<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://jessehirsh.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Security</title>
 <link>http://jessehirsh.com/category/security</link>
 <description>The taxonomy view with a depth of 0.</description>
 <language>en</language>
<item>
 <title>Always question the assertion that your privacy is protected</title>
 <link>http://jessehirsh.com/always-question-the-assertion-your-privacy-protected</link>
 <description>&lt;p&gt;Last week my CBC radio column covered &lt;a href=&quot;http://www.catsa-acsta.gc.ca/english/media/rel_comm/2008-06-19.shtml&quot;&gt;the recent introduction of a 3D imaging surveillance system used at the Kelowna BC airport to screen passengers&lt;/a&gt;. Using millimetre waves the system is able to penetrate clothing and create a vivid 3D model of the passenger without clothes on. Thus it is a far more thorough system then the existing setup which only scans for metal.&lt;/p&gt;
&lt;p&gt;Part of the focus of the column was on the privacy implications of such a system, and at the time CATSA (the Canadian Air Transport Security Authority) was claiming it had the support of the federal privacy commissioner. I mentioned this in my column, but also expressed skepticism that the current steps being taken to protect passenger&#039;s privacy was not enough.&lt;/p&gt;
&lt;p&gt;Turns out, the privacy commissioner does not support the pilot project, and does indeed have concerns with how passengers privacy might be violated. Here&#039;s &lt;a href=&quot;http://www.theglobeandmail.com/servlet/story/RTGAM.20080625.wlscreening25/BNStory/lifeMain/?page=rss&amp;amp;id=RTGAM.20080625.wlscreening25&quot;&gt;a quote from the Globe and Mail&lt;/a&gt;:&lt;/p&gt;
&lt;p&gt;&quot;However, the privacy commissioner&#039;s office said yesterday it is concerned about the implications of the new system and it never told CATSA officials that the body-scanning technology meets Canadian privacy standards.&lt;/p&gt;
&lt;p&gt;&quot;At this very early stage we certainly don&#039;t know enough to endorse the project, so the suggestion that we endorsed it is perhaps a bit off,&quot; commission spokeswoman Anne-Marie Hayden said. &quot;I think we&#039;re going to have to watch it closely and we&#039;re going to want to ensure that individuals&#039; privacy rights are protected.&quot;&lt;/p&gt;
&lt;p&gt;Thanks to Blair Campbell for alerting me to this. Goes to show that even when an organization says it is protecting your privacy you should still question that assertion, and try and think of unforeseen ways in your rights my be violated.&lt;/p&gt;
</description>
 <comments>http://jessehirsh.com/always-question-the-assertion-your-privacy-protected#comments</comments>
 <category domain="http://jessehirsh.com/category/blog-topics/cbc">CBC</category>
 <category domain="http://jessehirsh.com/category/security">Security</category>
 <category domain="http://jessehirsh.com/category/surveillance">Surveillance</category>
 <category domain="http://jessehirsh.com/category/travel">Travel</category>
 <pubDate>Mon, 30 Jun 2008 10:20:36 -0400</pubDate>
 <dc:creator>jesse</dc:creator>
 <guid isPermaLink="false">258 at http://jessehirsh.com</guid>
</item>
<item>
 <title>Child Pornography and Computer Hacking</title>
 <link>http://jessehirsh.com/child-pornography-and-computer-hacking</link>
 <description>&lt;p&gt;This past week I was overwhelmed with responses from a number of media stories. A couple of &lt;a href=http://canadianpress.google.com/article/ALeqM5jJDpsCCzHWHuOC4flOvOLDcvc5HA&gt;Blackberry business&lt;/a&gt; &lt;a href=http://canadianpress.google.com/article/ALeqM5j6mRYroq6jTHtNf_BtjySaTHxIEA&gt;articles&lt;/a&gt;, a couple of &lt;a href=http://jessehirsh.com/facebook-expert-witness-testimony&gt;Facebook expert&lt;/a&gt; articles, an &lt;a href=http://www.theglobeandmail.com/servlet/story/RTGAM.20080222.wbcchen22/BNStory/Entertainment/home&gt;article about a Hong Kong sex scandal&lt;/a&gt;, as well as some TV and radio appearances, first about the bust of a child porn ring, and then about the bust of a Quebec based Hacker cell.&lt;/p&gt;
&lt;p&gt;In general my policy is to respond to anyone who takes the time to get in touch with me. Yet I&#039;ve now had to revise this policy to only reply to people who show respect rather than outright hostility. Something about the audience that reads the National Post that brings all sorts of trolls out from under the bridge.&lt;/p&gt;
