&gt;&lt;/FONT&gt;in personal decisions about the computer you think you own, and stuff stored on it, is not you but Microsoft. 
&lt;LI&gt;Google Features 
&lt;LI&gt;Cyber Squatting 
&lt;LI&gt;&lt;A href=&quot;http://www.bankofengland.co.uk/euro/euroiss0205.htm&quot;&gt;Euro Glitches&lt;/A&gt; 
&lt;LI&gt;Euro Zone 
&lt;LI&gt;Nigeria Scam Clones 
&lt;LI&gt;&lt;A href=&quot;http://www.milleniuminternetdesigns.netfirms.com/&quot;&gt;Worst Web site&lt;/A&gt;&amp;nbsp;(&lt;FONT color=red&gt;&lt;STRONG&gt;warning&lt;/STRONG&gt;&lt;/FONT&gt;: protect your eyes) 
&lt;LI&gt;Longest domain name&lt;/LI&gt;&lt;/UL&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/09/08.html#a226</guid>
			<pubDate>Sun, 08 Sep 2002 20:06:48 GMT</pubDate>
			</item>
		<item>
			<description>&lt;P&gt;&lt;A href=&quot;http://www.quicktopic.com/boing/H/XzNVFwXbeiJV&quot;&gt;Comment&lt;/A&gt; on Al&apos;s &lt;A href=&quot;http://radio.weblogs.com/0107846/stories/2002/08/23/radioDocSources.html&quot;&gt;&lt;FONT size=+1&gt;&lt;B&gt;Radio Doc Sources&lt;/B&gt;&lt;/FONT&gt;&lt;/A&gt; using &lt;FONT color=green size=4&gt;&lt;STRONG&gt;Quick Topics&lt;/STRONG&gt;&lt;/FONT&gt;.&amp;nbsp; Eventually, Al wants to look into pros &amp;amp; cons of several different commenting systems for Radio, but we have to start some place.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/09/05.html#a212</guid>
			<pubDate>Thu, 05 Sep 2002 21:23:31 GMT</pubDate>
			</item>
		<item>
			<description>&lt;P&gt;[&lt;A href=&quot;http://www.scripting.com/&quot;&gt;Scripting News&lt;/A&gt;] QUOTE&lt;/P&gt;
&lt;P&gt;A mostly user-level &lt;A href=&quot;http://www.blogroots.com/comments.blog/157#1194&quot;&gt;discussion&lt;/A&gt; on Blogroots about syndication and aggregation. It&apos;s good to get grounded with users every once in a while to relearn that what to us seems neat and cool, often trips up people who have expertise in areas other than ours. &lt;/P&gt;
&lt;P&gt;UNQUOTE [&lt;A href=&quot;http://www.scripting.com/&quot;&gt;Scripting News&lt;/A&gt;]&lt;/P&gt;
&lt;P&gt;[&lt;A href=&quot;http://blogs.salon.com/0001010/2002/08/22.html&quot;&gt;Ken Dow&lt;/A&gt;] also shares links from [Dave Winer&apos;s &lt;A href=&quot;http://www.scripting.com/&quot;&gt;Scripting News&lt;/A&gt;]&amp;nbsp;from [&lt;A href=&quot;http://www.wired.com/news/politics/0,1283,54681,00.html&quot;&gt;Wired&lt;/A&gt;] QUOTE&lt;/P&gt;
&lt;P&gt;&quot;[&lt;A href=&quot;http://www.wired.com/news/mp3/0,1285,54678,00.html&quot;&gt;Verizon&lt;/A&gt;] refused to comply with the order, arguing the entertainment industry is presuming the guilt of its users without any due process.&quot; &lt;/P&gt;
&lt;P&gt;UNQUOTE [&lt;A href=&quot;http://www.scripting.com/&quot;&gt;Scripting News&lt;/A&gt;]&lt;/P&gt;
&lt;P&gt;While reading related stories on [&lt;A href=&quot;http://www.wired.com/news/politics/0,1283,54681,00.html&quot;&gt;Wired&lt;/A&gt;] I came across a law suit against Hollywood by people who want the right to &lt;A href=&quot;http://www.wired.com/news/digiwood/0,1412,54852,00.html&quot;&gt;Edit the Movies to remove material that they find to be objectionable&lt;/A&gt;.&amp;nbsp; The suit has been brought by someone who has a patent pending that will help home users, such as parents, to edit what Hollywood delivers to the home, to remove material unsuitable for their children.&lt;/P&gt;
&lt;P&gt;You have probably heard my opinion on this before.&amp;nbsp; But I restate it and revise it as reality shifts.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Intellectual Property Rights need to be protected, so that there is good incentive for people to improve the quality of what we get, be it literature, music, movies, software. 
&lt;UL&gt;
&lt;LI&gt;If we accept a society in which anyone can take whatever they want, without proper compensation to the artists and authors, then the market place quality will be driven towards crud. 
&lt;LI&gt;We are in a society in which the mass consumers seek the lowest price and are getting what we are paying for, and the intellectuals are having a hard time getting a decent income. 
&lt;LI&gt;The publishers of the intellectual property are getting the lion&apos;s share of the income, and there is rebellion against them by both the consumers, who want&amp;nbsp;freedom to get the stuff at low price, and the artists who think they are not getting fair share of the income. 
&lt;LI&gt;There needs to be ways that we can get the entertainment that we want and pay a fair price for it. 
&lt;LI&gt;My sister composed and performed music which she sent me by e-mail.&amp;nbsp; Is that kind of artist to audience delivery to now be banned because so many people are abusing the communication links for delivery of entertainment for which the copyright has been violated? 
&lt;LI&gt;I am extremely unhappy about the degree to which advertisements are intruding on the content stream, and law suits by the advertisers to try to block the ability of consumers to switch channels, fast forward, etc. to get around having to view the ads.&amp;nbsp; The main product should be packaged at a price that we can get it without having any of the advertisements in the first place.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;Computer usage can get complex.&amp;nbsp; Business Accounting is complex and difficult to understand.&amp;nbsp; Some of it is that way deliberately,&amp;nbsp;where&amp;nbsp;special interests lobby&amp;nbsp;Congress to make it complex. 
&lt;UL&gt;
&lt;LI&gt;Consider our Income Taxes ... how many people figure it out themselves without help from some software or going to a Tax place to figure it for us? 
&lt;LI&gt;Those tax places lobby&amp;nbsp;Congress to keep it so complicated that we have to go to them to figure our taxes.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;Decisions are made that rule our lives by people who not understand the implications of what they are mucking with. 
&lt;UL&gt;
&lt;LI&gt;One thing that really alarmed me was when I bought and read a book by a former National Security Advisor about cyber threats, it shows that he seemed to be really ignorant about some computer stuff, reminiscent of the kinds of thinking that Bruce Sterling wrote about in his book &lt;A href=&quot;http://dub.home.texas.net/sterling/hackcrck.html&quot;&gt;The Hacker Crackdown&lt;/A&gt;. 
&lt;UL&gt;
&lt;LI&gt;We&apos;ve talked about some of these things in Computer Community and it is evident that some of this is hogwash (threat is not real) and some of it is naive (threat is much worse than these people realize) but the news media repeats the book author stuff without much review by people who theoretically can comment on how much the author got it right and how much should have got expert advice before finalizing these writings.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;I believe that the computer community needs to give seminars to the law enforcement community to bring them up to speed on where the risks really are, and which of the risks in the popular media are really Science Fiction. 
&lt;UL&gt;
&lt;LI&gt;End consumers ought to be allowed to obtain entertainment in one form, and listen to it in &lt;A href=&quot;http://www.wired.com/news/digiwood/0,1412,54270,00.html&quot;&gt;another form&lt;/A&gt;, be it put those tapes into your car stereo, boom box, walkman, home appliance, or whatever.&amp;nbsp; Just so long as the original obtaining was legally purchased or legal copies. 
