<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Security forum - dslreports.com community</title>
<link>http://www.dslreports.com/forum/security</link>
<description>Security forum current topics</description>
<language>en</language>
<copyright>Copyright 2007, dslreports.com</copyright>
<pubDate>Mon, 06 Feb 2012 23:58:35 EDT</pubDate>
<lastBuildDate>Mon, 06 Feb 2012 23:58:35 EDT</lastBuildDate>

<image>
<title>dslreports.com</title>
<url>http://i.dslr.net/bbrdisc1.gif</url>
<link>http://www.dslreports.com</link>
<width>19</width>
<height>18</height>
<description>bbr disc</description>
</image>

<item>
<title>Anatomy of a Bribe |The Symantec pcAnywhere Ransom Saga</title>
<link>http://www.dslreports.com/forum/remark,26862442</link>
<description><![CDATA[What we 'ave 'ear is not a failua to communicate.

This is the content of a purported partial email exchange between whoever grabbed the pcAnywhere code and some hoo-ha from Symantec.

 quote:=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
        Sam Thomas 
       yamatough 
    07 February 2012, 02:46:43
         10 minutes
            html
--====----====----====----====----====----====----====----====----====----===--
We can't make a decision in ten minutes.  We need more time.  
 
2012/2/6 yamatough 
 
 Since no code yet being released
 and our email communication wasnt also released
 we give you 10 minutes to decide which way you go
 after that two of your codes fly to the moon PCAnywhere and Norton
 Antivirus totaling 2350MB in size (rar)
 10 minutes if no reply from you we consider it a START
 this time we've made mirrors so it will be hard for you to get rid of
 it
 
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
        Sam Thomas 
       yamatough 
    07 February 2012, 00:13:42
         ?
            html
--====----====----====----====----====----====----====----====----====----===--
We've looked into Liberty reserve and offshore accounts.  These options wont work.  We want to protect our code but we need other options.  
 
2012/2/6 yamatough 
 
your silence considered as No
 r we clear?
  
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
        Sam Thomas 
       yamatough 
    02 February 2012, 04:27:14
         say hi to FBI
            html
--====----====----====----====----====----====----====----====----====----===--
We are not in contact with the FBI.  We are using this email account to protect our network from you.  
 
 
Protecting our company and property are our top priorities.   
 
 
We can't pay you $50,000 at once for the reasons we discussed previously.  We can pay you $2,500 per month for the first three months.  In exchange, you will make a public statement on behalf of your group that you lied about the hack (as you previously stated).   Once that's done, we will pay the rest of the $50,000 to your account and you can take it all out at once.  That should solve your problem.
 
 
Obviously you still have our code so if we don't follow through you still have the upper hand. 
 
2012/2/1 yamatough 
 
Say hi to FBI agents,
 It's funny you do not use your corp account anymore =)
 We wonder why is that be that way? =)
  
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
        Sam Thomas 
       yamatough 
    02 February 2012, 00:28:33
         sorry
            html
--====----====----====----====----====----====----====----====----====----===--
So now what does this mean? 
 
2012/2/1 yamatough 
 
  I am afraid we have to cancel the whole deal because our offshore people
   wont let us securely get the money because they wont process amounts less
    than 50k a shot. Therefore we are afraid we can not proceed with you on the
     conditions offered.
  
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
        Sam Thomas 
       yamatough 
    01 February 2012, 02:59:06
         please read carefully
            html
--====----====----====----====----====----====----====----====----====----===--
Got your message.
 
 
We are still looking into Liberty Reserve but we have to figure out how to get our money safely into our Liberty Reserve account through an exchanger.  
 
 
We will pay you $50,000.00 USD total.  
 
 
However, we need assurances that you are not going to release the code after payment.  We will pay you $2,500 a month for the first three months.  Payments start next week.  After the first three months you have to convince us you have destroyed the code before we pay the balance.  We are trusting you to keep your end of the bargain.  
 
 
You know how the corporate environment works and we have to treat this like a business transaction.  
 
On Tue, Jan 31, 2012 at 12:26 PM, yamatough wrote:
 
   
 No offence, nobody's trying to give you a hard time.
 We have a clear understanding on how things work inside corp environment.
 Do not send us any money (we do not use paypal period) do not send us any 1k etc.
 We can wait till we agree on final amount.
 
 Please confirm that you received this message so we are not anxious.
  
