<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Security For All</title>
	<atom:link href="http://secforall.info/feed/" rel="self" type="application/rss+xml" />
	<link>http://secforall.info</link>
	<description>Security for everyone.</description>
	<lastBuildDate>Sat, 07 Apr 2012 02:46:34 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='secforall.info' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Security For All</title>
		<link>http://secforall.info</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://secforall.info/osd.xml" title="Security For All" />
	<atom:link rel='hub' href='http://secforall.info/?pushpress=hub'/>
		<item>
		<title>Captain X-Ploit: Another Crack in the Wall</title>
		<link>http://secforall.info/2012/04/06/captain-x-ploit-another-crack-in-the-wall/</link>
		<comments>http://secforall.info/2012/04/06/captain-x-ploit-another-crack-in-the-wall/#comments</comments>
		<pubDate>Sat, 07 Apr 2012 02:46:32 +0000</pubDate>
		<dc:creator>Joseph Webster</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[professional]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[security Tags: Captain X-Ploit]]></category>
		<category><![CDATA[Trustonia]]></category>

		<guid isPermaLink="false">http://secforall.info/?p=2015</guid>
		<description><![CDATA[The Adventures of Captain X-Ploit: Another Crack in the Wall – Part 4.5 of the epic chronicle – Captain X-Ploit vs. The Bills             As the heads of zombies rolled and his teammates droned about changing clips and needing med kits, David’s mind wandered. He began to contemplate zombies&#8230; and then it just clicked. David’s [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secforall.info&amp;blog=4666223&amp;post=2015&amp;subd=webjoseph425&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://webjoseph425.files.wordpress.com/2010/02/the-adv-cap-x-ploit.jpg"><img class="alignleft size-thumbnail wp-image-1254" title="Captain X-Ploit" src="http://webjoseph425.files.wordpress.com/2010/02/the-adv-cap-x-ploit.jpg?w=100&#038;h=100" alt="" width="100" height="100" /></a></p>
<p align="center"><strong>The Adventures of Captain X-Ploit:</strong><br />
<strong>Another Crack in the Wall</strong><br />
<em>– Part 4.5 of the epic chronicle –</em><br />
<strong>Captain X-Ploit vs. The Bills</strong></p>
<p>            As the heads of zombies rolled and his teammates droned about changing clips and needing med kits, David’s mind wandered. He began to contemplate zombies&#8230; and then it just clicked.</p>
<p>David’s character stood still for nearly three minutes and it took his teammates yelling, having lost their sniper support, to bring him back to reality. He hit the chat key responded “I have to go now,” and threw his headset off as he powered down the game and logged online to do a quick confirmatory search.</p>
<p>He didn’t really know what he was onto; he had the first step of a vague plan forming. He could see the beginning but no end. Still something compelled him to throw himself forward into this plan with full force. He reached for his phone and dialed the number on his computer screen.</p>
<p>“Hi, you’ve reached Trustonia Valley Hospital records office how can I help you today?”</p>
<p>“Hi, yes I appear to have been falsely reported as dead.” David responded.</p>
<p>“Oh, dear that is bad! What is your name?”</p>
<p>David scanned the obituary page until he found a suitable sounding name, “I’m Curtis Trent, I desperately need that corrected in all my files as well as a change of address”</p>
<p>“Of course sir, that will just be a minute what address would you like to change it to?”</p>
<p>“1302 Deven Ave, Trustonia. Oh and I have recently changed my name to David Nicholas Stone, if you could update that for me too.”</p>
<p>“Sure thing sir, just give me a few minutes to make those changes.”</p>
<p>About five minutes later David hung up the phone after giving himself a rather ghostly roommate. He then dialed a different hospital and repeated this activity. Continuing in this vein he gave himself over 100 new ghostly roommates, maximizing his time by submitting requests in emails while waiting on the phone.</p>
<p>He then spent the next several hours submitting online requests for unemployment benefits for his new friends who happened to live at the same address as him with the same name.</p>
<p>The day drew to a close and he found himself one step closer to not only paying off his bills but to completing the ultimate exploit. All he had to do was wait for those checks to roll in.</p>
<blockquote><p><em>Short but sweet this time and clearly to-be-continued. Our hero continues with his recent penchant for identity theft variants, this time appropriating the identities of folks who are beyond caring what happens to their good name. Now clearly this gambit is only going to work for a short time since even the Trustonia Department of Unemployment, who we assume to be even more inept that the typical real world division of employment, will certainly twig to paying benefits to the deceased with no prior graft arrangement in place. It will be interesting to see what the good Captain has planned with the ill-gotten government benefits of his undead namesakes. Stay Tuned.</em></p></blockquote>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/webjoseph425.wordpress.com/2015/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/webjoseph425.wordpress.com/2015/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/webjoseph425.wordpress.com/2015/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/webjoseph425.wordpress.com/2015/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/webjoseph425.wordpress.com/2015/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/webjoseph425.wordpress.com/2015/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/webjoseph425.wordpress.com/2015/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/webjoseph425.wordpress.com/2015/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/webjoseph425.wordpress.com/2015/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/webjoseph425.wordpress.com/2015/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/webjoseph425.wordpress.com/2015/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/webjoseph425.wordpress.com/2015/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/webjoseph425.wordpress.com/2015/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/webjoseph425.wordpress.com/2015/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secforall.info&amp;blog=4666223&amp;post=2015&amp;subd=webjoseph425&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secforall.info/2012/04/06/captain-x-ploit-another-crack-in-the-wall/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8cb97cf53947d19ef34fcb97961820df?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Joe</media:title>
		</media:content>

		<media:content url="http://webjoseph425.files.wordpress.com/2010/02/the-adv-cap-x-ploit.jpg?w=100" medium="image">
			<media:title type="html">Captain X-Ploit</media:title>
		</media:content>
	</item>
		<item>
		<title>Captain X-Ploit: Matlock rocks my socks off</title>
		<link>http://secforall.info/2012/03/18/captain-x-ploit-matlock-rocks-my-socks-off/</link>
		<comments>http://secforall.info/2012/03/18/captain-x-ploit-matlock-rocks-my-socks-off/#comments</comments>
		<pubDate>Sun, 18 Mar 2012 22:33:37 +0000</pubDate>
		<dc:creator>Joseph Webster</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[professional]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Captain X-Ploit]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Trustonia]]></category>

		<guid isPermaLink="false">http://secforall.info/?p=1994</guid>
		<description><![CDATA[The Adventures of Captain X-Ploit: Matlock rocks my socks off. – Part 5 of the epic chronicle – Captain X-Ploit vs. The Bills A bank is a place that will lend you money if you can prove that you don&#8217;t need it. ~ Bob Hope Foreword: Since this Captain X-Ploit episode is a continuation of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secforall.info&amp;blog=4666223&amp;post=1994&amp;subd=webjoseph425&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://webjoseph425.files.wordpress.com/2010/02/the-adv-cap-x-ploit.jpg"><img class="alignleft  wp-image-1254" title="Captain X-Ploit" src="http://webjoseph425.files.wordpress.com/2010/02/the-adv-cap-x-ploit.jpg?w=120&#038;h=125" alt="" width="120" height="125" /></a></p>
<p align="center"><strong>The Adventures of Captain X-Ploit:</strong><br />
<strong>Matlock rocks my socks off.</strong><br />
<em>– Part 5 of the epic chronicle –</em><br />
<strong>Captain X-Ploit vs. The Bills</strong></p>
<p align="center">A bank is a place that will lend you money if you can prove that you don&#8217;t need it. ~ <strong>Bob Hope</strong></p>
<blockquote><p><em><strong>Foreword:</strong></em></p>
<p><em>Since this Captain X-Ploit episode is a continuation of the original saga, and since it&#8217;s been a really, really long time since the good Captain has deigned to make an appearance, the following are links to the original episodes so we can all get caught up with the story thus far.</em></p>
<ul>
<li><em><a title="Captain X-Ploit vs. The Bills" href="http://secforall.info/2010/02/16/captain-x-ploit-vs-the-bills/" rel="bookmark">Captain X-Ploit vs. The Bills</a></em></li>
<li><em><a title="Captain X-Ploit:  Bills + Bagels = BOOYA!!!" href="http://secforall.info/2010/02/26/captain-x-ploit-bills-bagels-booya/" rel="bookmark">Captain X-Ploit: Bills + Bagels = BOOYA!!!</a></em></li>
<li><em><a title="Captain X-Ploit: Cars, candy and girls" href="http://secforall.info/2010/03/26/captain-x-ploit-cars-candy-and-girls/" rel="bookmark">Captain X-Ploit: Cars, candy and girls</a></em></li>
<li><em><a title="Captain X-Ploit: Banished from Bloodshot" href="http://secforall.info/2010/04/02/captain-x-ploit-banished-from-bloodshot/" rel="bookmark">Captain X-Ploit: Banished from Bloodshot</a></em></li>
<li><em><a title="Captain X-Ploit: The great liberation of the coffee from the oppressive closet of motivation." href="http://secforall.info/2010/04/09/captain-x-ploit-the-great-liberation-of-the-coffee-from-the-oppressive-closet-of-motivation/" rel="bookmark">Captain X-Ploit: The great liberation of the coffee from the oppressive closet of motivation.</a></em></li>
</ul>
</blockquote>
<p>David went back to his home. It was a rather pleasant house in a nice neighborhood. Its generic white walls gave no indication that an evil genius might live inside. That was exactly how David liked it and exactly why he had bought it.</p>
<p>As he parked his new prize in the garage he could hear the excited clicking of Nicky’s nails on the tile as she doubtlessly was rushing to see why the garage door was opening. As he walked in he knelt down to pet her affectionately and passed her an oatmeal raisin bagel.</p>
<p>She barked appreciatively and then began to wolf it down. “Oh Nicky, you’re the best roommate a guy could ask for.” That thought gave him pause for a moment. “Roommate,” he re-uttered the word. Perhaps that is the key for today’s adventure he thought. Leaving Nicky to enjoy her bagel, he hastily ran upstairs to hop online and do some research while enjoying his bagel and coffee.</p>
<p>After about ten minutes of useful research and about three hours of watching internet videos, he picked up his phone and called the bank.</p>
<p>“Hello, you’ve reached ‘Stage Coach Banking’, my name is Jenny. How can I help you today?”</p>
<p>“Hello Jenny, My name is David Nicholas Stone and I regret to inform you that I will not be paying my mortgage payment this month.”</p>
<p>“Hmmm&#8230; It says here that you have <em>never</em> made a payment and I need to send the police to evict you.”</p>
<p>“Ah, yes, I figured as much. But see, the problem is that I have suffered a bout of extreme aging and I am now over the age of 65 and therefore am exempt from eviction.”</p>
<p>“Oh, goodness! Are you OK, sir?”</p>
<p>Quite. In fact, the senior discounts are very handy and I find myself truly enjoying Matlock for the first time in well… ever I guess.”</p>
<p>“That&#8217;s a relief! But you do realize we will require at least a doctor’s note confirming your age, Mr. Stone”</p>
<p>David smiled and joyfully rolled his chair over to the file cabinet next to his desk and fingered through it until his hands landed on the file he was looking for. It was labeled “<strong>Nicky’s vet records.</strong>” He pulled out the latest checkup. Among the general stats at the top was written “<strong>age: 13</strong>” and “<strong>age in dog years: 65</strong>”.</p>
<p>“I have the file here from my medical care provider clearly stating that by a unit of measure I am to be considered 65 years of age.”</p>
<p>“Excellent. If you will just scan and email that file to us we will be forced to leave you be until you die.” Jenny said cheerfully.</p>
<p>“Sure thing. Oh, one last detail. Under <em>age</em> it says “13” that is in reference to the age of my new hip, not my actual age. My actual age is labeled “<em>dog years</em>” but in fact that is a typo, they meant to put “<em>God years</em>,” as in how long it has been since God created my magnificent body.”</p>
<p>“I will make a note of that right here, Mr. Stone, and we will be sure to consider that when viewing your file. Is there anything else you need help with today, sir?” Jenny asked politely.</p>
<p>“No, I believe I have been served quite well, Jenny. Thank you.” He said.</p>
<p>“Well, would like to take a brief survey to rate my…&#8221; Click.</p>
<p><em>&#8220;Nice girl,&#8221;</em> David thought to himself as he hung up the phone and scanned in Nicky’s vet document. <em>&#8220;Well, that takes care of the mortgage, now I just have to deal with electricity, gas, and credit cards.&#8221;</em></p>
<p>David couldn’t help but feel pleased with himself after this solution. The only thing he liked more than a well implemented exploit was one that tied up a loose end for the foreseeable future. He figured he deserved a break to blow the heads off of some zombies before returning to the tiring yet fulfilling task of escaping work.</p>
<p>As he watched the zombie heads bouncing off his HD monitor in time to the resonating sloppy thuds emitting from his surround sound system he couldn’t help but feel depressed that he hadn’t yet cracked the ultimate shell; His ultimate prize and undying desire. This was of course to game the system so completely and so perfectly that he could have his lifelong goal of unlimited money. Until that day he felt like a rank amateur playing at his profession of slacker.</p>
<p>This nagging feeling had plagued him since childhood. His parents had always been on the overbearing side and watched his every move. While the normal kids experimented with drugs, alcohol and sex, he was left to only watch. Stuck between their rock hard force in his life during the times of their explicit presence and their unshakable expectations when there weren’t by his side.</p>
<p>His youth was one filled with angst and rebellion building in an un-manifestable form. It began when he was fourteen; the world opened to him as he realized a non-physical but equally caustic way to vent his adolescent aggression. A way that was invisible to his ever present parents. It was the life of exploits. He could practice this form of rebellion anywhere at any time without accomplices and without raising a single flag to his parents.</p>
<p>And so, with no conscious knowledge or understanding deeper than raw, raging adolescent emotion piloting his brilliant mind toward anarchistic oblivion, the greatest hacking mind was born into the world. The idea that what he was doing was hacking had never crossed his mind. For hacking, you see, isn’t anything more than a label affixed to a mindset. It wouldn’t be until later that the world would forcibly open David’s eyes to the cause he was part of.</p>
<p>It was this evolution of mentality that brought David to this exact tipping point that would thrust him over the edge into a world of politics and aliens. But I am getting ahead of myself. Back to the precipice, back to the original unending quest for the perfect exploit; the exploit that to David consciously meant unlimited money and power, but subconsciously meant so much more.  It meant the quenching of an unquenchable thirst; the scratching of an invisible ever-present itch; the completion of his greatest work of art.</p>
<p>I mention all of this not to ruin the readers surprise, but in hopes of whetting their appetite. This exact day was the day David succeeded in breaking the system so completely that his dream was realized.</p>
<blockquote><p><em>So once again David uses his awesome Social Engineering skills, mixed with fraudulent information hacked into the bank records (recall that <a title="Captain X-ploit: Bills + Bagels = BOOYA!" href="http://secforall.info/2012/03/16/whatever-happened-to-security-for-all/" target="_blank">Nicky the dog&#8217;s &#8220;legal&#8221; name is David Nicholas Stone</a>) to avoid his mortgage payment. This exploit is particularly interesting in that it&#8217;s a variation of identity theft where rather than stealing someone&#8217;s identity you give your identity to someone who doesn&#8217;t know or doesn&#8217;t care &#8211; like Nicky, David&#8217;s canine roommate &#8211; such that they are responsible for your debts. Now, granted this exploit only works <strong>this</strong> well in Trustonia, but I suspect there are variations that work quite nicely here in reality. To the extent that we live in reality.</em></p>
<p><em>The last part is an interesting discourse on the hacker mindset from the thinly veiled pen (er&#8230; keyboard) of the creator of Captain X-ploit. Certainly something to think about while you are planning your next exploit (er&#8230; adventure).</em></p></blockquote>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/webjoseph425.wordpress.com/1994/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/webjoseph425.wordpress.com/1994/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/webjoseph425.wordpress.com/1994/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/webjoseph425.wordpress.com/1994/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/webjoseph425.wordpress.com/1994/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/webjoseph425.wordpress.com/1994/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/webjoseph425.wordpress.com/1994/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/webjoseph425.wordpress.com/1994/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/webjoseph425.wordpress.com/1994/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/webjoseph425.wordpress.com/1994/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/webjoseph425.wordpress.com/1994/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/webjoseph425.wordpress.com/1994/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/webjoseph425.wordpress.com/1994/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/webjoseph425.wordpress.com/1994/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secforall.info&amp;blog=4666223&amp;post=1994&amp;subd=webjoseph425&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secforall.info/2012/03/18/captain-x-ploit-matlock-rocks-my-socks-off/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8cb97cf53947d19ef34fcb97961820df?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Joe</media:title>
		</media:content>

