<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ethical Hacker</title>
	<atom:link href="http://www.the-ethical-hacker.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.the-ethical-hacker.com</link>
	<description>Ethical Hacking news. From hackers, with Love.</description>
	<lastBuildDate>Sat, 25 May 2013 20:05:08 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<item>
		<title>Friday Squid Blogging: Eating Giant Squid</title>
		<link>http://www.the-ethical-hacker.com/2013/05/friday-squid-blogging-eating-giant-squid/</link>
		<comments>http://www.the-ethical-hacker.com/2013/05/friday-squid-blogging-eating-giant-squid/#comments</comments>
		<pubDate>Sat, 25 May 2013 20:05:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[How does he know this? Chris Cosentino, the Bay Area’s &#8220;Offal Chef&#8221; at Incanto in San Francisco and PIGG at Umamicatessen in Los Angeles, opted for the most intimidating choice of all &#8212; giant squid. &#8220;When it comes to underutilized &#8230; <a href="http://www.the-ethical-hacker.com/2013/05/friday-squid-blogging-eating-giant-squid/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>How does he <a href="http://the-ethical-hacker.com/out.php?url=http://www.latimes.com/features/food/dailydish/la-dd-sustainable-seafood-would-you-eat-a-giant-squid-20130521,0,6232880.story" >know this</a>?</p>
<blockquote><p>Chris Cosentino, the Bay Area’s &#8220;Offal Chef&#8221; at Incanto in San Francisco and PIGG at Umamicatessen in Los Angeles, opted for the most intimidating choice of all &#8212; giant squid. &#8220;When it comes to underutilized fish, I wish the public wasn&#8217;t so afraid of different shapes and sizes outside of the standard fillet,&#8221; he said.</p>
<p>&#8220;I think the giant squid is a perfect example of an undervalued ocean creature. Everyone isn&#8217;t afraid of squid but the size and flavor of the giant squid scares people because it has a very intense flavor but it is quite delicious.&#8221;</p></blockquote>
<p>I am surprised he has tasted giant squid?</p>
<p>As usual, you can also use this squid post to talk about the security stories in the news that I haven&#8217;t covered. </p>
<p><b>More</b> <a href="http://the-ethical-hacker.com/out.php?url=http://www.schneier.com/blog/archives/2013/05/friday_squid_bl_377.html" rel='nofollow' target='_blank' >here</a></p>
<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://www.the-ethical-hacker.com/2013/05/friday-squid-blogging-eating-giant-squid/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://www.the-ethical-hacker.com/2013/05/friday-squid-blogging-eating-giant-squid/" data-text="Friday Squid Blogging: Eating Giant Squid"></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ffriday-squid-blogging-eating-giant-squid%2F&amp;linkname=Friday%20Squid%20Blogging%3A%20Eating%20Giant%20Squid" title="Facebook" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_friendfeed" href="http://www.addtoany.com/add_to/friendfeed?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ffriday-squid-blogging-eating-giant-squid%2F&amp;linkname=Friday%20Squid%20Blogging%3A%20Eating%20Giant%20Squid" title="FriendFeed" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/friendfeed.png" width="16" height="16" alt="FriendFeed"/></a><a class="a2a_button_wordpress" href="http://www.addtoany.com/add_to/wordpress?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ffriday-squid-blogging-eating-giant-squid%2F&amp;linkname=Friday%20Squid%20Blogging%3A%20Eating%20Giant%20Squid" title="WordPress" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/wordpress.png" width="16" height="16" alt="WordPress"/></a><a class="a2a_button_blogger_post" href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ffriday-squid-blogging-eating-giant-squid%2F&amp;linkname=Friday%20Squid%20Blogging%3A%20Eating%20Giant%20Squid" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ffriday-squid-blogging-eating-giant-squid%2F&amp;linkname=Friday%20Squid%20Blogging%3A%20Eating%20Giant%20Squid" title="Digg" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_delicious" href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ffriday-squid-blogging-eating-giant-squid%2F&amp;linkname=Friday%20Squid%20Blogging%3A%20Eating%20Giant%20Squid" title="Delicious" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ffriday-squid-blogging-eating-giant-squid%2F&amp;linkname=Friday%20Squid%20Blogging%3A%20Eating%20Giant%20Squid" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ffriday-squid-blogging-eating-giant-squid%2F&amp;title=Friday%20Squid%20Blogging%3A%20Eating%20Giant%20Squid" id="wpa2a_2"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.the-ethical-hacker.com/2013/05/friday-squid-blogging-eating-giant-squid/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Twitter&#8217;s 2FA: SMS Double-Duty</title>
		<link>http://www.the-ethical-hacker.com/2013/05/twitters-2fa-sms-double-duty/</link>
		<comments>http://www.the-ethical-hacker.com/2013/05/twitters-2fa-sms-double-duty/#comments</comments>
		<pubDate>Fri, 24 May 2013 20:05:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Twitter introduced multi-factor login verification on Wednesday. Good news? Well&#8230; that depends. Twitter&#8217;s initial implementation of two-factor authentication (2FA) relies on SMS. But&#8230; Twitter also uses SMS as a way to send and receive Tweets (making use of SMS for &#8230; <a href="http://www.the-ethical-hacker.com/2013/05/twitters-2fa-sms-double-duty/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p> 			 			Twitter introduced <a href="http://the-ethical-hacker.com/out.php?url=https://blog.twitter.com/2013/getting-started-login-verification" >multi-factor login verification</a> on Wednesday. Good news? Well&hellip; that depends.</p>
<p>Twitter&#8217;s initial implementation of two-factor authentication (2FA) relies on SMS.</p>
<p>But&hellip; Twitter also uses SMS as a way to send and receive Tweets (making use of SMS for double-duty: social and security). It&#8217;s possible to &#8220;STOP&#8221; incoming Tweets via SMS, and that makes sense, because people sometimes end up roaming unexpectedly &mdash; and there needs to be a way to stop the SMS feature. Otherwise it could generate a costly bill.</p>
<p>Unfortunately, an attacker could use <a href="http://the-ethical-hacker.com/out.php?url=http://en.wikipedia.org/wiki/SMS_spoofing" >SMS spoofing</a> to disable 2FA if he knows the target&#8217;s phone number.</p>
