<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>uncompiled.com &#187; Privacy</title>
	<atom:link href="http://www.uncompiled.com/category/privacy/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.uncompiled.com</link>
	<description>Technology News That You Need</description>
	<lastBuildDate>Fri, 30 Jul 2010 01:19:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Overcome E-Health Record Security Challenge</title>
		<link>http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/</link>
		<comments>http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/#comments</comments>
		<pubDate>Mon, 26 Jul 2010 13:57:58 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[Legislation]]></category>
		<category><![CDATA[Medical]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1396</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Many large healthcare organizations have been securing electronic health records for years. But now, industrywide adoption will include providers of all shapes and sizes—most of which don&#8217;t have chief security officers, compliance specialists, CIOs, or even full-time IT staffs.<br />
Helping them secure their electronic records is an unprecedented challenge. The products and technologies needed are available, but the trick is in getting all providers to understand what&#8217;s required, prepare physicians and staff, and tap into the appropriate expertise.</p>
<p>The Health Insurance Portability And Accountability Act, or HIPAA, requires that EHRs and the data in them be guarded throughout their life cycles. Risk assessments must be performed and access privileges determined. You&#8217;ll need policies to secure all possible points of data leakage, including desktops, servers, databases, mobile devices, and the Internet.</p>
<p>In short, you must protect data at rest and in motion, and prepare for the inevitable breaches.</p>
<p>Creation And Use</p>
<p>When a patient walks into a provider&#8217;s office for the first time, the terminal at reception must be hardened, hosted on a trusted network, and continually scanned for viruses and malware. Receptionists should be able to add basic patient information but have limited access to executable files.</p>
<p>Access privileges should be assigned that strictly regulate employees&#8217; ability to view, enter, edit, and delete data based on what they need for their jobs. For example, billing personnel don&#8217;t need to see the results of the medical tests that they&#8217;re charging patients for.</p>
<p>Attending physicians should use unique credentials to access the EHR application to record diagnoses. E-medical records must be signed with electronic signatures, which include PIN codes and are saved in encrypted files. Signatures verify that information has been reviewed every time a physician signs off on an EHR. They also let the medical staff sign off on records from any location, expediting processing, reducing workflow costs, and maintaining HIPAA compliance.</p>
<p><a href="http://www.informationweek.com/news/healthcare/EMR/showArticle.jhtml?articleID=226200102">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;n=Overcome+E-Health+Record+Security+Challenge&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;title=Overcome+E-Health+Record+Security+Challenge" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;t=Overcome+E-Health+Record+Security+Challenge" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;title=Overcome+E-Health+Record+Security+Challenge" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;title=Overcome+E-Health+Record+Security+Challenge&amp;srcUrl=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;srcTitle=Overcome+E-Health+Record+Security+Challenge&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;title=Overcome+E-Health+Record+Security+Challenge&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Overcome%20E-Health%20Record%20Security%20Challenge%22&amp;body=Link: http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;t=Overcome+E-Health+Record+Security+Challenge" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;title=Overcome+E-Health+Record+Security+Challenge&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;title=Overcome+E-Health+Record+Security+Challenge" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;title=Overcome+E-Health+Record+Security+Challenge" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Overcome+E-Health+Record+Security+Challenge+-+http://b2l.me/acttwh&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/&amp;submitHeadline=Overcome+E-Health+Record+Security+Challenge&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Overcome+E-Health+Record+Security+Challenge&amp;body=Link: http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/07/overcome-e-health-record-security-challenge/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Gliffy, the popular online Visio replacement makes you pay for an SSL login</title>
		<link>http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/</link>
		<comments>http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/#comments</comments>
		<pubDate>Wed, 02 Jun 2010 18:01:41 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Reviews]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1236</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p><strong>Update:</strong> So as you can see from the comment section, Chris Kohlhardt, the CEO of Gliffy took the time to reply and set the record straight from their end. Their login process is SSL-enabled for all, despite their statement of &#8220;Secure SSL login&#8221; only for Premium accounts is apparently an error in&#8230; semantics? It&#8217;s not really up to me to figure out whether the person who wrote that site copy is unaware of what the difference between a &#8216;secure SSL login&#8217; and &#8216;secure browsing&#8217; is, but I&#8217;d at least say to get that changed and not expect consumers to view an HTML source to find out the truth.</p>
<p>As I was logging into <a href="http://www.gliffy.com/">Gliffy</a> today for the first time in a few years, I noticed that there were two buttons to submit the login form with: one for a &#8216;basic&#8217; login and one for a &#8216;secure&#8217; login. To me, a secure login in 2010 <strong>is</strong> a basic login. The people behind Gliffy however believe that protecting your login credentials is worth at least $5/mo to you.<br />
<img src="http://www.uncompiled.com/wp-content/uploads/2010/06/Screen-shot-2010-06-02-at-1.56.28-PM.png" alt="" title="Gliffy Packages" width="500" height="310" class="alignright size-full wp-image-1262" /><br />
In a business model that offers both free and paid accounts, I feel that a company should make you pay for added features, storage, or accessibility to data that you are using their site for. I, like most people, realize that ad-based sites aren&#8217;t the preferred option. A site like Gliffy allows for many areas to make users pay for &#8216;more&#8217;. The number of documents you are able to store, file upload size limits, the number of users allowed to access your files. With all of these major points of wanting to upgrade, why nickel-and-dime our security?</p>
<p>It&#8217;s appreciated whenever a company offers free service, of any magnitude. What&#8217;s not appreciated, however, is when a company feels that they should charge you to securely give your username and a password to a form. The sharing of data networks is only continuing to grow and as-such, a vast majority of web sites (reputable ones, at least) at the very least encrypt your login credentials. Whether they encrypt all data during your session is a whole different matter, but most can agree that protecting credentials is a general necessity.</p>