		<media:content url="http://webjoseph425.files.wordpress.com/2010/02/the-adv-cap-x-ploit.jpg?w=145" medium="image">
			<media:title type="html">Captain X-Ploit</media:title>
		</media:content>
	</item>
		<item>
		<title>Whatever Happened to Security For All?</title>
		<link>http://secforall.info/2012/03/16/whatever-happened-to-security-for-all/</link>
		<comments>http://secforall.info/2012/03/16/whatever-happened-to-security-for-all/#comments</comments>
		<pubDate>Sat, 17 Mar 2012 04:57:02 +0000</pubDate>
		<dc:creator>Joseph Webster</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Captain X-Ploit]]></category>

		<guid isPermaLink="false">http://secforall.info/?p=1981</guid>
		<description><![CDATA[Where have all your good words gone? Where have all your stories gone? From Where Have All Your Good Words Gone by Laura Gibson Long, long ago, way back in December of 2011 the latest blog entry appeared in Security For All. What become of the author and his intrepid sidekicks Dr. Security and Captain X-Ploit [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secforall.info&amp;blog=4666223&amp;post=1981&amp;subd=webjoseph425&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="I'm back" src="http://webjoseph425.files.wordpress.com/2012/03/im-back.jpg?w=109&#038;h=118" alt="" width="109" height="118" /><em>Where have all your good words gone?<br />
Where have all your stories gone?<br />
From <strong>Where Have All Your Good Words Gone</strong> by <strong>Laura Gibson</strong></em></p>
<p>Long, long ago, way back in December of 2011 the latest blog entry appeared in Security For All. What become of the author and his intrepid sidekicks <a title="Greatest Security Breakthrough" href="http://secforall.info/2009/07/20/greatest-security-breakthrough/" target="_blank">Dr. Security</a> and <a title="Captain X-Ploit vs. The Bills" href="http://secforall.info/2010/02/16/captain-x-ploit-vs-the-bills/">Captain X-Ploit</a> has been the stuff of no small amount of speculation among the Information Security literati. Actually to my knowledge there has been no speculation at all. Small or otherwise. But I digress.</p>
<p>By way of excuses let me say that a whole bunch of stuff has happened since that <a title="Another Nasty Christmas Present from Facebook" href="http://secforall.info/2011/12/21/another-nasty-christmas-present-from-facebook/" target="_blank">last post</a> around Christmas time. Primarily, in January I started  a new position as Software Architect for Trustwave. I could let you guess at my employer like I did back when I first started blogging while working at StillSecure, but anyone can look it up on LinkedIn so the thrill is gone. Also let me point out that Trustwave and Spiderlabs are quite well known in the blogosphere having several excellent corporate blogs. This is not one of them. Whatever I say here is strictly me and they have nothing to with it. Much less approve or disapprove. In any case I&#8217;ve been drinking from the firehose since January without much opportunity to do much of anything else.  Thus the reason for the 3 month hiatus of Security For All.</p>
<p>But I&#8217;m back. And so is the good Captain. So stay tuned.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/webjoseph425.wordpress.com/1981/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/webjoseph425.wordpress.com/1981/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/webjoseph425.wordpress.com/1981/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/webjoseph425.wordpress.com/1981/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/webjoseph425.wordpress.com/1981/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/webjoseph425.wordpress.com/1981/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/webjoseph425.wordpress.com/1981/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/webjoseph425.wordpress.com/1981/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/webjoseph425.wordpress.com/1981/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/webjoseph425.wordpress.com/1981/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/webjoseph425.wordpress.com/1981/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/webjoseph425.wordpress.com/1981/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/webjoseph425.wordpress.com/1981/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/webjoseph425.wordpress.com/1981/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secforall.info&amp;blog=4666223&amp;post=1981&amp;subd=webjoseph425&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secforall.info/2012/03/16/whatever-happened-to-security-for-all/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8cb97cf53947d19ef34fcb97961820df?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Joe</media:title>
		</media:content>

