<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7633748372187898893</id><updated>2011-09-11T10:12:25.510-04:00</updated><category term='hackers islam websites internet security defacement'/><title type='text'>SafeCentral Blog</title><subtitle type='html'>The official blog from inside SafeCentral:  The Safer Internet</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.safecentral.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>56</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-7397212062276768442</id><published>2010-10-29T12:47:00.004-04:00</published><updated>2010-10-29T15:25:06.669-04:00</updated><title type='text'>Boo!  Are your employee's computers haunted?</title><content type='html'>These are scary times for information security professionals who face increasing  demands for protecting sensitive company information and at the same time are supporting more and more employee-owned devices connecting to the corporate network.  &lt;br /&gt;&lt;br /&gt;In my last posting I mentioned an &lt;a target="_blank" href="http://www.informationweek.com/news/security/antivirus/showArticle.jhtml?articleID=227700360"&gt;Information Week article&lt;/a&gt; that I will return to this week.  The article describes how anti-malware software is not getting the job done.  The author was focusing on enterprise IT organizations protecting corporate networks and devices.  &lt;br /&gt;&lt;br /&gt;But the successful evasion of software defenses that malware authors are enjoying in the enterprise is even more troubling when we look at the Bring Your Own PC model of corporate computing.  In this model company employees use their own PCs and laptops to access enterprise resources.  Bring Your Own PC could also be called "Bring Your Own Malware."  If million dollar enterprise software budgets cannot keep the hackers away, how can we assume an employee-owned PC will be free of infection?&lt;br /&gt;&lt;br /&gt;&lt;div style="background-color: #e1e1e1; padding: 15px; margin-left: auto; margin-right: auto; margin-top: 5px; margin-bottom: 5px; font-size: 1.2em; width: 70%;"&gt;"Bring Your Own PC" could also be called "Bring Your Own Malware"&lt;/div&gt;&lt;br /&gt;There are two eye-opening statistics in the Information Week article, derived from a Ponemon Institute survey of IT and IT security practitioners:  Nearly 80% of companies report malware evades their antivirus systems, and almost half report malware infections take longer than 30 days to remove.  That's a long time for malware-infected computers to continue connecting to corporate networks and accessing sensitive data--and these are fully managed PCs controlled by corporate IT.  The numbers must be much worse for employee-owned PCs.  Last year &lt;a target="_blank" href="http://blog.trendmicro.com/the-internet-infestation-how-bad-is-it-really/"&gt;Trend Micro reported&lt;/a&gt; their results from monitoring 100 million compromised IP addresses:  &lt;b&gt;half of the addresses showed signs of infection for over 300 days.&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="background-color: #e1e1e1; padding: 15px; margin-left: auto; margin-right: auto; margin-top: 5px; margin-bottom: 5px; font-size: 1.2em; width: 70%;"&gt;Nearly 80% of companies report malware evades their antivirus systems, and almost half report malware infections take longer than 30 days to remove.&lt;/div&gt;&lt;br /&gt;SafeCentral Enterprise delivers secure remote access even from machines that are compromised with malware.  SafeCentral blocks the keylogging and other data-stealing techniques of malware, providing focused protection for web, VPN, remote desktop, hosted virtual desktop and other client sessions.  You can &lt;a href="http://www.safecentral.com/business-user.html"&gt;learn more here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-7397212062276768442?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/7397212062276768442/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=7397212062276768442' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/7397212062276768442'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/7397212062276768442'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2010/10/boo-are-your-employees-computers.html' title='Boo!  Are your employee&apos;s computers haunted?'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-4887922492644227171</id><published>2010-10-20T16:23:00.005-04:00</published><updated>2010-10-20T19:17:28.400-04:00</updated><title type='text'>Protecting Corporate Data on the Edge</title><content type='html'>Information is money and modern criminals know how to get their hands on both.  Enterprise IT professionals are severely challenged these days to keep corporate data both protected and available to authorized users at the same time.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Going to Sea in a Sieve&lt;/strong&gt;&lt;br /&gt;Greg Shipley called out security software vendors in &lt;a href="http://www.informationweek.com/news/security/antivirus/showArticle.jhtml?articleID=227700360"&gt;this InformationWeek article&lt;/a&gt;, pointing out that:  "...we've spent billions of dollars on security technologies, and we still can't curb these threats. Intruders trot through firewalls deployed to block them, while malware flourishes on systems that antivirus vendors pledge to immunize."&lt;br /&gt;&lt;br /&gt;When it comes to endpoint PCs I have to agree.  The problem I see is that the Windows PC is too open, too programmable, with too many APIs and too many extensible applications like web browsers and productivity suites.  This creates a rich environment for malware authors to infiltrate and take up permanent, or at least persistent, residence as a malicious ghost haunting the machine.  From this position a malware operator can harvest sensitive data, including authentication credentials, customer records, employee data and other sensitive information.&lt;br /&gt;&lt;br /&gt;IT teams have the strange mandate to deploy an extremely flexible operating system, but immediately take flexibility away from end users.  This creates a tug of war between security and usability.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Benefits of Data Centralization&lt;/strong&gt;&lt;br /&gt;These facts are inducing a reverse in the swing of the IT pendulum, which is now moving back to centralization.  Cloud-based apps, which keep data-at-rest in the data center, are helping to limit the physical spread of data and keep it under tight control behind many layers of physical and network protection.  Hosted Virtual Desktops like Citrix XenDesktop do the same thing for entire virtual machines..allowing IT to build, deploy and maintain virtual PCs inside the data center and then deliver them over the Internet to thin client applications like the Citrix Receiver.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Don't Forget the Endpoint&lt;/strong&gt;&lt;br /&gt;Centralization is good for data, but not for people.  The workforce has become more distributed, working from home or the road or a branch office.  The point is that data can be stored centrally in the data center but it must be used out on the edge of the network; that's where the users are.  In most cases, "the edge" still means a Windows PC or laptop (I exclude call centers from "the edge").&lt;br /&gt;&lt;br /&gt;The information security benefits of data centralization are lost when unmanaged or semi-managed endpoint PCs connect to the data center.  All the risks that Greg Shiply called out then come into play:  &lt;br /&gt;&lt;br /&gt;&lt;div style="background-color: #e1e1e1; padding: 15px; margin-left: auto; margin-right: auto; margin-top: 5px; margin-bottom: 5px; font-size: 1.2em; width: 70%;"&gt;"Walking into the CEO's office and saying that the products you've spent a small fortune on are effective only at stopping novices and for checking off compliance forms? That takes more intestinal fortitude than most can muster."&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Centralized Data with Secure Remote Access&lt;/strong&gt;&lt;br /&gt;I think the pendulum is swinging to a safer place.  Centralizing data and functionality, along with endpoint lockdown and secure remote access create a formula that works.  Network Access Control (NAC) was an attempt to ensure that only properly secured endpoint computers could connect to a corporate network.  But NAC relies on the imperfect Antivirus and Firewalls Greg Shipley called out as ineffective.&lt;br /&gt;&lt;br /&gt;Here at SafeCentral we are addressing the risks to data in use on remote endpoints differently.  We do not protect the endpoint, we protect the data..while it is in use.  We provide a Secure Desktop that protects against keyloggers, screen-scrapers, DNS redirection, code injection and other threats.  From the Secure Desktop the user launches their VPN client and logs in, with full anti-keylogger protection for their username and password.  Once connected to the VPN and while on the Secure Desktop, the user can only run applications white-listed by the IT administrator.  "Thin client applications" like Citrix or Microsoft Remote Desktop are perfect fits for the SafeCentral Secure Desktop (see my earlier posting:  &lt;a href="http://blog.safecentral.com/2010/09/patented-data-loss-protection-from.html"&gt;Patented Data Loss Protection&lt;/a&gt;).  Users can switch back and forth between the locked-down Secure Desktop and their normal Windows desktop, multi-tasking throughout the day.  This gives them the benefit of extreme lock-down while accessing corporate data, with an option to switch out to the more open environment of the standard Windows desktop when they want.  The data on the Secure Desktop remain protected.&lt;br /&gt;&lt;br /&gt;&lt;div style="background-color: #e1e1e1; padding: 15px; margin-left: auto; margin-right: auto; margin-top: 5px; margin-bottom: 5px; font-size: 1.2em; width: 70%;"&gt;Centralizing data and functionality, along with endpoint lockdown and secure remote access create a formula that works.&lt;/div&gt; &lt;br /&gt;&lt;br /&gt;Examples of White-listed Clients on the SafeCentral Secure Desktop:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Cisco AnyConnect VPN&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Juniper Netconnect VPN&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Juniper Citrix Services secure proxy&lt;/li&gt;&lt;br /&gt;&lt;li&gt;F5 Firepass VPN&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Citrix XenDesktop or XenApp&lt;/li&gt;&lt;br /&gt;&lt;li&gt;VMWare View 4.5 Client&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Microsoft Remote Desktop Client&lt;/li&gt;&lt;br /&gt;&lt;li&gt;SafeCentral SafeBrowser (a locked-down web browser)&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Attachmate&lt;/li&gt;&lt;br /&gt;&lt;li&gt;more on the way...&lt;/li&gt;&lt;br /&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;If you are interested in hearing more, please drop me a line at rdickenson/at/safecentral/dot/com or post a comment here.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-4887922492644227171?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/4887922492644227171/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=4887922492644227171' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/4887922492644227171'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/4887922492644227171'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2010/10/protecting-corporate-data-on-edge.html' title='Protecting Corporate Data on the Edge'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-2104966289624302256</id><published>2010-09-28T23:35:00.011-04:00</published><updated>2010-09-29T09:37:29.262-04:00</updated><title type='text'>$10 Million Stolen in 3 Months by an e-Crime Gang in London</title><content type='html'>The London Metropolitan Police Central e-Crime Unit arrested 15 men and women who &lt;a href="http://www.bbc.co.uk/news/uk-11431989"&gt;stole nearly $10 million from online bank accounts&lt;/a&gt; in only 3 months.  The gang infected the personal computers of unsuspecting Internet users with a mass-market crimeware trojan named "Zeus" and transferred the money out of their victims' online banking accounts.  &lt;br /&gt;&lt;br /&gt;Police representatives said the total amount of money stolen will likely climb as the investigation proceeds.&lt;br /&gt;&lt;br /&gt;The Zeus trojan is a very effective piece of "crimeware," software designed to conduct online crimes, that can be purchased for $300 on black market websites.  Willing criminals do not have to be computer experts to operate a Zeus network.  The authors of the Zeus trojan have automated most of the details of the crimeware's operation, and even offer guarantees that it will not be detected by antivirus programs.&lt;br /&gt;&lt;br /&gt;The Zeus trojan comes with a "Command and Control" server that collects stolen data and can be configured to control hundreds of thousands of infected PCs, issuing instructions on how and where to transfer funds automatically out of online bank accounts.&lt;br /&gt;&lt;br /&gt;The Zeus trojan is a top money-earner for online criminals worldwide.  We use Zeus in our tests of &lt;a href="http://www.safecentral.com"&gt;SafeCentral WebProtection&lt;/a&gt; and verify that SafeCentral blocks the trojan's data-stealing features.  Below is a screenshot from a control test of the Zeus trojan, showing keystrokes being collected out of a Bank of America online banking session when SafeCentral is not being used.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;strong&gt;Stolen Data Report from a Zeus Trojan Server&lt;/strong&gt;&lt;/center&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_4wLdyS_V2Q8/TKK9Ob0HtRI/AAAAAAAAAEU/jZQDpU-94yo/s1600/Zeus_Screen2.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 321px;" src="http://1.bp.blogspot.com/_4wLdyS_V2Q8/TKK9Ob0HtRI/AAAAAAAAAEU/jZQDpU-94yo/s400/Zeus_Screen2.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5522184148791833874" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-2104966289624302256?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/2104966289624302256/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=2104966289624302256' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/2104966289624302256'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/2104966289624302256'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2010/09/10-million-stolen-in-3-months-by-e.html' title='$10 Million Stolen in 3 Months by an e-Crime Gang in London'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_4wLdyS_V2Q8/TKK9Ob0HtRI/AAAAAAAAAEU/jZQDpU-94yo/s72-c/Zeus_Screen2.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-7613261320559294978</id><published>2010-09-06T17:44:00.011-04:00</published><updated>2010-09-07T11:48:30.065-04:00</updated><title type='text'>Patented Data Loss Protection from SafeCentral, Inc.</title><content type='html'>It's been a busy summer for SafeCentral and I am eager to share the results of our hard work.  We've put out a couple of press releases recently that hint at the action going on behind the scenes:  we got the &lt;a href="http://www.safecentral.com/press/releases/TSX_System_Level%20Security_Patent.html"&gt;first of 5 patents assigned&lt;/a&gt; to our Trusted Security Extensions (TSX) technology and just completed the &lt;a href="http://www.safecentral.com/press/releases/Authentium_Commtouch_Announcement.html"&gt;sale of our antivirus business to Commtouch&lt;/a&gt;.  First I'd like to say that the Commtouch folks have been a real pleasure to work with over the summer as we put together a deal that makes a ton of sense both to them and us.  That transaction allows us to focus on proactive data and application protection powered by TSX and embodied in our SafeCentral product.  TSX brings unparalleled protection to sensitive data for consumers and enterprises alike.&lt;br /&gt;&lt;br /&gt;There is no better signal of our focus than renaming the entire company to SafeCentral, Inc.!  We will be launching a new website in a couple of weeks that takes the wraps off some additional products we are bringing to market.  &lt;br /&gt;&lt;br /&gt;Our consumer product is going strong--we will be announcing several distribution partnerships for SafeCentral over the next few weeks.  We will also be announcing some of the new things we have been working on for enterprise customers.  Here is a sneak peek at endpoint data protection for thin client access methods such as Virtual Desktop Infrastructure (VDI), Virtual Applications, and Remote Desktop.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;strong&gt;Data Loss Protection for XenApp Clients&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;object style="background-image:url(http://1.bp.blogspot.com/_4wLdyS_V2Q8/TIVqS1vCpgI/AAAAAAAAAEM/J5na2o6G3aM/s1600/VDIVideoSplashScreen.png)"  width="720" height="405"&gt;&lt;param name="movie" value="http://www.youtube.com/v/q4eLWeo6QGs?fs=1&amp;amp;hl=en_US"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/q4eLWeo6QGs?fs=1&amp;amp;hl=en_US" width="720" height="430" allowScriptAccess="never" allowFullScreen="true" wmode="transparent" type="application/x-shockwave-flash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;/center&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-7613261320559294978?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/7613261320559294978/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=7613261320559294978' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/7613261320559294978'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/7613261320559294978'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2010/09/patented-data-loss-protection-from.html' title='Patented Data Loss Protection from SafeCentral, Inc.'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-122661884949729163</id><published>2010-04-27T10:58:00.003-04:00</published><updated>2010-04-27T11:13:34.748-04:00</updated><title type='text'>SafeCentral featured on AOL.com</title><content type='html'>&lt;div&gt;SafeCentral is featured today in one of the &lt;a href="http://www.aol.com/?dlact=dl3"&gt;lead stories on AOL.com&lt;/a&gt;. In a story about phishing, "&lt;a href="http://daol.aol.com/articles/if-you-get-this-email-delete-it-asap"&gt;If You Get This E-Mail, Delete It ASAP&lt;/a&gt;," a sidebar focuses on how SafeCentral helps secure your online shopping and banking transactions. SafeCentral is available to AOL subscribers at a 50% discount.&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;img id="BLOGGER_PHOTO_ID_5464835403702708722" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 328px; HEIGHT: 391px; TEXT-ALIGN: center" alt="" src="http://2.bp.blogspot.com/_4wLdyS_V2Q8/S9b-2IGtqfI/AAAAAAAAAD8/emJh-QHZdos/s400/aolsidebar.PNG" border="0" /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-122661884949729163?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.aol.com/?dlact=dl3' title='SafeCentral featured on AOL.com'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/122661884949729163/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=122661884949729163' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/122661884949729163'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/122661884949729163'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2010/04/safecentral-featured-on-aolcom.html' title='SafeCentral featured on AOL.com'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_4wLdyS_V2Q8/S9b-2IGtqfI/AAAAAAAAAD8/emJh-QHZdos/s72-c/aolsidebar.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-1898818607324954969</id><published>2010-03-17T17:11:00.009-04:00</published><updated>2010-03-18T07:46:49.915-04:00</updated><title type='text'>Tax Season Starts with FBI Report on Doubling of Internet Crime</title><content type='html'>The IRS refunded $43.5 billion to tax filers last year, 72% of whom filed electronically (&lt;a href="http://www.gao.gov/products/GAO-09-640"&gt;GAO report here)&lt;/a&gt;. That much money and sensitive information flowing over the network attracts the attention of online thieves who move in like grizzly bears during a salmon run. Today I will share a few tips on how you can avoid being snatched up by the bad guys while you do your annual patriotic duty to help fund Uncle Sam.&lt;br /&gt;&lt;br /&gt;First it is worth noting that dollars lost to Internet crime doubled from 2008 to 2009, topping half a billion dollars in the US. The &lt;a href="http://www.ic3.gov/media/2010/100312.aspx"&gt;2009 Internet Crime Report&lt;/a&gt; released on Friday listed average losses at over $5,000 per incident with a mean loss closer to $500. The report pointed out that prosecution of online crimes is difficult because the victim and perpetrator "may be located anywhere in the world."&lt;br /&gt;&lt;br /&gt;The same convenience that electronic tax preparation and filing presents to the tax payer can also work for the criminal. Simply having an electronic copy of your tax return on your computer can expose you to risk. Last August a Seattle man was convicted of fraud when a lucky break allowed authorities to catch him with tax returns, financial aid applications and other documents pilfered over the Internet from family computers across the country. &lt;a href="http://www.justice.gov/usao/waw/press/2009/mar/wood.html"&gt;Frederick Wood&lt;/a&gt; used file-sharing programs to search for keywords like "tax return" and find documents on personal computers thousands of miles away. He used information in these documents to commit financial fraud.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Tips for Safe Tax Filing&lt;/strong&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;strong&gt;Start with a clean machine:&lt;/strong&gt; don't use the same computer to prepare your taxes that you use for social networking like Facebook and Twitter. Online criminals use these services to spread malware via links that appear to come from friends, or even through display ads that can infect your computer even if you don't click on them.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Turn on WiFi Encryption:&lt;/strong&gt; if your home network uses WiFi, make sure it is encrypted with WPA or at least WEP. Consult your wireless router manual or the manufacturer's website for setup instructions. Unencrypted wireless networks can allow thieves to connect to your network and gain access to sensitive documents on your computer even when you are not at home.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Run a full antivirus scan:&lt;/strong&gt; antivirus can't catch everything, but running a full scan before performing sensitive work like tax filing will give you the best chance for privacy. These scans can take an hour or more to run, so plan ahead and let the scan run overnight before your marathon tax session.&lt;/li&gt;&lt;li&gt;&lt;strong&gt;Use unique passwords:&lt;/strong&gt; if you are signing up for a new online tax filing service, resist the impulse to use that same password you use for everything else. Create a password that is memorable only to you--use something you can see from your computer, like "Green Vase" but mix it up with some punctuation and other characters: "Green--Vase:)" Just don't break the vase!&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Remove dangerous programs:&lt;/span&gt;  if you have a file-sharing program like LimeWire, remove it or carefully review the files it is sharing.  Latest versions of LimeWire will no longer share documents by default, but many users do not update software and may be running with an older version.  If you want to keep your file sharing program but be really sure you are not sharing sensitive files, ask a friend to connect to your library and see what you are sharing (see LimeWire's "Direct Connect" feature).  You should know, however, that file sharing programs are a &lt;a href="http://blog.safecentral.com/2009/02/kids-download-darndest-things.html"&gt;major source of malware infection&lt;/a&gt;.&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;While the Clean Machine is the best bet for safe filing, you may be planning on using your tax refund to buy your new laptop--this puts you in a bit of a chicken-egg situation. For you, we have SafeCentral. SafeCentral creates a "clean desktop" on your existing computer, shielding you from keyloggers and other nasty programs that try to steal your sensitive information. You can give it a try free for 14 days &lt;a href="http://www.safecentral.com/"&gt;here on the website&lt;/a&gt;. That should be plenty of time to get your taxes filed and decide whether a small piece of your refund is worth the price of protecting you online all year with SafeCentral.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-1898818607324954969?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/1898818607324954969/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=1898818607324954969' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/1898818607324954969'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/1898818607324954969'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2010/03/tax-filing-season-starts-with-fbi.html' title='Tax Season Starts with FBI Report on Doubling of Internet Crime'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-3364813951690617078</id><published>2010-01-11T11:47:00.008-05:00</published><updated>2010-01-11T12:21:03.779-05:00</updated><title type='text'>PC Magazine Four-Star Review of SafeCentral 2.6</title><content type='html'>We earned 4 stars in the &lt;a href="http://www.pcmag.com/article2/0,2817,2357889,00.asp"&gt;PC Magazine review of SafeCentral 2.6&lt;/a&gt; that review that appeared on Friday.  I am very happy to see the review up on the &lt;a href="http://www.pcmag.com"&gt;PCMag.com &lt;/a&gt;home page.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_4wLdyS_V2Q8/S0taeWBDZZI/AAAAAAAAAD0/CdxPPLstRzc/s1600-h/SC2.6ReviewPCMagHomePageJan2010.PNG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 300px;" src="http://2.bp.blogspot.com/_4wLdyS_V2Q8/S0taeWBDZZI/AAAAAAAAAD0/CdxPPLstRzc/s400/SC2.6ReviewPCMagHomePageJan2010.PNG" border="0" alt=""id="BLOGGER_PHOTO_ID_5425529653450466706" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The reviewer, &lt;a href="http://www.pcmag.com/author_bio/0,1908,a%253D184,00.asp"&gt;Neil J. Rubenking&lt;/a&gt;, commends our ease-of-use and the real-time feedback we give users on the safety of their web sessions.  Our support for 64-bit platforms, including XP, Vista and Windows 7 was also noted.&lt;br /&gt;&lt;br /&gt;One of the "Cons" in the review is the closed nature of the SafeCentral browser.  We do not allow any and all browser plugins.  We see this as a strong positive.  On our work computers we are used to the network admins at our companies limiting what we can install and run, and which websites we visit.  We understand that these constraints are necessary to protect company assets.  Now is the time for us to recognize that we need to exercise the same control over our home PCs and laptops.  When we sign into our bank or online retirement account, we should think and act differently--we have more to protect at this moment that when we are watching the latest funny YouTube video or posting a photo to Facebook.&lt;br /&gt;&lt;br /&gt;Just like the iPhone is carefully managed by Apple to ensure the quality and security of iPhone applications, we recognize that browser plugins can introduce additional risks into sensitive web sessions and seek to protect users from those risks.  