&lt;LI&gt;End consumers ought to be allowed to obtain information or software onto their computers and make reasonable backup copies.&amp;nbsp; The issue should be related to the number of users and the number of platforms, and the licensing agreement should make it clear what the ceiling is, with a way to upgrade the ceiling, or to move your stuff from your old computer to a replacement one.&amp;nbsp; Just so long as the original aquisition was a legal purchase or legal copy. 
&lt;LI&gt;End consumers ought to be allowed to remove software, like games, or entertainment, like music, from their computers and personal places, like home and auto, then sell or trade that with some other consumer.&amp;nbsp; Just so long as the original user no longer keeps the copy.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;It seems like Government Beaurocracy is growing out of control.&amp;nbsp; All those agencies competing with each other and not doing a great job of communicating with each other in a national crisis. &lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;
&lt;UL&gt;
&lt;UL&gt;
&lt;LI&gt;Is there any hope for simplification, or will&amp;nbsp;that have to wait on another generation?&amp;nbsp;&amp;nbsp; &lt;/LI&gt;&lt;/UL&gt;&lt;/UL&gt;
&lt;LI&gt;
&lt;UL&gt;
&lt;LI&gt;New ordinary users of computer technology often do not understand &lt;A href=&quot;http://radio.weblogs.com/0107846/stories/2002/08/12/etiquetteOnline.html&quot;&gt;e-etiquette&lt;/A&gt;&amp;nbsp;let alone all the stuff their software is doing, so they learn by emulating the other users around them. 
&lt;UL&gt;
&lt;LI&gt;We see this blind leading the blind process with all the people on the public highways who are oblivious to speed limits, and the accident rate from drunk drivers. 
&lt;LI&gt;We see this blind leading the blind in the cyber-plagues of our own making, popularly known as computer viruses, and how people get infected. 
&lt;LI&gt;Consumers are smart enough not to be wearing t-shirts with their credit card numbers emblazened for anyone to use, or take the doors off of homes for anyone to help self to contents, but there seems to be a widespread misconception that there is such a thing as Internet Privacy.&amp;nbsp; That is an Oxymoron.&amp;nbsp; If you not want anyone to copy your stuff, do not connect it to the Internet.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;A generation or so ago, before PCs invented, students were stealing computer time to play space war simulation games.&amp;nbsp; The students had no conception of intellectual property rights, a problem that continues to this day.&amp;nbsp; The owners of the stolen computer resources had no conception of security, a problem that continues to this day. 
&lt;UL&gt;
&lt;LI&gt;Now that the price of computer power has dropped so that anyone can use it, we have new generations of people making the same mistakes.&amp;nbsp; Put your stuff on the Internet and have this fantasy that no one is going to use it. &lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;Professional places, that post stuff to the internet, do a really good job of confusing the customers. 
&lt;UL&gt;
&lt;LI&gt;Visit just about any news organization web site. 
&lt;UL&gt;
&lt;LI&gt;With one message they clearly state that to copy anything from that site without their permission is a violation of copyright.&amp;nbsp; In other words reading the data from screen through my eyes to my brain is in violation of their rules. 
&lt;LI&gt;With other messages you can push a button and get a printer friendly copy, e-mail it to some discussion group, or copy the pages.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;Who reads the contract that comes with software? 
&lt;UL&gt;
&lt;LI&gt;Radio license clearly states that this is not to be exported outside the USA and a very narrow range of countries. 
&lt;LI&gt;Anyone who looks at the popular sites and discussion lists can see that Radio is being sold all over the world. 
&lt;LI&gt;Does this mean that their contract is meaningless, or is there some law that called for putting some phrases in their contract and at some point 100% of Userland executives are going to be in trouble with the government for export violations?&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;Documentation exists but where is the motivation for software vendors to do a good job with it ... how many end consumers bother to read the documentation before they have some kind of a problem? 
&lt;UL&gt;
&lt;LI&gt;A potential problem exists with the acronyms and new uses for new technology. 
&lt;LI&gt;Can we reasonably expect any new buyer of Radio to know what RSS means? 
&lt;LI&gt;New users see something on other people sites and want to do that on their own sites, but do not know the right terminology for the phenomena.&amp;nbsp; This is like looking up the correct spelling of a word in the dictionary, when you do not even know what the word is.&amp;nbsp; That makes it difficult to pose good questions to the discussion groups, or use search engine to find prior answers.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;With Radio Referers we can see who is reading our stuff and giving us proper credit for it.&amp;nbsp; We can not see who is quoting us without attribution. 
&lt;UL&gt;
&lt;LI&gt;I am learning how to give good credit to my sources, but many sites (most recently Slashroot), in combination with the software that I am using, won&apos;t let me edit to just do part of their story. 
&lt;UL&gt;
&lt;LI&gt;It is getting difficult for me to figure out how to do credit when information flows through a series of people before it gets to me. 
&lt;LI&gt;When something is written with a summary statement at the beginning like a journalist story, then it can make sense to copy just the headline with a link to the source for full details, but many beginning webloggers are not that good writers to provide something that can be extracted like that. 
&lt;LI&gt;Some web sites have strict copyright rules, but those rules don&apos;t get into the RSS feeds.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;Many newbies don&apos;t give any credit until someone points out to them the need to do so.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;Different people want different things.&amp;nbsp; You can&apos;t blame software for being a square peg that you try to put in a round hole.&amp;nbsp; If you want a round peg, buy one.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;This&amp;nbsp;does not bode well for the long term health of the Republic. 
&lt;LI&gt;The bulletin boards taken down by the government that led ultimately to the Steve Jackson case ... those BBSes were not selected at random.&amp;nbsp; There was stuff going on that gave the government reason to suspect criminal behavior.&amp;nbsp; It may or may not have been sufficient probable cause had the case been appealed all the way up the court system, but they did not move in with zero evidence. 
&lt;UL&gt;
&lt;LI&gt;There were criminals using the bulletin boards to trade information on how to break into private computers.&amp;nbsp; Now people can always argue whether hacking is not illegal immoral etc. and what the responsibility of the host of a network has to help authorities catch abusers of the services, but the fact remains that there were serious assaults on the nation&apos;s infrastructure, such as a cracker bringing down a 911 service, attacks on computers in hospitals whose work was essential to the health of patients there.&amp;nbsp; Locating the responsible people was no easy task for the early cyber cops. 
&lt;LI&gt;Steve Jackson was working on a simulation game about cyber criminal activity.&amp;nbsp; As research for this game, he had employees trying to infiltrate the cyber criminal underworld.&amp;nbsp; Now when a bunch of people sit down to discuss their criminal behavior, the odds are that at least one is a police spy, and at least one is a journalist, but the police spy does not know which one is there as a journalist and which is there as a criminal. 
