<?xml version="1.0"?>
<!-- RSS generated by Radio UserLand v8.0.8 on Sun, 08 Feb 2004 02:22:04 GMT -->
<rss version="2.0">
	<channel>
		<title>Spire Security News and Views</title>
		<link>http://radio.weblogs.com/0134433/</link>
		<description>Spire Security is a market research and analysis firm dedicated to bringing clarity to the information security world. This blog is focused on providing analysis and insight to the happenings of the day, current security trends, and missing pieces to the information security puzzle.</description>
		<copyright>Copyright 2004 Pete Lindstrom</copyright>
		<lastBuildDate>Sun, 08 Feb 2004 02:22:04 GMT</lastBuildDate>
		<docs>http://backend.userland.com/rss</docs>
		<generator>Radio UserLand v8.0.8</generator>
		<managingEditor>petelind@spiresecurity.com</managingEditor>
		<webMaster>petelind@spiresecurity.com</webMaster>
		<category domain="http://www.weblogs.com/rssUpdates/changes.xml">rssUpdates</category> 
		<cloud domain="radio.xmlstoragesystem.com" port="80" path="/RPC2" registerProcedure="xmlStorageSystem.rssPleaseNotify" protocol="xml-rpc"/>
		<ttl>60</ttl>
		<item>
			<description>&lt;P&gt;&lt;STRONG&gt;&lt;FONT face=Verdana,Geneva,Arial,Helvetica,Sans-Serif&gt;Email Notices&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;I consider myself fairly well-versed when it comes to security, but I must confess that I am completely baffled by the notices at the end of email messages. Here&apos;s one I saw recently: &lt;/FONT&gt;&lt;/P&gt;
&lt;BLOCKQUOTE dir=ltr style=&quot;MARGIN-RIGHT: 0px&quot;&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;&lt;EM&gt;&quot;Important Notice: This email is confidential, may be legally privileged, and is for the intended recipient only. Access, disclosure, copying, distribution, or reliance on any of it by anyone else is prohibited and may be a criminal offense. Please delete if obtained in error and email confirmation to the sender.&quot;&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P dir=ltr&gt;&lt;FONT face=Verdana&gt;Does anyone actually read these things? A couple of interesting points:&lt;/FONT&gt;&lt;/P&gt;
&lt;P dir=ltr&gt;&lt;FONT face=Verdana&gt;1) This particular notice was at the end of a message sent to a mailing list. A mailing list. So apparently the mailing list was prohibited from distributing the email to the rest of the mailing list. Although perhaps since the list was the intended recipient, that is okay. But is it confidential? This particular list has an archive on the web. Hmmm, they got past the first hurdle on the technicality, but this next one is a bit tougher.&lt;/FONT&gt;&lt;/P&gt;
&lt;P dir=ltr&gt;&lt;FONT face=Verdana&gt;2) How on earth would I know if I obtained it in error - it was addressed to &lt;EM&gt;me&lt;/EM&gt;. They sent it. Ok, I&apos;ll admit that sometimes I know things are sent by mistake, but still... just doesn&apos;t seem right.&lt;/FONT&gt;&lt;/P&gt;
&lt;P dir=ltr&gt;&lt;FONT face=Verdana&gt;3) I like the whole &quot;reliance&quot; angle - so if Bill Gates had this notice at the end of his emails, he could have told the courts they were committing a criminal offense by relying on all of those emails.&lt;/FONT&gt;&lt;/P&gt;
&lt;P dir=ltr&gt;&lt;FONT face=Verdana&gt;4) Doesn&apos;t the whole deletion thing mean something like &quot;I made a mistake, now you have to fix it for me, or you may be criminally liable&quot;?&lt;/FONT&gt;&lt;/P&gt;
&lt;P dir=ltr&gt;&lt;FONT face=Verdana&gt;Who can tell me with a straight face that any of this would hold up in court?&lt;/FONT&gt;&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0134433/2004/02/07.html#a10</guid>
			<pubDate>Sun, 08 Feb 2004 02:22:04 GMT</pubDate>
			<category>My Friends</category>
			<comments>http://radiocomments2.userland.com/comments?u=134433&amp;amp;p=10&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0134433%2F2004%2F02%2F07.html%23a10</comments>
			</item>
		<item>