Increased security almost always comes with some impact on usability.  With SafeCentral, though, you still can use your regular browser and those Digg and Flickr toolbars to do all your fun stuff.  Use SafeCentral for serious web stuff like banking, stock trading and tax filing.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-3364813951690617078?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/3364813951690617078/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=3364813951690617078' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/3364813951690617078'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/3364813951690617078'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2010/01/pc-magazine-four-star-review-of.html' title='PC Magazine Four-Star Review of SafeCentral 2.6'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_4wLdyS_V2Q8/S0taeWBDZZI/AAAAAAAAAD0/CdxPPLstRzc/s72-c/SC2.6ReviewPCMagHomePageJan2010.PNG' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-2534416668355695927</id><published>2009-12-18T06:46:00.013-05:00</published><updated>2009-12-19T08:09:17.990-05:00</updated><title type='text'>Twitter Hack and the Iranian Cyber Army</title><content type='html'>&lt;span style='font-size:0.9em;'&gt;(See &lt;a href="#updates"&gt;continuing updates&lt;/a&gt; to this story below.)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Earlier this morning a DNS hack took control of Twitter.com traffic and redirected to a website with a splash page proclaiming, "THIS SITE HAS BEEN HACKED BY IRANIAN CYBER ARMY."  This hack has a lot in common with the &lt;a href="http://blog.safecentral.com/2009/12/drhiad-islamic-terrorist-or-teenager.html"&gt;Dr.Hiad&lt;/a&gt; website defacement I reported on two weeks ago.  &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;New information&lt;/strong&gt;&lt;br /&gt;The so-called Iranian Cyber Army has defaced websites in the same manner as Dr.Hiad.  At this moment (7:35AM Eastern Time) there is a website displaying the exact image that Twitter users saw earlier today during the Twitter hack event.  A screenshot of that web page is shown below.  The webpage contains an email link to the Iranian Cyber Army's Gmail account.&lt;br /&gt;&lt;br /&gt;It is likely that the Twitter DNS attackers simply pointed "twitter.com" to the IP address of a defaced website like the one below.  It would not make sense for them to point Twitter traffic to their own web server:  that would allow them to be traced and possibly caught.&lt;br /&gt;&lt;br /&gt;When the Twitter attackers realized they could take over Twitter's DNS, they had to decide where to point the traffic.  Redirect it to comedycentral.com?  Disney.com?  Or how about a defaced webpage bearing the image of the Iranian Cyber Army?&lt;br /&gt;&lt;br /&gt;There is some chance the Twitter attackers executed both the website defacement and the DNS takeover.&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;strong&gt;Screenshot of Iranian Cyber Army Website Defacement&lt;/strong&gt;&lt;/center&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_4wLdyS_V2Q8/SytzlvEzISI/AAAAAAAAADs/1YBBzxHDfp8/s1600-h/ica_sm.PNG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 377px; height: 400px;" src="http://3.bp.blogspot.com/_4wLdyS_V2Q8/SytzlvEzISI/AAAAAAAAADs/1YBBzxHDfp8/s400/ica_sm.PNG" border="0" alt=""id="BLOGGER_PHOTO_ID_5416550068972101922" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;DNS is Fundamental&lt;/strong&gt;&lt;br /&gt;DNS is the Internet service that kicks in when we type a website name into our browser or click a link on a web page.  Type "twitter.com" into your browser and DNS will lookup the IP address of the Twitter web server so your browser can connect and download all those tweets.  As fundamental as DNS is to our Internet experience, it has virtually no security, particularly on our home computers and Internet connections.  Also, the DNS servers "up in the cloud" are &lt;a href="http://icannwiki.org/DNS-The_Value_and_Vulnerability"&gt;rife with vulnerabilities&lt;/a&gt; that enable attackers to gain control and carry out pranks like the Twitter redirection this morning.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a name="updates"&gt;&lt;span style="font-size:1.4em;font-weight:bold;"&gt;Updates&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;December 18, 2009 8:20AM - Update&lt;/strong&gt;&lt;br /&gt;The defaced website that Twitter users were directed to, shown in the screenshot above, is an online forum for the Green Freedom Wave, an Iranian reform movement.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;December 18, 2009 9:08AM - Update&lt;/strong&gt;&lt;br /&gt;The Green Freedom Wave website was hosted at Netfirms, a managed web server company that is well-known to website defacers who exploit weaknesses in web and database servers.  These web hosting companies offer lots of functionality, including web sites, databases and online shops, at very reasonable prices.  However, these features also can make them vulnerable to compromise.&lt;br /&gt;&lt;br /&gt;The website defacement is the minor part of this story.  The DNS takeover is extremely serious, especially since it happened at Twitter.com, which receives over 20 million visitors per month.  If the Twitter.com site had been redirected to a web page containing malware, a huge chunk of the Internet population would be infected.  Perhaps I should say a "huger" chunk:  &lt;a href="http://www.computerworld.com/s/article/9138514/Russian_cybergangs_make_the_Web_a_dangerous_place"&gt;35 million computers infected per month with one type of malware.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;December 18, 2009 10:35AM - Update&lt;/strong&gt;&lt;br /&gt;The Green Freedom Wave website was probably hacked using SQL Injection, Remote File Inclusion, or similar techniques that are well-documented on the web.  Note the &lt;a href="http://blog.safecentral.com/2009/12/drhiad-islamic-terrorist-or-teenager.html#dr.hiad.sig"&gt;signature line of Dr.Hiad &lt;/a&gt;from my earlier post.  &lt;a href="http://en.wikipedia.org/wiki/Remote_File_Inclusion"&gt;Remote File Inclusion&lt;/a&gt; allows an attacker to exploit a script on the target website to replace the home page of the website.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;December 19, 2009 7:49AM - Update&lt;/strong&gt;&lt;br /&gt;Busy day yesterday speaking to reporters and colleagues about the Twitter DNS compromise.  Here are a couple of stories:&lt;br /&gt;&lt;div style='margin:0px 30px'&gt;&lt;br /&gt;eWeek:&lt;br /&gt;&lt;a href='http://www.eweek.com/c/a/Security/New-Twitter-Attack-Details-Emerge-175634'&gt;http://www.eweek.com/c/a/Security/New-Twitter-Attack-Details-Emerge-175634&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Computerworld:&lt;br /&gt;&lt;a href='http://www.computerworld.com/s/article/9142485/Twitter_s_own_account_caused_blackout_says_DNS_provider'&gt;http://www.computerworld.com/s/article/9142485/Twitter_s_own_account_caused_blackout_says_DNS_provider&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-2534416668355695927?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/2534416668355695927/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=2534416668355695927' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/2534416668355695927'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/2534416668355695927'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2009/12/twitter-hack-and-iranian-cyber-army.html' title='Twitter Hack and the Iranian Cyber Army'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_4wLdyS_V2Q8/SytzlvEzISI/AAAAAAAAADs/1YBBzxHDfp8/s72-c/ica_sm.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-8250006329351316836</id><published>2009-12-08T18:38:00.002-05:00</published><updated>2009-12-08T18:51:26.644-05:00</updated><title type='text'>Securing the Cloud</title><content type='html'>I will be a speaker at a &lt;a href="https://event.on24.com/eventRegistration/EventLobbyServlet?target=registration.jsp&amp;eventid=177034&amp;sessionid=1&amp;key=B16ECE464CF54BB25BBC8B437B1746DC&amp;partnerref=fcioweb&amp;sourcepage=register"&gt;free cloud security webinar &lt;/a&gt;sponsored by Enterprise Florida on Thursday, December 10 and 2PM Eastern Time.  Cloud computing is a topic generating both hype and anti-hype right now.  The anti-hype comes mostly from the security community warning that the benefits of fast, easy development and hosting are just what we do not need right now.&lt;br /&gt;&lt;br /&gt;Also presenting will be Chris Day, Chief Security Architect at Terremark, and Alex Eckelberry, CEO of Sunbelt Software.  The event is moderated by Esther Schindler, author and industry expert.&lt;br /&gt;&lt;br /&gt;See you there!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-8250006329351316836?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/8250006329351316836/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=8250006329351316836' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/8250006329351316836'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/8250006329351316836'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2009/12/securing-cloud.html' title='Securing the Cloud'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-18389972715364471</id><published>2009-12-01T21:25:00.023-05:00</published><updated>2009-12-18T10:54:54.276-05:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='hackers islam websites internet security defacement'/><title type='text'>Dr.HiaD:  Islamic Terrorist or Teenager Having Fun?</title><content type='html'>&lt;center&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_4wLdyS_V2Q8/SxX3GUvZoHI/AAAAAAAAADc/a6RtRUao6_4/s1600-h/auto.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 254px;" src="http://2.bp.blogspot.com/_4wLdyS_V2Q8/SxX3GUvZoHI/AAAAAAAAADc/a6RtRUao6_4/s400/auto.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5410502215374315634" /&gt;&lt;/a&gt;&lt;span style='font-size: .8em;margin-left:auto;margin-right:auto;'&gt;Click image for expanded view&lt;/span&gt;&lt;/center&gt;&lt;br /&gt;&lt;br /&gt;Let me steal my own thunder and go with Teen Having Fun.&lt;br /&gt;&lt;br /&gt;Earlier today the campaign website of Bill Connor, candidate for Lieutenant Governer in South Carolina, was defaced with a graffiti-like image in the typical fashion of juvenile hackers.  &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;strong&gt;Screenshot of the Bill Connor Website Defacement&lt;/strong&gt;&lt;br /&gt;Source:  FITSNews Political Blog (not verified)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_4wLdyS_V2Q8/SxX96FGbfhI/AAAAAAAAADk/oaYAOrgRY5Q/s1600-h/hacked.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 235px;" src="http://3.bp.blogspot.com/_4wLdyS_V2Q8/SxX96FGbfhI/AAAAAAAAADk/oaYAOrgRY5Q/s400/hacked.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5410509701598903826" /&gt;&lt;/a&gt;&lt;span style='font-size: .8em;margin-left:auto;margin-right:auto;'&gt;Click image for expanded view&lt;/span&gt;&lt;/center&gt;&lt;br /&gt;&lt;br /&gt;The hacked page included a small amount of Arabic text, which got the attention of the candidate and former US Army officer, who served in Afghanistan.  A statement on &lt;a href="http://www.facebook.com/home.php?#/group.php?v=wall&amp;ref=search&amp;gid=54819625761"&gt;his campaign's Facebook page&lt;/a&gt; said, "I do hope this serves as a wakeup call to the continuing danger we face in South Carolina from the threat of radical Islam and shari’a law."&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div style="background-color: #e1e1e1; padding: 15px; margin-left: auto; margin-right: auto; margin-top: 5px; margin-bottom: 5px; font-size: 1.2em; width: 70%;"&gt;"I do hope this serves as a wakeup call to the continuing danger we face in South Carolina from the threat of radical Islam and shari’a law."&lt;br /&gt;&lt;br /&gt;Bill Connor&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;Was this a political act by Isamic extremists?  Examining the facts makes it hard to draw that conclusion.  There are many valid threats to our safety on the Internet today, but it is important to isolate the facts and not rush to judgement when it comes to identifying and prosecuting true crime online.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;"Hi ADmin your security = 0"&lt;/strong&gt; Thus reads the graphic that displaced the candidate's home page.  That statement is a poke in the eye at the web hosting company that operates the web server (not the candidate) and is typical of widespread pranks conducted by computer savvy kids who enjoy exercising their technical skills to penetrate weak server configurations from far across the Internet and leave their mark.&lt;br /&gt;&lt;br /&gt;"Dr.HiaD" in this case is the online nickname used by the hacker.  Dr.HiaD has taken credit for over one hundred such website defacements.  I have seen lists of URLs of over 4,000 web pages with his signature on them.  Other pranksters have perpetrated many more thousands of website hacks and even keep track of their scores.  See below a screenshot of one such scorecard showing recent defacements by Dr.HiaD.  The score for all "players" on this website is a staggering 43,000 on December 1, 2009 alone.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;strong&gt;Website defacement scoresheet of Dr.HiaD&lt;/strong&gt;&lt;br /&gt;Source:  Ray Dickenson&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_4wLdyS_V2Q8/SxXq6c8oHcI/AAAAAAAAADE/hIVDIvK8UYA/s1600-h/score.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 290px;" src="http://1.bp.blogspot.com/_4wLdyS_V2Q8/SxXq6c8oHcI/AAAAAAAAADE/hIVDIvK8UYA/s400/score.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5410488817279311298" /&gt;&lt;/a&gt;&lt;span style='font-size: .8em;margin-left:auto;margin-right:auto;'&gt;Click image for expanded view&lt;/span&gt;&lt;/center&gt;&lt;br /&gt;&lt;br /&gt;I have blocked out the website names in order to prevent readers from attempting to visit these sites, which may now host malware that can infect PCs.  But you can see Dr.HiaD is a prolific defacement artist.&lt;br /&gt;&lt;br /&gt;Another site Dr.HiaD hacked, that also contained a short snippet of Arabic script, was the website of a Chinese baby products company.  Again, I will withhold the name of the site, but share the graphic that was posted there.&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;br /&gt;&lt;strong&gt;One of many other websites defaced by Dr.HiaD&lt;/strong&gt;&lt;br /&gt;Source: Ray Dickenson&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_4wLdyS_V2Q8/SxXtJMHQ5yI/AAAAAAAAADM/5slWXqeC538/s1600-h/baby.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 329px;" src="http://4.bp.blogspot.com/_4wLdyS_V2Q8/SxXtJMHQ5yI/AAAAAAAAADM/5slWXqeC538/s400/baby.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5410491269481817890" /&gt;&lt;/a&gt;&lt;span style='font-size: .8em;margin-left:auto;margin-right:auto;'&gt;Click image for expanded view&lt;/span&gt;&lt;/center&gt;&lt;br /&gt;&lt;br /&gt;Who is Dr.HiaD?  He appears on an Arabic hacker website with the below signature.  Now, when it comes to teenage hackers, it is difficult to believe everything we read.  Is Dr.HiaD really 15-years-old?  Is Dr.HiaD from Morocco?  Hard to say for sure, but I believe he (or she) is.  These pranksters must balance two competing goals:  (1) not getting caught and (2) claiming and receiving credit for their exploits.  For young hackers, recognition normally trumps caution.  On the score-keeping website mentioned above, there are hackers from Singapore, Russia, India, Switzerland, Germany and many more countries around the world.  So Dr.HiaD really could be from anywhere.&lt;br /&gt;&lt;br /&gt;&lt;a name="drhiadsig"&gt;&amp;nbsp;&lt;/a&gt;&lt;br /&gt;&lt;center&gt;&lt;a name="dr.hiad.sig"&gt;&lt;strong&gt;Dr.HiaD Signature on Hacker Website&lt;/strong&gt;&lt;/a&gt;&lt;br /&gt;Source: Ray Dickenson&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_4wLdyS_V2Q8/SxXuLLPqvMI/AAAAAAAAADU/heZCaDyA-SU/s1600-h/dr.hiad.sig.PNG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 189px;" src="http://2.bp.blogspot.com/_4wLdyS_V2Q8/SxXuLLPqvMI/AAAAAAAAADU/heZCaDyA-SU/s400/dr.hiad.sig.PNG" border="0" alt=""id="BLOGGER_PHOTO_ID_5410492403119996098" /&gt;&lt;/a&gt;&lt;span style='font-size: .8em;margin-left:auto;margin-right:auto;'&gt;Click image for expanded view&lt;/span&gt;&lt;br /&gt;&lt;/center&gt;&lt;br /&gt;&lt;br /&gt;One last point about the colors used in Bill Connor's website defacement.  Some of the English letters appeared in white, green and red with black background.  It is true that these are Islamic colors.  But they are also the simplest colors to use in web pages.  The RGB color codes for these colors are:  FF0000, 00FF00, 000000, FFFFFF.  Extremely simple for kids making web pages who do not want to be bothered with shades like 0CF1E2, CECE28.  They are also stark and strong.  Perfect for a prankster.&lt;br /&gt;&lt;br /&gt;Let's close with a comment about the first screenshot above (source: Ray Dickenson).  That one came from the website of an auto accessories company in China that was hacked by Dr.HiaD.  Is this a photo of the real Dr.HiaD?  Probably not.  But it does convey something about the Dr's personality and the artistic flair of his or her pranks.  Many teenagers who crave technical accomplishment and get into trouble pursuing recognition for their talents grow up to be valuable contributors in the computer field.  Ask &lt;a href="http://www.michaelcalce.com/about/about.htm"&gt;Michael "MafiaBoy" Calce&lt;/a&gt; or &lt;a href="http://www.mitnicksecurity.com/"&gt;Kevin Mitnick&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;December 2, 2009 - Update&lt;/strong&gt;&lt;br /&gt;I spoke with Susanne Schafer of the Associated Press about this story, and she wrote an article that &lt;a href="http://www.heraldonline.com/120/story/1781472.html"&gt;appeared here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;December 3, 2009 - Update&lt;/strong&gt;&lt;br /&gt;The dramatic image in the first screenshot above comes from an Italian photographer, posted here on Flickr:  &lt;a href="http://www.flickr.com/photos/violator3/345415341/"&gt;Amegliocchi&lt;/a&gt;.  One interesting connection is that a large number of Italian language websites were defaced by Dr.Hiad.  &lt;br /&gt;&lt;br /&gt;Connection to Dr.Hiad splash screen courtesy of &lt;a href="http://www.tineye.com/"&gt;TinEye&lt;/a&gt;, a pretty effective reverse image search engine.  Want to find photos of you on the web?  Try TinEye.  If you dare :)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-18389972715364471?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/18389972715364471/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=18389972715364471' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/18389972715364471'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/18389972715364471'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2009/12/drhiad-islamic-terrorist-or-teenager.html' title='Dr.HiaD:  Islamic Terrorist or Teenager Having Fun?'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_4wLdyS_V2Q8/SxX3GUvZoHI/AAAAAAAAADc/a6RtRUao6_4/s72-c/auto.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-4356382735040758759</id><published>2009-11-18T22:50:00.004-05:00</published><updated>2009-11-19T08:21:59.621-05:00</updated><title type='text'>SafeCentral: New York Times article says it "protects users even if there’s malware on the computer"</title><content type='html'>A few weeks ago I demonstrated &lt;a href="http://www.safecentral.com"&gt;SafeCentral&lt;/a&gt; to &lt;a href="http://www.rivarichmond.com/"&gt;Riva Richmond&lt;/a&gt; of the New York Times.  She wrote an article appears in Friday's &lt;a href="http://www.nytimes.com/2009/11/19/technology/personaltech/19basics.html?_r=1"&gt;New York Times&lt;/a&gt; covering a "new breed of products" that address online identity fraud.  The article features SafeCentral alongside other new services that directly address online threats to our identities and bank accounts.  Riva Richmond points out that traditional tools like antivirus are struggling to keep up with the flood of high-tech crimeware that invades our computers to install keyloggers or conduct automated phishing.&lt;br /&gt;&lt;br /&gt;This article is not an online holiday shopping scare fest.  It provides helpful information on tools consumers can use to proactively protect themselves and remain safe and happy through the new year.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-4356382735040758759?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/4356382735040758759/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=4356382735040758759' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/4356382735040758759'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/4356382735040758759'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2009/11/new-york-times-article-covers-web.html' title='SafeCentral: New York Times article says it &quot;protects users even if there’s malware on the computer&quot;'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-8259017320644901824</id><published>2009-11-03T16:29:00.011-05:00</published><updated>2009-11-04T18:56:35.933-05:00</updated><title type='text'>Twitter:  The Internet is a more dangerous place</title><content type='html'>Twitter has made it extremely easy for people to share news and web links and at the same time has created a boon for online criminals.  It is hard to find a web service that has done more to make malware distributors' jobs easier.&lt;br /&gt;&lt;br /&gt;I don't mean just the explosive growth in the Twitter user base.  Microblogging in general, and Twitter specifically, contribute to malware distribution in fundamental ways that must be re-examined and corrected.&lt;br /&gt;&lt;br /&gt;Here are the Twitter features that make it so dangerous:&lt;br /&gt;&lt;ol&gt;&lt;br /&gt;&lt;li&gt;Twitter usernames are easily harvested in vast quantities&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Criminals can send tweets to anyone on Twitter&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Twitter encourages its users to share without thinking&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Twitter and supporting services like bit.ly strip away critical context&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Twitter is programmable and can be automated using their published APIs&lt;/li&gt;&lt;br /&gt;&lt;/ol&gt;&lt;br /&gt;&lt;div style="background-color: #e1e1e1; padding: 15px; margin: 5px; font-size: 1.2em;"&gt;Twitter features look like an Internet criminal's wish list.&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;While each of these features has appeared to some degree in other Internet services like email and instant messaging, Twitter has taken them to a new level and -- as icing on the cake -- got celebrities like Ashton Kusher and Miley Cyrus to help fuel the frenzy of massive sharing.&lt;br /&gt;&lt;br /&gt;Before describing how these features introduce vulnerabilities hackers can exploit more easily than ever, let's be clear that this is not Twitter bashing.  There is a reason Twitter has become so popular:  it clearly meets a need shared by many millions of users.  On Twitter.com we see people using the best features of the Internet to be more connected and more informed.  But just as we think twice about attending large gatherings during a swine flu pandemic, we should also think twice about sharing links on an infected Internet.&lt;br /&gt;&lt;br /&gt;Okay, let's look at our hacker wish list in more detail.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Twitter usernames are easily harvested in vast quantities&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Compared to email, collecting huge lists of Twitter usernames is incredibly easy.  Part of the attraction of Twitter is that anyone can see what all the users are up to, including seeing usernames.  Showing everyone what everyone else is saying is a great way to encourage new users to join the fun.  It's also a great way to build a list of users to target.&lt;br /&gt;&lt;br /&gt;Quality email lists, on the contrary, are harder to build.  Malware authors have been very creative in building tools to collect email address lists.  The &lt;a href="http://www.networkworld.com/news/2006/103006-tricky-new-malware-challenges.html"&gt;Warezov worm&lt;/a&gt;, for example, would scan a PC for email addresses and then send itself to those addresses to continue the process.  These worms, however, require a user to open a binary attachment to start the process, and then require the next recipients to do the same.  &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Warezov&lt;/strong&gt; and other email worms were pretty darn effective, but gathering lists of Twitter users does not require jumping through such technical and social engineering hoops.  The public nature of Twitter usernames, combined with the Twitter API (see below), make it outrageously easy "crawl" across Twitter and build massive lists of users.&lt;br /&gt;&lt;br /&gt;Here is an interesting look at a Twitter-crawling app created by some good guys -- repeat Good Guys! -- that demonstrates the concept.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.flickr.com/photos/porternovelli/3194953832/in/set-72157611051629857/"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 500px; height: 485px;" src="http://farm4.static.flickr.com/3373/3194953832_78f625caa1.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Looking at the image above, it is important to note that not only are lists of usernames easy to build, but relationships between users are also publicly available on Twitter, raising the possibility of targeted attacks against organizations using (seemingly) inside information.  ("Harry Reid said you should respond to this:  [click here]")&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Criminals can send tweets to anyone on Twitter&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Now that we have a huge list of usernames that we generated in a couple of hours, our next step will be to send them malicious links to infect their computers.  Before the rist of Twitter, there were other methods malware distributors used to get links in front of people.  "Spim" is the term of sending spammy links through an Instant Messaging (IM) network.  But the Instant Messaging model calls for users to establish relationships by a two-way handshake.  I add a new user to my contact list, they see the request and choose to accept the relationship.  Then I can send messages.  Now, it is true that malware writers can circumvent this requirement for a handshake but, like the email address harvesting example above, it requires malware engineering to get around protection designed into IM systems.  On Twitter there is no such requirement.&lt;br /&gt;&lt;br /&gt;Twitter has a similar model wherein I follow you and you follow me.  But you do not have to choose to follow me in order to see messages from me.  I can follow you, see your tweets, and send a reply that you will see in your reply box.  The Replies page is labeled "Tweets mentioning [myusername]".  And on Twitter, who does NOT want to see tweets mentioning them?  (Miley Cyrus aside.)  Compared to the effort of hacking an IM system to send unsolicited links, Twitter makes it very easy for anyone to send links to arbitrary users.&lt;br /&gt;&lt;br /&gt;So I build a huge list of usernames, follow all the users, wait for them to tweet and then reply with:  "You are so right and this proves it:  [click here]"&lt;br /&gt;At this point, the only thing keeping my huge list of users from clicking the link is a good dose of caution.  And Twitter is not about caution.  Read on.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Twitter encourages its users to share without thinking&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Stepping out of the technical realm for a moment, let's look at the Twitter social phenomenon.  Twitter is not about privacy.  Twitter is about massive-scale sharing. The tagline on the Twitter home page is, "Share and discover what's happening right now, anywhere in the world."  And, "Join the conversation."  THE conversation.  Not one on one conversations with your known friends.  We're talking about The Big conversation that we crawled through collecting our usernames up in step one.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_4wLdyS_V2Q8/SvHnBxojlXI/AAAAAAAAACU/WTmqw5GVyK4/s1600-h/twithead.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 116px;" src="http://2.bp.blogspot.com/_4wLdyS_V2Q8/SvHnBxojlXI/AAAAAAAAACU/WTmqw5GVyK4/s400/twithead.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5400351445883262322" /&gt;&lt;/a&gt; &lt;br /&gt;Twitter does provide Public or Protected accounts.  But the default setting is public and the message is clear:  don't be shy.  Jump in the deep end of the pool.  &lt;br /&gt;&lt;br /&gt;On top of that, the first step you see after creating an account is "See if your friends are on Twitter" and a web form that asks for your Gmail, Yahoo or AOL email  password.  Yes, your password.  Twitter will log into your email account and retrieve your contact list to see if there are matching Twitter accounts.  Doesn't this sound just like our friend Warezov described above?&lt;br /&gt;&lt;br /&gt;Of course these are features designed to maximize the number of users and connections between users, and that's the attraction of Twitter.  The sunny day scenario is positive one that helps build the Big Conversation.  What we are doing here is looking at these features with an eye on how they contribute to the spread of malware across the Internet.&lt;br /&gt;&lt;br /&gt;So to recap:  we have a huge list of usernames with known relationships between users, we can send any of them a link that includes some apparently familiar context even though they don't know us, and the users are in a hurry.  Tweets are short and sweet and meant to be posted and read frequently.  This favors the social engineering malware distributor who hopes the users do not spend too much time deciding whether or not to click a link in a tweet.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Twitter and supporting services like bit.ly strip away critical context&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Tweets are very short messages that don't leave a lot of room to establish familiar context.  "Check this out:  [click here]" is a classic line from emails that distribute malware.&lt;br /&gt;&lt;br /&gt;The shortened URLs that appear in tweets remove all the warning signs that indicate dangerous links.  When a link appears in your email, an IM message or a tweet it is important to inspect the URL and see where it goes before clicking on it.  If we receive a message that looks like it is from a friend asking us to look at their vacation pictures, we have a chance to be suspicious if the URL ends in a .ru (Russia) or .cn (China).  It's not likely that our friends chose a Russian or Chinese photo hosting service.  Or if the link is purportedly from our bank but the URL looks like http://aimee.pl345xxx.ru/scripts/infector/clickit.html, we might be wary about clicking it.&lt;br /&gt;&lt;br /&gt;&lt;div style="background-color: #e1e1e1; padding: 15px; margin: 5px; font-size: 1.2em;"&gt;Would you be suspicious of this URL?&lt;/br&gt;&lt;br /&gt;&lt;span&gt;http://aimee.pl345xxx.ru/scripts/infector/clickit.html&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;URL shortening services like bit.ly, tinyurl.com or tweetburner remove all the useful context and turn all URLs into generic nonsense.  There is no chance for a user to screen out risky URLs when they are shortened.&lt;br /&gt;&lt;br /&gt;&lt;div style="background-color: #e1e1e1; padding: 15px; margin: 5px; font-size: 1.2em;"&gt;How about this one?&lt;/br&gt;&lt;br /&gt;&lt;span&gt;http://bit.ly/YTmnD&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;Then there is the risk of someone penetrating the URL shortening service itself and hijacking previously shortened links to point them to malware sites.  Over &lt;a href="http://blog.internetnews.com/skerner/2009/06/2-million-cligs-short-urls-hac.html"&gt;2 million shortened links were hijacked&lt;/a&gt; this summer at URL shortening service Cligs.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Twitter is programmable and can be automated using their published APIs&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;As I mentioned above, Twitter &lt;a href="http://apiwiki.twitter.com/"&gt;provides an Application Programming Interface &lt;/a&gt;(API) that lets developers create programs to automatically exercise Twitter features.  Features that the API does not support can be accessed by automating web requests as described here:  &lt;a href="http://www.sakana.fr/blog/2007/03/18/scripting-twitter-with-curl/"&gt;Scripting Twitter with cURL.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Countermeasures&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;As we have seen, Twitter is a feature-rich malware distribution platform with a ready-to-go user base of 25 million Tweeters who are predisposed to do exactly what the bad guys want:  click it fast.  Here is a short list of things users can do protect themselves:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;br /&gt;&lt;li&gt;&lt;strong&gt;Protect your tweets:&lt;/strong&gt;  Go into your Twitter settings and click the "Protect my tweets" checkbox at the bottom.  This will remove you from the public timeline and only people you approve can follow your tweets and send you replies.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;strong&gt;Check those short links:&lt;/strong&gt;  Network security firm Sucuri provides a free service that scans shortened URLs with McAfee SiteAdvisor and Google's SafeBrowsing service.  It's available here:  &lt;a href="http://sucuri.net/index.php?page=tools&amp;title=check-url"&gt;http://sucuri.net/index.php?page=tools&amp;title=check-url&lt;/a&gt;.  &lt;a href="http://www.linkscanner.avg.com/"&gt;AVG's LinkScanner&lt;/a&gt; is also an option that will scan all the links you visit in a supported browser.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;strong&gt;Use Twitter security tools:&lt;/strong&gt;  Security tools designed specifically for Twitter are starting to appear on the market.  I haven't evaluated them yet, but one recent example is Krab Krawler from Kaspersky.&lt;/li&gt;&lt;br /&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-8259017320644901824?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/8259017320644901824/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=8259017320644901824' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/8259017320644901824'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/8259017320644901824'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2009/11/twitter-has-made-it-extremely-easy-for.html' title='Twitter:  The Internet is a more dangerous place'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://farm4.static.flickr.com/3373/3194953832_78f625caa1_t.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-1008304840812847586</id><published>2009-10-15T18:01:00.003-04:00</published><updated>2009-10-15T18:55:15.843-04:00</updated><title type='text'>Windows 7 Security versus Usability:  The Beat Goes On</title><content type='html'>Usability and security are competing goals:  the more secure a computer is, the harder it is to use.  The easier a computer is to use, the less secure it is.  In my opinion, Windows 7 is easier to use than Vista.  &lt;br /&gt;&lt;br /&gt;With Vista, Microsoft introduced User Account Control (UAC), which frequently shows pop-ups asking the user to confirm any configuration changes, like changing network settings.  UAC was one of the biggest usability problems with Vista and was lampooned by Apple in &lt;a href="http://movies.apple.com/movies/us/apple/getamac/apple-getamac-security_480x376.mov"&gt;one of their hilarious "I'm a Mac and I'm a PC" commercials."&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;With Windows 7, Microsoft backed off on the UAC prompts, which greatly improves usability.  My personal observation as a user is that Windows 7 is much more pleasant to use than Vista.  This is important, because UAC had the effect of making the entire Vista experience very un-fun and slowed adoption of an operating system that has other important security improvements.&lt;br /&gt;&lt;br /&gt;However, as is nearly always the case, increasing operating system usability also increases security risks -- risks of infection and compromise of data and functionality.  The changes to Windows 7 UAC have made it easy for malware writers to turn UAC off entirely without the user's knowledge.  Microsoft recommends keeping UAC turned on and yet allows malware to turn it off without the user's knowledge.  &lt;a href="http://blogs.msdn.com/e7/archive/2009/02/05/update-on-uac.aspx"&gt;A post on the Windows 7 Engineering Blog &lt;/a&gt;explains some of the thinking behind the no-prompt-to-turn-off-UAC issue.&lt;br /&gt;&lt;br /&gt;The story gets much more complicated at this point.  If malware is on the computer, hasn't the game already been lost?  Why worry about UAC if a password-stealing Trojan is on your computer?  The answer lies in the difficulties inherent in identifying a program as goodware or malware.  If my son downloads a game (goodware) that has been secretly tampered with to introduce malicious capability (malware) that tries to change my system configuration, I will not see a UAC prompt warning me of the configuration change.  The first step of this malicious code will be to turn off UAC and avoid warnings.  I cannot depend on antivirus to detect the malware, and I cannot depend on UAC to put up a prompt that will make my son say, "Daaaaaaad??!"&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-1008304840812847586?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/1008304840812847586/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=1008304840812847586' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/1008304840812847586'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/1008304840812847586'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2009/10/windows-7-security-versus-usability.html' title='Windows 7 Security versus Usability:  The Beat Goes On'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-8180815583884477197</id><published>2009-10-13T17:06:00.002-04:00</published><updated>2009-10-14T11:59:19.124-04:00</updated><title type='text'>Will the Internet be there when you need it?</title><content type='html'>I have &lt;a href="http://www.technewsworld.com/rsstory/68352.html"&gt;an article&lt;/a&gt; appearing in TechNewsWorld about the reliability of Internet web services.  The Twitter outage in August shocked a lot of people and called into question the dependability of Internet-based services.  In this article I look back on other notable outages -- eBay, MySpace, and Yahoo have all had their bad days -- and look into the root causes of the failures.&lt;br /&gt;&lt;br /&gt;While researching the article I read "Mafiaboy: How I Cracked the Internet and Why It's Still Broken."  This is the story of distributed denial of service (DDoS) attacks that took down Yahoo, CNN and other websites in February of 2000.  The perpetrator was a 15-year-old high school student from Montreal who had built up his DDoS capabilities by hacking university and corporate servers for many months.  If a high school student with no budget can take down top websites, it's clear that politically-motivated adults with even modest funding can do the same or worse.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-8180815583884477197?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/8180815583884477197/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=8180815583884477197' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/8180815583884477197'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/8180815583884477197'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2009/10/will-internet-be-there-when-you-need-it.html' title='Will the Internet be there when you need it?'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-8389405413536392773</id><published>2009-09-17T14:45:00.005-04:00</published><updated>2009-09-17T15:38:35.223-04:00</updated><title type='text'>The Importance of a Good (Consumer) Education</title><content type='html'>Vicki Salemi &lt;a href="http://www.sheknows.com/articles/809748.htm"&gt;posted an article&lt;/a&gt; on SheKnows.com about shopping securely online.  Educating consumers about safe online behavior is extremely important, and Vicki is certainly doing her part.&lt;br /&gt;&lt;br /&gt;The article highlights ecommerce safety tips I shared with Vicki this summer.  These tips are even more important as we head towards the holidays, so I'll recap them briefly here:&lt;ul&gt;&lt;br /&gt;&lt;li&gt;It is best to shop on "name brand" websites that are well-known and have a distinctive look and feel.  Unfamiliar websites that look cheap and poorly designed are not a wise place to spend money, even if they have eye-popping prices.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Check the address bar in the browser when you are ready to buy, reading from left to right, and be sure it starts with "https://" followed by the name of the website and ".com".&lt;/li&gt;&lt;br /&gt;&lt;li&gt;It is best to type the name of your favorite shopping website into the browser to get started. Clicking on links in emails is a risky way to start an online shopping excursion, since the links may be fake.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Don't forget to log out when you have made your purchases.  If you remain logged in and then go browsing other sites, it is possible for malware to use that login in surprising ways.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Don't make purchases on public computers.  Do you use public computers in libraries or other places?  Don't enter your credit card or other information into computers that aren't yours.  They may have information-stealing software that can give your credit card number to the bad guys.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Pay attention to what your anti-virus program is telling you.  If it says it needs an update, get the update.  If it says it expired, renew it.&lt;/li&gt;&lt;br /&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-8389405413536392773?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/8389405413536392773/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=8389405413536392773' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/8389405413536392773'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/8389405413536392773'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2009/09/importance-of-good-consumer-education.html' title='The Importance of a Good (Consumer) Education'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-1998289058625811476</id><published>2009-09-14T15:27:00.005-04:00</published><updated>2009-09-15T10:04:28.938-04:00</updated><title type='text'>High-level Attention on the Growing Cyber Crime Threat</title><content type='html'>A couple of weeks ago &lt;a href="http://blog.safecentral.com/2009/08/how-to-protect-your-commercial-bank.html"&gt;we warned &lt;/a&gt;that small businesses and local governments are being ripped off by online thieves who have learned to tap into commercial bank accounts by infecting computers with crimeware.&lt;br /&gt;&lt;br /&gt;Yesterday, the Senate Committee on Homeland Security and Governmental Affairs met to hear from government and industry experts on the growing threat of cyber-crime targeting small- and medium-sized businesses.  In his opening remarks, Committee Chairman Joseph Lieberman focused the hearing with the question: "What can be done by the public and private sectors to make commercial cyberspace secure, especially for organizations that can’t afford to have large IT staffs on the job 24/7?"&lt;br /&gt;&lt;br /&gt;&lt;div style="background-color: #e1e1e1; padding: 15px; margin: 5px; font-size: 1.2em;"&gt;“The latest targets of cybercrime are small- and medium-sized businesses."  &lt;span style="font-size: .8 em;width:100%;text-align:right;"&gt;Senator Joseph Lieberman&lt;/span&gt; &lt;/div&gt;&lt;br /&gt;&lt;br /&gt;He went on to cite the same recent thefts from small businesses and local governments we &lt;a href="http://blog.safecentral.com/2009/08/how-to-protect-your-commercial-bank.html"&gt;talked about in this blog &lt;/a&gt;a couple of weeks ago.  You can check out the hearing yourself:  &lt;a href="http://hsgac.senate.gov/public/index.cfm?FuseAction=Hearings.Hearing&amp;Hearing_ID=c643f97a-0814-4770-8121-ba20ce4d90db"&gt;&lt;strong&gt;Cyber Attacks: Protecting Industry Against Growing Threats&lt;/strong&gt;&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-1998289058625811476?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/1998289058625811476/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=1998289058625811476' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/1998289058625811476'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/1998289058625811476'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2009/09/high-level-attention-on-growing-cyber.html' title='High-level Attention on the Growing Cyber Crime Threat'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-825162410820138708</id><published>2009-08-25T11:53:00.018-04:00</published><updated>2010-01-08T15:16:23.254-05:00</updated><title type='text'>How to Protect Your Commercial Bank Account</title><content type='html'>&lt;div&gt;Remember in Ferris Bueller's Day Off, when Principal Rooney watched on his computer as Ferris' number of days absent ticked down..down..down? Ferris had hacked into the school computer and was "adjusting" his attendance record right under the nose of the principal.&lt;/div&gt;&lt;br /&gt;&lt;div&gt;Online criminals may be doing the same thing to your bank account.  Crimeware operators are stealing money right from under the noses of consumer and commercial banking customers who may not be able to recover the stolen funds. &lt;/div&gt;&lt;br /&gt;&lt;div style="background-color: #e1e1e1; padding: 15px; margin: 5px; font-size: 1.2em;"&gt;Crimeware - viruses that get onto your computer and steal money from your bank account&lt;/div&gt;&lt;br /&gt;&lt;div&gt;Security researcher Joe Stewart of SecureWorks details the workings of a piece of crimeware dubbed "Clampi".  "Clampi is operated by a serious and sophisticated organized crime group from Eastern Europe and has been implicated in numerous high-dollar thefts from banking institutions. Any user whose system has been infected by Clampi should immediately change any and all passwords used on that system for any websites, but especially financial credentials."  &lt;a href="http://www.secureworks.com/research/threats/clampi-trojan/"&gt;Full report  here&lt;/a&gt;.&lt;/div&gt;&lt;br /&gt;&lt;div&gt;Here are examples of recent thefts from commercial bank accounts:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.fox41.com/Global/story.asp?S=10627534"&gt;Bullitt County, Kentucky:  $415,000 stolen from the county government bank account by a ZeuS trojan infection.&lt;/a&gt;  The county was able to recover $105,000 but is still out $310,000.  The bank points out that the theft occurred on government computers, not bank computers.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.computerworld.com/s/article/print/9136334/Cyber_attackers_empty_business_accounts_in_minutes?taxonomyName=Security&amp;taxonomyId=17"&gt;The Western Beaver School District in Pennsylvania had $704,610.35 in school funds transfered out of its bank account to 42 other accounts as far away as Puerto Rico by a virus on a Western Beaver computer system.&lt;/a&gt;  The bank was able to reverse $263,413.34 of the transfers, leaving the school district with a $441,197.01 loss.  The school district is suing the bank to recover the full amount plus interest.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://voices.washingtonpost.com/securityfix/2009/07/the_pitfalls_of_business_banki.html"&gt;Slack Auto Parts in Gainesville, GA lost almost $75,000 due to fraudulent transfers of funds from its commercial bank account by a Clampi trojan.&lt;/a&gt;  Once again, the victim was able to get back $14,000 but is still missing over $60,000.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;Brian Krebs of the Washington Post &lt;a href="http://voices.washingtonpost.com/securityfix/"&gt;Security Fix&lt;/a&gt; blog &lt;a href="http://voices.washingtonpost.com/securityfix/2009/08/tighter_security_measures_urge.html"&gt;now reports&lt;/a&gt; that users of commercial banking accounts are being warned to take extra precautions with the computers they use to do online banking.  Brian reports that &lt;strong&gt;the Financial Services Information Sharing and Analysis Center is recommending that its members "carry out all online banking activity from a standalone, hardened, and locked-down computer from which e-mail and Web browsing is not possible."&lt;/strong&gt; &lt;br /&gt;&lt;/div&gt;&lt;div&gt;This guidance reflects an important reality about today's Internet-connected computers.  If the same computer used for online banking is also used for general web browsing, email and other Internet activities, there is a strong likelihood the computer will become infected with money- and password-stealing crimeware.  We cannot assume that our computers are free of this malware that evades detection by even the best antivirus programs.&lt;br /&gt;&lt;/div&gt;&lt;div&gt;In fact, my position is that it is better to assume the computer has been compromised and take special steps to perform online banking as safely as possible.  At Authentium we have created &lt;a href="http://www.safecentral.com"&gt;SafeCentral&lt;/a&gt; for just this purpose.  SafeCentral creates a separate Secure Desktop that protects passwords, bank accounts and other information from crimeware.&lt;/div&gt;&lt;br /&gt;&lt;div&gt;SafeCentral provides the following protection:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;Block keyloggers:&lt;/strong&gt; stops crimeware keyloggers from stealing usernames, passwords and other account information&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;strong&gt;Blocks screenshots:&lt;/strong&gt;  Prevents crimeware from taking "snaphots" of web pages that display bank account balances and other sensitive details&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;strong&gt;Secure DNS:&lt;/strong&gt;  Provides its own secure DNS lookups to stop DNS-changing crimeware from sending you to fake banking sites that steal your account credentials.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;strong&gt;High-tech Protection:&lt;/strong&gt;  Stops code injection attacks that can snoop on banking session even when they are protected by the familiar "HTTPS" and lock icon appearing in the browser.&lt;/li&gt;&lt;br /&gt;&lt;li&gt;&lt;strong&gt;Browser Security:&lt;/strong&gt;  Prevents malicious browser plugins from infiltrating the browser and performing real-time fraudulent bank transactions.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;As you can see, we built SafeCentral to provide a separate, hardened environment on computers you already own to provide a safer online experience.  Even if you buy a separate computer for online banking, we recommend that you also install and use &lt;a href="http://www.safecentral.com"&gt;SafeCentral&lt;/a&gt; to provide that extra measure of protection.&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;Update:&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;September 15, 2009: Replaced links to news stories with new, non-broken links&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-825162410820138708?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/825162410820138708/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=825162410820138708' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/825162410820138708'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/825162410820138708'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2009/08/how-to-protect-your-commercial-bank.html' title='How to Protect Your Commercial Bank Account'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-4996611916082433324</id><published>2009-08-24T13:58:00.010-04:00</published><updated>2009-08-24T18:44:37.546-04:00</updated><title type='text'>Give Your PC a Back-to-School Check-up</title><content type='html'>&lt;div align="left"&gt;While parents are getting their kids to re-focus on math and English, it's also a good time to get the computers in the house ready for school, too.&lt;br /&gt;&lt;br /&gt;After a long and busy summer of playing games, downloading music and browsing Facebook, PC's can be out of shape or downright dangerous for serious use. Here is a handy guide for giving your computers that back-to-school check-up.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;1. Remove Dangerous Programs&lt;/strong&gt;&lt;br /&gt;P2P File Sharing programs like Limewire, eMule, or Shareaza are typically used to download pirated music, games and other programs. "Other programs" can include viruses, as I &lt;a href="http://safecentral.blogspot.com/2009/02/kids-download-darndest-things.html"&gt;described here&lt;/a&gt;. Besides getting a computer infected with viruses, File Sharing programs can also make every document on your computer visible and available to users all around the world--users you don't know (and probably don't want to know). &lt;a href="http://www.thenewstribune.com/updates/story/841771.html"&gt;A Seattle man was sentenced &lt;/a&gt;earlier this month to over 3 years in prison for stealing tax returns, bank statements and canceled checks from computers all across the country.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;2. Free up Disk Space&lt;/strong&gt;&lt;br /&gt;Windows needs gigabytes of free space to run properly. When important security updates are downloaded by Windows Updates, they may fail to install because of insufficient disk space. Here is a &lt;a href="http://windowshelp.microsoft.com/Windows/en-US/help/1a8040b6-90ef-4400-a89f-52bd4d1292441033.mspx"&gt;guide from Microsoft&lt;/a&gt; on freeing up space on your hard drive. You might ask the kids to find and delete music or videos they know they don't need anymore.