&lt;LI&gt;Journalists need some sources protection so they can get the information they need to do stories, but they also have an obligation to the nation.&amp;nbsp; When we have knowledge of criminal behavior,&amp;nbsp; we ought to make an effort to inform law enforcement of this, or risk being treated as being part of the criminal conspiracy.&amp;nbsp; This applies equally to journalists, authors, game designers, computer professionals.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/09/02.html#a192</guid>
			<pubDate>Mon, 02 Sep 2002 21:54:58 GMT</pubDate>
			</item>
		<item>
			<description>&lt;P&gt;[&lt;A href=&quot;http://radio.weblogs.com/0111198/&quot;&gt;Blogfish&lt;/A&gt;] QUOTE&lt;/P&gt;
&lt;P&gt;&lt;A href=&quot;http://radio.weblogs.com/0111198/2002/08/29.html#a168&quot;&gt;Uncover the real WINNT killer&lt;/A&gt;. &lt;/P&gt;
&lt;P&gt;Last Friday I got to work and was greeted by&amp;nbsp;mr. blue screen. After rebooting a couple of times only to see the message &quot;kernelos32.exe is either missing or corrupt&quot; I asked our sysadmin for help.&lt;/P&gt;
&lt;P&gt;&quot;Your Winnt directory is missing&quot; he told me. What? &quot;It&apos;s not there. &lt;FONT size=4&gt;What were you doing that caused this to happen?&lt;/FONT&gt;&quot; That last inquiry has propelled me into a virus hunt&amp;nbsp;that will&amp;nbsp;uncover the real WINNT killer.&lt;/P&gt;
&lt;P&gt;Just jotting down one possility I saw on &lt;A href=&quot;http://radio.weblogs.com/0103807/2002/08/23.html#a486&quot;&gt;FuzzyBlog&lt;/A&gt;:&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;SPAN class=a2&gt;&lt;B&gt;Microsoft said Thursday that &quot;critical&quot; security lapses in its Office software and Internet Explorer Web browser put tens of millions of users at risk of having their files read and altered by online attackers.&lt;/B&gt; 
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The world&apos;s leading software maker said that an attacker, using e-mail or a Web page, could use Internet related parts of Office to run programs, alter data and &lt;STRONG&gt;&lt;FONT size=4&gt;wipe out a hard drive&lt;/FONT&gt;&lt;/STRONG&gt;, as well as view file and clipboard contents on a user&apos;s system.&lt;/P&gt;&lt;/SPAN&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I never thought viruses actually wiped out hard drives. I never even knew someone who knew someone who had an aunt whose entire hard drive was wiped out. Does this really happen? QUOTE [&lt;A href=&quot;http://radio.weblogs.com/0111198/&quot;&gt;Blogfish&lt;/A&gt;]&lt;/P&gt;
&lt;P&gt;Alison&lt;/P&gt;
&lt;P&gt;You need to&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Check the anti-virus hoax pages to find out what your exact situation is.&amp;nbsp; There are viruses that say you have some problem other than what you really have.&amp;nbsp; There are virus hoaxes that say there is this file that the anti-viruses can&apos;t detect &amp;amp; if you find it on your system you need to delete it, but it is really a file you need to run your system, so you follow the hoax instructions, delete the file, and now your system really is crashed.&amp;nbsp; Even though you may be too wise to fall for this, some co-worker might not.&amp;nbsp; Millions of dollars have been ssiphoned from American Businesses because the Nigerian Scam is sent out very much the same way as computer viruses are distributed.&amp;nbsp; Anyone who can fall for a hoax, can fall for a financial con game.&amp;nbsp; I have a lot more faith in the anti-hoax anti-virus vendors than I do in the outfits that supply the software, or the people in charge of computer systems in corporate America. 
&lt;LI&gt;&amp;nbsp;&lt;a href=&quot;http://www.vmyths.com/&quot;&gt;http://www.vmyths.com/&lt;/a&gt; 
&lt;P class=MsoNormal&gt;Truth About Computer Virus Myths &amp;amp; Hoaxes&lt;/P&gt;
&lt;LI&gt;Check my guide to the basics of personal computer security posted &lt;A href=&quot;http://radio.weblogs.com/0107846/2002/08/15.html#a73&quot;&gt;Aug 15&lt;/A&gt;.&amp;nbsp; I can send you by e-mail attachment the Word document I am referring to.&amp;nbsp; I just do not want to put into general circulation a working document that has tons of links where I have not asked permission to quote people, and do in fact quote without attribution, because I figured out netiquette after I started on the document.&amp;nbsp; 
&lt;UL&gt;
&lt;LI&gt;Ask me to send you my Computer Security Myths document.&amp;nbsp; I try to avoid sending people as e-mail attachments something I think would be of interest to them, because of the high risk of a virus in any attachment you were not expecting.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;I have a few other Security documents I can share.&amp;nbsp; Mac Policy doc is a barely begun outline that spells out the philosophy of what I want to accomplish with my Computer Security Essays.&amp;nbsp; There are some risks&amp;nbsp;that I must not detail because the cyber terrorists have not yet figured out how to do those things.&amp;nbsp; I want to communicate at a level that anyone can understand, non-technical or technical, not talk down to people, avoid bashing any vendor, and avoid getting in an arguement.&amp;nbsp; I will let someone else&apos;s documents bash vendor practices that put us at this kind of risk.&amp;nbsp; Getting this work to the web was one of the reasons I started my Radio Weblog.&amp;nbsp; I wanted to learn what could be done, get good at it, then select presentation method.&amp;nbsp; I leaning towards a separate category on a separate host with Instant Outlining. 
&lt;UL&gt;
&lt;LI&gt;There is one that I downloaded from Europe that explains Banking practices and why Identity Theft is so prevalent.&amp;nbsp; Ask for my e-fraud document.&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;&amp;nbsp;I&amp;nbsp;did a series of messages (#s 3258 3261 3293 3314 3341) at 
&lt;P class=MsoNormal&gt;&lt;a href=&quot;http://groups.yahoo.com/group/TYR&quot;&gt;http://groups.yahoo.com/group/TYR&lt;/a&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;basically spelling out that the situation with a lack of Internet Privacy has been permitted to deteriorate a lot worse than most people realize, but for each hazard there are things that people can do to mitigate the risks.&lt;/P&gt;
&lt;P class=MsoNormal&gt;I was planning to expand on these but then thought that my Computer Myths approach was a better way to hopefully contribute to customers of computer systems putting an end to this idiocy.&lt;/P&gt;
&lt;P class=MsoNormal&gt;I also plan to incorporate these TYR posts&amp;nbsp;into my eventual FAQ on Computer Security Common Sense.&lt;/P&gt;
&lt;LI&gt;An earlier effort was via 
&lt;P class=MsoNormal&gt;&lt;A href=&quot;http://www.TechRepublic.com/forumdiscuss/thread_detail.jhtml?thread_id=20600&quot;&gt;&lt;a href=&quot;http://www.TechRepublic.com/forumdiscuss/thread_detail.jhtml?thread_id=20600&quot;&gt;http://www.TechRepublic.com/forumdiscuss/thread_detail.jhtml?thread_id=20600&lt;/a&gt;&lt;/A&gt;&lt;/P&gt;
&lt;LI&gt;&amp;nbsp;go to the archives of &lt;A href=&quot;http://www.year2000.com/ecommerce&quot;&gt;&lt;a href=&quot;http://www.year2000.com/ecommerce&quot;&gt;http://www.year2000.com/ecommerce&lt;/a&gt;&lt;/A&gt; &lt;SPAN style=&quot;FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;and search for the post I made called &quot;Computer Myths&quot;&lt;/SPAN&gt; 