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
        Sam Thomas 
       yamatough 
    31 January 2012, 23:54:54
         ???
            html
--====----====----====----====----====----====----====----====----====----===--
We already told you we are doing the best we can.  You threatening to release the code is not helping the situation. 
 
 
We've been looking into Liberty Reserve.  Looks like we have to use an exchanger to get money into our Liberty Reserve account.
This is more complicated than we expected.   
 
 
Our plan was to get you $1,000 by the end of the week as a test and a sign of good faith but we don't know if we can make this work
that quickly through Liberty Reserve. 
 
 
We've used paypal numerous times and we know how it works.  We can definitely send you $1,000 by the end of the week through 
paypal until we can get Liberty Reserve setup for a large payment.  We will send the paypal payment to the yamatough@terra.com.ve
email address on Friday.     
 
On Mon, Jan 30, 2012 at 5:50 PM, yamatough wrote:
 
   
 there are no options but :
 Liberty Reserve (tell your people to look into their website www.libertyreserve.com and check how it works - its easy   we shall give you our account number within the LR system and you send money from your LR acct to ours) To put money on ya LR account you can do by wire transfer within the USA etc. just check the website
  this option is nice for you because it leaves the FATF and Anti Terror units behind and raises no suspicions like the Lithuanian transfer would.
 Wire transfer to a bank account in Lithuania or Latvia is also an option.
 
 Above mentioned are the only ways to work it out.
 
 We are afraid if you can not comply we proceed with the release.
 
 What are the guarantees that we wont come back for more?   - NONE ofcourse, you have to trust us on this one, if we were really bad guys we would have already released or sold your code at the time of exchanging emails with you which is almost a month - AND WE KEPT SILENT all that time and stuck to our word given to you.
  So - No Guarantees - Trust Us - We wont come back and wont manipulate the code.
 At least it is worth a try and we assure you we are man of honor we keep our promise.
    What you are going to get if no agreement reached? - We both know.
            Partial release of code - Official Auction Bidding on some of it - 0day exploitation
            That happens as soon as we understand your negative call.
 
 As of files sent to you partially - we are getting tired of all this please do not make us more angry than we already are you know we got the full line so please nothing is going to be send to you once again.
      Time's up - We are patient to get Positive or Negative from you. You have two options to complete Wire. And name the price. Period.
 
 
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
        Sam Thomas 
       yamatough 
    31 January 2012, 05:22:24
         ???
            html
--====----====----====----====----====----====----====----====----====----===--
We are really trying to work with you but we can't meet all the deadlines that you keep throwing at us.  We need approvals by a lot of people who all have different opinions.  This is the first time we've heard of Liberty Reserve and we are hesitant to just wire money straight to an offshore account.  
 
 
You didn't provide all the files requested last time.  What assurances can you provide that once we pay, you will actually destroy the code and not ask for more money?  
 
 
Finance is asking us what offshore account it is and also how we could make a payment through liberty reserve.  Send us that info to give to them.  If they shoot these options down, do you have any other ways to accept your payment?
 
 
We are willing to do what it takes to get our code back and protect our customers but we've never been in this position before.  Please be patient and we will find something that works for both of us.  
 
2012/1/30 yamatough 
 
 you have 24 hours for a definite answer
 
 
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
        Sam Thomas 
       yamatough 
    30 January 2012, 21:12:24
         monday
            html
--====----====----====----====----====----====----====----====----====----===--
Before we can discuss a dollar amount, we need to figure out how the payment is going to be made.  
 
2012/1/25 yamatough 
 
We expect answer by monday.
 
 
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
        Sam Thomas 
       yamatough 
    26 January 2012, 01:13:10
         procedure
            html
--====----====----====----====----====----====----====----====----====----===--
Bottom line, we need more time, at least 2-3 days.  This is not a simple process on our end.  
 
2012/1/25 yamatough 
 
We have a rule - and we always follow it:
     If you are the owner - you have the right to be the first one
     asked. That is why we kept silent at the time of negotiating with
     you.
     We stick to the word given and nothing is going to happen to the code
     if we complete the deal.
     Were we not that way we would have already sold your code to that
     willing many.
 
     SO  - you told us a week ago that you've being requesting a
     response from Fin dprtmnt. We got no answer for the below question
     so far:
             ?How much do you consider ENOUGH to pay us in order to
             work all the issues out?
 
