<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Vincent Arnold</title>
	<atom:link href="http://vincentarnold.com/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://vincentarnold.com/blog</link>
	<description>Information Security, Technology and General Musings</description>
	<pubDate>Wed, 27 Aug 2008 00:29:47 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
	<language>en</language>
			<item>
		<title>Separation of Duties and IT Security</title>
		<link>http://vincentarnold.com/blog/separation-of-duties-and-it-security/</link>
		<comments>http://vincentarnold.com/blog/separation-of-duties-and-it-security/#comments</comments>
		<pubDate>Wed, 27 Aug 2008 00:29:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Information Security]]></category>

		<category><![CDATA[infosec]]></category>

		<guid isPermaLink="false">http://vincentarnold.com/blog/?p=287</guid>
		<description><![CDATA[Muddied responsibilities create unwanted risk. Kevin Coleman says auditors may start labeling poorly defined IT duties as a material deficiency.
By Kevin Coleman, Technolytics Institute
August 26, 2008 — 																											CSO — Separation of duties is a key concept of internal controls and is the most difficult and sometimes the most costly one to achieve. This objective is [...]]]></description>
			<content:encoded><![CDATA[<h2>Muddied responsibilities create unwanted risk. Kevin Coleman says auditors may start labeling poorly defined IT duties as a material deficiency.</h2>
<h2 id="byline">By Kevin Coleman, Technolytics Institute</h2>
<p><span class="date">August 26, 2008</span> — 																											<a href="http://www.csoonline.com/article/446017/www.csoonline.com">CSO</a> — Separation of duties is a key concept of internal controls and is the most difficult and sometimes the most costly one to achieve. This objective is achieved by disseminating the tasks and associated privileges for a specific security process among multiple people.</p>
<p>The term SoD is already well-known in financial accounting systems. Companies in all sizes understand not to combine roles such as receiving checks (payment on account) and approving write-offs, depositing cash and reconciling bank statements, approving time cards and have custody of pay checks, etc. However, SoD is fairly new to the IT organization&#8230;</p>
<p><a href="http://www.csoonline.com/article/446017/Separation_of_Duties_and_IT_Security">Source</a></p>

]]></content:encoded>
			<wfw:commentRss>http://vincentarnold.com/blog/separation-of-duties-and-it-security/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Superstar 9 year old pitcher throws too hard: Opposing team forfeits game, packs gear and bails.</title>
		<link>http://vincentarnold.com/blog/superstar-9-year-old-pitcher-throws-too-hard-opposing-teams-coach-forfeits-game-packs-its-gear-and-leaves/</link>
		<comments>http://vincentarnold.com/blog/superstar-9-year-old-pitcher-throws-too-hard-opposing-teams-coach-forfeits-game-packs-its-gear-and-leaves/#comments</comments>
		<pubDate>Tue, 26 Aug 2008 23:33:03 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Sports]]></category>

		<guid isPermaLink="false">http://vincentarnold.com/blog/?p=286</guid>
		<description><![CDATA[Commentary: Whaaaaaa!!!!! Are you kidding me? We&#8217;re gettin&#8217; our arses kicked so let&#8217;s bail to stop the pwnage and have a good cry while we are at it&#8230;This is absolutely ridiculous. Nice way to teach values New Haven.

NEW HAVEN, Conn. &#8212; Nine-year-old Jericho Scott is a good baseball player &#8212; too good, it turns out.
The [...]]]></description>
			<content:encoded><![CDATA[<p><em><strong>Commentary: Whaaaaaa!!!!! Are you kidding me? We&#8217;re gettin&#8217; our arses kicked so let&#8217;s bail to stop the pwnage and have a good cry while we are at it&#8230;This is absolutely ridiculous. Nice way to teach values New Haven.<br />
</strong></em></p>
<p>NEW HAVEN, Conn. &#8212; Nine-year-old Jericho Scott is a good baseball player &#8212; too good, it turns out.</p>
<p>The right-hander has a fastball that tops out at about 40 mph. He throws so hard that the Youth Baseball League of New Haven told his coach that the boy could not pitch any more. When Jericho took the mound anyway last week, the opposing team forfeited the game, packed its gear and left, his coach said.</p>
<p><a href="http://sports.espn.go.com/espn/news/story?id=3553475">Source</a></p>