&lt;LI&gt;When you are past this crisis, go visit&amp;nbsp;Internet Storm Watch &lt;SPAN style=&quot;FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;&lt;a href=&quot;http://www.incidents.org/isw/iswp.php&quot;&gt;http://www.incidents.org/isw/iswp.php&lt;/a&gt;&lt;/SPAN&gt; 
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;
&lt;P&gt;&amp;nbsp;Basically they have software so that people&apos;s Firewalls can send copies of Intrusion Logs to this outfit.&lt;SPAN style=&quot;mso-spacerun: yes&quot;&gt;&amp;nbsp; &lt;/SPAN&gt;They merge logs &amp;amp; sort by where the trouble is originating &amp;amp; notify the ISPs of the hackers &amp;amp; work with law enforcement to track the hackers down &amp;amp; put them out of business.&lt;SPAN style=&quot;mso-spacerun: yes&quot;&gt;&amp;nbsp; &lt;/SPAN&gt;This is a beautiful concept &amp;amp; I betcha a lot of people are not aware that this is going on, such as the people making federal government pronouncements these days about computer security.&lt;/P&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;
&lt;P&gt;&amp;nbsp;&lt;A href=&quot;http://www.radium.ncsc.mil/tpep/epl/epl-by-vendor.html&quot;&gt;&lt;a href=&quot;http://www.radium.ncsc.mil/tpep/epl/epl-by-vendor.html&quot;&gt;http://www.radium.ncsc.mil/tpep/epl/epl-by-vendor.html&lt;/a&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;There is such a thing as a secure computer system.&lt;/P&gt;
&lt;P class=MsoNormal&gt;There is such a thing as a computer system that can be made secure.&lt;/P&gt;
&lt;P class=MsoNormal&gt;Various government agencies, such as the military, have some standards for security that computer systems that they buy &amp;amp; install need to meet.&amp;nbsp; Then a new bunch of people get elected and want nothing to do with the work that was done by their enemy in the political party that was in charge before, and they reinvent the wheel.&lt;/P&gt;
&lt;P class=MsoNormal&gt;Here is a directory of secure systems by vendor.&lt;/P&gt;
&lt;P class=MsoNormal&gt;Some vendors are conspicuous by their absense.&lt;/P&gt;
&lt;P class=MsoNormal&gt;Some vendors that are here, I would study the small print with great interest.&lt;/P&gt;
&lt;P class=MsoNormal&gt;There are technical documents here explaining ..if you get such &amp;amp; such a system that can be made secure ... how to go about doing so.&lt;/P&gt;&lt;/SPAN&gt;
&lt;LI&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;
&lt;P class=MsoNormal&gt;If you reading this and you really in government, politics, law enforcement, and saying &lt;STRONG&gt;Oh Al, you too cynical, but this stuff is constructive, &lt;/STRONG&gt;then prove to me you really are in a position to change policy or to go after the computer criminals&lt;STRONG&gt; &lt;/STRONG&gt;(I not going to send some of my stuff to malware creators pretending to be cybercops), I could send you as an e-mail attachment collection of some posts I have made to Government sites soliciting Security Tips, such as what I think needs to be done about Terrorists and Airport Security.&amp;nbsp; &lt;/P&gt;&lt;/SPAN&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;
&lt;P class=MsoNormal&gt;My Air Security to FBI document is what I posted 10 days after 9/11 after I calmed down and checked phraseology and elegance of my writing.&lt;/P&gt;&lt;/SPAN&gt;
&lt;LI&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;
&lt;P class=MsoNormal&gt;My Security Gov document has what I sent to the Gore commission back when there were all the arsons of Black Churches, the&amp;nbsp;terrorist attack in Atlanta GA, and some suspicion that an American airliner had been brought down by a surface to air missile.&lt;/P&gt;&lt;/SPAN&gt;
&lt;LI&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;
&lt;P class=MsoNormal&gt;My Cyber TV Word document has collection of places allegedly selling illegal consumer electronics, through spam, which I want to share with any law enforcement that really wants to crack down on such places.&amp;nbsp; When I see spam that seems obviously for some illegal enterprise and they stupid enough to give name of place to send money to, I think in terms of starting such a collection of places to share with law enforcement, if we can ever figure out how not to drown them in millions of spam forwards.&lt;/P&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;LI&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;
&lt;P class=MsoNormal&gt;Lobby inside your corporation to get a real computer security audit, or to have your annual financial auditors do a computer security audit.&amp;nbsp; It does not matter if you run your biz on Microsoft Operating System, one of IBM&apos;s, Unix, Linux, etc.&amp;nbsp; You can get a competent audit.&amp;nbsp; There are audits designed for major ERP packages.&amp;nbsp;&amp;nbsp; Check out&amp;nbsp; &lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;A href=&quot;http://www.pentasafe.com&quot;&gt;&lt;a href=&quot;http://www.pentasafe.com&quot;&gt;http://www.pentasafe.com&lt;/a&gt;&lt;/A&gt; ... basically IS security management lets them load this thing that rattles your computer door knobs and gives a report on how many insecure entrances you have, and makes computer security policy reccommendations based on where your biz is most at risk.&amp;nbsp; It does not provide any info that would help the bad guys, and it communicates at a level understandable to non-technical management.&lt;/P&gt;&lt;/SPAN&gt;
&lt;LI&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;
&lt;P class=MsoNormal&gt;Here is a place for computer security technical professionals&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;a href=&quot;http://groups.yahoo.com/group/e-com-sec/&quot;&gt;http://groups.yahoo.com/group/e-com-sec/&lt;/a&gt;&lt;/P&gt;&lt;/SPAN&gt;
&lt;LI&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;
&lt;P class=MsoNormal&gt;&amp;nbsp;&lt;a href=&quot;http://www.ifccfbi.gov&quot;&gt;http://www.ifccfbi.gov&lt;/a&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;There is a depth to this computer fraud complaint operation that goes beyond what is apparent to most consumers.&lt;SPAN style=&quot;mso-spacerun: yes&quot;&gt;&amp;nbsp; &lt;/SPAN&gt;Law enforcement individuals doing investigations can post here that they are interested in a particular business, web site, suspect, etc. then there are regular searches to see if two or more policepersons expressed an interest in the same suspect, within the last 24 hours &amp;amp; an e-mail is sent to introduce them to each other.&lt;SPAN style=&quot;mso-spacerun: yes&quot;&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&amp;nbsp;Computer crime is global.&lt;SPAN style=&quot;mso-spacerun: yes&quot;&gt;&amp;nbsp; &lt;/SPAN&gt;The victims are global.&lt;SPAN style=&quot;mso-spacerun: yes&quot;&gt;&amp;nbsp; &lt;/SPAN&gt;Law enforcement personnel could be working in duplicate investigations except for this cooperative venture.&lt;/P&gt;&lt;/SPAN&gt;
&lt;LI&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;
&lt;P class=MsoNormal&gt;&amp;nbsp;&lt;a href=&quot;http://www.icsa.net/html/labs/&quot;&gt;http://www.icsa.net/html/labs/&lt;/a&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&amp;nbsp;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;I think I have the right link here.&lt;SPAN style=&quot;mso-spacerun: yes&quot;&gt;&amp;nbsp; &lt;/SPAN&gt;I found this outfit when researching what firewall to get for my home PC.&lt;SPAN style=&quot;mso-spacerun: yes&quot;&gt;&amp;nbsp; &lt;/SPAN&gt;They have firewalls from 40 some outfits on PCs connected to the internet &amp;amp; they continuously bombard them with every piece of nonsense the malware people come up with.&lt;SPAN style=&quot;mso-spacerun: yes&quot;&gt;&amp;nbsp; &lt;/SPAN&gt;What they are doing is quality testing the fact that the firewalls really do what they are advertised to do.&lt;SPAN style=&quot;mso-spacerun: yes&quot;&gt;&amp;nbsp; &lt;/SPAN&gt;Many popular brand names are conspicuous by their absence from the list of firewalls that do in fact do what they are advertised to do.&lt;/SPAN&gt;&lt;/P&gt;&lt;/SPAN&gt;
