<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule">
<channel>
    <title>JaBbA's Hut - Security</title>
    <link>http://jalcorn.net/weblog/</link>
    <description>White Hat Liberal Geek Dad</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.2.1 - http://www.s9y.org/</generator>
    <pubDate>Tue, 29 Jan 2008 15:39:19 GMT</pubDate>

    <image>
        <url>http://jalcorn.net/weblog/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: JaBbA's Hut - Security - White Hat Liberal Geek Dad</title>
        <link>http://jalcorn.net/weblog/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>Schneier on Security vs. Privacy</title>
    <link>http://jalcorn.net/weblog/archives/1073-Schneier-on-Security-vs.-Privacy.html</link>
            <category>Freedom</category>
            <category>Musings</category>
            <category>Security</category>
    
    <comments>http://jalcorn.net/weblog/archives/1073-Schneier-on-Security-vs.-Privacy.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=1073</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=1073</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Bruce Schneier posted an article today on the false dichotomy between &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5zY2huZWllci5jb20vYmxvZy9hcmNoaXZlcy8yMDA4LzAxL3NlY3VyaXR5X3ZzX3ByaS5odG1s&amp;amp;entry_id=1073&quot;  onmouseover=&quot;window.status=&#039;http://www.schneier.com/blog/archives/2008/01/security_vs_pri.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; title=&quot;Schneier.com&quot;&gt;Security vs. Privacy&lt;/a&gt;:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;If you set up the false dichotomy, of course people will choose security over privacy -- especially if you scare them first. But it&#039;s still a false dichotomy. There is no security without privacy. And liberty requires both security and privacy. The famous quote attributed to Benjamin Franklin reads: &quot;Those who would give up essential liberty to purchase a little temporary safety, deserve neither liberty nor safety.&quot; It&#039;s also true that those who would give up privacy for security are likely to end up with neither.&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
The American people have been bombarded with so much fear and anxiety that they have stopped thinking.  And, unfortunately, for many people that&#039;s the way they like it.  But I take some heart from the freefall of Rudy &quot;9-11&quot; Guiliani in the Polls - given enough time, people finally started looking at something other than his constant fear speech, and didn&#039;t like what they saw.  He miscalculated, thinking that the security message could last almost 2 years.  It&#039;s not that people are beginning to wake up - I think it&#039;s more that they have become habituated to the constant drumbeat that they are able to look past it.&lt;br /&gt;
&lt;br /&gt;
But Schneier&#039;s right - security comes before social issues like privacy on Maslow&#039;s Hierarchy of Needs.  We have to get over the fear before we can worry about civil liberties - and that&#039;s what the government is counting on.  But there is a way - and that is to get people to fear the loss of privacy.  Unfortunately, balancing fear of government intrusion against complete paranoia is difficult - and it&#039;s much easier to make people fear a violent attack.   &lt;br /&gt;
&lt;br /&gt;
This may be why I&#039;m attracted do Obama&#039;s message of hope.  If we can look forward to a future where we don&#039;t see enemies all around us, we can be more cognizant of the importance of personal liberty.  I am beginning to believe that Obama sees that future and wants to lead the country there.&lt;br /&gt;
&lt;br /&gt;
JaBbA says check it out.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Tue, 29 Jan 2008 10:39:19 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/1073-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Finally, a reality show for geeks</title>
    <link>http://jalcorn.net/weblog/archives/1071-Finally,-a-reality-show-for-geeks.html</link>
            <category>Security</category>
    
    <comments>http://jalcorn.net/weblog/archives/1071-Finally,-a-reality-show-for-geeks.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=1071</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=1071</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    The newly-rebranded TruTV (nee CourtTV) is starting a new reality series, but instead of following Police Detectives, or Ghost Hunters, this time it&#039;s following a team of &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5jb3VydHR2LmNvbS9vbmFpci9zaG93cy91cGNvbWluZ19zZXJpZXMvI3RpZ2VyX3RlYW0g&amp;amp;entry_id=1071&quot;  onmouseover=&quot;window.status=&#039;http://www.courttv.com/onair/shows/upcoming_series/#tiger_team &#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; title=&quot;Tiger Team&quot;&gt;penentration testers!&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;This verite action series follows Tiger Team &quot;a group of elite professionals hired to infiltrate major business and corporate interests with the objective of exposing weaknesses in the world&#039;s most sophisticated security systems, defeating criminals at their own game. Tiger Team is comprised of Security Audit Specialists Chris Nickerson, Luke McOmie and Ryan Jones who employ a variety of covert techniques - electronic, psychological and tactical - as they take on a new assignment in each episode.&quot;&lt;br /&gt;
&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
The first show is December 25th at 11:30pm.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;UPDATE&lt;/B&gt; TruTV now says it was a special, and will not be made into a series.   I heard from someone who was working with the team that there was a lot they just couldn&#039;t show, so it was probably too difficult to make it a series.   Nevertheless, the Car Dealership break-in is online at TruTV&#039;s website (important point - it&#039;s amazing what a skilled researcher can find out from someone&#039;s trash), and if you can find the Jewelry dealer show, it&#039;s a fantastic example of how social engineering and lack of user security awareness can lead to trouble.&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Wed, 19 Dec 2007 16:33:01 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/1071-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Real risk - the Phishing Trojan</title>
    <link>http://jalcorn.net/weblog/archives/1068-Real-risk-the-Phishing-Trojan.html</link>
            <category>Phishing</category>
            <category>Security</category>
    