			<description>&lt;P&gt;&lt;STRONG&gt;Bandwidth-based Web DDOS Attacks&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This article: &lt;A href=&quot;http://www.computerworld.com/securitytopics/security/story/0,10801,89932,00.html?f=x10&quot;&gt;Mydoom lesson: Take proactive steps to prevent DDoS attacks&lt;/A&gt;&amp;nbsp;discusses the problem of bandwidth DDOS attacks that are difficult to defend against. Distributing the servers is the key - a la Akamai.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0134433/2004/02/06.html#a9</guid>
			<pubDate>Sat, 07 Feb 2004 01:23:33 GMT</pubDate>
			<source url="http://www.computerworld.com/news/xml/10/0,5009,,00.xml">Computerworld News</source>
			<comments>http://radiocomments2.userland.com/comments?u=134433&amp;amp;p=9&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0134433%2F2004%2F02%2F06.html%23a9</comments>
			</item>
		<item>
			<description>&lt;P&gt;&lt;STRONG&gt;&lt;FONT face=Verdana,Geneva,Arial,Helvetica,Sans-Serif&gt;VMyths current target: &lt;A href=&quot;http://seclists.org/lists/isn/2004/Feb/0016.html&quot;&gt;Mi2G and MyDoom Estimates&lt;/A&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;An interesting attack from VMyths&apos; Rob Rosenberger:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;I am interested because I, too, would like to estimate damage done and am currently investigating ways to do this. Of course, if you subscribe to VMyths&apos; philosophy, this virus didn&apos;t cost anyone anything... I tend to differ slightly - comments inline below.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Vmyths.com Virus Hysteria Alert &lt;BR&gt;{2 February 2004, 22:05 CT} &lt;BR&gt;&lt;/EM&gt;
&lt;P&gt;&lt;EM&gt;In our previous Hysteria Alert, we predicted &quot;someone will soon &lt;BR&gt;declare a &apos;guesstimate&apos; damage value for the MyDoom virus/worm, &lt;BR&gt;strictly for its PR value.&quot; Vmyths named mi2g as one of the more &lt;BR&gt;dubious candidates. &lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana,Geneva,Arial,Helvetica,Sans-Serif&gt;It is always fun when somebody &quot;predicts&quot; something so obvious that it is hard to be wrong. Some folks do it with caveats and percentages, while still others just state the obvious. Virus damage estimation has been going on for at least three years now. (Full disclosure: I may very well do this sometime in the future as well.) So here is my prediction: sometime in the future, VMyths will blast someone for &quot;fearmongering&quot; strictly for its PR value. (Gosh, I feel like &lt;A href=&quot;http://www.hayhouse.com.au/books/edward/800x.shtm&quot;&gt;John Edward&lt;/A&gt; must when he is speaking with the dead).&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;mi2g played its PR card with a wag of $38.5 billion in global damages. &lt;BR&gt;We dismiss it as completely absurd. mi2g&apos;s guesstimate is:&amp;nbsp;&lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;* 1.6% of the U.S. federal budget proposed for the next fiscal year; &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;* 40% of the damage to New York City on 9/11/01; and &lt;BR&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;* more than double the cost of Hurricane Andrew in 1992. &lt;BR&gt;&lt;/EM&gt;&lt;EM&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana,Geneva,Arial,Helvetica,Sans-Serif&gt;These numbers he is using is the first indication of error. Each of these examples deal with real dollars, not economic dollars - certainly for the first one, though there is a chance that it is not true for the other two, but I can only assume that if VMyths doesn&apos;t like the mi2g estimates, they won&apos;t like estimates used anywhere.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;There is something else going on here as well. I call it the &quot;world wide rash&quot; syndrome.&amp;nbsp; It is the difference in the way we feel about one person losing a million dollars (must really be awful) versus two million people each losing a dollar (at least each person only lost a dollar). Of course, the net result is &quot;double the cost of the guy who lost a million dollars...&quot;&lt;/P&gt;
