<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AllThingsD &#187; F-Secure</title>
	<atom:link href="http://allthingsd.com/tag/f-secure/feed/" rel="self" type="application/rss+xml" />
	<link>http://allthingsd.com</link>
	<description></description>
	<lastBuildDate>Sat, 11 Feb 2012 20:29:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><image>
		  <url>http://allthingsd.com/theme/images/logo-rss.jpg</url>
		  <title>All Things Digital</title>
		  <link>http://allthingsd.com/</link>
		  <width>144</width>
		  <height>22</height>
	</image>		<item>
		<title>Anonymous Plays Robin Hood With Stolen Credit Cards</title>
		<link>http://allthingsd.com/20111226/anonymous-plays-robin-hood-with-stolen-credit-cards/</link>
		<comments>http://allthingsd.com/20111226/anonymous-plays-robin-hood-with-stolen-credit-cards/#comments</comments>
		<pubDate>Mon, 26 Dec 2011 15:34:58 +0000</pubDate>
		<dc:creator>Arik Hesseldahl</dc:creator>
				<category><![CDATA[Enterprise]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[anonymous]]></category>
		<category><![CDATA[care]]></category>
		<category><![CDATA[F-Secure]]></category>
		<category><![CDATA[George Friedman]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[LulzSec]]></category>
		<category><![CDATA[Mikko Hypponen]]></category>
		<category><![CDATA[Red Cross]]></category>
		<category><![CDATA[Robin Hood]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Stratfor]]></category>
		<category><![CDATA[think tank]]></category>

		<guid isPermaLink="false">http://allthingsd.com/?p=156899</guid>
		<description><![CDATA[The hackers of Anonymous are at it again, attacking the servers of intelligence think tank Stratfor, and then using the pilfered credit cards to give money to charities.]]></description>
			<content:encoded><![CDATA[<p><a href="http://allthingsd.com/20110528/lockheed-martin-confirms-it-came-under-attack/hackers_ver1-2/" rel="attachment wp-att-79611"><img src="http://allthingsd.com/files/2011/05/hackers_ver1-375x285.jpg" alt="" title="hackers_ver1" width="375" height="285" class="alignright size-Featured wp-image-79611" /></a>The hacking collective that goes by the name Anonymous appears to have had a busy Christmas weekend. First came word that that its members had attacked and compromised the servers of the global intelligence think tank <a href="http://www.stratfor.com/">Stratfor</a>. (The Stratfor site is currently down for maintenance.) Then Anonymous claimed to have used the stolen credit cards to make charitable donations to aid organizations like CARE and the Red Cross.</p>
<p>Some people claiming to represent Anonymous &#8212; the lines and affiliations are always difficult to discern &#8212; said that the information taken in the attack included user names and passwords of some Stratfor subscribers, plus another 200 gigabytes worth of other data.</p>
<p>Stratfor founder George Friedman confirmed the attack in an email to subscribers; I received it because I&#8217;ve been an intermittent Stratfor subscriber over the years. Here&#8217;s Friedman&#8217;s email:</p>
<blockquote class="memo"><p>Dear Stratfor Member,</p>
<p>We have learned that Stratfor&#8217;s web site was hacked by an unauthorized party. As a result of this incident the operation of Stratfor&#8217;s servers and email have been suspended.</p>
<p>We have reason to believe that the names of our corporate subscribers have been posted on other web sites. We are diligently investigating the extent to which subscriber information may have been obtained.</p>
<p>Stratfor and I take this incident very seriously. Stratfor&#8217;s relationship with its members and, in particular, the confidentiality of their subscriber information, are very important to Stratfor and me. We are working closely with law enforcement in their investigation and will assist them with the identification of the individual(s) who are responsible.</p>
<p>Although we are still learning more and the law enforcement investigation is active and ongoing, we wanted to provide you with notice of this incident as quickly as possible. We will keep you updated regarding these matters.</p>
<p>Sincerely,<br />
George Friedman </p></blockquote>
<p>And here&#8217;s an update to Stratfor subscribers, from Dec. 25:</p>
<blockquote class="memo"><p>Dear Stratfor Member,</p>
