<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Redcatco &#187; security</title>
	<atom:link href="http://redcatco.com/blog/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://redcatco.com</link>
	<description>Connecting People With Technology</description>
	<lastBuildDate>Sat, 21 Apr 2012 10:56:37 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Upgrading to WordPress 3.3.2</title>
		<link>http://redcatco.com/blog/technology/upgrading-to-wordpress-3-3-2/</link>
		<comments>http://redcatco.com/blog/technology/upgrading-to-wordpress-3-3-2/#comments</comments>
		<pubDate>Sat, 21 Apr 2012 10:55:22 +0000</pubDate>
		<dc:creator>Benjamin Ellis</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[blogging]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://redcatco.com/?p=2120</guid>
		<description><![CDATA[We&#8217;ve just upgraded all of our WordPress blogs to WordPress 3.3.2,. Assuming you&#8217;ve kept up to date, the upgrade is very minor . The changes between 3.3, 3.3.1 and 3.3.2 are predominantly security related, and shouldn&#8217;t cause any issues with themes or plugins. To be clear, there aren&#8217;t any major security issues to be concerned [...]]]></description>
			<content:encoded><![CDATA[<p>We&#8217;ve just upgraded all of our <a href="http://wordpress.org/">WordPress blogs</a> to WordPress 3.3.2,. Assuming you&#8217;ve kept up to date, the upgrade is very minor . The changes between 3.3, 3.3.1 and 3.3.2 are predominantly security related, and shouldn&#8217;t cause any issues with themes or plugins. To be clear, there aren&#8217;t any major security issues to be concerned with here, but moving up to 3.3.2 (if we were back at 3.3) addresses the following issues:</p>
<ul>
<li>Potential cross-site scripting vulnerability on WordPress sites configured directly by IP address (<a href="http://www.ethicalhack3r.co.uk/security/wordpress-3-3-cross-site-scripting-xss/">tested here</a>).</li>
<li>A couple of other potential cross-site scripting / redirect issues.</li>
<li>Potential issue with privilege escalation for admin users in WordPress networks.</li>
<li><a href="http://www.plupload.com/punbb/viewtopic.php?id=1685">Plupload issue</a> &#8211; the code WordPress uses to upload files.</li>
<li>SWFUpload issue &#8211; the old code WordPress used to upload files.</li>
<li>SWFObject issue &#8211; code used to embed Flash content.</li>
</ul>
<p>Although none of these are critical, the update(s) should be applied to minimise any potential risks. The two point releases also include some css and JavaScript tweaks, which save loading some images in the admin interface, and address a couple of cosmetic issues, including an upgrade to the hoverIntent and press-this code.</p>
<p>While we are on the topic of upgrades, WordPress 3.4 is just around the corner (<a href="http://wordpress.org/news/2012/04/wordpress-3-4-beta-2/">currently in beta</a>). The upcoming release features a number of enhancements to internationalization functionality, particularly of interest for non-English WordPress users, new features for theme designers (child themes and configuration for headers and backgrounds), and a number of performance enhancements and API tweaks, which will need a fair bit of testing with older plugins and themes before sites can be upgraded.</p>
<p>As ever, always keep regular back ups of your blog &#8211; you don&#8217;t want to lose any of those hard written posts, hard-earned comments or those pictures, videos and links you spent hours curating. For our business blogs, we back up databases nightly, and keep a rolling archive. Uploads and other content are mirrored to our standby servers in real-time. If you can&#8217;t afford that sort of protection, then at least take an export of your blog once every few posts, and do keep a local copy of any images or other files that you upload. And, of course, always do a full back up before any upgrade or adding plugins.</p>
<p>Happy, and safe, blogging!</p>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://redcatco.com/blog/technology/wordpress-3-2-intranets-internet-explorer-and-the-web/" title="WordPress 3.2 Intranets Internet Explorer and The Web">WordPress 3.2 Intranets Internet Explorer and The Web</a></li><li><a href="http://redcatco.com/blog/communication/communication-becoming-fluid-by-getting-uncomfortable/" title="Communication &#8211; Becoming Fluid by Getting Uncomfortable">Communication &#8211; Becoming Fluid by Getting Uncomfortable</a></li><li><a href="http://redcatco.com/blog/communication/blogging/is-ghost-blogging-ethical/" title="Is Ghost Blogging Ethical?">Is Ghost Blogging Ethical?</a></li><li><a href="http://redcatco.com/blog/communication/social-media-at-a-business-event-but-why/" title="Social Media at a Business Event &#8211; But Why?">Social Media at a Business Event &#8211; But Why?</a></li><li><a href="http://redcatco.com/blog/communication/caught-by-a-spy-easier-than-it-sounds/" title="Caught by a Spy &#8211; Easier Than it Sounds">Caught by a Spy &#8211; Easier Than it Sounds</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://redcatco.com/blog/technology/upgrading-to-wordpress-3-3-2/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Caught by a Spy &#8211; Easier Than it Sounds</title>
