<?xml version='1.0' encoding='UTF-8'?><rss xmlns:atom='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' version='2.0'><channel><atom:id>tag:blogger.com,1999:blog-23304275</atom:id><lastBuildDate>Thu, 03 Sep 2009 02:53:10 +0000</lastBuildDate><title>Webproze Labs</title><description>Information Security News, Developments, and Rants</description><link>http://www.webproze.com/default.html</link><managingEditor>noreply@blogger.com (Webproze)</managingEditor><generator>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-23304275.post-1090327586091281765</guid><pubDate>Thu, 03 Sep 2009 02:53:00 +0000</pubDate><atom:updated>2009-09-02T19:53:10.456-07:00</atom:updated><title>hmm</title><description>&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://www.webproze.com/uploaded_images/dogsitting-781845.jpeg" imageanchor="1" style="clear: right; float: right; margin-bottom: 1em; margin-left: 1em;"&gt;&lt;img border="0" src="http://www.webproze.com/uploaded_images/dogsitting-781844.jpeg" /&gt;&lt;/a&gt;&lt;/div&gt;Is it wrong that I named my fantasy football team "Vick's Dog-sitting Service"?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23304275-1090327586091281765?l=www.webproze.com%2Fdefault.html'/&gt;&lt;/div&gt;</description><link>http://www.webproze.com/2009/09/hmm.html</link><author>noreply@blogger.com (Webproze)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-23304275.post-4682057323806204149</guid><pubDate>Tue, 04 Mar 2008 15:21:00 +0000</pubDate><atom:updated>2008-03-04T07:21:46.205-08:00</atom:updated><title>Tell me this ain't true</title><description>&lt;object width="425" height="355"&gt;&lt;param name="movie" value="http://www.youtube.com/v/1LLTsSnGWMI"&gt;&lt;/param&gt;&lt;param name="wmode" value="transparent"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/1LLTsSnGWMI" type="application/x-shockwave-flash" wmode="transparent" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23304275-4682057323806204149?l=www.webproze.com%2Fdefault.html'/&gt;&lt;/div&gt;</description><link>http://www.webproze.com/2008/03/tell-me-this-aint-true.html</link><author>noreply@blogger.com (Webproze)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-23304275.post-5204309769724835021</guid><pubDate>Wed, 09 Jan 2008 13:42:00 +0000</pubDate><atom:updated>2008-01-09T05:47:39.879-08:00</atom:updated><title>"Hacker Safe"? I don't think so</title><description>In the first announced of what I'm sure will be many more, a site experienced a data compromise despite the fact that they subscribe to ScanAlert, a service where the site is scanned daily for vulnerabilities.  BTW, in October, McAfee announced that they would be purchasing ScanAlert.  Coincidence?  I think not.&lt;br /&gt;&lt;br /&gt;You can read more &lt;a href="http://www.networkworld.com/news/2008/010708-hacker-safe-web-site-gets.html"&gt;information here&lt;/a&gt;, but if you're a customer of Geeks.com, you may want to start checking your snail mail for a notification from them about your data being compromised.  You may also want to check your credit card statement on a daily basis. &lt;br /&gt;&lt;br /&gt;Just throwin that out there.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23304275-5204309769724835021?l=www.webproze.com%2Fdefault.html'/&gt;&lt;/div&gt;</description><link>http://www.webproze.com/2008/01/hacker-safe-i-dont-think-so.html</link><author>noreply@blogger.com (Webproze)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-23304275.post-114174678041006291</guid><pubDate>Tue, 07 Mar 2006 15:52:00 +0000</pubDate><atom:updated>2006-03-07T07:53:00.420-08:00</atom:updated><title>Run a Mac and think you're safe?</title><description>Think &lt;a href="http://www.zdnet.com.au/news/security/soa/Mac_OS_X_hacked_in_less_than_30_minutes/0,2000061744,39241748,00.htm"&gt;again&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23304275-114174678041006291?l=www.webproze.com%2Fdefault.html'/&gt;&lt;/div&gt;</description><link>http://www.webproze.com/2006/03/run-mac-and-think-youre-safe.html</link><author>noreply@blogger.com (Webproze)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-23304275.post-114132665309941800</guid><pubDate>Thu, 02 Mar 2006 19:10:00 +0000</pubDate><atom:updated>2006-03-04T07:39:41.743-08:00</atom:updated><title>Bad week for CPA firms</title><description>&lt;a href="http://www.infoworld.com/article/06/02/24/75877_HNmcafeedata_1.html"&gt;Deloitte and Touche&lt;/a&gt; suffered a bit of an image hit when one of their auditors left a CD that held the stock holding information for thousands of &lt;a href="http://software.silicon.com/security/0,39024655,39156741,00.htm"&gt;McAfee&lt;/a&gt; current and former employees.  The data was not encrypted.  Staffers were offered a two-year membership to a credit monitoring program offered by &lt;a href="http://www.experian.com/"&gt;Experian&lt;/a&gt;.&lt;br /&gt;A &lt;a href="http://www.chron.com/disp/story.mpl/headline/metro/3679070.html"&gt;PriceWaterhouseCoopers employee &lt;/a&gt;had a laptop with data from 4000 patients of University of Texas M.D. Anderson Cancer Center.  PWC says that the data was encrypted using a 'sophisticated encryption software'.  (*Probably an Excel spreadsheet with a password on it-jj)&lt;br /&gt;&lt;br /&gt;From personal experience, after having worked for a CPA firm, it's regular practice to have gigabytes of client information on a laptop and not have that data encrypted.  This isn't just something that's happened at the firm I worked, but at several firms that I had interaction with during my tenure there.  Data was frequently shared between the internal auditors and external auditors, and when I would send it encrypted, was told on a regular basis by clients and other auditors as well "Why do you encrypt it, no one else at your firm, outside of your security group does?", or "We don't encrypt stuff we send to you, just send it to me unencrypted (other firms)".&lt;br /&gt;&lt;br /&gt;If you look over the news in the last several years, there are a multitude of cases where data has been stolen from CPA firms or lost by them, thanks to their poor security practices.  If hackers were smart, they'd start targeting the REAL sources of information storage.  You hack one company, you get their data.  You hack a CPA firm, you get hundreds or thousands of companies data.  And no amount of compliance with PCAOB will change that.  Talk about your inmates running the asylum.....&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23304275-114132665309941800?l=www.webproze.com%2Fdefault.html'/&gt;&lt;/div&gt;</description><link>http://www.webproze.com/2006/03/bad-week-for-cpa-firms.html</link><author>noreply@blogger.com (Webproze)</author><thr:total xmlns:thr='http://purl.org/syndication/thread/1.0'>0</thr:total></item></channel></rss>