]]></content:encoded>
			<wfw:commentRss>http://vincentarnold.com/blog/superstar-9-year-old-pitcher-throws-too-hard-opposing-teams-coach-forfeits-game-packs-its-gear-and-leaves/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Local councils accused of spying on residents&#8217; sex lives</title>
		<link>http://vincentarnold.com/blog/local-councils-accused-of-spying-on-residents-sex-lives/</link>
		<comments>http://vincentarnold.com/blog/local-councils-accused-of-spying-on-residents-sex-lives/#comments</comments>
		<pubDate>Sun, 24 Aug 2008 20:10:48 +0000</pubDate>
		<dc:creator>Vince</dc:creator>
		
		<category><![CDATA[Privacy]]></category>

		<guid isPermaLink="false">http://vincentarnold.com/blog/?p=285</guid>
		<description><![CDATA[Commentary: Never saw this comin&#8217;&#8230;Who&#8217;s watchin&#8217; the watchers?

Council have been accused of using surveillance powers to pry into residents sex lives.
By James Kirkup
Last Updated: 5:35PM BST 24 Aug 2008
The Conservatives say local government officials are monitoring couples&#8217; sleeping arrangements for council tax purposes.
They have released documents they say shows that councils are invading households&#8217; privacy [...]]]></description>
			<content:encoded><![CDATA[<p><em><strong>Commentary: </strong>Never saw this comin&#8217;&#8230;Who&#8217;s watchin&#8217; the watchers?<br />
</em></p>
<h2>Council have been accused of using surveillance powers to pry into residents sex lives.</h2>
<p>By James Kirkup<br />
Last Updated: 5:35PM BST 24 Aug 2008</p>
<p>The Conservatives say local government officials are monitoring couples&#8217; sleeping arrangements for council tax purposes.</p>
<p>They have released documents they say shows that councils are invading households&#8217; privacy to check on claims for council tax discounts.</p>
<p>More than 7.5 million people claim a 25 per cent discount on their council tax bill because they live alone</p>
<p>Councils are responsible for verifying that people who claim to live alone really do so.</p>
<p>A &#8220;surveillance dossier&#8221; used by Rotherham Council and released under freedom of information laws has shown how claims are checked.</p>
<p>The document suggests officials undertake &#8220;surveillance&#8221; of cars registered to addresses &#8220;to substantiate the allegation of living together&#8221;.</p>
<p><a href="http://www.telegraph.co.uk/news/newstopics/politics/lawandorder/2614206/Local-councils-accused-of-spying-on-residents-sex-lives.html">Source</a></p>

]]></content:encoded>
			<wfw:commentRss>http://vincentarnold.com/blog/local-councils-accused-of-spying-on-residents-sex-lives/feed/</wfw:commentRss>
		</item>
		<item>
		<title>White House missing as many as 225 days of e-mail</title>
		<link>http://vincentarnold.com/blog/white-house-missing-as-many-as-225-days-of-e-mail/</link>
		<comments>http://vincentarnold.com/blog/white-house-missing-as-many-as-225-days-of-e-mail/#comments</comments>
		<pubDate>Thu, 21 Aug 2008 01:06:43 +0000</pubDate>
		<dc:creator>Vince</dc:creator>
		
		<category><![CDATA[Government InfoSec]]></category>

		<category><![CDATA[ediscovery]]></category>

		<category><![CDATA[email]]></category>

		<category><![CDATA[whitehouse]]></category>

		<guid isPermaLink="false">http://vincentarnold.com/blog/?p=284</guid>
		<description><![CDATA[
Commentary: I don&#8217;t know&#8230;maybe it&#8217;s me but I think this is a serious problem.