<p>On December 24th an unauthorized party disclosed personally identifiable information and related credit card data of some of our members. We have reason to believe that your personal and credit card data could have been included in the information that was illegally obtained and disclosed.</p>
<p>Also publicly released was a list of our members which the unauthorized party claimed to be Stratfor&#8217;s &#8220;private clients.&#8221; Contrary to this assertion the disclosure was merely a list of some of the members that have purchased our publications and does not comprise a list of individuals or entities that have a relationship with Stratfor beyond their purchase of our subscription-based publications.</p>
<p>We have also retained the services of a leading identity theft protection and monitoring service on behalf of the Stratfor members that have been impacted by these events. Details regarding the services to be provided will be forwarded in a subsequent email that is to be delivered to the impacted members no later than Wednesday, December 28th.</p>
<p>In the interim, precautions that can be taken by you to minimize and prevent the misuse of information which may have been disclosed include the following:</p>
<p>- contact your financial institution and inform them of this incident;<br />
- if you see any unauthorized activity on your accounts promptly notify your financial institution;<br />
- submit a complaint with the Federal Trade Commission (&#8220;FTC&#8221;) by calling 1-877-ID-THEFT (1-877- 438-4338) or online at https://www.ftccomplaintassistant.gov/; and<br />
- contact the three U.S. credit reporting agencies: Equifax (http://www.equifax.com/ or (800) 685-1111), Experian (http://www.experian.com/ or (888) 397-3742), and TransUnion (http://www.transunion.com/ or (800) 888-4213), to obtain a free credit report from each.</p>
<p>Even if you do not find any suspicious activity on your initial credit reports, the FTC recommends that you check your credit reports periodically. Checking your credit reports can help you spot problems and address them quickly.</p>
<p>To ease any concerns you may have about your personal information going forward, we have also retained an experienced outside consultant that specializes in such security matters to bolster our existing efforts on these issues as we work to better serve you. We are on top of the situation and will continue to be vigilant in our implementation of the latest, and most comprehensive, data security measures.</p>
<p>We are also working to restore access to our website and continuing to work closely with law enforcement regarding these matters. We will continue to update you regarding the status of these matters.</p>
<p>Again, my sincerest apologies for this unfortunate incident.</p>
<p>Sincerely,<br />
George Friedman</p></blockquote>
<p>Then came reports that whoever had taken the information &#8212; which included credit card numbers &#8212; had used the numbers to make donations in the name of the hacking victims. Here&#8217;s a link to what is said to be a screen grab following <a href="http://imagebin.org/190299">just such a donation</a> to CARE by an employee of the Defense Intelligence Agency.</p>
<p>While some might applaud the apparent cleverness of Anonymous&#8217;s &#8220;steal from the rich, give to the poor&#8221; attitude, it&#8217;s unlikely that the charities in question will ever see a dime of the money that&#8217;s been &#8220;donated&#8221; to them. As Mikko Hypponen of F-Secure <a href="http://www.f-secure.com/weblog/archives/00002288.html">pointed out here</a>, once the credit cards in question are reported stolen, the charges will  be reversed and the charities will more than likely be on the hook for any fees or penalties that result.</p>
<p>As is often the case with a headline-making attack carried out in the name of Anonymous, there followed a series of claims and counterclaims as to whether or not this was an &#8220;official&#8221; Anonymous attack, or just the work of someone falsely claiming the Anonymous cloak. There was, for instance, this &#8220;emergency press release,&#8221; claiming that the attack on Stratfor was &#8220;most definitely not the work of Anonymous&#8221;:</p>