<p>This isn&#8217;t meant to be a launch point for &#8216;well SSL is useless anyways&#8217;. SSL for credential logins is useful in the vast majority of situations people actually deal with every day. At this point in the Internet and networking, not allowing someone to choose to login securely with personal credentials for a reputable and fairly well-known (for the context) company, is ridiculous. </p>
<p>Lastly, I am not complaining that the Gliffy site doesn&#8217;t run in SSL for all content, merely that an SSL login should be provided, free of charge, to anyone using their service. This is a standard practice for most web sites and Gliffy should step-up and do the right thing for everyone&#8217;s privacy.</p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;n=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;title=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;t=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;title=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;title=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login&amp;srcUrl=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;srcTitle=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;title=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Gliffy%2C%20the%20popular%20online%20Visio%20replacement%20makes%20you%20pay%20for%20an%20SSL%20login%22&amp;body=Link: http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;t=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;title=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;title=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;title=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login+-+http://b2l.me/ynyvj&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/&amp;submitHeadline=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Gliffy%2C+the+popular+online+Visio+replacement+makes+you+pay+for+an+SSL+login&amp;body=Link: http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/06/gliffy-the-popular-online-visio-replacement-makes-you-pay-for-an-ssl-login/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>When protecting personal data, the public trust is in the breach</title>
		<link>http://www.uncompiled.com/2010/05/when-protecting-personal-data-the-public-trust-is-in-the-breach/</link>
		<comments>http://www.uncompiled.com/2010/05/when-protecting-personal-data-the-public-trust-is-in-the-breach/#comments</comments>
		<pubDate>Thu, 20 May 2010 13:33:57 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Breach]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Legal]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1201</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>It could be argued that when companies are attacked by computer hackers who loot customer credit card numbers or other personal data, they are as much the victims as their customers. The question for the hotel industry is, who will guests hold accountable—the hackers or the hotel brands?As data breaches become more commonplace in the hotel industry, with Radisson Hotels &#038; Resorts, Wyndham Worldwide and a Westin hotel most recently falling prey to cyber criminals, the public’s patience with apologies and excuses can be expected to wane. If brands fail to protect data, will guests continue to trust them with their credit cards and patronage?</p>
<p>Reputational damage</p>
<p>Consider the reputational damage suffered by Radisson following its admission last fall that computers at some of its hotels in North America were breached between November 2008 and May 2009. Network World reported Radisson didn’t realize its guest data was compromised until alerted by credit card companies and processors.</p>
<p>In an open letter to guests posted on Radisson’s website, executive VP and COO Fredrik Korallus revealed that credit and debit card numbers, expiration dates and guest names may have been compromised, noting “the number of potentially affected hotels involved in the incident is limited.”</p>
<p>The latter comment hardly could have proved comforting to Radisson guests, who would not know whether they had stayed at one of those hotels and now have to shoulder the extra time and effort to check their bank and credit accounts for bogus transactions.</p>
<p>Wyndham’s response</p>
<p>The Wyndham data breach, discovered by the company in January and publicly acknowledged in late February, was particularly embarrassing and potentially more damaging to the brand’s reputation because it was the third hacking reported by the company in a 12-month period.</p>
<p>Unlike Radisson, which issued a news release to alert the public about the potential threat, Wyndham chose to share information with reporters in response to questions. Wyndham did post an open letter on its website along with frequently asked questions and a data breach claim form—if you can find them.</p>
<p>A search of Wyndham’s website by entering the search terms “open letter,” “breach,” “data breach,” “identity theft” and “payment card” in the site’s own search field failed to turn up the letter, FAQs or claim form. But I found the documents by researching online news stories, which included links to the pages.</p>
<p>The letter, signed by Kirsten Hotchkiss, senior VP, enterprise compliance and employment counsel, said the company believes no more than 37 Wyndham-branded hotels and resorts were involved, and “it is unlikely that identity theft will occur” because personally identifying information was “not at risk of compromise.”</p>
<p>Furthermore, she noted Wyndham provided each of the major credit card issuers with “card numbers that potentially could have been accessed” so that those companies “could take any appropriate action to protect their customers from possible misuse of the cards.” Wyndham also provided a toll-free number for guests to call for information.</p>
<p>“Never mind three strikes and you’re out,” said Paul McNamara in the 4 March issue of Computerworld. “How about three strikes and I’ve got to ask myself if I even want to be in one your hotels in the first place?”</p>
<p>Kelly Todd, a project manager for DataLossDB, which tracks and compiles information about data breaches, told Computerworld in that article, “Personally, I’d try my best to avoid using any business that suffered multiple breaches in a relatively short time frame.”</p>
<p>In a twist of irony, Wyndham neglected to encrypt its online data breach claim form. That means the information submitted by each potential data breach victim could once again be exposed to prying eyes. While the form does not request credit card numbers, it does include fields for the guest’s name, address, telephone number, e-mail address and Wyndham ByRequest number.</p>
<p>Barbara Hernandez expressed concern about Wyndham’s commitment to data security in a BNET travel blog posted 3 March. “Unless Wyndham requires its properties to have uniform and solid security measures, these data breaches will continue,” she said.  “Perhaps it may take customers avoiding the hotel chain for Wyndham to realize the extent of the security risk.”</p>