<p><img width="687" height="159" border="0" src="http://www.f-secure.com/weblog/archives/Twitter_2FA_01.png" alt="Twitter's SMS 2FA" /></p>
<p>We&#8217;ve done some testing.</p>
<p>The STOP command removes the phone number from the account &mdash; and that in turn disables Twitter&#8217;s 2FA.</p>
<p>Not great.</p>
<p>But there&#8217;s an even worse possibility at the moment.</p>
<p>If you don&#8217;t yet have 2FA enabled, an attacker who gains access to your account via spear phishing could enable it for himself!</p>
<p>All that&#8217;s required is random phone number and SMS spoofing the word &#8220;GO&#8221;.</p>
<p><img width="530" height="310" border="0" src="http://www.f-secure.com/weblog/archives/Twitter_2FA_02.png" alt="Twitter's SMS 2FA" /></p>
<p>Then the attacker can enable the account&#8217;s 2FA.</p>
<p><img width="527" height="140" border="0" src="http://www.f-secure.com/weblog/archives/Twitter_2FA_03.png" alt="Twitter's SMS 2FA" /></p>
<p>Then send a message. (The message doesn&#8217;t contain a confirmation code, so it isn&#8217;t really needed.)</p>
<p><img width="500" height="144" border="0" src="http://www.f-secure.com/weblog/archives/Twitter_2FA_04.png" alt="Twitter's SMS 2FA" /></p>
<p>And then click &#8220;Yes&#8221;.</p>
<p><img width="510" height="190" border="0" src="http://www.f-secure.com/weblog/archives/Twitter_2FA_05.png" alt="Twitter's SMS 2FA" /></p>
<p>That&#8217;s it.</p>
<p>No confirmation code is needed to add a number. (Confirmation is required to change the account&#8217;s associated e-mail address.)</p>
<p>This is what the victim will see &mdash; even if they reset the account&#8217;s password.</p>
<p><img width="768" height="289" border="0" src="http://www.f-secure.com/weblog/archives/Twitter_2FA_06.png" alt="Twitter's SMS 2FA" /></p>
<p>The victim will be locked out, and cannot recover the account without Twitter&#8217;s support.</p>
<p>So&hellip; perhaps you should enable your account&#8217;s 2FA &mdash; before somebody else does it for you.</p>
<p>Fortunately, the majority of Twitter users aren&#8217;t big targets. Unfortunately, accounts such as @<a href="http://the-ethical-hacker.com/out.php?url=https://twitter.com/AP" >AP</a> are. And Twitter&#8217;s SMS-based 2FA could be more harm than help when the use case is a dedicated attacker.</p>
<p>Twitter&#8217;s blog post says &#8220;this feature has cleared the way for us to deliver more account security enhancements in the future.&#8221;</p>
<p>Let&#8217;s hope so.
<p>On 24/05/13 At 12:40 PM</p>
<p><b>More</b> <a href="http://the-ethical-hacker.com/out.php?url=http://www.f-secure.com/weblog/archives/00002560.html" rel='nofollow' target='_blank' >here</a></p>
<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://www.the-ethical-hacker.com/2013/05/twitters-2fa-sms-double-duty/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://www.the-ethical-hacker.com/2013/05/twitters-2fa-sms-double-duty/" data-text="Twitter&#8217;s 2FA: SMS Double-Duty"></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ftwitters-2fa-sms-double-duty%2F&amp;linkname=Twitter%E2%80%99s%202FA%3A%20SMS%20Double-Duty" title="Facebook" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_friendfeed" href="http://www.addtoany.com/add_to/friendfeed?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ftwitters-2fa-sms-double-duty%2F&amp;linkname=Twitter%E2%80%99s%202FA%3A%20SMS%20Double-Duty" title="FriendFeed" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/friendfeed.png" width="16" height="16" alt="FriendFeed"/></a><a class="a2a_button_wordpress" href="http://www.addtoany.com/add_to/wordpress?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ftwitters-2fa-sms-double-duty%2F&amp;linkname=Twitter%E2%80%99s%202FA%3A%20SMS%20Double-Duty" title="WordPress" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/wordpress.png" width="16" height="16" alt="WordPress"/></a><a class="a2a_button_blogger_post" href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ftwitters-2fa-sms-double-duty%2F&amp;linkname=Twitter%E2%80%99s%202FA%3A%20SMS%20Double-Duty" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ftwitters-2fa-sms-double-duty%2F&amp;linkname=Twitter%E2%80%99s%202FA%3A%20SMS%20Double-Duty" title="Digg" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_delicious" href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ftwitters-2fa-sms-double-duty%2F&amp;linkname=Twitter%E2%80%99s%202FA%3A%20SMS%20Double-Duty" title="Delicious" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ftwitters-2fa-sms-double-duty%2F&amp;linkname=Twitter%E2%80%99s%202FA%3A%20SMS%20Double-Duty" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ftwitters-2fa-sms-double-duty%2F&amp;title=Twitter%E2%80%99s%202FA%3A%20SMS%20Double-Duty" id="wpa2a_4"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.the-ethical-hacker.com/2013/05/twitters-2fa-sms-double-duty/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Report on Teens, Social Media, and Privacy</title>
		<link>http://www.the-ethical-hacker.com/2013/05/new-report-on-teens-social-media-and-privacy/</link>
		<comments>http://www.the-ethical-hacker.com/2013/05/new-report-on-teens-social-media-and-privacy/#comments</comments>
		<pubDate>Fri, 24 May 2013 20:05:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Interesting report from the From the Pew Internet and American Life Project: Teens are sharing more information about themselves on their social media profiles than they did when we last surveyed in 2006: 91% post a photo of themselves, up &#8230; <a href="http://www.the-ethical-hacker.com/2013/05/new-report-on-teens-social-media-and-privacy/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p><a href="http://the-ethical-hacker.com/out.php?url=http://www.pewinternet.org/Reports/2013/Teens-Social-Media-And-Privacy.aspx" >Interesting</a> report from the From the Pew Internet and American Life Project:</p>
<blockquote><p>Teens are sharing more information about themselves on their social media profiles than they did when we last surveyed in 2006:</p>
<ul>
<li>91% post a photo of themselves, up from 79% in 2006.</p>
<li>71% post their school name, up from 49%.
<li>71% post the city or town where they live, up from 61%.
<li>53% post their email address, up from 29%.