<p><iframe src="http://pastebin.com/embed_iframe.php?i=8yrwyNkt" style="border:none;width:100%"></iframe></p>
<p>Following that, Anonymous tweeted, via its semi-official Twitter account @AnonymousIRC, that it &#8220;laughed so hard&#8221; in response to that message &#8212; essentially saying it&#8217;s a fake. The group has hinted that it is going to be busy over the next several days.</p>
<p><!-- tweet id : 151293774415400960 --><br />
<style type="text/css">#bbpBox_151293774415400960 a { text-decoration:none; color:#99001a; }#bbpBox_151293774415400960 a:hover { text-decoration:underline; }</style>
<div id="bbpBox_151293774415400960" class="bbpBox" style="padding:20px; margin:5px 0; background-color:#131516; background-image:url(http://a1.twimg.com/images/themes/theme14/bg.gif);">
<div style="background:#fff; padding:10px; margin:0; min-height:48px; color:#333333; -moz-border-radius:5px; -webkit-border-radius:5px;"><span style="width:100%; font-size:18px; line-height:22px;">RT @<a href="http://twitter.com/intent/user?screen_name=FiloSottile" class="twitter-action">FiloSottile</a>: &#8220;Anonymous denies involvement in <a href="http://twitter.com/search?q=%23STRATFOR" title="#STRATFOR">#STRATFOR</a> hack. <a href="http://t.co/cQ1INYlh&#038;#8221" rel="nofollow">http://t.co/cQ1INYlh&#038;#8221</a>; | We laughed so hard at this!</span>
<div class="bbp-actions" style="font-size:12px; width:100%; padding:5px 0; margin:0 0 10px 0; border-bottom:1px solid #e6e6e6;"><img align="middle" src="http://allthingsd.com/wp-content/plugins/twitter-blackbird-pie//images/bird.png" /><a title="tweeted on December 26, 2011 5:30 am" href="http://twitter.com/#!/AnonymousIRC/status/151293774415400960" target="_blank">December 26, 2011 5:30 am</a> via <a href="http://code.google.com/p/qwit/" rel="nofollow" target="blank">Qwit</a><a href="https://twitter.com/intent/tweet?in_reply_to=151293774415400960" class="bbp-action bbp-reply-action" title="Reply"><span><em style="margin-left: 1em;"></em><strong>Reply</strong></span></a><a href="https://twitter.com/intent/retweet?tweet_id=151293774415400960" class="bbp-action bbp-retweet-action" title="Retweet"><span><em style="margin-left: 1em;"></em><strong>Retweet</strong></span></a><a href="https://twitter.com/intent/favorite?tweet_id=151293774415400960" class="bbp-action bbp-favorite-action" title="Favorite"><span><em style="margin-left: 1em;"></em><strong>Favorite</strong></span></a></div>
<div style="float:left; padding:0; margin:0"><a href="http://twitter.com/intent/user?screen_name=AnonymousIRC"><img style="width:48px; height:48px; padding-right:7px; border:none; background:none; margin:0" src="http://a1.twimg.com/profile_images/1554234337/anontopenyan_normal.png" /></a></div>
<div style="float:left; padding:0; margin:0"><a style="font-weight:bold" href="http://twitter.com/intent/user?screen_name=AnonymousIRC">@AnonymousIRC</a>
<div style="margin:0; padding-top:2px">AnonymousIRC</div>
</div>
<div style="clear:both"></div>
</div>
</div>
<p><!-- end of tweet --></p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20111226/anonymous-plays-robin-hood-with-stolen-credit-cards/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Twitter Begins Filtering Links</title>
		<link>http://allthingsd.com/20090803/twitter-begins-filtering-links/</link>
		<comments>http://allthingsd.com/20090803/twitter-begins-filtering-links/#comments</comments>
		<pubDate>Mon, 03 Aug 2009 21:41:00 +0000</pubDate>
		<dc:creator>Andrew LaVallee</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Social]]></category>
		<category><![CDATA[Voices]]></category>
		<category><![CDATA[account hijacking]]></category>
		<category><![CDATA[Andrew LaVallee]]></category>
		<category><![CDATA[digital]]></category>
		<category><![CDATA[Digits]]></category>
		<category><![CDATA[F-Secure]]></category>
		<category><![CDATA[frontpage]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[microblogging]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[The Wall Street Journal]]></category>
		<category><![CDATA[Twitter]]></category>
		<category><![CDATA[worms]]></category>

		<guid isPermaLink="false">http://voices.allthingsd.com/?p=14000</guid>
		<description><![CDATA[Twitter quietly started checking the URLs that its users post, a security measure aimed at weeding out links to known malware sites.