&lt;LI&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;
&lt;P class=MsoNormal&gt;One of my computer security e-mail contacts sent me his Computer Security Glossary that spells out his honey pot strategy for keeping an intruder distracted long enough to back trace him.&amp;nbsp; I personally feel people time better spent keeping the intruders out in the first place, but my view is a minority in the West today.&lt;/P&gt;&lt;/SPAN&gt;
&lt;LI&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;
&lt;P class=MsoNormal&gt;Another contact sent me copy of Halcrow&apos;s draft policy on corporate Computer Security Policy.&lt;/P&gt;&lt;/SPAN&gt;
&lt;LI&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;
&lt;P class=MsoNormal&gt;I am collecting goodies like these, and then can share some with other people making similar collections.&lt;/P&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/08/29.html#a170</guid>
			<pubDate>Thu, 29 Aug 2002 16:33:08 GMT</pubDate>
			<source url="http://radio.weblogs.com/0111198/rss.xml">Blogfish</source>
			</item>
		<item>
			<description>&lt;P&gt;[&lt;A href=&quot;http://www.bruceoleary.com/categories/computing/&quot;&gt;Bruce&apos;s Computing Category&lt;/A&gt;] passes on news of Radio&apos;s change to referrer visibility.&amp;nbsp; QUOTE&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;&lt;A href=&quot;http://radio.userland.com/moreVisibleInRefererLogs&quot;&gt;A tiny change&lt;/A&gt; in Radio&apos;s aggregator makes referer logs more interesting. Please read this if you provide an RSS source for Radio users, and you watch your referer logs. &lt;I&gt;Updated.&lt;/I&gt; [&lt;A href=&quot;http://www.scripting.com/&quot;&gt;Scripting News&lt;/A&gt;]&lt;/P&gt;
&lt;P&gt;Well I don&apos;t watch my referer logs every day, but I do check them from time to time.&lt;/P&gt;
&lt;P&gt;UNQUOTE [&lt;A href=&quot;http://www.bruceoleary.com/categories/computing/&quot;&gt;Bruce&apos;s Computing Category&lt;/A&gt;] &lt;/P&gt;
&lt;P&gt;[&lt;A href=&quot;http://www.bruceoleary.com/2002/06/06.html#a274&quot;&gt;Bruce&apos;s Place&lt;/A&gt;] shares a story QUOTE&lt;A name=a274&gt;&lt;/A&gt; 
&lt;TABLE cellPadding=1 width=&quot;100%&quot;&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD vAlign=top&gt;&lt;BR&gt;&lt;A href=&quot;http://www.wired.com/news/technology/0,1282,52997,00.html&quot;&gt;Dead Men Tell No Passwords&lt;/A&gt;&lt;BR&gt;The man in charge of some of Norway&apos;s most precious electronic documents died without divulging the way to access them. A plea to hackers to help crack the system is out. By Michelle Delio. [&lt;A href=&quot;http://www.wired.com/&quot;&gt;Wired News&lt;/A&gt;]&lt;BR&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;UNQUOTE [&lt;A href=&quot;http://www.bruceoleary.com/2002/06/06.html#a274&quot;&gt;Bruce&apos;s Place&lt;/A&gt;] &lt;/P&gt;
&lt;P&gt;If the security works, why break it?&amp;nbsp; If the documents cannot be accessed, and the only person who knew how to access them died, then it is as if the data was in the man&apos;s head and he died.&amp;nbsp; There is something wrong with this picture.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;Where I work, I have some computer security responsibilities, but they are not exclusively in my head.&amp;nbsp; With each new boss, I ask if I can give a briefing on what kind of computer security we have, and what to do if I get run over by the proverbial union truck.&amp;nbsp; One of my suggestions is to provide on paper, a list of the most secret passwords to get into such things as computer security itself, then that paper is to go in an envelope in the safe of our corporate lawyer or auditor or some outside firm that we have some confidentiality agreement with, then if anything happens to me or my boss, there is this backup of the most important corporate stuff that is in our brains.&amp;nbsp; When I change the master security access codes, I tell my boss that I did so, and why I did so.&lt;/P&gt;
&lt;P&gt;After a new boss has been on board a year or two, I ask if I can give a briefing on the strengths and weaknesses of our computer security.&amp;nbsp; We do get intruder alerts, and I notify the managers involved.&amp;nbsp; For example, executives are out to lunch, and some unknown person is in their office trying different password combinations, then the computer security kicks in and pulls the plug on that work station (you only get a certain number tries to forget your password, then computer security makes certain automatic assumptions), then a few minutes later history repeats at the next office down the hall.&amp;nbsp; Then a few hours later, I am reviewing the system message logs and discover the fact that this was happening.&amp;nbsp; I have made some changes to the system logging so that we discover this kind of stuff faster.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/08/29.html#a168</guid>
			<pubDate>Thu, 29 Aug 2002 07:55:33 GMT</pubDate>
			</item>
		<item>
			<description>&lt;P&gt;The Bush administration is calling for a centralized Network Operations Center (NOC) to coordinate cyber-security warnings, says &lt;A href=&quot;http://www.eweek.com/article2/0,3959,484669,00.asp&quot;&gt;this week&apos;s e-week&lt;/A&gt;.&amp;nbsp; Previously Computer Security has been voluntary and optional, but the feds want corporations to disclose what they are doing, if anything, towards that goal.&amp;nbsp; The feds do not know if there is any such thing as&amp;nbsp;&lt;A href=&quot;http://www.eweek.com/article2/0,3959,484678,00.asp&quot;&gt;secure wireless technology&lt;/A&gt;, and if none, no federal agency is to buy any.&amp;nbsp; I wonder what the military will do to communicate with planes in the sky and ships at sea, if this ban goes into effect.&lt;/P&gt;
&lt;P&gt;&lt;FONT color=red&gt;&lt;STRONG&gt;Wednesday &lt;/STRONG&gt;&lt;/FONT&gt;= no posts except updates to some stories and categories (access my collection via &quot;Radio url number system&quot;) because my health was temporarily impaired (I suspect a new food allergy ... as we get older, our body discovers new things to complain about).&lt;/P&gt;
&lt;P&gt;&lt;FONT color=red&gt;&lt;STRONG&gt;Tuesday topics&lt;/STRONG&gt;&lt;/FONT&gt;:&amp;nbsp; Blog Education; Computer Illiteracy; Current Events; Politics; Quality; Tara Sue Grubb vs. Howard Coble;&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/08/29.html#a164</guid>
			<pubDate>Thu, 29 Aug 2002 06:44:55 GMT</pubDate>
			</item>
		<item>
			<description>&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;&lt;FONT color=purple&gt;[&lt;A href=&quot;http://radio.weblogs.com/0104634/&quot;&gt;Ernie the Attorney&lt;/A&gt;]&lt;/FONT&gt;&lt;/U&gt;&lt;/STRONG&gt; QUOTE &lt;/P&gt;
&lt;P&gt;Copyright Law - what should it be? I agree with &lt;A href=&quot;http://www.hyperorg.com/blogger/index.html#85374247&quot;&gt;&lt;FONT color=blue&gt;this statement.&lt;/FONT&gt;&lt;/A&gt; &lt;/P&gt;
&lt;P&gt;UNQUOTE [&lt;A href=&quot;http://radio.weblogs.com/0104634/&quot;&gt;Ernie the Attorney&lt;/A&gt;]&lt;/P&gt;