<li>20% post their cell phone number, up from 2%.</ul>
<p>60% of teen Facebook users set their Facebook profiles to private (friends only), and most report high levels of confidence in their ability to manage their settings.</p></blockquote>
<p>danah boyd <a href="http://the-ethical-hacker.com/out.php?url=http://www.zephoria.org/thoughts/archives/2013/05/22/pew-race-privacy.html" >points out</a> something interesting in the data:</p>
<blockquote><p>My favorite finding of Pew&#8217;s is that 58% of teens cloak their messages either through inside jokes or other obscure references, with more older teens (62%) engaging in this practice than younger teens (46%)&#8230;.</p>
<p>While adults are often anxious about shared data that might be used by government agencies, advertisers, or evil older men, teens are much more attentive to those who hold immediate power over them &#8212; parents, teachers, college admissions officers, army recruiters, etc. To adults, services like Facebook that may seem &#8220;private&#8221; because you can use privacy tools, but they don&#8217;t feel that way to youth who feel like their privacy is invaded on a daily basis. (This, btw, is part of why teens feel like Twitter is more intimate than Facebook. And why you see data like Pew&#8217;s that show that teens on Facebook have, on average 300 friends while, on Twitter, they have 79 friends.) Most teens aren&#8217;t worried about strangers; they&#8217;re worried about getting in trouble.</p>
<p>Over the last few years, I&#8217;ve watched as teens have given up on controlling access to content. It&#8217;s too hard, too frustrating, and technology simply can&#8217;t fix the power issues. Instead, what they&#8217;ve been doing is focusing on controlling access to meaning. A comment might look like it means one thing, when in fact it means something quite different. By cloaking their accessible content, teens reclaim power over those who they know who are surveilling them. This practice is still only really emerging en masse, so I was delighted that Pew could put numbers to it. I should note that, as Instagram grows, I&#8217;m seeing more and more of this. A picture of a donut may not be about a donut. While adults worry about how teens&#8217; demographic data might be used, teens are becoming much more savvy at finding ways to encode their content and achieve privacy in public.</p></blockquote>
<p><b>More</b> <a href="http://the-ethical-hacker.com/out.php?url=http://www.schneier.com/blog/archives/2013/05/new_report_on_t_1.html" rel='nofollow' target='_blank' >here</a></p>
<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://www.the-ethical-hacker.com/2013/05/new-report-on-teens-social-media-and-privacy/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://www.the-ethical-hacker.com/2013/05/new-report-on-teens-social-media-and-privacy/" data-text="New Report on Teens, Social Media, and Privacy"></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fnew-report-on-teens-social-media-and-privacy%2F&amp;linkname=New%20Report%20on%20Teens%2C%20Social%20Media%2C%20and%20Privacy" title="Facebook" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_friendfeed" href="http://www.addtoany.com/add_to/friendfeed?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fnew-report-on-teens-social-media-and-privacy%2F&amp;linkname=New%20Report%20on%20Teens%2C%20Social%20Media%2C%20and%20Privacy" title="FriendFeed" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/friendfeed.png" width="16" height="16" alt="FriendFeed"/></a><a class="a2a_button_wordpress" href="http://www.addtoany.com/add_to/wordpress?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fnew-report-on-teens-social-media-and-privacy%2F&amp;linkname=New%20Report%20on%20Teens%2C%20Social%20Media%2C%20and%20Privacy" title="WordPress" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/wordpress.png" width="16" height="16" alt="WordPress"/></a><a class="a2a_button_blogger_post" href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fnew-report-on-teens-social-media-and-privacy%2F&amp;linkname=New%20Report%20on%20Teens%2C%20Social%20Media%2C%20and%20Privacy" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fnew-report-on-teens-social-media-and-privacy%2F&amp;linkname=New%20Report%20on%20Teens%2C%20Social%20Media%2C%20and%20Privacy" title="Digg" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_delicious" href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fnew-report-on-teens-social-media-and-privacy%2F&amp;linkname=New%20Report%20on%20Teens%2C%20Social%20Media%2C%20and%20Privacy" title="Delicious" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fnew-report-on-teens-social-media-and-privacy%2F&amp;linkname=New%20Report%20on%20Teens%2C%20Social%20Media%2C%20and%20Privacy" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fnew-report-on-teens-social-media-and-privacy%2F&amp;title=New%20Report%20on%20Teens%2C%20Social%20Media%2C%20and%20Privacy" id="wpa2a_6"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.the-ethical-hacker.com/2013/05/new-report-on-teens-social-media-and-privacy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Training Baggage Screeners</title>
		<link>http://www.the-ethical-hacker.com/2013/05/training-baggage-screeners/</link>
		<comments>http://www.the-ethical-hacker.com/2013/05/training-baggage-screeners/#comments</comments>
		<pubDate>Fri, 24 May 2013 20:05:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[The research in G. Giguère and B.C. Love, &#8220;Limits in decision making arise from limits in memory retrieval,&#8221; Proceedings of the National Academy of Sciences v. 19 (2013) has applications in training airport baggage screeners. Abstract: Some decisions, such as &#8230; <a href="http://www.the-ethical-hacker.com/2013/05/training-baggage-screeners/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>The <a href="http://the-ethical-hacker.com/out.php?url=http://www.pnas.org/content/110/19/7613.short?rss=1" >research</a> in G. Giguère and B.C. Love, &#8220;Limits in decision making arise from limits in memory retrieval,&#8221; <i>Proceedings of the National Academy of Sciences</i> v. 19 (2013) has applications in training airport baggage screeners.</p>
<blockquote><p><b>Abstract</b>:  Some decisions, such as predicting the winner of a baseball game, are challenging in part because outcomes are probabilistic. When making such decisions, one view is that humans stochastically and selectively retrieve a small set of relevant memories that provides evidence for competing options. We show that optimal performance at test is impossible when retrieving information in this fashion, no matter how extensive training is, because limited retrieval introduces noise into the decision process that cannot be overcome. One implication is that people should be more accurate in predicting future events when trained on idealized rather than on the actual distributions of items. In other words, we predict the best way to convey information to people is to present it in a distorted, idealized form. Idealization of training distributions is predicted to reduce the harmful noise induced by immutable bottlenecks in people’s memory retrieval processes. In contrast, machine learning systems that selectively weight (i.e., retrieve) all training examples at test should not benefit from idealization. These conjectures are strongly supported by several studies and supporting analyses. Unlike machine systems, people’s test performance on a target distribution is higher when they are trained on an idealized version of the distribution rather than on the actual target distribution. Optimal machine classifiers modified to selectively and stochastically sample from memory match the pattern of human performance. These results suggest firm limits on human rationality and have broad implications for how to train humans tasked with important classification decisions, such as radiologists, baggage screeners, intelligence analysts, and gamblers.</p></blockquote>