    <comments>http://jalcorn.net/weblog/archives/1068-Real-risk-the-Phishing-Trojan.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=1068</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=1068</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Of course, there are real risks out there that we need to avoid.&lt;br /&gt;
&lt;br /&gt;
The targeted emails warning of IRS Audits or overdue invoices are a perfect example.   Executives receiving these quite alarming emails click on the attachments to find out what the problem is, and the bad guys now own their computers.&lt;br /&gt;
&lt;br /&gt;
I&#039;ve seen multiple examples of the IRS audit scam, all of which came to executives here at work.  Someone&#039;s been doing their homework.&lt;br /&gt;
&lt;br /&gt;
I&#039;d suggest warning all executives of your companies about these emails.&lt;br /&gt;
&lt;br /&gt;
Example, from &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url_id=24&amp;amp;entry_id=1068&quot; title=&quot;http://isc.sans.org/diary.html?storyid=2979&quot;  onmouseover=&quot;window.status=&#039;http://isc.sans.org/diary.html?storyid=2979&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;SANS&lt;/a&gt;:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;Proforma Invoice for &quot;Company Name&quot; (Attn: &quot;Executive Name&quot;)&lt;br /&gt;
&lt;br /&gt;
The Body of the email included this text&lt;br /&gt;
&lt;br /&gt;
&quot;Hello,&lt;br /&gt;
&lt;br /&gt;
The Proforma Invoice is attached to this message. You can find the file&lt;br /&gt;
in the attachments area of your email software.&lt;br /&gt;
&lt;br /&gt;
PS: The invoice also includes the cost for the services provided for the&lt;br /&gt;
second quarter of 2007.&lt;br /&gt;
Please read, evaluate and reply with any comments. Thanks.&quot;&lt;/blockquote&gt; 
    </content:encoded>

    <pubDate>Fri, 15 Jun 2007 13:26:17 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/1068-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Risk and Perception</title>
    <link>http://jalcorn.net/weblog/archives/1067-Risk-and-Perception.html</link>
            <category>Musings</category>
            <category>Security</category>
    
    <comments>http://jalcorn.net/weblog/archives/1067-Risk-and-Perception.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=1067</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=1067</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Bruce Schneier has written another excellent article on the &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url_id=20&amp;amp;entry_id=1067&quot;  onmouseover=&quot;window.status=&#039;http://www.schneier.com/crypto-gram-0706.html#1&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;Crypto-Gram&quot;&gt;perception of risk&lt;/a&gt;:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;...when faced with a very available and highly vivid event like 9/11 or the Virginia Tech shootings, we overreact. And when faced with all the salient related events, we assume causality. We pass the Patriot Act. We think if we give guns out to students, or maybe make it harder for students to get guns, we&#039;ll have solved the problem. We don&#039;t let our children go to playgrounds unsupervised. We stay out of the ocean because we read about a shark attack somewhere.&lt;br /&gt;
&lt;br /&gt;
It&#039;s our brains again. We need to &quot;do something,&quot; even if that something doesn&#039;t make sense; even if it is ineffective. And we need to do something directly related to the details of the actual event. So instead of implementing effective, but more general, security measures to reduce the risk of terrorism, we ban box cutters on airplanes. And we look back on the Virginia Tech massacre with 20-20 hindsight and recriminate ourselves about the things we *should have done. &lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
He&#039;s written about &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url_id=21&amp;amp;entry_id=1067&quot; title=&quot;http://jalcorn.net/weblog/archives/1027-Schneier-What-the-Terrorists-Want.html&quot;  onmouseover=&quot;window.status=&#039;http://jalcorn.net/weblog/archives/1027-Schneier-What-the-Terrorists-Want.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;risk, perception and &quot;security theater&quot;&lt;/a&gt; many times.&lt;br /&gt;
&lt;br /&gt;
JaBbA says check it out. 
    </content:encoded>

    <pubDate>Fri, 15 Jun 2007 13:19:44 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/1067-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Windows ANI Patch</title>
    <link>http://jalcorn.net/weblog/archives/1065-Windows-ANI-Patch.html</link>
            <category>Security</category>
    