<p><a href="http://www.hotelnewsnow.com/Articles.aspx?ArticleId=3356">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/05/when-protecting-personal-data-the-public-trust-is-in-the-breach/&amp;n=When+protecting+personal+data%2C+the+public+trust+is+in+the+breach&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/05/when-protecting-personal-data-the-public-trust-is-in-the-breach/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/05/when-protecting-personal-data-the-public-trust-is-in-the-breach/&amp;title=When+protecting+personal+data%2C+the+public+trust+is+in+the+breach" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/05/when-protecting-personal-data-the-public-trust-is-in-the-breach/&amp;t=When+protecting+personal+data%2C+the+public+trust+is+in+the+breach" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/05/when-protecting-personal-data-the-public-trust-is-in-the-breach/&amp;title=When+protecting+personal+data%2C+the+public+trust+is+in+the+breach" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/05/when-protecting-personal-data-the-public-trust-is-in-the-breach/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/05/when-protecting-personal-data-the-public-trust-is-in-the-breach/&amp;title=When+protecting+personal+data%2C+the+public+trust+is+in+the+breach&amp;srcUrl=http://www.uncompiled.com/2010/05/when-protecting-personal-data-the-public-trust-is-in-the-breach/&amp;srcTitle=When+protecting+personal+data%2C+the+public+trust+is+in+the+breach&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/05/when-protecting-personal-data-the-public-trust-is-in-the-breach/&amp;title=When+protecting+personal+data%2C+the+public+trust+is+in+the+breach&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22When%20protecting%20personal%20data%2C%20the%20public%20trust%20is%20in%20the%20breach%22&amp;body=Link: http://www.uncompiled.com/2010/05/when-protecting-personal-data-the-public-trust-is-in-the-breach/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/05/when-protecting-personal-data-the-public-trust-is-in-the-breach/&amp;t=When+protecting+personal+data%2C+the+public+trust+is+in+the+breach" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/05/when-protecting-personal-data-the-public-trust-is-in-the-breach/&amp;title=When+protecting+personal+data%2C+the+public+trust+is+in+the+breach&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/05/when-protecting-personal-data-the-public-trust-is-in-the-breach/&amp;title=When+protecting+personal+data%2C+the+public+trust+is+in+the+breach" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/05/when-protecting-personal-data-the-public-trust-is-in-the-breach/&amp;title=When+protecting+personal+data%2C+the+public+trust+is+in+the+breach" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/05/when-protecting-personal-data-the-public-trust-is-in-the-breach/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=When+protecting+personal+data%2C+the+public+trust+is+in+the+breach+-+http://b2l.me/vp2uv&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/05/when-protecting-personal-data-the-public-trust-is-in-the-breach/&amp;submitHeadline=When+protecting+personal+data%2C+the+public+trust+is+in+the+breach&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=When+protecting+personal+data%2C+the+public+trust+is+in+the+breach&amp;body=Link: http://www.uncompiled.com/2010/05/when-protecting-personal-data-the-public-trust-is-in-the-breach/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/05/when-protecting-personal-data-the-public-trust-is-in-the-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>VA ramps up enforcement of contractor data security</title>
		<link>http://www.uncompiled.com/2010/05/va-ramps-up-enforcement-of-contractor-data-security/</link>
		<comments>http://www.uncompiled.com/2010/05/va-ramps-up-enforcement-of-contractor-data-security/#comments</comments>
		<pubDate>Thu, 20 May 2010 13:31:28 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[Legal]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1199</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>The Veterans Affairs Department will step up enforcement of its contractors to make certain that they meet information security requirements in protecting veterans’ personal health data.</p>
<p>VA includes a clause in its contracts requiring information security safeguards, including encryption and policies limiting who can access personal data. But that is no guarantee that vendors follow through, said VA senior IT and procurement officials at a hearing May 19 of the House Veterans Affair Committee subcommittee on oversight and investigations.</p>
<p>The challenge lies in verifying that over 22,000 VA contractors with whom the department shares veteran information adhere to security requirements, said Roger Baker, VA’s CIO. These vendors help VA provide healthcare and benefits.</p>
<p>“Our policy, which is stronger than any similarly sized private sector organization that I’m aware of, is that supply chain partners must follow VA’s information protection policies, including encryption of mobile devices,” he said.</p>
<p>The hearing occurred in the aftermath of the April 22 theft in Texas of a laptop with the personal information of 644 veterans from the vehicle of an employee of a health services contractor.</p>
<p>VA subsequently notified the affected veterans and is providing them with precautionary credit monitoring services. The contractor reported the incident immediately to law enforcement and to the agency and disabled the user account and server access from the stolen laptop, Baker said.</p>
<p>“The information was not encrypted despite contracts with the company that included the required security clause and the company had certified to the VA that they were in compliance,” he said.</p>
<p>The incident compelled VA to starting auditing its supply chain partners to ensure compliance with its policies.</p>
<p>“While it is impossible to audit all of our partners, these steps should provide us with substantially improved insight into the level of protection provided to veterans’ information anywhere it exists in our extended enterprise,” Baker said.</p>
<p>Among the steps, VA will verify that contracts where information is exchanged have the necessary information security clause, he said. Baker also expanded the authority of information security officers at VA facilities to review all contracts where information is exchanged. Previously their scope was limited to IT contracts.</p>
<p>VA will also randomly select a number of contracts at a facility for more in-depth audits of vendors’ compliance with VA security policies.<br />
To ensure that the contractor that reported the Texas data breach is beefing up security safeguards, VA said it will conduct an onsite assessment of the contractor’s facility and its scope of compliance with all IT information and physical security and records management requirements.</p>
<p>VA is also examining security related to the vendor’s 55 other contracts with the Veterans Health Administration and will ultimately work with the department’s legal counsel to determine any consequences.</p>
<p>At the same time, Baker said VA has to encourage vendors and others to report breaches, “because we can’t mitigate the issue unless we know about it.”</p>
<p>VA has required the security clause in contracts after November 2008 and last year reviewed contracts to make sure they contained the clause. Out of more than 22,000 contracts reviewed, vendors in 578 contracts refused or did not believe that their services required adhering t0 the clause, said Frederick Downs Jr., chief procurement and clinical logistics officer in the Veterans Health Administration.</p>
<p>“The 578 contracts were critical to our medical centers’ ability to provide patient care,” he said. The contracts were for direct healthcare services for nursing homes, hospices and physicians or to support maintenance for MRIs and CT scans.</p>
<p>“We had to weigh that because the risk of not having the contracts was high,” Downs said, adding that VA has since clarified guidance for when the information security clause applies to healthcare contracts.</p>
<p>Rep. Steve Buyer (R-Ind.) questioned Baker about what a VA medical center should do when a contractor who delivers a radiologic service refuses to sign the information security clause.</p>
<p>“That is the challenge writ large across the organization with this information,” Baker said. “How do we do great medical care and protect the information at the same time?”</p>