<p><b>More</b> <a href="http://the-ethical-hacker.com/out.php?url=http://www.schneier.com/blog/archives/2013/05/training_baggag.html" rel='nofollow' target='_blank' >here</a></p>
<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://www.the-ethical-hacker.com/2013/05/training-baggage-screeners/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://www.the-ethical-hacker.com/2013/05/training-baggage-screeners/" data-text="Training Baggage Screeners"></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ftraining-baggage-screeners%2F&amp;linkname=Training%20Baggage%20Screeners" title="Facebook" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_friendfeed" href="http://www.addtoany.com/add_to/friendfeed?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ftraining-baggage-screeners%2F&amp;linkname=Training%20Baggage%20Screeners" title="FriendFeed" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/friendfeed.png" width="16" height="16" alt="FriendFeed"/></a><a class="a2a_button_wordpress" href="http://www.addtoany.com/add_to/wordpress?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ftraining-baggage-screeners%2F&amp;linkname=Training%20Baggage%20Screeners" title="WordPress" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/wordpress.png" width="16" height="16" alt="WordPress"/></a><a class="a2a_button_blogger_post" href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ftraining-baggage-screeners%2F&amp;linkname=Training%20Baggage%20Screeners" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ftraining-baggage-screeners%2F&amp;linkname=Training%20Baggage%20Screeners" title="Digg" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_delicious" href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ftraining-baggage-screeners%2F&amp;linkname=Training%20Baggage%20Screeners" title="Delicious" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ftraining-baggage-screeners%2F&amp;linkname=Training%20Baggage%20Screeners" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ftraining-baggage-screeners%2F&amp;title=Training%20Baggage%20Screeners" id="wpa2a_8"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.the-ethical-hacker.com/2013/05/training-baggage-screeners/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fake Squirrel Mail emails</title>
		<link>http://www.the-ethical-hacker.com/2013/05/fake-squirrel-mail-emails/</link>
		<comments>http://www.the-ethical-hacker.com/2013/05/fake-squirrel-mail-emails/#comments</comments>
		<pubDate>Thu, 23 May 2013 23:05:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[&#160; Text of email: “Dear E-Mail User Due to the package compromise of 1.4.11,1.4.12 and 1.4.13, we are forced to release 1.4.15 to ensure no confusions. While initial review didn&#39;t uncover a need for concern, several proof of concepts show &#8230; <a href="http://www.the-ethical-hacker.com/2013/05/fake-squirrel-mail-emails/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p><a href="http://the-ethical-hacker.com/out.php?url=http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/0172.image_5F00_1A4C8BFD.png" ><img title="image" style="border-top:0px;border-right:0px;background-image:none;border-bottom:0px;float:left;padding-top:0px;padding-left:0px;margin:10px 10px 0px 0px;border-left:0px;display:inline;padding-right:0px;" border="0" alt="image" align="left" src="http://msmvps.com/cfs-file.ashx/__key/CommunityServer.Blogs.Components.WeblogFiles/spywaresucks.metablogapi/5355.image_5F00_thumb_5F00_429BBE51.png" width="555" height="240" /></a></p>
<p>&#160;</p>
<p>Text of email:</p>
<p>“<em>Dear E-Mail User     <br />Due to the package compromise of 1.4.11,1.4.12 and 1.4.13, we are forced to release 1.4.15 to ensure no confusions. While initial review didn&#39;t uncover a need for concern, several proof of concepts show that the package alterations introduce a high risk security issue, allowing remote inclusion of files. These changes would allow a remote user the ability to execute exploit code on a victim machine, without any user interaction on the victim&#39;s server. This could grant the attacker the ability to deploy further code on the victim&#39;s server.      <br />So upgrade to&#160; Squirrel Mail Development Team by&#160; click Squirrel Mail Login SquirrelMail 1.4.15 Released      <br />We STRONGLY advise all users of 1.4.11, 1.4.12 and 1.4.13 upgrade immediately.</em>”</p>
<p>The page, when I looked at it anyway, didn’t contain any exploits. It&#39;s a simple email address/password harvest (of course very valuable to spammers).&#160; Of course, you should still stay away from the page. It’s behavior could change at any moment (or even change depending on your IP address, or browser used, or time of date or who knows what…)</p>
<div style="clear:both;"></div>
<p><img src="http://msmvps.com/aggbug.aspx?PostID=1831339" width="1" height="1"><img src="http://feeds.feedburner.com/~r/SpywareSucks/~4/kUp83xG6dnI" height="1" width="1"/></p>
<p><b>More</b> <a href="http://the-ethical-hacker.com/out.php?url=http://feedproxy.google.com/~r/SpywareSucks/~3/kUp83xG6dnI/1831339.aspx" rel='nofollow' target='_blank' >here</a></p>
<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://www.the-ethical-hacker.com/2013/05/fake-squirrel-mail-emails/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://www.the-ethical-hacker.com/2013/05/fake-squirrel-mail-emails/" data-text="Fake Squirrel Mail emails"></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ffake-squirrel-mail-emails%2F&amp;linkname=Fake%20Squirrel%20Mail%20emails" title="Facebook" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_friendfeed" href="http://www.addtoany.com/add_to/friendfeed?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ffake-squirrel-mail-emails%2F&amp;linkname=Fake%20Squirrel%20Mail%20emails" title="FriendFeed" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/friendfeed.png" width="16" height="16" alt="FriendFeed"/></a><a class="a2a_button_wordpress" href="http://www.addtoany.com/add_to/wordpress?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ffake-squirrel-mail-emails%2F&amp;linkname=Fake%20Squirrel%20Mail%20emails" title="WordPress" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/wordpress.png" width="16" height="16" alt="WordPress"/></a><a class="a2a_button_blogger_post" href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ffake-squirrel-mail-emails%2F&amp;linkname=Fake%20Squirrel%20Mail%20emails" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ffake-squirrel-mail-emails%2F&amp;linkname=Fake%20Squirrel%20Mail%20emails" title="Digg" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_delicious" href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ffake-squirrel-mail-emails%2F&amp;linkname=Fake%20Squirrel%20Mail%20emails" title="Delicious" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ffake-squirrel-mail-emails%2F&amp;linkname=Fake%20Squirrel%20Mail%20emails" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Ffake-squirrel-mail-emails%2F&amp;title=Fake%20Squirrel%20Mail%20emails" id="wpa2a_10"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.the-ethical-hacker.com/2013/05/fake-squirrel-mail-emails/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>One-Shot vs. Iterated Prisoner&#8217;s Dilemma</title>