 
             Name the price,
 
             Clock's tikin
 
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
        Sam Thomas 
       yamatough 
    25 January 2012, 23:49:38
         ON SALE
            html
--====----====----====----====----====----====----====----====----====----===--
We are not trying to trick you.  You said you had the PC Anywhere code and we were just being cautious.  What would you have us do? 
 
We really don't want our code out there.  How do you want to proceed. 
 
 
2012/1/25 yamatough 
 
If we dont hear from you in 30m
we make an official announcement and put your code on sale at auction
terms. We have many people who are willing to get your code
 Dont f*** with us
 
 
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
        Sam Thomas 
       yamatough 
    25 January 2012, 05:38:08
         problem
            html
--====----====----====----====----====----====----====----====----====----===--
we are having network issues with ftp on the standalone computer. we think we can have it ready tomorrow and will send you login details. 
 
On Tue, Jan 24, 2012 at 9:05 AM, yamatough wrote:
 
   
 roger that
 
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
        Sam Thomas 
       yamatough 
    24 January 2012, 05:39:49
         problem
            html
--====----====----====----====----====----====----====----====----====----===--
we are trying to setup a stand alone computer so this doesn't affect our network.  we only want to ensure our environment is safe.  we will send you the ftp details tomorrow.
 
2012/1/23 yamatough 
 
If you are trying to trace with the ftp trick it's just worthless.
 If we detect any malevolent tracing action we cancel the deal.
 Is that clear?
 You've got the doc files and pathes to the files
 what's the problem ?
 Explain
 
 
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
        Sam Thomas 
       yamatough 
    24 January 2012, 01:15:05
         it's monday
            html
--====----====----====----====----====----====----====----====----====----===--
in the process of setting up a secure ftp site. should be ready today or tomorrow.
 
2012/1/23 yamatough 
 
 It's monday...
 
 
 
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
        Sam Thomas 
       yamatough 
    21 January 2012, 03:54:28
         updates samplez
            html
--====----====----====----====----====----====----====----====----====----===--
the gmail account and the internal account are deleting the attachments.  working on another way to get these from you. hopefully will have a solution over the weekend or on monday.
 
On Fri, Jan 20, 2012 at 5:20 AM, yamatough wrote:
 
   
  /depot/pcAnywhere/pcA-NG/Thin/site/deploy/remstart.exe
       /depot/pcAnywhere/pca32/trunk/Design/12.5/Design - Smart Card Authentication.doc
 
      /depot/pcAnywhere/pca32/trunk/Design/12.0/Design - pcA Connection Server UIs.vsd
     /depot/pcAnywhere/pca32/r12.0.2/Design/12.0/Design - pcA Connection Server UIs.vsd
 
 In case you did not get the first email
 
 
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
        Sam Thomas 
       yamatough 
    20 January 2012, 08:37:52
         updates samplez
            html
--====----====----====----====----====----====----====----====----====----===--
Give us through the weekend to figure out how to get these from you. We don't want these docs posted on a public site.
 
2012/1/19 yamatough 
 
your google acc rejects attachments so we sent it to sym addie
  
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
        Sam Thomas 
       yamatough 
    20 January 2012, 00:32:11
         updates2
        
--====----====----====----====----====----====----====----====----====----===--
We need assurance on PCAnywhere.  Because our email system strips large attachments, send sample files to this address where we can get attachments:  sam.thomas.sym@gmail.com
Send the following sample files:
ft_advanced.rec
Design - Smart Card Authentication.doc
design - pca connection server uis.vsd
remstart.exe
1151up.pcg
We want:
1) Actual file
2) Path where you found file
 
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
        Sam Thomas 
       yamatough 
    19 January 2012, 22:04:59
         updates
        
--====----====----====----====----====----====----====----====----====----===--
 
Management needs assurances.  Your last email before today said &#147;PCAN and NU got pub&#148;  - where did PCAN get pub?
 
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
        Sam Thomas 
       "yamatough@terra.com.ve" 
    18 January 2012, 03:11:37
         up to you
            html
--====----====----====----====----====----====----====----====----====----===--
Have  to check with Finance people.  We will contact you tomorrow.
.

.

