Category: security

  • Navy finds website with Sailor's SSNs

    The Site included their names, birth dates, and Social Security Numbers. The information has been taken down, and the site is under investigation by Naval CIS.

    read more | digg story

  • FISC on geeks oppinion

    I'll admit, I really stereotyped the Federal Information Security Conference (FISC).  I saw the speakers and saw director, senior and thought manager… they don't have anything to teach me that I want to know.  While there were a lot of manager types talking about some high level stuff (i.e. DoD 8570 and its affect on GS Civilians), mostly the FISC is about Government employees and their contractors getting exposure to the commercial market. 

    The great thing about it is that it brings together so much information security talent.  I learned more from casual conversation then I did from four seperate briefings.

    I don't think that the FISC is worth paying more than maybe $20 for.  The reason I say this is because even though you learn somethings, those that benefit most from the FISC are the vendors who are actually doing most of the speaking.

    Prices for the FISC:

      Federal Government – stationed in Colorado: $50 per person
      Federal Government – out of state: $245 per person
      Industry: $345 per person

    On-line preregistration after March 31, 2006

      Federal Government – stationed in Colorado: $100 per person
      Federal Government – out of state: $295 per person
      Industry: $395 per person

    On-line preregistration closes June 15, 2006 at 12:00 p.m.
    The cost to register on site is:

      Federal Government – stationed in Colorado: $100 per person
      Federal Government – out of state: $395 per person
      Industry: $495 per person

    FREE for ISSA members

  • Account Update Request nr 33945 ***SCAM ALERT***

    Wells Fargo is sending me mail from… updateit@meinesdomainsins.de  <— Deutcheland?! 

    This idiot doesn't even have enough brains to mask his REAL E-mail: updateit@meinesdomainsins.de 


    Dear valued WellsFargo ® member:

    Due to concerns, for the safety and integrity of the wellsfargo account we have issued this warning message.

    It has come to our attention that your WellsFargo ® account information needs to be updated as part of our continuing commitment to protect your account and to
    reduce the instance of fraud on our website. If you could please take 5-10 minutes out of your online experience and update your personal records you will not run into
    any future problems with the online service.

    Once you have updated your account records your wellsfargo account service will not be interrupted and will continue as normal.

    To update your WellsFargo® records click on the following link:

    http://www.wellsfargo.com/signon?LOB=CONS&screenid=Update_Acct

    Thank You.

    Accounts Management As outlined in our User Agreement, WellsFargo ® will periodically send you information about site changes and enhancements.

    Visit our Privacy Policy and User Agreement if you have any questions.
    http://www.wellsfargo.com/help/index.jhtml

  • Need to hear from you ****SCAM ALERT****

    I get so many scam letters and spam that 95% of my email is worthless.  Here is a scam from Mr. Danmisi. 

    Submit Mr. Danmisi to some free stuff!!
    Here is his email:
    nelsondanmisi@walla.com

    Sir,

    I am Dr. Nelson Danmisi., the Regional computing auditor of
    (FNB OF SOUTH AFRICA) JOHANNESBURG BRANCH (SBSA).There is an
    account opened in this bank in 1985 and since 1992 nobody
    has operated on this account again. After going through some
    old files in the records I discovered that if I do not remit
    this money out urgently it will be forfeited for nothing
    according to South Africa laws and act of 1993, the money
    will be reverted to the government treasury after 15 years
    if there is, no valid claim to the money or account.

    I need a foreign partner that I will present as a relative
    to this late man. The owner of this account is Mr. Daniel
    B.Jones, a foreigner, and a Miner at Kruger Gold Co. A
    geologist by profession and he died since 1992. The account
    has no other beneficiary and my investigation proved to me
    as well that this company does not know anything about this
    account and the amount involved is US$24,000,000 Twenty Four
    Million US Dollars Only.

    I am only contacting you as a foreigner, I will use my
    influence to effect legal approvals and onward transfer into
    your account At the conclusion of this business, you will be
    given 50% of the total amount, 50% will be for me and my
    family. I await to hear from you.

    Yours truly,
    Dr. Nelson Danmisi.
    FNB OF SOUTH AFRICA.

    Submit Mr. Danmisi to some free stuff!!
    ProductTestPanel.com

    Here is his email:
    nelsondanmisi@walla.com

  • Want to outwit hackers? Hire an ethical one

    Some of my colleagues in the information security profession think that hacking is evil.  They strongly rebuke any information security professionals for condoning hacking. 

    I think that is a ridiculous position to take.  How can we be any good at our job (particulary the more technical information security professionals) if we ignore the skills that malicious hackers use to exploit the very systems we protect?  Why would we bind our own hands from finding vulnerabilities before our enemys? 

    Not knowing the darker side of security is like a Drug Enforcement Agent who can't recognize drugs because he or she has never had any exposure to controlled substances.  It is not my position that cops should rob a bank or abuse crack to REALLY know the criminal mind.  I'm just saying that security is not just about implementing secuirty practice, it is about knowing the exploits, vulnerabilities and threats and knowing them well.

    Hacking is cool.  It is not all evil or criminal.  Sometimes I have to hack my system after locking myself out.  I've attempted to hack my own network to find vulnerabilities. 

    I think hacking is about mastering systems, finding easier ways to do things in life, being clever.  The dangerous thing about hacking is that sometimes individuals are smarter than the systems that they interface with (or control them).  It is the mutant strain that changes everything, the revolution that forces change, the rebel refuses to submit and any of those can be very good or very bad.

    Unfortunately, it is easier to destroy than to create, so some weak, ignorant, sociopaths give in to the darkside.  This is true of any method, skill, talent, profession ect.  It is a part of human nature to have users and abusers in our ranks.  You may even have some in your family!  It is my personal belief that what you reap is what you sow (karma); those who do bad will get theirs.  I choose to hack ethically lest I incur the wrath of the universe.

    The first ethical-hacking course was started six years ago. Today, there are some half-dozen organizations offering similar instruction around the world

    read more | digg story

  • The Open–source PKI Book

    This document describes Public Key Infrastructures, the PKIX standards, practical PKI functionality and gives an overview of available open–source PKI implementations. Its aim is foster the creation of viable open–source PKI implementatations.

    read more | digg story

  • MySpace to Add Restrictions to Protect Younger Teenagers

    “Starting next week, MySpace, the popular online hangout, will make it harder for strangers to send messages to younger teenagers. The site has been under pressure because members are frequently subjected to lewd or inappropriate messages and occasionally lured into dangerous real-world encounters.”

    read more | digg story

  • "Secret" UV messages on your credit cards and driver's license

    If you have a UV light handy, you'll discover a world of secret messages printed on licenses, credit cards, and other official documents as an anti-counterfeiting measure. This web page has some nice photos of the UV ink on a Visa Card, a Master Card, and a CA driver's license.

    read more | digg story

  • Encryption project has teen feeling pretty secure

    His project, the “Embedded Secure Network Bridge” has already attracted some attention; not bad for a sixteen year old.

    read more | digg story

  • Alternate Net Neutrality Proposals Submitted Just 2 Days Before the Debate

    Civil liberties advocacy group the Center for Democracy and Technology and New Yorkers for Fair Use, comprised of businesspeople and technology advocates, both released net neutrality proposals Tuesday, two days before the U.S. Senate Commerce, Science and Transportation Committee is set to debate the issue.

    read more | digg story