		<link>http://www.the-ethical-hacker.com/2013/05/one-shot-vs-iterated-prisoners-dilemma/</link>
		<comments>http://www.the-ethical-hacker.com/2013/05/one-shot-vs-iterated-prisoners-dilemma/#comments</comments>
		<pubDate>Thu, 23 May 2013 20:05:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[This post by Aleatha Parker-Wood is very applicable to the things I wrote in Liars &#038; Outliers: A lot of fundamental social problems can be modeled as a disconnection between people who believe (correctly or incorrectly) that they are playing &#8230; <a href="http://www.the-ethical-hacker.com/2013/05/one-shot-vs-iterated-prisoners-dilemma/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>This <a href="http://the-ethical-hacker.com/out.php?url=https://plus.google.com/107475727645912993113/posts/3BVKXUhqSrV" >post</a> by Aleatha Parker-Wood is very applicable to the things I wrote in <i>Liars &#038; Outliers</i>:</p>
<blockquote><p>A lot of fundamental social problems can be modeled as a disconnection between people who believe (correctly or incorrectly) that they are playing a non-iterated game (in the game theory sense of the word), and people who believe that (correctly or incorrectly) that they are playing an iterated game.</p>
<p>For instance, mechanisms such as reputation mechanisms, ostracism, shaming, etc., are all predicated on the idea that the person you&#8217;re shaming will reappear and have further interactions with the group.  Legal punishment is only useful if you can catch the person, and if the cost of the punishment is more than the benefit of the crime.</p>
<p>If it is possible to act as if the game you are playing is a one-shot game (for instance, you have a very large population to hide in, you don&#8217;t need to ever interact with people again, or you can be anonymous), your optimal strategies are going to be different than if you will have to play the game many times, and live with the legal or social consequences of your actions. If you can make enough money as CEO to retire immediately, you may choose to do so, even if you&#8217;re so terrible at running the company that no one will ever hire you again.</p>
<p>Social cohesion can be thought of as a manifestation of how &#8220;iterated&#8221; people feel their interactions are, how likely they are to interact with the same people again and again and  have to deal with long term consequences of locally optimal choices, or whether they feel they can &#8220;opt out&#8221; of consequences of interacting with some set of people in a poor way.</p></blockquote>
<p><b>More</b> <a href="http://the-ethical-hacker.com/out.php?url=http://www.schneier.com/blog/archives/2013/05/one-shot_vs_ite.html" rel='nofollow' target='_blank' >here</a></p>
<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://www.the-ethical-hacker.com/2013/05/one-shot-vs-iterated-prisoners-dilemma/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://www.the-ethical-hacker.com/2013/05/one-shot-vs-iterated-prisoners-dilemma/" data-text="One-Shot vs. Iterated Prisoner&#8217;s Dilemma"></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fone-shot-vs-iterated-prisoners-dilemma%2F&amp;linkname=One-Shot%20vs.%20Iterated%20Prisoner%E2%80%99s%20Dilemma" title="Facebook" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_friendfeed" href="http://www.addtoany.com/add_to/friendfeed?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fone-shot-vs-iterated-prisoners-dilemma%2F&amp;linkname=One-Shot%20vs.%20Iterated%20Prisoner%E2%80%99s%20Dilemma" title="FriendFeed" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/friendfeed.png" width="16" height="16" alt="FriendFeed"/></a><a class="a2a_button_wordpress" href="http://www.addtoany.com/add_to/wordpress?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fone-shot-vs-iterated-prisoners-dilemma%2F&amp;linkname=One-Shot%20vs.%20Iterated%20Prisoner%E2%80%99s%20Dilemma" title="WordPress" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/wordpress.png" width="16" height="16" alt="WordPress"/></a><a class="a2a_button_blogger_post" href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fone-shot-vs-iterated-prisoners-dilemma%2F&amp;linkname=One-Shot%20vs.%20Iterated%20Prisoner%E2%80%99s%20Dilemma" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fone-shot-vs-iterated-prisoners-dilemma%2F&amp;linkname=One-Shot%20vs.%20Iterated%20Prisoner%E2%80%99s%20Dilemma" title="Digg" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_delicious" href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fone-shot-vs-iterated-prisoners-dilemma%2F&amp;linkname=One-Shot%20vs.%20Iterated%20Prisoner%E2%80%99s%20Dilemma" title="Delicious" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fone-shot-vs-iterated-prisoners-dilemma%2F&amp;linkname=One-Shot%20vs.%20Iterated%20Prisoner%E2%80%99s%20Dilemma" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fone-shot-vs-iterated-prisoners-dilemma%2F&amp;title=One-Shot%20vs.%20Iterated%20Prisoner%E2%80%99s%20Dilemma" id="wpa2a_12"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.the-ethical-hacker.com/2013/05/one-shot-vs-iterated-prisoners-dilemma/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mac Spyware Bait: Lebenslauf für Praktitkum</title>
		<link>http://www.the-ethical-hacker.com/2013/05/mac-spyware-bait-lebenslauf-fur-praktitkum/</link>
		<comments>http://www.the-ethical-hacker.com/2013/05/mac-spyware-bait-lebenslauf-fur-praktitkum/#comments</comments>
		<pubDate>Thu, 23 May 2013 20:05:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[As a follow up to yesterday&#8217;s Kumar in the Mac post&#8230; have you received e-mail attachments such as this? Attachments: &#160;&#160;&#8226;&#160;&#160;Christmas_Card.app.zip&#160;&#160;&#8226;&#160;&#160;Content_for_Article.app.zip&#160;&#160;&#8226;&#160;&#160;Content_of_article_for_[NAME REMOVED].app.zip&#160;&#160;&#8226;&#160;&#160;Interview_Venue_and_Questions.zip&#160;&#160;&#8226;&#160;&#160;Lebenslauf_für_Praktitkum.zip If so, you may be the target of a spear phishing campaign designed to install a spyware on &#8230; <a href="http://www.the-ethical-hacker.com/2013/05/mac-spyware-bait-lebenslauf-fur-praktitkum/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>As a follow up to yesterday&#8217;s <a href="http://the-ethical-hacker.com/out.php?url=http://www.f-secure.com/weblog/archives/00002558.html" rel="nofollow" target="_blank" >Kumar in the Mac</a> post&hellip; have you received e-mail attachments such as this?</p>
<p><img width="768" height="350" border="0" src="http://www.f-secure.com/weblog/archives/lebenslauf_fur_praktitkum.png" alt="Lebenslauf f&#xfc;r Praktitkum"/></p>
<p>Attachments:</p>
<p>&nbsp;&nbsp;&bull;&nbsp;&nbsp;Christmas_Card.app.zip<br />&nbsp;&nbsp;&bull;&nbsp;&nbsp;Content_for_Article.app.zip<br />&nbsp;&nbsp;&bull;&nbsp;&nbsp;Content_of_article_for_[NAME REMOVED].app.zip<br />&nbsp;&nbsp;&bull;&nbsp;&nbsp;Interview_Venue_and_Questions.zip<br />&nbsp;&nbsp;&bull;&nbsp;&nbsp;Lebenslauf_für_Praktitkum.zip</p>
<p>If so, you may be the target of a spear phishing campaign designed to install a spyware on your Mac.</p>
<p>Here&#8217;s a list of binaries signed by Apple Developer &#8220;Rajinder Kumar&#8221;.</p>