		<media:content url="http://webjoseph425.files.wordpress.com/2012/03/im-back.jpg?w=284" medium="image">
			<media:title type="html">I&#039;m back</media:title>
		</media:content>
	</item>
		<item>
		<title>Another nasty Christmas Present from Facebook</title>
		<link>http://secforall.info/2011/12/21/another-nasty-christmas-present-from-facebook/</link>
		<comments>http://secforall.info/2011/12/21/another-nasty-christmas-present-from-facebook/#comments</comments>
		<pubDate>Wed, 21 Dec 2011 23:11:25 +0000</pubDate>
		<dc:creator>Joseph Webster</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[professional]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[credit rating]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://secforall.info/?p=1968</guid>
		<description><![CDATA[Whenever somebody comes up with a new business idea involving social media it&#8217;s usually time to cover your private parts. To the extent that you can. Take this idea from Hong Kong-based microlending startup Lenddo as described in this article in The Observer. [Lendo] calls itself “the first credit scoring service that uses your online social network to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secforall.info&amp;blog=4666223&amp;post=1968&amp;subd=webjoseph425&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="bad Christmas present" src="http://media.egotvonline.com/wp-content/uploads/2010/12/bad-Christmas-present.jpg" alt="" width="100" height="85" />Whenever somebody comes up with a new business idea involving social media it&#8217;s usually time to cover your private parts. To the extent that you can. Take this idea from Hong Kong-based microlending startup <a id="" href="http://lenddo.com/" target="_blank">Lenddo</a> as described in <a title="As Banks Start Nosing Around Facebook and Twitter, the Wrong Friends Might Just Sink Your Credit" href="http://www.betabeat.com/2011/12/13/as-banks-start-nosing-around-facebook-and-twitter-the-wrong-friends-might-just-sink-your-credit/2/" target="_blank">this article in The Observer</a>.</p>
<blockquote><p><em>[Lendo] calls itself “the first credit scoring service that uses your online social network to assess credit.” The first thing Lenddo asks for is a Facebook account; then it wants access to Gmail, Twitter, Yahoo, and Windows Live. The Observer was given a respectable score of 470. But when we tried to apply for a loan, we were told “you need at least 3 connections with scores above 400 in your Lenddo trusted network.”</em></p>
<p><em>The company’s algorithm is proprietary and secret, said CEO Jeff Stewart, but the primary metric is what Lenddo knows about the people you’re friends with. “We think that in the age of the internet you should be able to establish your reputation and your identity through your social graph, through your on- and offline community, and use that to get access to financial products and information,” he said.</em></p>
<p><em>If Lenddo sees one of your best Facebook buddies took out a loan and paid it back, there’s a good chance you will too. “Our backgrounds are in machine learning and pattern recognition,” Mr. Stewart said. “It’s some serious math.</em></p>
<p><em>“There’s no reason there shouldn’t be thousands of engineers working to assess creditworthiness.”</em></p></blockquote>
<p>I should note here that I too have a background in machine learning and pattern recognition but would hardly summarize it as &#8220;some serious math&#8221; except maybe to US GOP Presidential nominee hopefuls to whom addition is apparently an arcane art, but I digress&#8230;</p>
<p>Marketing hype aside, this simply checks to see if your Facebook &#8220;friends&#8221; are creditworthy and makes the unwarranted leap that you are like them with respect to creditworthiness. Problem with that idea is when you have &#8220;friends&#8221; with completely fictional profiles on social media sites. Like say <a title="Can you be social and private simultaneously?" href="http://secforall.info/2010/06/05/can-you-be-social-and-private-simultaneously/" target="_blank">me (when I was on Facebook)</a> or <a title="The Joy of Tech" href="http://www.joyoftech.com/joyoftech/joyarchives/1629.html" target="_blank">Nitrozac and Snaggy</a>. If you had friended me on Facebook, services like Lendo might conclude (not without basis) that you were a total wackjob. Seriously though, there is a very ugly side to this social credit rating business.</p>
<blockquote><p><em>In another nifty but nefarious innovation, Lenddo reserves the right to broadcast your loan status if you fall into default. As the site warns: “Failure to repay will negatively impact your Lenddo score, as well as the score of your Lenddo friends. Lenddo MAINTAINS THE RIGHT TO NOTIFY YOUR FRIENDS, FAMILY AND COMMUNITY if the borrower fails to repay, however, this is only done after several notifications to the borrower and an attempt to work out a payment plan.”</em></p>
<p><em>“I think Mark Zuckerberg said it best,” Mr. Stewart said. “Every industry will be in fact impacted by social.”</em></p>
<p><em>Banks have been curious about using social media to gauge risk for at least a year, said Matt Thomson, VP of platform at Klout, which calculates “influence” based on a user’s social media activity. Determining creditworthiness is not a core product of Klout’s, he said, but banks have approached the startup to ask about it. He wouldn’t name names. “It’s really like the who’s who of banking,” he said.</em></p>
<p><em>(Mr. Stewart of Lenddo also said his startup is approached “regularly” by major banks curious about the algorithm.)</em></p></blockquote>
<p>So let me get this straight, the same weasels who trashed the global economy with financial instruments that institutionalized fraudulent and unsecured, except by other equally dodgy financial instruments like credit default swaps, mortgages are now using the fact that everyone knows &#8211; or is &#8211; someone who was victimized in this debacle to further victimize people?</p>
<p>This time I&#8217;m not even going though the pretense of some imaginary conversation about privacy being dead, I&#8217;ll just throw out this quote and leave it at that.</p>
<blockquote><p><em>Media theorist Douglas Rushkoff dismissed the idea that social media credit scoring is a serious erosion of privacy, mostly because there’s nothing left to hide. “We’re already in the nightmare scenario,” he wrote in an email. “They already know everything about you—more than most of us realize. If anything, the addition of social networking information to this data mining will help us come to some understanding of how much more these companies know about us than we know about ourselves.”</em></p></blockquote>
<p>And there you have it folks from the lips (or keyboard) of a bona fide Media theorist &#8211; social media credit scoring doesn&#8217;t invade your privacy because you have no privacy to invade. So if you are still on Facebook you might as well just bend over. Again. Or quit being a tool. I&#8217;m just saying.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/webjoseph425.wordpress.com/1968/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/webjoseph425.wordpress.com/1968/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/webjoseph425.wordpress.com/1968/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/webjoseph425.wordpress.com/1968/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/webjoseph425.wordpress.com/1968/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/webjoseph425.wordpress.com/1968/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/webjoseph425.wordpress.com/1968/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/webjoseph425.wordpress.com/1968/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/webjoseph425.wordpress.com/1968/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/webjoseph425.wordpress.com/1968/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/webjoseph425.wordpress.com/1968/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/webjoseph425.wordpress.com/1968/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/webjoseph425.wordpress.com/1968/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/webjoseph425.wordpress.com/1968/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secforall.info&amp;blog=4666223&amp;post=1968&amp;subd=webjoseph425&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secforall.info/2011/12/21/another-nasty-christmas-present-from-facebook/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8cb97cf53947d19ef34fcb97961820df?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Joe</media:title>
		</media:content>

		<media:content url="http://media.egotvonline.com/wp-content/uploads/2010/12/bad-Christmas-present.jpg" medium="image">
			<media:title type="html">bad Christmas present</media:title>
		</media:content>
	</item>
		<item>
		<title>Thanks for all the phishing in 2011</title>
		<link>http://secforall.info/2011/11/24/thanks-for-all-the-phishing-in-2011/</link>
		<comments>http://secforall.info/2011/11/24/thanks-for-all-the-phishing-in-2011/#comments</comments>
		<pubDate>Thu, 24 Nov 2011 07:37:01 +0000</pubDate>
		<dc:creator>Joseph Webster</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Nigerian 419]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Thanksgiving]]></category>
		<category><![CDATA[Unemployment]]></category>