    <comments>http://jalcorn.net/weblog/archives/1065-Windows-ANI-Patch.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=1065</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=1065</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Microsoft just released an emergency patch for the ANI Vulnerability.  The Internet Storm center has been condition yellow for 76 hours, longer than ever before, because of this vulnerability.&lt;br /&gt;
&lt;br /&gt;
Don&#039;t wait for the regular update.  go to &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url_id=2&amp;amp;entry_id=1065&quot;  onmouseover=&quot;window.status=&#039;http://update.microsoft.com/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;Microsoft Update&quot;&gt;http://update.microsoft.com/&lt;/a&gt; and get it now.  Really.  I&#039;ll wait......&lt;br /&gt;
&lt;br /&gt;
And be sure not to type &#039;microfost&#039; by accident.  That&#039;s one of the websites that was hacking people when they visited.&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Tue, 03 Apr 2007 15:47:36 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/1065-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Dolphin Stadium site hacked</title>
    <link>http://jalcorn.net/weblog/archives/1061-Dolphin-Stadium-site-hacked.html</link>
            <category>Security</category>
    
    <comments>http://jalcorn.net/weblog/archives/1061-Dolphin-Stadium-site-hacked.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=1061</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=1061</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Someone has compromised the official Dolphin Stadium website and inserted malicious javascript into the header.  DO NOT visit dolphinstadium.com and if you have any kind of filters block it immediately.&lt;br /&gt;
&lt;br /&gt;
Screenshots can be found at &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy53ZWJzZW5zZXNlY3VyaXR5bGFicy5jb20vYWxlcnRzL2FsZXJ0LnBocD9BbGVydElEPTczMw==&amp;amp;entry_id=1061&quot; title=&quot;http://www.websensesecuritylabs.com/alerts/alert.php?AlertID=733&quot;  onmouseover=&quot;window.status=&#039;http://www.websensesecuritylabs.com/alerts/alert.php?AlertID=733&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;&gt;Websense Security Labs&lt;/a&gt; 
    </content:encoded>

    <pubDate>Fri, 02 Feb 2007 12:49:38 -0500</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/1061-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Nervous Yet?</title>
    <link>http://jalcorn.net/weblog/archives/1042-Nervous-Yet.html</link>
            <category>Security</category>
            <category>The Election</category>
    
    <comments>http://jalcorn.net/weblog/archives/1042-Nervous-Yet.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=1042</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=1042</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Control of the congress is going down to the wire, and there is no reason to think that the election is going to go any more smoothly this time than in May, especially here in Cuyahoga County.&lt;br /&gt;
&lt;br /&gt;
See my &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL25vcnRoY29hc3RibHVlcy5vcmcvYmxvZy9hcmNoaXZlcy8zNC1Wb3Rlci1TdXBwcmVzc2lvbi1pbi1DbGV2ZWxhbmQtSHRzLmh0bWw=&amp;amp;entry_id=1042&quot;  onmouseover=&quot;window.status=&#039;http://northcoastblues.org/blog/archives/34-Voter-Suppression-in-Cleveland-Hts.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;NorthCoastBlues&quot;&gt;Voter Registration experience&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
And a new article today from the IBM Center for Business and Government about possible &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy50ZWNobm9sb2d5cmV2aWV3LmNvbS9yZWFkX2FydGljbGUuYXNweD9pZD0xNzYxNiZjaD1pbmZvdGVjaA==&amp;amp;entry_id=1042&quot;  onmouseover=&quot;window.status=&#039;http://www.technologyreview.com/read_article.aspx?id=17616&amp;amp;ch=infotech&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;Technology Review&quot;&gt;large scale disenfranchisement&lt;/a&gt; 
    </content:encoded>

    <pubDate>Mon, 16 Oct 2006 15:25:07 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/1042-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Columbus Day SPAM Attack</title>
    <link>http://jalcorn.net/weblog/archives/1041-Columbus-Day-SPAM-Attack.html</link>
            <category>SPAM</category>
    