<p>Detected as Trojan-Spy:OSX/HackBack.B:</p>
<p>&nbsp;&nbsp;&bull;&nbsp;&nbsp;1eedde872cc14492b2e6570229c0f9bc54b3f258<br />&nbsp;&nbsp;&bull;&nbsp;&nbsp;6737d668487000207ce6522ea2b32c7e0bd0b7cb<br />&nbsp;&nbsp;&bull;&nbsp;&nbsp;a2b8e636eb4930e4bdd3a6c05348da3205b5e8e0<br />&nbsp;&nbsp;&bull;&nbsp;&nbsp;505e2e25909710a96739ba16b99201cc60521af9<br />&nbsp;&nbsp;&bull;&nbsp;&nbsp;45a4b01ef316fa79c638cb8c28d288996fd9b95a<br />&nbsp;&nbsp;&bull;&nbsp;&nbsp;290898b23a85bcd7747589d6f072a844e11eec65 &mdash; mentioned in yesterday&#8217;s post.</p>
<p>Detected as Backdoor:OSX/KitM.A (includes screenshot feature):</p>
<p>&nbsp;&nbsp;&bull;&nbsp;&nbsp;4395a2da164e09721700815ea3f816cddb9d676e</p>
<p>Though the spear phishing payloads are not particularly &#8220;sophisticated&#8221;, the campaign&#8217;s use of German localization and the target&#8217;s name (removed in the example above) does indicate the attackers have done some homework.</p>
<p>Be vigilant.</p>
<p>More information:<br /><a href="http://the-ethical-hacker.com/out.php?url=http://www.f-secure.com/weblog/archives/00002554.html" rel="nofollow" target="_blank" >Mac Spyware Found at Oslo Freedom Forum</a><br /><a href="http://the-ethical-hacker.com/out.php?url=http://www.f-secure.com/weblog/archives/00002557.html" rel="nofollow" target="_blank" >Big Hangover</a>
<p>On 23/05/13 At 10:12 AM</p>
<p><b>More</b> <a href="http://the-ethical-hacker.com/out.php?url=http://www.f-secure.com/weblog/archives/00002559.html" rel='nofollow' target='_blank' >here</a></p>
<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://www.the-ethical-hacker.com/2013/05/mac-spyware-bait-lebenslauf-fur-praktitkum/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://www.the-ethical-hacker.com/2013/05/mac-spyware-bait-lebenslauf-fur-praktitkum/" data-text="Mac Spyware Bait: Lebenslauf für Praktitkum"></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fmac-spyware-bait-lebenslauf-fur-praktitkum%2F&amp;linkname=Mac%20Spyware%20Bait%3A%20Lebenslauf%20f%C3%BCr%20Praktitkum" title="Facebook" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_friendfeed" href="http://www.addtoany.com/add_to/friendfeed?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fmac-spyware-bait-lebenslauf-fur-praktitkum%2F&amp;linkname=Mac%20Spyware%20Bait%3A%20Lebenslauf%20f%C3%BCr%20Praktitkum" title="FriendFeed" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/friendfeed.png" width="16" height="16" alt="FriendFeed"/></a><a class="a2a_button_wordpress" href="http://www.addtoany.com/add_to/wordpress?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fmac-spyware-bait-lebenslauf-fur-praktitkum%2F&amp;linkname=Mac%20Spyware%20Bait%3A%20Lebenslauf%20f%C3%BCr%20Praktitkum" title="WordPress" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/wordpress.png" width="16" height="16" alt="WordPress"/></a><a class="a2a_button_blogger_post" href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fmac-spyware-bait-lebenslauf-fur-praktitkum%2F&amp;linkname=Mac%20Spyware%20Bait%3A%20Lebenslauf%20f%C3%BCr%20Praktitkum" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fmac-spyware-bait-lebenslauf-fur-praktitkum%2F&amp;linkname=Mac%20Spyware%20Bait%3A%20Lebenslauf%20f%C3%BCr%20Praktitkum" title="Digg" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_delicious" href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fmac-spyware-bait-lebenslauf-fur-praktitkum%2F&amp;linkname=Mac%20Spyware%20Bait%3A%20Lebenslauf%20f%C3%BCr%20Praktitkum" title="Delicious" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fmac-spyware-bait-lebenslauf-fur-praktitkum%2F&amp;linkname=Mac%20Spyware%20Bait%3A%20Lebenslauf%20f%C3%BCr%20Praktitkum" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fmac-spyware-bait-lebenslauf-fur-praktitkum%2F&amp;title=Mac%20Spyware%20Bait%3A%20Lebenslauf%20f%C3%BCr%20Praktitkum" id="wpa2a_14"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.the-ethical-hacker.com/2013/05/mac-spyware-bait-lebenslauf-fur-praktitkum/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8220;The Global Cyber Game&#8221;</title>
		<link>http://www.the-ethical-hacker.com/2013/05/the-global-cyber-game/</link>
		<comments>http://www.the-ethical-hacker.com/2013/05/the-global-cyber-game/#comments</comments>
		<pubDate>Wed, 22 May 2013 20:05:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[This 127-page report was just published by the UK Defence Academy. I have not read it yet, but it looks really interesting. Executive Summary: This report presents a systematic way of thinking about cyberpower and its use by a variety &#8230; <a href="http://www.the-ethical-hacker.com/2013/05/the-global-cyber-game/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>This 127-page <a href="http://the-ethical-hacker.com/out.php?url=http://www.da.mod.uk/publications/library/technology/20130508-Cyber_report_final_U.pdf/view" >report</a> was just published by the UK Defence Academy.  I have not read it yet, but it looks really interesting.</p>
<blockquote><p><b>Executive Summary</b>:  This report presents a systematic way of thinking about cyberpower and its use by a variety of global players. The urgency of addressing cyberpower in this way is a consequence of the very high value of the Internet and the hazards of its current militarization.</p>
<p>Cyberpower and cyber security are conceptualized as a &#8217;Global Game&#8217; with a novel &#8217;Cyber Gameboard&#8217; consisting of a nine-cell grid. The horizontal direction on the grid is divided into three columns representing aspects of information (i.e. cyber): connection, computation and cognition. The vertical direction on the grid is divided into three rows representing types of power: coercion, co-option, and cooperation. The nine cells of the grid represent all the possible combinations of power and information, that is, forms of cyberpower.</p>
<p>The Cyber Gameboard itself is also an abstract representation of the surface of cyberspace, or C-space as defined in this report. C-space is understood as a networked medium capable of conveying various combinations of power and information to produce effects in physical or &#8217;flow space,&#8217; referred to as F-space in this report. Game play is understood as the projection via C-space of a cyberpower capability existing in any one cell of the gameboard to produce an effect in F-space vis-a-vis another player in any other cell of the gameboard. By default, the Cyber Game is played either actively or passively by all those using network connected computers. The players include states, businesses, NGOs, individuals, non-state political groups, and organized crime, among others. Each player is seen as having a certain level of cyberpower when its capability in each cell is summed across the whole board. In general states have the most cyberpower.</p>
<p>The possible future path of the game is depicted by two scenarios, <i>N-topia</i> and <i>N-crash</i>. These are the stakes for which the Cyber Game is played. <i>N-topia</i> represents the upside potential of the game, in which the full value of a globally connected knowledge society is realized. <i>N-crash</i> represents the downside potential, in which militarization and fragmentation of the Internet cause its value to be substantially destroyed. Which scenario eventuates will be determined largely by the overall pattern of play of the Cyber Game.</p>
