<?xml version='1.0' encoding='UTF-8'?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-7357937</id><updated>2008-01-16T19:39:01.539-05:00</updated><title type='text'>::PepperTech:: Security Management News Blog</title><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/index.htm'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default?start-index=26&amp;max-results=25'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default'/><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml'/><author><name>avant-garde</name></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>516</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7357937.post-6575474446250885958</id><published>2008-01-16T19:36:00.000-05:00</published><updated>2008-01-16T19:39:01.563-05:00</updated><title type='text'>Last Post... Bye Bye...</title><content type='html'>&lt;span style="font-size:85%;"&gt;It has been a few years since I have been posting to this website. Lately, I have been really busy that I have not had time to focus on this as much as I had hoped. So... I decided to shut this blog down. I will revive it when I am ready again. Thanks, and bye for now.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2008/01/last-post-bye-bye.html' title='Last Post... Bye Bye...'/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/6575474446250885958'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/6575474446250885958'/><author><name>avant-garde</name></author></entry><entry><id>tag:blogger.com,1999:blog-7357937.post-314434214272901465</id><published>2007-10-28T22:51:00.000-04:00</published><updated>2007-10-28T22:53:38.251-04:00</updated><title type='text'>Art.com Hacking</title><content type='html'>&lt;span style="font-size:85%;"&gt;Art.com Inc. said that recently a hacker illegally gained access to some of its customers' names and encrypted credit-card numbers for some transactions made on its Websites from July through September. More details &lt;a href="http://www.marketwatch.com/news/story/artcom-inc-hacker-accessed-some/story.aspx?guid=%7BAF391148%2D394C%2D4ED4%2DB9A0%2D01C7D2451E25%7D&amp;amp;dist=sp_inthis"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2007/10/artcom-hacking.html' title='Art.com Hacking'/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/314434214272901465'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/314434214272901465'/><author><name>avant-garde</name></author></entry><entry><id>tag:blogger.com,1999:blog-7357937.post-1098086679764896</id><published>2007-10-16T10:12:00.000-04:00</published><updated>2007-10-16T10:13:00.342-04:00</updated><title type='text'>Full body scan or "striptease"? </title><content type='html'>&lt;DIV&gt;EPIC (Electronic Privacy Information Center) calls the full-body scans a virtual striptease. However, TSA claims that 79% of the public prefer the full-body scan! For one thing, I do not know where the TSA got the stats, but it appears as though people prefer to be stripteasers than just be padded down. &lt;/DIV&gt;  &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;  &lt;DIV&gt;In all seriousness, I am glad that there are security checks, but are they effective and how does it affect the general traveller in terms of privacy, reasonable comfort and all such feel-good factors? &lt;/DIV&gt;  &lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;  &lt;DIV&gt;</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2007/10/full-body-scan-or-striptease.html' title='Full body scan or &quot;striptease&quot;? '/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/1098086679764896'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/1098086679764896'/><author><name>avant-garde</name></author></entry><entry><id>tag:blogger.com,1999:blog-7357937.post-9155717242682200372</id><published>2007-08-07T08:42:00.000-04:00</published><updated>2007-10-13T16:58:15.831-04:00</updated><title type='text'>Do not hack the hackers</title><content type='html'>&lt;span style="font-size:85%;"&gt;Interesting read from &lt;a href="http://www.forbes.com/home/technology/2007/08/06/security-hacking-challenge-tech-cx_ag_0806toughhack.html"&gt;Forbes &lt;/a&gt;on how hacker's do not want to be threatened.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2007/08/do-not-hack-hackers.html' title='Do not hack the hackers'/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/9155717242682200372'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/9155717242682200372'/><author><name>avant-garde</name></author></entry><entry><id>tag:blogger.com,1999:blog-7357937.post-6051241868547735927</id><published>2007-06-16T11:01:00.001-04:00</published><updated>2007-06-16T11:06:16.777-04:00</updated><title type='text'>Data Privacy Watchdog for India</title><content type='html'>&lt;span style="font-size:85%;"&gt;India does not have strict data privacy laws. This has allowed for a huge number of security breaches in the recent past. Now, India has a self-regulated industry watchdog that is going to oversee data privacy in regards to offshoring. More details on &lt;a href="http://services.silicon.com/bpo/0,3800004865,39167417,00.htm"&gt;silicon.com.