As online security firm F-Secure points out, the microblogging service “is increasingly targeted by worms, spam and account hijacking” and can easily filter links posted through it.]]></description>
			<content:encoded><![CDATA[<p>Twitter quietly started checking the URLs that its users post, a security measure aimed at weeding out links to known malware sites.</p>
<p>As online security firm F-Secure points out, the microblogging service “is increasingly targeted by worms, spam and account hijacking” and can easily filter links posted through it.</p>
<p>Twitter hasn’t announced this initiative and didn’t respond to a request for comment about it.</p>
<p>Now, when posting a link to a fraudulent site, it deletes the tweet and flashes the message “Oops! Your tweet contained a URL to a known malware site!”</p>
<p><a href="http://blogs.wsj.com/digits/2009/08/03/twitter-begins-filtering-links/">Read the rest of this post on the original site</a></p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20090803/twitter-begins-filtering-links/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>If Stupidity Were Illegal, You Might Have a Valid Counterclaim &#8230;</title>
		<link>http://allthingsd.com/20070713/sony-rootkit-suit/</link>
		<comments>http://allthingsd.com/20070713/sony-rootkit-suit/#comments</comments>
		<pubDate>Fri, 13 Jul 2007 07:01:49 +0000</pubDate>
		<dc:creator>John Paczkowski</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Amergence]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[CD]]></category>
		<category><![CDATA[F-Secure]]></category>
		<category><![CDATA[John Paczkowski]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[Sony BMG]]></category>

		<guid isPermaLink="false">http://digitaldaily.allthingsd.com/20070713/sony-rootkit-suit/</guid>
		<description><![CDATA[Still smarting over the flogging it suffered back in 2005 for encoding some of its music CDs with a harebrained rootkit copy-protection software, Sony BMG lashed out against the company that developed it last week, slapping it with a lawsuit. Sony accuses Amergence Group, formerly SunnComm International, of &#8220;negligence, unfair business practices and breaching the [...]]]></description>
			<content:encoded><![CDATA[<p><img src='http://digitaldaily.allthingsd.com/files/2007/07/guillotine.gif' width=250 height=321 style="border: 1px solid #000;" alt='guillotine.gif' />Still smarting over <a href="http://svextra.com/blogs/gmsv/2005/11/lets_see_--_sec.html">the flogging it suffered back in 2005</a> for encoding some of its music CDs with a harebrained rootkit copy-protection software, <a href="http://arstechnica.com/news.ars/post/20070712-sony-seeks-closure-on-mediamax-drm-fiasco-by-suing-developer.html">Sony BMG lashed out against the company that developed it last week</a>, slapping it with a lawsuit. Sony accuses Amergence Group, formerly SunnComm International, of &#8220;negligence, unfair business practices and breaching the terms of its license agreement by delivering software that &#8216;did not perform as warranted.&#8217; &#8221; It seeks $12 million in damages&#8211;<a href="http://news.com.com/Sony%20settles%20rootkit%20class%20action%20lawsuit/2100-1002_3-6012173.html?part=rss&amp;tag=6012173&amp;subj=news">about twice what Sony BMG paid out last fall to settle the various lawsuits</a> brought against it.</p>
<p>Interesting that Sony would accuse Amergence of failure to meet its specifications now. After all, you&#8217;d think that&#8217;s an issue it would have taken up with the company two years ago, after its own engineers presumably reviewed the software and, if not then, perhaps on Oct. 4, 2005&#8211;the day Finnish security outfit F-Secure warned it that <a href="http://www.businessweek.com/technology/content/nov2005/tc20051129_938966.htm">the software posed a serious security risk</a>. “If [Sony] had woken up and smelled the coffee when we told them there was a problem, they could have avoided this trouble,” Mikko Hypponen, F-Secure’s director of antivirus research, told BusinessWeek at the time.</p>
<p> “We told them it was a major security risk,” added Santeri Kangas, F-Secure’s director of research. “They thought we were silly. They wanted to keep the problem quiet.”</p>
<p>That&#8217;s certainly what it looked like at the time. What with Thomas Hesse, president of Sony BMG&#8217;s global digital business division, telling NPR that &#8220;<a href="http://www.npr.org/templates/story/story.php?storyId=4989260">most people don&#8217;t even know what a rootkit is, so why should they care about it?</a>&#8221;  &#8216;Course you tend to forget about those things when you&#8217;re busy redistributing blame, right?</p>
]]></content:encoded>
			<wfw:commentRss>http://allthingsd.com/20070713/sony-rootkit-suit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