By PETE YOST
The Associated Press
Wednesday, August 20, 2008; 6:27 PM 
WASHINGTON &#8212; The White House is missing as many as 225 days of e-mail dating back to 2003 and there is little if any likelihood a recovery effort will be completed by [...]]]></description>
			<content:encoded><![CDATA[<p><span style="font-size: x-small;"></p>
<div id="byline"><em><strong>Commentary: </strong>I don&#8217;t know&#8230;maybe it&#8217;s me but I think this is a serious problem.<br />
</em></div>
<div>
</div>
<div>By PETE YOST</div>
<p>The Associated Press<br />
Wednesday, August 20, 2008; 6:27 PM </span></p>
<p>WASHINGTON &#8212; The White House is missing as many as 225 days of e-mail dating back to 2003 and there is little if any likelihood a recovery effort will be completed by the time the Bush administration leaves office, according to an internal White House draft document obtained by The Associated Press.</p>
<p>The nine-page outline of the White House&#8217;s e-mail problems invites companies to bid on a project to recover the missing electronic messages.</p>
<p>The work would be carried out through April 19, 2009, according to the Office of Administration request for contractors&#8217; proposals, which was dated June 20.</p>
<p>Last week, the White House declined to comment on the document.</p>
<p><a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/08/20/AR2008082002617.html?hpid=moreheadlines">Source</a></p>

]]></content:encoded>
			<wfw:commentRss>http://vincentarnold.com/blog/white-house-missing-as-many-as-225-days-of-e-mail/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Ok, it&#8217;s done&#8230;I have an iPhone 3G.</title>
		<link>http://vincentarnold.com/blog/ok-its-donei-have-an-iphone-3g/</link>
		<comments>http://vincentarnold.com/blog/ok-its-donei-have-an-iphone-3g/#comments</comments>
		<pubDate>Mon, 11 Aug 2008 03:50:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Gadgets]]></category>

		<guid isPermaLink="false">http://vincentarnold.com/blog/?p=283</guid>
		<description><![CDATA[Coming from Windows Mobile from way back in the day, this should be interesting. Folks that know me know that I wouldn&#8217;t touch an Apple product if it was the last device of it&#8217;s kind on the planet. I&#8217;m a staunch Windows guys (early 1990&#8217;s) and plan to stay that way. So, this move to [...]]]></description>
			<content:encoded><![CDATA[<p>Coming from Windows Mobile from way back in the day, this should be interesting. Folks that know me know that I wouldn&#8217;t touch an Apple product if it was the last device of it&#8217;s kind on the planet. I&#8217;m a staunch Windows guys (early 1990&#8217;s) and plan to stay that way. So, this move to the iPhone was not taken lightly considering I passed on the first gen iPhone because it lacked 3G. Today I also have an HTC TyTN II which is a good phone but some of it&#8217;s quirks really bugged like the 2.8 inch screen. Sorry, but that is too small for an all around media device imho. Not to say that the iPhone doesn&#8217;t have it&#8217;s own quirks. Haven&#8217;t had it long enough to get a good feel for it&#8217;s capabilities but right of the bat I noticed there isn&#8217;t a lot of customization that can be done with the home screen. Also as noted, no cut and past which is kinda nuts because you have retype everything. My biggest concern though as you might have guessed is security. Stay tuned.</p>

]]></content:encoded>
			<wfw:commentRss>http://vincentarnold.com/blog/ok-its-donei-have-an-iphone-3g/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Note to France&#8217;s Men&#8217;s 4&#215;100m Swimming Relay Team&#8230;Oh, nm.</title>
		<link>http://vincentarnold.com/blog/note-to-frances-mens-4x100m-swimming-relay-teamoh-nm/</link>
		<comments>http://vincentarnold.com/blog/note-to-frances-mens-4x100m-swimming-relay-teamoh-nm/#comments</comments>
		<pubDate>Mon, 11 Aug 2008 03:40:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Just because it's cool]]></category>

		<guid isPermaLink="false">http://vincentarnold.com/blog/?p=282</guid>
		<description><![CDATA[

]]></description>
			<content:encoded><![CDATA[

]]></content:encoded>
			<wfw:commentRss>http://vincentarnold.com/blog/note-to-frances-mens-4x100m-swimming-relay-teamoh-nm/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Russian Gang Hijacking PCs in Vast Scheme</title>
		<link>http://vincentarnold.com/blog/russian-gang-hijacking-pcs-in-vast-scheme/</link>
		<comments>http://vincentarnold.com/blog/russian-gang-hijacking-pcs-in-vast-scheme/#comments</comments>
		<pubDate>Wed, 06 Aug 2008 03:54:13 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Attack Vector]]></category>