<p>States have a high level of responsibility for determining the outcome. The current pattern of play is beginning to resemble traditional state-on-state geopolitical conflict. This puts the civil Internet at risk, and civilian cyber players are already getting caught in the crossfire. As long as the civil Internet remains undefended and easily permeable to cyber attack it will be hard to achieve the <i>N-topia</i> scenario.</p>
<p>Defending the civil Internet in depth, and hardening it by re-architecting will allow its full social and economic value to be realized but will restrict the potential for espionage and surveillance by states. This trade-off is net positive and in accordance with the espoused values of Western-style democracies. It does however call for leadership based on enlightened self-interest by state players.</p></blockquote>
<p><b>More</b> <a href="http://the-ethical-hacker.com/out.php?url=http://www.schneier.com/blog/archives/2013/05/the_global_cybe.html" rel='nofollow' target='_blank' >here</a></p>
<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://www.the-ethical-hacker.com/2013/05/the-global-cyber-game/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://www.the-ethical-hacker.com/2013/05/the-global-cyber-game/" data-text="&#8220;The Global Cyber Game&#8221;"></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fthe-global-cyber-game%2F&amp;linkname=%E2%80%9CThe%20Global%20Cyber%20Game%E2%80%9D" title="Facebook" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_friendfeed" href="http://www.addtoany.com/add_to/friendfeed?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fthe-global-cyber-game%2F&amp;linkname=%E2%80%9CThe%20Global%20Cyber%20Game%E2%80%9D" title="FriendFeed" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/friendfeed.png" width="16" height="16" alt="FriendFeed"/></a><a class="a2a_button_wordpress" href="http://www.addtoany.com/add_to/wordpress?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fthe-global-cyber-game%2F&amp;linkname=%E2%80%9CThe%20Global%20Cyber%20Game%E2%80%9D" title="WordPress" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/wordpress.png" width="16" height="16" alt="WordPress"/></a><a class="a2a_button_blogger_post" href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fthe-global-cyber-game%2F&amp;linkname=%E2%80%9CThe%20Global%20Cyber%20Game%E2%80%9D" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fthe-global-cyber-game%2F&amp;linkname=%E2%80%9CThe%20Global%20Cyber%20Game%E2%80%9D" title="Digg" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_delicious" href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fthe-global-cyber-game%2F&amp;linkname=%E2%80%9CThe%20Global%20Cyber%20Game%E2%80%9D" title="Delicious" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fthe-global-cyber-game%2F&amp;linkname=%E2%80%9CThe%20Global%20Cyber%20Game%E2%80%9D" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fthe-global-cyber-game%2F&amp;title=%E2%80%9CThe%20Global%20Cyber%20Game%E2%80%9D" id="wpa2a_16"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.the-ethical-hacker.com/2013/05/the-global-cyber-game/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mac Spyware: OSX/KitM (Kumar in the Mac)</title>
		<link>http://www.the-ethical-hacker.com/2013/05/mac-spyware-osxkitm-kumar-in-the-mac/</link>
		<comments>http://www.the-ethical-hacker.com/2013/05/mac-spyware-osxkitm-kumar-in-the-mac/#comments</comments>
		<pubDate>Wed, 22 May 2013 20:05:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[There&#8217;s another case of Backdoor:OSX/KitM.A in the wild. A German-based investigator reached out to us yesterday regarding OSX/KitM. (We wrote about it last week.) KitM stands for &#8220;Kumar in the Mac&#8221;, which is our designation for spyware &#8212; related to &#8230; <a href="http://www.the-ethical-hacker.com/2013/05/mac-spyware-osxkitm-kumar-in-the-mac/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>There&#8217;s another case of Backdoor:OSX/KitM.A in the wild.</p>
<p>A German-based investigator reached out to us yesterday regarding OSX/KitM. (<a href="http://the-ethical-hacker.com/out.php?url=http://www.f-secure.com/weblog/archives/00002554.html" rel="nofollow" target="_blank" >We wrote about it last week</a>.) KitM stands for &#8220;Kumar in the Mac&#8221;, which is our designation for spyware &mdash; related to OSX/Filesteal a.k.a. OSX/HackBack &mdash; that is signed using an Apple Developer ID in the name of Rajinder Kumar. The Developer ID has since been revoked by Apple.</p>
<p>This latest version of OSX/KitM used a Romanian C&amp;C server called liveapple.eu during the period of attack, December 2012 to early February 2013. The spear phishing used an attachment called Christmas_Card.app.zip. (Remember, the attack started in December.)</p>
<p>So, that brings us to this bit of advice for those of you who might be targets.</p>
<p>This is the default &#8220;Gatekeeper&#8221; security setting:</p>
<p><img width="678" height="532" border="0" src="http://www.f-secure.com/weblog/archives/Mac_Security_Privacy_01.png" alt="Mac, Security &amp; Privacy"/><br /><i>Mac App Store and identified developers</i></p>
<p>This is the setting that you want, unless you&#8217;re actively installing software:</p>
<p><img width="678" height="532" border="0" src="http://www.f-secure.com/weblog/archives/Mac_Security_Privacy_02.png" alt="Mac, Security &amp; Privacy"/><br /><i>Mac App Store</i></p>
<p>This is the prompt that results when OSX/KitM attempts to install with the stricter setting:</p>
<p><img width="430" height="233" border="0" src="http://www.f-secure.com/weblog/archives/KitM_Christmas_Card.png" alt="Kumar's Christmas Card"/></p>
<p>If you&#8217;re running OS X Mountain Lion or Lion v10.7.5 &mdash; adjust your settings as an extra layer of precaution.</p>
<p>SHA1: 290898b23a85bcd7747589d6f072a844e11eec65
<p>On 22/05/13 At 12:45 PM</p>
<p><b>More</b> <a href="http://the-ethical-hacker.com/out.php?url=http://www.f-secure.com/weblog/archives/00002558.html" rel='nofollow' target='_blank' >here</a></p>
<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://www.the-ethical-hacker.com/2013/05/mac-spyware-osxkitm-kumar-in-the-mac/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://www.the-ethical-hacker.com/2013/05/mac-spyware-osxkitm-kumar-in-the-mac/" data-text="Mac Spyware: OSX/KitM (Kumar in the Mac)"></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fmac-spyware-osxkitm-kumar-in-the-mac%2F&amp;linkname=Mac%20Spyware%3A%20OSX%2FKitM%20%28Kumar%20in%20the%20Mac%29" title="Facebook" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_friendfeed" href="http://www.addtoany.com/add_to/friendfeed?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fmac-spyware-osxkitm-kumar-in-the-mac%2F&amp;linkname=Mac%20Spyware%3A%20OSX%2FKitM%20%28Kumar%20in%20the%20Mac%29" title="FriendFeed" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/friendfeed.png" width="16" height="16" alt="FriendFeed"/></a><a class="a2a_button_wordpress" href="http://www.addtoany.com/add_to/wordpress?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fmac-spyware-osxkitm-kumar-in-the-mac%2F&amp;linkname=Mac%20Spyware%3A%20OSX%2FKitM%20%28Kumar%20in%20the%20Mac%29" title="WordPress" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/wordpress.png" width="16" height="16" alt="WordPress"/></a><a class="a2a_button_blogger_post" href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fmac-spyware-osxkitm-kumar-in-the-mac%2F&amp;linkname=Mac%20Spyware%3A%20OSX%2FKitM%20%28Kumar%20in%20the%20Mac%29" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fmac-spyware-osxkitm-kumar-in-the-mac%2F&amp;linkname=Mac%20Spyware%3A%20OSX%2FKitM%20%28Kumar%20in%20the%20Mac%29" title="Digg" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_delicious" href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fmac-spyware-osxkitm-kumar-in-the-mac%2F&amp;linkname=Mac%20Spyware%3A%20OSX%2FKitM%20%28Kumar%20in%20the%20Mac%29" title="Delicious" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fmac-spyware-osxkitm-kumar-in-the-mac%2F&amp;linkname=Mac%20Spyware%3A%20OSX%2FKitM%20%28Kumar%20in%20the%20Mac%29" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fmac-spyware-osxkitm-kumar-in-the-mac%2F&amp;title=Mac%20Spyware%3A%20OSX%2FKitM%20%28Kumar%20in%20the%20Mac%29" id="wpa2a_18"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.the-ethical-hacker.com/2013/05/mac-spyware-osxkitm-kumar-in-the-mac/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DDOS as Civil Disobedience</title>