    <comments>http://jalcorn.net/weblog/archives/1041-Columbus-Day-SPAM-Attack.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=1041</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=1041</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    The last few months, the mailware writers have been taking advantage of the fact that even security people like to take their weekends off to blast the Internet with their latest and greatest creations.&lt;br /&gt;
&lt;br /&gt;
&lt;a class=&#039;serendipity_image_link&#039; href=&#039;http://jalcorn.net/weblog/uploads/spamgraph.png&#039;&gt;&lt;img width=&quot;110&quot; height=&quot;69&quot; border=&quot;0&quot; hspace=&quot;5&quot; align=&quot;left&quot; src=&quot;http://jalcorn.net/weblog/uploads/spamgraph.serendipityThumb.png&quot; alt=&quot;&quot;  /&gt;&lt;/a&gt;Apparently, the pump-and-dump SPAMmers have decided to use the same tactic, and thought maybe the Columbus day weekend might be a good time to do it.&lt;br /&gt;
&lt;br /&gt;
At work, my usual volume of SPAM on a Sunday is about 90,000 emails.  Here&#039;s my current graph.  That huge spike at the end - 204,000 email on Sunday.&lt;br /&gt;
&lt;br /&gt;
Where are they coming from?  Delivery failures.  We&#039;ve become the spoofed From: line for some spammer out there.  And &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2lzYy5zYW5zLm9yZy9kaWFyeS5waHA/c3RvcnlpZD0xNzY2&amp;amp;entry_id=1041&quot;  onmouseover=&quot;window.status=&#039;http://isc.sans.org/diary.php?storyid=1766&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;ISC Diary&quot;&gt;we&#039;re not the only ones&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
It&#039;s getting nasty out there.&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Mon, 09 Oct 2006 11:15:04 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/1041-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>FIrefox Flaw?  Maybe...maybe not</title>
    <link>http://jalcorn.net/weblog/archives/1037-FIrefox-Flaw-Maybe...maybe-not.html</link>
            <category>Browser Wars</category>
            <category>Security</category>
    
    <comments>http://jalcorn.net/weblog/archives/1037-FIrefox-Flaw-Maybe...maybe-not.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=1037</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=1037</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    There&#039;s been a lot of uproar over a presentation at &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy50b29yY29uLm9yZy8=&amp;amp;entry_id=1037&quot; title=&quot;http://www.toorcon.org/&quot;  onmouseover=&quot;window.status=&#039;http://www.toorcon.org/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;Toorcon&lt;/a&gt; where a pair of &quot;Security Researchers&quot; (which is what they would be called if they used responsible disclosure) / &quot;Hackers&quot; (which is the term almost universally used in press accounts) claimed to have found a bug in Firefox which they used to build a botnet.&lt;br /&gt;
&lt;br /&gt;
This understandably concerned the Mozilla team, and a member of the Mozilla security team joined the presentation.  Turns out they were &quot;joking&quot;.  I&#039;m not sure how the announcement of the creation of a botnet based on a non-existent security flaw constitutes a &quot;joke&quot; - and I&#039;m a geek.  I &quot;get&quot; some pretty esoteric jokes. &lt;img src=&quot;http://jalcorn.net/weblog/templates/default/img/emoticons/smile.png&quot; alt=&quot;:-)&quot; style=&quot;display: inline; vertical-align: bottom;&quot; class=&quot;emoticon&quot; /&gt;  They wanted to tweak the &quot;Firefox fanboys&quot;.  &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2RldmVsb3Blci5tb3ppbGxhLm9yZy9kZXZuZXdzL2luZGV4LnBocC8yMDA2LzEwLzAyL3VwZGF0ZS1wb3NzaWJsZS12dWxuZXJhYmlsaXR5LXJlcG9ydGVkLWF0LXRvb3Jjb24v&amp;amp;entry_id=1037&quot;  onmouseover=&quot;window.status=&#039;http://developer.mozilla.org/devnews/index.php/2006/10/02/update-possible-vulnerability-reported-at-toorcon/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;mozilla.org&quot;&gt;Mischa later apologized&lt;/a&gt;:&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;he main purpose of our talk was to be humorous.&lt;br /&gt;
&lt;br /&gt;
As part of our talk we mentioned that there was a previously known Firefox vulnerability that could result in a stack overflow ending up in remote code execution. However, the code we presented did not in fact do this, and I personally have not gotten it to result in code execution, nor do I know of anyone who has.&lt;br /&gt;
&lt;br /&gt;
I have not succeeded in making this code do anything more than cause a crash and eat up system resources, and I certainly havenât used it to take over anyone elseâs computer and execute arbitrary code.&lt;br /&gt;
&lt;br /&gt;
I do not have 30 undisclosed Firefox vulnerabilities, nor did I ever make this claim. I have no undisclosed Firefox vulnerabilities. The person who was speaking with me made this claim, and I honestly have no idea if he has them or not.&lt;br /&gt;
&lt;br /&gt;
I apologize to everyone involved, and I hope I have made everything as clear as possible.&lt;br /&gt;
&lt;br /&gt;
Sincerely,&lt;br /&gt;
&lt;br /&gt;
Mischa Spiegelmock&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
Nevertheless, there apparently is a little bit of fire in all that smoke - a &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2RldmVsb3Blci5tb3ppbGxhLm9yZy9kZXZuZXdzL2luZGV4LnBocC8yMDA2LzEwLzAyL3VwZGF0ZS1wb3NzaWJsZS12dWxuZXJhYmlsaXR5LXJlcG9ydGVkLWF0LXRvb3Jjb24v&amp;amp;entry_id=1037&quot;  onmouseover=&quot;window.status=&#039;http://developer.mozilla.org/devnews/index.php/2006/10/02/update-possible-vulnerability-reported-at-toorcon/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;mozilla.org&quot;&gt;flaw in Firefox&lt;/a&gt; that can apparently be used for a Denial of service.  Of course, I didn&#039;t say too much about the IE setslice vulnerability on Thursday because it, too, was a DoS bug - until Friday night, when suddenly a remote code execution exploit was released and caused enough havoc to prompt the ISC to &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2lzYy5zYW5zLm9yZy9kaWFyeS5waHA/c3RvcnlpZD0xNzQ5&amp;amp;entry_id=1037&quot;  onmouseover=&quot;window.status=&#039;http://isc.sans.org/diary.php?storyid=1749&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;isc.sans.org&quot;&gt;go to yellow alert&lt;/a&gt;.  So be aware, if I hear of this escalating to an exploit I&#039;ll post asap.&lt;br /&gt;
&lt;br /&gt;
The most important thing - Mozilla immediately reacted, is concerned with finding the truth, not maintaining a corporate image, and is taking this very seriously.  &lt;br /&gt;
&lt;br /&gt;
JaBbA says: Open Source means more than just source code.&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Tue, 03 Oct 2006 10:54:23 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/1037-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Why did I make a big deal out of the latest MS exploit?</title>
    <link>http://jalcorn.net/weblog/archives/1035-Why-did-I-make-a-big-deal-out-of-the-latest-MS-exploit.html</link>
            <category>Security</category>
    
