Securosis Blog

Friday Summary: Happy Halloween!

Rich · October 31, 2008

Man, I love Halloween; it is the ultimate hacker holiday. When else do we have an excuse to build home animatronics, scare the pants off people, and pretend to be someone else (outside of a penetration test)? Last year I built something I called “The Hanging Man” using a microcontroller, some windshield wiper motors, wireless sensors, my (basic) home automation system, and streaming audio. When trick or treaters walked up to the house it would trigger a sensor, black out the front of the house,…

State Department Data Theft

Adrian Lane · October 31, 2008

‘This story has it all … theft of State Department data, forged credit cards, multi-government branch conspiracy, and murdered suspects. Sounds like an afternoon soap opera more than a Stolen Passport Data story from the Washington Post:

Attacking The Law With Photing

Rich · October 30, 2008

As a security pro I tend to be a bit paranoid and cynical even outside the domain of technology. Heck, I can’t even get past a nice simple election without picking up on some interesting fraudulent twist.

I was pretty honored a couple months ago when Johnny Long asked me to participate in a new project for Hackers for Charity called The HFC Security Informer. Johnny is a seriously cool guy who founded Hackers for Charity, which provides a mix of services and financial support in underdeveloped countries. I think most geeks that aren’t running evil botnets have a bit of altruism in them, and HFC is a great way we can use our technical backgrounds (and swag) to help out the rougher parts of the…

I’m very excited to announce a new project I’ve been working on for some time with Debix. Yesterday, they released a new study today on child identity theft. I was astounded to discover that on average one out of twenty kids has their identity compromised in some way before they reach adulthood. That’s essentially one kid in every classroom. And those kids had on average almost $12,800 of debt fraudulenly associated with them. Talk about a nightmare to clean up! Anyway, there are more details…

The Skype gods definitely worked against us last night as David Mortman from Debix joined us to to talk about a new study the released on identity theft and children. No, you’re 8 month old is stealing identities like I suspect that creepy kid from the ETrade commercials is, but due to both error and fraud a surprising number of children have financial histories they didn’t know about. We also discuss last week’s Microsoft emergency update, Bono frolicking on MySpace, and the usual TSA foibles.…

I don’t get it. I mean I really don’t get it. I can’t possibly imagine why it isn’t so obvious to everyone else!! Don’t you see what’s happening!!! Soylent Green is QSAs!!!

Picture 2.png

  1. Denial : There is no cloud.

  2. Anger : Why the f&*k is this sales guy trying to sell me a cloud?

I just read over at Computerworld that the TSA will start requiring gender and date of birth when we buy plane tickets. This is part of Secure Flight, and meant to increase the accuracy of matches to the terrorist watch list(s).

Minor Online Banking FAIL?

Rich · October 28, 2008

I was amused today when I logged into my business account bank (Wells Fargo) and they had me set up a new set of security questions. The variety wasn’t bad and the questions were reasonably original. After setting them, I was asked to confirm my contact information.