&lt;P&gt;Here&apos;s what I believe / desire.&lt;/P&gt;
&lt;P&gt;Capitalism belongs to many shareholders: Employees with decent jobs and investments in 401k or other retirement plans; Stockholders; Management Executives; Creditors; Customers who expect Integrity with respect to product service promises, whether they are on the side of the box of purchase, in the documentation, contract, any advertising.&amp;nbsp; As new rules are imposed, we should have both notification of the rule changes, and able to opt out of whatever arrangement got us there.&amp;nbsp; If a company not like new SEC rules, they should be allowed to offer their shareholders more than the stock is worth, so they can quit being a public company.&lt;/P&gt;
&lt;P&gt;Industries should have special protection when they are new, such as Cable TV was protected against Broadcast TV, but this protection should not last forever.&amp;nbsp; As technology advances, the Horse and Buggy Entertainment Industry does not have a Constitutional right to permanent existance.&lt;/P&gt;
&lt;P&gt;Contracts need to be in plain English.&amp;nbsp; Incomprehensible Contracts should be automatically null and void until they get re-written.&amp;nbsp; People with disabilities ought to have the right to access to contracts and key documents in a form that they can read or hear.&amp;nbsp; See &quot;Blind of NH&quot; for what reality is instead.&lt;/P&gt;
&lt;P&gt;Artists and Writers and other creators of Intellectual Property need to get proper compensation for their labors so as to provide incentive to future quality.&amp;nbsp; Look at it this way, over 300 firemen died in the WTC, but they are not paid enough money to live in NYC without their families having a second job.&amp;nbsp; The people we value, be they teachers or parents, they need to have honest access to enough money for a quality life. &lt;/P&gt;
&lt;P&gt;Public Libraries available to everyone regardless of economic status, in which the public can take turns reading what is in the library, and the publishers do get financially compensated because their books are distributed to thousands of libraries all over the planet.&amp;nbsp; Ditto rent a movie at the video store.&amp;nbsp; We are not supposed to make our own personal copies of what we borrowed.&amp;nbsp; We can also have Private Exchanges, whether flea market or auction.&amp;nbsp; We show up with books videos whatever that we are done with, trade them with other people, go home with new selections.&lt;/P&gt;
&lt;P&gt;Schools have text books in which they may contract with the publishers for permission to make cheap copies, and pay a royalty for doing so, just like non-profit theatrical performances and churches are allowed to buy one copy of sheet music or a play, make photocopies for all performances, and pay a fee to the publisher based on size of audience and number of performances.&lt;/P&gt;
&lt;P&gt;Home Computer technology is still in its infancy with great potential.&amp;nbsp; I say infancy because it is so fragile.&amp;nbsp; How often do you have to reboot your Operating System?&amp;nbsp; When something goes wrong, how fast do you find out what it is and get it fixed with assurance that nothing else will go wrong for a while?&lt;/P&gt;
&lt;P&gt;I do not approve of &lt;A href=&quot;http://www.techcentralstation.com/1051/techwrapper.jsp?PID=1051-250&amp;amp;CID=1051-082202B&quot;&gt;high tech vigilanteism,&lt;/A&gt; just as I do not approve of real world vigilanteism.&lt;/P&gt;
&lt;P&gt;If it appears like someone is doing improper behavior, prove it in small claims computer court, or gather evidence for a computer crimes court where the suspect can face accuser with both sides access to competent technical witnesses.&amp;nbsp; The state of art of software to catch improper actions is pretty dismal.&amp;nbsp; How often do we have to update our anti-virus protection?&amp;nbsp; How many false positives does spam blocking filters generate?&lt;/P&gt;
&lt;P&gt;I do approve of the government attempting to protect the citizenry from future attacks by terrorists.&amp;nbsp; In a war it is sometimes neccessary to do things that would never happen in peacetime.&amp;nbsp; Individuals, who are dedicated to the other side and who will never surrender or stand down, they need to be locked up in perpetuity, but there also needs to be some proof that these people are in fact guilty of being the enemy.&amp;nbsp; It is an extremely slippery slope to allow government to lock people up, with no legal protections such as a defense attorney, based on mere suspicion, or to spy on the people without &lt;A href=&quot;http://research.yale.edu/lawmeme/&quot;&gt;probable cause as defined by the court system&lt;/A&gt;.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/08/23.html#a135</guid>
			<pubDate>Fri, 23 Aug 2002 21:12:50 GMT</pubDate>
			<source url="http://radio.weblogs.com/0104634/rss.xml">Ernie the Attorney</source>
			</item>
		<item>
			<description>&lt;P&gt;The Greenpeace Blog has lots of interesting stuff, and also a few design bugs.&amp;nbsp; I did a post to their comments area, and it still says zero comments.&amp;nbsp; Gilla asks for people to e-mail suggestions to her (him?) but where&amp;nbsp;the e-mail link invokes my old AOL archives (I am now using Eudora for my e-mail).&lt;/P&gt;
&lt;P&gt;I can&apos;t figure out how to Radio subscribe to [&lt;A href=&quot;http://weblog.greenpeace.org/&quot;&gt;&lt;a href=&quot;http://weblog.greenpeace.org/&quot;&gt;http://weblog.greenpeace.org/&lt;/a&gt;&lt;/A&gt;&amp;nbsp;powered by Moveable Type] QUOTE&lt;/P&gt;
&lt;P&gt;a comprehensive list of &lt;A href=&quot;http://www.greenpeaceusa.org/living/001013_ants.html&quot;&gt;safer ways to avoid invasions of indoor pests&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&quot;Spiders:&lt;BR&gt;Under ideal conditions, do not kill spiders because they help to control pests.&quot; &lt;/P&gt;
&lt;P&gt;Every web developer should read this &lt;A href=&quot;http://diveintoaccessibility.org/&quot;&gt;book&lt;/A&gt;, since more and more people with disabilites access websites and they simply cannot be left out.&lt;/P&gt;
&lt;P&gt;also check out their&amp;nbsp;&lt;A href=&quot;http://www.greenpeaceusa.org/nuclear/locator.htm&quot;&gt;zip code nuclear reactor finder&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;UNQUOTE [&lt;A href=&quot;http://weblog.greenpeace.org/&quot;&gt;&lt;a href=&quot;http://weblog.greenpeace.org/&quot;&gt;http://weblog.greenpeace.org/&lt;/a&gt;&lt;/A&gt;] &lt;/P&gt;
&lt;P&gt;Lots more good stuff in their archives.&lt;/P&gt;
&lt;P&gt;I saw on C-Span not so long ago that &lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;100% of the US nuclear power plants were tested for terrorist threats. 
&lt;LI&gt;50% of them failed the test for NORMAL terrorist attacks. 
&lt;LI&gt;NONE of them passed any test for protection against cyber attacks. 
&lt;LI&gt;The problem is that control systems, like Air Traffic Control, Water Treatment, etc. were built as stand alone units, with zero consideration for any security other than physical security.&amp;nbsp; Now corporate and government managers are linking those instruments to their computer networks because they want to know what&apos;s going on, but many networks are brain brain dead on security, because after all, the information in the networks are not that important to protect, but that is not the case for some of these control systems. 
&lt;LI&gt;This management philosophy gave us the Challenger disaster. 