<p>The primary purpose of sensitive health information is to provide specific care for veterans. “We have to protect that information from unwanted access at the same time that we provide it to any one who needs to use it,” he said.</p>
<p>Medical devices, which are certified by the Food and Drug Administration, add another layer of complexity to providing comprehensive information security. Some vendors who provide or support medical devices for VA cite FDA authority in refusing the VA security clause.</p>
<p>“We have to be careful from an IT perspective how we interact with the medical technology,” Baker said. For example, VA can’t apply patches to medical technology because it could have unknown effects on, say, an MRI machine.</p>
<p>It’s an issue that “VA today is tackling in advance of the rest of the country,” he said</p>
<p><a href="http://www.govhealthit.com/newsitem.aspx?nid=73775">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/05/va-ramps-up-enforcement-of-contractor-data-security/&amp;n=VA+ramps+up+enforcement+of+contractor+data+security&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/05/va-ramps-up-enforcement-of-contractor-data-security/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/05/va-ramps-up-enforcement-of-contractor-data-security/&amp;title=VA+ramps+up+enforcement+of+contractor+data+security" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/05/va-ramps-up-enforcement-of-contractor-data-security/&amp;t=VA+ramps+up+enforcement+of+contractor+data+security" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/05/va-ramps-up-enforcement-of-contractor-data-security/&amp;title=VA+ramps+up+enforcement+of+contractor+data+security" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/05/va-ramps-up-enforcement-of-contractor-data-security/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/05/va-ramps-up-enforcement-of-contractor-data-security/&amp;title=VA+ramps+up+enforcement+of+contractor+data+security&amp;srcUrl=http://www.uncompiled.com/2010/05/va-ramps-up-enforcement-of-contractor-data-security/&amp;srcTitle=VA+ramps+up+enforcement+of+contractor+data+security&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/05/va-ramps-up-enforcement-of-contractor-data-security/&amp;title=VA+ramps+up+enforcement+of+contractor+data+security&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22VA%20ramps%20up%20enforcement%20of%20contractor%20data%20security%22&amp;body=Link: http://www.uncompiled.com/2010/05/va-ramps-up-enforcement-of-contractor-data-security/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/05/va-ramps-up-enforcement-of-contractor-data-security/&amp;t=VA+ramps+up+enforcement+of+contractor+data+security" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/05/va-ramps-up-enforcement-of-contractor-data-security/&amp;title=VA+ramps+up+enforcement+of+contractor+data+security&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/05/va-ramps-up-enforcement-of-contractor-data-security/&amp;title=VA+ramps+up+enforcement+of+contractor+data+security" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/05/va-ramps-up-enforcement-of-contractor-data-security/&amp;title=VA+ramps+up+enforcement+of+contractor+data+security" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/05/va-ramps-up-enforcement-of-contractor-data-security/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=VA+ramps+up+enforcement+of+contractor+data+security+-+http://b2l.me/vpzxa&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/05/va-ramps-up-enforcement-of-contractor-data-security/&amp;submitHeadline=VA+ramps+up+enforcement+of+contractor+data+security&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=VA+ramps+up+enforcement+of+contractor+data+security&amp;body=Link: http://www.uncompiled.com/2010/05/va-ramps-up-enforcement-of-contractor-data-security/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/05/va-ramps-up-enforcement-of-contractor-data-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google&#8217;s &#8216;Gaia&#8217; password system was infiltrated during January attacks</title>
		<link>http://www.uncompiled.com/2010/04/googles-gaia-password-system-was-infiltrated-during-january-attacks/</link>
		<comments>http://www.uncompiled.com/2010/04/googles-gaia-password-system-was-infiltrated-during-january-attacks/#comments</comments>
		<pubDate>Tue, 20 Apr 2010 14:34:18 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Breach]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Legal]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Web 2.0]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1062</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Google&#8217;s password system that controls access to almost all Google web services was among the losses incurred in January.</p>
<p>An insider told the New York Times that the Gaia program was attacked in a lightning raid taking less than two days last December. It claimed that this was only mentioned once at a technical conference four years ago, and the software is intended to enable users and employees to sign in with their password just once to operate a range of services.</p>
<p>The report claimed that intruders did not appear to have stolen passwords of Gmail users, and the company quickly started making significant changes to the security of its networks after the intrusions.</p>
<p>Google executives declined on Monday to comment about the new details of the case, saying they had dealt with the security issues raised by the theft of the company&#8217;s intellectual property in their initial statement in January.</p>
<p>They also privately said that the company had been far more transparent about the intrusions than any of the more than two dozen other companies that were compromised, the vast majority of which have not acknowledged the attacks.</p>
<p>Google is continuing to use the Gaia system, now known as Single Sign-On. Hours after announcing the intrusions, Google said it would activate a new layer of encryption for the Gmail service. The company also tightened the security of its data centres and further secured the communications links between its services and the computers of its users.</p>
<p>David Harley, director of malware intelligence at ESET, said: “So I certainly wouldn&#8217;t assume any connection between the alleged Chinese breach disclosed in January and recent reports of compromised Gmail accounts, but I wouldn&#8217;t discount the possibility either. After all, many of the respondents to the thread flagged by Aleksandr Matrosov were adamant that they hadn&#8217;t fallen prey to a phishing attack, and earlier reports did suggest attempts to access the accounts of Chinese human rights activists.</p>
<p>“The point of a single sign-on is to access a range of services: the problem with a single sign-on is that if it&#8217;s compromised, it becomes a single point of failure. Of course, it&#8217;s a long stretch from confidentiality attacks on Chinese dissidents to a South Korean spam server: I can&#8217;t help but wonder, though, what interesting weaknesses the original attackers may have found, and how widely the information on those issues may have been disseminated subsequently.”</p>