I'm struck by the 419 feel of this.
--
Adopting other people's animosity is The New Stupid.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,26862442</guid>
<pubDate>2012-02-06 23:06:24</pubDate>
</item>

<item>
<title>Winpatrol has no registry protection with limited account?</title>
<link>http://www.dslreports.com/forum/remark,26694947</link>
<description><![CDATA[Installed on my windows 7 64 bit machine latest version. Upon install under my admin. account. It has registry protection entries. I go in my limited account and it is blank. Is this by design or fault of the program? Btw. A new version has not been released in months. Thought I remember reading a new version coming in December. 64 bit as well.....?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,26694947</guid>
<pubDate>2011-12-25 01:18:37</pubDate>
</item>

<item>
<title>Do You Like Online Privacy? You May Be a Terrorist</title>
<link>http://www.dslreports.com/forum/remark,26846063</link>
<description><![CDATA[http://yro.slashdot.org/story/12/02/02/1719221/do-you-like-online-privacy-you-may-be-a-terrorist]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,26846063</guid>
<pubDate>2012-02-02 16:29:06</pubDate>
</item>

<item>
<title>Anonymous to the rescue?</title>
<link>http://www.dslreports.com/forum/remark,26862148</link>
<description><![CDATA[Wish I could get the hacker Anonymous Group to go after companies that trick uniformed personal computer users into thinking they have a threat on their computer and run a scan to remove it. The scan installs a very sophisticated malware program that hijacks their browser and renders their computer useless. It's impossible to remove unless you pay them for their software removal program.  Otherwise only solution is to wipe your hard drive and reinstall OS which can be a problem for average computer user especially if they do not have install disk. Creates a nightmare for these folks. I am retired computer tech and help people with their computers for free and I continually encounter this problem.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,26862148</guid>
<pubDate>2012-02-06 21:58:08</pubDate>
</item>

<item>
<title>CC companies threaten Discovery over Mythbusters Show</title>
<link>http://www.dslreports.com/forum/remark,26855284</link>
<description><![CDATA[I ran across an interesting article on Gizmodo tonight about several credit card companies (VISA, American Express and Discover) threatening to pull advertising from the Discovery Channel if they aired a Mythbusters special about RFID technology and how susceptible it may be to hacking and tracking.

The Mythbusters crew called Texas Instruments for an initial interview about the technology, and who pops up but Chief Council from each of these companies. It begs the question, how insecure is this technology really? What's being hidden or undisclosed to the consumer (if anything) and why?

RFID chips are super cool because those little buggers can beam things wirelessly. The guys at Mythbusters totally thought so too and wanted to make an episode about how trackable and hackable RFID chips were. Sounds amazing! Everyone would've learned more about the technology that's invisibly invading our lines. But, nope. Credit Card companies banned 'em.

Specifically, it looks like the lawyers of Visa, American Express, Discover and all the other bigwig debt slurpin' credit card companies got in immediate contact with Discovery (the network that airs Mythbusters) and told 'em if Savage and crew did the episode, the credit card companies would pull its advertisements and commercials from Discovery. Discovery caved and the RFID episode was axes. Bummer.Link: http://gizmodo.com/5882102/mythbusters-was-banned-from-talking-about-rfid-chips-because-credit-card-companies-are-little-weenies

http://www.youtube.com/watch?v=hq7kBhts9a8&feature=mfu_in_order&list=UL]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,26855284</guid>
<pubDate>2012-02-04 22:58:32</pubDate>
</item>

<item>
<title>States sell email addresses for campaigns to reach voters</title>
<link>http://www.dslreports.com/forum/remark,26858835</link>
<description><![CDATA[Fox

 quote:They will often merge voter data with other data to create profiles to help them more precisely target their message to particular voters."

Personal information about registered voters can be invaluable information to campaigns, but selling it is not a big moneymaker for states.

A few states make it available for free, considering it a matter of public record. Some sell a statewide list of every voters' name, address and date of birth for as little as $25. Others offer regularly updated subscriptions for $5,000 per year. The most expensive statewide list Fox News found is in Wisconsin, at $12,500, which includes emails.

Emphasis mine. gag]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,26858835</guid>
<pubDate>2012-02-06 08:44:52</pubDate>
</item>

<item>
<title>BTJunkie Offlines itself - permanently</title>
<link>http://www.dslreports.com/forum/remark,26858180</link>
<description><![CDATA[For reasons not specified on this page, BTJunkie has brought about it's own demise.