		<category><![CDATA[botnet]]></category>

		<guid isPermaLink="false">http://vincentarnold.com/blog/?p=281</guid>
		<description><![CDATA[By JOHN MARKOFF
Published: August 5, 2008
A criminal gang is using software tools normally reserved for computer network administrators to infect thousands of PCs in corporate and government networks with programs that steal passwords and other information, a security researcher has found.
The new form of attack indicates that little progress has been made in defusing the [...]]]></description>
			<content:encoded><![CDATA[<p>By <a title="More Articles by John Markoff" href="http://topics.nytimes.com/top/reference/timestopics/people/m/john_markoff/index.html?inline=nyt-per">JOHN MARKOFF</a><br />
Published: August 5, 2008</p>
<p>A criminal gang is using software tools normally reserved for computer network administrators to infect thousands of PCs in corporate and government networks with programs that steal passwords and other information, a security researcher has found.</p>
<p>The new form of attack indicates that little progress has been made in defusing the threat of botnets, networks of infected computers that criminals use to send spam, steal passwords and do other forms of damage, according to computer security investigators.</p>
<p><a href="http://www.nytimes.com/2008/08/06/technology/06hack.html?partner=rssnyt&amp;emc=rss">Source</a></p>

]]></content:encoded>
			<wfw:commentRss>http://vincentarnold.com/blog/russian-gang-hijacking-pcs-in-vast-scheme/feed/</wfw:commentRss>
		</item>
		<item>
		<title>S.F. officials locked out of computer network</title>
		<link>http://vincentarnold.com/blog/sf-officials-locked-out-of-computer-network/</link>
		<comments>http://vincentarnold.com/blog/sf-officials-locked-out-of-computer-network/#comments</comments>
		<pubDate>Wed, 16 Jul 2008 00:29:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Attack Vector]]></category>

		<guid isPermaLink="false">http://vincentarnold.com/blog/?p=279</guid>
		<description><![CDATA[(07-14) 19:23 PDT SAN FRANCISCO &#8212; A disgruntled city computer engineer has virtually commandeered San Francisco&#8217;s new multimillion-dollar computer network, altering it to deny access to top administrators even as he sits in jail on $5 million bail, authorities said Monday.
Terry Childs, a 43-year-old computer network administrator who lives in Pittsburg, has been charged with [...]]]></description>
			<content:encoded><![CDATA[<p><span id="bodytext" class="georgia md"><strong>(07-14) 19:23 PDT SAN FRANCISCO</strong> &#8212; A disgruntled city computer engineer has virtually commandeered San Francisco&#8217;s new multimillion-dollar computer network, altering it to deny access to top administrators even as he sits in jail on $5 million bail, authorities said Monday.</p>
<p>Terry Childs, a 43-year-old computer network administrator who lives in Pittsburg, has been charged with four counts of computer tampering and is scheduled to be arraigned today.</p>
<p><a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/07/14/BAOS11P1M5.DTL">Source</a></p>
<p></span></p>

]]></content:encoded>
			<wfw:commentRss>http://vincentarnold.com/blog/sf-officials-locked-out-of-computer-network/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Inside NSA Red Team Secret Ops With Government&#8217;s Top Hackers</title>
		<link>http://vincentarnold.com/blog/inside-nsa-red-team-secret-ops-with-governments-top-hackers/</link>
		<comments>http://vincentarnold.com/blog/inside-nsa-red-team-secret-ops-with-governments-top-hackers/#comments</comments>
		<pubDate>Tue, 01 Jul 2008 13:58:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://vincentarnold.com/blog/?p=278</guid>
		<description><![CDATA[
By Glenn Derene
Published on: June 30, 2008