<p><a href="http://www.scmagazineuk.com/googles-gaia-password-system-was-infiltrated-during-january-attacks/article/168356/">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/04/googles-gaia-password-system-was-infiltrated-during-january-attacks/&amp;n=Google%27s+%27Gaia%27+password+system+was+infiltrated+during+January+attacks&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/04/googles-gaia-password-system-was-infiltrated-during-january-attacks/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/04/googles-gaia-password-system-was-infiltrated-during-january-attacks/&amp;title=Google%27s+%27Gaia%27+password+system+was+infiltrated+during+January+attacks" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/04/googles-gaia-password-system-was-infiltrated-during-january-attacks/&amp;t=Google%27s+%27Gaia%27+password+system+was+infiltrated+during+January+attacks" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/04/googles-gaia-password-system-was-infiltrated-during-january-attacks/&amp;title=Google%27s+%27Gaia%27+password+system+was+infiltrated+during+January+attacks" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/04/googles-gaia-password-system-was-infiltrated-during-january-attacks/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/04/googles-gaia-password-system-was-infiltrated-during-january-attacks/&amp;title=Google%27s+%27Gaia%27+password+system+was+infiltrated+during+January+attacks&amp;srcUrl=http://www.uncompiled.com/2010/04/googles-gaia-password-system-was-infiltrated-during-january-attacks/&amp;srcTitle=Google%27s+%27Gaia%27+password+system+was+infiltrated+during+January+attacks&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/04/googles-gaia-password-system-was-infiltrated-during-january-attacks/&amp;title=Google%27s+%27Gaia%27+password+system+was+infiltrated+during+January+attacks&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Google%27s%20%27Gaia%27%20password%20system%20was%20infiltrated%20during%20January%20attacks%22&amp;body=Link: http://www.uncompiled.com/2010/04/googles-gaia-password-system-was-infiltrated-during-january-attacks/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/04/googles-gaia-password-system-was-infiltrated-during-january-attacks/&amp;t=Google%27s+%27Gaia%27+password+system+was+infiltrated+during+January+attacks" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/04/googles-gaia-password-system-was-infiltrated-during-january-attacks/&amp;title=Google%27s+%27Gaia%27+password+system+was+infiltrated+during+January+attacks&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/04/googles-gaia-password-system-was-infiltrated-during-january-attacks/&amp;title=Google%27s+%27Gaia%27+password+system+was+infiltrated+during+January+attacks" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/04/googles-gaia-password-system-was-infiltrated-during-january-attacks/&amp;title=Google%27s+%27Gaia%27+password+system+was+infiltrated+during+January+attacks" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/04/googles-gaia-password-system-was-infiltrated-during-january-attacks/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Google%27s+%27Gaia%27+password+system+was+infiltrated+during+January+attacks+-+http://b2l.me/qbxg3&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/04/googles-gaia-password-system-was-infiltrated-during-january-attacks/&amp;submitHeadline=Google%27s+%27Gaia%27+password+system+was+infiltrated+during+January+attacks&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Google%27s+%27Gaia%27+password+system+was+infiltrated+during+January+attacks&amp;body=Link: http://www.uncompiled.com/2010/04/googles-gaia-password-system-was-infiltrated-during-january-attacks/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/04/googles-gaia-password-system-was-infiltrated-during-january-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Send Secure Info Over the Internet</title>
		<link>http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/</link>
		<comments>http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/#comments</comments>
		<pubDate>Tue, 13 Apr 2010 13:42:03 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Math]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1009</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Michael Spector (and yes, he&#8217;s my brother) asked how to safely email passwords, account numbers, and other sensitive information.</p>
<p>You can&#8217;t trust Internet email with potentially compromising information, such as your credit card or account numbers, social security numbers, or important passwords. As your message moves from one server to another, several people have the opportunity to read it.</p>
<p>o what should you do when you have to get sensitive information to someone, and snailmail just isn&#8217;t fast enough? I&#8217;ll give you several solutions.</p>
<p>Whatever option you pick, see What Is the Best Way to Create Strong Passwords? And if you have to share the password with the recipient, use the phone&#8211;just to be safe.</p>
<p>Public/Private Key Encryption: This elegant solution is supported by several programs, including Outlook 2007. The public key can encrypt but not decrypt, so you can safely share it with anyone. You keep the private key, which does the decrypting, to yourself.</p>
<p>Unfortunately, both the sender and the recipient must set up this type of encryption, and it&#8217;s not easy for the less technically inclined. That makes this a good choice in a business environment where everyone has an IT department, but not for occasional, personal communication.</p>
<p>Password-Protected .Zip Files: Depending on what software you use to create compressed .zip archives, you may or may not have an option to password-protect the files inside it. And that option may or may not support high-quality AES encryption.</p>
<p>And don&#8217;t go this route if it doesn&#8217;t support AES. The .zip format&#8217;s standard password protection is easy to hack.</p>
<p>Luckily, many third-party .zip programs support AES encryption, and they&#8217;re compatible with each other. These include industry leader WinZip, and the free, open-source 7-Zip. Whatever program you use, make sure you pick the AES option when you compress and encrypt your files.</p>
<p>Unfortunately, Windows&#8217; built-in .zip tool doesn&#8217;t support AES, so you can&#8217;t simply assume that your recipient will be able to open your archive. If they don&#8217;t have a compression program that supports AES .zips, don&#8217;t want to install one, or don&#8217;t know what you&#8217;re talking about, this isn&#8217;t your option.</p>
<p>Secure Message and File-Sending Services: You don&#8217;t have to actually email your private information. You can upload it to a secure web site, and let the recipient download.</p>
<p>I&#8217;m recommending one service in particular: Send. (the period is part of the company name). It&#8217;s free, and you don&#8217;t even have to share your password with the recipient. Each person has their own private password.</p>
<p>When you post a message on Send., the site emails a notice to the recipient, who will need their own free Send. account to access your message.</p>
<p>There&#8217;s a slight chance that a criminal will intercept that first email and create the account before the legitimate recipient does. To avoid this, send an initial message with nothing confidential in it. That way, the recipient will be safely signed up, with their own, hopefully strong password, before you send them something important.</p>
<p><a href="http://www.networkworld.com/news/2010/041210-send-secure-info-over-the.html">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;n=Send+Secure+Info+Over+the+Internet&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;title=Send+Secure+Info+Over+the+Internet" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;t=Send+Secure+Info+Over+the+Internet" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;title=Send+Secure+Info+Over+the+Internet" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;title=Send+Secure+Info+Over+the+Internet&amp;srcUrl=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;srcTitle=Send+Secure+Info+Over+the+Internet&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;title=Send+Secure+Info+Over+the+Internet&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Send%20Secure%20Info%20Over%20the%20Internet%22&amp;body=Link: http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;t=Send+Secure+Info+Over+the+Internet" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;title=Send+Secure+Info+Over+the+Internet&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;title=Send+Secure+Info+Over+the+Internet" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;title=Send+Secure+Info+Over+the+Internet" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Send+Secure+Info+Over+the+Internet+-+http://b2l.me/pb6sr&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/&amp;submitHeadline=Send+Secure+Info+Over+the+Internet&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Send+Secure+Info+Over+the+Internet&amp;body=Link: http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/04/send-secure-info-over-the-internet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Medical records secured by code-changing algorithm</title>