    <comments>http://jalcorn.net/weblog/archives/1035-Why-did-I-make-a-big-deal-out-of-the-latest-MS-exploit.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=1035</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=1035</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2lzYy5zYW5zLm9yZy9kaWFyeS5waHA/biZzdG9yeWlkPTE3NDU=&amp;amp;entry_id=1035&quot;  onmouseover=&quot;window.status=&#039;http://isc.sans.org/diary.php?n&amp;amp;storyid=1745&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;ISC.sans.org&quot;&gt;This is why&lt;/a&gt;:&lt;br /&gt;
&lt;br /&gt;
[From SANS]&lt;br /&gt;
&lt;blockquote&gt;Kevin Shea wrote in to report:&lt;br /&gt;
&lt;br /&gt;
&lt;i&gt;Yesterday morning (9/27) when dropping off my son at school, I told his first grade teacher about the VML exploits and patch availability. She said she had computers at home and would call her husband to make sure they were patched.&lt;br /&gt;
&lt;br /&gt;
When my signifigant-other picked him up around 5:30, the teachers were all talking about how her husband checked and found out they were infected with one of the trojans. Their bank accounts had been drained, by electronic withdrawals and money transfers. Since it had occurred the day before, the bank (unknown) was able to reverse the transfers and replace the money in their accounts. They won&#039;t even bounce a check.&lt;/i&gt;&lt;br /&gt;
&lt;br /&gt;
After receiving the report, I had a few questions and I received a prompt follow-up.  What the thieves did with the money was interesting.  Most of the funds were transferred out using one of those services where you can wire cash to people.  I&#039;m not sure if these were wired to other accounts using the intermediary, of it people actually walked up to a counter to retrieve the funds.  They also used funds in this account to purchase background checks at certain people-search/information-broker companies.  Most likely this is an attempt to gather further identities in a way that won&#039;t tip-off the broker.&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
Because Kevin told people about this, that teacher was able to quickly recover all the lost money.&lt;br /&gt;
&lt;br /&gt;
JaBbA says tell your friends: Friends don&#039;t let friends get ripped off by using unpatched software.&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Fri, 29 Sep 2006 12:41:41 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/1035-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Electronic Voting and the upcoming election</title>
    <link>http://jalcorn.net/weblog/archives/1033-Electronic-Voting-and-the-upcoming-election.html</link>
            <category>Security</category>
            <category>The Election</category>
    
