<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><atom:link rel="hub" href="http://tumblr.superfeedr.com/" xmlns:atom="http://www.w3.org/2005/Atom"/><description>… and then THAT happened!</description><title>twice-refried news</title><generator>Tumblr (3.0; @ataferner)</generator><link>http://trn.n0t.net/</link><item><title>Hackers Release Symantec Source Code After Failed $50K Extortion Attempt</title><description>&lt;a href="http://www.wired.com/threatlevel/2012/02/symantec-extortion-attempt/"&gt;Hackers Release Symantec Source Code After Failed $50K Extortion Attempt&lt;/a&gt;: &lt;blockquote&gt;
&lt;p&gt;Hackers with the Anonymous collective have released source code for Symantec’s pcAnywhere product after failing to secure $50,000 from the company in an extortion attempt. A hacker going by the online name YamaTough published 1.27 GB of the source code on Pirate Bay Monday night after negotiations to extort money from someone he believed was a Symantec employee fell through. In reality, the Symantec “employee” was an undercover law enforcement agent who was using a fake Symantec email address to communicate with the hacker.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a href="http://www.wired.com/threatlevel/2012/02/symantec-extortion-attempt/" target="_blank"&gt;Full Article&lt;/a&gt;&lt;/p&gt;</description><link>http://trn.n0t.net/post/17329110948</link><guid>http://trn.n0t.net/post/17329110948</guid><pubDate>Thu, 09 Feb 2012 15:01:29 -0500</pubDate></item><item><title>What the RIAA Won’t Tell You: Users Matter</title><description>&lt;a href="https://www.eff.org/deeplinks/2012/02/what-riaa-won’t-tell-you-users-matter-0"&gt;What the RIAA Won’t Tell You: Users Matter&lt;/a&gt;: &lt;blockquote&gt;
&lt;p&gt;We really have to wonder when the message is going to sink in. On January 18, millions of Internet users spoke out together in one of the most profound and effective uses of technology to organize political opposition in U.S. history, sending a clear message to Congress that voters will not tolerate crippling of the Internet. But big content remains tone deaf to this chorus of Internet users.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a href="https://www.eff.org/deeplinks/2012/02/what-riaa-wont-tell-you-users-matter-0" target="_blank"&gt;Full Article&lt;/a&gt;&lt;/p&gt;</description><link>http://trn.n0t.net/post/17329084596</link><guid>http://trn.n0t.net/post/17329084596</guid><pubDate>Thu, 09 Feb 2012 15:00:54 -0500</pubDate></item><item><title>The Password Analysis Red Herring</title><description>&lt;a href="http://www.secureconsulting.net/2012/02/password-analysis-red-herring.html"&gt;The Password Analysis Red Herring&lt;/a&gt;: &lt;blockquote&gt;
&lt;p&gt;Alrighty, this will be a fairly light post (in terms of my own applied analysis)… and, apologies as it’s a wee bit behind the curve on various news pieces in the past couple months (I’d intended to write this in early January - oops!;). Please note that this post applies only to user passwords, and it does not apply to system and database password maintained within various environments. Main Thesis: All this password analysis on compromised user password databases is fairly absurd. The breaches themselves are not generally the result of user password being compromised. As such, the time spent analyzing these passwords is largely a waste of time because it does not appreciably represent much risk to businesses; especially not to those that were compromised.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a href="http://www.secureconsulting.net/2012/02/password-analysis-red-herring.html" target="_blank"&gt;Full Article&lt;/a&gt;&lt;/p&gt;</description><link>http://trn.n0t.net/post/17329057744</link><guid>http://trn.n0t.net/post/17329057744</guid><pubDate>Thu, 09 Feb 2012 15:00:18 -0500</pubDate></item><item><title>Hackers outwit online banking identity security systems</title><description>&lt;a href="http://www.bbc.co.uk/news/technology-16812064"&gt;Hackers outwit online banking identity security systems&lt;/a&gt;: &lt;blockquote&gt;
&lt;p&gt;Criminal hackers have found a way round the latest generation of online banking security devices given out by banks, the BBC has learned. After logging in to the bank’s real site, account holders are being tricked by the offer of training in a new “upgraded security system”. Money is then moved out of the account but this is hidden from the user.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a href="http://www.bbc.co.uk/news/technology-16812064" target="_blank"&gt;Full Article&lt;/a&gt;&lt;/p&gt;</description><link>http://trn.n0t.net/post/17329019500</link><guid>http://trn.n0t.net/post/17329019500</guid><pubDate>Thu, 09 Feb 2012 14:59:24 -0500</pubDate></item><item><title>Mozilla considers removing Trustwave CA</title><description>&lt;a href="http://www.h-online.com/security/news/item/Mozilla-considers-removing-Trustwave-CA-1430998.html"&gt;Mozilla considers removing Trustwave CA&lt;/a&gt;: &lt;blockquote&gt;