&lt;P&gt;Btw, &lt;A href=&quot;http://w3.access.gpo.gov/usbudget/fy2000/pdf/1999_erp.pdf&quot;&gt;this report&lt;/A&gt;&amp;nbsp;estimates the losses due to Hurricane Andrew at $63.9 billion. Not to worry, we don&apos;t pay much attention to the U.S. Bureau of Economic Analysis anyway. They were probably just in it for the PR.&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;mi2g has pulled PR stunts since 1999 on an almost regular basis. &lt;BR&gt;See &lt;/EM&gt;&lt;A href=&quot;http://vmyths.com/resource.cfm?id=64&amp;amp;page=1&quot;&gt;&lt;EM&gt;&lt;a href=&quot;http://Vmyths.com/resource.cfm?id=64&amp;amp&quot;&gt;http://Vmyths.com/resource.cfm?id=64&amp;amp&lt;/a&gt;;page=1&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt; for a critical look at &lt;BR&gt;the firm&apos;s shenanigans. &lt;BR&gt;&lt;/P&gt;&lt;/EM&gt;
&lt;P&gt;&lt;EM&gt;Unfortunately, gullible reporters have already started to latch onto &lt;BR&gt;this latest PR stunt. The Web Host Industry Review, for example, &lt;BR&gt;published it in breathless tones. Vmyths believes major media outlets &lt;BR&gt;will fall like dominoes -- mi2g&apos;s declaration is simply too large for &lt;BR&gt;them to ignore. &lt;BR&gt;&lt;/EM&gt;
&lt;P&gt;&lt;EM&gt;It sounds incredible to say it, but mi2g now demands money if you want &lt;BR&gt;to read press releases associated with their PR stunts. You&apos;ll pay &lt;BR&gt;&quot;&amp;#163;29.38 (including taxes)&quot; just to read their &quot;$38.5 billion&quot; press &lt;BR&gt;release, for example. &lt;BR&gt;&lt;/EM&gt;
&lt;P&gt;&lt;EM&gt;Visit &lt;/EM&gt;&lt;A href=&quot;http://www.mi2g.com/cgi/mi2g/press/010204.php&quot;&gt;&lt;EM&gt;&lt;a href=&quot;http://www.mi2g.com/cgi/mi2g/press/010204.php&quot;&gt;http://www.mi2g.com/cgi/mi2g/press/010204.php&lt;/a&gt;&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt; if you don&apos;t &lt;BR&gt;believe us. &lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana,Geneva,Arial,Helvetica,Sans-Serif&gt;This is actually pretty funny.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;&lt;/FONT&gt;&lt;BR&gt;&lt;EM&gt;We asked it before and we&apos;ll ask it again. Why do British fearmongers &lt;BR&gt;so often give guesstimates in U.S. dollars? &lt;BR&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana,Geneva,Arial,Helvetica,Sans-Serif&gt;A cute distraction, intended to &quot;warm&quot; you up to the wit of VMyths. And since I am an American, I would look too proud if I answered this honestly.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;mi2g has threatened to sue Vmyths for libel &lt;BR&gt;(see &lt;/EM&gt;&lt;A href=&quot;http://vmyths.com/rant.cfm?id=497&amp;amp;page=4&quot;&gt;&lt;EM&gt;&lt;a href=&quot;http://Vmyths.com/rant.cfm?id=497&amp;amp&quot;&gt;http://Vmyths.com/rant.cfm?id=497&amp;amp&lt;/a&gt;;page=4&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt; for details) and this &lt;BR&gt;Hysteria Alert may lead to a renewed effort to crush us. For the &lt;BR&gt;record: we stand by our criticisms of mi2g. However, Vmyths prides &lt;BR&gt;itself for an industry-leading &quot;corrections &amp;amp; clarifications&quot; page. &lt;BR&gt;Anyone may write to &lt;/EM&gt;&lt;A href=&quot;mailto:VeaCulpa_at_Vmyths.com?Subject=Re:%20[Vmyths.com%20ALERT]%20Absurd%20MyDoom%20damage%20values&quot;&gt;&lt;EM&gt;VeaCulpa_at_Vmyths.com&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt; to contest our claims &amp;amp; &lt;BR&gt;accusations. &lt;BR&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana,Geneva,Arial,Helvetica,Sans-Serif&gt;One can only hope that someone will care enough to pursue legal action. It is even better PR than estimating the damage done by viruses and worms.&lt;EM&gt;&lt;/P&gt;&lt;/EM&gt;&lt;/FONT&gt;
&lt;P&gt;&lt;EM&gt;Anyone may visit &lt;/EM&gt;&lt;A href=&quot;http://vmyths.com/rant.cfm?id=470&amp;amp;page=4&quot;&gt;&lt;EM&gt;&lt;a href=&quot;http://Vmyths.com/rant.cfm?id=470&amp;amp&quot;&gt;http://Vmyths.com/rant.cfm?id=470&amp;amp&lt;/a&gt;;page=4&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt; to rebut our &lt;BR&gt;opinions &amp;amp; criticisms. &lt;BR&gt;&lt;/EM&gt;