		<link>http://www.the-ethical-hacker.com/2013/05/ddos-as-civil-disobedience/</link>
		<comments>http://www.the-ethical-hacker.com/2013/05/ddos-as-civil-disobedience/#comments</comments>
		<pubDate>Wed, 22 May 2013 11:05:45 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[For a while now, I have been thinking about what civil disobedience looks like in the Internet Age. Certainly DDOS attacks, and politically motivated hacking in general, is a part of that. This is one of the reasons I found &#8230; <a href="http://www.the-ethical-hacker.com/2013/05/ddos-as-civil-disobedience/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>For a while now, I have been thinking about what civil disobedience looks like in the Internet Age.  Certainly DDOS attacks, and politically motivated hacking in general, is a part of that.  This is one of the reasons I found Molly Sauter&#8217;s recent thesis, &#8220;<a href="http://the-ethical-hacker.com/out.php?url=http://www.scribd.com/doc/141893154/DISTRIBUTED-DENIAL-OF-SERVICE-ACTIONS-AND-THE-CHALLENGE-OF-CIVIL-DISOBEDIENCE-ON-THE-INTERNET" rel="nofollow" target="_blank" >Distributed Denial of Service Actions and the Challenge of Civil Disobedience on the Internet</a>,&#8221; so interesting:</p>
<blockquote><p><b>Abstract</b>:  This thesis examines the history, development, theory, and practice of distributed denial of service actions as a tactic of political activism. DDOS actions have been used in online political activism since the early 1990s, though the tactic has recently attracted significant public attention with the actions of Anonymous and Operation Payback in December 2010. Guiding this work is the overarching question of how civil disobedience and disruptive activism can be practiced in the current online space. The internet acts as a vital arena of communication, self expression, and interpersonal organizing. When there is a message to convey, words to get out, people to organize, many will turn to the internet as the zone of that activity. Online, people sign petitions, investigate stories and rumors, amplify links and videos, donate money, and show their support for causes in a variety of ways. But as familiar and widely accepted activist tools &#8212; petitions, fundraisers, mass letter-writing, call-in campaigns and others &#8212; find equivalent practices in the online space, is there also room for the tactics of disruption and civil disobedience that are equally familiar from the realm of street marches, occupations, and sit-ins? This thesis grounds activist DDOS historically, focusing on early deployments of the tactic as well as modern instances to trace its development over time, both in theory and in practice. Through that examination, as well as tool design and development, participant identity, and state and corporate responses, this thesis presents an account of the development and current state of activist DDOS actions. It ends by presenting an analytical framework for the analysis of activist DDOS actions.</p></blockquote>
<p>One of the problems with the legal system is that it doesn&#8217;t make any differentiation between civil disobedience and &#8220;normal&#8221; criminal activity on the Internet, though it does in the real world.</p>
<p><b>More</b> <a href="http://the-ethical-hacker.com/out.php?url=http://www.schneier.com/blog/archives/2013/05/ddos_as_civil_d.html" rel='nofollow' target='_blank' >here</a></p>
<p><a class="a2a_button_facebook_like addtoany_special_service" data-href="http://www.the-ethical-hacker.com/2013/05/ddos-as-civil-disobedience/"></a><a class="a2a_button_twitter_tweet addtoany_special_service" data-count="none" data-url="http://www.the-ethical-hacker.com/2013/05/ddos-as-civil-disobedience/" data-text="DDOS as Civil Disobedience"></a><a class="a2a_button_facebook" href="http://www.addtoany.com/add_to/facebook?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fddos-as-civil-disobedience%2F&amp;linkname=DDOS%20as%20Civil%20Disobedience" title="Facebook" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/facebook.png" width="16" height="16" alt="Facebook"/></a><a class="a2a_button_friendfeed" href="http://www.addtoany.com/add_to/friendfeed?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fddos-as-civil-disobedience%2F&amp;linkname=DDOS%20as%20Civil%20Disobedience" title="FriendFeed" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/friendfeed.png" width="16" height="16" alt="FriendFeed"/></a><a class="a2a_button_wordpress" href="http://www.addtoany.com/add_to/wordpress?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fddos-as-civil-disobedience%2F&amp;linkname=DDOS%20as%20Civil%20Disobedience" title="WordPress" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/wordpress.png" width="16" height="16" alt="WordPress"/></a><a class="a2a_button_blogger_post" href="http://www.addtoany.com/add_to/blogger_post?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fddos-as-civil-disobedience%2F&amp;linkname=DDOS%20as%20Civil%20Disobedience" title="Blogger Post" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/blogger.png" width="16" height="16" alt="Blogger Post"/></a><a class="a2a_button_digg" href="http://www.addtoany.com/add_to/digg?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fddos-as-civil-disobedience%2F&amp;linkname=DDOS%20as%20Civil%20Disobedience" title="Digg" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/digg.png" width="16" height="16" alt="Digg"/></a><a class="a2a_button_delicious" href="http://www.addtoany.com/add_to/delicious?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fddos-as-civil-disobedience%2F&amp;linkname=DDOS%20as%20Civil%20Disobedience" title="Delicious" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/delicious.png" width="16" height="16" alt="Delicious"/></a><a class="a2a_button_google_bookmarks" href="http://www.addtoany.com/add_to/google_bookmarks?linkurl=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fddos-as-civil-disobedience%2F&amp;linkname=DDOS%20as%20Civil%20Disobedience" title="Google Bookmarks" rel="nofollow" target="_blank"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/icons/google.png" width="16" height="16" alt="Google Bookmarks"/></a><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.the-ethical-hacker.com%2F2013%2F05%2Fddos-as-civil-disobedience%2F&amp;title=DDOS%20as%20Civil%20Disobedience" id="wpa2a_20"><img src="http://www.the-ethical-hacker.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://www.the-ethical-hacker.com/2013/05/ddos-as-civil-disobedience/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