&lt;p&gt;The CBC audience on the other hand is a pleasure to interact with. Even when they strongly disagree with me I find CBC viewers and listeners to be intelligent and engaging. One particularly pleasant email I received was from a &quot;middle-aged mother&quot; who will remain nameless, but I suspect represents a typical Canadian, from an average family. For the sake of argument, let&#039;s call her Louise.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://jessehirsh.com/child-pornography-and-computer-hacking&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://jessehirsh.com/child-pornography-and-computer-hacking#comments</comments>
 <category domain="http://jessehirsh.com/category/blog-topics/cbc">CBC</category>
 <category domain="http://jessehirsh.com/category/internet">Internet</category>
 <category domain="http://jessehirsh.com/category/legal">Legal</category>
 <category domain="http://jessehirsh.com/category/media">Media</category>
 <category domain="http://jessehirsh.com/category/security">Security</category>
 <category domain="http://jessehirsh.com/category/technology">Technology</category>
 <pubDate>Sun, 24 Feb 2008 16:38:12 -0500</pubDate>
 <dc:creator>jesse</dc:creator>
 <guid isPermaLink="false">223 at http://jessehirsh.com</guid>
</item>
<item>
 <title>JS/Snz an example of what&#039;s wrong with computer security</title>
 <link>http://jessehirsh.com/jssnz-example-whats-wrong-computer-security</link>
 <description>&lt;p&gt;Computer security is a field I&#039;ve always been interested in, both as a journalist, researcher, and system administrator. However I&#039;m also often quite critical of the industry as a whole, and the manner in which they communicate with their customers.&lt;/p&gt;
&lt;p&gt;Today a particularly symbolic and silly episode is transpiring that illustrates why the trust and power we put into security and anti-virus software is often misplaced.&lt;/p&gt;
&lt;p&gt;Users of the CA eTrust software are being alerted that they&#039;ve been infected by the JS/SNZ.a virus whenever they surf a website that runs any one of a few common javascript libraries. This includes my own site, which is causing some of my readers to get alerts, one of whom emailed me about it.&lt;/p&gt;
&lt;p&gt;The problem of course is that this is not a virus at all, rather a false positive. Most users however won&#039;t know that, and instead are being scared away from thousands if not millions of legitimate websites.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://jessehirsh.com/jssnz-example-whats-wrong-computer-security&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://jessehirsh.com/jssnz-example-whats-wrong-computer-security#comments</comments>
 <category domain="http://jessehirsh.com/category/blog-topics/analysis">Analysis</category>
 <category domain="http://jessehirsh.com/category/security">Security</category>
 <pubDate>Mon, 31 Dec 2007 16:19:52 -0500</pubDate>
 <dc:creator>jesse</dc:creator>
 <guid isPermaLink="false">174 at http://jessehirsh.com</guid>
</item>
<item>
 <title>2007 was about cyber crime</title>
 <link>http://jessehirsh.com/2007-was-about-cyber-crime</link>
 <description>&lt;p&gt;In my latest article for cbcnews.ca I&#039;ve taken a &lt;a href=http://www.cbc.ca/news/background/tech/hightech/online-crime2007.html&gt;look back at 2007 as a profitable and successful year for cyber crime&lt;/a&gt;. Explicitly I take my analysis of the storm worm and draw out a thread that shows the larger socio-political implications of this emerging technology:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;The organization of all this criminal activity manifests in the form of bot nets (see sidebar) such as the storm worm, networks of hijacked machines that allow criminals to engage in their activities without being traced or identified. The sophistication of these bot nets has increased so rapidly that many observers have begun speculating that we&#039;re witnessing the early stages of a new online arms race, a cyber cold-war in which new weapons and tactics are being developed and tested.&lt;/p&gt;&lt;/blockquote&gt;
</description>
 <comments>http://jessehirsh.com/2007-was-about-cyber-crime#comments</comments>
 <category domain="http://jessehirsh.com/category/blog-topics/analysis">Analysis</category>
 <category domain="http://jessehirsh.com/category/blog-topics/cbc">CBC</category>
 <category domain="http://jessehirsh.com/category/politics">Politics</category>
 <category domain="http://jessehirsh.com/category/security">Security</category>
 <pubDate>Tue, 25 Dec 2007 09:40:53 -0500</pubDate>
 <dc:creator>jesse</dc:creator>
 <guid isPermaLink="false">173 at http://jessehirsh.com</guid>
</item>
<item>
 <title>Who am I? Who is the Storm Worm?</title>
 <link>http://jessehirsh.com/who-am-i-who-is-the-storm-worm</link>
 <description>&lt;p&gt;Today&#039;s my birthday, I was born 3.3 decades ago, at around 6:10 in the morning. I&#039;ve always enjoyed my birthdays. I tend to take the time to reflect on this day, remembering where I came from, while thinking about where I&#039;m going.&lt;/p&gt;