&lt;p&gt;Scandalised by the snooping certificate issued by Trustwave, a heise Security reader, Sebastian Wiesinger, has submitted a report to Mozilla’s bug database in which he requests that Trustwave’s root certificates be removed from all Mozilla products. Mozilla’s Kathleen Wilson, who handles the issue, has accepted the submission and requested a statement from Trustwave. Trustwave’s Brian Trzupek has already announced the release of further information which, he says, is still waiting for internal approval.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a href="http://www.h-online.com/security/news/item/Mozilla-considers-removing-Trustwave-CA-1430998.html" target="_blank"&gt;Full Article&lt;/a&gt;&lt;/p&gt;</description><link>http://trn.n0t.net/post/17322101161</link><guid>http://trn.n0t.net/post/17322101161</guid><pubDate>Thu, 09 Feb 2012 11:45:09 -0500</pubDate></item><item><title>NSA Is Waiting For A Major Incident To Create New Cyber Law</title><description>&lt;a href="http://www.liquidmatrix.org/blog/2012/02/08/nsa-is-waiting-for-a-major-incident-to-create-new-cyber-law/"&gt;NSA Is Waiting For A Major Incident To Create New Cyber Law&lt;/a&gt;: &lt;blockquote&gt;
&lt;p&gt;So, it appears that the NSA is waiting for a major incident to create new cyber law. They have made it clear that they would enjoy nothing better than to have open access to private networks. This article from Jan 23, 2012 has some unsettling overtones in it.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a href="http://www.liquidmatrix.org/blog/2012/02/08/nsa-is-waiting-for-a-major-incident-to-create-new-cyber-law/" target="_blank"&gt;Full Article&lt;/a&gt;&lt;/p&gt;</description><link>http://trn.n0t.net/post/17274205463</link><guid>http://trn.n0t.net/post/17274205463</guid><pubDate>Wed, 08 Feb 2012 14:43:11 -0500</pubDate></item><item><title>Game Theory, Anonymous Causality, and 2012</title><description>&lt;a href="https://krypt3ia.wordpress.com/2012/02/05/game-theory-anonymous-causality-and-2012/"&gt;Game Theory, Anonymous Causality, and 2012&lt;/a&gt;: &lt;blockquote&gt;
&lt;p&gt;Anonymous being what it is, has always been susceptible to influence and infiltration from the outside as well as the inside. The nature of the movement is such that it resembles the cell structure of terrorist action groups like Al Qaeda have adopted over the years.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a href="https://krypt3ia.wordpress.com/2012/02/05/game-theory-anonymous-causality-and-2012/" target="_blank"&gt;Full Article&lt;/a&gt;&lt;/p&gt;</description><link>http://trn.n0t.net/post/17274016189</link><guid>http://trn.n0t.net/post/17274016189</guid><pubDate>Wed, 08 Feb 2012 14:38:31 -0500</pubDate></item><item><title>Defendant Ordered to Decrypt Laptop May Have Forgotten Password</title><description>&lt;a href="http://www.wired.com/threatlevel/2012/02/forgotten-password/"&gt;Defendant Ordered to Decrypt Laptop May Have Forgotten Password&lt;/a&gt;: &lt;blockquote&gt;
&lt;p&gt;&lt;a href="http://www.wired.com/threatlevel/2012/02/forgotten-password/" target="_blank"&gt;http://www.wired.com/threatlevel/2012/02/forgotten-password/&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Full Article&lt;/p&gt;</description><link>http://trn.n0t.net/post/17273991322</link><guid>http://trn.n0t.net/post/17273991322</guid><pubDate>Wed, 08 Feb 2012 14:37:55 -0500</pubDate></item><item><title>Symantec: We Didn't Know in 2006 Source Code Was Stolen</title><description>&lt;a href="http://www.wired.com/threatlevel/2012/01/symantec-source-code-hack/"&gt;Symantec: We Didn't Know in 2006 Source Code Was Stolen&lt;/a&gt;: &lt;blockquote&gt;
&lt;p&gt;Anti-virus giant Symantec says it did not know back in 2006 that source code for its software was stolen when it experienced a breach at that time. The company surprised the public last week when it disclosed that hackers had obtained source code for its pcAnywhere software and other products, and that the code had likely been stolen in a six-year-old breach that Symantec had never disclosed.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a href="http://www.wired.com/threatlevel/2012/01/symantec-source-code-hack/" target="_blank"&gt;Full Article&lt;/a&gt;&lt;/p&gt;</description><link>http://trn.n0t.net/post/17224043686</link><guid>http://trn.n0t.net/post/17224043686</guid><pubDate>Tue, 07 Feb 2012 16:09:07 -0500</pubDate></item><item><title>Database Password Storage Exposes Need For Better ID Management</title><description>&lt;a href="http://www.darkreading.com/database-security/167901020/security/news/232500511/dreamhost-password-database-breach-highlights-need-for-better-identity-management.html"&gt;Database Password Storage Exposes Need For Better ID Management&lt;/a&gt;: &lt;blockquote&gt;
