<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-387318336536837178</id><updated>2011-09-04T02:48:48.102-04:00</updated><title type='text'>A Beacon of Light</title><subtitle type='html'>It's better to light a candle than curse the darkness</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://faithyoung.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://faithyoung.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Faith Young</name><uri>http://www.blogger.com/profile/04686761912731944625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>23</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-387318336536837178.post-6098351967380607409</id><published>2011-08-27T10:52:00.002-04:00</published><updated>2011-08-27T10:54:07.564-04:00</updated><title type='text'>Testing a photo</title><content type='html'>&lt;a href="http://lh5.ggpht.com/-3GKVCKQZCgQ/TlkEoswZCfI/AAAAAAAAAEc/VFzUzFNt2SI/s1600-h/Sunset%25255B3%25255D.jpg"&gt;&lt;img alt="Sunset" border="0" height="164" src="http://lh6.ggpht.com/-vXRfK9bZbRk/TlkEo7KtfzI/AAAAAAAAAEg/CUzuXodIoNk/Sunset_thumb.jpg?imgmax=800" style="background-image: none; border: 0px currentColor; display: inline; padding-left: 0px; padding-right: 0px; padding-top: 0px;" title="Sunset" width="244" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/387318336536837178-6098351967380607409?l=faithyoung.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://faithyoung.blogspot.com/feeds/6098351967380607409/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://faithyoung.blogspot.com/2011/08/testing-photo.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/6098351967380607409'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/6098351967380607409'/><link rel='alternate' type='text/html' href='http://faithyoung.blogspot.com/2011/08/testing-photo.html' title='Testing a photo'/><author><name>Faith Young</name><uri>http://www.blogger.com/profile/04686761912731944625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/-vXRfK9bZbRk/TlkEo7KtfzI/AAAAAAAAAEg/CUzuXodIoNk/s72-c/Sunset_thumb.jpg?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-387318336536837178.post-6250741856544087993</id><published>2010-06-26T11:06:00.001-04:00</published><updated>2010-06-26T11:06:39.820-04:00</updated><title type='text'>Microsoft's Free Windows Live Essentials Beta Debuts</title><content type='html'>&lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;h4&gt;Microsoft's Free Windows Live Essentials Beta Debuts&lt;/h4&gt;    &lt;p&gt;&lt;em&gt;By Jeff Bertolucci, PC World, Jun 24, 2010 &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;The new &lt;a href="http://windowsteamblog.com/windows_live/b/windowslive/archive/2010/06/23/announcing-the-new-windows-live-essentials-beta.aspx"&gt;Windows Live Essentials&lt;/a&gt; beta will be available for public testing starting Thursday, according to &lt;a href="http://windowsteamblog.com/windows_live/b/windowslive/archive/2010/06/02/preview-of-the-new-windows-live-essentials.aspx"&gt;Microsoft&lt;/a&gt;. A collection of free Web-oriented applications and services for Windows Vista and Windows 7 PCs, Live Essentials is currently available in English, French, Dutch, Japanese, Portuguese, Simplified Chinese, or Spanish.&lt;/p&gt;    &lt;p&gt;You can download the beta &lt;a href="http://explore.live.com/windows-live-essentials-beta"&gt;here&lt;/a&gt;. (The beta wasn't live as of 10 a.m. U.S. Pacific, although it should be available sometime today.)&lt;/p&gt;    &lt;p&gt;Live Essentials programs include Windows Live Photo Gallery, Movie Maker, Mail, Writer, and &lt;a href="http://explore.live.com/windows-live-messenger-beta"&gt;Messenger&lt;/a&gt;. The new beta connects these apps to online services from Microsoft and other providers, including social networking sites such as Facebook, MySpace, and Linkedin; popular blogging tools like Spaces, WordPress, and Blogger; online storage and photo/video sharing sites including SkyDrive, Flickr, YouTube, and SmugMug; email sites such as Hotmail, Gmail, and Yahoo Mail; and Microsoft &lt;a href="http://www.pcworld.com/businesscenter/article/198397/productivity_on_the_go_with_office_web_apps.html"&gt;Office Web Apps&lt;/a&gt;, Redmond's new online productivity suite.&lt;/p&gt;    &lt;p&gt;In addition, the new Windows Live Sync feature synchronizes your files across multiple PCs and on cloud-based (online) servers. Sync's new remote desktop feature also lets you access your PC via the Web.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&amp;#160;&lt;/p&gt; &lt;em&gt;&lt;a href="http://www.pcworld.com/article/199805/microsofts_free_windows_live_essentials_beta_debuts.html"&gt;More…&lt;/a&gt;&lt;/em&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/387318336536837178-6250741856544087993?l=faithyoung.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://faithyoung.blogspot.com/feeds/6250741856544087993/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://faithyoung.blogspot.com/2010/06/microsoft-free-windows-live-essentials.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/6250741856544087993'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/6250741856544087993'/><link rel='alternate' type='text/html' href='http://faithyoung.blogspot.com/2010/06/microsoft-free-windows-live-essentials.html' title='Microsoft&amp;#39;s Free Windows Live Essentials Beta Debuts'/><author><name>Faith Young</name><uri>http://www.blogger.com/profile/04686761912731944625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-387318336536837178.post-348137932636377935</id><published>2010-05-22T08:47:00.002-04:00</published><updated>2010-05-22T08:51:15.152-04:00</updated><title type='text'>Twitter</title><content type='html'>I hope no one thinks I am ignoring their requests in Twitter.&amp;nbsp; I keep a protected account in Twitter and I have been experiencing this for almost the past two weeks.&amp;nbsp; I receive an email saying that I have a new Follower Request at Twitter.&amp;nbsp; When I click on the link, the page is blank.&amp;nbsp;&amp;nbsp; If you are experiencing this, post a reply at the link below so they can keep track of who is affected by this.&lt;br /&gt;&lt;blockquote&gt;&lt;strong&gt;Empty Follower Request Page/Trouble Following Private Accts&lt;/strong&gt;&lt;br /&gt;&lt;em&gt;Marc May 12&lt;/em&gt;&lt;br /&gt;&lt;em&gt;Do you have a protected account ?&lt;/em&gt;&lt;br /&gt;If your are receiving new follower notifications via email, but your page appears empty when you go to &lt;a href="http://twitter.com/friend_requests"&gt;http://twitter.com/friend_requests&lt;/a&gt;, what you are experiencing is a known issue.&lt;/blockquote&gt;&lt;a href="http://help.twitter.com/entries/172436-empty-follower-request-page-trouble-following-private-accts"&gt;More…&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/387318336536837178-348137932636377935?l=faithyoung.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://faithyoung.blogspot.com/feeds/348137932636377935/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://faithyoung.blogspot.com/2010/05/twitter.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/348137932636377935'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/348137932636377935'/><link rel='alternate' type='text/html' href='http://faithyoung.blogspot.com/2010/05/twitter.html' title='Twitter'/><author><name>Faith Young</name><uri>http://www.blogger.com/profile/04686761912731944625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-387318336536837178.post-6578537722750038135</id><published>2010-05-17T04:35:00.002-04:00</published><updated>2010-05-18T03:50:54.467-04:00</updated><title type='text'>Will there ever be a “Facebook for Dummies” Book?</title><content type='html'>There is never a dull moment at Twitter.&amp;nbsp; Just yesterday someone asked, “When are they going to publish a "Facebook Privacy for Dummies" book.”&amp;nbsp; My reply was that I would bet on never, but this got me thinking about all that has been written already about Facebook’s current Privacy challenges and we already have a book.&amp;nbsp; &lt;br /&gt;Here is the history of their ever changing Privacy Policy.&lt;br /&gt;&lt;b&gt;Evolution of Privacy Policies on Facebook – a Panel Chart in Excel&lt;/b&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;i&gt;By Chandoo, May 13th, 2010&lt;/i&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;There is a chart called “&lt;a href="http://mattmckeon.com/facebook-privacy/"&gt;Evolution of Privacy on Facebook&lt;/a&gt;” going around on the web.&lt;/b&gt;&lt;/i&gt; The chart made by Matt Mckeon, a developer in IBM’s visual communications lab has created quite a stir in the interwebs.&lt;/blockquote&gt;&lt;a href="http://chandoo.org/wp/2010/05/13/facebook-privacy-panel-chart/?utm_source=feedburner&amp;amp;utm_medium=twitter&amp;amp;utm_campaign=Feed%3A+PointyHairedDilbert+%28Chandoo.org+-+Learn+Excel+%26+Charting+Online%29&amp;amp;utm_content=Twitter"&gt;More……&lt;/a&gt;&lt;br /&gt;Here is an article on what Facebook passwords not to use. &lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;20 passwords to never use on Facebook&lt;/b&gt;&lt;br /&gt;&lt;i&gt;By Josh Smith, May 14th 2010&lt;/i&gt;&lt;br /&gt;&lt;i&gt;Excerpt.... &lt;/i&gt;&lt;br /&gt;In addition to those poorly-chosen passwords we've come up with our own list of 10 words or phrases not to use as your Facebook password.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Employer info &lt;/li&gt;&lt;li&gt;School name &lt;/li&gt;&lt;li&gt;&lt;a href="http://www.walletpop.com/blog/category/school/"&gt;School&lt;/a&gt; mascot &lt;/li&gt;&lt;li&gt;Names of groups, artists or shows you "Like" on Facebook &lt;/li&gt;&lt;li&gt;Spouses name or birthday &lt;/li&gt;&lt;li&gt;&lt;a href="http://www.walletpop.com/blog/category/banks/"&gt;Banking&lt;/a&gt; passwords &lt;/li&gt;&lt;li&gt;E-mail password &lt;/li&gt;&lt;li&gt;No dictionary based words -- even those in a different language &lt;/li&gt;&lt;li&gt;Pet's name if you post captioned pictures to your profile &lt;/li&gt;&lt;li&gt;Anything you might answer in a Facebook quiz &lt;/li&gt;&lt;/ul&gt;Creating a strong password doesn't have to be a chore or difficult to remember. Simply adding a number and a punctuation mark greatly increase the strength of a password. You can also use a phrase, condensed to a string of words and numbers, as an &lt;a href="http://news.cnet.com/8301-19518_3-10310092-238.html"&gt;easy-to-remember secure password&lt;/a&gt;. For example, "WalletPop is my #1 Personal Finance Blog!" becomes the "Wim#1PFb!". &lt;br /&gt;&lt;a href="http://www.walletpop.com/blog/2010/05/14/20-passwords-to-never-use-on-facebook/"&gt;More…….&lt;/a&gt;&lt;/blockquote&gt;and….&lt;br /&gt;This article is jammed with links to more information on Facebook Privacy.&amp;nbsp; First, to convince people that they are sharing information with the world there is Openbook.org and Zesty.ca.&amp;nbsp; It links you to an article about how to delete your Facebook account.&amp;nbsp; If deletion is something you choose not to do, it includes a chart that maps out how to find all the hidden Privacy settings in Facebook. &lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;Facebook Privacy: Secrets Unveiled&lt;/b&gt;&lt;br /&gt;&lt;i&gt;By JR Raphael, PC World, May 16, 2010 &lt;/i&gt;&lt;br /&gt;&lt;i&gt;Excerpt.... &lt;/i&gt;&lt;br /&gt;Thanks to a couple of handy new tools, you can now check out exactly what Facebook is telling the world about you -- and about everyone else. First up is &lt;a href="http://youropenbook.org/"&gt;Openbook&lt;/a&gt;, a project created by three computer geeks from San Francisco.