		<link>http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/</link>
		<comments>http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/#comments</comments>
		<pubDate>Tue, 13 Apr 2010 13:40:15 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Financial]]></category>
		<category><![CDATA[Math]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1007</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Medical records databases are a treasure trove for researchers &#8211; mapping trends in diseases and studying them to discover better treatment methods has never been easier. </p>
<p>Information that was previously available to a restricted number of researchers is now digital and accessible to many, making the issue of patient privacy prominent in discussions regarding the handling of these records.</p>
<p>Electronic medical records consist of very detailed patient data, where every disease, symptom or injury has its own code, which makes analysis easier and faster. But, the problem is that these codes are available through public databases and electronic medical records, and with this knowledge, this anonymized data can be still tied to the persons to whom it belongs.</p>
<p>To prove that this is a realistic problem, a research team form the Vanderbilt University in Nashville has conducted an experiment which resulted in 96 percent of the 2,762 patients belonging to the test group identified through diagnosis codes.</p>
<p>Scientific American reports that &#8211; as a solution to this problem &#8211; they introduced an algorithm that generalizes clinical information, but doesn&#8217;t interfere with the medical and genetic inter-data connections needed for research. The algorithm exchanges the publicly known ICD codes with an other code system. </p>
<p>They tested it by simulating a hacker attack, with the premise that the hacker is privy to the patients&#8217; identity, their ICD codes and the fact that the patients&#8217; data is included in the database. The test was completely successful &#8211; the hacker couldn&#8217;t uncover the patient&#8217;s private information, and the information remained useful for research.</p>
<p><a href="http://www.net-security.org/secworld.php?id=9128">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;n=Medical+records+secured+by+code-changing+algorithm&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;title=Medical+records+secured+by+code-changing+algorithm" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;t=Medical+records+secured+by+code-changing+algorithm" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;title=Medical+records+secured+by+code-changing+algorithm" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;title=Medical+records+secured+by+code-changing+algorithm&amp;srcUrl=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;srcTitle=Medical+records+secured+by+code-changing+algorithm&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;title=Medical+records+secured+by+code-changing+algorithm&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Medical%20records%20secured%20by%20code-changing%20algorithm%22&amp;body=Link: http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;t=Medical+records+secured+by+code-changing+algorithm" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;title=Medical+records+secured+by+code-changing+algorithm&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;title=Medical+records+secured+by+code-changing+algorithm" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;title=Medical+records+secured+by+code-changing+algorithm" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Medical+records+secured+by+code-changing+algorithm+-+http://b2l.me/pb6fs&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/&amp;submitHeadline=Medical+records+secured+by+code-changing+algorithm&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Medical+records+secured+by+code-changing+algorithm&amp;body=Link: http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/04/medical-records-secured-by-code-changing-algorithm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Details on the Network Solutions / WordPress mass hack</title>
		<link>http://www.uncompiled.com/2010/04/details-on-the-network-solutions-wordpress-mass-hack/</link>
		<comments>http://www.uncompiled.com/2010/04/details-on-the-network-solutions-wordpress-mass-hack/#comments</comments>
		<pubDate>Mon, 12 Apr 2010 17:46:05 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Attack]]></category>
		<category><![CDATA[Breach]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Legal]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Web 2.0]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1002</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Update 1: The attack continues! Now they are using the domain http://mainnetsoll.com/grep/. Make sure to fix your wp-config and change your database password ASAP.</p>
<p>Update 2: A quick fix if you can&#8217;t change your database password. Set the WP_SITEURL inside your wp-config. It will override the change in the database. Just add this line inside your file:<br />
define(&#8216;WP_SITEURL&#8217;, &#8216;yoursite.com&#8217;);</p>
<p>Update 3: If you are seeing attacks from a different domain, please let us know. If you need help, send us an email and we will try to help asap (use contact@sucuri.net ).</p>
<p>Yesterday we reported of a mass infection of WordPress blogs that were hosted at Network Solutions.</p>
<p>First of all, I must say that the response from Network Solutions was very good. They were active on the forums, responding to users via Twitter and really trying to find and fix the problem. They even send me an email just after my first post went live to get more information and share notes. That&#8217;s what I like to see from a hosting company.</p>
<p>Anyway, we discussed via the phone yesterday and after a long analysis they have nailed the cause of the problem. This is what happened:<br />
WordPress stores the database credentials in plain-text at the wp-config.php file.</p>
<p>This configuration file should only be read by Apache, but some users (well, lots of users) left it in a way that anyone could read it (755 instead of 750 in Linux slang).</p>
<p>A malicious user at Network Solutions creates a script to find those configuration files that were incorrectly configured.</p>
<p>This same malicious user finds hundreds of configuration files with the incorrect permissions and retrieves the database credentials</p>
<p>Yes, he again (the bad guy) launches an attack and modify the database for all these blogs. Now the siteurl for all of them just became networkads.net/grep. Easy hack.</p>
<p>So, at the end anyone can be blamed. At WordPress for requiring that the database credentials be stored in clear-text. At WordPress again for not installing itself securely by default. At the users for not securing their blogs. At Network Solutions for allowing this to happen.</p>