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;3. Run a Full Virus Scan&lt;/strong&gt;&lt;br /&gt;You do have antivirus software, don't you? If not, install a security suite immediately. AVG offers a free antivirus program you can &lt;a href="http://free.avg.com/download"&gt;get here&lt;/a&gt;. Today's antivirus programs are on all the time, watching for badware and blocking what they find. But they don't stop everything the first time they see it. So it's a good idea to pull up a chair, find your antivirus program's "Manual Scan" or "Full Scan" feature and let it run for the hour or more it may take to search the entire computer for badware. Don't worry, you don't have to sit there and watch it. Just check back periodically to see if the scan is complete and review the findings. Choose to "Quarantine" any malware that was found.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;4. Set Internet Time Limits&lt;/strong&gt;&lt;br /&gt;It may have been okay for kids to stay up late on the computer during the summer, but if you want your kids to get a good night's sleep on school nights you'll need to set some limits. First, talk to your kids and agree on an appropriate schedule and the "lights out" policy for computer use. How do you monitor and enforce this policy without watching them every minute? Many security suites include Parental Controls options to set time limits on Internet usage. Wireless routers also have this feature. You can read about &lt;a href="http://www.netgear.com/lpc"&gt;Netgear's here &lt;/a&gt;. World of Warcraft has an excellent Parental Controls feature that allows parents to create a separate password for managing a time schedule that the game servers will all enforce; the game will log your child out at whatever time you specify. (See screenshot, below) Other online games and most game consoles have at least some ability to control game play.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;5. Check Printer Ink and Paper&lt;/strong&gt;&lt;br /&gt;Okay, this is an easy one. Remember the big lemonade stand banner the kids printed out this summer that used up all the yellow? You won't want any excuses when it comes time to print out that homework. So check for printer paper and get an extra ink cartridge for the printer. That way you'll avoid any "teacher's dirty looks" when your kid hands in their first assignment printed out in magenta.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;strong&gt;Settings Play Schedules for World of Warcraft&lt;/strong&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://4.bp.blogspot.com/_4wLdyS_V2Q8/SpMXY-BvEII/AAAAAAAAAB4/YVRgQ35ardw/s1600-h/wow-pc.PNG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5373664498117709954" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 400px; CURSOR: hand; HEIGHT: 316px; TEXT-ALIGN: center" alt="" src="http://4.bp.blogspot.com/_4wLdyS_V2Q8/SpMXY-BvEII/AAAAAAAAAB4/YVRgQ35ardw/s400/wow-pc.PNG" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-4996611916082433324?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/4996611916082433324/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=4996611916082433324' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/4996611916082433324'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/4996611916082433324'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2009/08/give-your-pc-back-to-school-check-up.html' title='Give Your PC a Back-to-School Check-up'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_4wLdyS_V2Q8/SpMXY-BvEII/AAAAAAAAAB4/YVRgQ35ardw/s72-c/wow-pc.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-3487232974781439054</id><published>2009-08-06T12:05:00.006-04:00</published><updated>2009-08-06T16:29:57.436-04:00</updated><title type='text'>Are you contributing to the Twitter Denial of Service Attack?</title><content type='html'>Twitter has been dealing with a denial of service attack this morning that has resulted in millions of users not receiving or posting tweets.&lt;br /&gt;&lt;br /&gt;These days denial of service attacks typically are launched from botnets--large numbers of consumer PCs that have been infected with Trojans that wait to do the bidding of the "bot-herders" who manage them.  The users of these machines may not know anything is wrong other than, "Gee, the Internet seems slow today."  Their Internet is slow because their computer is sending lots of traffic to the targeted site, in this case twitter.com.  The bot-herders collect infected machines and then rent them out.  Twitter is such a high profile site, it may be just a bot-herder or one of their customers wanting to show off the power of their bot net.&lt;br /&gt;&lt;br /&gt;Is your computer a member of one of these botnets?  It's not easy for the average Internet user to find out.  Seeing rapidly blinking lights on your cable modem even if you aren't using your computer may suggest something is going on.  But it could just be an updater downloading a new Firefox or operating system patch.&lt;br /&gt;&lt;br /&gt;You may not be too worried about the state of Twitter.  But you should Know that botnets can be told to do many things.  They can be instructed, for example, to download keyloggers or other data stealing malware.  The stolen data is then shipped off to collection servers where the bad guys can then use your bank username and password to steal money.&lt;br /&gt;&lt;br /&gt;Keep your antivirus up to date and perform a full scan if you're a little concerned.&lt;br /&gt;&lt;br /&gt;Download and use &lt;a href="http://www.safecentral.com"&gt;SafeCentral &lt;/a&gt;if you want to bank and shop without the worry.  SafeCentral users talk about this stuff here:  &lt;a href="http://community.safecentral.com/"&gt;community.safecentral.com&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Update:&lt;br /&gt;&lt;br /&gt;It may be coincidental, but we saw a large increase yesterday in our virus-collection network.  We received 200 times the normal average of emails with malicious attachments.  One node, for example, went from 10 items to 2000 in a day.  These were phony emails telling random recipients that a UPS parcel could not be delivered and asking the reader to "print out the attached invoice".  The attachment was not an invoice, it was a trojan.&lt;br /&gt;&lt;br /&gt;Example of the email.  Do not open the attachments in these emails if you get one!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_4wLdyS_V2Q8/SnsgqAcWtaI/AAAAAAAAABw/zLWg2s7lVLM/s1600-h/phonyupsemail.PNG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 184px;" src="http://4.bp.blogspot.com/_4wLdyS_V2Q8/SnsgqAcWtaI/AAAAAAAAABw/zLWg2s7lVLM/s400/phonyupsemail.PNG" border="0" alt=""id="BLOGGER_PHOTO_ID_5366919286987601314" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-3487232974781439054?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/3487232974781439054/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=3487232974781439054' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/3487232974781439054'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/3487232974781439054'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2009/08/are-you-contributing-to-twitter-denial.html' title='Are you contributing to the Twitter Denial of Service Attack?'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_4wLdyS_V2Q8/SnsgqAcWtaI/AAAAAAAAABw/zLWg2s7lVLM/s72-c/phonyupsemail.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-7696590008534441190</id><published>2009-06-02T15:48:00.005-04:00</published><updated>2009-06-02T16:32:24.449-04:00</updated><title type='text'>Four-star review of SafeCentral</title><content type='html'>PC Magazine published a review of SafeCentral 2.0 today, giving our latest version 4 stars. You can read the entire review &lt;a href="http://www.pcmag.com/article2/0,2817,2347938,00.asp"&gt;here&lt;/a&gt;.  Neil Rubenking, the reviewer, looks at a lot of products and has a good eye for what works and what doesn't.  This is his second look at SafeCentral.&lt;br /&gt;&lt;br /&gt;If you haven't given SafeCentral your first look yet, here is a little flash video to whet your appetite.  Visit &lt;a href="http://www.safecentral.com"&gt;www.safecentral.com &lt;/a&gt;for the full story.&lt;br /&gt;&lt;object height="234" width="537" &gt;&lt;br /&gt;  &lt;param name="movie" value="http://www.safecentral.com/Flash/HowTo.swf"&gt;&lt;br /&gt;  &lt;embed src="http://www.safecentral.com/Flash/HowTo.swf" width="537" height="234"&gt;&lt;br /&gt;&lt;/embed&gt;&lt;br /&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-7696590008534441190?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/7696590008534441190/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=7696590008534441190' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/7696590008534441190'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/7696590008534441190'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2009/06/four-star-review-of-safecentral.html' title='Four-star review of SafeCentral'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-6471033810277106927</id><published>2009-05-06T16:29:00.005-04:00</published><updated>2009-05-08T17:06:43.925-04:00</updated><title type='text'>Safe Travels</title><content type='html'>&lt;div align="left"&gt;I've been on constant travel for the past month, connecting to various hotel, airport and coffee shop wireless networks, and talking with people about information risks while on the go. More and more travelers--business people, vacationers, kids and grandparents--are using laptops, netbooks and smartphones to stay connected, informed and entertained on the road and in the air. Our computers are more susceptible to infection by malicious software when we are on the move, connecting to different networks and dealing with distractions caused by unfamiliar surroundings and fear of missing a connecting flight. We are also far away from our safety net of computer support, whether that is the computer help desk at our company or the "computer guru" friend you can depend on to help you out of a jam.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-family:arial;"&gt;True Story&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;I was sitting on an airplane at the Charlotte, NC, airport waiting to return home after visiting a couple of banks. Another business traveler sat down next to me and asked if I connected to the free Wifi the airport provides in the terminal. "I connected to the network and saw a certificate warning page," he said, "I clicked past that page and a few minutes later my McAfee antivirus started alerting me about viruses on my computer." I introduced myself and offered to take a look when we got up to cruising altitude.&lt;br /&gt;&lt;br /&gt;We opened his laptop and I reviewed the virus alerts and looked in his browser cache. He said the only thing he did was connect to the network and open his browser, which loaded the Yahoo home page. I saw the file McAfee was complaining about, which was a download triggered by a javascript file downloaded from a server in China about a minute after the Yahoo home page loaded.&lt;br /&gt;&lt;br /&gt;A little more reverse engineering and I found that a flash ad on the Yahoo home page had infected the computer and installed a downloader which started downloading all manner of malware. McAfee was not telling him it had blocked the infection, it was telling him he was already infected. The first Flash exploit got right past his antivirus protection with no problem. It wasn't until the second or third install of malware that McAfee finally noticed something was up.&lt;br /&gt;&lt;br /&gt;Turns out the guy was general manager of a US company and this was the laptop he used for his corporate computing, commercial banking, everything. I strongly recommended that he rebuild the laptop, reinstall all the software and in the meantime refrain from any banking or other sensitive online use. But he was on the way to important meetings and far away from his IT support group. I invited him to stop by our offices near West Palm Beach, Florida for some cyber-assistance but I never heard from him again. I'm pretty sure he continued to use his compromised laptop, perhaps after trying multiple antivirus scan-and-clean routines.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-family:arial;"&gt;Preparing for Travel&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;Given the increased chances for malware infection while traveling, here are a few things we can do to be safer on the road. These steps should be completed the day before you head out on your business trip or vacation.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;1. Update Windows&lt;/strong&gt; - Run Windows Updates and install all updates. This is your chance to let Microsoft close as many holes as possible in your operating system and Microsoft programs.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;2. Update Applications&lt;/strong&gt; - Adobe Flash Player, Apple Quicktime and a few other applications are closely tied to web browsing and are prone to exploitation if they are out of date. In the anecdote above, an out-of-date Flash Player was responsible for the business traveler's infection. Run the &lt;a href="http://secunia.com/vulnerability_scanning/"&gt;vulnerability scan &lt;/a&gt;at &lt;strong&gt;Secunia&lt;/strong&gt; for free. It's a great tool that shows you what is out-of-date and gives easy links to click to make it all better (see screenshot below).&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;3. Update Antivirus&lt;/strong&gt; - And, of course, make sure your antivirus is updated with the latest definition files. &lt;/div&gt;&lt;div align="left"&gt; &lt;/div&gt;&lt;p align="center"&gt;&lt;a href="http://1.bp.blogspot.com/_4wLdyS_V2Q8/SgSdn-lHAwI/AAAAAAAAABg/C_9VYFRYBGY/s1600-h/secunia.scan.PNG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5333561168852615938" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 400px; CURSOR: hand; HEIGHT: 237px; TEXT-ALIGN: center" alt="" src="http://1.bp.blogspot.com/_4wLdyS_V2Q8/SgSdn-lHAwI/AAAAAAAAABg/C_9VYFRYBGY/s400/secunia.scan.PNG" border="0" /&gt;&lt;/a&gt; &lt;strong&gt;&lt;span style="font-family:arial;"&gt;Secunia Online Scan for Out-of-Date Applications&lt;/span&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Making sure your operating system, application programs and antivirus are up-to-date will give you the best chance to stay safe during your travels.  Good luck!&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-6471033810277106927?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/6471033810277106927/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=6471033810277106927' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/6471033810277106927'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/6471033810277106927'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2009/05/safe-travels.html' title='Safe Travels'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_4wLdyS_V2Q8/SgSdn-lHAwI/AAAAAAAAABg/C_9VYFRYBGY/s72-c/secunia.scan.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-3863714536231074863</id><published>2009-04-24T14:13:00.003-04:00</published><updated>2009-04-24T16:48:14.766-04:00</updated><title type='text'>Quips and Comments - RSA Conference 2009</title><content type='html'>I just returned from the RSA Conference in San Francisco where the focus was on cloud security, identity theft, data protection, and online fraud prevention.  The Expo floor was busy, with lots of foot traffic and a higher-than-expected level of energy.  Especially from the guy who escaped a straightjacket while balancing atop a high-rise unicycle and pitching a security product.  We all have to multi-task.&lt;br /&gt;&lt;br /&gt;More than half of my meetings were in hotel suites and other locations away from the Moscone Center.  Power-walking between venues, it took me a while to realize that the biz-hipsters in hair gel and rock-star sunglasses were not the new wave in computer security--they were from the AdTech conference in the Moscone Center West.  Yes, geeks, infosec is still in our hands.&lt;br /&gt;&lt;br /&gt;The "gubment" was there--in the towering National Security Agency booth/condo.  They could neither confirm nor deny jamming my iPhone.&lt;br /&gt;&lt;br /&gt;More seriously, Defense Secretary Robert Gates was &lt;a href="http://news.zdnet.com/2100-9595_22-291026.html"&gt;interviewed&lt;/a&gt; during the week on CBS News about cyber-spying.  It's worth noting that the same basic techniques are used by spies stealing government secrets and crimeware operators stealing consumer identities.  If the government cannot stop spies from &lt;a href="http://www.chicagotribune.com/news/politics/sns-ap-us-cyber-hacking-fighter,0,6775964.story"&gt;stealing secret plans&lt;/a&gt; for our latest fighter planes or &lt;a href="http://www.cnn.com/video/#/video/politics/2008/11/06/tsr.todd.candidate.hacking.cnn?iref=videosearch"&gt;infiltrating presidential campaigns&lt;/a&gt;, what chance do ordinary citizens have protecting their bank accounts?&lt;br /&gt;&lt;br /&gt;I'd like to thank Neil Rubenking, PC Magazine Lead Analyst and AppScout contributor, for taking the time to meet with us, talk about SafeCentral 2.0 and post his observations on &lt;a href="http://www.appscout.com/2009/04/updated_safecentral_offers_fas.php"&gt;AppScout&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-3863714536231074863?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.safecentral.com' title='Quips and Comments - RSA Conference 2009'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/3863714536231074863/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=3863714536231074863' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/3863714536231074863'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/3863714536231074863'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2009/04/quips-and-comments-rsa-conference-2009.html' title='Quips and Comments - RSA Conference 2009'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-2805432139743904643</id><published>2009-03-30T12:22:00.009-04:00</published><updated>2009-03-30T16:04:21.678-04:00</updated><title type='text'>When Websites Attack</title><content type='html'>&lt;div align="center"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left"&gt;Wouldn't it be crazy if a banking website infected our computer with a virus that steals money from our bank account? If you agree, then get ready for a big dose of crazy. Here's the inside scoop on a banking website we discovered doing just that: infecting its customers' computers with banking malware.&lt;br /&gt;&lt;/div&gt;&lt;div align="left"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="left"&gt;[Quick note: 60 Minutes ran a segment yesterday on infected websites. You can view the segment &lt;a href="http://www.cbsnews.com/video/watch/?id=4901282n"&gt;here&lt;/a&gt;. They interviewed a woman who watched her bank account get hacked before her very eyes.]&lt;/div&gt;&lt;div align="left"&gt;&lt;/div&gt;&lt;div align="left"&gt;During a routine scan of banking, shopping and financial services websites, the virus lab here at Authentium discovered malicious code on the website of a credit union in Lousiana. The code, which would have been invisible to us humans, was inserted at the bottom of each web page on the site. Here are some Before and After shots of the site, showing the source code:&lt;br /&gt;&lt;/div&gt;&lt;div align="center"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="center"&gt;&lt;strong&gt;Before&lt;/strong&gt; &lt;/div&gt;&lt;p align="center"&gt;&lt;img id="BLOGGER_PHOTO_ID_5319023733592286258" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 400px; CURSOR: hand; HEIGHT: 148px; TEXT-ALIGN: center" alt="" src="http://1.bp.blogspot.com/_4wLdyS_V2Q8/SdD354Cj5DI/AAAAAAAAAAw/-S4IpOX6y8U/s400/OriginalCode.crop.png" border="0" /&gt;&lt;/p&gt;&lt;div align="center"&gt;&lt;/div&gt;&lt;div align="center"&gt;&lt;strong&gt;After&lt;/strong&gt; &lt;/div&gt;&lt;div align="center"&gt;&lt;br /&gt;&lt;/div&gt;&lt;img id="BLOGGER_PHOTO_ID_5319070933900252786" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 362px; CURSOR: hand; HEIGHT: 400px; TEXT-ALIGN: center" alt="" src="http://3.bp.blogspot.com/_4wLdyS_V2Q8/SdEi1S461nI/AAAAAAAAABQ/cdjjFVGhQxs/s400/InjectedCode.red.crop.png" border="0" /&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;What does this code do?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Any Internet user who pointed their browser at the site would have the bad code downloaded and run inside their Internet Explorer or other web browser. The web browser would run this code just like all the other "good" code that shows us the text, images and links that make up the web page we're viewing. The bad code is smart. It pulls down more code from various places, jumping from China to the Ukraine and back to China. It's pretty tough for the good guys to track down the bad guys with that kind of world-hopping behavior. Here's a simple view:&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;img id="BLOGGER_PHOTO_ID_5319027589662867378" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 324px; CURSOR: hand; HEIGHT: 278px; TEXT-ALIGN: center" alt="" src="http://3.bp.blogspot.com/_4wLdyS_V2Q8/SdD7aVBbf7I/AAAAAAAAABA/kU-lU9HiULk/s400/malware.flow.sm.png" border="0" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;During Step 3, the code tries to infect our computer, betting on the fact that our Windows software is not up to date like Microsoft warns &lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS07-009.mspx"&gt;here&lt;/a&gt;, or we have not updated our Adobe PDF viewer like Adobe warns &lt;a href="http://www.adobe.com/support/security/bulletins/apsb08-19.html"&gt;here &lt;/a&gt;and &lt;a href="http://www.adobe.com/support/security/advisories/apsa09-01.html"&gt;here&lt;/a&gt;. In spite of these warnings from software vendors, an alarming percentage of computers remain out-of-date and vulnerable to infection.&lt;/p&gt;&lt;p&gt;The code in Step 3 is identified on &lt;a href="http://www.virustotal.com/"&gt;http://www.virustotal.com/&lt;/a&gt; as the (variously named) Zbot Trojan. The trojan installs a keylogger, steals sensitive data and enables fraudulent banking transactions. One thing to note in the following screenshot is that only some antivirus products detect the infection. If you were running Trend Micro or McAfee when you visited the site you would not have been protected.&lt;br /&gt;&lt;/p&gt;&lt;p align="center"&gt;&lt;a href="http://www.virustotal.com/"&gt;http://www.virustotal.com/&lt;/a&gt; analysis of the infection&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;img id="BLOGGER_PHOTO_ID_5319040134704076434" style="DISPLAY: block; MARGIN: 0px auto 10px; WIDTH: 400px; CURSOR: hand; HEIGHT: 377px; TEXT-ALIGN: center" alt="" src="http://3.bp.blogspot.com/_4wLdyS_V2Q8/SdEG0i8VFpI/AAAAAAAAABI/ecc3sfJeFkI/s400/virustotal.report.detail.PNG" border="0" /&gt;&lt;/p&gt;&lt;p&gt;So the upshot of the above is: simply browsing to the credit union website can get you infected with a trojan that steals your money.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;How did the code get there?&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;It's likely that the company managing the website did not keep the operating system, database, web server or other software up-to-date, allowing criminals to gain administrative access to the server and insert the bad code. They need to make sure the servers are up-to-date with the latest patches from Microsoft and the other vendors, just like we need to do with our own computers.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Happy Ending?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;The malicious code has been removed from the banking website we are profiling here. That doesn't mean it won't be back. Authentium continues to scan banking and shopping websites to make sure that users of our SafeCentral secure browsing service are as protected as possible. &lt;a href="http://www.safecentral.com/"&gt;SafeCentral &lt;/a&gt;is designed to provide safe web transactions even if you've been unlucky enough to visit a website that has infected your computer.&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-2805432139743904643?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/2805432139743904643/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=2805432139743904643' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/2805432139743904643'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/2805432139743904643'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2009/03/when-websites-attack.html' title='When Websites Attack'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_4wLdyS_V2Q8/SdD354Cj5DI/AAAAAAAAAAw/-S4IpOX6y8U/s72-c/OriginalCode.crop.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-3616901156029881538</id><published>2009-02-26T21:33:00.011-05:00</published><updated>2010-03-18T07:49:55.678-04:00</updated><title type='text'>Kids Download the Darnedest Things</title><content type='html'>As a kid I loved to hunt wild creatures, trap them and bring them home alive. Snakes were my favorite. My mom still tells the story of my bringing home a four foot reptile during her tea party with neighborhood moms.&lt;br /&gt;&lt;br /&gt;These days kids are just as likely to introduce dangerous creatures of the digital kind into the home computer.&lt;br /&gt;&lt;br /&gt;An &lt;a href="http://www.msnbc.msn.com/id/22425001/vp/29405819#29405819"&gt;interesting segment&lt;/a&gt; appeared on NBC's Today Show this morning that describes the risk. The story focused on kids who downloaded and used a file sharing program to access music online. Unfortunately they were using the same computer that Mom and Dad used to prepare the family tax return and did not realize the completed tax forms were shared for the entire world to see! Any identity thief could simply type "Tax Return" into their own file sharing program's search field and find the family's 1040 form ripe for the picking. The family profiled in the Today Show story had their tax form filed electronically by an online thief who was very happy to receive their $2000 tax refund.&lt;br /&gt;&lt;br /&gt;There are more insidious risks to file sharing networks: they are an excellent means for spreading Trojans that quietly infect computers, remain under your antivirus radar, and do more long-term damage than grabbing a tax return. File sharing programs are used by millions of users around the world to download "free" software. Need Photoshop but don't want to spend the money? File sharing programs can deliver you a "cracked" copy (a permanent free trial) or a key generator you can use to generate your own license key. Bogus key generators ("keygens") are the most common form of malware on file sharing networks.&lt;br /&gt;&lt;br /&gt;Malware distributors watch for file sharing searches of any and all keywords and immediately offer up files that match the keywords. Searches for "Benjamin Franklin" in a file sharing program will return hits like "Benjamin Franklin keygen" or "Benjamin Franklin Greatest Hits." The files these search results point to can be executable programs or songs and videos that can deliver infections to computers that play them.&lt;br /&gt;&lt;br /&gt;Here is an example of a file sharing search this morning. The marked entry, "benjamin franklin KeyGen," is identified by Authentium's Command Anti-Malware as "W32/Trojan2.FXIS." This is a trojan that infects the Windows login service so it runs every time a user logs in. What does it do next? Anything it wants to.