    <comments>http://jalcorn.net/weblog/archives/1033-Electronic-Voting-and-the-upcoming-election.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=1033</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=1033</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    I&#039;m about half way through &lt;em&gt;&lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5icmF2ZW5ld2JhbGxvdC5vcmcv&amp;amp;entry_id=1033&quot; title=&quot;http://www.bravenewballot.org/&quot;  onmouseover=&quot;window.status=&#039;http://www.bravenewballot.org/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;Brave New Ballot&lt;/a&gt;&lt;/em&gt;, the new book about electronic voting by &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2F2aXJ1YmluLm9yZy8=&amp;amp;entry_id=1033&quot; title=&quot;http://avirubin.org/&quot;  onmouseover=&quot;window.status=&#039;http://avirubin.org/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;Avi Rubin&lt;/a&gt;.  Since I&#039;ve been following the Diebold case since &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2JsYWNrYm94dm90aW5nLm9yZy8=&amp;amp;entry_id=1033&quot; title=&quot;http://blackboxvoting.org/&quot;  onmouseover=&quot;window.status=&#039;http://blackboxvoting.org/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;Bev Harris&lt;/a&gt; first reported problems with the machines, none of the facts presented are any surprise to me.  However, the book is well written, and fair to a fault, as appropriate for a serious academic.  I&#039;d recommend it to anyone interested in why the Voter Verified Paper Trails are so important to saving American Democracy.  I&#039;ll have more as I finish the book.&lt;br /&gt;
&lt;br /&gt;
Also, I finally got the info about helping with the election itself.  I was planning on volunteering but, as it turns out, since I&#039;m a computer expert the Cuyahoga County BOE will pay me $250 to be a technical person helping with the vote.  So, like Avi Rubin, I&#039;ll be working at the polls on election day.   I&#039;ll be on the lookout for issues that could allow wholesale vote fraud, not that I can &lt;em&gt;fix&lt;/em&gt; them, mind you.  But the first step is to be sure that someone is watching.&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Fri, 29 Sep 2006 00:32:37 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/1033-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Microsoft Patch</title>
    <link>http://jalcorn.net/weblog/archives/1032-Microsoft-Patch.html</link>
            <category>Viruses</category>
    
    <comments>http://jalcorn.net/weblog/archives/1032-Microsoft-Patch.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=1032</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=1032</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Microsoft released a patch for the &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2phbGNvcm4ubmV0L3dlYmxvZy9hcmNoaXZlcy8xMDMxLVN0YXR1cy1ZZWxsb3cuLUV4cGxvaXQtQ29kZS1pcy1tYWtpbmctdGhlLXJvdW5kcyEuaHRtbA==&amp;amp;entry_id=1032&quot; title=&quot;http://jalcorn.net/weblog/archives/1031-Status-Yellow.-Exploit-Code-is-making-the-rounds!.html&quot;  onmouseover=&quot;window.status=&#039;http://jalcorn.net/weblog/archives/1031-Status-Yellow.-Exploit-Code-is-making-the-rounds!.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;VML Issue&lt;/a&gt;.  Make sure your automatic update is on, or go to windowsupdate.com to get the update directly.&lt;br /&gt;
&lt;br /&gt;
JaBbA says patch.  Now!&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Tue, 26 Sep 2006 17:32:06 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/1032-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Status: Yellow.  Exploit Code is making the rounds!</title>
    <link>http://jalcorn.net/weblog/archives/1031-Status-Yellow.-Exploit-Code-is-making-the-rounds!.html</link>
            <category>Viruses</category>
    
    <comments>http://jalcorn.net/weblog/archives/1031-Status-Yellow.-Exploit-Code-is-making-the-rounds!.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=1031</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=1031</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    ISC has gone &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2lzYy5zYW5zLm9yZy9kaWFyeS5waHA/c3RvcnlpZD0xNzI3&amp;amp;entry_id=1031&quot;  onmouseover=&quot;window.status=&#039;http://isc.sans.org/diary.php?storyid=1727&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;Internet Storm Center&quot;&gt;Status Yellow&lt;/a&gt; because of new exploit code.&lt;br /&gt;
&lt;br /&gt;
It&#039;s a drive by - you&#039;ll NEVER know you got hacked on a fully-patched Win XP system until someone empties your PayPal account.&lt;br /&gt;
&lt;br /&gt;
Video of it happening is at &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy53ZWJzZW5zZS5jb20vc2VjdXJpdHlsYWJzL2Jsb2cvYmxvZy5waHA/QmxvZ0lEPTgy&amp;amp;entry_id=1031&quot;  onmouseover=&quot;window.status=&#039;http://www.websense.com/securitylabs/blog/blog.php?BlogID=82&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;Websense&quot;&gt;The Websense Security Blog&lt;/a&gt;.  &lt;br /&gt;
&lt;br /&gt;
More info in &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2lzYy5zYW5zLm9yZy9kaWFyeS5waHA/c3RvcnlpZD0xNzEz&amp;amp;entry_id=1031&quot;  onmouseover=&quot;window.status=&#039;http://isc.sans.org/diary.php?storyid=1713&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;ISC&quot;&gt;Tuesday&#039;s ISC Diary&lt;/a&gt;, and &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2lzYy5zYW5zLm9yZy9kaWFyeS5waHA/c3RvcnlpZD0xNzIy&amp;amp;entry_id=1031&quot;  onmouseover=&quot;window.status=&#039;http://isc.sans.org/diary.php?storyid=1722&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;ISC&quot;&gt;Thursday&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
JaBbA&#039;s Recommendations:&lt;br /&gt;
&lt;br /&gt;
#1 - &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5nZXRmaXJlZm94LmNvbS8=&amp;amp;entry_id=1031&quot;  onmouseover=&quot;window.status=&#039;http://www.getfirefox.com/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;getfirefox.com&quot;&gt;Use Firefox&lt;/a&gt; with &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5ub3NjcmlwdC5uZXQvd2hhdHM=&amp;amp;entry_id=1031&quot; title=&quot;http://www.noscript.net/whats&quot;  onmouseover=&quot;window.status=&#039;http://www.noscript.net/whats&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;NoScript&lt;/a&gt;.&lt;br /&gt;
#2 - Update your Antivirus.  If you don&#039;t have Antivirus, try &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL2ZyZWUuZ3Jpc29mdC5jb20v&amp;amp;entry_id=1031&quot;  onmouseover=&quot;window.status=&#039;http://free.grisoft.com/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;GRISoft&quot;&gt;AVG Anti-Virus Free Edition&lt;/a&gt;.&lt;br /&gt;
#3 - &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5tb3ppbGxhLmNvbS90aHVuZGVyYmlyZC8=&amp;amp;entry_id=1031&quot;  onmouseover=&quot;window.status=&#039;http://www.mozilla.com/thunderbird/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;mozilla&quot;&gt;Use Thunderbird&lt;/a&gt; instead of outlook.&lt;br /&gt;
#4 - Slow down on that itchy trigger finger.  Do you really need to click that link that was just sent to you?&lt;br /&gt;
#5 - Unregister the DLLs.  This isn&#039;t for the faint of heart, but it will stop the hack&lt;br /&gt;
&lt;blockquote&gt;&lt;center&gt;regsvr32 -u &quot;%ProgramFiles%\Common Files\Microsoft Shared\VGX\vgx.dll&quot;&lt;br /&gt;
or&lt;br /&gt;
regsvr32 /u &quot;%CommonProgramFiles%\Microsoft Shared\VGX\vgx.dll&quot; &lt;br /&gt;
&lt;/center&gt;&lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
Remove the -u to reregister them after October 10th, the date this is supposed to be fixed. 
    </content:encoded>