&amp;nbsp; Openbook lets you search through Facebook's publicly available user data to find out what everyone is saying. &lt;br /&gt;&lt;i&gt;Excerpt.... &lt;/i&gt;&lt;br /&gt;So what to do? You can always say &lt;a href="http://www.pcworld.com/businesscenter/article/196237/why_i_left_facebook.html"&gt;so long to Facebook&lt;/a&gt;, of course. Or you can choose to stay with the site and simply be vigilant about protecting your privacy. It isn't easy, but it can be done. &lt;br /&gt;You can see what Facebook shares with the world about you by using this &lt;a href="http://zesty.ca/facebook/"&gt;free tool at zesty.ca&lt;/a&gt;; just input your Facebook user ID or account number (found by looking at the URL for your Facebook profile page), then click through the fields to see what's actually public. The tool won't take into account info that could be shared by applications or &lt;a href="http://www.pcworld.com/article/194821/facebooks_social_web_how_to_protect_your_privacy.html"&gt;Facebook's "instant personalization" feature&lt;/a&gt;, but it's a start. &lt;br /&gt;After that, get ready to dig. This &lt;a href="http://www.nytimes.com/interactive/2010/05/12/business/facebook-privacy.html"&gt;daunting chart&lt;/a&gt; breaks down all of the categories of settings you'll need to review (hint: be sure to clear out a couple hours of your afternoon). &lt;a href="http://www.pcworld.com/article/195884/how_to_keep_your_privacy_safer_on_facebook.html"&gt;This story&lt;/a&gt; provides a slightly less overwhelming summary of the main settings you should revisit. And &lt;a href="http://www.pcworld.com/article/194821/facebooks_social_web_how_to_protect_your_privacy.html"&gt;this one&lt;/a&gt; goes through some additional steps you'll want to take to address the aforementioned new "instant personalization" options. &lt;/blockquote&gt;&lt;a href="http://www.pcworld.com/article/196410/facebook_privacy_secrets_unveiled.html"&gt;More.......&lt;/a&gt;&lt;br /&gt;Now you have the start of a “Facebook for Dummies” book.&amp;nbsp; That is of course until it changes again because change is the only constant in life or in Facebook Privacy.&lt;br /&gt;&lt;br /&gt;I just wanted to add that this will help you manage the instant personalization feature on Facebook.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;b&gt;ReclaimPrivacy.org &lt;/b&gt;&lt;br /&gt;&lt;br /&gt;This website provides an &lt;strong&gt;independent&lt;/strong&gt; and &lt;strong&gt;open&lt;/strong&gt;  tool for scanning             your Facebook privacy settings.&amp;nbsp;  &lt;em&gt;&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;and-&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;The scanner operates entirely within your own browser.         &lt;/blockquote&gt;&amp;nbsp;&lt;a href="http://www.reclaimprivacy.org/facebook"&gt;More..... &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/387318336536837178-6578537722750038135?l=faithyoung.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://faithyoung.blogspot.com/feeds/6578537722750038135/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://faithyoung.blogspot.com/2010/05/will-there-ever-be-facebook-for-dummies.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/6578537722750038135'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/6578537722750038135'/><link rel='alternate' type='text/html' href='http://faithyoung.blogspot.com/2010/05/will-there-ever-be-facebook-for-dummies.html' title='Will there ever be a “Facebook for Dummies” Book?'/><author><name>Faith Young</name><uri>http://www.blogger.com/profile/04686761912731944625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-387318336536837178.post-6991887859511351296</id><published>2010-05-09T08:26:00.001-04:00</published><updated>2010-05-09T08:26:24.993-04:00</updated><title type='text'>Bkis Blog » Skype – New target of the worm spreading via IM</title><content type='html'>&lt;p&gt;This worm uses social engineering techniques that trick users into thinking the link (URL) is only to a picture (JPG).&amp;#160; It comes from people you know that have been infected and is spread to everyone in your Skype or Yahoo Messenger friend list.&amp;#160; Please be careful if you use Skype or Yahoo Messenger.&lt;/p&gt;  &lt;p&gt;An analysis and screen shots can be found here.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://blog.bkis.com/en/skype-new-target-of-the-worm-spreading-via-im/"&gt;Bkis Blog » Skype – New target of the worm spreading via IM&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/387318336536837178-6991887859511351296?l=faithyoung.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://faithyoung.blogspot.com/feeds/6991887859511351296/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://faithyoung.blogspot.com/2010/05/bkis-blog-skype-new-target-of-worm.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/6991887859511351296'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/6991887859511351296'/><link rel='alternate' type='text/html' href='http://faithyoung.blogspot.com/2010/05/bkis-blog-skype-new-target-of-worm.html' title='Bkis Blog » Skype – New target of the worm spreading via IM'/><author><name>Faith Young</name><uri>http://www.blogger.com/profile/04686761912731944625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-387318336536837178.post-52332152655050339</id><published>2010-05-04T03:47:00.001-04:00</published><updated>2010-05-04T03:47:16.238-04:00</updated><title type='text'>Facebook - Privacy Controls &amp; Targeted Malware</title><content type='html'>&lt;p&gt;&lt;/p&gt;  &lt;p&gt;Social media (like Facebook) is a great way to stay in touch with your family and friends.&amp;#160; There is nothing wrong with this and it is free to use.&amp;#160; Facebook has actually crossed generational gaps, where many of the young, old, and in-between love it.&amp;#160;&amp;#160; I remember writing letters and mailing them home when I was younger.&amp;#160; The Privacy settings of the old fashioned letter writing was the envelope, but that did not protect you from the letter being delivered to the wrong person or the person on the other end publishing your letter in a newspaper.&amp;#160; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Facebook's Privacy Controls Broken&lt;/strong&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;em&gt;By Dan Tynan, May 03, 2010, &lt;/em&gt;&lt;em&gt;Analysis: Inconsistency in controls raises (more) questions about Facebook's privacy options. &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;I've spent a fair amount of time lately messing about with &lt;a href="http://www.itworld.com/internet/105438/whats-about-facebooks-like-button?source=peer2peerpromo"&gt;Facebook's privacy settings,&lt;/a&gt; which is almost like having a life, but not quite. Then I discovered something odd and disturbing: I cannot make all of my &amp;quot;likes and interests&amp;quot; &lt;a href="http://www.pcworld.com/article/194821/facebooks_social_web_how_to_protect_your_privacy.html?tk=rel_news"&gt;private so that only my friends can see them.&lt;/a&gt; Even when I tell Facebook to do it, it won't -- they're still visible to anyone who looks up my Facebook profile.&lt;/p&gt;    &lt;p&gt;Is it a bug? Was it something I said? Was it all those jokes about &lt;a href="http://www.esarcasm.com/12860/facebook-syphilis/"&gt;Facebook causing venereal disease&lt;/a&gt; or because I published &lt;a href="http://www.esarcasm.com/10237/facebooks-mark-zuckerberg-bares-all/"&gt;a nude photo of Mark Zuckerberg?&lt;/a&gt; I dunno. But whatever the reason, even with every single Facebook setting turned to &amp;quot;friends only,&amp;quot; anyone on Facebook can still see the 128 groups I have joined on the site.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.pcworld.com/article/195448-2/facebooks_privacy_controls_broken.html"&gt;More…..&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;-and this.&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;A HijackThis Toolbar from Facebook? &lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;By AndyAtHull, May 03, 2010&lt;/em&gt; &lt;/p&gt;    &lt;p&gt;The title will come across as shocking if you are a security expert. However don’t let the title scare you too much.&lt;/p&gt;    &lt;p&gt;Symantec today &lt;a href="http://www.symantec.com/connect/blogs/hijackthis-toolbar-facebook"&gt;blogged&lt;/a&gt; about spam e-mail making the rounds that looks like the following hoping to lure recipients into downloading a Facebook toolbar:&lt;/p&gt;    &lt;p&gt;&lt;em&gt;(see the article for the pictures)&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;Excerpt-&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;So as you can see, there is some mentioned this file to be associated with HijackThis, an analysis tool by Trend Micro. Symantec detect this file as a&lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2002-082718-3007-99"&gt; Trojan.Dropper&lt;/a&gt;. HijackThis is a legit tool and Facebook have not released a toolbar dubbed HijackThis.&lt;/p&gt;    &lt;p&gt;Be careful what you click on as some disguise themselves differently to others. And should you come across a suspicious e-mail, report it.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.securitycadets.com/2010/05/a-hijackthis-toolbar-from-facebook/"&gt;More….&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;When I say Facebook is free to use, you have to be careful with your Privacy settings, suspicious emails, and the links you click on.&amp;#160; Additionally, it seems like you have to re-check your Privacy settings frequently.&amp;#160;&amp;#160; &lt;a href="http://defensio.com/what-is-it"&gt;Defensio&lt;/a&gt; will help protect you against malicious links while using Facebook.&amp;#160; It is the one application that I will allow on Facebook.&amp;#160;&amp;#160; It can also be used on your blog.&amp;#160;&amp;#160; &lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/387318336536837178-52332152655050339?l=faithyoung.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://faithyoung.blogspot.com/feeds/52332152655050339/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://faithyoung.blogspot.com/2010/05/facebook-privacy-controls-targeted.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/52332152655050339'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/52332152655050339'/><link rel='alternate' type='text/html' href='http://faithyoung.blogspot.com/2010/05/facebook-privacy-controls-targeted.html' title='Facebook - Privacy Controls &amp;amp; Targeted Malware'/><author><name>Faith Young</name><uri>http://www.blogger.com/profile/04686761912731944625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-387318336536837178.post-4707246177510688534</id><published>2010-05-02T08:50:00.001-04:00</published><updated>2010-05-02T08:50:28.395-04:00</updated><title type='text'>Windows 7 Security</title><content type='html'>&lt;p&gt;This is a great guide to read if you are trying to understand Windows 7 Security.&amp;#160; It does not go too far into the weeds (or details) that will confuse someone with a security background.&amp;#160; If you want an easy to read overview of some of the new security features that are available in Windows 7, this is the place to start.&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;-Ultimate guide to Windows 7 security &lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;Use AppLocker, BitLocker to Go and other Microsoft security tools       &lt;br /&gt;By Roger A. Grimes, InfoWorld, 21 April 10&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;a href="http://www.techworld.com/topics/windows-7/"&gt;Windows 7&lt;/a&gt; has been warmly received and swiftly adopted by businesses, with the result that many IT admins are now struggling with the platform's new security features. In addition to changes to User Account Control, BitLocker, and other features inherited from Windows Vista, Windows 7 introduces a slew of security capabilities that businesses will want to take advantage of.&lt;/p&gt;    &lt;p&gt;Windows 7 improves on Vista with a friendlier UAC mechanism, the ability to encrypt removable media and hard drive volumes, broader support for strong cryptographic ciphers, hassle-free secure remote access, and sophisticated protection against Trojan malware in the form of AppLocker, to name just a few.&lt;/p&gt;    &lt;p&gt;In this guide, I'll run through these and other significant security enhancements in Windows 7, and provide my recommendations for configuring and using them. I'll pay especially close attention to the new AppLocker application control feature, which may be a Windows shop's most practical and affordable way to combat socially engineered &lt;a href="http://www.techworld.com/topics/trojan-horse/"&gt;Trojan malware&lt;/a&gt;.