		<guid isPermaLink="false">http://secforall.info/?p=1942</guid>
		<description><![CDATA[So thank you for showing me, That best friends can not be trusted, And thank you for lying to me, Your friendship and good times we had you can have them back. From Thank You by Simple Plan In 2009, the first year of this blog, in honor of Thanksgiving here in the USA I [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secforall.info&amp;blog=4666223&amp;post=1942&amp;subd=webjoseph425&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="Thank You" src="http://www.lovelleofficial.com/wp-content/uploads/2011/06/thank_you.jpg" alt="" width="130" height="100" /></p>
<blockquote><p><em>So thank you for showing me,<br />
That best friends can not be trusted,<br />
And thank you for lying to me,<br />
Your friendship and good times we had you can have them back.<br />
From <strong>Thank You</strong> by <strong>Simple Plan</strong></em></p></blockquote>
<p>In 2009, the first year of this blog, in honor of Thanksgiving here in the USA I posted an entry about <a title="Thanks for all the phishing" href="http://secforall.info/2009/11/22/thanks-for-all-the-phishing/" target="_blank">some things I would have been thankful for in 2009. If they were even remotely true</a>. I’m a collector and, dare I say connoisseur, of Nigerian 419 style phishing messages. Since then it&#8217;s become an annual event. So without further ado, here is a sampling of my favorites from 2011. The things I’m thankful for.</p>
<p>I am thankful that the <a title="Compensation Details" href="http://webjoseph425.files.wordpress.com/2011/11/compensation-details.pdf" target="_blank">Nigerian Government has finally recognized their negligence and are going to help me get my rightful inheritance at last</a>.</p>
<blockquote><p><em>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-ICPC NIGERIA ( An Anti-Fraud Unit)</em><br />
<em>&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;&#8230;we fight against fraud, funds delay and impersonation.</em><br />
<em>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;Head Office: Plot 802, Constitution Avenue</em></p>
<p><em> A LETTER OF COMPENSATION/SETTLEMENT.</em></p>
<p><em> This letter will definitely be amazing to you because of its realistic value.</em></p>
<p><em>Sorry for the inconveniences that was rendered to you in your line of Inheritance Payment transaction with some impersonators some while ago.</em><br />
<em>I know that this letter will hit you by surprise, but firstly I will like to introduce myself; I am (Mr Emmanuel Ayoola ) the Legal chairman of &#8220;ICPC&#8221;, (Nigeria&#8217;s Anti-Fraud Unit).</em></p>
<p><em>On the 1st of October  2000 the former President of The Federal Republic of Nigeria (Chief Olusegun Obasanjo) introduced a Commission named the &#8220;ICPC&#8221;, (Nigeria&#8217;s Anti-Fraud Unit) which is duly registered under the United Nations (U.N.O). Secondly, we are mandated by the United States Government to Settle foreign indebted beneficiaries to satisfactory in other to maintain peace in the world at large and also to create a good relationship with the international bodies.</em></p>
<p><em>You are being contacted by this office today because your Case data is the very first File on our Settlement Files Cabinet. From our Intelligent investigations and Probing processes we discovered that you are a victim of  delay.</em><br />
<em>The &#8220;ICPC&#8221;, is faithfully under my governance as the Legal Chairman of the great Commission and to this Authority I took an oath of allegiance to settle all victims peacefully.</em><br />
<em>This Memorandum is to notify you that you will be settled by the Nig Govt from our initial Deposit. Your settlement will be actualized within  three working days after your response to this Official Letter.</em></p></blockquote>
<p>I was definitely amazed because of the <em>realistic value</em>. And any organization with the motto <em>we fight against fraud, funds delay and impersonation</em> just has to be legit, right? Although I am worried by the address of the Head Office, <em>Plot 802, Constitution Avenue</em>. Sounds like a cemetery.</p>
<p>I am thankful that <a title="official_letter_from_fbi" href="http://webjoseph425.files.wordpress.com/2011/11/official_letter_from_fbi.pdf" target="_blank">the FBI is willing to assist me in transferring my funds from the Central Bank of Nigeria which they discovered through attempting to wiretap the internet</a>.</p>
<blockquote><p><em>ATTENTION: BENEFICIARY </em><br />
<em>FROM: ROBERT MUELLER III EXECUTIVE DIRECTOR FBI FEDERAL BUREAU OF INVESTIGATION WASHINGTON DC.</em></p>
<p><em>FBI SEEKING TO WIRETAP INTERNET </em><br />
<em>The federal bureau of investigation (FBI).Through our intelligence-monitoring network has discovered that the transaction that the bank contacted you previously was legal. Recently the fund has been legally approved to be paid via Central Bank of Nigeria. We the federal bureau of investigation (FBI) Washington Dc, in conjunction with the United Nations (UN) financial department have investigated through our monitoring network noting that your transaction with the Central Bank of Nigeria legal. You have the legitimate right to complete your transaction to claim your fund <strong>US$15.5,000,000.00</strong>(Fifteen million five Hundred Thousand united states dollars).</em></p></blockquote>
<p>First <em>Mr Emmanuel Ayoola</em> finds my missing megabucks and then <em>ROBERT MUELLER III EXECUTIVE DIRECTOR FBI</em> contacts me directly to let me know it&#8217;s all legal. How sweet is that!</p>
<p>I am thankful for <a title="am-writing-this-letter-with-tears-and-sorrow-from-my-heart" href="http://webjoseph425.files.wordpress.com/2011/11/am-writing-this-letter-with-tears-and-sorrow-from-my-heart.pdf" target="_blank">22-year-old princesses from Burkina Faso who want not only a relationship but desire my help in investing large sums of money</a>.</p>
<blockquote><p><em>Dear Sir / Madam, </em><br />
<em>How are you today,I hope fine? I am a female student from University of Burkina-Faso, Ouagadougou. I am 22 yrs old. I will love to have a long-term relationship with you and to know more about you. I would like to build up a solid foundation with you in time coming if you can be able to help me in this transaction. Well, my father died earlier 1 year ago and left I and my junior brother behind. He was a king, which our town citizens titled him over sixteen years before his death.I was a princess to him and I am the only person who can take care of his wealth now because my junior brother is still young and my late mother is also late two years ago before the death of my Late father. He left the sum of <strong>)Twelve Million Five Hundred Thousand united state dollars ($12.5mUSD)</strong> in a Bank. This money was annually paid into my late fathers account from Gold Exploring companies operating in our locality for the compensation of youth and community development in our jurisdiction. I don&#8217;t know how and what I will do to invest this money somewhere in abroad, so that my father&#8217;s kindred will not take over what belongs to my father and our family, which they were planning to do without my present because I am a female as stated by our culture in the town.Now, I urgently need your humble assistance to move this money from the Bank of Africa to your bank account after which i come over to meet with you. and I strongly believe that by the grace of God, you will help me invest this money wisely. I am ready to pay 40% of the total amount to you if you help us in this transaction and another 10% interest of Annual After Income to you, for handling this transaction for us, which you will strongly have absolute control over. Please if you are interested to help me, then get back to me urgent so that I will give you more details including my picturs. </em><br />
<em>Yours sincerely, </em><br />
<em>Princess Ruki Yaya.</em></p></blockquote>
<p>As much as I&#8217;d like to help Princess Ruki Yaya I&#8217;m concerned about the statement <em>I am a female as stated by our culture in the town</em>. I&#8217;m only interested in women who are female in all cultures everywhere.</p>
<p>I am thankful for <a title="Dearest One" href="http://webjoseph425.files.wordpress.com/2011/11/dearest-one.pdf" target="_blank">dying rich guys who recognize my humanitarian fervor and want to leave me lots of money</a>.</p>
<blockquote><p><em>Subject: Dearest One, </em><br />
<em>Dearest One, Assalam Allekum, My name is Abul Kalam Azad. I am a dying man who have decided to Donate the sum of $18million dollars. to you for the good work of the Humanity. Please contact me via. Email: aazad@yahoo.cn for detailed information on this noble project of mine. Please note that I have WILLED <strong>$18m</strong> to you by quoting my personal reference number De/Jds/533/0068/HtrI/33ln/eg. So that i can confirm that you actually received my email notice to you. Wassalam and Regards, Abul Kalam Azad</em></p></blockquote>
<p>While I appreciate the generous bequest, what&#8217;s up with that &#8220;Dearest One&#8221; stuff and the Yahoo! China email address?</p>
<p>I am thankful for <a title="accept-this-little-token-with-good-faith" href="http://webjoseph425.files.wordpress.com/2011/11/accept-this-little-token-with-good-faith.pdf">dying rich women who recognize my humanitarian fervor and want to leave me lots of money</a>.</p>
<blockquote><p><em>Goodday, </em></p>
<p><em>My names are Mrs. Irene Cesarec. I was diagnosed of cancer about 2 years ago, and was receiving treatment for it, but now the doctors are saying I have a short time to live.   </em></p>
<p><em>When I was in better health, I never really cared for any body with no children of my own and a late husband I was a selfish and greedy person. I have decided to donate the sum of <strong>$10.8M</strong> to you, so you can disburse to charities, widows, orphans and less privileged. I was doing this myself but now my health has deteriorated, I wanted my relatives to do this for me but they only saw it as an opportunity to enrich themselves. </em></p>
<p><em>I will be going in for an operation soon, I want this last act of mine to be an offering unto God, perhaps he will have mercy on me. Please contact my lawyer with the below: </em></p>
<p><em>Quote my ref # : will/Wlaw/Pn/lr/93/ytx/ when responding. </em></p>
<p><em>I am sending him a copy of this message as well so he is aware of my intentions, Please use the funds well and always extend the good works to others. </em></p>
<p><em>Stay blessed,</em></p>
<p><em>Mrs. Irene Cesarec.</em></p></blockquote>
<p>Whoa! It&#8217;s like deja vu. Sorry Abul but I&#8217;m going to have to go with Irene. Even though she&#8217;s only giving me <em><strong>$10.8M</strong></em>  she admits to being <em>a selfish and greedy person</em>. My kind of benefactor.</p>
<p>I am thankful for <a title="prize-notification-2011-new-toyota-cars-promotion" href="http://webjoseph425.files.wordpress.com/2011/11/prize-notification-2011-new-toyota-cars-promotion.pdf">winning contests staged in places I&#8217;ve never been to promote products I don&#8217;t buy that I don&#8217;t recall entering</a>.</p>
<blockquote><p><em>TOYOTA MOTORS CORPORATION INTERNATIONAL PRIZE NOTIFICATION 2011 NEW CARS PROMOTION </em><br />
<em>We are pleased to inform you of the result of the just concluded annual final draws held on the 1ST OF January,2011 by Toyota Motor Company in conjunction with the Japan International Email Lottery Worldwide Promotion,your email address was among the 20 Lucky winners who won US$1,000,000.00 each on the Toyota Motors Company Email Promotion programme dated as stated above.This is from the total price of $20 million United State Dollars ($20,000,000.00usd)shared among the 20 lucky winners.</em></p>