&lt;p&gt;The recent hack against a database full of FTP passwords held by Web hosting firm DreamHost highlights a growing database breach trend that’s seeing password stores exposed by the boatload. Though these databases contain sensitive authentication information, they’re often left far less protected than databases containing PII. Experts warn that if organizations are truly serious about their security and compliance programs, they need to either find better ways to secure the passwords in the databases they’re distributed across the network, or look for alternatives that will ditch this method of storage altogether.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a href="http://www.darkreading.com/database-security/167901020/security/news/232500511/dreamhost-password-database-breach-highlights-need-for-better-identity-management.html" target="_blank"&gt;Full Article&lt;/a&gt;&lt;/p&gt;</description><link>http://trn.n0t.net/post/17224002306</link><guid>http://trn.n0t.net/post/17224002306</guid><pubDate>Tue, 07 Feb 2012 16:08:24 -0500</pubDate></item><item><title>Under Obama, the Freedom of Information Act is Still in Shackles</title><description>&lt;a href="https://www.eff.org/deeplinks/2012/01/under-obama-administration-freedom-information-act-still-shackles"&gt;Under Obama, the Freedom of Information Act is Still in Shackles&lt;/a&gt;: &lt;blockquote&gt;
&lt;p&gt;Three years ago this past weekend, on his first full day in office, President Barack Obama issued his now infamous memo on transparency and open government, which was supposed to fulfill his campaign promise to lead the “most transparent administration in history.” Instead, his administration has been just as secretive—if not more so—than his predecessors, and the Freedom of Information Act (FOIA) has become the prime example of his administration’s lack of progress.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a href="https://www.eff.org/deeplinks/2012/01/under-obama-administration-freedom-information-act-still-shackles" target="_blank"&gt;Full Article&lt;/a&gt;&lt;/p&gt;</description><link>http://trn.n0t.net/post/17223708452</link><guid>http://trn.n0t.net/post/17223708452</guid><pubDate>Tue, 07 Feb 2012 16:03:06 -0500</pubDate></item><item><title>The Value Of Device Authentication</title><description>&lt;a href="http://www.darkreading.com/authentication/167901072/security/news/232500670/the-value-of-device-authentication.html"&gt;The Value Of Device Authentication&lt;/a&gt;: &lt;blockquote&gt;
&lt;p&gt;Since the beginning of e-commerce in the mid-1990s, businesses noticed that transactions conducted online can be strengthened in assurance if we can “remember” that a particular device is the same that was used before to conduct successful transactions. A known device provides knowledge about the history of the device and can mitigate against fraudulent transactions that use stolen cards. Later on, similar techniques now referred to as device fingerprinting are quite popular in detecting devices that have been used to conduct fraud online. Several businesses have started up that provide knowledge about connected devices.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a href="http://www.darkreading.com/authentication/167901072/security/news/232500670/the-value-of-device-authentication.html" target="_blank"&gt;Full Article&lt;/a&gt;&lt;/p&gt;</description><link>http://trn.n0t.net/post/17223672804</link><guid>http://trn.n0t.net/post/17223672804</guid><pubDate>Tue, 07 Feb 2012 16:02:26 -0500</pubDate></item><item><title>The Future of Web Authentication</title><description>&lt;a href="http://www.darkreading.com/security/client-security/232500640/the-future-of-web-authentication.html"&gt;The Future of Web Authentication&lt;/a&gt;: &lt;blockquote&gt;