[att=1]
--
Adopting other people's animosity is The New Stupid.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,26858180</guid>
<pubDate>2012-02-05 22:35:57</pubDate>
</item>

<item>
<title>Automated License Plate Recognition in Canada</title>
<link>http://www.dslreports.com/forum/remark,26860010</link>
<description><![CDATA[This has been discussed before, but the article is a good read on the subjects privacy implications.

http://www.focusonline.ca/?q=node/312;bcsi-ac-AB21A726D5A3213D=1C9AB58400000105lMSLJE6O50Rg3E/6lKZlQ2FS/BDIAQAABQEAAIoHrgGAcAAAAAAAAMZTAgA=
--
--Standard disclaimers apply.--
google this "(sqrt(cos(x))*cos(200*x)+sqrt(abs(x))-0.7)*(4-x*x)^0.01, sqrt(9-x^2), -sqrt(9-x^2)"]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,26860010</guid>
<pubDate>2012-02-06 13:57:47</pubDate>
</item>

<item>
<title>Anonymous &#x27;intercept FBI and  Scotland Yard phone call&#x27;</title>
<link>http://www.dslreports.com/forum/remark,26849632</link>
<description><![CDATA[from
http:\\www.bbc.co.uk/news/world-us-canada-16875921
"..The call, said to have taken place last month, covers the tracking of Anonymous and similar groups"

Such fun ;)

Cudni
--
"what we know we know the same, what we don't know, we don't know it differently." Help yourself so God can help you.Microsoft MVP,  2006 - 2011/12]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,26849632</guid>
<pubDate>2012-02-03 12:24:25</pubDate>
</item>

<item>
<title>Google to Mandate User Tracking - No Opt Out</title>
<link>http://www.dslreports.com/forum/remark,26808697</link>
<description><![CDATA[I'm still getting my head around this.  Please read on while I do.

WashPost has a regwall.  Here's the entire article.

said by WashPost :Google said Tuesday it will require users to allow the company to follow their activities across e-mail, search, YouTube and other services, a radical shift in strategy that is expected to invite greater scrutiny of its privacy and competitive practices.

The information will enable Google to develop a fuller picture of how people use its growing empire of Web sites. Consumers will have no choice but to accept the changes.

The policy will take effect March 1 and will also impact Android mobile phone users, who are required to log in to Google accounts when they activate their phones.

FAQ: What kind of data can Google collect and integrate? How will this affect me?

The changes comes as Google is facing stiff competition and recently disappointed investors for the first time in several quarters, failing last week to meet earnings expectations. Apple, perhaps its primary rival, is expected to announce strong earnings Tuesday.

Google&#146;s changes are appeared squarely aimed at Apple and Facebook, which have been successful in keeping people in their ecosystem of products. Google, which makes money by selling ads tailored to its users, is hoping to do the same by offering a Web experience tailored to personal tastes.

&#147;If you&#146;re signed in, we may combine information you&#146;ve provided from one service with information from other services,&#148; Alma Whitten, Google&#146;s director of privacy, product and engineering wrote in a blog post.

&#147;In short, we&#146;ll treat you as a single user across all our products which will mean a simpler, more intuitive Google experience,&#148; she said.

After March 1, a user who has recently watched YouTube videos of the Washington Wizards might suddenly see basketball ticket ads appear in his or her Gmail accounts.

That person may also be reminded of a business trip to Washington on Google Calendar and asked whether he or she wants to notify friends who live in the area, information Google would cull from online contacts or its social network Google+.

Privacy advocates say Google&#146;s changes betray users who are not accustomed to having their information shared across different Web sites.

A user of Gmail, for instance, may send messages about a private meeting with a colleague and may not want the location of that meeting to be thrown into Google&#146;s massive cauldron of data or used for Google&#146;s maps application.

Google recently settled a privacy complaint by the Federal Trade Commission after it allowed users of its now defunct social network Google Buzz to see contacts lists from its e-mail program.

Privacy advocates in recent weeks filed a separate complaint that Google deceived consumers by using information from its new social network Google+ in general search results.

Some worry about security. Gmail users, including some White House staff, last year were targeted by hackers who were able to breach the company&#146;s e-mail accounts.

Google on Tuesday described its new business plan as changes in its privacy policy and terms of service for all its services except for Google Wallet, its Chrome browser and Google Books.