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_4wLdyS_V2Q8/SafSTZ9yqgI/AAAAAAAAAAc/8qbxtOA3F3Y/s1600-h/benjamin.franklin2.PNG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5307441916708825602" style="display: block; margin: 0px auto 10px; width: 400px; height: 189px; text-align: center;" alt="" src="http://1.bp.blogspot.com/_4wLdyS_V2Q8/SafSTZ9yqgI/AAAAAAAAAAc/8qbxtOA3F3Y/s400/benjamin.franklin2.PNG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;These infections can include Banking Trojans, &lt;a href="http://safecentral.blogspot.com/2008/11/undetectable-data-stealing-trojan-nabs.html"&gt;Keyloggers&lt;/a&gt; and &lt;a href="http://safecentral.blogspot.com/2008/12/dns-changer-learns-new-trick.html"&gt;DNS Changers&lt;/a&gt; that are described elsewhere on this blog.&lt;br /&gt;&lt;br /&gt;Kids do download the darndest things. Authentium's &lt;a href="http://www.safecentral.com/"&gt;SafeCentral&lt;/a&gt; provides secure banking and shopping even on computers that may have been infected by the kids.&lt;br /&gt;&lt;br /&gt;Now I'm going to call my mom and remind her that none of the snakes, crabs or lizards I brought home ever emptied the family bank account.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;Update:&lt;br /&gt;&lt;/strong&gt;&lt;/span&gt;March 16, 2009:  A couple of media outlets picked up on this story over the weekend:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Dallas Morning News&lt;/strong&gt; - Pamela Yip covered the story in Sunday's paper here:&lt;br /&gt;&lt;a href="http://www.dallasnews.com/sharedcontent/dws/bus/columnists/pyip/stories/031609dnmoneytalk.3b94f52.html"&gt;Protect your personal data when filing taxes online&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;MarketWatch&lt;/strong&gt; - Andrea Coombes included it in last Friday's &lt;a href="http://www.marketwatch.com/news/story/if-you-file-your-taxes/story.aspx?guid=%7BF4FD80E5-C3DE-422C-AD8C-7FD5069F2C3C%7D"&gt;Taxing Times&lt;/a&gt; and will be following up with more this week in the &lt;a href="http://www.marketwatch.com/personalfinance/taxes"&gt;Market Watch Personal Finance &lt;/a&gt;section&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-3616901156029881538?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/3616901156029881538'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/3616901156029881538'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2009/02/kids-download-darndest-things.html' title='Kids Download the Darnedest Things'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_4wLdyS_V2Q8/SafSTZ9yqgI/AAAAAAAAAAc/8qbxtOA3F3Y/s72-c/benjamin.franklin2.PNG' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-8370672700733888820</id><published>2009-02-17T14:10:00.003-05:00</published><updated>2009-02-17T18:56:05.924-05:00</updated><title type='text'>The Next Internet..Now</title><content type='html'>Internet Security is broken, and the best way to fix it is to start over.  This is the idea presented in an excellent article in the New York Times this weekend:  &lt;a href="http://www.nytimes.com/2009/02/15/weekinreview/15markoff.html"&gt;Do We Need a New Internet?&lt;/a&gt;  John Markoff describes "a growing belief among engineers and security experts that Internet security and privacy have become so maddeningly elusive that the only way to fix the problem is to start over."&lt;br /&gt;&lt;br /&gt;This is an excellent topic for debate and discussion among Internet technologists and everyday users alike.  Technologists can (and will) endlessly debate the merits of a revolutionary approach like the &lt;a href="http://cleanslate.stanford.edu/"&gt;Clean Slate&lt;/a&gt; program at Stanford versus a more evolutionary approach to incremental improvements like deploying DNSSEC and IPv6.  Whichever approach we take, it is safe to say the solution will take decades to develop and get into mass deployment.&lt;br /&gt;&lt;br /&gt;But the fact that stands out clearly is:  Something Must Be Done.&lt;br /&gt;&lt;br /&gt;Authentium has taken a revolutionary approach to Internet security and developed a solution that gives users access to The Next Internet, now.  We recognized the limitations of DNS and the critical impact its compromise can have on Internet transactions.  We saw the "maddening" failure of antivirus and firewall suites in their efforts to keep computers clean of infection by identity-stealing malware that allows criminals to "take over someone's computer from half a world away."&lt;br /&gt;&lt;br /&gt;So we developed SafeCentral, which has its own Secure DNS and its own hardening against the keyloggers and screen-stealers found in Banker Trojans.  Our goal was to create an island of safety on a computer that is otherwise adrift on an unsafe Internet, which is the only Internet we have right now.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-8370672700733888820?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://safecentral.blogspot.com/2009/02/blog-post.html' title='The Next Internet..Now'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/8370672700733888820/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=8370672700733888820' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/8370672700733888820'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/8370672700733888820'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2009/02/blog-post.html' title='The Next Internet..Now'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-6716631274746886859</id><published>2009-02-10T15:25:00.008-05:00</published><updated>2009-02-10T16:48:29.512-05:00</updated><title type='text'>Is there Safety in the Cloud?</title><content type='html'>Web applications that run in Data Centers can be well-protected with physical, network and system security by applying sufficient people, processes and technology to manage infrastructure that is directly under the control of operations staff.&lt;br /&gt;&lt;br /&gt;Unmanaged endpoints, like desktop computers of tele-workers or laptops of mobile users who access these applications, can introduce holes into an otherwise complete security model.&lt;br /&gt;&lt;br /&gt;The best efforts of server and network professionals can protect data in the server farm, but data that originates from or is downloaded to compromised endpoints is subject to theft and exploitation.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;So, yes, there is safety in the cloud, but the endpoint is another matter.&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.safecentral.com"&gt;Authentium's SafeCentral&lt;/a&gt; is an endpoint-based solution that creates a secure footprint on an otherwise unmanaged computer to allow it to access sensitive data and applications and block data leakage. Such leakage can result from &lt;a href="http://www.scmagazineus.com/Sinowal-data-stealing-trojan-has-infected-half-million-PCs/article/120243/"&gt;mass-market&lt;/a&gt; or &lt;a href="http://www.informationweek.com/blog/main/archives/2008/09/the_steady_rise.html"&gt;targeted&lt;/a&gt; attacks on endpoints that install keyloggers, SSL data hijackers, remote access tools or other malware.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.safecentral.com"&gt;SafeCentral&lt;/a&gt; creates a managed session on an otherwise unmanaged computer. SafeCentral applies special, restrictive policies to the unmanaged operating system during web application usage such that data and functions the application makes available can be shielded from monitoring, recording and theft by malware that has infected the endpoint.&lt;br /&gt;&lt;br /&gt;Examples of shielding include:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Blocking keyloggers&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Blocking screen capture&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Preventing code injection that can steal data even out of SSL/TLS-protected web connections&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Providing alternate, secure DNS lookups that bypass vulnerable DNS resolvers&lt;/li&gt;&lt;br /&gt;&lt;li&gt;Providing browser lockdown that blocks malicious plugins and extensions&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Online banking is a good example of extremely sensitive web applications that run on unmanaged clients. Banking trojans are increasingly used by online criminals to take advantage of these access points to create a multi-billion-dollar industry of fraudulent transactions. The largest banks around the world will be deploying SafeCentral to their clients during 2009.&lt;br /&gt;&lt;br /&gt;There will be many interesing ways in which remote desktops, virtual machines or virtual browsers on the client side, and other security approaches evolve over the next decade. Given that Citrix Winframe has been available for over a decade, it's clear that these technologies take time to achieve maturity and large-scale deployment.&lt;br /&gt;&lt;br /&gt;SafeCentral is available now as a managed service that provides a secure web application client on Windows endpoints that are prone to infection and exploitation even when antivirus, antispyware, firewall and other security software is already installed. Data Center staff cannot also take responsibility for keeping endpoints clean of malware, but they can require use of SafeCentral to access their server-side applications and rest assured that web sessions remain private and protected.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-6716631274746886859?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://safecentral.blogspot.com/2009/02/is-there-safety-in-cloud.html' title='Is there Safety in the Cloud?'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/6716631274746886859/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=6716631274746886859' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/6716631274746886859'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/6716631274746886859'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2009/02/is-there-safety-in-cloud.html' title='Is there Safety in the Cloud?'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-5907650023184409974</id><published>2009-01-22T17:41:00.010-05:00</published><updated>2009-01-23T09:27:11.751-05:00</updated><title type='text'>Where Did All the Nice Web Sites Go?</title><content type='html'>There is a &lt;a href="http://investor.websense.com/releasedetail.cfm?ReleaseID=360276"&gt;new report&lt;/a&gt; out from Websense that summarizes their research into the status of web-based malicious code in the second half of 2008. The major takeaway for me was: there are no safe web sites anymore. By "safe" I mean not likely to contain malicious code that will infect your browser or your computer.&lt;br /&gt;&lt;br /&gt;Here are a some snippets from the report:&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;em&gt;&lt;strong&gt;77 percent of Web sites with malicious code are legitimate sites that have been compromised&lt;/strong&gt;.&lt;/em&gt; &lt;/em&gt;&lt;br /&gt;By "legitimate sites" they mean web sites that Internet users would not expect to be hosting malicious code. Sites like the New York Times, Business Week, and CNET. It's remarkable that Websense numbers show there are more legitimate websites distributing malware than there are malicious websites set up by the bad guys!&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;strong&gt;70 percent of the top 100 sites either hosted malicious content or contained a masked redirect to lure unsuspecting victims from legitimate sites to malicious sites.&lt;/strong&gt;&lt;/em&gt;&lt;br /&gt;A large majority of the most-visited web sites on the Internet either had malicious content on them or had links to malicious sites posted by users who exploit social networking features like comments and messages.&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;strong&gt;39 percent of malicious Web attacks included data-stealing code.&lt;/strong&gt;&lt;/em&gt;&lt;br /&gt;If you regularly visit web sites in the top 100 most-visited sites, chances are you were exposed to malware. You could still be safe if your operating system, web browser and plug-ins like Adobe Viewer and Flash were all the latest versions AND you did not encounter an exploit for an unpatched vulnerability. &lt;a href="http://secunia.com/blog/37/"&gt;Secunia's statistics&lt;/a&gt; show that less than 2% of computers are fully patched, and over 45% have 11 or more insecure programs.&lt;br /&gt;&lt;br /&gt;These numbers show the shocking truth: there is a very high chance an average Internet user will get infected with data stealing malware even if they stay on the well-lit, well-traveled portions of the web.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Dedicate a Computer for Banking and Shopping&lt;/strong&gt;&lt;br /&gt;My advice is to keep a dedicated computer for banking and shopping. Here is a checklist for this "safe computer:"&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Make sure Windows Updates are set to automatic. &lt;/li&gt;&lt;li&gt;Always keep Adobe and Flash plugins up-to-date (make sure you don't click on fake update windows). &lt;/li&gt;&lt;li&gt;On this dedicated computer, never visit any social networking site like MySpace or Facebook. &lt;/li&gt;&lt;li&gt;Do not view any videos. &lt;/li&gt;&lt;li&gt;Do not check your email. &lt;/li&gt;&lt;li&gt;Do not read news sites.&lt;/li&gt;&lt;li&gt;Do not install any programs other than a web browser like Firefox or Safari. &lt;/li&gt;&lt;li&gt;Do not use Internet Explorer.&lt;/li&gt;&lt;li&gt;Wipe the disk and re-install Windows once every three months (more frequently if it starts behaving erratically)&lt;/li&gt;&lt;li&gt;If you are up to it, use Linux rather than Windows&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;I know this is a large list and it may be easier to lose weight and quit smoking than abide by its rules. I hope you're not reading this list on your dedicated safe computer, because you will have just broken a rule!&lt;/p&gt;&lt;p&gt;Another thing you can do is install &lt;a href="http://www.safecentral.com/"&gt;SafeCentral&lt;/a&gt; and use its secure browser for banking, shopping and financial services. We built SafeCentral knowing that there are too many hoops a user needs to jump through to keep their identity and their money safe online.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-5907650023184409974?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://safecentral.blogspot.com/2009/01/where-did-all-nice-web-sites-go.html' title='Where Did All the Nice Web Sites Go?'/><link rel='enclosure' type='application/pdf' href='http://media.haymarketmedia.com/Documents/2/WSL_ReportQ3Q4FNL_Print_1198.pdf' length='0'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/5907650023184409974/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=5907650023184409974' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/5907650023184409974'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/5907650023184409974'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2009/01/where-did-all-nice-web-sites-go.html' title='Where Did All the Nice Web Sites Go?'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-6459940745292956579</id><published>2008-12-18T09:21:00.011-05:00</published><updated>2008-12-18T12:12:45.781-05:00</updated><title type='text'>The Promiscuous Browser in a Dangerous World</title><content type='html'>&lt;span style="font-family:trebuchet ms;font-size:100%;"&gt;Microsoft released an &lt;/span&gt;&lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-078.mspx"&gt;&lt;span style="font-family:trebuchet ms;"&gt;urgent patch&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:trebuchet ms;"&gt; for a critical Internet Explorer vulnerability yesterday, highlighting the risks our web browsers represent to our online safety. &lt;strong&gt;Web browsers in general, and Internet Explorer specifically, are the most promiscuous programs we run on our computers.&lt;/strong&gt; "Promiscuous" refers to the quantity and diversity of web sites we visit, content we view, programs we download, and sensitive information we exchange when browsing the web. Browser promiscuity also refers to what happens after we type a URL into the address bar. The browser first downloads an HTML page that includes tags and pointers to other content: images, stylesheets, scripts and videos. This content can come from many different web servers operated by many different organizations and can carry harmful data that infect our computers, steal our data or just sit there, undetected, until an online criminal issues remote commands to bring it to life.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Trebuchet MS;"&gt;Richard Adhikari posted an &lt;a href="http://www.internetnews.com/webcontent/article.php/12221_3791986_2"&gt;excellent article&lt;/a&gt; on InternetNews.com that describes the Internet Explorer patch, why it was necessary and what it means for online safety going forward. The multitude of exploitable features in Internet Explorer make it an excellent target for online criminals seeking to gain control of our computers and our bank accounts.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;span style="font-size:100%;"&gt;Simply put, it is not reasonable to use one browser for everything we do on the Internet. It is important for us to segment our web activities into two basic buckets:&lt;/span&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;strong&gt;&lt;span style="font-family:trebuchet ms;"&gt;Casual Web Use&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Casual use includes reading the news, listening to music, researching recipes, and clicking links to the latest must-see Flash video our friends send us in email.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-family:trebuchet ms;"&gt;Sensitive Web Use&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Sensitive use includes online banking, shopping, applying for a job, or any other transaction that requires information we would not want everyone to know.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Casual use is where we are most likely to get our computer or browser infected. It's easy to visit hundreds of websites a month, clicking from link to link, moving from reasonably safe websites to a dangerous Internet neighborhood where crimeware infections are likely to occur. Sensitive use is where we are most likely to get our money or identity stolen if we are using an infected computer or browser. Moving from one activity to the other with the same browser is just not smart. I like the excerpt from court-ordered wiretaps of Illinois Gov. Rod R. Blagojevich, quoted here from a Department of Justice &lt;/span&gt;&lt;a href="http://chicago.fbi.gov/dojpressrel/pressrel08/dec09_08.htm"&gt;&lt;span style="font-family:trebuchet ms;"&gt;press release&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:trebuchet ms;"&gt;: &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div align="center"&gt;&lt;strong&gt;&lt;span style="font-family:trebuchet ms;"&gt;"assume everybody’s listening, the whole world is listening."&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;That is smart advice for Internet users. If you have casually browsed the web for a few weeks or months on your computer, there is a high likelihood you have been infected through a web browser vulnerability. Infections can include "&lt;/span&gt;&lt;a href="http://research.pandasecurity.com/archive/Banking-Trojans-I.aspx"&gt;&lt;span style="font-family:trebuchet ms;"&gt;banker trojans&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:trebuchet ms;"&gt;," password- and money-stealing programs that listen in to your online banking sessions. So, when you move from casual use to sensitive use, assume the whole world is listening.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-family:trebuchet ms;"&gt;Safe Web Use&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;A new category of web usage that we are pioneering at Authentium is "Safe Web Use." Safe Web Use means we assume "everybody's listening" and still protect your sensitive online transactions. Our &lt;/span&gt;&lt;a href="http://www.safecentral.com/"&gt;&lt;span style="font-family:trebuchet ms;"&gt;SafeCentral&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:trebuchet ms;"&gt; service helps to automatically switch between Casual and Sensitive web use and kicks in extra protection to block crimeware that got past your antivirus software during a casual web browsing session. SafeCentral stops keyloggers, screen-stealers, harmful browser plug-ins and many other crimeware components. We also provide a Secure DNS services that protects against another class of threat: &lt;/span&gt;&lt;a href="http://safecentral.blogspot.com/2008/12/dns-changer-learns-new-trick.html"&gt;&lt;span style="font-family:trebuchet ms;"&gt;DNS redirection&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:trebuchet ms;"&gt;. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;So, be sure you get yesterday's Internet Explorer patch. But please understand that yesterday's patch will not protect against tomorrow's exploit. In October Microsoft released an unscheduled, &lt;/span&gt;&lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx"&gt;&lt;span style="font-family:trebuchet ms;"&gt;critical update&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:trebuchet ms;"&gt; for Windows. Chances are the online criminals are already working on exploits we will only hear about in January or February.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Also be sure to check out &lt;/span&gt;&lt;a href="http://www.safecentral.com/"&gt;&lt;span style="font-family:trebuchet ms;"&gt;SafeCentral&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:trebuchet ms;"&gt; and be safe even if everybody's listening.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-6459940745292956579?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.internetnews.com/webcontent/article.php/12221_3791986_2' title='The Promiscuous Browser in a Dangerous World'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/6459940745292956579/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=6459940745292956579' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/6459940745292956579'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/6459940745292956579'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/12/promiscuous-browser-in-dangerous-world.html' title='The Promiscuous Browser in a Dangerous World'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-7799708998060300195</id><published>2008-12-09T17:46:00.007-05:00</published><updated>2008-12-09T18:48:36.230-05:00</updated><title type='text'>DNS Changer Learns a New Trick</title><content type='html'>&lt;span style="font-family:trebuchet ms;"&gt;SANS, Symantec, McAfee and others have reported on a new trick that malware is using to redirect unsuspecting users from authentic web destinations--the name we type into the browser address bar or pick from our favorites--to a web server operated by the Bad Guys. These guys can set up web sites that look just like the real Citibank or Wachovia but are designed to steal our user ID and password or transfer money out of our account.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;The trickiest part of the new trick is that we can follow all of the best security advice and still be susceptible. If one user on a Wifi network is infected with this new DNS Changer, all users who connect to that network can have their DNS settings changed by the one infected computer. So that guy who is halfway through his latte when you sit down in the coffee shop and open your laptop could be a threat to you. Even if you are super careful about the websites you visit and the security software you have installed.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-family:trebuchet ms;"&gt;How?&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;DNS is the Internet-wide system that translates names like "online.mybank.com" into the numerical address our computers need to actually connect to MyBank. If the Bad Guys control your DNS, they control where your web browser really goes when you think it is going to PayPal.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;Every time we open our laptop and connect to a new network, a router on that network will send down settings that let us connect, (pay!), and get out on the Internet. The new DNS Changer trick is this: a computer infected with this DNS Changer variant will listen for new computers requesting a connection on the same network (the same coffee shop) and try to answer with Bad Guy settings before the "official" router can send it the "official" settings. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;As fundamental as DNS is to the operation of the world-wide web, it's amazingly susceptible to compromise. This new DNS Changer behavior capitalizes on the vulnerability of DNS settings and: (1) leaves no traces, (2) doesn't require your computer to be infected with anything that your antivirus software will complain about.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-family:trebuchet ms;"&gt;Now What?&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;This is why we invented &lt;/span&gt;&lt;a href="http://www.safecentral.com/"&gt;&lt;span style="font-family:trebuchet ms;"&gt;SafeCentral&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:trebuchet ms;"&gt;. SafeCentral includes a unique Secure DNS feature that protects against DNS Changer and other threats. SafeCentral uses it's own DNS. It uses Authentium's Secure DNS servers and it does so through an encrypted (HTTPS) connection.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;So even if we connect to a Wifi hotspot that is hosting an infected computer, we can happily browse the web, bank and shop safely.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:trebuchet ms;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-7799708998060300195?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://isc.sans.org/diary.html?storyid=5434' title='DNS Changer Learns a New Trick'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/7799708998060300195/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=7799708998060300195' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/7799708998060300195'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/7799708998060300195'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/12/dns-changer-learns-new-trick.html' title='DNS Changer Learns a New Trick'/><author><name>Ray Dickenson</name><uri>http://www.blogger.com/profile/07798531329556389583</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-5179144380623967408</id><published>2008-11-04T10:29:00.002-05:00</published><updated>2008-11-04T11:00:55.806-05:00</updated><title type='text'>Undetectable data-stealing trojan nabs 500,000 virtual wallets</title><content type='html'>&lt;a href="http://www.rsa.com/blog/blog_entry.aspx?id=1378"&gt;RSA&lt;/a&gt; issued a report earlier this week confirming the enormous threat posed to all internet users by the "Sinowal" trojan (a.k.a "Torpig" and "Mebroot").  This insidious agent is virtually undetectable, infecting a user's PC regardless of Anti-Virus and other defenses - thanks to a steady stream of variants and a highly-advanced design.  