&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2007/06/data-privacy-watchdog-for-india.html' title='Data Privacy Watchdog for India'/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/6051241868547735927'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/6051241868547735927'/><author><name>avant-garde</name></author></entry><entry><id>tag:blogger.com,1999:blog-7357937.post-7247971297146235852</id><published>2007-06-16T10:59:00.000-04:00</published><updated>2007-06-16T11:00:41.032-04:00</updated><title type='text'>BBC/Yahoo Hackday</title><content type='html'>&lt;span style="font-size:85%;"&gt;Hackers meet in London for the first BBC/Yahoo hackday. See details &lt;a href="http://news.bbc.co.uk/2/hi/technology/6757361.stm"&gt;here&lt;/a&gt;. &lt;/span&gt;</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2007/06/bbcyahoo-hackday.html' title='BBC/Yahoo Hackday'/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/7247971297146235852'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/7247971297146235852'/><author><name>avant-garde</name></author></entry><entry><id>tag:blogger.com,1999:blog-7357937.post-8784815384366082206</id><published>2007-04-24T13:32:00.000-04:00</published><updated>2007-04-24T13:52:09.659-04:00</updated><title type='text'>Scalability in Compliance</title><content type='html'>Compliance is generally either towards internal requirements or to external regulations. And ideally, since there is no single way to interpret external regulations, corporates create internal interpretations of external regulations. So, in essence, you are complying with a set of internal requirements. That said, the universe of your requirements will be unique to your business. Lot of times you hear corporates whining about too many regulations that they have to comply with. However what one does not realize is the upshot that the ridiculous vagueness presetned by the regulations. That is, it allows you the wiggle room to interpret the regulations in multiple ways. &lt;em&gt;SOX 404 interpretation in corporate A may very well be different from SOX 404 interpretation in corporate B.&lt;/em&gt; You can establish compliance to multiple regulations if you can establish a link between them and a singular industry standard (eg: ISO 17799 or BS 7799) that you want your corporate to follow. Most times, all of the regulations have a common denominator of security requirements that can be addressed by one industry standard. And if you align with the chosen standards, you can easily prove your alignment with the regulatory requirements as long as you have a clear mapping on the regulation to the industry standard and its applicability in your business. In summary, a) if your internal audit and security teams can distill the regulations into a universe of compliance requirements, b) map those requirements into an industry standard such as ISO17799 and c) implement processes in alignment to the established mapping, it would make your life easier, implementation more streamlined and compliance readily scalable to multiple regulations.</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2007/04/scalability-in-compliance.html' title='Scalability in Compliance'/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/8784815384366082206'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/8784815384366082206'/><author><name>avant-garde</name></author></entry><entry><id>tag:blogger.com,1999:blog-7357937.post-4876352105878988375</id><published>2007-03-25T23:46:00.000-04:00</published><updated>2007-03-25T23:50:00.268-04:00</updated><title type='text'>Basic rules while on the net...</title><content type='html'>&lt;span style="font-size:85%;"&gt;Just in line with my last post for a layman user on being safe on the net -- please read &lt;a href="http://news.bbc.co.uk/2/hi/technology/6472723.stm"&gt;this &lt;/a&gt;article.&lt;br /&gt;&lt;br /&gt;An additional note: Change the default user id and password on the router, and if you are an advanced user, put some physical address based filters on it. That way only the router will recognize only those computers that are on your network based on the filter configuration.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2007/03/basic-rules-while-on-net.html' title='Basic rules while on the net...'/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/4876352105878988375'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/4876352105878988375'/><author><name>avant-garde</name></author></entry><entry><id>tag:blogger.com,1999:blog-7357937.post-420434489097915515</id><published>2007-03-25T09:17:00.000-04:00</published><updated>2007-03-25T09:29:30.443-04:00</updated><title type='text'>Gift card float fraud scheme</title><content type='html'>&lt;span style="font-size:85%;"&gt;Customer data stolen from TJ Maxx had been in use in what the investigators call the gift card float scheme. See details here. Some of the things that you should do are 1) always verify your purchases either manually or using a tool like Intuit Quicken or MS Money, 2) notify your card company right away, and invalidate the card, and 3) set up alert on your credit report through. You can get information on all these through your bank. And many banks offer this for free to their clients.