&lt;p&gt;Web authentication protocols took a pounding last year. Problems with the Secure Sockets Layer and Transport Layer Security protocols, which encrypt all sorts of communication among websites, were at the center of several security breaches. Hacks of high-profile certificate authority providers undermined the security of some of the Internet’s biggest brands, including Google and Yahoo; new man-in-the-middle attacks hit the Web; and the powerful Beast vulnerability exposed the most commonly used versions of SSL and TLS. Taken as a whole, it appears the Internet’s trust model is broken. However, many security experts aren’t ready to scrap SSL. Rather than starting over, they recommend fixing the existing system. It’s clear that we need to evolve the way we authenticate on the Web; the question is, how?&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a href="http://www.darkreading.com/security/client-security/232500640/the-future-of-web-authentication.html" target="_blank"&gt;Full Article&lt;/a&gt;&lt;/p&gt;</description><link>http://trn.n0t.net/post/17223619727</link><guid>http://trn.n0t.net/post/17223619727</guid><pubDate>Tue, 07 Feb 2012 16:01:29 -0500</pubDate></item><item><title>Google, Facebook and Others Join to Write New Email-Authentication Spec Called DMARC</title><description>&lt;a href="https://threatpost.com/en_us/blogs/google-facebook-and-others-join-write-new-email-authentication-spec-called-dmarc-013012"&gt;Google, Facebook and Others Join to Write New Email-Authentication Spec Called DMARC&lt;/a&gt;: &lt;blockquote&gt;
&lt;p&gt;Google, Yahoo, AOL and a group of other large email senders and receivers have banded together to develop a new framework for sending and receiving email that is designed to stop phishing attacks and other email-borne scams. Called DMARC.org, the new group has come up with a specification called Domain-based Message Authentication, Reporting and Compliance that implements message authentication through the mail-transport agent and not the sender or user agents.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a href="https://threatpost.com/en_us/blogs/google-facebook-and-others-join-write-new-email-authentication-spec-called-dmarc-013012" target="_blank"&gt;Full Article&lt;/a&gt;&lt;/p&gt;</description><link>http://trn.n0t.net/post/17223568882</link><guid>http://trn.n0t.net/post/17223568882</guid><pubDate>Tue, 07 Feb 2012 16:00:34 -0500</pubDate></item><item><title>The Art of Cyberwar</title><description>&lt;a href="http://www.internetevolution.com/author.asp?doc_id=237983"&gt;The Art of Cyberwar&lt;/a&gt;: &lt;blockquote&gt;
&lt;p&gt;The establishment of the US Cyber Command in 2010 confirmed that cyberspace is a new domain of warfare. The computer is not only a target but also a weapon. Therefore, national security thinkers must find a way to incorporate cyberattacks and defense into military doctrine as soon as possible. The world’s most influential military treatise is Sun Tzu’s Art of War. Its compelling and adaptive wisdom has survived myriad revolutions in technology and human conflict. And its tactics and strategies have been applied to other disciplines, including business, sports, and personal relationships. Future cybercommanders will also find Sun Tzu’s guidance beneficial. For example, on defense, he warns leaders never to rely on the good intentions of others or to count on best-case scenarios. This is sound advice in cyberspace, because computers are attacked from the moment they connect to the Internet.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a href="http://www.internetevolution.com/author.asp?doc_id=237983" target="_blank"&gt;Full Article&lt;/a&gt;&lt;/p&gt;</description><link>http://trn.n0t.net/post/17223522234</link><guid>http://trn.n0t.net/post/17223522234</guid><pubDate>Tue, 07 Feb 2012 15:59:44 -0500</pubDate></item><item><title>The Right to Anonymity is a Matter of Privacy</title><description>&lt;a href="https://www.eff.org/deeplinks/2012/01/right-anonymity-matter-privacy"&gt;The Right to Anonymity is a Matter of Privacy&lt;/a&gt;: &lt;blockquote&gt;
&lt;p&gt;Throughout history, there have been a number of reasons why individuals have taken to writing or producing art under a pseudonym. In the 18th century, James Madison, Alexander Hamilton, and John Jay took on the pseudonym Publius to publish The Federalist Papers. In 19th century England, pseudonyms allowed women—like the Brontë sisters, who initially published under Currer, Ellis, and Acton Bell—to be taken seriously as writers. Today, pseudonyms continue to serve a range of individuals, and for a variety of reasons. At EFF, we view anonymity as both a matter of free speech and privacy, but in light of International Privacy Day, January 28, this piece will focus mainly on the latter, looking at the ways in which the right to anonymity—or pseudonymity—is truly a matter of privacy.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a href="https://www.eff.org/deeplinks/2012/01/right-anonymity-matter-privacy" target="_blank"&gt;Full Article&lt;/a&gt;&lt;/p&gt;</description><link>http://trn.n0t.net/post/17223474974</link><guid>http://trn.n0t.net/post/17223474974</guid><pubDate>Tue, 07 Feb 2012 15:58:51 -0500</pubDate></item><item><title>New Mobile-Phone Privacy Law Proposed</title><description>&lt;a href="http://www.wired.com/threatlevel/2012/01/new-mobile-phone-privacy-law-proposed/"&gt;New Mobile-Phone Privacy Law Proposed&lt;/a&gt;: &lt;blockquote&gt;