<p><em>The online draws was conducted by a random selection of email addresses from an exclusive list of 35,031 E-mail addresses of individuals and corporate bodies picked by an advanced automated random computer search from the internet. However, no tickets were sold but all email addresses were assigned to different ticket numbers for representation and privacy to make sure the money reaches you.</em></p></blockquote>
<p>Uh&#8230; Not sure I understand any of that or what it has to do with Toyota, but hey I&#8217;ll take the cool mil.</p>
<p>Since 2011 was a terrible year for employment I&#8217;m thankful that I&#8217;ve received so many <a title="Database Management Position" href="http://webjoseph425.files.wordpress.com/2011/11/database-management-position1.pdf" target="_blank">guaranteed job offers like this one from a company that respects my awesome database management abilities</a>.</p>
<blockquote><p><em>Subject: Database Management Position </em></p>
<p><em>We have assessed your curriculum vitae and wish to introduce to you a job opportunity in clerical and administrative services at NHN Team. The ideal applicant must possess outstanding communication skills, be attentive to details, perfect reporting skills, responsible and able to work in a fast paced working environment. </em><br />
<em>The principal duties of the job include but are not limited to: recording orders for services and merchandise, compiling transaction records, compiling correspondence, performing basic bookkeeping and other clerical duties. </em><br />
<em>At NHN Group we provide an encouraging working environment. The position offers an attractive performance related commission. Flexible schedules, part time and full time available. If you are interested in entering an organization where contribution matters, please get back to work-dept@nhn-jobs.com and we will forward to you further information on this opportunity. </em><br />
<em>Best regards, </em><br />
<em>NHN Team</em></p></blockquote>
<p>I&#8217;m not even sure what a <em>curriculum vitae</em> is but apparently mine indicates that I would be good at clerical and administrative services which is apparently database management.</p>
<p>On a more serious note there was a marked increase in the number of phony job offer phishing in 2011. I usually get several good ones per year, but in 2011 out of the 60 funny emails I saved, 37 of them &#8211; a whopping 62% &#8211; were phony job offers. Some were completely silly like the one above, but others were pretty decent CareerBuilder forgeries. So while I mock these ham-fisted attempts at fooling the naive, it&#8217;s sobering to recognize that there are a lot of really desperate unemployed folks out there who are willing to try almost anything to get a job. And the slimeballs who are exploiting that nauseate me.</p>
<p>Once again I’m thankful that <a title="Google Translate" href="http://translate.google.com/" target="_blank">Google Translate</a> hasn’t improved significantly since 2010.  Otherwise this stuff wouldn’t be nearly as amusing. So Happy Thanksgiving 2011. So long and thanks for all the phish.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/webjoseph425.wordpress.com/1942/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/webjoseph425.wordpress.com/1942/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/webjoseph425.wordpress.com/1942/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/webjoseph425.wordpress.com/1942/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/webjoseph425.wordpress.com/1942/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/webjoseph425.wordpress.com/1942/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/webjoseph425.wordpress.com/1942/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/webjoseph425.wordpress.com/1942/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/webjoseph425.wordpress.com/1942/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/webjoseph425.wordpress.com/1942/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/webjoseph425.wordpress.com/1942/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/webjoseph425.wordpress.com/1942/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/webjoseph425.wordpress.com/1942/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/webjoseph425.wordpress.com/1942/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secforall.info&amp;blog=4666223&amp;post=1942&amp;subd=webjoseph425&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secforall.info/2011/11/24/thanks-for-all-the-phishing-in-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8cb97cf53947d19ef34fcb97961820df?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Joe</media:title>
		</media:content>

		<media:content url="http://www.lovelleofficial.com/wp-content/uploads/2011/06/thank_you.jpg" medium="image">
			<media:title type="html">Thank You</media:title>
		</media:content>
	</item>
		<item>
		<title>Hiding in Glass Houses</title>
		<link>http://secforall.info/2011/10/26/hiding-in-glass-houses/</link>
		<comments>http://secforall.info/2011/10/26/hiding-in-glass-houses/#comments</comments>
		<pubDate>Thu, 27 Oct 2011 05:07:08 +0000</pubDate>
		<dc:creator>Joseph Webster</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[professional]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Find My Friends]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://secforall.info/?p=1911</guid>
		<description><![CDATA[You&#8217;re building glass houses on the sand Then you stand around and shake your head When they all fall down From Glass Houses by Steel Magnolias So the big tech and style news this month, in case you missed it, was Apple&#8217;s hyperbole laden and new(ish) iPhone 4s and iOS5. This baby boasts everything better, faster [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secforall.info&amp;blog=4666223&amp;post=1911&amp;subd=webjoseph425&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="Glass_House" src="http://www.fantom-xp.com/wallpapers/29/Glass_House.jpg" alt="" width="127" height="80" /></p>
<blockquote><p><em>You&#8217;re building glass houses on the sand</em><br />
<em> Then you stand around and shake your head</em><br />
<em> When they all fall down</em><br />
<em> From <strong>Glass Houses</strong> by <strong>Steel Magnolias</strong></em></p></blockquote>
<p>So the big tech and style news this month, in case you missed it, was Apple&#8217;s hyperbole laden and new(ish) iPhone 4s and iOS5. This baby boasts everything better, faster and smarter (Siri notwithstanding) than the old school iPhone 4. Including this swell new(ish) app called <a title="Find My Friends iOS 5 app revealed" href="http://www.slashgear.com/find-my-friends-ios-5-app-revealed-04185210/" target="_blank">Find My Friends</a> which is described in Slashgear thusly [<em>emphasis mine</em>].</p>
<blockquote><p><em>The free app, which uses GPS to locate your friends and family and, <strong>if the privacy settings mash correctly</strong>, display them on a map in real-time, can be found <a href="http://itunes.apple.com/us/app/find-my-friends/id466122094?mt=8" target="_blank">here</a>.</em></p></blockquote>
<p>But as <a title="MythAdventures" href="http://en.wikipedia.org/wiki/MythAdventures" target="_blank">Aahz the Pervect</a> was wont to say &#8220;Therein lies the story&#8221;. That deal about privacy settings should be a clue [<em>hint - turn them all off</em>]. There&#8217;s even an interesting <a title="Divorcing wife. Thanks iPhone 4s and Find My Friends" href="http://forums.macrumors.com/showthread.php?t=1254206" target="_blank">thread on MacRumors</a> making it&#8217;s way around the blogosphere with a tale to make divorce lawyers weep. In agony or ecstasy depending on which side they represent.</p>
<blockquote><p><em>I got my wife a new 4s and loaded up find my friends without her knowing. She  told me she was at her friends house in the east village. I&#8217;ve had suspicions  about her meeting this guy who live uptown. Lo and behold, Find my Friends has  her right there.</em></p></blockquote>
<p>Regardless of the veracity of the post, I posit the following question: Who really thinks it&#8217;s a good idea to have everyone know exactly (within 10 meters) where you are at all times? I can think of a number of folks, in addition to suspicious spouses, who love this idea including:</p>
<ol>
<li>Law Enforcement &#8211; rounding up the usual suspects has never been easier</li>
<li>Burglars who prefer victims to be elsewhere than the location being burgled &#8211; saves all that unpleasantness associated with being surprised by irate property owners.</li>
<li>Employers who want to verify that employees are actually working from home &#8211; or really at the dentist instead of interviewing for another job.</li>
</ol>
<p>Now certainly there might be situations where this feature would have a non-nefarious or even beneficial usage, like say finding a missing child. I&#8217;m just doubtful that would work in a serious situation like say kidnapping. Unless the kidnapper was stupid enough to keep the phone,  like say users of Find My Friends.</p>
<p>You see, here&#8217;s the deal &#8211; owning a smart phone or other GPS-enabled mobile device is like hiding in a glass house. Unless you take extraordinary measures anyone can find you. At any time.  Problem is most users of the aforementioned devices have no idea how exposed they are by default &#8211; not to mention what happens when they use an app like Find My Friends.</p>
<p>About now you may be thinking, &#8220;Yeah, well maybe that&#8217;s true, but everybody knows that privacy has been dead since 1999 so deal with it&#8221;,  channeling Scott McNealy&#8217;s infamous comment. Or even &#8220;You shouldn&#8217;t be worried about privacy unless you have something to hide&#8221;.</p>
<p>And that, my friend, is what concerns me. When everyone accepts this truism and becomes willing to trade their privacy &#8211; and ultimately their liberty to disagree with whatever authority is currently watching &#8211; for slick but useless diversions there will be serious consequences.</p>
<p>We may not be able to do anything about our modern life in glass houses. But at least we can try to hide without constantly screaming our location.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/webjoseph425.wordpress.com/1911/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/webjoseph425.wordpress.com/1911/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/webjoseph425.wordpress.com/1911/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/webjoseph425.wordpress.com/1911/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/webjoseph425.wordpress.com/1911/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/webjoseph425.wordpress.com/1911/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/webjoseph425.wordpress.com/1911/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/webjoseph425.wordpress.com/1911/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/webjoseph425.wordpress.com/1911/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/webjoseph425.wordpress.com/1911/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/webjoseph425.wordpress.com/1911/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/webjoseph425.wordpress.com/1911/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/webjoseph425.wordpress.com/1911/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/webjoseph425.wordpress.com/1911/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secforall.info&amp;blog=4666223&amp;post=1911&amp;subd=webjoseph425&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secforall.info/2011/10/26/hiding-in-glass-houses/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8cb97cf53947d19ef34fcb97961820df?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Joe</media:title>
		</media:content>