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://features.techworld.com/security/3221198/ultimate-guide-to-windows-7-security/"&gt;More.......&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/387318336536837178-4707246177510688534?l=faithyoung.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://faithyoung.blogspot.com/feeds/4707246177510688534/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://faithyoung.blogspot.com/2010/05/windows-7-security.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/4707246177510688534'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/4707246177510688534'/><link rel='alternate' type='text/html' href='http://faithyoung.blogspot.com/2010/05/windows-7-security.html' title='Windows 7 Security'/><author><name>Faith Young</name><uri>http://www.blogger.com/profile/04686761912731944625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-387318336536837178.post-7806793462581010205</id><published>2010-04-05T04:56:00.001-04:00</published><updated>2010-04-05T04:56:12.717-04:00</updated><title type='text'>ID Theft Protection Services</title><content type='html'>&lt;p&gt;I was researching a topic that was possibly related to fraud the other day.&amp;#160; It was closer to the grey line of consumer fraud, but I refuse to draw any conclusions based solely on my opinion.&amp;#160; Life has a way of teaching you that even if something grates on your nerves, there are always two sides to every story or even two, three, four sides, depending on who you are speaking to at that time.&amp;#160; &lt;/p&gt;  &lt;p&gt;What I ran into was some news about ID Theft Protection Services.&amp;#160;&amp;#160; I do not think that you will find anyone who will tell you that ID Theft is not a serious crime or that the documented cases have sky-rocketed in the past three years.&amp;#160; When you look at this from a Risk Management point of view,&amp;#160; you want to look at some options that will help mitigate this threat.&amp;#160; One option that is available is ID Theft Protection Services.&lt;/p&gt;  &lt;p&gt;When choosing an ID Theft Protection Service or Insurance, you have to read the fine print to see if it will be a benefit you.&amp;#160; You have to watch out for consumer fraud and conduct research on the company.&amp;#160; Personally, I would never accept an offer by way of phone marketing because there is an increased chance that you are being scammed.&amp;#160; The person on the other end of the phone might not be who you think they are and if they really want your business they can provide a phone number that can be validated (searched for on the Internet).&amp;#160; That way, you can call them back when you are ready to conduct business with them.&lt;/p&gt;  &lt;p&gt;Lifelock claimed that it covered all types of ID Theft and basically it didn’t.&amp;#160; &lt;/p&gt;  &lt;p&gt;-This is a link to the FTC Case Information with a phone number to contact them for more information.&lt;/p&gt;  &lt;h4&gt;&lt;strong&gt;&lt;a href="http://www.ftc.gov/lifelock"&gt;INFORMATION ON LIFELOCK SETTLEMENT&lt;/a&gt;&lt;/strong&gt;&lt;/h4&gt;  &lt;p&gt;Here are some more newsworthy angles to the LifeLock controversy and the ID Theft Protection industry.&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;b&gt;-Lifelock CEO Todd Davis Does Damage Control&lt;/b&gt;      &lt;br /&gt;&lt;i&gt;By Dave Nielsen, March 16, 2010&lt;/i&gt;&lt;/p&gt;   &lt;em&gt;&lt;/em&gt;    &lt;p&gt;     &lt;br /&gt;If you hadn't heard, identity theft company LifeLock agreed to pay $12 million dollars to settle charges from the Federal Trade Commission and 35 states. The FTC felt that LifeLock ads were deceptive and overstated the protection provided by the service.&lt;/p&gt;    &lt;p&gt;     &lt;br /&gt;Personally, I think the charges are valid and I had to chuckle a bit when I read this email from CEO Todd Davis sent out to his partners. Mr. Davis certainly has his public relations firm working overtime to write something like this.      &lt;br /&gt;&lt;/p&gt;    &lt;p&gt;&lt;a href="http://www.fightidentitytheft.com/blog/lifelock-ceo"&gt;More....&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;em&gt;and-&lt;/em&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;b&gt;-Identity Theft Protection Industry: Divided we Stand, for Better or for Worse&lt;/b&gt;      &lt;br /&gt;&lt;i&gt;By Denise Richardson, March 17, 2010, updated March 22, 2010&lt;/i&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;&lt;/em&gt;      &lt;br /&gt;When have you ever seen one bank tear apart another?&amp;#160; Never.&amp;#160; Why?&amp;#160; Because they unify as part of the same industry and work together, for good or ill.&amp;#160; Think about it: the same could be said about any industry--the insurance, credit and debt collection industries to name a few. They band together in a sort of code of honor where one never knocks the other.&amp;#160; They go about their business promoting their own products and services.&amp;#160; It boggles my mind why the identity theft industry does things differently.&amp;#160; Why is it so divided?&lt;/p&gt;    &lt;p&gt;     &lt;br /&gt;Last week's press conference by the FTC and 35 Attorneys General launched a media frenzy that left some of us shaking our heads and others scurrying about to see how best they can twist the news of this recent settlement with LifeLock into their own personal pot of gold.&lt;/p&gt;    &lt;p&gt;     &lt;br /&gt;&lt;a href="http://www.givemebackmycredit.com/blog/2010/03/identity-theft-protection-industry-divided-we-stand-for-better-or-for-worse.html"&gt;More...&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;I have only found one ID Theft Protection Service that offers a Recovery service that covers all types of ID Theft (financial, criminal, social security, medical, etc) and Family Fraud.&amp;#160; They are honest in claiming, “While we provide a comprehensive approach to help prevent the occurrence of Identity Theft for our members, no identity protection service can prevent identity theft from happening.”&amp;#160; They do not even collect your SSN unless you need the Recovery service.&amp;#160; &lt;a href="http://www.zanderins.com/idtheft/faq.aspx"&gt;Zander Insurance Group (FAQ)&lt;/a&gt; Also, check out the link to how they compare to other ID Theft Protection Services.&lt;/p&gt;  &lt;p&gt;   &lt;blockquote&gt;     &lt;p&gt;&lt;a href="http://www.ftc.gov/bcp/edu/pubs/consumer/general/gen07.shtm"&gt;&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/387318336536837178-7806793462581010205?l=faithyoung.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://faithyoung.blogspot.com/feeds/7806793462581010205/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://faithyoung.blogspot.com/2010/04/id-theft-protection-services.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/7806793462581010205'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/7806793462581010205'/><link rel='alternate' type='text/html' href='http://faithyoung.blogspot.com/2010/04/id-theft-protection-services.html' title='ID Theft Protection Services'/><author><name>Faith Young</name><uri>http://www.blogger.com/profile/04686761912731944625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-387318336536837178.post-4004353307004264248</id><published>2010-03-10T02:14:00.001-05:00</published><updated>2010-03-10T02:14:40.319-05:00</updated><title type='text'>MSRC - Security Advisory 981374 Released</title><content type='html'>&lt;p&gt;Does not affect IE8 or Windows 7.&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;Security Advisory 981374 Released&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;Microsoft Security Response Center(MSRC) Blog, March 09, 2010&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;Hi everyone,&lt;/p&gt;    &lt;p&gt;Today we released Security Advisory 981374 addressing a publicly disclosed vulnerability in Internet Explorer 6 and Internet Explorer 7. Internet Explorer 8 is not affected by this issue. Customers using Internet Explorer 6 or 7 should upgrade to Internet Explorer 8 immediately to benefit from the improved security features and defense in depth protections. Additionally, Internet Explorer 5.01 on Windows 2000 is not affected.&lt;/p&gt;    &lt;p&gt;At this time, we are aware of targeted attacks seeking to exploit this vulnerability against Internet Explorer 6. Internet Explorer Protected Mode in Internet Explorer 7 running on Windows Vista helps to mitigate the impact of this issue. Additionally, Internet Explorer on Windows Server 2003 and Windows Server 2008 runs in a restricted mode that is known as Enhanced Security Configuration. This mode sets the security level for the Internet zone to High. This is a mitigating factor for Web sites that you have not added to the Internet Explorer Trusted sites zone. Please review the Security Advisory for additional workarounds which include modifying the Access Control List (ACL) on iepeers.dll (the affected component), setting the Internet and local Intranet security zones to &amp;quot;high&amp;quot;, configuring Internet Explorer to prompt before running Active Scripting, and enabling Data Execution Prevention (DEP) where possible which makes it difficult to successfully exploit the vulnerability.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://blogs.technet.com/msrc/archive/2010/03/09/security-advisory-981374-released.aspx"&gt;More.......&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;-Microsoft Security Advisory (981374)&lt;/p&gt;  &lt;p&gt;Vulnerability in Internet Explorer Could Allow Remote Code Execution&lt;/p&gt;  &lt;p&gt;Published: March 09, 2010&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.microsoft.com/technet/security/advisory/981374.mspx"&gt;Link&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/387318336536837178-4004353307004264248?l=faithyoung.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://faithyoung.blogspot.com/feeds/4004353307004264248/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://faithyoung.blogspot.com/2010/03/msrc-security-advisory-981374-released.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/4004353307004264248'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/4004353307004264248'/><link rel='alternate' type='text/html' href='http://faithyoung.blogspot.com/2010/03/msrc-security-advisory-981374-released.html' title='MSRC - Security Advisory 981374 Released'/><author><name>Faith Young</name><uri>http://www.blogger.com/profile/04686761912731944625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-387318336536837178.post-5617999746659666962</id><published>2010-03-07T07:15:00.001-05:00</published><updated>2010-03-07T07:15:23.368-05:00</updated><title type='text'>The Economics of Spam &amp; Botnets</title><content type='html'>&lt;p&gt;To state that it has been a while since my last blog post would be an understatement.&amp;#160; I will quote a true unnamed mentor of mine and just say, “Life Happens.”&amp;#160;&amp;#160; My work changed and brought me into the world of Project Management.&amp;#160; This subject almost interests me as much as Information Security.&amp;#160; I want to highlight this TechRepublic article because it describes the most recent top 10 spam botnets.&amp;#160; The economic reasons for spam and why the spammers use botnets became somewhat clearer to me.&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;The top 10 spam botnets: New and improved&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&amp;#160;&lt;em&gt;by Michael Kassner, February 25th, 2010&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;While doing research for this project, I came across a blog series (&lt;a href="http://blogs.msdn.com/tzink/archive/2010/02/03/which-botnet-sends-the-most-spam.aspx"&gt;first&lt;/a&gt;, &lt;a href="http://blogs.msdn.com/tzink/archive/2010/02/04/which-botnet-sends-the-most-spam-part-2.aspx"&gt;second&lt;/a&gt;, &lt;a href="http://blogs.msdn.com/tzink/archive/2010/02/05/which-botnet-sends-the-most-spam-part-3.aspx"&gt;third post&lt;/a&gt;) that forced me to rethink. Ranking spam botnets is not as simple as I thought. The blog author, Terry Zink, pointed out that there are several measurement philosophies:&lt;/p&gt;    &lt;ul&gt;     &lt;li&gt;The number of bot members &lt;/li&gt;      &lt;li&gt;The number of bytes sent &lt;/li&gt;      &lt;li&gt;The number of messages sent &lt;/li&gt;   &lt;/ul&gt;    &lt;p&gt;In the grand scheme of things, it may not seem important. But techies like details. Counting the number of bot members or bytes sent is straightforward enough. You would assume that the number of messages would be, too.