    <pubDate>Fri, 22 Sep 2006 15:05:45 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/1031-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Calling all Computer Geeks</title>
    <link>http://jalcorn.net/weblog/archives/1030-Calling-all-Computer-Geeks.html</link>
            <category>Security</category>
            <category>The Election</category>
    
    <comments>http://jalcorn.net/weblog/archives/1030-Calling-all-Computer-Geeks.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=1030</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=1030</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    &lt;b&gt;Especially&lt;/b&gt; Computer Security people....&lt;br /&gt;
&lt;br /&gt;
Your skills are needed on November 7th to work the election.  The more computer-literate election judges and technicians we have, the more likely it is that people will be able to exercise their right to vote.&lt;br /&gt;
&lt;blockquote&gt;&lt;br /&gt;
&lt;H1&gt;NIPA  MEETING&lt;/H1&gt;&lt;br /&gt;
&lt;br /&gt;
Network for Interfaith Political Action&lt;br /&gt;
Educate-Organize-Advocate&lt;br /&gt;
&lt;br /&gt;
SATURDAY, OCTOBER 7, 2006&lt;br /&gt;
1:00 â 3:00&lt;br /&gt;
&lt;br /&gt;
Make a difference on November 7th (and beyond)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
         Get the Facts â¦.         Get Involved â¦.     Make a difference!!!!!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
                                        &lt;br /&gt;
Place: Forest Hills Presbyterian Church&lt;br /&gt;
	     3031 Monticello Blvd, Cleveland Heights&lt;br /&gt;
                (Corner of Lee Rd and Monticello)&lt;br /&gt;
          &lt;br /&gt;
Purpose:  Make a difference on November 7th (and beyond).  &lt;br /&gt;
                     This election is too important to be left to chance. &lt;br /&gt;
â¢	Learn about the new voter I.D. requirements&lt;br /&gt;
â¢	Publicize absentee ballot use in your congregation&lt;br /&gt;
â¢	How to avoid voting a âprovisionalâ? ballot&lt;br /&gt;
â¢	Board of Election poll worker recruitment (paid) and other poll worker volunteer opportunities&lt;br /&gt;
â¢	NIPAâs enforcement of the 1993 Voter Registration Act with Cuyahoga County Assistance Agencies&lt;br /&gt;
â¢	Hear success stories of people (like you) making a difference in their congregation and beyond&lt;br /&gt;
&lt;br /&gt;
Questions and Registration:  Susan Alcorn, 440-247-6604&lt;br /&gt;
&lt;/blockquote&gt; 
    </content:encoded>

    <pubDate>Fri, 22 Sep 2006 13:32:07 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/1030-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>
<item>
    <title>Schneier: What the Terrorists Want</title>
    <link>http://jalcorn.net/weblog/archives/1027-Schneier-What-the-Terrorists-Want.html</link>
            <category>Political Rants</category>
            <category>Security</category>
    
