<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Andy Cunningham &#187; Security</title>
	<atom:link href="http://www.cunningham.me.uk/wordpress/category/technology/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cunningham.me.uk/wordpress</link>
	<description>Musing, Ranting, and What&#039;s happening to me</description>
	<lastBuildDate>Mon, 26 Jul 2010 18:08:02 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Airport Security, ID cards, and failure all round.</title>
		<link>http://www.cunningham.me.uk/wordpress/2009/08/07/airport-security-id-cards-and-failure-all-round/</link>
		<comments>http://www.cunningham.me.uk/wordpress/2009/08/07/airport-security-id-cards-and-failure-all-round/#comments</comments>
		<pubDate>Fri, 07 Aug 2009 14:07:52 +0000</pubDate>
		<dc:creator>AndyC</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.cunningham.me.uk/wordpress/?p=707</guid>
		<description><![CDATA[Overheard at a US airport: &#8220;Excuse me, sir,&#8221; said the TSA officer, pointing to the young female, &#8220;She does not need to have her ID out, she&#8217;s a minor.&#8221; Dad: &#8220;How do you know she&#8217;s a minor if you don&#8217;t look at her ID?&#8221; Meanwhile, Adam Laurie (of hotel safe cracking fame) has proven the [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://scienceblogs.com/gregladen/2009/07/overheard_at_airport.php">Overheard at a US airport</a>:</p>
<p style="margin-top: 5px; margin-right: 0px; margin-bottom: 5px; margin-left: 0px; padding-top: 2px; padding-right: 0px; padding-bottom: 2px; padding-left: 0px; outline-width: 0px; outline-style: initial; outline-color: initial; font-size: 12pt; vertical-align: baseline; background-image: initial; background-repeat: initial; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: transparent; font-family: Georgia, 'Times New Roman', Times, serif; line-height: 1.5; background-position: initial initial; border: 0px initial initial;">&#8220;Excuse me, sir,&#8221; said the TSA officer, pointing to the young female, &#8220;She does not need to have her ID out, she&#8217;s a minor.&#8221;</p>
<p style="margin-top: 5px; margin-right: 0px; margin-bottom: 5px; margin-left: 0px; padding-top: 2px; padding-right: 0px; padding-bottom: 2px; padding-left: 0px; outline-width: 0px; outline-style: initial; outline-color: initial; font-size: 12pt; vertical-align: baseline; background-image: initial; background-repeat: initial; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: transparent; font-family: Georgia, 'Times New Roman', Times, serif; line-height: 1.5; background-position: initial initial; border: 0px initial initial;">Dad: &#8220;How do you know she&#8217;s a minor if you don&#8217;t look at her ID?&#8221;</p>
<p style="margin-top: 5px; margin-right: 0px; margin-bottom: 5px; margin-left: 0px; padding-top: 2px; padding-right: 0px; padding-bottom: 2px; padding-left: 0px; outline-width: 0px; outline-style: initial; outline-color: initial; font-size: 12pt; vertical-align: baseline; background-image: initial; background-repeat: initial; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: transparent; font-family: Georgia, 'Times New Roman', Times, serif; line-height: 1.5; background-position: initial initial; border: 0px initial initial;">Meanwhile, Adam Laurie (of <a href="http://www.youtube.com/watch?v=cPcmZ7zIqfo" target="_blank">hotel safe cracking</a> fame) has proven the new <a href="http://www.dailymail.co.uk/news/article-1204641/New-ID-cards-supposed-unforgeable--took-expert-12-minutes-clone-programme-false-data.html" target="_blank">UK ID cards to be a waste of time and tax payers money</a>&#8230;</p>
<p style="margin-top: 5px; margin-right: 0px; margin-bottom: 5px; margin-left: 0px; padding-top: 2px; padding-right: 0px; padding-bottom: 2px; padding-left: 0px; outline-width: 0px; outline-style: initial; outline-color: initial; font-size: 12pt; vertical-align: baseline; background-image: initial; background-repeat: initial; background-attachment: initial; -webkit-background-clip: initial; -webkit-background-origin: initial; background-color: transparent; font-family: Georgia, 'Times New Roman', Times, serif; line-height: 1.5; background-position: initial initial; border: 0px initial initial;">I love working in security.  Being good is so easy when there&#8217;s this much crap around.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cunningham.me.uk/wordpress/2009/08/07/airport-security-id-cards-and-failure-all-round/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jeremy Clarkson doing his bit for security awareness</title>
		<link>http://www.cunningham.me.uk/wordpress/2008/01/07/jeremy-clarkson-doing-his-bit-for-security-awareness/</link>
		<comments>http://www.cunningham.me.uk/wordpress/2008/01/07/jeremy-clarkson-doing-his-bit-for-security-awareness/#comments</comments>
		<pubDate>Mon, 07 Jan 2008 21:06:49 +0000</pubDate>
		<dc:creator>AndyC</dc:creator>