&lt;/p&gt;    &lt;p&gt;Well, it’s not. Botnets are smart enough to create a spam message but address it to a lot of different recipients. That adds another factor when counting messages.&lt;/p&gt;    &lt;p&gt;Confused? So am I. To make some sense out of it all, I juggled the different attributes (totally unscientifically, of course) and came up with the following list of the best of the breed.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://blogs.techrepublic.com.com/10things/?p=1373"&gt;More here&lt;/a&gt;…… &lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/387318336536837178-5617999746659666962?l=faithyoung.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://faithyoung.blogspot.com/feeds/5617999746659666962/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://faithyoung.blogspot.com/2010/03/economics-of-spam-botnets.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/5617999746659666962'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/5617999746659666962'/><link rel='alternate' type='text/html' href='http://faithyoung.blogspot.com/2010/03/economics-of-spam-botnets.html' title='The Economics of Spam &amp;amp; Botnets'/><author><name>Faith Young</name><uri>http://www.blogger.com/profile/04686761912731944625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-387318336536837178.post-4204291274069439107</id><published>2009-07-17T06:16:00.000-04:00</published><updated>2009-07-17T06:16:59.314-04:00</updated><title type='text'>Security Idiot: Impress Your Peers With Your Grasp of IT Security Terminology</title><content type='html'>This is a funny IT Security Glossary.  It is only meant as a joke because everyone needs a little humor in their lives, from time to time.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.securityidiot.com/2008/07/impress-your-peers-with-your-grasp-of.html"&gt;Security Idiot: Impress Your Peers With Your Grasp of IT Security Terminology&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/387318336536837178-4204291274069439107?l=faithyoung.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.securityidiot.com/2008/07/impress-your-peers-with-your-grasp-of.html' title='Security Idiot: Impress Your Peers With Your Grasp of IT Security Terminology'/><link rel='replies' type='application/atom+xml' href='http://faithyoung.blogspot.com/feeds/4204291274069439107/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://faithyoung.blogspot.com/2009/07/security-idiot-impress-your-peers-with.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/4204291274069439107'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/4204291274069439107'/><link rel='alternate' type='text/html' href='http://faithyoung.blogspot.com/2009/07/security-idiot-impress-your-peers-with.html' title='Security Idiot: Impress Your Peers With Your Grasp of IT Security Terminology'/><author><name>Faith Young</name><uri>http://www.blogger.com/profile/04686761912731944625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-387318336536837178.post-53329702413479277</id><published>2009-07-10T06:40:00.001-04:00</published><updated>2009-07-10T06:40:59.379-04:00</updated><title type='text'>Nikola Tesla Day</title><content type='html'>&lt;blockquote&gt;   &lt;p&gt;&lt;em&gt;Nikola Tesla is the true unsung prophet of the electronic age; without whom our radio, auto ignition, telephone, alternating current power generation and transmission, radio and television would all have been impossible.&lt;/em&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;blockquote&gt;   &lt;p&gt;Ben Johnston, &lt;i&gt;My Inventions : The Autobiography of Nikola Tesla&lt;/i&gt; (1983)&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;In my adult life, when I learn of some fact of history that has been twisted or omitted&amp;#160; – it always takes me by surprise.&amp;#160; The rock band Tesla was the first time that I heard about Nikola Tesla.&amp;#160; That was in 1990, when their live acoustic album, Five Man Acoustical Jam was released, which contained the &amp;quot;Love Song.&amp;quot;&amp;#160; Around that same time, I was visiting &lt;a href="http://en.wikipedia.org/wiki/Karlovy_Vary"&gt;Carlsbad, Czech Republic&lt;/a&gt;.&amp;#160; The hotel room had a radio that actually had the name &lt;a href="http://www.oldradio.cz/english.htm"&gt;Tesla&lt;/a&gt; on it.&amp;#160;&amp;#160; &lt;/p&gt;  &lt;p&gt;This really caught my interest and I have studied Nikola Tesla throughout the years.&amp;#160; One fact that astonished me was that he sold his patents for the polyphase alternating current system of generators, motors and transformers to George Westinghouse.&amp;#160; It would have made him a wealthy man, but he later released Westinghouse from the contract.&amp;#160; Where would we be today without his inventions and lifelong work?&amp;#160; While this has nothing to do with Information Assurance, sometimes it is good to remember the basics and somewhere in all of this is a lesson on patents or even copyrights.&amp;#160; Happy Nikola Tesla Day!&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;WHAT ARE TESLA'S GREATEST INVENTIONS?&lt;/p&gt;    &lt;p&gt;1. AC polyphase transmission and AC motor in 1887-1888 -- (the world's primary power--electrical and mechanical). (No, not Edison--Tesla has all the US patents for polyphase AC.)&lt;/p&gt;    &lt;p&gt;2. Fundamental circuitry for radio in 1891 -- (providing worldwide communication). (No, not Marconi--Tesla has the defining US patents for radio, upheld by the US Supreme Court.)&lt;/p&gt;    &lt;p&gt;&lt;a href="http://www.ntesla.org/index.php"&gt;More….&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;a href="http://www.ieeeghn.org/wiki/index.php/Nikola_Tesla%2C_A_Prophet_with_Honor%2C_Electricity%27s_Great_Radical"&gt;Oil Power, Nikola Tesla, A Prophet with Honor, Electricity's Great Radical, Volume V, No. 5, June 1930.&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.teslamemorialsociety.org/links.htm"&gt;The Tesla Memorial Society - Links to Other Tesla-related Web Sites&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.tesla.org/"&gt;The Tesla Foundation of North America (TFNA)&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.pbs.org/tesla/"&gt;PBS: Tesla – Master of Lightning&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;a href="http://web.mit.edu/most/Public/Tesla1/alpha_tesla.html"&gt;The Complete Nikola&amp;#160; Tesla U.S. Patent Collection - Title Order&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/387318336536837178-53329702413479277?l=faithyoung.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://faithyoung.blogspot.com/feeds/53329702413479277/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://faithyoung.blogspot.com/2009/07/nikola-tesla-day.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/53329702413479277'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/53329702413479277'/><link rel='alternate' type='text/html' href='http://faithyoung.blogspot.com/2009/07/nikola-tesla-day.html' title='Nikola Tesla Day'/><author><name>Faith Young</name><uri>http://www.blogger.com/profile/04686761912731944625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-387318336536837178.post-4141010088168783163</id><published>2009-07-02T05:32:00.001-04:00</published><updated>2009-07-02T05:32:33.076-04:00</updated><title type='text'>Sunbelt Software – New Partner of StopBadware.org</title><content type='html'>&lt;p&gt;This is great news!&amp;#160; I have been a longtime advocate for all the work that they do at Sunbelt Software.&amp;#160; &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;StopBadware.org, Sunbelt Software partner to fight badware&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;New Data Will Allow Broader Reach, Richer Analysis&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;CAMBRIDGE, Mass., June 30, 2009&lt;/em&gt; — StopBadware.org, the collaborative initiative to combat viruses, spyware, and other bad software, announced today that Sunbelt Software, developer of the VIPRE anti-malware product line, will participate in the effort as a data partner. Sunbelt Software joins Google in contributing data to the project, which is based at Harvard University’s Berkman Center for Internet &amp;amp; Society. The initiative is funded by Google, PayPal, Mozilla, AOL, and Trend Micro.&lt;/p&gt;    &lt;p&gt;Hundreds of thousands of websites—some might count them in the millions—are associated with the distribution of badware. Some are deliberately malicious, trying to trick users into installing a virus on their computers, while others are legitimate websites that have been tampered with, putting the site’s visitors at risk. In the most egregious cases, such sites can infect computers with vulnerable software simply by a user browsing to the page, a practice known as drive-by downloads.&lt;/p&gt;    &lt;p&gt;StopBadware.org collects the URLs of these badware websites, whether malicious or compromised, from its data partners. It uses the information to support and encourage site owners and web hosting companies in cleaning up and protecting their sites. The initiative also conducts analysis of infection trends, offers independent reviews of its partners’ findings, and operates a community website, BadwareBusters.org, that provides help to people who have been victims—or wish to avoid becoming victims—of badware.&lt;/p&gt;    &lt;p&gt;“We are thrilled that a well-respected anti-malware company like Sunbelt Software has come on board as a data partner,” said Maxim Weinstein, manager of StopBadware.org. “The new data offers us a different view of the badware website landscape and will help us to extend our reach and to provide richer analysis.”&lt;/p&gt;    &lt;p&gt;&lt;a href="http://www.stopbadware.org/home/pr_06302009"&gt;More………&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/387318336536837178-4141010088168783163?l=faithyoung.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://faithyoung.blogspot.com/feeds/4141010088168783163/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://faithyoung.blogspot.com/2009/07/sunbelt-software-new-partner-of.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/4141010088168783163'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/4141010088168783163'/><link rel='alternate' type='text/html' href='http://faithyoung.blogspot.com/2009/07/sunbelt-software-new-partner-of.html' title='Sunbelt Software – New Partner of StopBadware.org'/><author><name>Faith Young</name><uri>http://www.blogger.com/profile/04686761912731944625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-387318336536837178.post-8988610516332267038</id><published>2009-06-15T05:03:00.001-04:00</published><updated>2009-06-15T05:07:32.444-04:00</updated><title type='text'>Phishing Toolkits</title><content type='html'>&lt;p&gt;&lt;font size="2"&gt;News-&lt;/font&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;&lt;font size="2"&gt;Use of phishing toolkits on the rise &lt;/font&gt;&lt;/strong&gt;&lt;/p&gt;   &lt;strong&gt;&lt;/strong&gt;    &lt;p&gt;&lt;font size="2"&gt;&lt;em&gt;iTWire, &lt;/em&gt;&lt;em&gt;by Peter Dinham, 14 June 2009&lt;/em&gt;&amp;#160; &lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font size="2"&gt;There’s been a huge increase in the use of phishing toolkits, with 42 percent of phishing URLs last month generated using the toolkits, and the emergence of a new trend of phishing attacks towards the popular social networking site, Facebook.&lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font size="2"&gt;Symantec, in its June phishing report, says it observed an increase in URLs using phishing toolkits during May of 100 percent over the previous month, with a 14 percent decrease in non-English phishing sites compared to February.&lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font size="2"&gt;The security firm also reports that during May, more than 98 Web hosting services were used, which accounted for six percent of all phishing attacks, which was a decrease of five percent from the previous month.&lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;font size="2"&gt;David Cowings, executive editor security response at Symantec, says phishing sites were categorized based upon the domains they leveraged and “a considerable increase was seen in the number of phishing sites using automated toolkits,” and, he adds, “this increase was a result of a large toolkit attack targeting an information services brand.”&lt;/font&gt;&lt;/p&gt;    &lt;p&gt;&lt;a href="http://www.itwire.com/content/view/25643/53/"&gt;&lt;font size="2"&gt;More&lt;/font&gt;&lt;/a&gt;&lt;font size="2"&gt;.......&lt;/font&gt;&lt;/p&gt;&lt;/blockquote&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/387318336536837178-8988610516332267038?l=faithyoung.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://faithyoung.blogspot.com/feeds/8988610516332267038/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://faithyoung.blogspot.com/2009/06/phishing-toolkits.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/8988610516332267038'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/8988610516332267038'/><link rel='alternate' type='text/html' href='http://faithyoung.blogspot.com/2009/06/phishing-toolkits.html' title='Phishing Toolkits'/><author><name>Faith Young</name><uri>http://www.blogger.com/profile/04686761912731944625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-387318336536837178.post-5439232073182103672</id><published>2009-06-14T09:54:00.001-04:00</published><updated>2009-06-14T09:54:50.955-04:00</updated><title type='text'>Medical Identity Theft</title><content type='html'>&lt;p&gt;Medical identity theft is more devastating to the victim than traditional financial identity theft.&amp;#160; This article from the New York Times explains some of the known affects of this crime and the bureaucratic process to fix the erroneous information in medical or health insurance records.&amp;#160; &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;Medical Problems Could Include Identity Theft&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;New York Times&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;By Walecia Konrad, June 12, 2009 &lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;Excerpt……&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;The last time federal data on the crime was collected, for a 2007 report, more than 250,000 Americans a year were victims of medical identity theft. That number has almost certainly increased since then, because of the increased use of electronic medical records systems built without extensive safeguards, said Pam Dixon, executive director of the nonprofit World Privacy Forum and author of &lt;a href="http://www.worldprivacyforum.org/pdf/wpf_medicalidtheft2006.pdf"&gt;a report&lt;/a&gt; on medical identity theft. &lt;/p&gt;    &lt;p&gt;And uncountable, Ms. Dixon said, are the people who do not yet know they are victims. They may not know that their medical information has been tampered with for months or even years until, as in Mr. Sharp’s case, it shows up in collections on a credit report. &lt;/p&gt;    &lt;p&gt;Medical identity theft takes many guises. In Mr. Sharp’s case, someone got hold of his name and Social Security number and used them to receive emergency medical services, which many hospitals are obliged to provide whether or not a person has insurance. Mr. Sharp still does not know whether he fell victim to one calamitous perp who ended up in several emergency rooms or a ring of accident-prone conspirators. &lt;/p&gt;    &lt;p&gt;In another variant of the crime, someone can use stolen insurance information, like the basic member ID and group policy number found on insurance cards, to impersonate you — and receive everything from a routine physical to major surgery under your coverage. This is surprisingly easy to do, because many doctors and hospitals do not ask for identification beyond insurance information. &lt;/p&gt;    &lt;p&gt;Even more common, however, are cases where medical information is stolen by insiders at a medical office. Thieves download vital personal insurance data and related information from the operation’s computerized medical records, then sell it on the black market or use it themselves to make fraudulent billing claims. &lt;/p&gt;    &lt;p&gt;&lt;em&gt;and…..&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;And there are none of the consumer protections for medical identity theft victims that exist for traditional identity theft. Under the Fair Credit Reporting Act you can get a free copy of your credit report each year, put a fraud alert on your account and get erroneous charges deleted from your record. If your credit card is stolen and the thief goes on a spending spree, you’re not liable for more than $50 worth of the charges. &lt;/p&gt;    &lt;p&gt;With medical identity theft, though, the fraudulent charges can remain unpaid and unresolved for years, permanently damaging your credit rating. Under the federal law known as HIPAA — the Health Insurance Portability and Accountability Act — you are entitled to a copy of your medical records, but you may have to pay a hefty fee for them. &lt;/p&gt;    &lt;p&gt;Worse, HIPAA privacy rules can actually work against you. Once your medical information is intermingled with someone else’s, you may have trouble accessing your files. Privacy laws dictate that the thief’s medical information now contained in your records must be kept confidential, too. &lt;/p&gt;    &lt;p&gt;Even when you are able to correct a record, say in your doctor’s office, the erroneous information may have been passed on to dozens of other health care providers and insurers. Victims must track down and resolve these errors largely on a case-by-case basis, Ms. Dixon says.&lt;/p&gt;    &lt;p&gt;&lt;a href="http://www.nytimes.com/2009/06/13/health/13patient.html?ref=health"&gt;More&lt;/a&gt;…….&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;The &lt;a href="http://www.ftc.gov/opa/2009/04/redflagsrule.shtm"&gt;FTC Red Flags rule&lt;/a&gt; require&amp;#160; entities&amp;#160; with covered accounts to implement programs to identify, detect, and respond to patterns, practices, or specific activities that could indicate identity theft.&amp;#160; This will add another layer of consumer protection against identity theft and greatly expand the reach of the FTC, helping consumers fight fraud.&amp;#160; &lt;/p&gt;  &lt;p&gt;I would think that the providers of health care would be the first line of defense in preventing medical identity theft.&amp;#160; The American Medical Association (AMA) is making efforts to &lt;a href="http://www.ama-assn.org/ama/no-index/physician-resources/red-flags-rule.shtml"&gt;persuade&lt;/a&gt; the FTC that doctors are not “creditors.”&amp;#160; While the enforcement of the Red Flags rule has been postponed twice (November 2008 – original date, May 2009, and August 2009), the FTC has made it clear (see below:&amp;#160;&amp;#160; The “Red Flags” Rule: What Health Care Providers Need to Know About Complying with New Requirements for Fighting Identity Theft) that the Red Flags rule is based on each individual business.&amp;#160; Only after considering the definition of a “creditor” and “a covered account” can they determine the type of program that must be implemented, based on the risk of identity theft.&amp;#160;&amp;#160; &lt;/p&gt;  &lt;p&gt;These are references that relate to the Red Flags rule.&amp;#160;&amp;#160; &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Health care and the Red Flags rule- &lt;/p&gt;    &lt;p&gt;-&lt;a href="http://www.ftc.gov/bcp/edu/pubs/articles/art11.shtm"&gt;The “Red Flags” Rule: What Health Care Providers Need to Know About Complying with New Requirements for Fighting Identity Theft&lt;/a&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;The FTC, &lt;/em&gt;&lt;em&gt;by Steven Toporoff, May 2009&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;-Hot Issues Alerts - Law Firms:&amp;#160; &lt;a href="http://www.metrocorpcounsel.com/current.php?artType=view&amp;amp;artMonth=June&amp;amp;artYear=2009&amp;amp;EntryNo=9780"&gt;Do The FTC Red Flag Rules Apply To You? What Health Care Companies Should Know About The New FTC Requirements To Prevent Identity Theft&lt;/a&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;The Metropolitan Corporate Counsel, &lt;/em&gt;&lt;em&gt;H. Carol Saul and EpsteinBeckerGreen, 1 June, 2009&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;The FTC&amp;#160; - &lt;/p&gt;    &lt;p&gt;&lt;a href="http://www.ftc.gov/bcp/edu/microsites/redflagsrule/index.shtml"&gt;Fighting Fraud with the Red Flags rule&lt;/a&gt;&amp;#160;&lt;/p&gt;    &lt;p&gt;&lt;a href="http://www.ftc.gov/bcp/edu/microsites/redflagsrule/get-started.shtm"&gt;Do-It-Yourself Program for Businesses at Low Risk For Identity Theft&lt;/a&gt;&lt;/p&gt;    &lt;p&gt;The World Privacy Forum - &lt;a href="http://www.worldprivacyforum.org/medicalidentitytheft.html"&gt;The Medical Identity Theft Information Page&lt;/a&gt; &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;An unanswered question - Do ID Theft protection services even provide coverage for medical identity theft?&amp;#160; &lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/387318336536837178-5439232073182103672?l=faithyoung.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://faithyoung.blogspot.com/feeds/5439232073182103672/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://faithyoung.blogspot.com/2009/06/medical-identity-theft.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/5439232073182103672'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/5439232073182103672'/><link rel='alternate' type='text/html' href='http://faithyoung.blogspot.com/2009/06/medical-identity-theft.html' title='Medical Identity Theft'/><author><name>Faith Young</name><uri>http://www.blogger.com/profile/04686761912731944625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-387318336536837178.post-7573127831197036663</id><published>2009-06-03T10:15:00.002-04:00</published><updated>2009-06-03T10:45:11.775-04:00</updated><title type='text'>Why I Fight Phish</title><content type='html'>&lt;p&gt;Volunteering to help other people comes naturally to me.  At a point, I had been researching Volunteerism and came upon this quote:   &lt;em&gt;I am only one, but still I am one. I cannot do everything, but still I can do something. And because I cannot do everything, I will not refuse to do something that I can do.  &lt;/em&gt;&lt;a href="http://en.wikiquote.org/wiki/Edward_Everett_Hale"&gt;Edward Everett Hale&lt;/a&gt;, Ten Times One is Ten (1870)  The funny (ironically speaking) part of it was that it was a 13-year old boy,  Trevor Ferrell of Philadelphia, Pennsylvania that repeated that quote to &lt;a href="http://www.reagan.utexas.edu/archives/speeches/1985/42585a.htm"&gt;President Regan&lt;/a&gt; as he received a Presidential certificate for Volunteerism.  He started out by taking blankets to the homeless on a cold winter’s day and that spark grew into &lt;a href="http://www.trevorscampaign.org/"&gt;Trevor’s Place&lt;/a&gt;.  The point is that anyone can make a difference in the life of others and when you volunteer for something, it is better if it is for something you are interested in.  This is even true when you apply that interest to learning or work.&lt;/p&gt;&lt;p&gt;Back in 2006 when the PIRT initiative was announced, I knew that it was something that I wanted to contribute my time to.  The first reason was that it was in my opinion a great idea:  to send out take-down notices for phishing and keep a public repository of the reports.  Private citizens could submit email that is only normally deleted, erasing valuable evidence of a crime.   Secondly, it was the military MyPay phishes that hit home for me. To target these Soldiers who give up so many things just to serve our country is like a slap in the face.  Last but not least, I had the desire and willingness to learn.  