&lt;P&gt;&lt;EM&gt;Do the math. Stay calm. Stay reasoned. And stay tuned to Vmyths. &lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana,Geneva,Arial,Helvetica,Sans-Serif&gt;So here is the place I have the biggest problem. &quot;Do the math&quot;...&quot;do the math&quot;...&quot;do the math&quot;... has there been anything but the laziest of &quot;math&quot; done here? Come on - comparing random whole numbers.... it is absolutely silly. What would be interesting is if somebody actually &lt;EM&gt;did&lt;/EM&gt; &quot;do the math.&quot; I happen to think the number is pretty big as well, but in economic terms, productivity costs money. I like to think that an hour of my time is worth something. Big 5/Final 4 terms think an hour of their time is worth a bit more than something. So comparing the real dollars in a budget to economic dollars that are measuring productivity, among other things, is ridiculous. Of course, these numbers can&amp;nbsp;always be challenged with&amp;nbsp;alternative methods (VMyths chose not to, I suppose).&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;&lt;/FONT&gt;&lt;BR&gt;&lt;EM&gt;Rob Rosenberger, editor &lt;BR&gt;&lt;/EM&gt;&lt;A href=&quot;http://vmyths.com/&quot;&gt;&lt;EM&gt;&lt;a href=&quot;http://Vmyths.com&quot;&gt;http://Vmyths.com&lt;/a&gt;&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt; &lt;BR&gt;(319) 646-2800 &lt;BR&gt;&lt;/P&gt;&lt;/EM&gt;
&lt;P&gt;&lt;EM&gt;Acknowledgements: &lt;BR&gt;Mary Landesman, &lt;/EM&gt;&lt;A href=&quot;http://antivirus.about.com/&quot;&gt;&lt;EM&gt;&lt;a href=&quot;http://antivirus.about.com&quot;&gt;http://antivirus.about.com&lt;/a&gt;&lt;/EM&gt;&lt;/A&gt;&lt;EM&gt; &lt;BR&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0134433/2004/02/06.html#a8</guid>
			<pubDate>Sat, 07 Feb 2004 00:46:09 GMT</pubDate>
			<category>My Friends</category>
			<comments>http://radiocomments2.userland.com/comments?u=134433&amp;amp;p=8&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0134433%2F2004%2F02%2F06.html%23a8</comments>
			</item>
		<item>
			<description>&lt;P&gt;&lt;FONT face=Verdana,Geneva,Arial,Helvetica,Sans-Serif&gt;&lt;A href=&quot;http://searchsecurity.techtarget.com/webcasts/0,289675,sid14,00.html&quot;&gt;Expert&apos;s Guide to Effective Patch Management&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face=Verdana&gt;I will be giving a webcast on patch management for searchsecurity.com. This coincides with the article I&apos;ve written on patch management for Information Security Magazine (in February&apos;s issue, which should eventually show up at &lt;A href=&quot;http://www.infosecuritymag.com&quot;&gt;www.infosecuritymag.com&lt;/A&gt;).&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Note: check out &lt;A href=&quot;http://www.patchmanagement.org&quot;&gt;www.patchmanagement.org&lt;/A&gt; for a great mailing list on patch management.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0134433/2004/02/06.html#a7</guid>
			<pubDate>Fri, 06 Feb 2004 17:33:33 GMT</pubDate>
			<category>Vulnerability Management</category>
			<comments>http://radiocomments2.userland.com/comments?u=134433&amp;amp;p=7&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0134433%2F2004%2F02%2F06.html%23a7</comments>
			</item>
		<item>
			<description>&lt;P&gt;&lt;FONT face=Verdana,Geneva,Arial,Helvetica,Sans-Serif&gt;People seem to like this &lt;A href=&quot;http://www.spiresecurity.com/madlib.htm&quot;&gt;MadLib&lt;/A&gt; I wrote poking fun at whatever the latest and greatest virus or worm is... try it out, it actually still works fairly well:&lt;/FONT&gt;&lt;/P&gt;&lt;FONT face=&quot;Gill Sans MT&quot; color=#000080 size=6&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-SIZE: 24pt; COLOR: navy; FONT-FAMILY: &apos;Gill Sans MT&apos;&quot;&gt;Spire ViewPoint&lt;/SPAN&gt;&lt;?xml:namespace prefix = o ns = &quot;urn:schemas-microsoft-com:office:office&quot; /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=3&gt;&lt;FONT color=#000000&gt;&lt;B&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Book Antiqua&apos;&quot;&gt;last updated: &lt;/SPAN&gt;&lt;/B&gt;&lt;?xml:namespace prefix = st1 ns = &quot;urn:schemas-microsoft-com:office:smarttags&quot; /&gt;&lt;st1:date