Once on your system, it waits for you to visit a banking or any of its other 2,700+ trigger sites, then injects additional information fields designed to capture the necessary personal data for identity theft.  The gathered credentials are well organized and sent discretely off to the criminal servers. &lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;[RSA] recently discovered that, dating back as early as February 2006, the Sinowal Trojan has compromised and stolen login credentials from approximately 300,000 online bank accounts as well as a similar number of credit and debit cards. Other information such as email, and FTP accounts from numerous websites, have also been compromised and stolen.&lt;/blockquote&gt;&lt;br /&gt;The trojan is downloaded automatically through websites that exploit vulnerabilities in Windows or 3rd-party applications, and doesn't require any action or 'acceptance' by the user to install.  What's worse, is that once installed:&lt;br /&gt;&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;About the only remedy for victims fortunate enough to learn they are contaminated is to reformat their hard drive and reinstall their operating system.&lt;/blockquote&gt;&lt;br /&gt;So, here's a trojan that your standard defenses won't catch, and which can't be erradicated short of re-formatting your system.  This is exactly the reason we designed &lt;a href="http://www.safecentral.com"&gt;SafeCentral&lt;/a&gt; as a "Reverse Sandbox" solution.   The security industry battles the criminals every day, but no defense system is perfect; nothing is 100% effective at stopping every infection.  Also, no one wants to erase all of their data and start from scratch reformatting your drive.  So, what is a user to do when presented with an easy to catch, difficult to block, and almost impossible to erase evil bug like this?  Use &lt;a href="http://www.safecentral.com"&gt;SafeCentral&lt;/a&gt;!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.safecentral.com"&gt;SafeCentral&lt;/a&gt; keeps the URL's you enter private, thereby eliminating the 'trigger' event for this trojan, and &lt;a href="http://www.safecentral.com"&gt;SafeCentral&lt;/a&gt;'s secure DNS and anti-keylogging/anti-screen-scraping protect your data from exposure.  &lt;a href="http://www.safecentral.com"&gt;SafeCentral&lt;/a&gt; is the only way a PC user who might come in contact with a Sinowal variant can transact safely online.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-5179144380623967408?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.theregister.co.uk/2008/10/31/sinowal_trojan_heist/' title='Undetectable data-stealing trojan nabs 500,000 virtual wallets'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/5179144380623967408/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=5179144380623967408' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/5179144380623967408'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/5179144380623967408'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/11/undetectable-data-stealing-trojan-nabs.html' title='Undetectable data-stealing trojan nabs 500,000 virtual wallets'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-1574964678322618543</id><published>2008-10-06T12:38:00.001-04:00</published><updated>2008-10-06T12:38:38.823-04:00</updated><title type='text'>7 Online Blunders That Invite Identity Theft</title><content type='html'>Nothing revolutionary or surprising here; just good common sense tips for avoiding identity theft.  Unfortunately, the remedies to these 7 blunders are almost entirely reactionary; forcing the user to duck and dodge a scam rather than avoid it entirely.  &lt;br/&gt;&lt;br/&gt;&lt;a href='http://www.consumerreports.org/cro/electronics-computers/computers/internet-and-other-services/7-online-blunders/overview/7-online-blunders-ov.htm?EXTKEY=I72RSE0'&gt;read more&lt;/a&gt; | &lt;a href='http://digg.com/security/7_Online_Blunders_That_Invite_Identity_Theft'&gt;digg story&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-1574964678322618543?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/1574964678322618543/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=1574964678322618543' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/1574964678322618543'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/1574964678322618543'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/10/7-online-blunders-that-invite-identity.html' title='7 Online Blunders That Invite Identity Theft'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-6726692317917028930</id><published>2008-10-02T15:31:00.007-04:00</published><updated>2008-10-02T16:11:23.051-04:00</updated><title type='text'>Infection Happens:  What then?</title><content type='html'>There's been a lot of attention lately to a class of products defined as "sandboxes", which attempt to prevent malware from seeping onto a user's computer by establishing a virtual layer that internet data must traverse before reaching the 'host' machine's OS.   These products offer a reasonable level of protection from infection, but don't effectively prevent the activities of malware already present on your machine.&lt;br /&gt;&lt;br /&gt;I'll let you in on a little secret:  &lt;span style="font-weight: bold;"&gt;INFE&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;CTION HAPPENS&lt;/span&gt;.   Much like the comical bumper sticker about feces, this is just another fact of life: &lt;span style="font-style: italic;"&gt;infection happens&lt;/span&gt;.   Authentium has been in the anti-malware industry for over 20 years, and makes one of the most effective and efficient AVSDK's in the world.   However, no AV engine, no spyware engine, no anti-malware engine has &lt;span style="font-style: italic;"&gt;ever&lt;/span&gt; proven itself 100% effective at stopping ALL infections.   There are simply too many vectors for a piece of malicious code to find its way onto your system.    This isn't to suggest you shouldn't be running a good desktop security suite, or following good habits and behaviors when online, but realize that even those with the best intentions and most diligent practices can still become the victim of an infection.   In fact, according to &lt;a href="http://www.mediapost.com/publications/index.cfm?fuseaction=Articles.san&amp;amp;s=28738&amp;amp;Nid=12793&amp;amp;p=276816"&gt;Bigfoot Interactive&lt;/a&gt;, &lt;span style="font-weight: bold; font-style: italic;"&gt;55% of online users have been infected with spyware&lt;/span&gt;.  All these defenses, and yet most people will still get a bug in there machine.&lt;br /&gt;&lt;br /&gt;The real question for the security industry, and more importantly consumers, is &lt;span style="font-style: italic; font-weight: bold;"&gt;WHAT THEN?&lt;/span&gt;   Presuming the inevitability of an infection, what can the user do to protect themselves and their privacy when conducting sensitive transactions online.    The answer, of course, is &lt;a href="http://www.safecentral.com/"&gt;SafeCentral&lt;/a&gt;.  Which is an entirely new class of product we often describe as a "&lt;a href="http://www.safecentral.com/whatisit/rsandbox.html"&gt;Reverse Sandbox&lt;/a&gt;"; designed to safeguard your activities from the intent of malware even if your PC is already an infected cesspool of malware agents.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_EHhB3f_ny8k/SOUoM6Q3FII/AAAAAAAAAA8/5kQS1cl1QlQ/s1600-h/SC_v_Sandbox.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_EHhB3f_ny8k/SOUoM6Q3FII/AAAAAAAAAA8/5kQS1cl1QlQ/s400/SC_v_Sandbox.png" alt="" id="BLOGGER_PHOTO_ID_5252648742661067906" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;INFECTION HAPPENS.  And just like the bumper sticker suggests, it's how you deal with it that defines you're outlook on the world.   When 'Sh*t Happens', keep your head about you and an even, laid-back attitude.   When 'Infection Happens', arm yourself with a tool that can protect your identity and your data, so you can face the internet with confidence and that same laid-back attitude, knowing your safe despite the infection.&lt;br /&gt;&lt;br /&gt;Our chairman, John Sharp, offered a great explanation of SafeCentral's approach in &lt;a href="http://authentium.blogspot.com/2008/10/sandboxing-is-not-what-we-do.html"&gt;his blog&lt;/a&gt;.  Read that, and our &lt;a href="http://www.safecentral.com/documents/ReverseSandboxing.pdf"&gt;whitepaper on the reverse sandbox approach&lt;/a&gt;, to learn how to stay safe even when 'infection happens'.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-6726692317917028930?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/6726692317917028930/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=6726692317917028930' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/6726692317917028930'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/6726692317917028930'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/10/infection-happens-what-then.html' title='Infection Happens:  What then?'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_EHhB3f_ny8k/SOUoM6Q3FII/AAAAAAAAAA8/5kQS1cl1QlQ/s72-c/SC_v_Sandbox.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-320236029047366429</id><published>2008-09-18T10:26:00.002-04:00</published><updated>2008-09-18T10:33:25.150-04:00</updated><title type='text'>SafeCentral Updated!</title><content type='html'>This week we took the wraps of the &lt;a href="http://www.marketwatch.com/news/story/authentiums-safecentral-upgrade-improves-secure/story.aspx?guid=%7BA6599B99-E460-42FE-BAA2-15C213D9EBF6%7D&amp;amp;dist=hppr"&gt;biggest update&lt;/a&gt; to &lt;a href="http://www.safecentral.com"&gt;SafeCentral&lt;/a&gt; since launch, and we're thrilled with the results.  The new version 1.3 release includes an entirely redesigned interface, from desktop to web, which gives the service a unified and consistent look and feel.  In addition, major efforts have been taken to speed up the performance of all aspects of the service, increase compatibility, and to lay the foundation for exciting new features in the near future.  You can read the full details in our &lt;a href="http://www.safecentral.com/documents/SafeCentral_News_Sept08.pdf"&gt;newsletter&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Existing customers will have the update rolled out to them automatically in the next few days, and all new users to &lt;a href="http://www.safecentral.com"&gt;http://www.safecentral.com&lt;/a&gt; can download and enjoy version 1.3 immediately.&lt;br /&gt;&lt;br /&gt;As always, we welcome your feedback and comments.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-320236029047366429?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.marketwatch.com/news/story/authentiums-safecentral-upgrade-improves-secure/story.aspx?guid=%7BA6599B99-E460-42FE-BAA2-15C213D9EBF6%7D&amp;dist=hppr' title='SafeCentral Updated!'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/320236029047366429/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=320236029047366429' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/320236029047366429'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/320236029047366429'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/09/safecentral-updated.html' title='SafeCentral Updated!'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-4368530433812175832</id><published>2008-09-02T08:53:00.002-04:00</published><updated>2008-09-02T09:12:54.049-04:00</updated><title type='text'>I'm your Private Browser...</title><content type='html'>Last week Microsoft took the wraps off the latest Beta of &lt;a href="http://news.cnet.com/8301-1009_3-10025111-83.html"&gt;Internet Explorer 8&lt;/a&gt;; and just yesterday Google announced its own browser, currently named &lt;a href="http://www.appleinsider.com/articles/08/09/01/google_planning_new_chrome_browser_based_on_webkit.html"&gt;"Chrome"&lt;/a&gt;.  Both of these browsers include a feature already found in &lt;a href="http://en.wikipedia.org/wiki/Safari_%28web_browser%29"&gt;Apple's Safari&lt;/a&gt; by default and available via a variety of add-ons for &lt;a href="http://en.wikipedia.org/wiki/Firefox"&gt;Mozilla FireFox&lt;/a&gt; - "Private Browsing".&lt;br /&gt;&lt;br /&gt;&lt;a href="http://lifehacker.com/software/mac-os-x/safaris-private-porn-browsing-mode-102146.php"&gt;Private Browsing&lt;/a&gt;, often referred to as &lt;a href="http://lifehacker.com/software/mac-os-x/safaris-private-porn-browsing-mode-102146.php"&gt;'porn mode'&lt;/a&gt;, covers the tracks of the user by not saving or instantly deleting browser history, searches, cache, cookies and more.  Essentially, these features ensure that whomever uses your PC/Mac next won't be able to see what you were up to online.  This is great functionality and a worthwhile addition to all modern browsers.&lt;br /&gt;&lt;br /&gt;However, the name "private browsing" could certainly mislead users into thinking that it provides security against spyware, hackers and identity thieves; which is sadly not the case.  This feature does not prevent a keylogger from capturing every keystroke, including the URL's you type, usernames, passwords and more.  Nor does it prevent a screen-scraping agent from snapping an image of every click and every page you visit.  It also provides no protection from man-in-the-middle spying or DNS-poisoning.  In short, "private browsing" isn't really private.  Sure, it'll keep your spouse from discovering that you were researching a surprise trip, but it won't protect your money, your accounts, or your identity.  I've already been asked by 3 relatively computer-literate friends if the "private browsing" mode in Safari means they're safe.&lt;br /&gt;&lt;br /&gt;It's becoming increasingly clear that modern browsers need to be fortified against a variety of attacks, and users have recognized that the browser, the web, and email are simultaneously the most important parts of their PC use, and the most dangerous.  I sincerely hope that user's aren't lulled into a false sense of security thanks to these new features.   Whether you opt to use &lt;a href="http://www.safecentral.com"&gt;SafeCentral&lt;/a&gt;, or something else, be sure your gaining REAL privacy when you go online.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-4368530433812175832?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://news.cnet.com/8301-1009_3-10025111-83.html' title='I&apos;m your Private Browser...'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/4368530433812175832/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=4368530433812175832' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/4368530433812175832'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/4368530433812175832'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/09/im-your-private-browser.html' title='I&apos;m your Private Browser...'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-149873346022969003</id><published>2008-08-08T08:51:00.002-04:00</published><updated>2008-08-08T09:05:58.067-04:00</updated><title type='text'>SafeCentral Protects Users from Massive DNS Flaw</title><content type='html'>In the old days when you made a phone call, your request was routed to an operator who correlated the person  you wanted to reach against the circuit they were on, and physically connected the cables to enable your conversation.  Despite the wonders of the internet, things still work pretty much the same way.  When you make a request to visit "www.paypal.com", that request is interpreted and translated by a DNS (Domain Name Server) that matches "www.paypal.com" with the IP address of the web server before sending you on your way. &lt;br /&gt;&lt;br /&gt;One common method for hackers to steal identities, money, and more is to 'poison'  or hijack DNS servers and DNS requests, and to have your traffic re-routed to sites that look like the real thing, but exists solely to steal your account credentials.  So, when you type "www.paypal.com" into your browser, it's possible that a bad-guy could intercept that request and send you to his web server, which offers up a page that looks IDENTICAL to the real PayPal site.  After capturing your login credentials, these hackers are usually kind enough to forward you on to the real site, so you never know the difference - UNTIL YOUR MONEY IS GONE.&lt;br /&gt;&lt;br /&gt;In a presentation at the &lt;a href="http://www.blackhat.com/html/webinars/kaminsky-DNS.html"&gt;Black Hat&lt;/a&gt; security conference, Dan Kaminsky highlighted a massive flaw he'd discovered which affects millions of DNS servers across the internet.  This flaw makes these servers vulnerable to these hacker attacks, and puts every web user at risk.  Preventing DNS attacks was part of the central premise of the &lt;a href="http://www.safecentral.com"&gt;SafeCentral&lt;/a&gt; solution, and we're happy to report that our SecureDNS technology (built into SafeCentral) provides an effective defense against these attacks.  Read the &lt;a href="http://www.marketwatch.com/news/story/authentiums-safecentral-protects-users-massive/story.aspx?guid=%7B88C161B6-30C4-4370-8890-E0CDB6B70F62%7D&amp;amp;dist=hppr"&gt;press release&lt;/a&gt; for more detail, and visit &lt;a href="http://www.doxpara.com/"&gt;Dan Kaminsky's blog&lt;/a&gt; for full details and to test if your DNS connections are open to this kind of attack.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-149873346022969003?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.marketwatch.com/news/story/authentiums-safecentral-protects-users-massive/story.aspx?guid=%7B88C161B6-30C4-4370-8890-E0CDB6B70F62%7D&amp;dist=hppr' title='SafeCentral Protects Users from Massive DNS Flaw'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/149873346022969003/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=149873346022969003' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/149873346022969003'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/149873346022969003'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/08/safecentral-protects-users-from-massive.html' title='SafeCentral Protects Users from Massive DNS Flaw'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-3070633462021022905</id><published>2008-07-30T13:27:00.002-04:00</published><updated>2008-07-30T13:37:19.794-04:00</updated><title type='text'>Online Threats come faster</title><content type='html'>More evidence that a new approach to security is required if user's hope to stave off the threats caused by conventional browsers and PC vulnerabilities... &lt;br /&gt;&lt;br /&gt;While the security community has a responsibility to act as a watchdog and report the vulnerabilities that are discovered, these alerts are increasingly becoming a hand-book for even amateur hackers. &lt;br /&gt;&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;...online criminals have latched on in a big way to programs that help them automatically generate attacks based on publicly available information about vulnerabilities. In the past they apparently spent more time finding such holes themselves, but no longer find that as necessary.&lt;br /&gt;&lt;br /&gt;In Web browsers — an area heavily targeted by hackers — hacking exploits were available within a day after flaws were discovered 94 percent of the time, up from 79 percent in 2007, IBM's report said.&lt;br /&gt;&lt;br /&gt;For all PC vulnerabilities, over 80 percent of the exploit code was released the same day — or even before — the holes were publicly disclosed. That's up from 70 percent last year, according to the IBM study.&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;It would seem to me that a more private, well-vetted consortium of experts/companies should form a closed reporting system that prevents exploits (as much as possible) from becoming public until after they are addressed.  It'll never fully stop the publication of "proof of concept" hacks, but a 'silent whistle' system that is endorsed by all involved could make a dent in the problem.&lt;br /&gt;&lt;br /&gt;More importantly, it's clear that security can't be a 'reactive' system, patching exploits and issuing virus signatures in response to hackers.  Instead, security should be an active solution that 'allows' the good rather than seeking to prevent the bad.  SafeCentral is just one example of this new paradigm in security.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-3070633462021022905?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://news.yahoo.com/s/ap/20080729/ap_on_hi_te/tec_internet_threats' title='Online Threats come faster'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/3070633462021022905/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=3070633462021022905' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/3070633462021022905'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/3070633462021022905'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/07/online-threats-come-faster.html' title='Online Threats come faster'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-5411341977503474237</id><published>2008-07-25T12:13:00.002-04:00</published><updated>2008-07-25T12:27:13.519-04:00</updated><title type='text'>Firstrade Partnership Launches.</title><content type='html'>The entire SafeCentral team is thrilled to have announced the formal launch of our partnership with &lt;a href="http://www.firstrade.com"&gt;Firstrade&lt;/a&gt; this week.  Firstrade is providing SafeCentral access to Firstrade accounts free of charge, granting their customers the most secure trading environment available in the world.  We are proud to partner with Firstrade's consistently top-rated online brokerage, and to work with them to make trading even safer.&lt;br /&gt;&lt;br /&gt;This is significant when you consider the unique risks posed by account compromise in the trading markets.  After all, the exposure of your credit card or bank account information typically impacts just you, while the compromise of trading credentials can lead to stock price manipulation that could affect millions, and the very fabric of the market.  An &lt;a href="http://www.computerworld.com/action/article.do?command=printArticleBasic&amp;articleId=9004416"&gt;example&lt;/a&gt; of this occurred recently, with the &lt;a href="http://www.computerworld.com/action/article.do?command=printArticleBasic&amp;articleId=9004416"&gt;'pump and dump' scheme&lt;/a&gt; executed using stolen credentials from two other trading firms.  The resulting $22 Million in losses could have been prevented if users had been using secure browsing tools like SafeCentral.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-5411341977503474237?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.businesswire.com/portal/site/google/?ndmViewId=news_view&amp;newsId=20080723005810&amp;newsLang=en' title='Firstrade Partnership Launches.'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/5411341977503474237/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=5411341977503474237' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/5411341977503474237'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/5411341977503474237'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/07/firstrade-partnership-launches.html' title='Firstrade Partnership Launches.'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-7846665777153860979</id><published>2008-07-23T08:45:00.003-04:00</published><updated>2008-07-23T09:01:28.326-04:00</updated><title type='text'>PCMag.com Reviews SafeCentral</title><content type='html'>In my line of work, you grow accustomed to product reviews and opinions that either praise or punish the monumental efforts of the company.  Most reviews are fair, and most are conducted with integrity and impartiality.  However, nothing is more rewarding or satisfying than a review or opinion piece that begins by understanding and validating the fundamental purpose of a product or service &lt;span style="font-weight:bold;"&gt;correctly&lt;/span&gt;.  Such is &lt;a href="http://www.pcmag.com/article2/0,2817,2326037,00.asp"&gt;this review&lt;/a&gt; from PC Mag.com's  &lt;a href="http://www.pcmag.com/author_bio/0,1908,a%253D184,00.asp"&gt;Neil J. Rubenking&lt;/a&gt;; which truly 'gets it' with regard to SafeCentral's &lt;span style="font-style:italic;"&gt;raison de etre&lt;/span&gt;.  &lt;br /&gt;&lt;br /&gt;We're already working on a few of the small requests noted in this review (Password Manager coming soon!), while the rest of Neil's analysis captures and validates SafeCentral's revolutionary security promise superbly.  Please give it a read and share your comments.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-7846665777153860979?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.pcmag.com/article2/0,2817,2326037,00.asp' title='PCMag.com Reviews SafeCentral'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/7846665777153860979/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=7846665777153860979' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/7846665777153860979'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/7846665777153860979'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/07/pcmagcom-reviews-safecentral.html' title='PCMag.com Reviews SafeCentral'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-7653679331166828884</id><published>2008-07-07T15:16:00.003-04:00</published><updated>2008-07-07T15:19:29.725-04:00</updated><title type='text'>Take the Guided Tour!</title><content type='html'>I've posted a 5-part "Guided Tour" on the release version of SafeCentral.  This is the most complete and compelling look at the entire service, and should help even SafeCentral veterans understand the service a little better.&lt;br /&gt;&lt;a href="http://www.safecentral.com/howitworks/Guided_Tour.html"&gt;&lt;br /&gt;http://www.safecentral.com/howitworks/Guided_Tour.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Your feedback and comments are appreciated.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-7653679331166828884?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.safecentral.com/howitworks/Guided_Tour.html' title='Take the Guided Tour!'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/7653679331166828884/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=7653679331166828884' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/7653679331166828884'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/7653679331166828884'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/07/take-guided-tour.html' title='Take the Guided Tour!'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-5557350760742946609</id><published>2008-06-25T09:55:00.003-04:00</published><updated>2008-06-27T12:16:49.682-04:00</updated><title type='text'>The Road to Safety</title><content type='html'>One of the biggest challenges with any security product is trying to find the proper balance between security and usability.   The two goals often seem at odds with one-another; after all, for each thing you make possible, you may open a door for exploitation.  We made it a priority at the beginning of the SafeCentral project NOT to sacrifice the security of our solution, so we've been tirelessly seeking ways to provide a seamless experience without softening the security promise.   The suspend/resume functionality I previewed earlier (now in the live build), is an example of that.  