What I learned from the experience is that even the little guy (a figure of speech - small business owner, forums, personal websites, etc.) needs help from time to time and no one reached out to them in this aspect for free (at that time). &lt;/p&gt;&lt;p&gt;This PC World article highlights Gary Warner’s career up to 2007.  It also backs up my claim that even one private citizen can make a difference.  &lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;&lt;strong&gt;Digital Vigilantes: The White Knight of Phish-Busting&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;PC World, 24 Dec 2007&lt;/em&gt;&lt;/p&gt;&lt;p&gt;Warner is now focusing on fighting cyber-crime full-time and on training a new generation of network forensics investigators. "You wouldn't believe the looks on their eyes the first time they got an email back from a Webmaster saying, 'Thanks for letting me know. I just shut that down.'"&lt;/p&gt;&lt;p&gt;When he spoke with IDG News, it was five days after final exams at the University of Alabama at Birmingham and though it would have no effect on their marks, four students were still coming into the labs to help shut down phishers.&lt;/p&gt;&lt;p&gt;"That idea that as a private citizen, you can help, that's the kind of thing we're trying to inspire," he said.&lt;/p&gt;&lt;p&gt;&lt;a href="http://pcworld.about.com/od/cybercrime/Digital-Vigilantes-The-White.htm"&gt;More&lt;/a&gt;………&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;I am a member at &lt;a href="http://www.phishtank.com/"&gt;PhishTank&lt;/a&gt; and &lt;a href="https://www.digitalphishnet.org/Default.aspx"&gt;Digital PhishNet&lt;/a&gt; (DPN).   I do support the Anti‐Phishing Working Group (APWG), just not as member because I do not belong to any of the member organizations or have the required email address.  I wish that they would allow independent security researchers that are not a non-profit organization.  The APWG does provide expert advice to the little guy. &lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;&lt;strong&gt;What to Do if Your Web Site Has Been Hacked by Phishers&lt;/strong&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;p&gt;&lt;em&gt;APWG, January 2009 &lt;/em&gt;&lt;/p&gt;&lt;p&gt;You may receive a notice by phone or email from an individual or organization that claims knowledge of an attack. Obtain as much information from the third party as possible, including:&lt;/p&gt;&lt;p&gt;a) The person’s name&lt;/p&gt;&lt;p&gt;b) Name of their organization&lt;/p&gt;&lt;p&gt;c) Return contact information (phone, email, postal address, organization’s web site)&lt;/p&gt;&lt;p&gt;d) Web page(s), including the URL (link) the party alleges to be a phish web site&lt;/p&gt;&lt;p&gt;e) Nature of attack (attempt to steal personal information, to complete a bogus credit card transaction, to obtain user account credentials, etc.)&lt;/p&gt;&lt;p&gt;f) A description of any malicious content that appears to be downloadable from your web site (e.g., spyware)&lt;/p&gt;&lt;p&gt;&lt;em&gt;and……&lt;/em&gt;&lt;/p&gt;&lt;p&gt;APWG encourages you to report the phishing site URL to the APWG via the email address reportphishing@antiphishing.org. Reporting to this address will cause most anti‐phishing organizations to receive a notification of the phishing web site. Security products, e.g., anti‐phishing toolbars, will be updated with the offending URL, thus offering protection to thousands, if not millions of potential victims.&lt;/p&gt;&lt;p&gt;&lt;em&gt;and…..&lt;/em&gt;&lt;/p&gt;&lt;p&gt;The APWG provides a standard “you've been phished!” redirection page and instructions for its use at &lt;a href="http://education.apwg.org/r/about.html"&gt;http://education.apwg.org/r/about.html&lt;/a&gt;. This strategy will prevent further use of the phishing site, keep your customers informed, keep your web site online for real time analysis, and afford you additional time to perform containment actions.&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.antiphishing.org/reports/APWG_WTD_HackedWebsite.pdf"&gt;More&lt;/a&gt;………..&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Even with CastleCops and PIRT &lt;a href="http://faithyoung.blogspot.com/2009/04/beacon-of-light.html"&gt;gone&lt;/a&gt;, there are still ways to fight phishing on a daily basis.  The volunteer opportunities do exist as long as the volunteer is interested and willing to learn.  If ten people send a take-down request to the ISP for ten different phish, ten fraudulent websites will be able to remove that content, investigate the crime, and update their servers.  If a modest estimate that each phish could have led to twelve cases of ID Theft, 120 people could be spared this.  &lt;em&gt;Ten Times One is Ten&lt;/em&gt;.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/387318336536837178-7573127831197036663?l=faithyoung.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://faithyoung.blogspot.com/feeds/7573127831197036663/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://faithyoung.blogspot.com/2009/06/why-i-fight-phish.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/7573127831197036663'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/7573127831197036663'/><link rel='alternate' type='text/html' href='http://faithyoung.blogspot.com/2009/06/why-i-fight-phish.html' title='Why I Fight Phish'/><author><name>Faith Young</name><uri>http://www.blogger.com/profile/04686761912731944625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-387318336536837178.post-1993008232285961115</id><published>2009-05-29T06:29:00.001-04:00</published><updated>2009-05-29T06:29:26.569-04:00</updated><title type='text'>The Word Hacked</title><content type='html'>&lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;The Scrap Value of a Hacked PC&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;Security Fix - Brian Krebs, May 26, 2009&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;Computer users often dismiss Internet security best practices because they find them inconvenient, or because they think the rules don't apply to them. Many cling to the misguided belief that because they don't bank or shop online, that bad guys won't target them. The next time you hear this claim, please refer the misguided person to this blog post, which attempts to examine some of the more common -- yet often overlooked -- ways that cyber crooks can put your PC to criminal use.&lt;/p&gt;    &lt;p&gt;&lt;a href="http://voices.washingtonpost.com/securityfix/2009/05/the_scrap_value_of_a_hacked_pc.html#comments"&gt;More here&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;I think that I understand why Brian Krebs used the word hacked in this blog post on Security fix.&amp;#160; He wanted to reach out to the public and especially to people who say, I don’t have anything on my computer that is of any value to a cyber-criminal.&amp;#160; To reach out to them with this very useful information, it is understandable that you must use basic terms.&amp;#160; Terms that anyone can relate to in order to gain knowledge. &lt;/p&gt;  &lt;p&gt;The word hacked brings up the controversy of the word hacker or cracker to me.&amp;#160; My personal opinion is that you should call people by their name.&amp;#160; An example of this is that an Identity Thief steals identities.&amp;#160; An Identity Thief can be further categorized as a cyber-criminal, if they use a computer to commit the crime.&amp;#160; The word hacker is best described by Bruce Schneier in his book “Beyond Fear.”&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Hackers are as old as curiosity, although the term itself is modern. Galileo was a hacker. Mme. Curie was one, too. Aristotle wasn't. (Aristotle had some theoretical proof that women had fewer teeth than men. A hacker would have simply counted his wife's teeth. A good hacker would have counted his wife's teeth without her knowing about it, while she was asleep. A good bad hacker might remove some of them, just to prove a point.)&amp;#160;&amp;#160; &lt;a title="http://www.schneier.com/crypto-gram-0609.html#12" href="http://www.schneier.com/crypto-gram-0609.html#12"&gt;Bruce Schneier&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;My husband had a great idea of getting out of Canada as fast as we could on way home from Alaska. His plan was to cut down to the United States from Calgary instead of Winnipeg. We came out in Montana and drove Highway 90 through Wyoming and South Dakota. I will never forget that leg of the journey because we ended up driving through Sturgis, South Dakota in August. I do not know anything about motorcycles , but to see that many Harleys in one location is a breathtaking event. The reason I mention this story was that the motorcycle enthusiasts that flock to Sturgis once a year come from all different professions and have had bad encounters with the media. This led me to realize that they could be compared to hackers in the sense that you cannot judge the entire group only by the ones that receive bad press. &lt;/p&gt;  &lt;p&gt;I could name just as many good hackers as bad hackers, but understand that anyone can learn many valuable lessons from both of them.&amp;#160; This in itself is a double edged sword.&amp;#160; &lt;em&gt;Human beings, who are almost unique in having the ability to learn from the experience of others, are also remarkable for their apparent disinclination to do so.&lt;/em&gt;&amp;#160; &lt;a href="http://www.wisdomquotes.com/001322.html"&gt;Douglas Adams&lt;/a&gt; &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;a href="http://voices.washingtonpost.com/securityfix/2009/05/the_scrap_value_of_a_hacked_pc.html#comments"&gt;&amp;#160;&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/387318336536837178-1993008232285961115?l=faithyoung.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://faithyoung.blogspot.com/feeds/1993008232285961115/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://faithyoung.blogspot.com/2009/05/word-hacked.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/1993008232285961115'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/1993008232285961115'/><link rel='alternate' type='text/html' href='http://faithyoung.blogspot.com/2009/05/word-hacked.html' title='The Word Hacked'/><author><name>Faith Young</name><uri>http://www.blogger.com/profile/04686761912731944625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-387318336536837178.post-1133642760346332666</id><published>2009-05-28T05:38:00.001-04:00</published><updated>2009-05-28T05:38:19.326-04:00</updated><title type='text'>Gmail - Enabling the HTTPS setting</title><content type='html'>&lt;p&gt;I have been wanting to write about this for a while.&amp;#160; When you send an email without the encrypted settings set in Gmail, your email messages can be read in plain text during transit.&amp;#160; If you use web-based email it is better from a security or privacy perspective to use &lt;a href="http://en.wikipedia.org/wiki/Https"&gt;HTTPS&lt;/a&gt; (if it is available).&amp;#160; This point can be can be argued both ways, but the basis of &lt;a href="http://en.wikipedia.org/wiki/Defense_in_Depth_(computing)"&gt;Defense in Depth&lt;/a&gt; is that your use a layered approach and avoid a single point of failure.&amp;#160; &lt;/p&gt;  &lt;blockquote&gt;   &lt;ol&gt;     &lt;p&gt;&lt;em&gt;Updated 29 April 2009&lt;/em&gt;&lt;/p&gt;      &lt;p&gt;If you sign in to Gmail via a non-secure Internet connection, like a public wireless or non-encrypted network, your Google account may be more vulnerable to hijacking. Non-secure networks make it easier for someone to impersonate you and gain full access to your Google account, including any sensitive data it may contain like bank statements or online log-in credentials. We recommend selecting the 'Always use https' option in Gmail any time your network may be non-secure. HTTPS, or Hypertext Transfer Protocol Secure, is a secure protocol that provides authenticated and encrypted communication.