				<category><![CDATA[Musing]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.cunningham.me.uk/wordpress/2008/01/07/jeremy-clarkson-doing-his-bit-for-security-awareness/</guid>
		<description><![CDATA[Computer Security, my professional field, has hit the headlines over the last few weeks.  The loss of 25 million bank records by the British government is remarkable for the scale of the loss, and the ease with which it happened.  But I think the importance of is has been driven (no pun intended) home by [...]]]></description>
			<content:encoded><![CDATA[<p>Computer Security, my professional field, has hit the headlines over the last few weeks.  The loss of 25 million bank records by the British government is remarkable for the scale of the loss, and the ease with which it happened.  But I think the importance of is has been driven (no pun intended) home by Top Gear presenter Jeremy Clarkson.</p>
<p>Clarkson, in his usual tactful style, commented that he couldn&#8217;t see what the fuss was about, and published his own bank account details in the newspaper.  Details <a href="http://www.f-secure.com/weblog/archives/00001354.html">here</a>.</p>
<p>Predictably someone used them to create a direct debit from his account &#8211; to a charity, rather than themselves.</p>
<p>An interesting point here is that the bank clearly acted upon instructions other than those of the account holder, which me wonder how carefully banks check things like Direct Debit mandates.  Not very, I suspect.  Will they cough up the money that was stolen as a result of them acting on false instructions, or will they blame Clarkson for being a loudmouth?</p>
<p>The good thing to come out of this, hopefully, is people realising how serious this is!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cunningham.me.uk/wordpress/2008/01/07/jeremy-clarkson-doing-his-bit-for-security-awareness/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How not to approach a potential customer.</title>
		<link>http://www.cunningham.me.uk/wordpress/2007/09/26/how-not-to-approach-a-potential-customer/</link>
		<comments>http://www.cunningham.me.uk/wordpress/2007/09/26/how-not-to-approach-a-potential-customer/#comments</comments>
		<pubDate>Wed, 26 Sep 2007 12:44:50 +0000</pubDate>
		<dc:creator>AndyC</dc:creator>
				<category><![CDATA[Personal]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.cunningham.me.uk/wordpress/2007/09/26/how-not-to-approach-a-potential-customer/</guid>
		<description><![CDATA[I just received an email, the subject line of which started with &#8220;DO NOT DELEAT&#8221;.  It went on to make a bunch of wild security claims about a product (there&#8217;s no 100% security, ever), and mis-spelled the name of my employer (it&#8217;s only three letters, surely getting them in the right order isn&#8217;t that hard). [...]]]></description>
			<content:encoded><![CDATA[<p>I just received an email, the subject line of which started with &#8220;DO NOT DELEAT&#8221;.  It went on to make a bunch of wild security claims about a product (there&#8217;s no 100% security, ever), and mis-spelled the name of my employer (it&#8217;s only three letters, surely getting them in the right order isn&#8217;t that hard).</p>
<p>I  deleated it.  Right after I added them to my &#8220;try not to buy from this company&#8221; list.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cunningham.me.uk/wordpress/2007/09/26/how-not-to-approach-a-potential-customer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hotel Safe cracked with a paperclip</title>
		<link>http://www.cunningham.me.uk/wordpress/2007/04/11/hotel-safe-cracked-with-a-paperclip/</link>
		<comments>http://www.cunningham.me.uk/wordpress/2007/04/11/hotel-safe-cracked-with-a-paperclip/#comments</comments>
		<pubDate>Wed, 11 Apr 2007 12:54:21 +0000</pubDate>
		<dc:creator>AndyC</dc:creator>
				<category><![CDATA[Links]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.cunningham.me.uk/wordpress/?p=253</guid>
		<description><![CDATA[This YouTube Video is scary.60 seconds to get into a hotel safe.]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.youtube.com/watch?v=cPcmZ7zIqfo">This YouTube Video</a> is scary.60 seconds to get into a hotel safe.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cunningham.me.uk/wordpress/2007/04/11/hotel-safe-cracked-with-a-paperclip/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ID Theft</title>
		<link>http://www.cunningham.me.uk/wordpress/2007/02/04/id-theft/</link>
		<comments>http://www.cunningham.me.uk/wordpress/2007/02/04/id-theft/#comments</comments>
		<pubDate>Sun, 04 Feb 2007 17:20:02 +0000</pubDate>
		<dc:creator>AndyC</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://www.cunningham.me.uk/wordpress/?p=163</guid>
		<description><![CDATA[Wednesday night&#8217;s BBC TV featured a documentary on the subject of ID theft, and is scary even to someone who works in the security business. Most ID theft is worryingly low-tech. Scan someone&#8217;s rubbish for a couple of utility bills and a bank statement and you&#8217;ve got enough proof of your ID to get a [...]]]></description>