&lt;p&gt;On some levels identity is fluid, always changing, yet on the other hand there are constants that go through our lives as threads that bend but remain relatively the same.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://jessehirsh.com/who-am-i-who-is-the-storm-worm&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://jessehirsh.com/who-am-i-who-is-the-storm-worm#comments</comments>
 <category domain="http://jessehirsh.com/category/blog-topics/analysis">Analysis</category>
 <category domain="http://jessehirsh.com/category/blog-topics/facebook">Facebook</category>
 <category domain="http://jessehirsh.com/category/pack">Pack</category>
 <category domain="http://jessehirsh.com/category/security">Security</category>
 <pubDate>Thu, 18 Oct 2007 00:00:00 -0400</pubDate>
 <dc:creator>jesse</dc:creator>
 <guid isPermaLink="false">166 at http://jessehirsh.com</guid>
</item>
<item>
 <title>The Perpetual Information War</title>
 <link>http://jessehirsh.com/the-perpetual-information-war</link>
 <description>&lt;p&gt;I&#039;ve done a number of CBC segments recently around computer security and information warfare. While trying not to be sensational, these are subject areas that I feel require more attention, certainly from the news media, but also from the public at large.&lt;/p&gt;
&lt;p&gt;On the one hand they are fascinating unto themselves, and don&#039;t require any added emphasis to denote severity, yet at the same time, the phenomena generally flourishes due to the ignorance and fear of average computer users.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://jessehirsh.com/the-perpetual-information-war&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://jessehirsh.com/the-perpetual-information-war#comments</comments>
 <category domain="http://jessehirsh.com/category/blog-topics/analysis">Analysis</category>
 <category domain="http://jessehirsh.com/category/blog-topics/cbc">CBC</category>
 <category domain="http://jessehirsh.com/category/security">Security</category>
 <category domain="http://jessehirsh.com/category/blog-topics/television">Television</category>
 <pubDate>Sat, 15 Sep 2007 00:00:00 -0400</pubDate>
 <dc:creator>jesse</dc:creator>
 <guid isPermaLink="false">163 at http://jessehirsh.com</guid>
</item>
<item>
 <title>I got hit by a Polynomial Code Exploit!</title>
 <link>http://jessehirsh.com/i-got-hit-polynomial-code-exploit</link>
 <description>&lt;p&gt;When I got back from our &lt;a href=&quot;/thanksgiving-chicago-and-hip-hop-dead-according-nas&quot;&gt;mini-road trip to Chicago for American Thanksgiving&lt;/a&gt; I found that my windows workstation was infected with some kind of nasty malware. Initially from what I could see it was a type of rootkit that had taken over the machine and was using it to blast out spam to the world. From what I can tell neither the anti-virus nor anti-spyware software could detect it.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://jessehirsh.com/i-got-hit-polynomial-code-exploit&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://jessehirsh.com/i-got-hit-polynomial-code-exploit#comments</comments>
 <category domain="http://jessehirsh.com/category/blog-topics/analysis">Analysis</category>
 <category domain="http://jessehirsh.com/category/security">Security</category>
 <category domain="http://jessehirsh.com/category/technology">Technology</category>
 <pubDate>Tue, 28 Nov 2006 00:00:00 -0500</pubDate>
 <dc:creator>jesse</dc:creator>
 <guid isPermaLink="false">128 at http://jessehirsh.com</guid>
</item>
<item>
 <title>Chatting with Lynne Russell about Defcon 2006</title>
 <link>http://jessehirsh.com/chatting-lynne-russell-about-defcon-2006</link>
 <description>&lt;p&gt;Lynne Russell is one of my favourite news personality and it was a great thrill to be able to chat on-air with her about the 2006 Defcon conference. You might remember Lynne from CNN Headline News, she&#039;s now working for CBC Newsworld. In this segment we talk about hacking the blackberry as well as RFID vulnerabilities.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://jessehirsh.com/chatting-lynne-russell-about-defcon-2006&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://jessehirsh.com/chatting-lynne-russell-about-defcon-2006#comments</comments>
 <category domain="http://jessehirsh.com/category/blog-topics/cbc">CBC</category>
 <category domain="http://jessehirsh.com/category/security">Security</category>
 <category domain="http://jessehirsh.com/category/technology">Technology</category>
 <pubDate>Tue, 08 Aug 2006 00:00:00 -0400</pubDate>
 <dc:creator>jesse</dc:creator>
 <guid isPermaLink="false">110 at http://jessehirsh.com</guid>
</item>
</channel>
</rss>
