Bruce Schneier has a blog post about attacking bank-card PINs. Basically, the paper describes an inherent flaw with the way ATM PINs are encrypted and transmitted on the international financial networks, making them vulnerable to attack from malicious insiders in a bank. Just the fact that there are standalone ATMs in places like bus stations, seedy bars, and convenience stores worries me. Any bank in the whole ATM network could be the weak link.

To make up for the slow progress on SecurityMusings recently, here’s one mega-post with bunches of links. First off, PGP is 15 years old. The technology that started to put security and crypto into the average user’s hands has reached a pretty significant milestone, and deserves some recognition. Next is not specifically security related — it is how much of an IT disaster the electronic health records management system at Kaiser is. Aside from the problems of downtime and amazingly high ($4B) cost, it seems that it’s beginning to affect patient care, which is a Very Bad Thing. Although we don’t work with Kaiser (yet), we have dabbled in EHR for other customers. The EHR groups and vendors suffer from[…]

via SecurityFocus: On Tuesday night, Google accidentally sent out three posts on the official mailing list that contained copies of the Kapser.A worm, also known as the mass-mailing computer Kama Sutra. The video team pulled the posts from the archive on Wednesday, but not before 50,000 subscribers received the message, according to a PC World report. Come on, Google. What about your corporate motto, “Don’t be evil“? Oh well, a little joke at Google’s expense. That said, isn’t it about time that 100% of news and mailing list servers scan 100% of messages posted?

Via the Washington Post: Hackers have been breaking into customer accounts at large online brokerages in the United States and making unauthorized trades worth millions of dollars as part of a fast-growing new form of online fraud under investigation by federal authorities. Anyone else being pummled with an onslaught of advertisements to buy penny stocks? This recent spate of online brokerage fraud seems to be related to the same pump-and-dump schemes showing up in your inbox. Buy a penny stock at a low price. Spam a bunch of people and say that it’s a great deal—inevitably some will agree and buy it. Why not stop there? Use other peoples’ accounts to buy a bunch of it too, pumping up the[…]

Found in eWeek … Veteran malware researcher Joe Stewart was fairly sure he’d seen it all until he started poking at the SpamThru Trojan—a piece of malware designed to send spam from an infected computer. The Trojan, which uses peer-to-peer technology to send commands to hijacked computers, has been fitted with its own anti-virus scanner—a level of complexity and sophistication that rivals some commercial software. Other mass-mailing software running on your botnet getting you down? Not able to maximize that bandwidth on your pwned computer? Simply download, install, patch, and use pirated anti-virus software as part of your trojan! Much like the fight against the terrorists, the only way we can win this war is to take away the economic[…]

via Bruce Schneier’s blog. MSNBC has a neat article entitled Double Standards in Security Hassles: If you want to know why America’s security is so heavy on busywork and inconvenience and light on practicality, consider this: The people who make the rules don’t have to live with them. Public officials, some law enforcement officers and those who can afford expensive hobbies are often able to pull rank. Class warfare isn’t new. But in this form it is dangerous. By paying attention to the wrong things – grandma at the airport – we are ignoring the right things – identifying the most dangerous people. By training an army of low-paid workers to harass us all at airports by taking away our[…]