&lt;p&gt;Rep. Edward Markey (D-Massachusetts) unveiled draft legislation Monday requiring mobile-phone carriers to reveal if they are employing tracking software such as Carrier IQ. “Consumers have the right to know and to say ‘no’ to the presence of software on their mobile devices that can collect and transmit their personal and sensitive information,” Markey said in The Hill.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a href="http://www.wired.com/threatlevel/2012/01/new-mobile-phone-privacy-law-proposed/" target="_blank"&gt;Full Article&lt;/a&gt;&lt;/p&gt;</description><link>http://trn.n0t.net/post/17223335507</link><guid>http://trn.n0t.net/post/17223335507</guid><pubDate>Tue, 07 Feb 2012 15:56:15 -0500</pubDate></item><item><title>TSA discovery prompts New York bomb scare - six hours later</title><description>&lt;a href="http://www.cnn.com/2012/01/30/us/new-york-bomb-scare/index.html"&gt;TSA discovery prompts New York bomb scare - six hours later&lt;/a&gt;: &lt;blockquote&gt;
&lt;p&gt;A New York airport screener who removed two pipes from a traveler’s bag and set them aside Monday morning prompted a security scare six hours later when the next shift saw the pipes and feared they might be pipe bombs, local and federal officials said. The incident at New York’s LaGuardia Airport began at 11:30 a.m. when a screener discovered unidentifiable items inside a passenger’s carry-on bag. The officer screened the item for explosives, determined them not to be a threat and cleared the passenger through the checkpoint, a Transportation Security Administration official said.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a href="http://www.cnn.com/2012/01/30/us/new-york-bomb-scare/index.html" target="_blank"&gt;Full Article&lt;/a&gt;&lt;/p&gt;</description><link>http://trn.n0t.net/post/17223289907</link><guid>http://trn.n0t.net/post/17223289907</guid><pubDate>Tue, 07 Feb 2012 15:55:24 -0500</pubDate></item><item><title>Carder Forced Gang Members to Have Sex to Weed Out Undercover Feds</title><description>&lt;a href="http://www.wired.com/threatlevel/2012/01/carder-sex-gang/"&gt;Carder Forced Gang Members to Have Sex to Weed Out Undercover Feds&lt;/a&gt;: &lt;blockquote&gt;
&lt;p&gt;The mastermind of a carding gang in Georgia devised a novel way for weeding out undercover Feds from his operation — he forced members to have group sex, according to a local police detective who helped bust the ring. Vikas Yadav, an Indian national who was deported in 2010, recruited other carders and mules through sadomasochism web sites, forcing would-be accomplices to have group sex with other men and women while Yadav videotaped them, according to the Athens Banner-Herald.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a href="http://www.wired.com/threatlevel/2012/01/carder-sex-gang/" target="_blank"&gt;Full Article&lt;/a&gt;&lt;/p&gt;</description><link>http://trn.n0t.net/post/17222769770</link><guid>http://trn.n0t.net/post/17222769770</guid><pubDate>Tue, 07 Feb 2012 15:45:39 -0500</pubDate></item><item><title>Hacker extracts RFID credit card details</title><description>&lt;a href="http://www.h-online.com/security/news/item/Hacker-extracts-RFID-credit-card-details-1425974.html"&gt;Hacker extracts RFID credit card details&lt;/a&gt;: &lt;blockquote&gt;
&lt;p&gt;The widespread use, especially in US credit cards, of RFID chips which can be read through clothing or wallets for contactless payments can lead to cards being read without the owners knowledge or permission. At the Shmoocon security conference held in Washington D.C., US business magazine Forbes reports that Kristin Paget impressively demonstrated the ability to read data on RFID chipped credit cards and make a payment that hadn’t been authorised by the card owner. However, credit card manufacturers don’t think that there is an increased risk.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;a href="http://www.h-online.com/security/news/item/Hacker-extracts-RFID-credit-card-details-1425974.html" target="_blank"&gt;Full Article&lt;/a&gt;&lt;/p&gt;</description><link>http://trn.n0t.net/post/17222249586</link><guid>http://trn.n0t.net/post/17222249586</guid><pubDate>Tue, 07 Feb 2012 15:35:38 -0500</pubDate></item></channel></rss>