		<link>http://redcatco.com/blog/communication/caught-by-a-spy-easier-than-it-sounds/</link>
		<comments>http://redcatco.com/blog/communication/caught-by-a-spy-easier-than-it-sounds/#comments</comments>
		<pubDate>Mon, 01 Jun 2009 12:19:14 +0000</pubDate>
		<dc:creator>Benjamin Ellis</dc:creator>
				<category><![CDATA[communication]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[social networking]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://redcatco.com/?p=1579</guid>
		<description><![CDATA[If you are a regular Twitter user, you might have noticed that half of the world seems to have become a spy catcher of late. It turns that catching a spy via Twitter is easier than you might think. It also has some consequences for  social capital, information security and general communication noise too. You are a very fortunate individual [...]]]></description>
			<content:encoded><![CDATA[<p><img class="aligncenter size-full wp-image-1582" title="spy" src="http://redcatco.com/blog/wp-content/uploads/2009/06/spy.jpg" alt="spy" /><br />
If you are a regular Twitter user, you might have noticed that half of the world seems to have become a <a href="http://playspymaster.com/">spy catcher</a> of late. It turns that catching a spy via <a href="http://redcatco.com/about/twitter/">Twitter</a> is easier than you might think. It also has some consequences for  social capital, information security and general communication noise too.</p>
<p>You are a very fortunate individual if you have escaped the torrent of (somewhat spammy) messages from the spy catcher application. It is doing a rather good, and therefore bad, job of turning Twitter into Facebook &#8211; or rather the bad old Facebook of a while ago, with the legendary sheep throwing, pirates, vampires and sea of noise generated by that genre of social applications.</p>
<h2>Got You! Via Twitter</h2>
<p>The success of Spycatcher is a proof point of another unsettling trend: Notice how easily people hand over their username and passwords to a relatively unknown (and potentially untrusted) third party.</p>
<p>There has been a long term problem with twitter third party applications. The first generation of applications required users to enter their username and password on the third party site, where they were stored, so that the 3rd party could get access to the user&#8217;s Twitter stream, to do whatever wonderful things it did. It sounds relatively innocuous, but actually it sets a rather bad precedent. It is referred to as an anti-pattern, a commonly bad solution to a problem. It is bad because it <a href="http://adactio.com/journal/1357">teaches people how to be phished</a>.</p>
<h2>From Catching Fish to Helping Phishers</h2>
<p>Phishers spend their time trying to get users to hand over password details, so that they can gain access to accounts. Twitter has a bad anti-pattern problem, <a href="http://factoryjoe.com/blog/2009/01/02/twitter-and-the-password-anti-pattern/">and it knows it</a>, since the Twitter ecosystem trains users to hand over their security details to third parties. To tackle the issue Twitter has added <a href="http://oauth.net/">OAuth</a> to the service. It provides a way for third parties to validate users, without storing the username and password. However, this doesn&#8217;t solve the whole problem. People are still handing over passwords. So, back to catching those spies&#8230;</p>
<p>Increasingly third party Twitter applications are not only logging in to pull down information, but they are actively sending tweets from users accounts (including @ messages and Direct Messages) on behalf of, and in the name of, the user. And why wouldn&#8217;t they? If a developer can get away with using a bit of a user&#8217;s social capital to promote their application, they probably will. Spycatcher is a particular case in point.</p>
<h2>From Bad to Worse</h2>
<p>The annoying messages it tweets are one thing, &#8220;captured this&#8221;, &#8220;assassinated that&#8221;, <a href="http://twitter.com/BenjaminEllis/status/1984020138">they can be blocked</a>. However, over the weekend things took a turn for the worse when I started getting private direct messages from the people I follow asking me to join. Now, either my friends have suddenly all switched to the same writing style, or these were automated DMs. I&#8217;ll let you take your pick.</p>