Year=&quot;2003&quot; Day=&quot;3&quot; Month=&quot;2&quot;&gt;&lt;B&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Book Antiqua&apos;&quot;&gt;February 3, 2003&lt;/SPAN&gt;&lt;/B&gt;&lt;/st1:date&gt;&lt;B&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Book Antiqua&apos;&quot;&gt; &lt;/SPAN&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Book Antiqua&apos;&quot;&gt;&lt;BR&gt;&lt;B&gt;&lt;FONT color=#000000 size=3&gt;File under Spire Discipline: Threat Management&lt;/FONT&gt;&lt;/B&gt;&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=3&gt;&lt;FONT color=#000000&gt;&lt;B&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Book Antiqua&apos;&quot;&gt;Author: Pete Lindstrom&lt;/SPAN&gt;&lt;/B&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-SIZE: 18pt; COLOR: #993333; FONT-FAMILY: &apos;Gill Sans MT&apos;&quot;&gt;[Adjective] Computer Worm [verb] Internet&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=3&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Book Antiqua&apos;&quot;&gt;&lt;FONT color=#000000&gt;In the wee hours of &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[date]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt;, a &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[adjective]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt; computer worm spread &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[adverb]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt; throughout the Internet. Dubbed &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[silly name]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt; because &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[ridiculous reason that doesn&apos;t explain anything about how it works]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt;, and also known as &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[another random name]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt; and &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[another random name]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt;, the worm has infected an estimated &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[number]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt; systems within &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[length of time]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt;. Experts are calling this worm the most &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[adjective]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt; since &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[date in the past]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt;.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Book Antiqua&apos;&quot;&gt;&lt;FONT size=3&gt;&lt;FONT color=#000000&gt;The worm exploits a hole in &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[Microsoft product name]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt; that was first identified &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[number]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt; months ago by &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[security company name]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt;. In an attempt to secure the planet, and&lt;/FONT&gt;&lt;I&gt;&lt;FONT color=#000000&gt; for our own good, &lt;/FONT&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[same company, or name of parents]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt; released detailed information about the vulnerability and how to exploit it. They also mentioned how to fix it, but apparently &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[noun]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt; listened. Coincidentally, the worm&amp;nbsp;that exploited this hole was also first identified by &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[same company]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt;.