&lt;LI&gt;I fear we are overdue for another disaster.&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/08/19.html#a108</guid>
			<pubDate>Mon, 19 Aug 2002 23:16:21 GMT</pubDate>
			</item>
		<item>
			<description>&lt;P&gt;&lt;FONT color=red&gt;&lt;STRONG&gt;Computer Security &lt;/STRONG&gt;&lt;/FONT&gt;need not be Rocket Science.&amp;nbsp; I have a bunch of links, some of which I have not recently visited, so some might be broken.&amp;nbsp; All of this stuff is excerpted from Al Mac&apos;s Computer Security Myths project, not yet ready for prime time sharing.&amp;nbsp; But I thought I would mention a few things in the wake of some contrary views recently published by other voices.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Send an e-mail with any subject heading to &lt;A href=&quot;mailto:subscribe@talkbiz.com&quot;&gt;&lt;a href=&quot;mailto:mailto:subscribe@talkbiz.com&quot;&gt;mailto:subscribe@talkbiz.com&lt;/a&gt;&lt;/A&gt;&amp;nbsp; 
&lt;LI&gt;Within a few minutes you will get back a long e-mail article 
&lt;LI&gt;Data Security 101 For Small Businesses 
&lt;LI&gt;From Paul Myers&lt;/LI&gt;&lt;/UL&gt;
&lt;P&gt;When we install software on our PCs, sometimes the software vendor thinks they know more about us about what is best for us, so it pays occasionally to do a personal computer security audit.&amp;nbsp; You don&apos;t need to be an expert to do this.&amp;nbsp; Just visit &lt;SPAN style=&quot;FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;&lt;A href=&quot;http://grc.com/default.htm&quot;&gt;&lt;a href=&quot;http://grc.com/default.htm&quot;&gt;http://grc.com/default.htm&lt;/a&gt;&lt;/A&gt; Shields Up then Test - do both tests, then check FAQ on site.&amp;nbsp; There are many other web sites with similar services.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;This story in the Boston Globe examines the reasons why today&amp;#146;s teachers are using computers &amp;amp; the Internet quite heavily everywhere except in the classrooms for their students.&lt;SPAN style=&quot;mso-spacerun: yes&quot;&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal&gt;&lt;A href=&quot;http://www.boston.com/dailyglobe2/329/focus/System_crash+.shtml&quot;&gt;&lt;a href=&quot;http://www.boston.com/dailyglobe2/329/focus/System_crash+.shtml&quot;&gt;http://www.boston.com/dailyglobe2/329/focus/System_crash+.shtml&lt;/a&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;SPAN style=&quot;COLOR: black; FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;Some software vendors sell security software they do not use themselves &lt;SPAN style=&quot;COLOR: black; FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;&lt;BR&gt;&lt;A href=&quot;http://securityportal.com/closet/closet20000705.html&quot;&gt;&lt;a href=&quot;http://securityportal.com/closet/closet20000705.html&quot;&gt;http://securityportal.com/closet/closet20000705.html&lt;/a&gt;&lt;/A&gt;&lt;BR style=&quot;mso-special-character: line-break&quot;&gt;&lt;BR style=&quot;mso-special-character: line-break&quot;&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;A business enterprise can organize an audit of all computers on their network using products from companies like&amp;nbsp; &lt;A href=&quot;http://www.pentasafe.com&quot;&gt;&lt;a href=&quot;http://www.pentasafe.com&quot;&gt;http://www.pentasafe.com&lt;/a&gt;&lt;/A&gt; and in fact ordinary auditors who know nothing about computers can include security in a standard audit.&amp;nbsp; Basically they install software from pentasafe on the client&apos;s computer system, it runs a bunch of tests, and generates a report, on such things as passwords too easily guessable, passwords not changed in eons, and other topics that are related to the particular operating system used ... most Microsoft, IBM, and others such as UNIX are supported.&amp;nbsp; The reports do not identify the actual passwords that are not secure, just report card on the degree to which the system is not very secure.&lt;/P&gt;
&lt;P&gt;From time to time the government gets interested in computer security and tries to figure out standards that are going to work.&amp;nbsp; In a previous iteration than what is going on right now, the standards were also tested to make sure the security ideas really worked.&amp;nbsp; This led to a system of measuring which computer systems measured up to the security standards.&amp;nbsp; Take a look at &lt;SPAN style=&quot;mso-spacerun: yes&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href=&quot;http://www.radium.ncsc.mil/tpep/epl/epl-by-vendor.html&quot;&gt;&lt;a href=&quot;http://www.radium.ncsc.mil/tpep/epl/epl-by-vendor.html&quot;&gt;http://www.radium.ncsc.mil/tpep/epl/epl-by-vendor.html&lt;/a&gt;&lt;/A&gt;&amp;nbsp;and see which computer systems are conspicuous by their absense.&lt;/P&gt;
&lt;P&gt;The FBI has published a list of the most common computer security errors that everyone, all businesses, tend to repeat.&amp;nbsp; &lt;A href=&quot;http://www.sans.org/top20.htm&quot;&gt;&lt;a href=&quot;http://www.sans.org/top20.htm&quot;&gt;http://www.sans.org/top20.htm&lt;/a&gt;&lt;/A&gt; There is also a searchable&amp;nbsp;index of known computer security risks at &lt;A href=&quot;http://cve.mitre.org/cve/&quot;&gt;&lt;a href=&quot;http://cve.mitre.org/cve/&quot;&gt;http://cve.mitre.org/cve/&lt;/a&gt;&lt;/A&gt;&amp;nbsp; Here&apos;s a&amp;nbsp;collection of Security Recommendation Guides &lt;SPAN style=&quot;FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;from the National Security Agency of the US Government &lt;SPAN style=&quot;FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;&lt;A href=&quot;http://nsa1.www.conxion.com/&quot;&gt;&lt;a href=&quot;http://nsa1.www.conxion.com/&quot;&gt;http://nsa1.www.conxion.com/&lt;/a&gt;&lt;/A&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;One of the IBM platforms has a data base system in which business rules can be specified at the file level, such that it does not matter what software tool is used by any user or intruder, the rules cannot be broken.&amp;nbsp; One vendor has taken this to an extreme and offers a system in which the only thing on the system are the business rules, run a business with no commercial software whatsoever.&amp;nbsp; This &lt;SPAN style=&quot;FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;&lt;A href=&quot;http://www.erros.co.uk/&quot;&gt;&lt;a href=&quot;http://www.erros.co.uk/&quot;&gt;http://www.erros.co.uk/&lt;/a&gt;&lt;/A&gt; can be a bit difficult to wrap your mind around, so check out the review at &lt;SPAN style=&quot;FONT-FAMILY: &apos;Times New Roman&apos;; FONT-SIZE: 12pt; mso-fareast-font-family: &apos;Times New Roman&apos;; mso-ansi-language: EN-US; mso-fareast-language: EN-US; mso-bidi-language: AR-SA&quot;&gt;&lt;A href=&quot;http://www.400times.co.uk/Documents/ERROS1.htm&quot;&gt;&lt;a href=&quot;http://www.400times.co.uk/Documents/ERROS1.htm&quot;&gt;http://www.400times.co.uk/Documents/ERROS1.htm&lt;/a&gt;&lt;/A&gt; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/08/15.html#a73</guid>
			<pubDate>Fri, 16 Aug 2002 02:27:53 GMT</pubDate>
			</item>
		<item>
			<description>&lt;P&gt;e-Privacy assurances in our climate of anti-terrorism legislation is the topic of &lt;A href=&quot;http://www.eweek.com/article2/0,3959,463142,00.asp&quot;&gt;this&lt;/A&gt; e-week column by &lt;FONT color=red&gt;&lt;STRONG&gt;John Taschek&lt;/STRONG&gt;&lt;/FONT&gt;.&amp;nbsp; &lt;A href=&quot;http://radio.weblogs.com/0104634/2002/08/12.html#a1063&quot;&gt;Ernie the Attorney&lt;/A&gt; offers this link to &lt;STRONG&gt;&lt;FONT color=red&gt;Charles C. Mann &lt;/FONT&gt;&lt;/STRONG&gt;Atlantic &lt;A href=&quot;http://www.theatlantic.com/issues/2002/09/mann.htm&quot;&gt;Homeland Insecurity&lt;/A&gt; article on security systemic problems in general, and here is Ernie&apos;s &lt;A href=&quot;http://radio.weblogs.com/0104634/2002/08/05.html#a1019&quot;&gt;earlier post&lt;/A&gt; on Security in general.&amp;nbsp; Here are some examples of our general state of Insecurity thinking.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The US government has several networks never connected to the Internet, accessible only withing physically secure buildings.&amp;nbsp; But they&apos;ve been infected by computer viruses because humans with lap tops connect to both the Internet and the secure networks, and bypass the security.&amp;nbsp; The weakest link are the government users. 
&lt;LI&gt;Kerkhoff&apos;s Principle:&amp;nbsp; A good crypto system QUOTE should be able to fall into the enemy&apos;s hands without disadvantage.&amp;nbsp; UNQUOTE 
&lt;LI&gt;Encrypting Internet transactions, says Purdue computer scientist &lt;FONT color=red&gt;&lt;STRONG&gt;Eugene Spafford&lt;/STRONG&gt;&lt;/FONT&gt;, QUOTE is the equivalent of arranging an armored car to deliver credit-card info from someone living in a cardboard box to someone living on a park bench.&amp;nbsp; UNQUOTE 
&lt;LI&gt;Airport Security thinks that protection against car bombings is practical by having cars park 300 feet away from the terminal, but at the same time passengers can be dropped off right in front of the terminal.&amp;nbsp; That does not compute. 
&lt;LI&gt;Airports have to be evacuated all the time because of security breaches.&amp;nbsp; There is no way to shut down just the portion of the people movement where the problem occurred. 