<p>Twitter direct messages are my most trusted communications channel, since only people I have chosen to follow can send me messages (oh that my mobile phone was the same), and the messages generate alerts in near-real-time. So, when people start spamming me via that channel I sit up and take notice. There is another reason too. Because URLs that arrive via that channel are usually from a trusted human, I tend to trust the links. I shouldn&#8217;t of course, and neither should you. Combined with anti-patter behaviours, it is all too easy to receive a DM with a link and a &#8220;Benjamin, use your Twitter ID to check your security here&#8221; &#8211; you can see where that heads. If I was being dozy, 5 minutes later all of the people who follow me would be getting the same message. Injecting malware, or carrying out phishing attacks it all too easy. People need to realise that the twitter stream is part of their on-line identity, and to guard security credentials well. It was a little while back that <a href="http://www.readwriteweb.com/archives/twitter_security_collapses_oba.php">Britney Spears and Barack Obama had their login details compromised</a>.</p>
<h2>What to learn?</h2>
<ul>
<li>Don&#8217;t hand over your user name and password unless you are 100% sure where they are going, and what will be done with them.</li>
<li>Use different passwords for different services. That way any damage should be limited to one service. If your Twitter password is the same as your on-line banking one, fix that quickly!</li>
<li>Change your passwords every so often. Yes, I&#8217;m sounding like the moaning IT guy, but this does make a difference to your security.</li>
</ul>
<p>I expect to see more and more applications using the social capital of their users to promote them &#8211; that has been the model on Facebook, and now it&#8217;s coming to Twitter. As for Spymaster, I&#8217;m not sure if it should be called <a href="http://www.techcrunch.com/2009/05/29/spy-vs-spy-the-spymaster-backlash-begins-and-twitter-needs-to-fix-it/">spam master</a> rather than spymaster (if you want to play <a href="http://www.twitpic.com/6aqvi">please turn off the notifications</a> I hate having to unfollow people). I&#8217;m surprised their hasn&#8217;t been a bigger backlash against it.</p>
<p>Perhaps it is a sign of the shifting user. We have reached the &#8220;sheep throwing&#8221; phase of the social networking platfrom life cycle. It&#8217;ll take it as a sign of Twitter entering adolesence already.</p>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://redcatco.com/blog/communication/tweetcamp-london-beyond-140-characters/" title="Tweetcamp London &#8211; Beyond 140 Characters">Tweetcamp London &#8211; Beyond 140 Characters</a></li><li><a href="http://redcatco.com/blog/communication/replying-via-twitter/" title="Replying Via Twitter">Replying Via Twitter</a></li><li><a href="http://redcatco.com/blog/technology/not-so-private-data/" title="Not So Private Data">Not So Private Data</a></li><li><a href="http://redcatco.com/blog/technology/upgrading-to-wordpress-3-3-2/" title="Upgrading to WordPress 3.3.2">Upgrading to WordPress 3.3.2</a></li><li><a href="http://redcatco.com/blog/leadership/a-perspective-on-community/" title="A Perspective on Community">A Perspective on Community</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://redcatco.com/blog/communication/caught-by-a-spy-easier-than-it-sounds/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Information Security is for All</title>
		<link>http://redcatco.com/blog/technology/information-security-is-for-all/</link>
		<comments>http://redcatco.com/blog/technology/information-security-is-for-all/#comments</comments>
		<pubDate>Mon, 28 Apr 2008 11:03:18 +0000</pubDate>
		<dc:creator>Benjamin Ellis</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[teleworking]]></category>

		<guid isPermaLink="false">http://redcatco.com/blog/?p=446</guid>
		<description><![CDATA[We all understand the concepts of physical security reasonably well: Locks, Doors, Alarms, Security Guards&#8230; With the new digital universe we need to be just as conversant with information security. The front page headline of Computer Weekly last week was a good reminder: &#8220;More intruders found behind firewall, says 2008 Information Security Breaches survey.&#8221; The [...]]]></description>
			<content:encoded><![CDATA[<p>We all understand the concepts of physical security reasonably well: Locks, Doors, Alarms, Security Guards&#8230; With the new <a href="http://redcatco.com/blog/technology/the-exploding-digital-universe/">digital universe</a> we need to be just as conversant with information security. The front page headline of Computer Weekly last week was a good reminder: &#8220;<a href="http://www.computerweekly.com/Articles/2008/04/22/230363/more-intruders-found-behind-firewall-says-2008-information-security-breaches-survey.htm">More intruders found behind firewall, says 2008 Information Security Breaches survey</a>.&#8221;</p>
<p>The report is based on the recent <span class="noindex"><span id="ArticleBody">Information Security Breaches survey (<a href="http://www.berr.gov.uk/files/file45714.pdf">PDF</a> and <a href="http://www.berr.gov.uk/files/file45713.pdf">PDF of executive summary</a>) conducted for the <a href="http://www.berr.gov.uk/sectors/infosec/index.html">Department for Business, Enterprise and Regulatory Reform</a>, and reports a ten fold increase in hackers inside the firewall</span></span></p>