&amp;nbsp;&lt;/FONT&gt;&lt;SPAN style=&quot;COLOR: blue&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style=&quot;COLOR: black&quot;&gt;Not&lt;/SPAN&gt;&lt;SPAN style=&quot;COLOR: blue&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color=#000000&gt;coincidentally, they make a product to protect against &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[noun]&lt;/SPAN&gt;&lt;/I&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT color=#000000&gt;&lt;I&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: &apos;Book Antiqua&apos;&quot;&gt;.&lt;/SPAN&gt;&lt;/I&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=3&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Book Antiqua&apos;&quot;&gt;&lt;FONT color=#000000&gt;&quot;Actually, it&apos;s not really a &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[noun]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt;, it&apos;s a &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[noun]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt;,&quot; said &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[Pete Lindstrom, or some other person seeking publicity]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt;. &quot; A true &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[noun]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt; works by &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[random filler&amp;nbsp;that nobody will read]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt;.&quot; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Book Antiqua&apos;&quot;&gt;&lt;FONT size=3&gt;&lt;FONT color=#000000&gt;The worm&apos;s payload &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[verb]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt; every system by &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[verb ending in -ing]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt; the &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[noun]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt;. Comparatively speaking, this is much worse than &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[another worm]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt; but not as bad as &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[another worm]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt;. The computers of&lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt; [place]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt; were hit the hardest. Current damage is estimated at &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[dollar figure more than the GNP of two-thirds of the world&apos;s nations]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt;. &quot; This worm has the potential to &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[something or other]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt;,&quot; said &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[Pete Lindstrom, or&amp;nbsp;some other person&amp;nbsp;trying hard to&amp;nbsp;come up with something interesting to say&amp;nbsp;;-)]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt;. &quot; It just goes to show you that &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[another something or other]&lt;/SPAN&gt;&lt;/I&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT color=#000000&gt;&lt;I&gt;&lt;SPAN style=&quot;FONT-SIZE: 10pt; FONT-FAMILY: &apos;Book Antiqua&apos;&quot;&gt;.&quot;&lt;/SPAN&gt;&lt;/I&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-FAMILY: &apos;Book Antiqua&apos;&quot;&gt;&lt;FONT size=3&gt;&lt;FONT color=#000000&gt;Though there is no way to protect against this particular bug, experts recommend trying &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[longshot one]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt; or &lt;/FONT&gt;&lt;I&gt;&lt;SPAN style=&quot;COLOR: #993333&quot;&gt;[longshot two]&lt;/SPAN&gt;&lt;/I&gt;&lt;FONT color=#000000&gt;, neither of which matter, since nobody will do it anyway.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0134433/2004/02/06.html#a6</guid>
			<pubDate>Fri, 06 Feb 2004 06:09:42 GMT</pubDate>
			<category>My Friends</category>
			<comments>http://radiocomments2.userland.com/comments?u=134433&amp;amp;p=6&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0134433%2F2004%2F02%2F06.html%23a6</comments>
