<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss'><id>tag:blogger.com,1999:blog-23304275</id><updated>2009-09-02T19:53:10.438-07:00</updated><title type='text'>Webproze Labs</title><subtitle type='html'>Information Security News, Developments, and Rants</subtitle><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23304275/posts/default'/><link rel='alternate' type='text/html' href='http://www.webproze.com/default.html'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.webproze.com/atom.xml'/><author><name>Webproze</name><uri>http://www.blogger.com/profile/12580189478906190736</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-23304275.post-1090327586091281765</id><published>2009-09-02T19:53:00.000-07:00</published><updated>2009-09-02T19:53:10.456-07:00</updated><title type='text'>hmm</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.webproze.com/uploaded_images/dogsitting-781845.jpeg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://www.webproze.com/uploaded_images/dogsitting-781844.jpeg" /&gt;&lt;/a&gt;&lt;/div&gt;Is it wrong that I named my fantasy football team "Vick's Dog-sitting Service"?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23304275-1090327586091281765?l=www.webproze.com%2Fdefault.html'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/23304275/1090327586091281765/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=23304275&amp;postID=1090327586091281765' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23304275/posts/default/1090327586091281765'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23304275/posts/default/1090327586091281765'/><link rel='alternate' type='text/html' href='http://www.webproze.com/2009/09/hmm.html' title='hmm'/><author><name>Webproze</name><uri>http://www.blogger.com/profile/12580189478906190736</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='00737990915575806027'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-23304275.post-4682057323806204149</id><published>2008-03-04T07:21:00.001-08:00</published><updated>2008-03-04T07:21:46.205-08:00</updated><title type='text'>Tell me this ain't true</title><content type='html'>&lt;object width="425" height="355"&gt;&lt;param name="movie" value="http://www.youtube.com/v/1LLTsSnGWMI"&gt;&lt;/param&gt;&lt;param name="wmode" value="transparent"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/1LLTsSnGWMI" type="application/x-shockwave-flash" wmode="transparent" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23304275-4682057323806204149?l=www.webproze.com%2Fdefault.html'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/23304275/4682057323806204149/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=23304275&amp;postID=4682057323806204149' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23304275/posts/default/4682057323806204149'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23304275/posts/default/4682057323806204149'/><link rel='alternate' type='text/html' href='http://www.webproze.com/2008/03/tell-me-this-aint-true.html' title='Tell me this ain&apos;t true'/><author><name>Webproze</name><uri>http://www.blogger.com/profile/12580189478906190736</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='00737990915575806027'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-23304275.post-5204309769724835021</id><published>2008-01-09T05:42:00.000-08:00</published><updated>2008-01-09T05:47:39.879-08:00</updated><title type='text'>"Hacker Safe"? I don't think so</title><content type='html'>In the first announced of what I'm sure will be many more, a site experienced a data compromise despite the fact that they subscribe to ScanAlert, a service where the site is scanned daily for vulnerabilities.  BTW, in October, McAfee announced that they would be purchasing ScanAlert.  Coincidence?  I think not.&lt;br /&gt;&lt;br /&gt;You can read more &lt;a href="http://www.networkworld.com/news/2008/010708-hacker-safe-web-site-gets.html"&gt;information here&lt;/a&gt;, but if you're a customer of Geeks.com, you may want to start checking your snail mail for a notification from them about your data being compromised.  You may also want to check your credit card statement on a daily basis. &lt;br /&gt;&lt;br /&gt;Just throwin that out there.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23304275-5204309769724835021?l=www.webproze.com%2Fdefault.html'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/23304275/5204309769724835021/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=23304275&amp;postID=5204309769724835021' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23304275/posts/default/5204309769724835021'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23304275/posts/default/5204309769724835021'/><link rel='alternate' type='text/html' href='http://www.webproze.com/2008/01/hacker-safe-i-dont-think-so.html' title='&quot;Hacker Safe&quot;? I don&apos;t think so'/><author><name>Webproze</name><uri>http://www.blogger.com/profile/12580189478906190736</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='00737990915575806027'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-23304275.post-114174678041006291</id><published>2006-03-07T07:52:00.000-08:00</published><updated>2006-03-07T07:53:00.420-08:00</updated><title type='text'>Run a Mac and think you're safe?