<p>I also have to agree with Network Solutions that this problem can happen at any shared host site. Not only for WordPress, but for any CMS out there that store the passwords in clear-text. For anyone affected with this problem (or anyone at a shared server), change your database credentials ASAP and make sure your configuration file is not readable by everyone else.</p>
<p>*To change the permissions via FTP, just run chmod 750 wp-config.php inside your blog directory.</p>
<p><a href="http://blog.sucuri.net/2010/04/details-on-network-solutions-wordpress.html">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/04/details-on-the-network-solutions-wordpress-mass-hack/&amp;n=Details+on+the+Network+Solutions+%2F+Wordpress+mass+hack&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/04/details-on-the-network-solutions-wordpress-mass-hack/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/04/details-on-the-network-solutions-wordpress-mass-hack/&amp;title=Details+on+the+Network+Solutions+%2F+Wordpress+mass+hack" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/04/details-on-the-network-solutions-wordpress-mass-hack/&amp;t=Details+on+the+Network+Solutions+%2F+Wordpress+mass+hack" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/04/details-on-the-network-solutions-wordpress-mass-hack/&amp;title=Details+on+the+Network+Solutions+%2F+Wordpress+mass+hack" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/04/details-on-the-network-solutions-wordpress-mass-hack/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/04/details-on-the-network-solutions-wordpress-mass-hack/&amp;title=Details+on+the+Network+Solutions+%2F+Wordpress+mass+hack&amp;srcUrl=http://www.uncompiled.com/2010/04/details-on-the-network-solutions-wordpress-mass-hack/&amp;srcTitle=Details+on+the+Network+Solutions+%2F+Wordpress+mass+hack&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/04/details-on-the-network-solutions-wordpress-mass-hack/&amp;title=Details+on+the+Network+Solutions+%2F+Wordpress+mass+hack&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Details%20on%20the%20Network%20Solutions%20%2F%20Wordpress%20mass%20hack%22&amp;body=Link: http://www.uncompiled.com/2010/04/details-on-the-network-solutions-wordpress-mass-hack/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/04/details-on-the-network-solutions-wordpress-mass-hack/&amp;t=Details+on+the+Network+Solutions+%2F+Wordpress+mass+hack" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/04/details-on-the-network-solutions-wordpress-mass-hack/&amp;title=Details+on+the+Network+Solutions+%2F+Wordpress+mass+hack&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/04/details-on-the-network-solutions-wordpress-mass-hack/&amp;title=Details+on+the+Network+Solutions+%2F+Wordpress+mass+hack" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/04/details-on-the-network-solutions-wordpress-mass-hack/&amp;title=Details+on+the+Network+Solutions+%2F+Wordpress+mass+hack" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/04/details-on-the-network-solutions-wordpress-mass-hack/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Details+on+the+Network+Solutions+%2F+Wordpress+mass+hack+-+http://b2l.me/n8tsh&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/04/details-on-the-network-solutions-wordpress-mass-hack/&amp;submitHeadline=Details+on+the+Network+Solutions+%2F+Wordpress+mass+hack&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Details+on+the+Network+Solutions+%2F+Wordpress+mass+hack&amp;body=Link: http://www.uncompiled.com/2010/04/details-on-the-network-solutions-wordpress-mass-hack/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/04/details-on-the-network-solutions-wordpress-mass-hack/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>DHS To Pilot Enhanced Network Intrusion Prevention Technology</title>
		<link>http://www.uncompiled.com/2010/03/dhs-to-pilot-enhanced-network-intrusion-prevention-technology/</link>
		<comments>http://www.uncompiled.com/2010/03/dhs-to-pilot-enhanced-network-intrusion-prevention-technology/#comments</comments>
		<pubDate>Mon, 22 Mar 2010 17:04:04 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=919</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>The Department of Homeland Security (DHS) will be partnering with a government agency and an internet service provider to trial an enhanced and upcoming version Einstein, a system used to help secure the networks of certain federal departments and agencies.<br />
According to a Privacy Impact Assessment (PIA) released (.PDF) last week by the DHS, the latest version of the system, known as Einstein 3, will not only identify potential attacks, as the previous versions did, but also block them. From the description in the PIA:</p>
<p>EINSTEIN 3, will draw on commercial technology and specialized government technology to conduct real-time full packet inspection and threat-based decision-making on network traffic entering or leaving these executive branch networks. The goal of EINSTEIN 3 is to identify and characterize malicious network traffic to enhance cybersecurity analysis, situational awareness and security response.</p>
<p>The pilot will use combinations of early versions of Einstein plus new intrusion prevention technologies, as well as technologies developed by the NSA. The pilot will demonstrate the viability of a commercial ISP and a government agency for the US-CERT to apply intrusion detection and prevention technology on that traffic.</p>
<p>Some of the threats the system aims to identify and possibly block are phishing attacks, IP spoofing, botnets, denials of service, distributed denials of service, man-in-the-middle attacks, and other types of malware.</p>
<p>The system will also help support more security data sharing:</p>
<p>The EINSTEIN 3 system will also support enhanced information sharing by US-CERT with federal departments and agencies by giving DHS the ability to automate alerting of detected network intrusion attempts and, when deemed necessary by DHS, to send alerts that do not contain the content of communications to the NSA so that DHS efforts may be supported by NSA exercising its lawfully authorized missions.</p>
<p>Such deep analysts of network traffic by the government will certainly raise privacy concerns. Last summer, the Center for Democracy and Technology (CDT) issued a report that called on the government to release information about the role the NSA will have in building and running Einstein 3. The PIA on Einstein 3 may not answer all of the CDT&#8217;s questions on privacy, but it&#8217;s the most detailed information on Einstein 3 I&#8217;ve yet to be able to find. </p>
<p><a href="http://www.informationweek.com/blog/main/archives/2010/03/dhs_to_pilot_en.html">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/03/dhs-to-pilot-enhanced-network-intrusion-prevention-technology/&amp;n=DHS+To+Pilot+Enhanced+Network+Intrusion+Prevention+Technology&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/03/dhs-to-pilot-enhanced-network-intrusion-prevention-technology/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/03/dhs-to-pilot-enhanced-network-intrusion-prevention-technology/&amp;title=DHS+To+Pilot+Enhanced+Network+Intrusion+Prevention+Technology" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/03/dhs-to-pilot-enhanced-network-intrusion-prevention-technology/&amp;t=DHS+To+Pilot+Enhanced+Network+Intrusion+Prevention+Technology" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/03/dhs-to-pilot-enhanced-network-intrusion-prevention-technology/&amp;title=DHS+To+Pilot+Enhanced+Network+Intrusion+Prevention+Technology" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/03/dhs-to-pilot-enhanced-network-intrusion-prevention-technology/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/03/dhs-to-pilot-enhanced-network-intrusion-prevention-technology/&amp;title=DHS+To+Pilot+Enhanced+Network+Intrusion+Prevention+Technology&amp;srcUrl=http://www.uncompiled.com/2010/03/dhs-to-pilot-enhanced-network-intrusion-prevention-technology/&amp;srcTitle=DHS+To+Pilot+Enhanced+Network+Intrusion+Prevention+Technology&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/03/dhs-to-pilot-enhanced-network-intrusion-prevention-technology/&amp;title=DHS+To+Pilot+Enhanced+Network+Intrusion+Prevention+Technology&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22DHS%20To%20Pilot%20Enhanced%20Network%20Intrusion%20Prevention%20Technology%22&amp;body=Link: http://www.uncompiled.com/2010/03/dhs-to-pilot-enhanced-network-intrusion-prevention-technology/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/03/dhs-to-pilot-enhanced-network-intrusion-prevention-technology/&amp;t=DHS+To+Pilot+Enhanced+Network+Intrusion+Prevention+Technology" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/03/dhs-to-pilot-enhanced-network-intrusion-prevention-technology/&amp;title=DHS+To+Pilot+Enhanced+Network+Intrusion+Prevention+Technology&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/03/dhs-to-pilot-enhanced-network-intrusion-prevention-technology/&amp;title=DHS+To+Pilot+Enhanced+Network+Intrusion+Prevention+Technology" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/03/dhs-to-pilot-enhanced-network-intrusion-prevention-technology/&amp;title=DHS+To+Pilot+Enhanced+Network+Intrusion+Prevention+Technology" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/03/dhs-to-pilot-enhanced-network-intrusion-prevention-technology/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=DHS+To+Pilot+Enhanced+Network+Intrusion+Prevention+Technology+-+http://b2l.me/ku9nz&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/03/dhs-to-pilot-enhanced-network-intrusion-prevention-technology/&amp;submitHeadline=DHS+To+Pilot+Enhanced+Network+Intrusion+Prevention+Technology&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=DHS+To+Pilot+Enhanced+Network+Intrusion+Prevention+Technology&amp;body=Link: http://www.uncompiled.com/2010/03/dhs-to-pilot-enhanced-network-intrusion-prevention-technology/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/03/dhs-to-pilot-enhanced-network-intrusion-prevention-technology/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacked personal data originating from China</title>
		<link>http://www.uncompiled.com/2010/03/hacked-personal-data-originating-from-china/</link>
		<comments>http://www.uncompiled.com/2010/03/hacked-personal-data-originating-from-china/#comments</comments>
		<pubDate>Mon, 22 Mar 2010 16:45:37 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Breach]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=913</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Have you ever wondered why you get so many unwanted spam text messages and e-mails? The answer might be found in China.</p>
<p>A 22-year-old Korean man named Kim is under arrest for purchasing lists of Koreans’ personal information, such as cell phone numbers and e-mail addresses, which had been hacked in China. After spending 1 million won ($880) for 31 million items of data since July of last year, Kim posted an Internet ad and sold off 10 million such items.</p>
<p>A 27-year-old man Lee, who runs a branch for an Internet service provider, was one of the buyers. He spent 3 million won for 140,000 phone numbers for his branch’s telemarketing scheme.</p>
<p>The Seoul Metropolitan Police Agency took in Kim and Lee without physical detention, and also detained the owners of the companies that failed to protect their customer information from computer hackers.</p>
<p>Last September, a used-car trading Web site and the Internet home page for a car navigation manufacturer were victims of Chinese hackers who stole names and residential registration numbers of 910,000 online members. Hackers can use the stolen registration numbers to become members of certain Web sites that send spam messages, or sell the numbers to other hackers.</p>
<p>Seoul police charged a 32-year-old named Kim, the owner of the used-car site, and a 45-year-old named Lee, who runs the navigation maker, for negligence in protecting their customers’ information.</p>
<p>The law demands that companies protect their online customers’ information, and violations are punishable by a maximum of two years in prison or a 10 million won fine.</p>
<p>“This is the first case in which we applied this particular clause since it became effective in September 2008,” a police officer explained. “Protecting personal information is a legal obligation, not merely a recommendation. We will continue to charge companies that leave their customer information vulnerable to hacking.”</p>
<p>According to police, Chinese hackers have been targeting Web sites of Korean department stores and other frequently visited sites. The hackers offer the Korean information for sale on the Internet. </p>
<p><a href="http://joongangdaily.joins.com/article/view.asp?aid=2918142">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/03/hacked-personal-data-originating-from-china/&amp;n=Hacked+personal+data+originating+from+China&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/03/hacked-personal-data-originating-from-china/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/03/hacked-personal-data-originating-from-china/&amp;title=Hacked+personal+data+originating+from+China" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/03/hacked-personal-data-originating-from-china/&amp;t=Hacked+personal+data+originating+from+China" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/03/hacked-personal-data-originating-from-china/&amp;title=Hacked+personal+data+originating+from+China" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/03/hacked-personal-data-originating-from-china/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/03/hacked-personal-data-originating-from-china/&amp;title=Hacked+personal+data+originating+from+China&amp;srcUrl=http://www.uncompiled.com/2010/03/hacked-personal-data-originating-from-china/&amp;srcTitle=Hacked+personal+data+originating+from+China&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/03/hacked-personal-data-originating-from-china/&amp;title=Hacked+personal+data+originating+from+China&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Hacked%20personal%20data%20originating%20from%20China%22&amp;body=Link: http://www.uncompiled.com/2010/03/hacked-personal-data-originating-from-china/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/03/hacked-personal-data-originating-from-china/&amp;t=Hacked+personal+data+originating+from+China" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/03/hacked-personal-data-originating-from-china/&amp;title=Hacked+personal+data+originating+from+China&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/03/hacked-personal-data-originating-from-china/&amp;title=Hacked+personal+data+originating+from+China" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/03/hacked-personal-data-originating-from-china/&amp;title=Hacked+personal+data+originating+from+China" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/03/hacked-personal-data-originating-from-china/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Hacked+personal+data+originating+from+China+-+http://b2l.me/ku52w&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/03/hacked-personal-data-originating-from-china/&amp;submitHeadline=Hacked+personal+data+originating+from+China&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Hacked+personal+data+originating+from+China&amp;body=Link: http://www.uncompiled.com/2010/03/hacked-personal-data-originating-from-china/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/03/hacked-personal-data-originating-from-china/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