&lt;/p&gt;      &lt;p&gt;-To enable this feature in Gmail:&lt;/p&gt;      &lt;ol&gt;&lt;/ol&gt;      &lt;li&gt;       &lt;p&gt;Sign in to Gmail. &lt;/p&gt;     &lt;/li&gt;      &lt;li&gt;       &lt;p&gt;Click &lt;strong&gt;Settings&lt;/strong&gt; at the top of any Gmail page. &lt;/p&gt;     &lt;/li&gt;      &lt;li&gt;       &lt;p&gt;Set 'Browser Connection' to 'Always use https.' &lt;/p&gt;     &lt;/li&gt;      &lt;li&gt;       &lt;p&gt;Click &lt;strong&gt;Save Changes&lt;/strong&gt;. &lt;/p&gt;     &lt;/li&gt;      &lt;li&gt;       &lt;p&gt;Reload Gmail.&lt;/p&gt;     &lt;/li&gt;      &lt;ol&gt;&lt;/ol&gt;      &lt;p&gt;More &lt;a title="http://mail.google.com/support/bin/answer.py?hl=en&amp;amp;ctx=mail&amp;amp;answer=74765" href="http://mail.google.com/support/bin/answer.py?hl=en&amp;amp;ctx=mail&amp;amp;answer=74765"&gt;here&lt;/a&gt;&lt;/p&gt;   &lt;/ol&gt; &lt;/blockquote&gt;  &lt;p&gt;Please read the warnings and incompatibilities from the Gmail support page.&amp;#160; Number three of the steps above is under the General tab and located at the bottom of the page.&amp;#160; &lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/387318336536837178-1133642760346332666?l=faithyoung.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://faithyoung.blogspot.com/feeds/1133642760346332666/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://faithyoung.blogspot.com/2009/05/gmail-enabling-https-setting.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/1133642760346332666'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/1133642760346332666'/><link rel='alternate' type='text/html' href='http://faithyoung.blogspot.com/2009/05/gmail-enabling-https-setting.html' title='Gmail - Enabling the HTTPS setting'/><author><name>Faith Young</name><uri>http://www.blogger.com/profile/04686761912731944625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-387318336536837178.post-6680863923884602047</id><published>2009-05-22T05:52:00.001-04:00</published><updated>2009-05-22T05:52:54.019-04:00</updated><title type='text'>TechBite Highlights PC Pitstop</title><content type='html'>&lt;p&gt;TechBite Technology is Steve Bass's Weekly Newsletter.&amp;#160; I have read and enjoyed many of his PCWorld articles over the years.&amp;#160; This week he highlights PC Pitstop’s Full Tests&amp;#160; and other free tools.&amp;#160; If you are familiar with PC Pitstop, they are in the process of transitioning from the old &lt;a href="http://www.pcpitstop.com/pcpitstop/default.asp"&gt;Full Tests&lt;/a&gt; to &lt;a href="http://pcpitstop.com/betapit/"&gt;OverDrive&lt;/a&gt;.&amp;#160;&amp;#160; &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;Free Super Sites and Tools to Test Your PC&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;By Steve Bass, Newsletter #29, 20 May 2009&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;Are you sure your PC's healthy? Think back to when you heard that kerchunk sound coming from your hard drive. Or the last time your Internet connection was down -- and I don't mean just suffering from the blues. My advice: Check inside your computer's case with these free diagnostic tools and see if anything's amiss before disaster strikes.&lt;/p&gt;    &lt;p&gt;-PC Pitstop: The Best of the Best&lt;/p&gt;    &lt;p&gt;There are lots of testing sites around, but if you want to visit just one site to test your PC, I'd recommend PC Pitstop.&lt;/p&gt;    &lt;p&gt;More &lt;a href="http://www.techbite.com/newsletter/29/free-super-sites-and-tools-to-test-your-pc"&gt;here&lt;/a&gt;…..&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;PC Pitstop has a great forum with friendly staff and members.&amp;#160; Even if you think that you cannot learn anything about computers, PC Pitstop is the place to go to learn.&amp;#160; If you encounter problems running OverDrive, this is their &lt;a href="http://forums.pcpitstop.com/index.php?showforum=2"&gt;forum&lt;/a&gt; for help.&amp;#160; If you need help interpreting the results or have any questions about the test, go &lt;a href="http://forums.pcpitstop.com/index.php?showforum=6"&gt;here&lt;/a&gt;.&amp;#160; They allow you to run the test anonymously, but if you wish to post in these forums or provide a &lt;a href="http://www.pcpitstop.com/techexpress/howto.asp"&gt;TechExpress&lt;/a&gt; link you must be a registered member first.&amp;#160;&amp;#160; &lt;/p&gt;  &lt;p&gt;This is from Steve’s &lt;em&gt;Time Waster &lt;/em&gt;section. The video shows lighthouses in a very different light.&lt;/p&gt;  &lt;p&gt;&lt;a title="http://stevebass.posterous.com/so-you-want-to-live-in-a-lighthouse" href="http://stevebass.posterous.com/so-you-want-to-live-in-a-lighthouse"&gt;http://stevebass.posterous.com/so-you-want-to-live-in-a-lighthouse&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;You can subscribe to TechBite &lt;a href="http://www.techbite.com/"&gt;here&lt;/a&gt;.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/387318336536837178-6680863923884602047?l=faithyoung.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://faithyoung.blogspot.com/feeds/6680863923884602047/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://faithyoung.blogspot.com/2009/05/techbite-highlights-pc-pitstop.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/6680863923884602047'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/6680863923884602047'/><link rel='alternate' type='text/html' href='http://faithyoung.blogspot.com/2009/05/techbite-highlights-pc-pitstop.html' title='TechBite Highlights PC Pitstop'/><author><name>Faith Young</name><uri>http://www.blogger.com/profile/04686761912731944625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-387318336536837178.post-8939459358843055798</id><published>2009-05-15T05:47:00.001-04:00</published><updated>2009-05-15T05:47:41.502-04:00</updated><title type='text'>SpywareHammer – Social Media Security Forum</title><content type='html'>&lt;p&gt;&lt;a href="http://spywarehammer.com/"&gt;SpywareHammer&lt;/a&gt; is a great new anti-spyware forum.&amp;#160; They went live in September 2008 and currently have over 2000 registered members.&amp;#160; The experts will happily assist you with malware removal and more.&amp;#160; They have HJT, Rootkit Removal, Hardware, and Software troubleshooting.&amp;#160; Bugbatter is an Administrator at SpywareHammer and a fellow Microsoft Consumer Security MVP.&amp;#160; She has created a dedicated forum for &lt;a href="http://spywarehammer.com/simplemachinesforum/index.php?board=97.0"&gt;Social Media Security&lt;/a&gt; at SpywareHammer.&amp;#160;&amp;#160; Her latest two posts highlighted Facebook and were from the article excerpts below.&amp;#160; &lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;&lt;a href="http://spywarehammer.com/simplemachinesforum/index.php?topic=3428.0"&gt;New Websense Security Labs Research Finds Cybercriminals Imitating Social Networks to Spread Malware&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;Fraudsters Create Hundreds of Thousands of Facebook Clones to Target Users at Work&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;SAN DIEGO, CA, May 13, 2009 (MARKETWIRE via COMTEX News Network) -- Websense, Inc. (NASDAQ: WBSN) &lt;/em&gt;today released the results of &lt;a href="http://securitylabs.websense.com/content/Blogs/3397.aspx?cmpid=prnr"&gt;new research conducted by Websense Security Labs&lt;sup&gt;™&lt;/sup&gt;&lt;/a&gt; that reveals a growing domain-name cloning trend among cybercriminals seeking to take advantage of the huge number of social networking users, particularly those using Facebook, MySpace and Twitter. &lt;/p&gt;    &lt;p&gt;Criminals are increasingly using domain names that include words like Facebook, MySpace and Twitter, with no official connection to the real sites, to trick unsuspecting visitors to visit fake Web sites and lure them to input sensitive information or download malicious code. In fact, Websense Security Labs research indicates that in a research sample taken from the Websense URL database, more than 200,000 phony copycat sites were found, all using the terms Facebook, MySpace or Twitter in their URLs. Examples similar to samples found include, unblock.facebookproxy.com, buy.viagra.twitter.1234.com or hotbabesofmyspace999.com (note these are just sample site names that are similar to the sites researchers found). &lt;/p&gt;    &lt;p&gt;Further research shows that the hackers are taking steps to create these cloned domains to circumvent security measures put in place by organizations to filter the original domain in a business setting. Many of the domains are proxy avoidance sites which are used to try to evade traditional Web filtering technology. &lt;/p&gt;    &lt;p&gt;&lt;a href="http://investor.websense.com/releasedetail.cfm?ReleaseID=383928"&gt;More……&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;and-&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;&lt;a href="http://spywarehammer.com/simplemachinesforum/index.php?topic=3420.0"&gt;The Inside Facebook Guide to Protecting Your Privacy on Facebook&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;by Jessica Lee May 13th, 2009&lt;/em&gt;&lt;/p&gt;    &lt;p&gt;Now that everyone from family to colleagues are connecting on Facebook, how do you continue sharing freely while maintaining your privacy and reputation in the years to come?&lt;/p&gt;    &lt;p&gt;Facebook allows users to customize their privacy settings at a granular level, but a surprisingly low percentage of users actively manage their privacy settings. Many users who complain about the lack of privacy on Facebook aren’t even aware of the privacy configurations available to them. Below, Inside Facebook guides you through all the steps you need to know to protect your privacy on Facebook.&lt;/p&gt;    &lt;p&gt;&lt;a href="http://www.insidefacebook.com/2009/05/13/facebook-privacy-guide/"&gt;More…..&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;While these articles are about FaceBook, the discussions can cover any Social Media applications.&amp;#160; I will see a news article and go to post it only to find that Bugbatter has beaten me to it.&amp;#160; Keep up the great work!&amp;#160; Please feel free to register at SpywareHammer and comment, discuss any concerns, contribute your own lessons learned, or ask questions.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/387318336536837178-8939459358843055798?l=faithyoung.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://faithyoung.blogspot.com/feeds/8939459358843055798/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://faithyoung.blogspot.com/2009/05/spywarehammer-social-media-security.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/8939459358843055798'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/8939459358843055798'/><link rel='alternate' type='text/html' href='http://faithyoung.blogspot.com/2009/05/spywarehammer-social-media-security.html' title='SpywareHammer – Social Media Security Forum'/><author><name>Faith Young</name><uri>http://www.blogger.com/profile/04686761912731944625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-387318336536837178.post-5601346239545892109</id><published>2009-05-03T08:04:00.001-04:00</published><updated>2009-05-03T08:04:38.914-04:00</updated><title type='text'>Microsoft Windows 7 Release Candidate</title><content type='html'>&lt;p align="left"&gt;I am very interested in Beta Testing.&amp;#160; The valuable lesson that I learned from Office 2007 Beta was that in no circumstances should you ever Beta Test anything on a computer that you are not ready to reformat before installing the final application.&amp;#160; Due to the availability of Windows 7 Release Candidate (RC) and the fact that it will be free for at least a year, I will definitely be testing it.&amp;#160; &lt;/p&gt;  &lt;p align="left"&gt;You can follow the Windows Springboard Series on Twitter (&lt;a href="http://twitter.com/MSspringboard"&gt;MSspringboard&lt;/a&gt;) and this is a link to the &lt;a href="http://technet.microsoft.com/en-us/windows/dd361745.aspx"&gt;Featured Windows 7 Resources&lt;/a&gt; on Microsoft TechNet.&amp;#160; Just keep in mind that you are forewarned that the Windows 7 RC will expire June 1, 2010 and the bi-hourly shutdowns will begin on March 1, 2010.&lt;/p&gt;  &lt;p align="left"&gt;These are two interesting articles that relate to Windows 7 RC.