    <comments>http://jalcorn.net/weblog/archives/1027-Schneier-What-the-Terrorists-Want.html#comments</comments>
    <wfw:comment>http://jalcorn.net/weblog/wfwcomment.php?cid=1027</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://jalcorn.net/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=1027</wfw:commentRss>
    

    <author>nospam@example.com (JaBbA)</author>
    <content:encoded>
    Bruce Schneier is one of the world&#039;s leading experts on security, the founder of &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5jb3VudGVycGFuZS5jb20v&amp;amp;entry_id=1027&quot; title=&quot;http://www.counterpane.com/&quot;  onmouseover=&quot;window.status=&#039;http://www.counterpane.com/&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;Counterpane Security&lt;/a&gt;, the author of some of my favorite security books: &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5zY2huZWllci5jb20vYm9vay1wcmFjdGljYWwuaHRtbA==&amp;amp;entry_id=1027&quot; title=&quot;http://www.schneier.com/book-practical.html&quot;  onmouseover=&quot;window.status=&#039;http://www.schneier.com/book-practical.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;Practical Cryptography&lt;/a&gt;, &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5zY2huZWllci5jb20vYm9vay1zYW5kbC5odG1s&amp;amp;entry_id=1027&quot; title=&quot;http://www.schneier.com/book-sandl.html&quot;  onmouseover=&quot;window.status=&#039;http://www.schneier.com/book-sandl.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;Secrets and Lies&lt;/a&gt; and, most recently, &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5zY2huZWllci5jb20vYm9vay1iZXlvbmRmZWFyLmh0bWw=&amp;amp;entry_id=1027&quot; title=&quot;http://www.schneier.com/book-beyondfear.html&quot;  onmouseover=&quot;window.status=&#039;http://www.schneier.com/book-beyondfear.html&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot; &gt;Beyond Fear&lt;/a&gt;.  And someone I have had multiple opportunities to sit down with and talk about the state of security, both digital and real-world.&lt;br /&gt;
&lt;br /&gt;
He has long made the point that our government and media are giving the terrorists exactly what they want by engaging in &quot;security theatre&quot;, which has no real effect on safety.   He spells it out again in his newest essay, &lt;a href=&quot;http://jalcorn.net/weblog/exit.php?url=aHR0cDovL3d3dy5zY2huZWllci5jb20vY3J5cHRvLWdyYW0tMDYwOS5odG1sIzE=&amp;amp;entry_id=1027&quot;  onmouseover=&quot;window.status=&#039;http://www.schneier.com/crypto-gram-0609.html#1&#039;;return true;&quot; onmouseout=&quot;window.status=&#039;&#039;;return true;&quot;  title=&quot;CryptoGram&quot;&gt;What the Terrorists Want&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;blockquote&gt;It&#039;s time we calm down and fight terror with anti-terror. This does not mean that we simply roll over and accept terrorism. There are things our government can and should do to fight terrorism, most of them involving intelligence and investigation -- and not focusing on specific plots.&lt;br /&gt;
&lt;br /&gt;
But our job is to remain steadfast in the face of terror, to refuse to be terrorized. Our job is to not panic every time two Muslims stand together checking their watches. There are approximately 1 billion Muslims in the world, a large percentage of them not Arab, and about 320 million Arabs in the Middle East, the overwhelming majority of them not terrorists. Our job is to think critically and rationally, and to ignore the cacophony of other interests trying to use terrorism to advance political careers or increase a television show&#039;s viewership.&lt;br /&gt;
&lt;br /&gt;
The surest defense against terrorism is to refuse to be terrorized. Our job is to recognize that terrorism is just one of the risks we face, and not a particularly common one at that. And our job is to fight those politicians who use fear as an excuse to take away our liberties and promote security theater that wastes money and doesn&#039;t make us any safer. &lt;/blockquote&gt;&lt;br /&gt;
&lt;br /&gt;
Ever since Reagan declared a &quot;War on Drugs&quot; we have gotten used to thinking about this as a war - and, of course, Bush just loves to think about his legacy as a &quot;War President&quot;.  But The Clinton administration had it right - these people aren&#039;t an army, they&#039;re a criminal conspiracy and it is criminal investigation and intelligence work that will finally stop them.&lt;br /&gt;
&lt;br /&gt;
JaBbA says check it out. 
    </content:encoded>

    <pubDate>Fri, 15 Sep 2006 10:37:34 -0400</pubDate>
    <guid isPermaLink="false">http://jalcorn.net/weblog/archives/1027-guid.html</guid>
    <creativeCommons:license>http://creativecommons.org/licenses/by/1.0/</creativeCommons:license>
</item>

</channel>
</rss>