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2007/03/gift-card-float-fraud-scheme.html' title='Gift card float fraud scheme'/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/420434489097915515'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/420434489097915515'/><author><name>avant-garde</name></author></entry><entry><id>tag:blogger.com,1999:blog-7357937.post-7174972028747587342</id><published>2007-03-20T18:34:00.000-04:00</published><updated>2007-03-20T18:39:47.896-04:00</updated><title type='text'>Security at offshore vendors</title><content type='html'>With the advent of BPO has arrived a whole set of risks that may not be new, but definitely new in its &lt;em&gt;avatar&lt;/em&gt;. "Just How Secure Are Your Offshore Vendors?" is an interesting article that hits on the key assessment areas that you should focus on at your offshore vendors when they are handling your business processes. The article is available &lt;a href="http://www.outsourcingstrategist.com/articles/secure_offshore_vendors.html"&gt;here&lt;/a&gt;.</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2007/03/security-at-offshore-vendors.html' title='Security at offshore vendors'/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/7174972028747587342'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/7174972028747587342'/><author><name>avant-garde</name></author></entry><entry><id>tag:blogger.com,1999:blog-7357937.post-7060851733666758560</id><published>2007-03-11T22:40:00.000-04:00</published><updated>2007-03-11T23:09:43.210-04:00</updated><title type='text'>Should you stop at complying? Or go on to make money off of compliance??</title><content type='html'>&lt;span style="font-size:85%;"&gt;As I mentioned sometime back - certain companies are having difficulties to get funding for their security and risk initiatives, while some are well funded already. The thing is that off the second lot, only a few use the funding wisely. Its mostly because the second set of companies (of course, fortunate to get funding) set their goals on tactical security and risk initiatives - mainly to comply with internal requirements and/or external regulatory mandates. What they are not realizing is that the funding could be used in a strategic fashion to develop and implement projects that support the organization's risk initiatives and posture. Recommendation: Use the funding wisely... do not stop at compliance. Its only one milestone and there are several others, achieving which, would help your organization in ways unimaginable.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2007/03/should-you-stop-at-complying-or-go-on.html' title='Should you stop at complying? Or go on to make money off of compliance??'/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/7060851733666758560'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/7060851733666758560'/><author><name>avant-garde</name></author></entry><entry><id>tag:blogger.com,1999:blog-7357937.post-542582021775866156</id><published>2007-03-06T07:42:00.001-05:00</published><updated>2007-03-06T07:53:29.091-05:00</updated><title type='text'>Email Retention - lessons from Intel</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.marketwatch.com/"&gt;Marketwatch&lt;/a&gt; reports this morning that Intel may have lost its email pertaining to an antitrust law suit. Apparent from the &lt;a href="http://www.marketwatch.com/news/story/intel-may-have-lost-e-mails/story.aspx?guid=%7BBC9652AA%2D1FE2%2D4001%2DAF05%2D877F25A05DAD%7D&amp;amp;dist=TNMostRead"&gt;article &lt;/a&gt;is a common issue that corporates have today - inconsistent implementation of policies related to security, risk, compliance and governance management. There is something that everyone can learn from this - (i) Get your people (employees) on board with such policies and (ii) tie employee benefits/incentives to the quality of policy implementation, and (iii) continuously measure and monitor  policy performance and adjust accordingly.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2007/03/email-retention-lessons-from-intel_06.html' title='Email Retention - lessons from Intel'/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/542582021775866156'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/542582021775866156'/><author><name>avant-garde</name></author></entry><entry><id>tag:blogger.com,1999:blog-7357937.post-3599521118901212961</id><published>2007-03-02T18:08:00.000-05:00</published><updated>2007-03-02T18:15:55.829-05:00</updated><title type='text'>Real ID Controversy</title><content type='html'>&lt;span style="font-size:85%;"&gt;Yesterday, Secretary Chertoff issued a press conference on the Real ID initiative that has been gaining controversy momentum across the country. Truth be told, I am generally okay with a security-infused ID for every individual. However, I do not understand how the Secretary thought that some information was &lt;strong&gt;not top secret&lt;/strong&gt;. To quote from the press