&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;b&gt;Windows 7 setup secrets&lt;/b&gt;       &lt;br /&gt;&lt;i&gt;Ed Bott, May 1st, 2009&lt;/i&gt;       &lt;br /&gt;&lt;/p&gt;    &lt;p&gt;On May 5, the general public will finally be allowed to download the official Windows 7 Release Candidate. It’s been up on BitTorrent networks for more than a week, and developers with MSDN or TechNet subscriptions have had access to it since early this morning. But those groups constitute a tiny fraction of the people who will be seeing the Windows 7 release candidate for the first time next week.&lt;/p&gt;    &lt;p&gt;     &lt;br /&gt;For the benefit of the early adopters and those who patiently wait, I’ve been gathering information on the right and wrong ways to set up Windows 7. For the past week or so I’ve been installing and upgrading the RC code on a wide variety of systems—notebooks and desktops, with and without touch and tablet capabilities, with and without TV tuners and Blu-ray drives, as clean installs and upgrades, in x86 and x64 flavors, documenting the process.&lt;/p&gt;    &lt;p&gt;     &lt;br /&gt;In this post, I want to share seven of the lessons I’ve learned along the way, including a few setup secrets that even some Windows experts don’t know about.&lt;/p&gt;    &lt;p&gt;     &lt;br /&gt;Secret #1: Choose the right Setup option       &lt;br /&gt;Secret #2: Start with a clean disk       &lt;br /&gt;Secret #3: Back up your old drivers first       &lt;br /&gt;Secret #4: Do a nondestructive clean install       &lt;br /&gt;Secret #5: You need less disk space than you think       &lt;br /&gt;Secret #6: Unblock the upgrade path for Windows 7 beta       &lt;br /&gt;Secret #7: Unlock those extra editions       &lt;br /&gt;&lt;/p&gt;    &lt;p&gt;More.........&amp;#160;&amp;#160; &lt;a href="http://blogs.zdnet.com/Bott/?p=922"&gt;here&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;and&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;b&gt;Microsoft to give away free Windows 7 Release Candidate for a year&lt;/b&gt;       &lt;br /&gt;&lt;i&gt;Son Huynh, April 30th 2009&lt;/i&gt;&lt;/p&gt;   &lt;em&gt;&lt;/em&gt;    &lt;p&gt;     &lt;br /&gt;On May 5th, general users will have access to an entire year of Microsoft's brand new operating system, Windows 7 RC, for free! It is already available to download for MSDN and TechNet subscribers. This version is only the Release Candidate and will expire June 1, 2010. The Release Candidate is merely the near finished product and is basically the final stage in testing. It's supposed to have all the features of the final version. We don't know when the final version will be released but rumors say it'll be either late 2009 or early 2010.&lt;/p&gt;    &lt;p&gt;     &lt;br /&gt;A beta version of Windows 7 was released some time ago, and from using it for a short time, I can gather that it was much faster and more friendly than Windows Vista. Indeed for those of you who hated Vista, Windows 7 is Vista done right. Windows 7 boasts a lot of new features including a new taskbar, libraries, jump lists, etc. Windows 7 will also come packaged with the newest Internet Explorer (IE8).&lt;/p&gt;    &lt;p&gt;     &lt;br /&gt;The biggest improvement with Windows 7 is the performance. It will no longer take 5-10 minutes to boot up your machine. Windows 7 now has a much faster startup time, beating out both Vista and XP. We will also see a new feature called Windows XP mode which lets you run native XP programs on your machine.       &lt;br /&gt;People are saying good things about this Windows. Microsoft hopes it will make up for all the bad things about its previous version. I've heard news about IT developers leap-frogging Vista and going straight to 7 in their companies.&lt;/p&gt;    &lt;p&gt;More.... &lt;a href="http://www.mndaily.com/blogs/tech-corner/2009/04/30/microsoft-give-away-free-windows-7-year"&gt;here&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/387318336536837178-5601346239545892109?l=faithyoung.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://faithyoung.blogspot.com/feeds/5601346239545892109/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://faithyoung.blogspot.com/2009/05/microsoft-windows-7-release-candidate.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/5601346239545892109'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/5601346239545892109'/><link rel='alternate' type='text/html' href='http://faithyoung.blogspot.com/2009/05/microsoft-windows-7-release-candidate.html' title='Microsoft Windows 7 Release Candidate'/><author><name>Faith Young</name><uri>http://www.blogger.com/profile/04686761912731944625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-387318336536837178.post-4089995214023042379</id><published>2009-05-02T08:22:00.001-04:00</published><updated>2009-05-02T08:22:00.166-04:00</updated><title type='text'>MVP Spotlight - Hosts File &amp; Other Helpful Topics</title><content type='html'>&lt;p&gt;This is the Microsoft MVP Spotlight for Mike Burgess.&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Security MVP Offers Malware Protection&lt;/strong&gt;&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Consumer Security MVP Mike Burgess's Hosts file continues to lead the fight against malware and security threats from around the world. The internet can be a harsh place to surf, but Mike’s Hosts file for Windows, can be used to block ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and even most web browser hijackers. This is accomplished by blocking the internet connection to malware sites.&lt;/p&gt;    &lt;p&gt;Currently, he has over 10,000 mailing list members, with 126 updates last year, and accolades from Pricelesswarehome.org, and the &amp;quot;Hype-Free&amp;quot; security blog. Mike's contribution towards Windows is a strong piece of armor in the constant fight for internet security.&lt;/p&gt;    &lt;p&gt;Learn more about how the Hosts file can protect Windows users by clicking here.&lt;/p&gt;    &lt;p&gt;&lt;a href="http://www.mvps.org/winhelp2002/hosts.htm"&gt;http://www.mvps.org/winhelp2002/hosts.htm&lt;/a&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;em&gt;From URL: &lt;/em&gt;&lt;a href="http://blogs.msdn.com/mvpawardprogram/archive/2009/04/30/security-mvp-offers-malware-protection.aspx"&gt;http://blogs.msdn.com/mvpawardprogram/archive/2009/04/30/security-mvp-offers-malware-protection.aspx&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;What I thought was neat was that you can select from 11 different helpful topics with the drop down arrow (at the top of the page). This is &lt;em&gt;just a small example&amp;#160; &lt;/em&gt;of what Mike Burgess has to offer, in addition to the invaluable information about the Hosts file.&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;Security Issues for Windows and IE &lt;/strong&gt;&lt;/p&gt;    &lt;p&gt;&lt;em&gt;Practice Safe Hex!&lt;/em&gt;&amp;#160; - Browsing the Internet without protection is just plain foolish!&lt;/p&gt;    &lt;p&gt;It can't be stressed enough on how important it is to keep your system up-to-date. This not only involves Windows Update, but also all the other programs on your machine. The vast majority of user problems (hijacks, adware/spyware) I see are due to failure to keep Windows patched, and lack of a proper &amp;quot;Layer of Protection&amp;quot;.&lt;/p&gt;    &lt;p&gt;-Preventing Vulnerabilities in Windows and Internet Explorer&lt;/p&gt;    &lt;p&gt;* Tighten the Settings in Internet Explorer&lt;/p&gt;    &lt;p&gt;* Do NOT run as Administrator or an account with Administrator privileges&lt;/p&gt;    &lt;p&gt;* Build a Layer of Protection - there are enough freeware products available on the Internet that there is no excuse for not having an adequate defense. Add an anti-spyware program that has &amp;quot;real-time&amp;quot; protection such as Microsoft's Windows Defender (freeware)&lt;/p&gt;    &lt;p&gt;More......&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;&lt;em&gt;From URL: &lt;/em&gt;&lt;a href="http://www.mvps.org/winhelp2002/security.htm"&gt;http://www.mvps.org/winhelp2002/security.htm&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/387318336536837178-4089995214023042379?l=faithyoung.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://faithyoung.blogspot.com/feeds/4089995214023042379/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://faithyoung.blogspot.com/2009/05/mvp-spotlight-hosts-file-other-helpful.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/4089995214023042379'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/4089995214023042379'/><link rel='alternate' type='text/html' href='http://faithyoung.blogspot.com/2009/05/mvp-spotlight-hosts-file-other-helpful.html' title='MVP Spotlight - Hosts File &amp;amp; Other Helpful Topics'/><author><name>Faith Young</name><uri>http://www.blogger.com/profile/04686761912731944625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-387318336536837178.post-7623319668817294054</id><published>2009-04-19T08:00:00.001-04:00</published><updated>2009-04-19T08:00:11.059-04:00</updated><title type='text'>A Beacon of Light</title><content type='html'>&lt;p&gt;I have many mentors because I believe that you can learn something from everyone that will make you better or worse.&amp;#160; The choice is yours to make, along with the consequences of that choice.&amp;#160; One of my mentors once said, “Sunlight is the best disinfectant.”&amp;#160; To me that means exactly that.&amp;#160; Shine a light into the darkness and try to share what is discovered.&amp;#160; In the world of information security this process has been proven time after time.&amp;#160; Change is the only constant.&amp;#160;&amp;#160; &lt;/p&gt;  &lt;p&gt;This is where the name of my blog came from.&amp;#160; Like a lighthouse sitting on top of a cliff, shining it’s light into the dark sea to safely guide the ships away from the danger.&amp;#160; Another well respected mentor of mine told me to write about what interests you.&amp;#160; While I believe in responsible disclosure, if the information is already being written about all over the Internet – the information is already disclosed.&amp;#160; My interests are Information Assurance, Privacy, Information Security, Incident Response, Risk Management, Security Awareness Training, Security Policies, Log Analysis, Security Research, Security Metrics, ID Theft Prevention, Anti-Phishing, Anti-Spam, Anti-Malware, Social Media Security, Ethics in Computing, Beta Testing, and Writing.&lt;/p&gt;  &lt;p&gt;When CastleCops moved on in December 2008, it was a sad day in my life.&amp;#160; Paul, Robin, and all of the staff/members put a great amount of time (along with blood, sweat, &amp;amp; tears) to build CastleCops.&amp;#160;&amp;#160; In my opinion, it became a place on the front lines of the never ending and always changing fight against cyber-criminals.&amp;#160;&amp;#160; The team efforts of PIRT, MIRT, and SIRT were amazing.&amp;#160; I am very proud of my time as a PIRT Handler and fought the good fight every day.&amp;#160; Now that I have had the time to adjust to this change, I have realized that even with CastleCops gone - the fight still continues.&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; &lt;/p&gt;  &lt;p&gt;I do not know one person who knows everything.&amp;#160; Some professionals may have more expertise in one area, but weaknesses in other areas.&amp;#160; My point is that we need to work together as a community and share that expertise because that is exactly what the cyber-criminals are doing.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/387318336536837178-7623319668817294054?l=faithyoung.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://faithyoung.blogspot.com/feeds/7623319668817294054/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://faithyoung.blogspot.com/2009/04/beacon-of-light.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/7623319668817294054'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/387318336536837178/posts/default/7623319668817294054'/><link rel='alternate' type='text/html' href='http://faithyoung.blogspot.com/2009/04/beacon-of-light.html' title='A Beacon of Light'/><author><name>Faith Young</name><uri>http://www.blogger.com/profile/04686761912731944625</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry></feed>