Google has also faced greater scrutiny that it is using its dominance in online search to favor its other applications. Google&#146;s decision to blend Google+ data into search results has been included into a broad FTC antitrust investigation, according to a person familiar with the matter who spoke on the condition of anonymity because the investigation is private.

Engineers from Twitter, Facebook and MySpace responded by launching a Web tool that they say shows Google is moving away from its stated mission to be a neutral Web directory.

On the Web site for the plug-in, the engineers wrote that searches for generic terms such as &#147;movies&#148; or &#147;music&#148; prioritize Google+ results over more relevant content.--
Adopting other people's animosity is The New Stupid.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,26808697</guid>
<pubDate>2012-01-24 17:31:45</pubDate>
</item>

<item>
<title>Is Avast acting a little weird?</title>
<link>http://www.dslreports.com/forum/remark,26855996</link>
<description><![CDATA[I just downloaded ccleaner from filehippo and it was calling the file a virus.. it installed ok and seems to be running fine.. ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,26855996</guid>
<pubDate>2012-02-05 09:46:21</pubDate>
</item>

<item>
<title>Unknowingly used old version of Firefox. Should I worry?</title>
<link>http://www.dslreports.com/forum/remark,26855496</link>
<description><![CDATA[A few days ago I found out I had been using an old version of Firefox (version 5.0.) since July of 2011.  I manually updated to 9.0.1 and then today to version 10.

I never unchecked automatic updates and automatic installation of updates for Firefox, so I assumed everything would take care of itself.  My Firefox addons HAVE been updating automatically, and that option wasn't unchecked either.  So for all this time I didn't have the latest version, and I'm scared because I think that could mean I was surfing around without the latest security updates to Firefox.

Should I be worried?  What should I do?  I am currently using the latest version of Firefox for Mac OS X.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,26855496</guid>
<pubDate>2012-02-05 00:26:23</pubDate>
</item>

<item>
<title>PC Magazine AV Tests (blocking and removal) (31/1/2012)</title>
<link>http://www.dslreports.com/forum/remark,26855611</link>
<description><![CDATA[PC Magazine AV Tests (blocking and removal) (31/1/2012)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,26855611</guid>
<pubDate>2012-02-05 01:47:06</pubDate>
</item>

<item>
<title>Used Motorola Xooms resold with personal info on them</title>
<link>http://www.dslreports.com/forum/remark,26855598</link>
<description><![CDATA[http://informationweek.com/news/security/mobile/232600260
 quote:Motorola alerted customers on Friday that it shipped about 100 refurbished Xoom tablets that were not completely cleared of the original owner's data prior to resale. The tablets were sold between October and December of 2011 through Woot.com. Oops.

According to Motorola, some of the compromised data potentially includes user names and passwords for email and social media accounts, as well as other password-protected sites and applications, and possibly even photographs and documents.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,26855598</guid>
<pubDate>2012-02-05 01:34:51</pubDate>
</item>

<item>
<title>Canada RCMP program to log and track all drivers is underway</title>
<link>http://www.dslreports.com/forum/remark,26855463</link>
<description><![CDATA[This is an example of using License Plate recognition technology; for what it was meant to be used for.  

The RCMP has started a program to record and log the locations of all drivers, that their Plate-Rec equipped police cars come across.

Presently, those records are retained for at least 3 months.
There's an extended list of Canadians whose whereabouts will be tracked for a much longer time.

said by FocusOnline :The categories of people that generate alerts or "hits" in the ALPR system, alongside car thieves and child kidnappers, are much broader than has ever been disclosed publicly. 

And information on these people&#146;s movements is being retained in a database for two or more years. For example, though you may not be stopped, your car is a "hit" and its movements are tracked and recorded if you're on parole or probation or, in some cases, you've simply been accused of breaking a criminal law, federal or provincial statute, or municipal bylaw. 

You're also a hit if you 
 ever attended court to establish legal custody of your child, 
 if you've ever had an incident due to a mental health problem which police attended, or 
 if you've been linked to someone under investigation. 

The list of hit categories continues through three more pages, and a fourth page that the RCMP completely redacted.

Meanwhile, according to the Privacy Impact Assessment, the RCMP is also keeping records for three months on the whereabouts of everybody else's cars, too-this is called "non-hit" data. 

What, our team asked, did keeping massive databases of records on everyone&#146;s movements have to do with catching stolen vehicles or uninsured drivers? Kevin McArthur suggested: "[ALPR] is not intended to be a police cruiser improvement and efficiency tool, but to be a surveillance tool."The article also mentions that there's some discrepancy about whether the program has ever been properly vetted w/ Canada's Privacy Commissioner.