		<media:content url="http://www.fantom-xp.com/wallpapers/29/Glass_House.jpg" medium="image">
			<media:title type="html">Glass_House</media:title>
		</media:content>
	</item>
		<item>
		<title>Security For All is three years old!</title>
		<link>http://secforall.info/2011/10/09/security-for-all-is-three-years-old/</link>
		<comments>http://secforall.info/2011/10/09/security-for-all-is-three-years-old/#comments</comments>
		<pubDate>Mon, 10 Oct 2011 05:24:25 +0000</pubDate>
		<dc:creator>Joseph Webster</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[professional]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Security for All]]></category>
		<category><![CDATA[third birthday]]></category>

		<guid isPermaLink="false">http://secforall.info/?p=1889</guid>
		<description><![CDATA[Happy Birthday, now your one year older. Happy Birthday, your life still isn&#8217;t over. Happy Birthday, you did not accomplish much. But you didn&#8217;t die this year i guess that&#8217;s good enough. From Funny Happy Birthday Song by Adam Sandler Hard to believe that last month marked the third anniversary of Security For All. Actually [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secforall.info&amp;blog=4666223&amp;post=1889&amp;subd=webjoseph425&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="happy-3rd-birthday-foil-helium-party-balloons-pack-of-2-4664-p" src="http://www.partykiosk.co.uk/ekmps/shops/domestix/images/happy-3rd-birthday-foil-helium-party-balloons-pack-of-2-4664-p.bmp" alt="" width="112" height="97" /></p>
<blockquote><p><em>Happy Birthday, now your one year older.<br />
Happy Birthday, your life still isn&#8217;t over.<br />
Happy Birthday, you did not accomplish much.<br />
But you didn&#8217;t die this year i guess that&#8217;s good enough.<br />
From <strong>Funny Happy Birthday Song</strong> by <strong>Adam Sandler</strong></em></p></blockquote>
<p>Hard to believe that last month marked the third anniversary of <a title="Security For All" href="http://secforall.info" target="_blank">Security For All</a>. Actually the really hard thing to believe is that I actually found time to do this post. Whining aside, this last year has been a corker for everybody. A whole bunch of wild, wacky, wonderful, wasteful, woeful and wicked things happened during the last 13 months. I &#8216;ll leave it as an exercise to the reader to assign the appropriate W-word to the items in the following list. In no particular order:</p>
<ul>
<li>Steve Jobs, co-founder, chairman and former CEO of Apple passed away on October 5th, 2011 after a long struggle with pancreatic cancer. He was just 56 years old. It&#8217;s hard to imagine anyone who had a greater impact on technology and society. He will be sorely missed.</li>
<li>Britain&#8217;s Prince William announced his intention to marry long-term girlfriend Kate Middleton on November 16, 2010 , and subsequently followed through on that threat on April 29, 2011 where it was described thusly by USA Today: <em>More than a billion eyes were on Kate Middleton as she stepped out of the queen&#8217;s 1977 Rolls-Royce Phantom VI in front of London&#8217;s Westminster Abbey on Friday wearing a wedding dress of fairy-tale princess-esque proportions — a dress that will be immortalized in fashion history.</em> There were at least as many spammers and phishers rejoicing over the joyous event.</li>
<li>Nasa discovered a new lifeform, a bacteria they christened the GFAJ-1 strain, that apparently substituted arsenic for phosphorus, sparking all sorts of extra-terrestrial bacterial visitation speculation. Would have been game-changing if only it had been accurate. Oh well another study for the <a title="The Journal of Irreproducible Results" href="http://www.jir.com/" target="_blank">The Journal of Irreproducible Results</a>.</li>
<li>The United States Senate voted to repeal the U.S. military&#8217;s &#8216;Don&#8217;t Ask, Don&#8217;t Tell&#8217; policy of officially sanctioned homophobia. While the law has been in effect for several months now apparently a number of right wing politicians and military cheeses haven&#8217;t gotten the memo. Or maybe they just can&#8217;t figure out how to use the <a title="Reality distortion field" href="http://en.wikipedia.org/wiki/Reality_Distortion_Field" target="_blank">Reality distortion field</a> that worked out so well for President Bill Clinton and Apple CEO Steve Jobs. The more plausible possibility is that they can&#8217;t find anyone on their staff able to read something as complex as a memo.</li>
<li>U.S. Rep. Gabrielle Giffords was shot in the head by a lone wack-job after being included on Sarah Palin&#8217;s &#8216;Hit List&#8217;. But the craziness didn&#8217;t stop there. Sales of semiautomatic Glock pistols like that used in the shooting spiked in Arizona and across the nation in the days following the attack. Fortunately Ms. Giffords was able to overcome the staggering odds and appeared in person at her husband, Astronaut Mark Kelly&#8217;s retirement from the Navy. Not sure what the moral of this story is but I&#8217;m a little reluctant to hang out anywhere near people who disagree with Ms. Palin.</li>
<li>The now aptly monikered <a title="Arab Spring" href="http://en.wikipedia.org/wiki/2010%E2%80%932011_Middle_East_and_North_Africa_protests" target="_blank">Arab Spring</a> began in January of 2011 with the president of <a title="Tunisian Revolution" href="/wiki/Tunisian_Revolution">Tunisia</a> being driven from power by violent protests over soaring unemployment and corruption. In the following months <a title="2011 Egyptian revolution" href="/wiki/2011_Egyptian_revolution">Egypt</a> and <a title="2011 Libyan civil war" href="/wiki/2011_Libyan_civil_war">Libya</a> have seen regime changes with  <a title="2011 Bahraini uprising" href="/wiki/2011_Bahraini_uprising">Bahrain</a>, <a title="2011 Syrian uprising" href="/wiki/2011_Syrian_uprising">Syria</a>, and <a title="2011 Yemeni uprising" href="/wiki/2011_Yemeni_uprising">Yemen</a> also seeing civil uprisings. If Desert Storm (U.S. vs. Iraq episode 1) was the first made-for-TV conflict, Arab Spring must certainly count as the first made-for-social-media revolution. Whoever said &#8220;The Revolution will not be tweeted&#8221; was dead wrong [<em>apologies to Gil Scott-Heron, who also died in 2011, and is maliciously mis-quoted here</em>]. It&#8217;s also been argued, debated [<em>no - scratch that - since real debate requires some level of basic knowledge and understanding of the topic which is simply not available in this case</em>] and pontificated on, via traditional and the newly enfrancised social media. Speaking at the e-G8 Internet Forum in Paris, Facebook CEO Mark Zuckerberg downplayed Facebook’s role in places like Cairo, Homs and  Tunis, saying &#8220;It’s not a Facebook thing, it’s an Internet thing,” when asked about his site’s influence on the Middle East’s popular uprisings. &#8220;There&#8217;s no value to Facebook in invading the privacy of folks in those places.&#8221; [<em>I made that last quote up - but I'm sure that's what he meant to say</em>].</li>
<li>A tsunami rammed the coast of Japan following a powerful 9.0-magnitude earthquake causing widespread devastation and essentially shutting down some of Japan&#8217;s largest manufacturers including Honda and Toyota. But by far the greatest damage that resulted from this disaster was the meltdown of the Fukushima Dai-ichi nuclear power station in northeast Japan. This part of the tale just kept getting worse each day as the Japanese government and Tokyo Electric Power Co (TEPCO) kept trying to reassure the public and the world that things were under control. Some would argue that it&#8217;s still not entirely under control as there have been elevated levels of radiation detected in the Pacific waters as far away as the west coast of the U.S. So now a tsunami caused by a monster earthquake has turned into the worst nuclear crisis since Chernobyl in 1986, costing TEPCO 1.1 trillion yen. So far.</li>
<li>Osama bin Laden, the mastermind of the 911 attack, was killed in a firefight with [<em>actually he was terminated with extreme prejudice by</em>] United States forces in Pakistan. Turns out he&#8217;d been living in relative comfort in Abbottabad. Right under the noses of our Pakistani &#8220;allies&#8221;. Pakistani officials were &#8220;Shocked, Shocked! To find Osama bin Laden living in Pakistan&#8221;. [<em>OK, I made that last quote up too</em>].</li>
<li>On May 22, 2011 a massive EF5 rated tornado tore through Joplin, Missouri, killing over 120 people, carving a mile-wide path of destruction through the city and leaving fully a third of the population homeless. Somehow the people of Joplin, with the help of many other Americans, managed to rebuild enough of the devastated city to open all schools on time for the fall semester. It&#8217;s stuff like this that keeps my scant faith in my fellow citizens alive.</li>
<li>Former Illinois Gov. Rod Blagojevich was found guilty on 17 out of 20 federal corruption charges — including all charges tied to allegations that the Chicago Democrat tried to trade an appointment to fill the U.S. Senate seat vacated by President Barack Obama. Guilty! Thank You, That is all. [<em>Apologies to Mr. Toad's Wild Ride</em>]</li>
<li>In a frenzy not seen since the televised O.J. Simpson trial, Court TV became the latest reality-TV-cum-spectator-sport. Complete with announcers and color commentators like Nancy Grace. First we had the trial of Casey Anthony, who allegedly murdered her daughter Kaylee, which got better ratings than any Soap Opera and triggered widespread protests when she was acquitted (much to the chagrin of the aforementioned Ms. Grace) and pitted Floridians against each other, some restaurants even refusing to serve jury members. Those jury members later whined that had they been allowed to listen to Nancy they would surely have reached the right decision. Then we had Warren Jeffs, a particularly egregious polygamist, child pornographer, prophet of doom and leader of strange religious cult centered, apparently, around him getting it on with very young girls being tried for that lifestyle choice. This trial was so salacious that even I was taken aback when Dr. Drew Pinsky insisted that it was the right, yea even the<strong> duty</strong> of the court TV &#8220;journalists&#8221; to show the videos of the nasty Rev. Jeffs deflowering his youngest &#8220;brides&#8221;, video apparently being a sacrament in this cult. I&#8217;m guessing that the CNN lawyers were offering up their own prayers that the FCC would ignore Dr. Drew&#8217;s apparent journalistic fervor and not go after them for child porn. And finally we have the ongoing show trial of Dr. Conrad Murray who allegedly administered the fatal dose of propofol that killed Michael Jackson. This trial is hardly worth the nightly hystrionics of Dr. Drew and Nancy Grace (tag teaming this one) since the worst that can happen to Dr. Murray (other that the fact that the king of pop died before he could get paid) is that he can get probation. He&#8217;s already lost his medical license not to mention his credibility with anyone other than celebrities with nasty prescription drug habits. If you don&#8217;t think Mark Mothersbaugh was right about &#8216;<a title="Devolution (biology)" href="/wiki/Devolution_(biology)">de-evolution</a>&#8216; you should tune in some time.</li>
<li>Then we had the &#8216;Spectaular Summer Debt Ceiling Crisis&#8217; starring the U.S. Congress with special guest stars Pres. Barack Obama and Timothy Geitner. This long running polical theater farce, based on the hit &#8216;Nero Fiddling&#8217; had them rolling in both aisles to the disgust of viewers all over the world. This amazing display of gridlock and political brinksmanship resulted in Standard &amp; Poor&#8217;s downgrading the creditworthiness of the U.S. government to AA+ from AAA. What a show.</li>
<li>In tech and business, Google acquired Motorola Motility, AT&amp;T attempted to acquire T-Mobile but was slapped down by the DOJ. HP released the TouchPad, announced it&#8217;s killing the product line, sold the few they had built at a fire sale which was so popular they ramped up for another TouchPad fire sale. WTF? Apparently the notoriously quick on the fire-the-CEO trigger HP board had the same reaction and dumped Leo Apotheker for Meg Whitman of (GOP and E-Bay fame). But not before the stock did a swan dive.</li>
<li>The Sony Playstation Network (PSN) was well and truly pwned. Fingers were pointed everywhere but in the end it was just good old bad engineering and security hubris that proved their undoing. That and trying to piss off PS3 modders.</li>
<li>Then there was Anonymous whose DDoS-in-the-name-of-protest efforts were alternately lionized and villified in the media and political circus and managed to annoy pretty much everybody at sometime or another. They didn&#8217;t like Sony either and were early scapegoats in the ongoing Sony CYA efforts. Their 15 minutes is waning fast, but those Guy Fawkes masks are totally bitchun.</li>
<li>Security Bloggers were busy little beavers with <a href="http://chuvakin.blogspot.com/" target="_blank">Dr. Anton Chuvakin</a> taking a new job at Gartner, <a href="http://www.mckeay.net/" target="_blank">Martin McKeay</a> and <a href="http://securosis.com/tag/joshua+corman" target="_blank">Josh Corman</a> taking jobs at Akamai,  <a href="http://www.secureconsulting.net/">Ben Tomhave</a> taking a job at LockPath, <a href="http://blog.uncommonsensesecurity.com" target="_blank">Jack Daniel </a>moving into a new gig at Tenable after they acquired Astaro and <a href="/s/ref=ntt_athr_dp_sr_15?_encoding=UTF8&amp;sort=relevancerank&amp;search-alias=books&amp;field-author=Kai%20Roer">Kai Roer</a> and <a href="/s/ref=ntt_athr_dp_sr_16?_encoding=UTF8&amp;sort=relevancerank&amp;search-alias=books&amp;field-author=Mourad%20Ben%20Lakhoua">Mourad Ben Lakhoua</a> editing a great book with articles by <a href="/s/ref=ntt_athr_dp_sr_1?_encoding=UTF8&amp;sort=relevancerank&amp;search-alias=books&amp;field-author=Dr.%20Anton%20Chuvakin">Dr. Anton Chuvakin</a>, <a href="/s/ref=ntt_athr_dp_sr_2?_encoding=UTF8&amp;sort=relevancerank&amp;search-alias=books&amp;field-author=Margaretha%20Eriksson">Margaretha Eriksson</a>, <a href="/s/ref=ntt_athr_dp_sr_3?_encoding=UTF8&amp;sort=relevancerank&amp;search-alias=books&amp;field-author=Alistar%20Forbes">Alistar Forbes</a>, <a href="/s/ref=ntt_athr_dp_sr_4?_encoding=UTF8&amp;sort=relevancerank&amp;search-alias=books&amp;field-author=Brian%20Honan">Brian Honan</a>, <a href="/s/ref=ntt_athr_dp_sr_5?_encoding=UTF8&amp;sort=relevancerank&amp;search-alias=books&amp;field-author=Alex%20Hutton">Alex Hutton</a>, <a href="/s/ref=ntt_athr_dp_sr_6?_encoding=UTF8&amp;sort=relevancerank&amp;search-alias=books&amp;field-author=Javvad%20Malik">Javvad Malik</a>, <a href="/s/ref=ntt_athr_dp_sr_7?_encoding=UTF8&amp;sort=relevancerank&amp;search-alias=books&amp;field-author=Wendy%20Nather">Wendy Nather</a>, <a href="/s/ref=ntt_athr_dp_sr_8?_encoding=UTF8&amp;sort=relevancerank&amp;search-alias=books&amp;field-author=Rob%20Newby">Rob Newby</a>, <a href="/s/ref=ntt_athr_dp_sr_9?_encoding=UTF8&amp;sort=relevancerank&amp;search-alias=books&amp;field-author=Kevin%20Riggins">Kevin Riggins</a>, <a href="/s/ref=ntt_athr_dp_sr_10?_encoding=UTF8&amp;sort=relevancerank&amp;search-alias=books&amp;field-author=Eric%20Schwab">Eric Schwab</a> and  <a href="/s/ref=ntt_athr_dp_sr_12?_encoding=UTF8&amp;sort=relevancerank&amp;search-alias=books&amp;field-author=Lori%20Mac%20Vittie">Lori Mac Vittie</a> &#8211; <a title="The Cloud Security Rules: Technology is your friend. And enemy. A book about ruling the cloud." href="http://www.amazon.com/Cloud-Security-Rules-Technology-friend/dp/1463691785/" target="_blank">The Cloud Security Rules: Technology is your friend. And enemy. A book about ruling the cloud.</a></li>
<li>Finally Captain X-Ploit went completely off the rails with two spectacular holiday specials. The Halloween Special consisting of four posts: <a title="The Devil Walks Among Trustonians" href="http://secforall.info/2010/10/26/captain-x-ploit-halloween-special-the-devil-walks-among-trustonians/" target="_blank">The Devil Walks Among Trustonians</a>, <a title="Movies Can be Fun" href="http://secforall.info/2010/10/27/captain-x-ploit-movies-can-be-fun/" target="_blank">Movies Can be Fun</a>, <a title="Nightmare on Dream Street" href="http://secforall.info/2010/10/28/captain-x-ploit-nightmare-on-dream-street/" target="_blank">Nightmare on Dream Street </a>and <a title="28 Stores Later" href="http://secforall.info/2010/10/31/captain-x-ploit-halloween-special-28-stores-later/" target="_blank"> 28 Stores Later </a>which spoofed the classic horror films <a title="Halloween" href="http://www.imdb.com/title/tt0077651/" target="_blank">Halloween</a>, <a title="The Ring" href="http://www.imdb.com/title/tt0298130/" target="_blank">The Ring</a>, <a title="Nightmare on Elm Street" href="http://www.imdb.com/title/tt0087800/" target="_blank">Nightmare on Elm Street</a> and <a title="Dawn of the Dead" href="http://www.imdb.com/title/tt0077402/" target="_blank">Dawn of the Dead</a> respectively. The good Captain faced crazed mass murderers, lethally cursed movies, dream demons and spam distributing zombies and prevailed with great and hilarious feats of hacking. The <a title="Amazing Cross Dimensional Christmas Special" href="http://secforall.info/2010/12/25/captain-x-ploit-amazing-cross-dimensional-christmas-special/" target="_blank">Amazing Cross Dimensional Christmas Special</a> was a heartwarming mashup of Fox&#8217;s “Fringe”, Dr. Suess’s “How the Grinch Stole Christmas” and Tim Burton’s “Nightmare Before Christmas” where David and President Ted save Christmas. Sort of.</li>
</ul>
<p>So stay tuned. Maybe we&#8217;ll be a bit more concientious about blogging at Security For All. Or not. But it will probably be pretty funny and borderline informational.</p>
<p>Oh and be sure to actually go to the <a title="Security For All " href="http://secforall.info">Security For All </a>blog site and check out our annual swell theme change.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/webjoseph425.wordpress.com/1889/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/webjoseph425.wordpress.com/1889/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/webjoseph425.wordpress.com/1889/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/webjoseph425.wordpress.com/1889/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/webjoseph425.wordpress.com/1889/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/webjoseph425.wordpress.com/1889/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/webjoseph425.wordpress.com/1889/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/webjoseph425.wordpress.com/1889/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/webjoseph425.wordpress.com/1889/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/webjoseph425.wordpress.com/1889/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/webjoseph425.wordpress.com/1889/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/webjoseph425.wordpress.com/1889/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/webjoseph425.wordpress.com/1889/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/webjoseph425.wordpress.com/1889/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secforall.info&amp;blog=4666223&amp;post=1889&amp;subd=webjoseph425&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secforall.info/2011/10/09/security-for-all-is-three-years-old/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8cb97cf53947d19ef34fcb97961820df?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Joe</media:title>
		</media:content>

		<media:content url="http://www.partykiosk.co.uk/ekmps/shops/domestix/images/happy-3rd-birthday-foil-helium-party-balloons-pack-of-2-4664-p.bmp" medium="image">
			<media:title type="html">happy-3rd-birthday-foil-helium-party-balloons-pack-of-2-4664-p</media:title>
		</media:content>
	</item>
		<item>
		<title>So they exposed your personal info in a breach. Now what?</title>
		<link>http://secforall.info/2011/08/22/so-they-exposed-your-personal-info-in-a-breach-now-what/</link>
		<comments>http://secforall.info/2011/08/22/so-they-exposed-your-personal-info-in-a-breach-now-what/#comments</comments>
		<pubDate>Mon, 22 Aug 2011 21:18:02 +0000</pubDate>
		<dc:creator>Joseph Webster</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[professional]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[data breach]]></category>
		<category><![CDATA[personal information]]></category>
		<category><![CDATA[PII]]></category>
		<category><![CDATA[PlayStation Network]]></category>