We provided the ability for SafeCentral to seamlessly co-exist with your other applications/activities, without inviting the weaknesses of those applications into our safe environment.&lt;br /&gt;&lt;br /&gt;We've achieved similar success with a new browser plug-in feature, that actually INCREASES the security of our product by offering configurable alerts to the user when the site they're trying to visit might warrant the extra safety of SafeCentral.  The same framework can be used to prevent phishing, by filtering URL's against known phishing sites.  The great thing about this function is that it doesn't alter or weaken the security of the SafeCentral environment in exchange for simplicity, but provides the user with a completely seamless experience that makes SafeCentral a part of their normal workflow.  I like to think of SafeCentral as &lt;span style="font-weight: bold; font-style: italic;"&gt;the secure companion to your everyday browsing&lt;/span&gt;, and nothing makes that companion easier to access than this plugin feature.&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/Nyj3LD1_3Jc&amp;hl=en"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/Nyj3LD1_3Jc&amp;hl=en" type="application/x-shockwave-flash" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;As a self-described technology geek, I'm often asked by friends, neighbors and relatives for advice on what electronics to buy.  One of the most common requests is which camera to get.  I've read the reviews, tested various units, and formed plenty of opinions about the features that I think matter most.  However, I often recommend a camera with lower resolution, fewer features, and other sacrifices.  Why?  Because "the worst picture you can take is the one you never take".  Which is my way of saying that features and image quality are great, but if you don't have your camera with you because you can't stand lugging it around, all of those features aren't going to matter.  So, get the small one that fits in your pocket.  The same principle applies to security software design; &lt;span style="font-weight:bold;"&gt;the only security that matters is the security that you use.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;So, we've gone to great lengths to provide many 'on-ramps' to the SafeCentral experience: the Programs menu, desktop icons, the taskbar, your normal browser and more all can invoke a SafeCentral session.   As a user, that means you'll have the option to enter the safe environment whenever the whim, need, or  opportunity arises, without having to remind or retrain yourself to do it.  That, more than anything, is the most powerful form of security: security you'll use.&lt;br /&gt;The attached video previews the plugin function; I welcome comments and look forward to its release in our July build.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-5557350760742946609?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/5557350760742946609/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=5557350760742946609' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/5557350760742946609'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/5557350760742946609'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/06/road-to-safety.html' title='The Road to Safety'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-2666413445091078477</id><published>2008-06-10T22:53:00.005-04:00</published><updated>2008-06-10T23:18:01.874-04:00</updated><title type='text'>Testing Confirms SafeCentral Security</title><content type='html'>Sometimes you can get so caught up in the work to build, prepare and launch a product into market, that you forget to stop and measure it against your original vision.  Does it solve the problem you intended to solve?  After all, the rest is just presentation and packaging; if you don't meet the benefit statement you've promised your customer, you've already failed.&lt;br /&gt;&lt;br /&gt;With that in mind, we commissioned IRM's world-renowned security testing team to evaluate SafeCentral.  We were ecstatic to see that SafeCentral met or exceeded every claim, and indeed is 'certified' to provide true privacy when transacting online.  We've outlined the results in a &lt;a href="http://www.redorbit.com/news/technology/1425695/information_risk_management_validates_safecentrals_online_identity_theft_protection/index.html?source=r_technology"&gt;Press Release&lt;/a&gt; this morning, but I wanted to take a moment here to elaborate on the report.&lt;br /&gt;&lt;br /&gt;There are 3 points of peril when it comes to sharing sensitive information online.  First, and most importantly, is the user's PC.  A compromised system infested with spyware agents is an identity thief's greatest ally.   Second, is the connection to the site, you can't transact safely unless you know who you're transacting with (and know with certainty that it IS the site you intend).  And finally, is the authentication of user and site to one-another.  With multi-factor authentication, websites have done a pretty good job guarding up #3, but items 1 and 2 have been left open for far too long.  SafeCentral was built to sure up these holes.&lt;br /&gt;&lt;br /&gt;According to the IRM Report:&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;In all scenarios, it was observed that SafeCentral adequately protected a user's browsing session by &lt;span style="font-weight: bold;"&gt;ensuring no keystrokes entered in the secure Firefox web browser were intercepted. &lt;/span&gt;Viewing logs from various keyloggers clearly indicated that keystrokes entered in the duration SafeCentral was active were clearly missing. This was true for both user and kernel land keyloggers. &lt;/blockquote&gt;SafeCentral was built to cripple desktop spyware agents, like screen-scrapers and key-loggers, even if they're successfully installed and functional on the user's PC.  Every one of the more than 20 spyware agents thrown at SafeCentral was unable to capture the activities during the SafeCentral session.   And on item #2:&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;The first test involved editing the virtual machine's "host" file to contain static entries that would redirect requests for websites supported by SafeCentral to test websites setup by IRM consultants. However, when SafeCentral was launched, &lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;the user&lt;/span&gt;&lt;span style="font-style: italic;"&gt; was not redirected to the static entries and &lt;/span&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;was presented with genuine websites.&lt;/span&gt;&lt;/blockquote&gt;&lt;br /&gt;SafeCentral identifies the websites your visiting against our known directory of safe sites, and ensures that you can't be re-directed to phishing/pharming sites meant to steal your credentials.&lt;br /&gt;&lt;br /&gt;Again, while I'm happy to pat ourselves on the back, the important thing here is that we tested ourselves to ensure that we live up to our security claims, and our promise to our customers.  There is too much false information and 'snake oil' already in the identity theft sphere, we need bring real solutions to market.&lt;br /&gt;&lt;br /&gt;So, now we'll go back to putting the best possible presentation, polish, and packaging on SafeCentral.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-2666413445091078477?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.redorbit.com/news/technology/1425695/information_risk_management_validates_safecentrals_online_identity_theft_protection/index.html?source=r_technology' title='Testing Confirms SafeCentral Security'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/2666413445091078477/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=2666413445091078477' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/2666413445091078477'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/2666413445091078477'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/06/testing-confirms-safecentral-security.html' title='Testing Confirms SafeCentral Security'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-5614169461627877997</id><published>2008-06-05T15:50:00.004-04:00</published><updated>2008-06-05T15:56:37.862-04:00</updated><title type='text'>ID Fraud on the rise</title><content type='html'>According to leading industry analyst Avivah Litan, and a recent study by Carnegie Mellon sited in &lt;a href="http://www.pcworld.com/businesscenter/article/146738/researchers_say_notification_laws_not_lowering_id_theft.html"&gt;this PC World article&lt;/a&gt;, Identity Fraud has been on the rise over the last year and a half and is projected to maintain a meteoric rise.&lt;br /&gt;&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;&lt;p&gt;Gartner's Litan offered one more observation that might explain Carnegie Mellon's findings: The fraudsters are also getting better at what they do, she added. "If you talk to the largest banks, they will tell you that fraud has really increased in the past 18 months," she said. "And they project it going up very significantly in the next two years."&lt;/p&gt;&lt;p&gt;"The thieves are just getting better and there's more fraud," she said.&lt;/p&gt;&lt;/blockquote&gt;It appears that despite the recent focus on new authentication systems, and stronger data warehouses, the hackers are adjusting their tactics to take advantage of holes in the security chain.  As discussed here many times before, the weakest link is likely:  You, and your malware infested PC.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-5614169461627877997?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/5614169461627877997/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=5614169461627877997' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/5614169461627877997'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/5614169461627877997'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/06/id-fraud-on-rise.html' title='ID Fraud on the rise'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-1238326156824407873</id><published>2008-05-21T14:08:00.006-04:00</published><updated>2008-05-21T15:17:12.692-04:00</updated><title type='text'>ID Theft in the news...</title><content type='html'>Infoworld &lt;a href="http://news.yahoo.com/s/infoworld/20080521/tc_infoworld/101445"&gt;took a look&lt;/a&gt; at Check Point Software's &lt;a href="http://news.yahoo.com/s/infoworld/20080521/tc_infoworld/101445"&gt;ZoneAlarm Forcefield&lt;/a&gt;, and ultimately walked away unimpressed. &lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;Unfortunately, although ForceField does offer some real improvements over the other products I've reviewed, it wasn't enough to stop malware from infecting my test systems. In less than a minute, by clicking only my third malicious Web site link, my test system was silently compromised without so much as a chirp out of ForceField.&lt;/blockquote&gt;&lt;blockquote&gt;&lt;/blockquote&gt;The writer admits to being skeptical about 'sandbox' security clients,&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;I've reviewed similar over-marketed and under-effective virtualized or "sandbox" security clients over the years (most notably GreenBorder, subsequently acquired by Google), all of which promised to provide superior protection against all malicious Internet threats. &lt;/span&gt;&lt;/blockquote&gt;Ultimately, our outlook is that previously proposed solutions fall short thanks to limited security features beyond 'site classification' (prompting the user that a site is safe or 'risky' based on white-list/black-list rules and inaccurate logic) and rudimentary key-logger defenses.  No solution to date has offered network level protection, or a secure DNS/Directory to ensure that the user is going &lt;span style="font-weight: bold; font-style: italic;"&gt;only&lt;/span&gt; to safe sites.  No solution to date offered kernel-level security and the ability to defend itself from attack.  &lt;a href="http://www.safecentral.com"&gt;SafeCentral&lt;/a&gt; is a different kind of sandbox.  I hope we have a chance to get this reviewer and others to take a look at SafeCentral. &lt;br /&gt;&lt;br /&gt;In other news, LifeLock is facing a new &lt;a href="http://www.wvgazette.com/News/200805172662"&gt;class-action lawsuit&lt;/a&gt; claiming that it has made false and misleading claims about the level of 'protection' it provides.&lt;br /&gt;&lt;br /&gt;&lt;blockquote style="font-style: italic;"&gt;"While LifeLock has only publicly acknowledged that Davis' identity was compromised on one occasion, there are more than 20 driver's licenses that have been fraudulently obtained [using his personal information]," the suit states.&lt;br /&gt;&lt;br /&gt;"Furthermore, a simple background check performed using Davis' Social Security number reveals that his entire personal profile has been compromised to the extent that the birth date associated with his Social Security number is Nov. 2, 1940, which would [inaccurately] make Davis 67 years old."&lt;/blockquote&gt;To be honest, I'm not sure this lawsuit has merit.  I don't view the claims of LifeLock and the myriad of other 'identity insurers' to be PREVENTATIVE at all.  They claim to help you discover identity fraud quickly, and mitigate the financial losses associated with a breach (though disguising it as protection).   They do nothing to actually STOP identity theft from taking place.  Ultimately, they're like an alarm system - it only goes off only after a crime has begun.  A layered approach is best:  start with good defensive measures to protect your identity from theft, and then layer on monitoring/insurance to buffer against a breach.&lt;br /&gt;&lt;br /&gt;I'm not sure whether these articles help us by raising the 'noise-level' for the need for greater identity security, or hurt us by defining the problem as 'unsolvable' and establishing a poor reputation for companies associated with Identity Theft/Fraud solutions.  Leave a comment and let me know your take.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-1238326156824407873?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/1238326156824407873/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=1238326156824407873' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/1238326156824407873'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/1238326156824407873'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/05/id-theft-in-news.html' title='ID Theft in the news...'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-5525332033485552008</id><published>2008-05-13T16:56:00.002-04:00</published><updated>2008-05-13T17:07:05.977-04:00</updated><title type='text'>Pain in the aaS?</title><content type='html'>I was forwarded &lt;a href="http://www.economist.com/business/displaystory.cfm?story_id=11090522"&gt;this article&lt;/a&gt;  from the Economist which outlines the new "as-a-service" model now being adapted by cyber criminals.  The article makes an excellent point about the continuing migration of software from boxed discs to online services that we 'rent' or use as necessary, and points out the inevitable migration of that model to include malware.  Want to conduct a denial-of-service attack on a website without having to build your own army of zombie PC's, or even having any hacking skills at all?  You can.  Just rent the access from an established cyber-criminal and you can 'borrow' their hack for your personal mission of destruction. &lt;br /&gt;&lt;br /&gt;The tone of the article suggests that "as-a-service" is becoming a dirty word, which may be true.  However, I think the term is accurate and that the model actually provides an opportunity for greater security.  After all, with services living 'in the cloud' you're less prone to local attacks, and the effects are less likely to impact other applications.  What's required is secure access to those 'in the cloud' services, so that each session becomes a trip into a secure portal isolated from everything else...I might know &lt;a href="http://www.safecentral.com"&gt;something&lt;/a&gt; that's a possible solution for that.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-5525332033485552008?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.economist.com/business/displaystory.cfm?story_id=11090522' title='Pain in the aaS?'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/5525332033485552008/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=5525332033485552008' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/5525332033485552008'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/5525332033485552008'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/05/pain-in-aas.html' title='Pain in the aaS?'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-5102519975519189445</id><published>2008-05-12T17:21:00.003-04:00</published><updated>2008-05-12T17:38:15.438-04:00</updated><title type='text'>FBI Internet Crime Complaint Center (IC3) Report</title><content type='html'>I was reviewing the latest report from the &lt;a href="http://www.ic3.gov/media/annualreport/2007_IC3Report.pdf"&gt;FBI on internet crime&lt;/a&gt;, and found that the disturbing trend of skyrocketing losses continues, despite the number of claims holding relatively steady from it's peak in 2005.  This confirms that the cyber-thieves are refining their tactics to focus on extracting more money from every breach or scam.  The report includes all types of cyber-crime, but only tallies those that are reported to the IC3, so it's safe to presume that the actual numbers are much higher.&lt;br /&gt;&lt;br /&gt;The report calculates that the 206,884 claims received via the IC3 website in 2007 resulted in more than $239 Million in losses.  While only a small portion of the cases were specifically cited as 'Identity Theft', all were related to conducting business via criminal websites, email, or auctions.  This reinforces the notion that email is a broken system, and that people really do fall for the "Nigerian Letter" scam (1.1% of complaints!).  It also demonstrates that the general trust of the internet, websites, and email infrastructure is going to continue to decline, as users discover that there is really no way of knowing the origin of a message, or that they can be sure to visit the website they intend.&lt;br /&gt;&lt;br /&gt;Perhaps most disappointing, as a current Florida resident, is the state's #2 position among the top homes for perpetrators.  Thankfully I work for a security firm and my home Wi-Fi network is secured (as best as possible); you never know who the internet criminals are.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-5102519975519189445?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.ic3.gov/media/annualreport/2007_IC3Report.pdf' title='FBI Internet Crime Complaint Center (IC3) Report'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/5102519975519189445/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=5102519975519189445' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/5102519975519189445'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/5102519975519189445'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/05/fbi-internet-crime-complaint-center-ic3.html' title='FBI Internet Crime Complaint Center (IC3) Report'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-7617047474754579959</id><published>2008-05-08T14:05:00.005-04:00</published><updated>2008-05-08T20:24:15.106-04:00</updated><title type='text'>SafeCentral Video Introduction</title><content type='html'>Just finished a brief SafeCentral introduction video, you can see it &lt;a href="http://www.safecentral.com/Flash/Introducing_SafeCentral.htm"&gt;here&lt;/a&gt;.&lt;div&gt;&lt;br /&gt;&lt;object width="425" height="355"&gt;&lt;param name="movie" value="http://www.youtube.com/v/9Nv-nu6C_uI&amp;hl=en"&gt;&lt;/param&gt;&lt;param name="wmode" value="transparent"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/9Nv-nu6C_uI&amp;hl=en" type="application/x-shockwave-flash" wmode="transparent" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I learned something in making these snippets: trust your instincts.  I wanted 3 segments outlining (1) the threats people face when transacting online, (2) the solution SafeCentral provides, and (3) a brief overview of the user experience; I also wanted each segment to be no longer than 1.5 minutes.  Trying to fit a complex technical discussion, demonstration, and value proposition into that timeframe forces you to plan a tight script.  However, when I actually sat down to record the sessions (which are live screen-captures, not over-dubs), I realized that winging it was a better and more natural way to go.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-7617047474754579959?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.safecentral.com/Flash/Introducing_SafeCentral.htm' title='SafeCentral Video Introduction'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/7617047474754579959/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=7617047474754579959' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/7617047474754579959'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/7617047474754579959'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/05/safecentral-video-introduction.html' title='SafeCentral Video Introduction'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-8654945994640078843</id><published>2008-05-02T14:16:00.003-04:00</published><updated>2008-05-02T14:53:18.413-04:00</updated><title type='text'>30 Years of SPAM</title><content type='html'>30 Years ago the world got its first taste of SPAM (not the meat product), though the small distribution to 400 recipients is hardly comparable to the BILLIONS of bogus messages sent today.  I've often wrestled with the fundamental question of SPAM:  "&lt;span style="font-style: italic;"&gt;Are there people out there that actually respond to this stuff?&lt;/span&gt;", and I always come the same conclusion: "&lt;span style="font-style: italic;"&gt;There must be, otherwise why would anyone do it?&lt;/span&gt;".&lt;br /&gt;&lt;br /&gt;That depressing fact keeps the SPAM growing.  However, I think the most profound and unfortunate effect of SPAM is NOT in the people who get scammed, the deluge of bogus mail filling up servers, nor the burden of trash traffic clogging the web.  &lt;span style="font-weight: bold;"&gt;The most profound effect of SPAM is that it broke email. &lt;/span&gt; What should be an incredibly efficient, inexpensive and trustworthy tool for communication has been irreparably damaged.  As a marketer, I'd love to be able to get a message to my audience via email, but there's virtually no way it will be heard among the noise.  More importantly, as a security provider, I often NEED to get a message to my customers that addresses a critical security issue, and yet again the message will be lost in an inbox full of phony Viagra offers. &lt;br /&gt;&lt;br /&gt;When you need to get a message to a large audience of people, it's nearly impossible to do it in a cost-effective and timely manner.  Print/mail is expensive and slow, telephone calls are equally laborious, and traditional 'advertising' mediums don't allow you to target just your existing customers with an important message. &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;SPAMMERS have been crying wolf into the email village, and have guaranteed that no one will listen when real danger arises.  &lt;/span&gt;That is the most unfortunate cost of SPAM.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-8654945994640078843?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.news.com.au/technology/story/0,25642,23629365-5014239,00.html' title='30 Years of SPAM'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/8654945994640078843/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=8654945994640078843' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/8654945994640078843'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/8654945994640078843'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/05/30-years-of-spam.html' title='30 Years of SPAM'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-3370688218882523432</id><published>2008-04-29T17:51:00.002-04:00</published><updated>2008-04-29T18:14:19.669-04:00</updated><title type='text'>Finovate 08</title><content type='html'>Our CTO, Ray Dickenson, was kind enough to send me a live update on today's proceedings at FinovateStartup '08 in San Francisco.  Ray and Doug Brunt, our President &amp;amp; CEO, took the stage at 8:00AM to show off SafeCentral.  It's really our first public unveiling, so what better than to be first out of the starting gate. &lt;br /&gt;&lt;br /&gt;Ray said:&lt;br /&gt;&lt;br /&gt;&lt;blockquote style="font-style: italic; color: rgb(51, 51, 51);"&gt;"The software performed well during our demo and Doug did an excellent job as the spokesmodel for SafeCentral.&lt;br /&gt;&lt;br /&gt;Authentium was randomly picked to present first thing in the morning.  Any concerns I had that the audience would arrive late and not be alert and tuned in for an early start were dismissed when I peered through the curtains before we went on stage and saw about 260 faces alert and ready to see new stuff.&lt;br /&gt;&lt;br /&gt;Doug and I performed our patented 5-minute demo that showed me logging into Paypal and getting my credentials and account details stolen.  Then we launched SafeCentral.  I used the absolute latest build that launches the secure desktop and browser in about 3 seconds.  In SafeCentral, I logged in to my Bank of America account, sharing my wife's sitekey with the world.  Closing SafeCentral, we showed the blank keylogger screen that is familiar to all of you.&lt;br /&gt;&lt;br /&gt;As I mentioned, we are now sitting in the audience watching all the other presentations.  In about 15 minutes we adjourn to the hallway where 20 display screens are set up for each presenter to run additional one-on-one demos for attendees.&lt;br /&gt;&lt;br /&gt;There's the realtime update for you.  More later.&lt;br /&gt;&lt;br /&gt;Ray"&lt;/blockquote&gt;It can be a daunting challenge to attempt to showcase a solution to a problem as complex and multi-faceted as online identity theft in just 5 minutes, but I know Ray and Doug were up to the challenge.&lt;br /&gt;&lt;br /&gt;Coverage and Blogs are just starting to come in, including &lt;a href="http://clanglois.blogs.com/internet_banking/2008/04/banking-20----2.html"&gt;this post&lt;/a&gt; from Christophe Langlois.  Christophe is one of the most active and respected bloggers in the world of online banking, social media and associated technologies, and there's a wealth of great content over at &lt;a href="http://www.clanglois.blogs.com/internet_banking"&gt;visible-banking.com.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-3370688218882523432?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/3370688218882523432/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=3370688218882523432' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/3370688218882523432'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/3370688218882523432'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/04/finovate-08.html' title='Finovate 08'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-2122422558641430237</id><published>2008-04-28T16:09:00.006-04:00</published><updated>2008-04-28T16:49:43.561-04:00</updated><title type='text'>7 surefire ways to become an ID theft victim</title><content type='html'>Rarely do you see highly technical computer security articles address the problem in witty, easy to understand terms.  