<p>An attention grabbing article, but there are some things of note.<span class="noindex"><span id="ArticleBody"> Because corporate cyber defences are working well, <a href="http://www.computerweekly.com/Articles/2008/04/16/230302/malware-coders-shifting-focus-to-home-pc-users-report.htm">criminals are targeting home PCs</a> and careless web surfers. Having failed to hack us in the office, they are after us at home. The IT team has always been concerned about the security of remote workers, now they will be even more so.</span></span></p>
<p>The launch of the report coincided with the start of the <a title="InfoSec" href="http://www.infosec.co.uk/">InfoSec</a> security show London this week, which featured all of the major vendors showing their latest wares. Security is increasingly moving from network-based firewalls, to desktop-based software. This approach makes securing remote or home-based machines easier.</p>
<p>In the article, Jim Norton, senior policy adviser at the Institute of Directors, <a href="http://www.computerweekly.com/Articles/2006/04/19/215435/infosecurity-preview-the-inside-track-on-hackers.htm">suggested firms use honeypots</a> (servers designed to appear to contain valuable information). I wouldn&#8217;t say that was good advice. Using honey pots is a bit like guarding parked cars by putting a very expensive looking one in the middle and hoping the criminals hit that first.</p>
<p>Enterprise security measures are working increasingly well. What we have to watch out for now is social engineering attacks, such as emails that result in unwittingly handing over login information or personal details. Be on your guard, as these methods, including &#8220;phishing&#8221; e-mails, are becoming more and more sophisticated.</p>
<p>The threat is not just our personal or corporate information ending up in the public domain, it is also the risk of loosing valuable data. Yet another reason to have a good back up policy, be it for your family photos or corporate trade secrets!</p>
<p>Reference: <span class="noindex"><span id="ArticleBody"><a href="http://www.berr.gov.uk/files/file45714.pdf">Information Security Breaches survey</a> (<a href="http://www.berr.gov.uk/files/file45713.pdf">executive summary</a>)</span></span><span class="noindex"><span id="ArticleBody"><a href="http://www.berr.gov.uk/files/file45714.pdf"></a></span></span></p>
<p><span class="noindex"><span id="ArticleBody"></span></span></p>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://redcatco.com/blog/technology/upgrading-to-wordpress-3-3-2/" title="Upgrading to WordPress 3.3.2">Upgrading to WordPress 3.3.2</a></li><li><a href="http://redcatco.com/blog/communication/caught-by-a-spy-easier-than-it-sounds/" title="Caught by a Spy &#8211; Easier Than it Sounds">Caught by a Spy &#8211; Easier Than it Sounds</a></li><li><a href="http://redcatco.com/blog/technology/not-so-private-data/" title="Not So Private Data">Not So Private Data</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://redcatco.com/blog/technology/information-security-is-for-all/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Not So Private Data</title>
		<link>http://redcatco.com/blog/technology/not-so-private-data/</link>
		<comments>http://redcatco.com/blog/technology/not-so-private-data/#comments</comments>
		<pubDate>Thu, 21 Feb 2008 23:19:12 +0000</pubDate>
		<dc:creator>Benjamin Ellis</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Facebook]]></category>
		<category><![CDATA[Identity]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[social graph]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://redcatco.com/blog/productivity/not-so-private-data/</guid>
		<description><![CDATA[The issue of identity information isn&#8217;t as simple as private or public, unshared or shared. In the Internet age, searchablility and discoverability are also factors, as well as the more granular way we can choose to share data. Computers give the illusion that we can control what we share and who we share it with. [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://redcatco.com/blog/wp-content/uploads/2008/02/eyetoeye.jpg" alt="Eye to eye" align="right" border="2" hspace="2" vspace="2" />The issue of identity information isn&#8217;t as simple as private or public, unshared or shared. In the Internet age, <a href="http://personalbrandingblog.wordpress.com/2007/12/13/google-searchability-and-personal-branding-collide-face-to-face/" rel="nofollow">searchablility</a> and discoverability are also factors, as well as the more granular way we can choose to share data. Computers give the illusion that we can control what we share and who we share it with. It is just that, an illusion.</p>