			<content:encoded><![CDATA[<p>Wednesday night&#8217;s BBC TV featured a <a href="http://news.bbc.co.uk/1/hi/business/1395109.stm">documentary </a>on the subject of ID theft, and is scary even to someone who works in the security business.</p>
<p>Most ID theft is worryingly low-tech.  Scan someone&#8217;s rubbish for a couple of utility bills and a bank statement and you&#8217;ve got enough proof of your ID to get a loan on a £12,000 car.    Credit Card mag stripe writing is a minimal investment.  And, at the higher end, scanning wireless networks and installing malware on PCs is a great way to catch all the information you want.</p>
<p>Be careful out there, folks.   Specifically,</p>
<ul>
<li>Don&#8217;t let bars keep your credit card behind the bar if you&#8217;re running a tab.  How can you trust them to not spit in your dinner if they won&#8217;t trust you to pay the bill without running for it?</li>
<li><a href="http://www.amazon.co.uk/gp/product/B000J5VV6I?ie=UTF8&amp;tag=andycunninghs-21&amp;linkCode=as2&amp;camp=1634&amp;creative=6738&amp;creativeASIN=B000J5VV6I"> Shred</a><img src="http://www.assoc-amazon.co.uk/e/ir?t=andycunninghs-21&amp;l=as2&amp;o=2&amp;a=B000J5VV6I" style="border: medium none  ! important; margin: 0px ! important" border="0" height="1" width="1" />anything with any financial information on it.  A single credit card receipt can have the card number and your signature.  That&#8217;s all a criminal with an accomplice needs.</li>
<li>Complain at stores that double-swipe cards.  Petrol stations are a favourite culprit for this &#8211; or used to be.  If they&#8217;ve done the chip and pin bit, that&#8217;s all they need.  I&#8217;m going to start telling stores that swipe my card twice that I&#8217;m calling the police.</li>
<li>Watch out for ATM machines.  I&#8217;m going to start being more careful about using non-local machines and try to use the one down the road as much as possible.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.cunningham.me.uk/wordpress/2007/02/04/id-theft/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Planes, planes, and more planes.</title>
		<link>http://www.cunningham.me.uk/wordpress/2006/09/27/planes-planes-and-more-planes/</link>
		<comments>http://www.cunningham.me.uk/wordpress/2006/09/27/planes-planes-and-more-planes/#comments</comments>
		<pubDate>Wed, 27 Sep 2006 09:53:19 +0000</pubDate>
		<dc:creator>AndyC</dc:creator>
				<category><![CDATA[Musing]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.cunningham.me.uk/wordpress/?p=125</guid>
		<description><![CDATA[It&#8217;s a sad state of affairs when airline staff think it&#8217;s OK to lie to passengers to enforce a security rule that barely makes sense in the first place. Meanwhile, this announcement &#8220;This is the captain speaking&#8221;, definitely comes under the heading of stories where no-one will ever find out the truth. Was he just [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s a sad state of affairs when airline staff think it&#8217;s OK <a href="http://www.freakonomics.com/blog/2006/09/21/an-airplane-announcement-ive-been-waiting-for/">to lie to passengers</a> to enforce a security rule that barely makes sense in the first place.</p>
<p>Meanwhile, this announcement <a target="_blank" href="http://www.thisisbristol.co.uk/displayNode.jsp?nodeId=145365&#038;command=displayContent&#038;sourceNode=145191&#038;contentPK=15434133&#038;folderPk=83726&#038;pNodeId=144922">&#8220;This is the captain speaking&#8221;</a>, definitely comes under the heading of stories where no-one will ever find out the truth.  Was he just bored with working his notice, or was there really a problem?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cunningham.me.uk/wordpress/2006/09/27/planes-planes-and-more-planes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Laptops, Security and Cars&#8230;</title>
		<link>http://www.cunningham.me.uk/wordpress/2006/05/10/laptops-security-and-cars/</link>
		<comments>http://www.cunningham.me.uk/wordpress/2006/05/10/laptops-security-and-cars/#comments</comments>
		<pubDate>Wed, 10 May 2006 09:00:24 +0000</pubDate>
		<dc:creator>AndyC</dc:creator>
				<category><![CDATA[Driving]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.cunningham.me.uk/wordpress/?p=22</guid>
		<description><![CDATA[LeftLaneNews has an interesting article on using laptops to defeat security on modern vehicles.]]></description>
			<content:encoded><![CDATA[<p>LeftLaneNews has an <a title="http://www.leftlanenews.com/2006/05/03/gone-in-20-minutes-using-laptops-to-steal-cars/trackback/" target="_blank" href="http://www.leftlanenews.com/2006/05/03/gone-in-20-minutes-using-laptops-to-steal-cars/trackback/">interesting article</a> on using laptops to defeat security on modern vehicles.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cunningham.me.uk/wordpress/2006/05/10/laptops-security-and-cars/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