I was happy to discover &lt;a href="http://www.bankrate.com/brm/news/financial_literacy/identity_theft/how_to_be_an_identity_theft_victim_a1.asp?caret=93d"&gt;this post&lt;/a&gt; from the &lt;a href="http://www.bankrate.com/"&gt;Bankrate.com&lt;/a&gt; 'News &amp;amp; Advice' section (single-page available &lt;a href="http://biz.yahoo.com/brn/080421/25133.html?.v=1"&gt;here&lt;/a&gt;).   Sheyna Steiner takes on the topic of Identity Theft with a pragmatic, intelligent, and somewhat comical 'in your face' look at the perils we all willingly expose ourselves to when online.  It's a great read, and there's a lot of simple yet informative tips for staying safe.&lt;br /&gt;&lt;blockquote style="color: rgb(51, 51, 51); font-style: italic;"&gt;"Experience the hassles of being defrauded firsthand! If you love bureaucracy and the thrill of waiting in line to talk to government and bank employees again and again, becoming an identity theft victim might be right for you."&lt;/blockquote&gt;&lt;span&gt;Sign me up!  I wish every day could be a trip to the DMV.&lt;/span&gt;&lt;br /&gt;&lt;blockquote style="color: rgb(51, 51, 51); font-style: italic;"&gt;"For maximum risk, commit the computing equivalent of licking a handrail in a New York City subway station and do some online banking on a public computer -- like the one at the library or a public cafe. Bonus points are added if your Social Security number is your user ID for any transactions."&lt;/blockquote&gt;&lt;span&gt;Who hasn't licked the NYC subway station handrail?  I thought that's what they meant by the 'flavor of the city'?&lt;/span&gt;&lt;br /&gt;&lt;blockquote style="color: rgb(51, 51, 51); font-style: italic;"&gt;"Secret crushes, long lost friends saying "what's up" or strangers hawking cheap drugs -- you'll never know unless you peek at that e-mail."&lt;/blockquote&gt;&lt;span&gt;Thus shattering my fantasy that I had attracted 43 secret admirers today.&lt;/span&gt;&lt;br /&gt;&lt;blockquote style="color: rgb(51, 51, 51); font-style: italic;"&gt;"These days one has to assume that any communication with a business or government entity that hasn't been specifically initiated by the consumer with the appropriate authentication process is a complete swindle."&lt;/blockquote&gt;&lt;span&gt;Unfortunate and true.&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Tip of the hat to Sheyna and the Bankrate team for this excellent article&lt;span style="font-style: italic;"&gt;.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-2122422558641430237?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.bankrate.com/brm/news/financial_literacy/identity_theft/how_to_be_an_identity_theft_victim_a1.asp?caret=93d' title='7 surefire ways to become an ID theft victim'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/2122422558641430237/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=2122422558641430237' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/2122422558641430237'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/2122422558641430237'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/04/7-surefire-ways-to-become-id-theft.html' title='7 surefire ways to become an ID theft victim'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-3579045296293738675</id><published>2008-04-25T16:08:00.007-04:00</published><updated>2008-04-25T17:38:33.591-04:00</updated><title type='text'>Preview of Upcoming SafeCentral Features</title><content type='html'>The developers have really been cranking out some great work lately, pushing things forward in the areas we get the most feedback on.  Two things at the top of the priority list will be addressed in an upcoming release:&lt;br /&gt;&lt;ul style="font-weight: bold; font-style: italic;"&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Faster Launching&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:100%;"&gt;Simple suspend/resume and integration into standard Windows environment.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;Have a peek at this video for a brief look at these enhancements.﻿﻿﻿﻿﻿﻿﻿﻿&lt;br /&gt;&lt;span style="font-size:85%;"&gt;(Looks like YouTube 'chewed' the beginning of the video a bit, but it comes in fine after a moment - apologies)&lt;/span&gt;&lt;br /&gt;&lt;object height="350" width="425"&gt; &lt;param name="movie" value="http://www.youtube.com/v/nj375JgQjYE"&gt;  &lt;embed src="http://www.youtube.com/v/nj375JgQjYE" type="application/x-shockwave-flash" height="350" width="425"&gt;&lt;/embed&gt;  &lt;/object&gt;&lt;br /&gt;&lt;br /&gt;I'm sometimes blown away but what the coders can do in astonishingly short periods of time.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-3579045296293738675?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/3579045296293738675/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=3579045296293738675' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/3579045296293738675'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/3579045296293738675'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/04/preview-of-upcoming-safecentral.html' title='Preview of Upcoming SafeCentral Features'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-1047950744827267844</id><published>2008-04-23T17:13:00.002-04:00</published><updated>2008-04-23T17:26:33.391-04:00</updated><title type='text'>Bitten when browsing</title><content type='html'>Yesterday's &lt;a href="http://blogs.wsj.com/biztech/2008/04/22/hackers-shift-from-email-to-website-attacks/?mod=WSJBlog"&gt;technology blog post at the WallStreetJournal.com&lt;/a&gt; is a prime example of how hackers stay ahead of conventional security measures.  In the article, Ben Worthen, notes that hackers have migrated their focus from traditional email-based proliferation to more sophisticated and 'silent' means of malware distribution.  Just visiting a website can lead to a security breach, as hackers exploit the weaknesses of your web browser and install their nefarious agents on your machine.&lt;br /&gt;&lt;br /&gt;This only strengthens our belief that a new paradigm, which breaks away from the reliance on the traditional 'dirty' browser, is required to achieve any semblance of real safety online.&lt;br /&gt;&lt;br /&gt;What's most frustrating, as a marketer and someone passionate about our new service, is the summation of Worthen's post - which probably sums up how most people react to news like this:&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;"The bad news is that there isn’t much individuals can do to protect themselves from these attacks besides using the most recent version of a Web browser and hoping that the attacker’s code is designed to take advantage of an older browser."&lt;/blockquote&gt;&lt;br /&gt;Actually, &lt;span style="font-weight: bold;"&gt;there is something individuals can do&lt;/span&gt;.  You guessed it:  &lt;a href="http://www.safecentral.com/"&gt;SafeCentral&lt;/a&gt;.  Since we restrict all untrusted operations, and run our own protected browser, you're vastly more secure when visiting any site from within SafeCentral.  More importantly, you're protected from the bugs, viruses, spyware, and other hacker tidbits you picked up while casually surfing in IE or Firefox; so even if the malware is on your machine, it can't be used to steal your identity when using SafeCentral.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;How do we get the word out that there is an answer?&lt;/span&gt;  Feel free to add a comment with suggestions on better communicating the SafeCentral message.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-1047950744827267844?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://blogs.wsj.com/biztech/2008/04/22/hackers-shift-from-email-to-website-attacks/?mod=WSJBlog' title='Bitten when browsing'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/1047950744827267844/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=1047950744827267844' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/1047950744827267844'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/1047950744827267844'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/04/bitten-when-browsing.html' title='Bitten when browsing'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-9159225144875320520</id><published>2008-04-22T10:29:00.005-04:00</published><updated>2008-04-22T10:53:22.857-04:00</updated><title type='text'>A Key to Everything</title><content type='html'>There's nothing new in the latest &lt;a href="http://news.yahoo.com/s/ap/20080416/ap_on_hi_te/techbit_password_peril"&gt;survey&lt;/a&gt; findings from Accenture; the repeated use of a single password for all online accounts is human nature; who wants to try to remember 17 different username/password combinations in a world as busy and hectic as the high-tech one we live in today?&lt;br /&gt;&lt;br /&gt;Nonetheless, it emphasizes how easy we make it for hackers to gain access to our entire life online.  Every mail account, forum, banking site, shopping site, easily accessed with that one 'golden key' of a password we use repeatedly.  I admit, even as a member of the 'security community', I often repeat my favorite password, or some derivative thereof, on multiple sites.   It's just too hard and time-consuming to come up with 15 passwords I know I'll never remember. &lt;br /&gt;&lt;br /&gt;We're working on methods to aggregate your passwords into a single, manageable, and encrypted tool within the &lt;a href="http://www.safecentral.com"&gt;SafeCentral&lt;/a&gt; experience.   There are several very useful, encrypted 'password managers' or 'digital wallet' systems available, (as a frequent Mac user, I use the aptly named &lt;a href="http://www.waterfallsw.com/wallet/"&gt;Wallet&lt;/a&gt;; or &lt;a href="http://www.roboform.com/"&gt;Roboform&lt;/a&gt; when on my PC) and taking the time to incorporate one into your personal data management routine is a great way to improve your personal security, and still keep critical data at your fingertips.  Still, gaining access to these encrypted databases is usually accomplished with one 'golden password'.   The best protection remains preventing the interception of your password(s) by using a secure, &lt;a href="http://www.safecentral.com"&gt;encrypted browser&lt;/a&gt; whenever you log on to financial services.   All passwords are only as secure as the number of people who know them; we aim to keep that number to just one - YOU - with &lt;a href="http://www.safecentral.com"&gt;SafeCentral&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-9159225144875320520?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://news.yahoo.com/s/ap/20080416/ap_on_hi_te/techbit_password_peril' title='A Key to Everything'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/9159225144875320520/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=9159225144875320520' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/9159225144875320520'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/9159225144875320520'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/04/key-to-everything.html' title='A Key to Everything'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-850855792210512110</id><published>2008-04-21T15:38:00.005-04:00</published><updated>2008-04-21T16:49:07.320-04:00</updated><title type='text'>We need more than a seat belt.</title><content type='html'>&lt;a href="http://www.paypal.com/"&gt;PayPal&lt;/a&gt; made &lt;a href="http://www.nytimes.com/idg/IDG_852573C4006938800025742F0061AAFF.html?ref=technology"&gt;news&lt;/a&gt; at RSA with the publication of a paper that spells out a plan to eventually block older and otherwise "&lt;a href="http://news.bbc.co.uk/2/hi/technology/7354539.stm"&gt;unsafe browsers&lt;/a&gt;" from accessing its services.  Unfortunately, "unsafe browser" could be an apt description of every standard browser currently in use.&lt;br /&gt;&lt;br /&gt;PayPal's plan calls for shutting off access from older versions of Internet Explorer, Firefox (and possibly Apple's Safari, should Apple fail to add the requested features) which don't support the new &lt;a href="http://www.verisign.com/ssl/ssl-information-center/faq/extended-validation-ssl-certificates.html"&gt;Extended Validation SSL&lt;/a&gt; certificate system.  EV SSL certified sites display a green address bar and company name in an attempt to prevent phishing attacks by visually confirming to the user the validity of the site.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_EHhB3f_ny8k/SAz6hDcA60I/AAAAAAAAAAg/g8ORhsoKypU/s1600-h/EVSSL.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_EHhB3f_ny8k/SAz6hDcA60I/AAAAAAAAAAg/g8ORhsoKypU/s320/EVSSL.png" alt="" id="BLOGGER_PHOTO_ID_5191799916216773442" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;It's certainly a better system and a worthwhile addition to the layered security model, but it doesn't solve several underlying issues:&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;The world's been using SSL certification (those little locks at the bottom of your browser), and other tools for years in an effort to keep users from entering their personal data at falsified sites - and it hasn't stopped the problem from expanding.  These visual cues can be spoofed by hackers, and most users simply don't know what they mean, nor pay attention to their existence.&lt;br /&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Even if a user could be certain that they're on the actual PayPal site, there's nothing to prevent spyware and other agents from capturing every detail, password, keystroke and screen from that session.   The hacker then logs on with the stolen credentials, gets the same reassuring green address bar, &lt;span style="font-weight: bold; font-style: italic;"&gt;and cleans out your account&lt;/span&gt;.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;The latest browsers, including Internet Explorer 7, and Firefox beta 3, provide no protection against desktop spyware and other tools for 'listening in'.   As long as desktop agents are allowed to run unchecked, identity theft - and the resulting fraud - will continue to grow unabated.   As long is the industry relies on users to recognize a combination of cues, accept a barrage of alert pop-ups, and navigate the dirty minefield of traditional browsing, the problem will continue to grow.   We need a new paradigm, one that separates 'standard' browsing from activities that require real security.&lt;br /&gt;&lt;br /&gt;I applaud PayPal's effort to raise the security level on their site by locking out "unsafe browsers", but if it's security they seek, perhaps they should consider locking out all standard browsers and requiring &lt;a href="http://www.safecentral.com/"&gt;SafeCentral&lt;/a&gt;, which supports EV SSL while providing &lt;span style="font-weight: bold;"&gt;DNS security and desktop malware defense.  &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;PayPal said that allowing unsafe browsers to access its site &lt;blockquote&gt;"&lt;span style="font-style: italic;"&gt;is equal to a car manufacturer allowing drivers to buy one of their vehicles without seat belts.&lt;/span&gt;"&lt;/blockquote&gt;   True.  However, &lt;a href="http://en.wikipedia.org/wiki/Seat_belt"&gt;seat belts&lt;/a&gt; have been standard in cars since the early 60's; &lt;span style="font-weight: bold; font-style: italic;"&gt;perhaps requiring air-bags, and even accident avoidance systems would be a more appropriate goal in 2008. &lt;/span&gt;  Our goal in developing SafeCentral is to be ahead of the hackers, responding in advance to tomorrow's threats.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-850855792210512110?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/850855792210512110/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=850855792210512110' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/850855792210512110'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/850855792210512110'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/04/paypal-made-news-at-rsa-with.html' title='We need more than a seat belt.'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_EHhB3f_ny8k/SAz6hDcA60I/AAAAAAAAAAg/g8ORhsoKypU/s72-c/EVSSL.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-1538076335428771168</id><published>2008-04-18T14:54:00.004-04:00</published><updated>2008-04-18T16:59:01.607-04:00</updated><title type='text'>An ounce of prevention...</title><content type='html'>The old adage says that "an ounce of prevention is worth a pound of cure"; and nowhere is that more true than in the world of Identity Crime.  I was encouraged to see that Peter Piazza of &lt;a href="http://www.newsfactor.com/story.xhtml?story_id=102009DH8J3I"&gt;NewsFactor&lt;/a&gt; pressed this point in his first look at &lt;a href="http://www.safecentral.com/"&gt;SafeCentral&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;There are two terms used seemingly interchangeably to describe the problem: 'Identity Theft', and 'Identity Fraud', but these terms describe two distinctly different events.  The difference between these events highlights the reason we created &lt;a href="http://www.safecentral.com/"&gt;SafeCentral&lt;/a&gt;, and why it is such an important factor in the defense of your identity and your money.  An ounce of identity &lt;span style="font-style: italic;"&gt;theft&lt;/span&gt; prevention is worth a pound of identity &lt;span style="font-style: italic;"&gt;fraud&lt;/span&gt; cure.&lt;br /&gt;&lt;br /&gt;According to Webster's Dictionary, &lt;a href="http://www.merriam-webster.com/dictionary/theft"&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;theft&lt;/span&gt;&lt;/a&gt; is "&lt;span style="font-style: italic;"&gt;the action or crime of stealing&lt;/span&gt;"; &lt;a href="http://www.merriam-webster.com/dictionary/fraud"&gt; &lt;span style="font-weight: bold; font-style: italic;"&gt;fraud&lt;/span&gt;&lt;/a&gt; is "&lt;span style="font-style: italic;"&gt;wrongful or criminal deception intended to result in financial or personal gain&lt;/span&gt;".   You can't commit identity fraud without first having committed identity theft.  It is therefore paramount to one's personal security to safeguard the data that can lead to identity fraud.  SafeCentral aims to provide just such protection, isolating your online activities from prying eyes and assuring that your usernames, passwords, and personal credentials remain secure.&lt;br /&gt;&lt;br /&gt;The importance of prevention becomes evident when you look at the true cost of a cure.  There are several prominent (worthwhile, I might add) services that can monitor your credit and raise an alarm should someone try to conduct a fraudulent transaction or application in your name.   In addition, many of these services will go the extra mile and insure you against disastrous financial loss. Unfortunately, they cant make the clean-up after an identity breach any easier.  You're still going to spend as long as a year getting all new credit cards, perhaps a new social security number, closing out or migrating at-risk accounts, cleaning your dirtied credit, and realigning all of the payments and pay services that were auto-billing to your various accounts.  In short, &lt;span style="font-weight: bold;"&gt;you're going to pay in sweat and tears what you don't pay in plain cash.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;As with all security, a layered approach is best; but nothing can substitute for a SOLID first line of defense.  In the case of online identity crimes, that means prevention - which means &lt;a href="http://www.safecentral.com/"&gt;SafeCentral&lt;/a&gt;.  Combined with an up-to-date desktop security suite, and adequate credit monitoring or fraud prevention services, &lt;a href="http://www.safecentral.com/"&gt;SafeCentral&lt;/a&gt; can sure up your identity and give you the freedom and confidence to transact online at your leisure, and save you from ever having to fight to recover a stolen identity.&lt;br /&gt;&lt;br /&gt;Peter's &lt;a href="http://http//www.newsfactor.com/story.xhtml?story_id=102009DH8J3I"&gt;article&lt;/a&gt; is one of the first I've read that accurately differentiates the actions of theft and fraud in the internet age.   We at SafeCentral, and the entire team at parent-company Authentium, are excited to be bringing to market the first truly end-to-end identity theft prevention service.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-1538076335428771168?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.newsfactor.com/story.xhtml?story_id=102009DH8J3I' title='An ounce of prevention...'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/1538076335428771168/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=1538076335428771168' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/1538076335428771168'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/1538076335428771168'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/04/ounce-of-prevention.html' title='An ounce of prevention...'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-6064071345363812810</id><published>2008-04-17T17:06:00.003-04:00</published><updated>2008-04-17T17:29:53.211-04:00</updated><title type='text'>Launch Day Recap</title><content type='html'>Wow, what a day.&lt;br /&gt;&lt;br /&gt;Fortunately our &lt;a href="http://biz.yahoo.com/bw/080417/20080417005241.html?.v=1"&gt;press release&lt;/a&gt; was well-received, which led to a full day discussing SafeCentral's revolutionary approach with press and analysts from across the country.  I'm impressed with how quickly people seem to grasp the concept, and how many say they have been waiting for a solution like &lt;a href="http://www.safecentral.com"&gt;SafeCentral&lt;/a&gt;.  Even the most security-conscious and diligent analysts I spoke to said they were going to install SafeCentral for their personal use; which is a reassuring testament to the value of our new service.&lt;br /&gt;&lt;br /&gt;Allan Maurer, from &lt;a href="http://www.techjournalsouth.com/index.html"&gt;TechJournal South&lt;/a&gt;, inquired about SafeCentral, offered superb feedback, and had &lt;a href="http://www.techjournalsouth.com/news/article.html?item_id=5183"&gt;this article&lt;/a&gt; up in a flash. &lt;br /&gt;&lt;br /&gt;David Utter, from &lt;a href="http://www.securitypronews.com/"&gt;SecurityProNews&lt;/a&gt;, has always provided excellent analysis of online security, and took a fresh look at SafeCentral in his &lt;a href="http://www.securitypronews.com/2008/0327.html"&gt;recent article&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;I'm thrilled to finally have the opportunity to discuss SafeCentral with the public and press, and excited about the opportunities in the days and weeks to come to continue to share our message.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-6064071345363812810?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/6064071345363812810/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=6064071345363812810' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/6064071345363812810'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/6064071345363812810'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/04/launch-day-recap.html' title='Launch Day Recap'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7633748372187898893.post-885485310168462533</id><published>2008-04-17T08:14:00.009-04:00</published><updated>2008-04-17T09:13:46.170-04:00</updated><title type='text'>SafeCentral Arrives!</title><content type='html'>&lt;!--StartFragment--&gt;&lt;span style=";font-family:trebuchet ms;font-size:100%;"  &gt;&lt;span&gt;&lt;span class="Apple-style-span"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Welcome to SafeCentral!&lt;br /&gt;&lt;br /&gt;We officially launched our secure Internet portal a few minutes ago: &lt;a href="http://tinyurl.com/3jeh47"&gt;http://tinyurl.com/3jeh47&lt;/a&gt;, and I must say that after over a year of work, it’s great to finally go live.&lt;br /&gt;&lt;br /&gt;The main question we get asked by family, friends, and colleagues is:&lt;br /&gt;&lt;br /&gt;"&lt;span style="font-weight: bold; font-style: italic; color: rgb(0, 0, 0);"&gt;What is SafeCentral and why do I need it?&lt;/span&gt;"&lt;br /&gt;&lt;br /&gt;It’s simple, we created SafeCentral to give users the freedom to surf the Internet in complete privacy and safety. Over 50 percent of PCs are already infected with spyware, even though most have antivirus, anti-spyware, and firewall software installed. Clearly, traditional security products are not enough anymore. By creating this secure portal, we are hoping to restore users’ confidence in shopping, banking, or even filing taxes online and to actually prevent ID theft.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic; color: rgb(0, 0, 0);"&gt;So, how do we do it?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;SafeCentral prevents cyber crime and identity theft by locking down PCs, launching a secure browser, and connecting users to a trusted portal of their favorite destinations. We use our patent-pending TSX technology to create what we call a virtual “concrete bunker” that safeguards users from viruses, spyware, Trojan horses, keyloggers, phishers, man-in-the-middle attacks, screen scrapers, DNS poisoning, Wi-Fi interception – you name it.  We eliminate the confusing avalanche of threats and free you to use the internet the way you want.&lt;br /&gt;&lt;br /&gt;What we love about SafeCentral is users don’t have to change the way they work or waste hours scanning for threats that have already compromised their computers – SafeCentral takes care of your privacy with a single click. Our portal shields desktops from all the nastiest threats without limiting flexibility, functionality, or usability. We believe it is the only answer to preventing ID theft.  I'll be blogging more soon about the often confused terms of 'identity theft' and 'identity fraud', because so many other approaches focus on the wrong side of these distinct problems.&lt;br /&gt;&lt;br /&gt;Give it a try &lt;a href="http://www.safecentral.com"&gt;http://www.safecentral.com&lt;/a&gt;. We hope you like it. Let us know if you have any questions or suggestions on how to make it better. We’ll listen and get back to you ASAP.&lt;div&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-family:Times New Roman;"&gt;&lt;span style="font-size:11;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;!--EndFragment--&gt;  &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7633748372187898893-885485310168462533?l=blog.safecentral.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.safecentral.com' title='SafeCentral Arrives!'/><link rel='replies' type='application/atom+xml' href='http://blog.safecentral.com/feeds/885485310168462533/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7633748372187898893&amp;postID=885485310168462533' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/885485310168462533'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7633748372187898893/posts/default/885485310168462533'/><link rel='alternate' type='text/html' href='http://blog.safecentral.com/2008/04/safecentral-arrives.html' title='SafeCentral Arrives!'/><author><name>Corey O'Donnell</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='24' src='http://4.bp.blogspot.com/_EHhB3f_ny8k/ScjlNJUtD7I/AAAAAAAAABE/kOM30LtA-kY/S220/Me_B%26W.jpg'/></author><thr:total>0</thr:total></entry></feed>