&lt;LI&gt;Carjacking is on the rise partly because Automobile Manufacturers have made it more difficult to hot wire an unattended vehicle. 
&lt;LI&gt;QUOTE Bank Vaults are secure because to break in takes real skill. 
&lt;LI&gt;Computers are not, because to break in takes practically no skill. 
&lt;LI&gt;Millions of credit card numbers have been stolen from computer networks.&amp;nbsp; UNQUOTE 
&lt;LI&gt;German reporters tested a face recognition system, and iris scanner, and nine fingerprint readers.&amp;nbsp; All of them could be spoofed using output from a lap top screen.&amp;nbsp; They photographed an authorized user, blew up the face, cut out the pupils, help the image before their faces like a mask, and the iris scanner was spoofed. An authorized user&apos;s fingerprints were lifted from a drinking glass, on a tape pressed against the fingerprint reader, which accepted the data as valid. 
&lt;LI&gt;A corporation replaced paper ballots with electronic shareholder voting, which was hacked into.&amp;nbsp; Now they cannot reconstruct original votes. 
&lt;LI&gt;Since 9/11, at least 40 government networks have been cracked by vandals. 
&lt;LI&gt;People have trouble with passwords so an easy way to do industrial espionage is to offer pornographic web sites to business people in which they need a password.&amp;nbsp; Odds are they would use the same password there as for everywhere else.&lt;/LI&gt;&lt;/UL&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/08/13.html#a60</guid>
			<pubDate>Wed, 14 Aug 2002 02:00:52 GMT</pubDate>
			</item>
		<item>
			<description>&lt;P&gt;I have recently rediscovered some stuff we can do with Radio News Aggregation (subscribing to other web sites whose traffic particularly interests us).&amp;nbsp; Oh yes, I had read the documentation and struggled to understand what it all means.&amp;nbsp; But sometimes the DOING is educational.&lt;/P&gt;
&lt;P&gt;Thanks to &lt;FONT color=red&gt;&lt;STRONG&gt;Dave Winer &lt;/STRONG&gt;&lt;/FONT&gt;[&lt;A href=&quot;http://www.scripting.com/&quot;&gt;Scripting News&lt;/A&gt;] link to &lt;STRONG&gt;&lt;FONT color=red&gt;Ray Ozzie &lt;/FONT&gt;&lt;/STRONG&gt;on &lt;A href=&quot;http://www.ozzie.net/blog/stories/2002/08/12/architectureMattersTheRebirthOfPublicDiscussion.html&quot;&gt;why weblogs are good&lt;/A&gt; for discourse. Yes. Flames don&apos;t attract. New ideas do. Weblogs can have a high signal-to-noise ratio. Powerful statements are possible in this medium, where powerlessness rules in discussion fora. In this medium everyone can have the last word.&amp;nbsp; UNQUOTE&amp;nbsp;[&lt;A href=&quot;http://www.scripting.com/&quot;&gt;Scripting News&lt;/A&gt;] &lt;/P&gt;
&lt;P&gt;I agree with Ray that architecture can be critical.&amp;nbsp; We see in the Computer Security debate that people are trying the impossible.&amp;nbsp; We have software out there that did not have security considered in the original design, so it is like putting a padlock on a tent, or a house of cards, to make the results secure after the fact, when it is discovered that security should have been there all along.&lt;/P&gt;
&lt;P&gt;The power of a network are the number of people connected to it.&amp;nbsp; The value of a fax machine is the fact that millions of other businesses are networked to that technology.&amp;nbsp; With many architectures we have unwanted participants: flames; spam; intruders; other dysfunctional human behavior, that we label as noise getting in the way of useful signal content.&amp;nbsp; Ray is absolutely correct that the signal to noise ratio is extremely high with Blogging.&amp;nbsp; Plus, he does a great job of explaining how the architecture of Blogging makes that a reality.&lt;/P&gt;
&lt;P&gt;One downside of this is the risk that Blogging will eat excessive amounts of our time that could be more constructively expended.&amp;nbsp; Just as earlier generations of technological enthusiasts became TV couch potatoes, or in my case I used to spend hours every day dealing with e-mail, because there were hundreds of interesting posts I wanted to read, but I had to wade through a high ratio of spam and virus forwardings to get at the good stuff.&lt;/P&gt;
&lt;P&gt;By moving from AOL to Eudora, my e-mail is automatically categorized into that which I can look at any old time, and the more urgent categories.&amp;nbsp; I can always go to the directory of mailboxes and highlighted are which boxes contain e-mail not yet opened.&lt;/P&gt;
&lt;P&gt;News Aggregation of Web Site subscriptions has something similar.&amp;nbsp; It comes in, but I do not need to look at it right away, and even if archives from weeks ago get lost, there is a continual stream of new fascinating material for my perusal.&lt;/P&gt;
&lt;P&gt;Personal 2 do list ... the last time I backed up my Radio was beginning of July, and since then I have increased my Web Subscriptions to 15, and made some alterations to my Template, let alone the posts here.&amp;nbsp; My desk top dynamics also have&amp;nbsp;changed.&amp;nbsp; My Screen Saver&apos;s unused CPU seconds are now working on&amp;nbsp;finding a cure for cancer &lt;A href=&quot;http://members.ud.com/about/&quot; eudora=&quot;autourl&quot;&gt;&lt;a href=&quot;http://members.ud.com/about/&quot;&gt;http://members.ud.com/about/&lt;/a&gt;&lt;/A&gt;&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/08/12.html#a50</guid>
			<pubDate>Mon, 12 Aug 2002 19:03:49 GMT</pubDate>
			<source url="http://www.scripting.com/rss.xml">Scripting News</source>
			</item>
		<item>
			<description>&lt;A href=&quot;http://blog.qaddisin.com/&quot;&gt;Security News&lt;/A&gt; Blog = another interesting site.</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/08/12.html#a44</guid>
			<pubDate>Mon, 12 Aug 2002 08:32:48 GMT</pubDate>
			</item>
		<item>
			<description>&lt;P&gt;Guide to Real World (as opposed to Internet Virtual Reality) &lt;A href=&quot;http://www.nbc4.com/lawscope&quot;&gt;Legal Topics&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;We got these Terrorists in custody and we want to throw away the key, but how do the precedents compare to 50 years ago when America feared Loyal Japanese Citizens and wanted them locked up and throw away the key?&amp;nbsp; We think we are justified in locking up Terrorists without any trial, or access to a lawyer, or protections of the Geneva Convention on prisoners of war, and that the people 50 years ago were just racists.&lt;/P&gt;
&lt;P&gt;Domestic Issues (Husband Wife as opposed to Homeland Security).&lt;/P&gt;
&lt;P&gt;What should we do about these people who kidnap and abuse small children?&lt;/P&gt;
&lt;P&gt;Catholic Priests scandal.&lt;/P&gt;
&lt;P&gt;Computer Criminals.&lt;/P&gt;
&lt;P&gt;Various controversial law suits.&lt;/P&gt;
&lt;P&gt;These are hot topics, that &lt;A href=&quot;http://www.nbc4.com/lawscope&quot;&gt;Law Scope&lt;/A&gt; helps put in perspective for us.&lt;/P&gt;
&lt;P&gt;I hate it when a site disables the back button.&amp;nbsp; I want an icon that warns of that also.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/08/11.html#a34</guid>
			<pubDate>Mon, 12 Aug 2002 04:52:28 GMT</pubDate>
			</item>
		<item>
			<description>CDT&apos;s &lt;A href=&quot;http://www.cdt.org/privacy/guide/start/track.html&quot;&gt;Guide to On Line Privacy&lt;/A&gt;.</description>
			<guid>http://radio.weblogs.com/0107846/categories/security/2002/08/11.html#a33</guid>
			<pubDate>Mon, 12 Aug 2002 04:43:27 GMT</pubDate>
			</item>
		</channel>
	</rss>