<p>I get a handy example if I google for the excellent and insightful Fred Basset &#8211; yes, I did just use google as a verb, please don&#8217;t stone me.<span id="more-371"></span> In the results page I am overwhelmed by information on the cartoon character, rather than the new media expert. Fred is hidden in the camouflage of a mass of other data. Security by obscurity &#8211; he&#8217;s hidden in plain sight. If I Google for Benjamin Ellis, I account for most of the first page of results &#8211; your mileage may vary searching with Google from other countries (just for fun, e-mail the first page of results from where you live!). I&#8217;m not working as an SEO consultant for myself, there just seem to be less Benjamin Ellis&#8217;s out there, so I can&#8217;t hide.</p>
<p>Digital information has a rather free-flowing nature. Its natural tendency is to &#8216;escape&#8217; from where we put it. Unhappy accidents like the <a href="http://p10.hostingprod.com/@spyblog.org.uk/blog/2007/11/national_audit_office_reveals_some_emails_about_the_hmrc_data_security_and_priva.html">recent HMRC fiasco</a> are a reminder that it has a characteristic that physical property does not: it can be replicated, indefinitely.</p>
<p>If I mark something as &#8216;private&#8217;, to share with my &#8216;closed&#8217; social network, I am reliant on  those friends not making it public &#8211; either purposefully or accidentally. For example, if they tweet it on twitter, then it is indexed in Google by default. In the same way, companies rely on employees keeping information confidential. The difference is that data spillage now happens more easily, with our increasing connectedness.</p>
<p>There is an interesting characteristic of digital conversations that take place in social media, and that is a form of digital &#8216;spill&#8217;. The characteristic springs from the mismatch between peoples&#8217; social graphs &#8211; your set of friends/contacts and mine may have some common elements, but they also have differences.</p>
<p>If we &#8216;chat&#8217; between ourselves via the Facebook (using the wall feature) or Twitter, the differences in our social graphs cause shards of the conversation to propagate our beyond the original circle. That can be bad, or it can be good. One of the most interesting things about Twitter is the accidental conversations. It is the closest thing to creating that business haven of innovation, the water cooler conversation. With more and more remote workers, and reliance on external specialists, business will need these tools.</p>
<p>The reality is that Facebook is just describing the real world of social relationships. There is nothing new here. &#8216;Social graphs&#8217; have existed since humans first started raising children and gathering food together. Now we have a common place word to describe the phenomenon, and tools, like Facebook and Linkedin, that have digitised the information and enabled us to study it as never before.</p>
<p>Data has the rather nasty habit of being permanent, sometimes inconveniently. I recently stumbled upon an email I sent to a mailing list in 1988, which is now a web forum. There is my email, in all of its glory. Thankfully I wasn&#8217;t too embarrassing as a teenager, but none-the-less, it is quite a sobering fact that something I wrote twenty years ago is right there, neatly indexed on Google.</p>
<p>The real world of information security, especially around identity, is messy. Tools like Facebook are gradually drawing attention to old issues and creating new ones. In the first few decades of computing, the challenges were in the technology, in the next, I suspect the challenges reside elsewhere.</p>
<p>Having a universal digital identity has efficiency benefits, but it also has big data privacy challenges too. It takes discoverability to a new level, which means that integrity is going to take on a whole new meaning, however good your security is.</p>
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li><a href="http://redcatco.com/blog/productivity/whos-are-you-the-question-of-stolen-bits-of-identity/" title="Who&#8217;s are you? The Question of stolen (bits of) identity">Who&#8217;s are you? The Question of stolen (bits of) identity</a></li><li><a href="http://redcatco.com/blog/communication/caught-by-a-spy-easier-than-it-sounds/" title="Caught by a Spy &#8211; Easier Than it Sounds">Caught by a Spy &#8211; Easier Than it Sounds</a></li><li><a href="http://redcatco.com/blog/communication/foaf-building-networks-with-a-friend-of-a-friend/" title="FOAF &#8211; Building Networks With a Friend of a Friend">FOAF &#8211; Building Networks With a Friend of a Friend</a></li><li><a href="http://redcatco.com/blog/communication/going-hyper-local-location-based-internet/" title="Going Hyper-Local &#8211; Location Based Internet">Going Hyper-Local &#8211; Location Based Internet</a></li><li><a href="http://redcatco.com/blog/psychology/the-rather-complex-issue-of-identity/" title="The Rather Complex Issue of Identity">The Rather Complex Issue of Identity</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://redcatco.com/blog/technology/not-so-private-data/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>


<!-- Served from: redcatco.com @ 2012-05-24 13:43:28 by W3 Total Cache -->