release: &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;"Now here’s how these standards are going to work. It’s very simple and it’s really a matter of common sense. Applicants for driver’s licenses are going to need to bring documents to their state Department of Motor Vehicles offices in order to validate or prove five things: &lt;strong&gt;who they are&lt;/strong&gt;, &lt;strong&gt;what their date of birth is&lt;/strong&gt;, &lt;strong&gt;what their legal status is in the United States&lt;/strong&gt;, &lt;strong&gt;their social security number&lt;/strong&gt; and &lt;strong&gt;their address&lt;/strong&gt;. &lt;strong&gt;None of this stuff is top secret stuff." &lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;When he says that the Dept of Homeland Security will not maintain a master database of personal information on any individuals, I guess its because all personal information is not all that personal anyways! &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Perhaps that was not the intention he had, but definitely requires re-characterization. &lt;/span&gt;</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2007/03/real-id-controversy.html' title='Real ID Controversy'/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/3599521118901212961'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/3599521118901212961'/><author><name>avant-garde</name></author></entry><entry><id>tag:blogger.com,1999:blog-7357937.post-4573628561571450103</id><published>2007-03-02T00:23:00.000-05:00</published><updated>2007-03-02T00:30:25.394-05:00</updated><title type='text'>Buidling a case for security</title><content type='html'>&lt;span style="font-size:85%;"&gt;Couple nights ago, I attended a vendor-sponsored meeting where I heard some attendees talking about their issues in convincing their CFO to spend money on security initiatives. I thought this is a problem that should have a ready response from the security industry. Apparently, not!  So, how do you sell security and ask for a budget?&lt;br /&gt;&lt;br /&gt;The point is: You will never be able to win funding without talking to the CFO in a language that he understands. I believe that connecting the dots between security and risk management is what is key in convincing the CFO to get the money. i.e., lack of security means plenty of risks. And plenty of risks mean exposure that would directly affect the top management. As long as you do not distill your requirements in that fashion, it is not going to work in your favor.  And stop blaming the CFO... he just does not understand what you are talking about!&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2007/03/buidling-case-for-security.html' title='Buidling a case for security'/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/4573628561571450103'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/4573628561571450103'/><author><name>avant-garde</name></author></entry><entry><id>tag:blogger.com,1999:blog-7357937.post-7190330264945041292</id><published>2007-02-22T00:47:00.000-05:00</published><updated>2007-02-22T00:55:40.148-05:00</updated><title type='text'>TJ Maxx security lapse, PCI, and business value</title><content type='html'>&lt;span style="font-size:85%;"&gt;&lt;a href="http://www.eweek.com/article2/0,1759,2097398,00.asp?kc=EWRSS03129TX1K0000614"&gt;eWeek&lt;/a&gt; has an article on TJX and its disclosures coming in bits and pieces. While the article has interviews from several industry fellows that indicate PCI compliance as the"ultimate" solver of the data theft problem, I honestly believe that many corporates use such "compliance" requirements to their disadvantage by being narrowly focused. All they want to do is get it out of their way so they have a stamp or seal from an "approved" PCI vendor. Proving that you meet 12 requirements in 6 areas is not going to bring value, but leveraging that and going the extra mile is what brings value. Hear again for the n'th time: &lt;span style="font-weight: bold;"&gt;"Compliance is not the end game! Leveraging compliance to support your business processes and bringing in shareholder value is"&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2007/02/tj-maxx-security-lapse-pci-and-business.html' title='TJ Maxx security lapse, PCI, and business value'/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/7190330264945041292'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/7190330264945041292'/><author><name>avant-garde</name></author></entry><entry><id>tag:blogger.com,1999:blog-7357937.post-2391983498423475324</id><published>2007-02-20T17:21:00.000-05:00</published><updated>2007-02-20T17:26:01.530-05:00</updated><title type='text'>Stop &amp; Shop Breach</title><content type='html'>&lt;span style="font-size:85%;"&gt;I am little unclear on how the breach was executed! An "investigation" by &lt;a href="http://www.stopandshop.com/"&gt;Stop&amp;Shop &lt;/a&gt;says that no insider participated. However, its a bit strange how this whole thing was carried out. I think its my first time seeing this happen! Perhaps they broke-in prior to wire the ETFs, and started collecting data over a period of time? Would be interesting to watch the progress on this theft! &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;News available on &lt;a href="http://www.boston.com/business/articles/2007/02/19/stop__shop_reports_credit_data_was_stolen/"&gt;Boston Globe&lt;/a&gt;. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2007/02/stop-shop-breach.html' title='Stop &amp; Shop Breach'/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/2391983498423475324'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/2391983498423475324'/><author><name>avant-garde</name></author></entry><entry><id>tag:blogger.com,1999:blog-7357937.post-4408854761333068706</id><published>2007-02-14T22:27:00.000-05:00</published><updated>2007-02-14T22:33:30.003-05:00</updated><title type='text'>Its about time...</title><content type='html'>&lt;span style="font-size:85%;"&gt;PayPal announced the use of authentication tokens. I think PayPal will probably make money on this deal. Imagine 100 million accounts and $5 tokens sold to them! In any case, I think its a positive thing. I am not sure why all the banks have not done that!&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2007/02/its-about-time.html' title='Its about time...'/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/4408854761333068706'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/4408854761333068706'/><author><name>avant-garde</name></author></entry><entry><id>tag:blogger.com,1999:blog-7357937.post-6442744375403937430</id><published>2007-02-10T12:32:00.000-05:00</published><updated>2007-02-08T22:45:02.481-05:00</updated><title type='text'>RSA on Feb 9 2007</title><content type='html'>&lt;span style="font-size:85%;"&gt;Finally, I am home after a week in San Francisco. I attended one session Friday by Ben Rothke. He took the "Stephen Covey" avatar to discuss the 5 habits of enterprises that treat security seriously. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Overall, the conference proved one thing - security is an issue due to:  a) Lack of understanding of the requirements out there, b) People, and c) Processes. There are a ton of technologies out there that will solve a whole bunch of things, but they are defintiely not focusing on the challenges that the customers have. Bleeding edge technology in this industry is good, but not when it does not cater to the customer's real challenges! &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2007/02/rsa-on-feb-9-2007.html' title='RSA on Feb 9 2007'/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/6442744375403937430'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/6442744375403937430'/><author><name>avant-garde</name></author></entry><entry><id>tag:blogger.com,1999:blog-7357937.post-13038673860147199</id><published>2007-02-08T22:41:00.000-05:00</published><updated>2007-02-08T02:10:06.815-05:00</updated><title type='text'>RSA on Feb 8 2007</title><content type='html'>&lt;span style="font-size:85%;"&gt;Today was an alright day at the RSA. A very good presentation on infusing security into SDLC by Jeff Bardin of IBT. If they do have what they presented, I must say that they have a stellar program. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;The highlight of the day for me was the key note by Tom Kelley of IDEO on how we should be innovative! Our industry does support that, but never has promoted as much. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;I am in my hotel room blogging instead of attending the "CodeBreaker Bash Party"... Well, I do have a dinner with my good friends . So I am off to my friends in a bit. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Tomorrow is the last day, and off I go home, back to NYC! &lt;/span&gt;</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2007/02/rsa-on-feb-8-2007.html' title='RSA on Feb 8 2007'/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/13038673860147199'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/13038673860147199'/><author><name>avant-garde</name></author></entry><entry><id>tag:blogger.com,1999:blog-7357937.post-3445037327208104725</id><published>2007-02-08T01:59:00.000-05:00</published><updated>2007-02-07T01:42:35.958-05:00</updated><title type='text'>RSA on Feb 7 2007</title><content type='html'>&lt;span style="font-size:85%;"&gt;The day started off with a session around metrics. So they talked about Risk Circumvention. Interesting concept, but wonder how often that happens! Even if it happens, why would anyone want to re-brand "Risk Elimination" to "Risk Circumvention"? It almost sounds like you are trying to avoid dealing with risk! &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;The highlight was when Oracle's Larry Ellison did not show up for a key note due to flu. It was almost sad to watch everyone walk out of the key note delivered by Larry's VP of IAM. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;In general, I have seen a handful of products around risk management and reporting, but yet to find something thats specific around defining, monitoring and reporting metrics in a proper manner! &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2007/02/rsa-on-feb-7-2007.html' title='RSA on Feb 7 2007'/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/3445037327208104725'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/3445037327208104725'/><author><name>avant-garde</name></author></entry><entry><id>tag:blogger.com,1999:blog-7357937.post-8680959200415895657</id><published>2007-02-07T01:35:00.000-05:00</published><updated>2007-02-07T01:42:31.549-05:00</updated><title type='text'>RSA on Feb 6 2007</title><content type='html'>&lt;span style="font-size:85%;"&gt;So, here I am again at the RSA Conference. This morning started off with the key notes from Bill Gates, Craig Mundie, Art Coviello, Joe Tucci, John Thomson, etc. The theme was pretty consistent with what the industry is doing in terms of networks, data protection, identity management and consumer confidence. Microsoft made some annoucements around their collaboration with Open ID, while EMC announced the buy of an India-based DB encryption startup. The notions around moving from fortress security towards secure coding and passwords to smartcards were high notes. Do you think its time for a certificates/PKI to come back? I am sort of tired of hearing "this is the year of PKI" for the n'th time since I started in security/risk management!&lt;/span&gt;</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2007/02/rsa-on-feb-6-2007.html' title='RSA on Feb 6 2007'/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/8680959200415895657'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/8680959200415895657'/><author><name>avant-garde</name></author></entry><entry><id>tag:blogger.com,1999:blog-7357937.post-7239861562026487693</id><published>2007-02-02T21:16:00.000-05:00</published><updated>2007-02-02T21:34:48.277-05:00</updated><title type='text'>RSA Security Conference 2007</title><content type='html'>&lt;span style="font-size:85%;"&gt;Yes, after a long time, I am back. Work has been busy and hence was out of the loop. I'm glad I'm still part of the first page on Google search! :-)&lt;br /&gt;&lt;br /&gt;Anyways, I'll be at the RSA Conference Feb 5 through 9. I think I decided not to attend the Colin Powell thing, but definitely around for several other Keynotes and sessions. &lt;/span&gt;</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2007/02/rsa-security-conference-2007.html' title='RSA Security Conference 2007'/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/7239861562026487693'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/7239861562026487693'/><author><name>avant-garde</name></author></entry><entry><id>tag:blogger.com,1999:blog-7357937.post-115918747901306052</id><published>2006-09-25T08:31:00.000-04:00</published><updated>2006-09-25T08:31:22.643-04:00</updated><title type='text'>Internet crime to hit homes hard</title><content type='html'>The report by security firm Symantec &lt;a href="http://news.bbc.co.uk/2/hi/technology/5377334.stm"&gt;found &lt;/a&gt;that cyber criminals are targeting home PC owners because they are the easiest to catch out.</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2006/09/internet-crime-to-hit-homes-hard.html' title='Internet crime to hit homes hard'/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/115918747901306052'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/115918747901306052'/><author><name>avant-garde</name></author></entry><entry><id>tag:blogger.com,1999:blog-7357937.post-115573004973167038</id><published>2006-08-16T08:06:00.000-04:00</published><updated>2006-08-16T08:07:29.773-04:00</updated><title type='text'>Hackers target latest Windows fix</title><content type='html'>&lt;a href="http://news.bbc.co.uk/2/hi/technology/4797949.stm"&gt;A worm has been spotted &lt;/a&gt;in the wild that tries to use vulnerabilities to hijack home computers.</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2006/08/hackers-target-latest-windows-fix.html' title='Hackers target latest Windows fix'/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/115573004973167038'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/115573004973167038'/><author><name>avant-garde</name></author></entry><entry><id>tag:blogger.com,1999:blog-7357937.post-115512603199176913</id><published>2006-08-09T08:19:00.000-04:00</published><updated>2006-08-09T08:20:32.026-04:00</updated><title type='text'>Hijacked handheld turns data spy</title><content type='html'>A booby-trapped game of noughts and crosses has been &lt;a href="http://news.bbc.co.uk/2/hi/technology/4775367.stm"&gt;used &lt;/a&gt;to show how a Blackberry can be hijacked to steal confidential data.</content><link rel='alternate' type='text/html' href='http://www.pepperthought.com/PepperTech/2006/08/hijacked-handheld-turns-data-spy.html' title='Hijacked handheld turns data spy'/><link rel='replies' type='application/atom+xml' href='http://www.pepperthought.com/peppertech/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/115512603199176913'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7357937/posts/default/115512603199176913'/><author><name>avant-garde</name></author></entry></feed>