When it comes to the U.S. government’s computer security, we in the tech press have a habit of reporting only the bad news—for instance, last year’s hacks into Oak Ridge and Los Alamos National Labs, a break-in to an e-mail server used by Defense Secretary Robert Gates &#8230; the [...]]]></description>
			<content:encoded><![CDATA[<p><span id="intelliTXT"></p>
<div class="byline">By Glenn Derene<br />
Published on: June 30, 2008
</div>
<p></span><span id="intelliTXT"><span style="font-size: 11pt;"><strong>When it comes</strong></span> to the U.S. government’s computer security, we in the tech press have a habit of reporting only the bad news—for instance, last year’s hacks into <a href="http://www.scmagazineus.com/Attackers-hack-into-Oak-Ridge-National-Laboratory/article/99767/" target="_blank">Oak Ridge</a> and <a href="http://it.slashdot.org/article.pl?sid=07/12/07/2056246" target="_blank">Los Alamos National Labs</a>, a <a href="http://www.usatoday.com/tech/news/computersecurity/2007-06-22-pentagon-hackers_N.htm" target="_blank">break-in to an e-mail server</a> used by Defense Secretary Robert Gates &#8230; the list goes on and on. Frankly that’s because the good news is usually a bunch of nonevents: “Hackers deterred by diligent software patching at the Army Corps of Engineers.” Not too exciting.</p>
<p>So, in the world of IT security, it must seem that the villains outnumber the heroes—but there are some good-guy celebrities in the world of cyber security. In my years of reporting on the subject, I’ve often heard the National Security Agency’s red team referred to with a sense of breathless awe by security pros. These guys are purported to be just about the stealthiest, most skilled firewall-crackers in the game. Recently, I called up the secretive government agency and asked if it could offer up a top red teamer for an interview, and, surprisingly, the answer came back, “Yes.”</span></p>
<p><strong>Source:</strong> <a href="http://www.popularmechanics.com/technology/military_law/4270420.html">Popular Mechanics</a></p>

]]></content:encoded>
			<wfw:commentRss>http://vincentarnold.com/blog/inside-nsa-red-team-secret-ops-with-governments-top-hackers/feed/</wfw:commentRss>
		</item>
		<item>
		<title>British hacker faces extradition hearing</title>
		<link>http://vincentarnold.com/blog/british-hacker-faces-extradition-hearing/</link>
		<comments>http://vincentarnold.com/blog/british-hacker-faces-extradition-hearing/#comments</comments>
		<pubDate>Fri, 13 Jun 2008 15:21:12 +0000</pubDate>
		<dc:creator>Vince</dc:creator>
		
		<category><![CDATA[Government InfoSec]]></category>

		<category><![CDATA[gary]]></category>

		<category><![CDATA[hacker]]></category>

		<category><![CDATA[mckinnon]]></category>

		<guid isPermaLink="false">http://vincentarnold.com/blog/?p=277</guid>
		<description><![CDATA[By Jeremy Kirk, IDG News Service
June 13, 2008
Gary McKinnon could become the first British hacker extradited to the U.S. for allegedly deleting data and accessing information                   on U.S. military and NASA computers 
A British hacker fighting extradition to [...]]]></description>
			<content:encoded><![CDATA[<p>By Jeremy Kirk, IDG News Service<br />
June 13, 2008</p>
<p><span class="mdTitleGen">Gary McKinnon could become the first British hacker extradited to the U.S. for allegedly deleting data and accessing information                   on U.S. military and NASA computers </span></p>
<p><span class="artText">A <a href="http://www.infoworld.com/article/07/02/13/HNhackerextradition_1.html?INTRUSION%20DETECTION%20AND%20PREVENTION%20-%20IDP">British hacker fighting extradition</a> to the U.S. on computer hacking charges is preparing for his final U.K. appeal on Monday in London.</span><span class="artText"></p>
<p class="ArticleBody">If Gary McKinnon loses this appeal, he would be the first British hacker extradited to the U.S. He could face up to 60 years                      in prison.</p>
<p class="ArticleBody">McKinnon, of London, is <a href="http://www.infoworld.com/article/05/06/08/HNlondonhack_1.html">accused of deleting data and illegally accessing information</a> on 97 U.S. military and NASA computers between February 2001 and March 2002. He&#8217;s been charged in U.S. District Court for                      the Eastern District of Virginia.</p>
<p class="ArticleBody">McKinnon admitted to using a program called &#8220;RemotelyAnywhere&#8221; to hack into PCs late at night when employees were gone. His hacking exploits started to unravel after McKinnon miscalculated the time difference between the U.S. and U.K., and one employee noticed their PC was acting oddly.</p>
<p class="ArticleBody"><a href="http://www.infoworld.com/article/08/06/13/British_hacker_faces_extradition_hearing_1.html">Read More</a></p>
<p></span></p>

]]></content:encoded>
			<wfw:commentRss>http://vincentarnold.com/blog/british-hacker-faces-extradition-hearing/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