</title><content type='html'>Think &lt;a href="http://www.zdnet.com.au/news/security/soa/Mac_OS_X_hacked_in_less_than_30_minutes/0,2000061744,39241748,00.htm"&gt;again&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23304275-114174678041006291?l=www.webproze.com%2Fdefault.html'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/23304275/114174678041006291/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=23304275&amp;postID=114174678041006291' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23304275/posts/default/114174678041006291'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23304275/posts/default/114174678041006291'/><link rel='alternate' type='text/html' href='http://www.webproze.com/2006/03/run-mac-and-think-youre-safe.html' title='Run a Mac and think you&apos;re safe?'/><author><name>Webproze</name><uri>http://www.blogger.com/profile/12580189478906190736</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='00737990915575806027'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-23304275.post-114132665309941800</id><published>2006-03-02T11:10:00.000-08:00</published><updated>2006-03-04T07:39:41.743-08:00</updated><title type='text'>Bad week for CPA firms</title><content type='html'>&lt;a href="http://www.infoworld.com/article/06/02/24/75877_HNmcafeedata_1.html"&gt;Deloitte and Touche&lt;/a&gt; suffered a bit of an image hit when one of their auditors left a CD that held the stock holding information for thousands of &lt;a href="http://software.silicon.com/security/0,39024655,39156741,00.htm"&gt;McAfee&lt;/a&gt; current and former employees.  The data was not encrypted.  Staffers were offered a two-year membership to a credit monitoring program offered by &lt;a href="http://www.experian.com/"&gt;Experian&lt;/a&gt;.&lt;br /&gt;A &lt;a href="http://www.chron.com/disp/story.mpl/headline/metro/3679070.html"&gt;PriceWaterhouseCoopers employee &lt;/a&gt;had a laptop with data from 4000 patients of University of Texas M.D. Anderson Cancer Center.  PWC says that the data was encrypted using a 'sophisticated encryption software'.  (*Probably an Excel spreadsheet with a password on it-jj)&lt;br /&gt;&lt;br /&gt;From personal experience, after having worked for a CPA firm, it's regular practice to have gigabytes of client information on a laptop and not have that data encrypted.  This isn't just something that's happened at the firm I worked, but at several firms that I had interaction with during my tenure there.  Data was frequently shared between the internal auditors and external auditors, and when I would send it encrypted, was told on a regular basis by clients and other auditors as well "Why do you encrypt it, no one else at your firm, outside of your security group does?", or "We don't encrypt stuff we send to you, just send it to me unencrypted (other firms)".&lt;br /&gt;&lt;br /&gt;If you look over the news in the last several years, there are a multitude of cases where data has been stolen from CPA firms or lost by them, thanks to their poor security practices.  If hackers were smart, they'd start targeting the REAL sources of information storage.  You hack one company, you get their data.  You hack a CPA firm, you get hundreds or thousands of companies data.  And no amount of compliance with PCAOB will change that.  Talk about your inmates running the asylum.....&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23304275-114132665309941800?l=www.webproze.com%2Fdefault.html'/&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://www.blogger.com/feeds/23304275/114132665309941800/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='https://www.blogger.com/comment.g?blogID=23304275&amp;postID=114132665309941800' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23304275/posts/default/114132665309941800'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23304275/posts/default/114132665309941800'/><link rel='alternate' type='text/html' href='http://www.webproze.com/2006/03/bad-week-for-cpa-firms.html' title='Bad week for CPA firms'/><author><name>Webproze</name><uri>http://www.blogger.com/profile/12580189478906190736</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='00737990915575806027'/></author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></entry></feed>