		<guid isPermaLink="false">http://secforall.info/?p=1878</guid>
		<description><![CDATA[And now &#8211; what do I do now? Oh, I don&#8217;t know Oh, I&#8217;m leaving And now, who&#8217;s gonna save me next time? From Now What by Lisa Marie Presley So there you are just minding your own business and chilling on PlayStation Network when&#8230; Yikes! PSN has been breached! And now you and 100 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secforall.info&amp;blog=4666223&amp;post=1878&amp;subd=webjoseph425&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="Confused" src="http://webjoseph425.files.wordpress.com/2011/08/confused.png?w=100&#038;h=100" alt="" width="100" height="100" /></p>
<blockquote><p><em>And now &#8211; what do I do now?</em><br />
<em> Oh, I don&#8217;t know</em><br />
<em> Oh, I&#8217;m leaving</em><br />
<em> And now, who&#8217;s gonna save me next time?</em><br />
<em> From <strong>Now What</strong> by <strong>Lisa Marie Presley</strong></em></p></blockquote>
<p>So there you are just minding your own business and chilling on PlayStation Network when&#8230;</p>
<p>Yikes! PSN has been breached! And now you and 100 million of your closest friends have been exposed. Now what?</p>
<p>This post on <a title="6 Tips to Protect Your Personal Data After a Breach" href="http://www.credit.com/blog/2011/07/6-tips-to-protect-your-personal-data-after-a-breach/">Credit.com News and Advice has some advice</a> that you might want to check out.</p>
<blockquote><p><em>Data breaches are an everyday occurrence affecting millions of Americans each year.</em></p>
<p><em>Just ask crafters who shop at <a href="http://www.idt911.com/KnowledgeCenter/NewsAlerts/NewsAlertDetail.aspx?a=%7B0FC60ADC-9406-4F21-BACB-1FFFDB7C86CA%7D" target="_blank">Michael’s Stores</a>, <a href="http://www.idt911blog.com/2011/05/game-over-cloud-computing-and-the-sony-breach/" target="_blank">Sony PlayStation Network</a> gamers and investors at <a href="http://www.idt911blog.com/2011/07/feeling-compromised-what-to-do-when-you-get-a-data-breach-letter/" target="_blank">Morgan Stanley Smith Barney</a>.</em></p>
<p><em>They’re all vulnerable to identity theft and other fraud because their personally identifiable information (PII), such as a birth date or Social Security number, for example, was exposed. That information could be used to commit financial fraud.</em></p></blockquote>
<p>Here is a condensation of their 6 tips with my comments (you didn&#8217;t think you&#8217;d get off that easy did you).</p>
<blockquote>
<ol>
<li><em><strong>Review the breached account</strong>. Find out exactly what the pwned data losers (and I mean that quite literally) had of yours that might have been exposed. Forget what they ADMIT to losing and assume they lost it all. That includes not only credit card info but your credentials (login and password) to the site.</em></li>
<li><em><strong>Change all user access credentials</strong>. Change your password on the immediately affected site (DUH!) and then change your password on every other site that uses the compromised password. Now would be a dandy time to quit being an idiot and either get a <a title="Keys to the Kingdom" href="http://secforall.info/2008/09/09/keys-to-the-kingdom/" target="_blank">password safe or use another method to choose strong unique passwords</a> for every site and service you use. If you use the same password for PSN, your bank, YouTube, Facebook and Twitter&#8230; Uh Sorry. Sucks to be you.</em></li>
<li><em><strong>Notify existing creditors of the breach.</strong> MasterCard and Visa are pretty good about dropping fraudulent charges &#8211; if you tell them. The sooner the better. They will likely want to close that card and open a new one. If for some reason you used your debit card online&#8230; Again, Sucks to be you.</em></li>
<li><em><strong>Place a fraud alert on your credit file.</strong>Often the miscreant data losers will pony up for some kind of fraud protection in the wake of a breach. If they don&#8217;t you can &#8211; and should &#8211; set something up on your own. Often your creditors will offer at least limited time versions of these services at no charge. If they don&#8217;t then consider doing business with someone else. Seriously.</em>
<ul>
<li><em><strong>Initial Fraud Alerts</strong> last for 90 days and require potential creditors to confirm the legitimacy of your identity before granting credit.</em></li>
<li><em><strong>Extended Fraud Alerts</strong> last for seven years. Victims of identity theft who provide credit bureaus with an identity theft report like <a href="http://ftc.gov/bcp/edu/microsites/idtheft/" target="_blank">this one</a> are eligible.</em></li>
</ul>
</li>
<li><em><strong>Review your credit reports for any unusual activity.</strong> Credit.com suggests you use <a href="http://www.annualcreditreport.com/" target="_blank">annualcreditreport.com</a> to get free annual credit reports. That&#8217;s not a bad idea, but be wary about some of the extended credit monitoring services offered by the credit agencies. I&#8217;ve had a <a title="Experian Identity Theft Protection = FAIL" href="http://secforall.info/2011/03/25/experian-identity-theft-protection-fail/" target="_blank">less than satisfactory experience with Experian</a> but have had decent luck with Equifax. In any case, no service can substitute for good old due diligence on your part. Pay very close attention to not only your credit card statements, but social security or other government entitlement accounts. In general, make sure you understand every nuance of any statement from any entity that pays or bills you.</em></li>
<li><em><strong>Consider placing a security freeze on your credit report.</strong> This is the nuclear option. Be sure you really understand this before you push that button. Go to ConsumersUnion.org and check out the <a title="Consumers Union's Guide to Security Freeze Protection" href="http://www.consumersunion.org/pub/core_financial_services/005737.html" target="_blank">Consumers Union&#8217;s Guide to Security Freeze Protection</a> before considering this step.</em></li>
</ol>
</blockquote>
<p>So hopefully now you have at least some idea of what to do next. Since there doesn&#8217;t seem to be much hope in preventing these epic data breaches. At least as long as the data losers aren&#8217;t really penalized for their negligence. And before you start feeling sorry for poor Sony just pay attention to the cost of their services over the next few years after they&#8217;ve sucked you back in to PSN to see who really pays. But hey, you can always unplug the PS3 and play monopoly. Or basketball. With no risk of a data breach.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/webjoseph425.wordpress.com/1878/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/webjoseph425.wordpress.com/1878/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/webjoseph425.wordpress.com/1878/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/webjoseph425.wordpress.com/1878/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/webjoseph425.wordpress.com/1878/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/webjoseph425.wordpress.com/1878/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/webjoseph425.wordpress.com/1878/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/webjoseph425.wordpress.com/1878/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/webjoseph425.wordpress.com/1878/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/webjoseph425.wordpress.com/1878/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/webjoseph425.wordpress.com/1878/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/webjoseph425.wordpress.com/1878/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/webjoseph425.wordpress.com/1878/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/webjoseph425.wordpress.com/1878/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secforall.info&amp;blog=4666223&amp;post=1878&amp;subd=webjoseph425&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secforall.info/2011/08/22/so-they-exposed-your-personal-info-in-a-breach-now-what/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8cb97cf53947d19ef34fcb97961820df?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Joe</media:title>
		</media:content>

		<media:content url="http://webjoseph425.files.wordpress.com/2011/08/confused.png?w=300" medium="image">
			<media:title type="html">Confused</media:title>
		</media:content>
	</item>
		<item>
		<title>Captain X-Ploit: Sara and Maxi’s magnificent monetary mischievous maneuver.</title>
		<link>http://secforall.info/2011/08/12/captain-x-ploit-sara-and-maxi%e2%80%99s-magnificent-monetary-mischievous-maneuver/</link>
		<comments>http://secforall.info/2011/08/12/captain-x-ploit-sara-and-maxi%e2%80%99s-magnificent-monetary-mischievous-maneuver/#comments</comments>
		<pubDate>Fri, 12 Aug 2011 19:32:45 +0000</pubDate>
		<dc:creator>Joseph Webster</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[professional]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Captain X-Ploit]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[extraterrestrials]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[Trustonia]]></category>

		<guid isPermaLink="false">http://secforall.info/?p=1856</guid>
		<description><![CDATA[The Adventures of Captain X-Ploit: Sara and Maxi’s magnificent monetary mischievous maneuver. – Part 4 of the epic chronicle – Strangers are just Enemies you haven’t met. After the alien left, restoring time to its usual single dimensional, flowy self, Max and Sara found themselves at the library. Hunched over a computer, Sara was reading her [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secforall.info&amp;blog=4666223&amp;post=1856&amp;subd=webjoseph425&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://webjoseph425.files.wordpress.com/2010/02/the-adv-cap-x-ploit.jpg"><img class="alignleft size-thumbnail wp-image-1254" title="Captain X-Ploit" src="http://webjoseph425.files.wordpress.com/2010/02/the-adv-cap-x-ploit.jpg?w=90&#038;h=90" alt="" width="90" height="90" /></a></p>
<blockquote>
<p align="center">The Adventures of Captain X-Ploit:<br />
Sara and Maxi’s magnificent monetary mischievous maneuver.<br />
<em>– Part 4 of the epic chronicle –</em><br />
<strong>Strangers are just Enemies you haven’t met.</strong></p>
</blockquote>
<p>After <a title="Captain X-Ploit: Maxwell D. Higgens" href="http://secforall.info/2011/07/15/captain-x-ploit-maxwell-d-higgens/" target="_blank">the alien left, restoring time to its usual single dimensional, flowy self</a>, Max and Sara found themselves at the library. Hunched over a computer, Sara was reading her way through the wiki entries on several celebrities as Maxwell was standing next to her with an awe-filled grin plastered on his face.</p>
<p>“Sara?” he asked, “Yes, Maxi?” Sara responded with a stunning smile on her face. “So like… wow, you’re telling me I can take any of these books and no one would care?” he asked. His fascination with this concept had less to do with the concept of taking things without people caring and more with the concept that other places were supposed to operate differently. Being famous, handsome, and lucky he had never found people to be opposed to him taking whatever he wanted anyway.</p>
<p>“Well, yes… but you have to run them through the little machine over there,” she gestured with a hand, not removing her eyes from the screen, “before you can leave with it.”</p>
<p>“Weird,” Max said trailing off, distracted by a girl walking by. “I think I’ve got all the information I need,” she said snapping Max’s attention back to her.  “So like… what are we doing again?” Max asked, looking confused as Sara began to scribble several notes onto her hand. She smiled at Max without a hint of exasperation even though she’d explained it over thirty times on the way to the library.</p>
<p><strong>Later that day at the bank:</strong></p>
<p>Sara walked in confidently, leaving Max outside to ponder the complex plan. “Hi, I’m Sara Paylyn,” she said to the teller, “and I’d like to withdraw all my monies.”</p>
<p>“Sure thing Mrs. Paylyn, we just need to ask a question. For security reasons, of course.” Sara nodded and the lady began her list of questions.</p>
<p>“What is your pet’s name?”</p>
<p>Sara hastily glanced at her hand and responded quickly “Birstal.”</p>
<p>“Fantastic, Mrs. Paylyn! How much would you like to withdraw.”</p>
<p>Sara pretended to think for a moment before responding “All of it, I think.”</p>
<p><strong>Several moments later:</strong></p>
<p>Sara was standing outside the bank with $4,312,632.13, explaining to Max how she would surely win the contest now, when Max interrupted, “CONTEST!!! Oh man, I love contests&#8230; I wanna be a part of it!” Sara smiled at him wondering if every clone had hacking skill.</p>
<p>“Go for it, Maxi! What’s your plan?” she asked.</p>
<p>Max just shook his head, not wanting to reveal his brilliant plan, and walked confidently into the bank. At the counter the teller looked at him and said, “How can I help you, handsome?”</p>
<p>“Ya, hi, I’m some, like, rich dude and I want to, like, get my money… you know, like, for spending.”</p>
<p>“Okay&#8230;,” the lady said, her smile wavering for a moment, “What’s your name.”</p>
<p>“Maxwe…,” he stopped himself, “ahh… I mean,” his eyes dashed about wildly for a name he could use, “Trisha Smith” he exclaimed with a smile as he read her name tag.</p>
<p>Her eyes went wide for moment in shock as she responded “That’s <em>my</em> name, sir… what is <em>YOUR</em> name” she said.</p>
<p>His eyebrows furrowed in deep thought before reading another name off the business card on the counter. “Emmet Brown” he responded with a smile.</p>
<p>“You’re not Mr. Brown! Mr. Brown owns this bank and you’re far more handsome than he is.”</p>
<p>“I had plastic surgery&#8230;” Max smiled his perfect smile at her.</p>
<p>“Okay, well I have to ask you this question to be sure. What is your favorite color?”</p>
<p>Max puzzled for a moment thinking how to respond before he finally decided to guess at random, “Hot Pink”</p>
<p>Trisha looked astonished, staring at him “Emmet, is that really you?”</p>
<p>“Yes, now, I’d like to take the money please.”</p>
<p>“Of course, sir,” she said shuddering a little, “How much do you need?”</p>
<p>“All of it would be nice,” he responded without hesitation.</p>
<p>“<em>All of the money in the bank?</em>” she asked in amazement.</p>
<p>“Yes.” He responded politely with a smile.</p>
<p><strong>That night at midnight:</strong></p>
<p>Sara and Max were standing waiting for David to appear. Sara couldn’t help but feel a little crestfallen. As much as she liked Max and enjoyed seeing him win, she had only $4 million to her name whereas Max had walked off with the entire contents of the bank. Which happened to be transported at the moment in the truck of a man he had paid $1,000.</p>
<p><em>At least I can still beat David, that smug jerk, </em>she thought as she saw David and Tedward walking up the street toward her.</p>
<blockquote><p><em>At last we&#8217;re back to the hacking contest betwixt David and Sara &#8211; and Maxwell it seems &#8211; with Sara (and Max) using a tried and true exploit against weak authentication. I love the part where Maxi (AKA <a title="Captain X-Ploit: Put your hands together for Sara Boulder" href="http://secforall.info/2011/05/20/captain-x-ploit-put-your-hands-together-for-sara-boulder/" target="_blank">the stupidest life form in existence</a>) is the one to hit the mother-lode by sheer dumb (and I mean that in the nicest way possible) luck. Much like the &#8220;hackers&#8221;, script kiddies and others who are routinely publicized by the panic-stricken (and panic-mongering) popular press. It ain&#8217;t rocket science folks. But it works. Really, really well. I&#8217;m still pulling for <a title="Captain X-Ploit: Strangers are just Enemies you haven’t met. Part 2" href="http://secforall.info/2011/05/06/captain-x-ploit-strangers-are-just-enemies-you-haven%E2%80%99t-met-part-2/" target="_blank">David and his mouse minions</a>, though. How can you not be partial to plans involving cohorts like Mr. Biscuits, Señor Sparkles and Dr. Whiskers?</em></p></blockquote>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/webjoseph425.wordpress.com/1856/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/webjoseph425.wordpress.com/1856/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/webjoseph425.wordpress.com/1856/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/webjoseph425.wordpress.com/1856/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/webjoseph425.wordpress.com/1856/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/webjoseph425.wordpress.com/1856/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/webjoseph425.wordpress.com/1856/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/webjoseph425.wordpress.com/1856/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/webjoseph425.wordpress.com/1856/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/webjoseph425.wordpress.com/1856/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/webjoseph425.wordpress.com/1856/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/webjoseph425.wordpress.com/1856/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/webjoseph425.wordpress.com/1856/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/webjoseph425.wordpress.com/1856/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secforall.info&amp;blog=4666223&amp;post=1856&amp;subd=webjoseph425&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secforall.info/2011/08/12/captain-x-ploit-sara-and-maxi%e2%80%99s-magnificent-monetary-mischievous-maneuver/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8cb97cf53947d19ef34fcb97961820df?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Joe</media:title>
		</media:content>