Oh Canada. 
--
Adopting other people's animosity is The New Stupid.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,26855463</guid>
<pubDate>2012-02-05 00:05:30</pubDate>
</item>

<item>
<title>Darn scammers</title>
<link>http://www.dslreports.com/forum/remark,26853158</link>
<description><![CDATA[One would think that just about everything was right here:

1) Procure low limit cc specifically for web
2) Ensure that security both local and site are up to par
3) use valid, strong and maximum length unique passwords.
4) Only trade with well known locations - both for trade and subscriptions and lock down valid initiation sources (e.g. specific computer - where available).

Yet, somehow found out this morning that a foreign trade on my card (max avail) was done; for adobe software from adobe site.

Needless to say, already talked to CC and cx card but again I suspect that this CC number did not so much "leak" from transactions but from card generators...

What is the best way, considering that some transactions must be done on-line, to further minimize the vulnerabilities?
 :mad:]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,26853158</guid>
<pubDate>2012-02-04 10:40:34</pubDate>
</item>

<item>
<title>Microsoft Security Bulletin Minor Revisions - Feb. 1, 2012</title>
<link>http://www.dslreports.com/forum/remark,26843138</link>
<description><![CDATA[Summary
=======
The following bulletins have undergone a minor revision increment. 
Please see the appropriate bulletin for more details.

  * MS11-098 - Important
  * MS11-100 - Critical

Bulletin Information:
=====================

* MS11-098 - Important

  - http://technet.microsoft.com/security/bulletin/MS11-098
  - Reason for Revision: V1.1 (February 1, 2012): Added a link
    to Microsoft Knowledge Base Article 2633171 under Known Issues
    in the Executive Summary.
  - Originally posted: December 13, 2011
  - Updated: February 1, 2012
  - Bulletin Severity Rating: Important
  - Version: 1.1

* MS11-100 - Critical

  - http://technet.microsoft.com/security/bulletin/MS11-100
  - Reason for Revision: V1.3 (February 1, 2012): Corrected
    registry keys and installation switches in the deployment
    tables for Windows Server 2003 and Windows Server 2008,
    and installation switches in the deployment table for
    Windows Vista. This is an informational change only.
    There were no changes to the security update files
    or detection logic.
  - Originally posted: December 29, 2011
  - Updated: February 1, 2012
  - Bulletin Severity Rating: Critical
  - Version: 1.3
--
Microsoft&reg; Security MVP, 2004 - 2012
DP's Security Bits]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,26843138</guid>
<pubDate>2012-02-02 05:05:05</pubDate>
</item>

<item>
<title>How to secure laptop my children use?</title>
<link>http://www.dslreports.com/forum/remark,26854487</link>
<description><![CDATA[So my kids are growing up and are using the laptop more often. It is located in our kitchen so there isn't free reign on the thing. 

But to be honest I would love to be able to setup an OS to get it secured so I won't have to worry to much about what they might accidently search or visit or see. Crap happens sometimes, so I want to make sure I limit that problem.

So can anyone recommend a way to do this? Either by program, OS, or whatever.

Any help and advice would be greatly appreciated.

Thank you very much
--
801 Images]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,26854487</guid>
<pubDate>2012-02-04 17:48:27</pubDate>
</item>

<item>
<title>Daily Mail UK (recipe page) Defaced</title>
<link>http://www.dslreports.com/forum/remark,26855430</link>
<description><![CDATA[http://recipes.dailymail.co.uk/index.htm

[att=1]

and there you are.
--
Adopting other people's animosity is The New Stupid.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,26855430</guid>
<pubDate>2012-02-04 23:51:20</pubDate>
</item>

<item>
<title>Looking for the BEST Security Audit/Penetration Firm</title>
<link>http://www.dslreports.com/forum/remark,26846661</link>
<description><![CDATA[I am looking for recommendations on firms who specialize in security audit and penetration testing. I don't want to deal with companies who run a few off-the shelf tools that generate HTML reports.

BEST is a subjective term, so I'd like recommendations on who this forum considers the top firm who offers these services.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,26846661</guid>
<pubDate>2012-02-02 18:28:18</pubDate>
</item>

</channel>
</rss>