			</item>
		<item>
			<description>&lt;P&gt;&lt;A href=&quot;http://news.com.com/2010-1028_3-5154136.html?part=rss&amp;amp;tag=feed&amp;amp;subj=news&quot;&gt;Paying for e-mail: An idea whose time has come?&lt;/A&gt;. CNET News.com&apos;s Charles Cooper writes that charging for e-mail may not be so crazy an idea, after all.&lt;/P&gt;
&lt;P&gt;Another approach to stop spam. Interesting that it, too, is a story about efforts from Microsoft. Paying for email is interesting, though we&apos;d have to be pretty careful about ensuring against spoofed addresses (as the article points out).&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0134433/2004/02/06.html#a5</guid>
			<pubDate>Fri, 06 Feb 2004 05:50:50 GMT</pubDate>
			<source url="http://news.com.com/2547-1_3-0-5.xml">CNET News.com - Front Door</source>
			<category>My Friends</category>
			<comments>http://radiocomments2.userland.com/comments?u=134433&amp;amp;p=5&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0134433%2F2004%2F02%2F06.html%23a5</comments>
			</item>
		<item>
			<description>&lt;P&gt;&lt;A href=&quot;http://www.computerworld.com/securitytopics/security/story/0,10801,89887,00.html?f=x73&quot;&gt;ISS warns of holes in Check Point firewall, VPN server&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&quot;Internet Security System Inc. warned of critical vulnerabilities in Check Point Software Technologies Ltd.&apos;s Check Point Firewall-1, Check Point VPN-1 Server, and SecuRemote and SecureClient VPN clients.&quot;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Is it just me or does ISS tend to find a lot of security holes with its competitors?&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0134433/2004/02/06.html#a4</guid>
			<pubDate>Fri, 06 Feb 2004 05:38:11 GMT</pubDate>
			<source url="http://www.computerworld.com/news/xml/0,5000,73,00.xml">Computerworld Security News</source>
			<category>Vulnerability Management</category>
			<comments>http://radiocomments2.userland.com/comments?u=134433&amp;amp;p=4&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0134433%2F2004%2F02%2F06.html%23a4</comments>
			</item>
		<item>
			<description>&lt;P&gt;&lt;A href=&quot;http://www.computerworld.com/softwaretopics/software/groupware/story/0,10801,89900,00.html?f=x10&quot;&gt;&lt;STRONG&gt;Microsoft project aims to make spammers pay for spam&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This is a pretty interesting problem. Email scales so incredibly well that it costs the same to send 1 message as it does a million (sort of). So they are going to make email work harder to send one message. So the goal is to consciously cripple our systems. I am not sure this is a great direction to head. I would rather continue down the path of more trust in those we exchange email with... Sure, there are weaknesses with that, but I&apos;d rather have a system based on trust than one that purposely reduces capabilities.&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0134433/2004/02/06.html#a3</guid>
			<pubDate>Fri, 06 Feb 2004 05:10:17 GMT</pubDate>
			<source url="http://www.computerworld.com/news/xml/10/0,5009,,00.xml">Computerworld News</source>
			<category>My Friends</category>
			<comments>http://radiocomments2.userland.com/comments?u=134433&amp;amp;p=3&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0134433%2F2004%2F02%2F06.html%23a3</comments>
			</item>
		<item>
			<description>&lt;P&gt;&lt;STRONG&gt;Spire Security Website&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;I am considering modifying my current homepage at &lt;A href=&quot;http://www.spiresecurity.com&quot;&gt;www.spiresecurity.com&lt;/A&gt; to become a blog. I think it will be easier to update and syndicate, or should I say upd8 and syndic8?&lt;/P&gt;</description>
			<guid>http://radio.weblogs.com/0134433/2004/02/04.html#a2</guid>
			<pubDate>Thu, 05 Feb 2004 01:33:20 GMT</pubDate>
			<comments>http://radiocomments2.userland.com/comments?u=134433&amp;amp;p=2&amp;amp;link=http%3A%2F%2Fradio.weblogs.com%2F0134433%2F2004%2F02%2F04.html%23a2</comments>
			</item>
		</channel>
	</rss>