		<media:content url="http://webjoseph425.files.wordpress.com/2010/02/the-adv-cap-x-ploit.jpg?w=145" medium="image">
			<media:title type="html">Captain X-Ploit</media:title>
		</media:content>
	</item>
		<item>
		<title>Facebook will throw you under the bus</title>
		<link>http://secforall.info/2011/07/21/facebook-will-throw-you-under-the-bus/</link>
		<comments>http://secforall.info/2011/07/21/facebook-will-throw-you-under-the-bus/#comments</comments>
		<pubDate>Thu, 21 Jul 2011 21:35:34 +0000</pubDate>
		<dc:creator>Joseph Webster</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[professional]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Casey Anthony]]></category>
		<category><![CDATA[e-discovery]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[social networking]]></category>

		<guid isPermaLink="false">http://secforall.info/?p=1849</guid>
		<description><![CDATA[Tryin to ruin my name Threw me under the bus Riding all over the town Spreading rumors around Threw me under the bus From Under the Bus by Lolene In my previous post I explained why I left Facebook. Doing so freed up enough time to actually do another bl0g entry so it&#8217;s only apropos [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secforall.info&amp;blog=4666223&amp;post=1849&amp;subd=webjoseph425&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="throw me under the bus now t shirt" src="http://rlv.zcache.com/throw_me_under_the_bus_now_t_shirt-p235733789470023798trlf_400.jpg" alt="" width="100" height="100" /></p>
<blockquote><p><em>Tryin to ruin my name<br />
Threw me under the bus<br />
Riding all over the town<br />
Spreading rumors around<br />
Threw me under the bus<br />
From <strong>Under the Bus</strong> by <strong>Lolene</strong></em></p></blockquote>
<p>In my previous post I explained <a title="Why I left Facebook" href="http://secforall.info/2011/07/10/why-i-left-facebook/" target="_blank">why I left Facebook</a>. Doing so freed up enough time to actually do another bl0g entry so it&#8217;s only apropos that this entry reinforce the idea that Facebook is not your friend. Unless of course your friends are conniving weasels who steal from you and will throw you under the bus in a heartbeat. Like being friends with <a title="Casey Anthony" href="http://www.mahalo.com/casey-anthony/" target="_blank">Casey Anthony</a> (but I digress). If you have friends like that then Facebook is what you are used to. If not then read on.</p>
<p>In this post by the oft quoted (by Security For All at any rate) Sharon D. Nelson, Esq. of the {ride the lightning} blog the following question is asked: <a title="How Much Data is Facebook Giving Law Enforcement Under Secret Warrants?" href="http://ridethelightning.senseient.com/2011/07/how-much-data-is-facebook-giving-law-enforcement-under-secret-warrants.html?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+sensei+%28Ride+The+Lightning%29" target="_blank">How Much Data is Facebook Giving Law Enforcement Under Secret Warrants?</a></p>
<blockquote><p><em>According to <a title=" " href="http://www.smh.com.au/technology/technology-news/a-new-us-lawenforcement-tool-facebook-searches-20110713-1hcuv.html#ixzz1RyN4Xl2b" target="_blank">Reuters</a>, since 2008, federal judges have authorized at least two dozen warrants to search Facebook accounts to the FBI, the DEA and ICE. The investigations have involved such things as arson, rape and terrorrism.</em></p>
<p><em>What interested me most is that these warrants demands a user&#8217;s &#8220;Neoprint&#8221; and Photoprint&#8221; &#8211; terms I had never heard before which apparently appear in law enforcement manuals and refer to a Facebook compilation of data that the users themselves do not have access to. So much for Facebook&#8217;s claim that the &#8220;Download Your Account&#8221; button gives you everything that Facebook itself possesses.</em></p>
<p><em><strong>Facebook doesn&#8217;t tell users about the warrants to give them a chance to challenge those warrants legally.</strong></em></p></blockquote>
<p>Yikes! Talk about throwing your users under the bus. And without notice. As Sharon points out even Twitter has a policy of notifying users before they hand over anything to law enforcement. But not Facebook.</p>
<p>And then there is this post by fellow Security Blogger <a title="View all posts by Carole Theriault" href="http://nakedsecurity.sophos.com/author/caroletheriault/" target="_blank">Carole Theriault</a> in the nakedsecurity blog that asks <a title="Does using Facebook put you at more risk elsewhere on the internet?" href="http://nakedsecurity.sophos.com/2011/07/18/facebook-users-trust-risk/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+nakedsecurity+%28Naked+Security+-+Sophos%29" target="_blank">Does using Facebook put you at more risk elsewhere on the internet?</a></p>
<blockquote><p><em>The Pew Research Center has shown that the more time you spend on the internet, especially social networks like Facebook and Twitter, the more trusting you become.</em></p>
<p><em>Not just on social networks, but everywhere &#8211; both online and in real life.</em></p>
<p><em>With <a href="http://www.internetworldstats.com/stats.htm" rel="nofollow">30% of the world</a> estimated to be online &#8211; about 80% of North America and 60% of Europe &#8211; and more than half of these users belonging to some social networking site, an increase in trust could have major impacts on how people interact in the future.</em></p>
<p><em>Does this mean that social network users will eventually become a bunch of loved-up hippies? It is really difficult for me to imagine what I would be like if I shed my cynical armour.</em></p>
<p><em>I shouldn&#8217;t really worry: while I study social networks all the time, I am more of a voyeur than a player. Let&#8217;s be honest here &#8211; I find them really scary.</em></p>
<p><em>Many users of social networks seem completely addicted &#8211; they are on there all the time, recording every event of their lives. It just seems so intrusive to me&#8230;and compulsive.</em></p>
<p><em>So the premise is that people on Facebook are more trusting than other internet users, and MUCH more trusting than non-internet users.</em></p>
<p><em>It seems clear me to me that if Facebook users are genuinely more trusting, they are more at risk of online scams, both on and off social media sites.</em></p>
<p><em>Maybe research like this proves that <strong>social networking sites like Facebook and Twitter need to show greater interest in educating their users about being safe online</strong>.</em></p>
<p><em>One could argue that they <strong>should proactively protect their community against commonly encountered threats</strong>.</em></p></blockquote>
<p>I agree that it would be swell if Facebook showed a <em><strong>greater interest in educating their users about being safe online </strong></em>but from where I sit I&#8217;ve only seen an interest in exploiting their users. But it is a great interest.</p>
<p>To borrow a soundbite (in spite of the lack of audio in this blog) from former First Lady Nancy Reagan, Just say No! to Facebook. Or friend Casey Anthony.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/webjoseph425.wordpress.com/1849/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/webjoseph425.wordpress.com/1849/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/webjoseph425.wordpress.com/1849/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/webjoseph425.wordpress.com/1849/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/webjoseph425.wordpress.com/1849/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/webjoseph425.wordpress.com/1849/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/webjoseph425.wordpress.com/1849/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/webjoseph425.wordpress.com/1849/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/webjoseph425.wordpress.com/1849/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/webjoseph425.wordpress.com/1849/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/webjoseph425.wordpress.com/1849/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/webjoseph425.wordpress.com/1849/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/webjoseph425.wordpress.com/1849/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/webjoseph425.wordpress.com/1849/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secforall.info&amp;blog=4666223&amp;post=1849&amp;subd=webjoseph425&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secforall.info/2011/07/21/facebook-will-throw-you-under-the-bus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/8cb97cf53947d19ef34fcb97961820df?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">Joe</media:title>
		</media:content>

		<media:content url="http://rlv.zcache.com/throw_me_under_the_bus_now_t_shirt-p235733789470023798trlf_400.jpg" medium="image">
			<media:title type="html">throw me under the bus now t shirt</media:title>
		</media:content>
	</item>
	</channel>
</rss>
