<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Confidential Resource &#187; Security</title>
	<atom:link href="http://www.confidentialresource.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.confidentialresource.com</link>
	<description>Sources &#38; Methods for the Investigator</description>
	<lastBuildDate>Fri, 10 Feb 2012 12:00:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Who&#8217;s Watching &amp; Listening</title>
		<link>http://www.confidentialresource.com/2012/02/06/whos-watching-listening/</link>
		<comments>http://www.confidentialresource.com/2012/02/06/whos-watching-listening/#comments</comments>
		<pubDate>Mon, 06 Feb 2012 12:00:51 +0000</pubDate>
		<dc:creator>Richard McEachin</dc:creator>
				<category><![CDATA[Methods]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Private Investigator]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Surveillance]]></category>

		<guid isPermaLink="false">http://www.confidentialresource.com/?p=3697</guid>
		<description><![CDATA[You never know who is watching. Please note that if you are Investigating someone inside your own company, and using the company network to search the Internet, at least use the encrypted search sites.  However, it is becoming more common for large companies to insert an inline HTTPS proxy in the network to  read and [...]]]></description>
			<content:encoded><![CDATA[<p>You never know who is watching. Please note that if you are Investigating someone inside your own company, and using the company network to search the Internet, at least use the encrypted search sites.  However, it is becoming more common for large companies to insert an inline HTTPS proxy in the network to  read and analyze this traffic by creating a man-in-the-middle. You can&#8217;t be sure that your investigation won&#8217;t be compromised because someone sees what you are searching and then tells the wrong person.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.confidentialresource.com/2012/02/06/whos-watching-listening/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Remote File Handling</title>
		<link>http://www.confidentialresource.com/2012/01/30/remote-file-handling/</link>
		<comments>http://www.confidentialresource.com/2012/01/30/remote-file-handling/#comments</comments>
		<pubDate>Mon, 30 Jan 2012 12:00:07 +0000</pubDate>
		<dc:creator>Richard McEachin</dc:creator>
				<category><![CDATA[Dirty Tricks]]></category>
		<category><![CDATA[Due Diligence]]></category>
		<category><![CDATA[Methods]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.confidentialresource.com/?p=3652</guid>
		<description><![CDATA[High Risk Files When doing IIR, I often come across files that I don&#8217;t want to handle for security reasons. These can be Word documents, PDF documents, PostScript, or even Gzipped PostScript files. These file may include a load of malicious code. I sometimes don&#8217;t want any record of viewing the file on my computer. [...]]]></description>
			<content:encoded><![CDATA[<h2>High Risk Files</h2>
<p>When doing IIR, I often come across files that I don&#8217;t want to handle for security reasons. These can be Word documents, PDF documents, PostScript, or even Gzipped PostScript files. These file may include a load of malicious code. I sometimes don&#8217;t want any record of viewing the file on my computer. To accomplish this I must load these files remotely and safely so they don&#8217;t touch your system (the web cache should be disabled to accomplish a true remote viewing of the file as should the swap and home partitions, if the whole system isn&#8217;t encrypted).</p>
<p>Unless you verify each file through checksum verification (like MD5 or GPG) there&#8217;s a chance they could&#8217;ve been trojaned or the file may contain phoning home instructions or some other type of malicious feature within the file. If I don&#8217;t want to be recorded as a recipient of the file via something like <a href="http://www.confidentialresource.com/2009/07/08/where-did-this-email-come-from/" target="_blank">ReadNotify</a> then the file must be verified clear of such code or it must be viewed remotely.</p>
<h2>The Remote File Viewer</h2>
<p>I use the site at<a href="http://view.samurajdata.se/" target="_blank"> http://view.samurajdata.se/</a>. I have only used it with PDF and Word documents. PDF and Word files are transformed into single paged graphics which you may navigate through. Most of the time it works, occasionally a PDF does not load. It doesn&#8217;t require Flash and works without cookies or javascript enabled.</p>
<p>I don&#8217;t know anything about the site&#8217;s privacy policy and how that might that might affect anonymity.</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.confidentialresource.com/2012/01/30/remote-file-handling/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Clean Machine</title>
		<link>http://www.confidentialresource.com/2012/01/27/the-clean-machine/</link>
		<comments>http://www.confidentialresource.com/2012/01/27/the-clean-machine/#comments</comments>
		<pubDate>Fri, 27 Jan 2012 12:00:42 +0000</pubDate>
		<dc:creator>Richard McEachin</dc:creator>
				<category><![CDATA[Methods]]></category>
		<category><![CDATA[Power User Tips]]></category>
		<category><![CDATA[Private Investigator]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[The Investigator's Computer]]></category>
		<category><![CDATA[DBAN]]></category>

		<guid isPermaLink="false">http://www.confidentialresource.com/?p=3643</guid>
		<description><![CDATA[When doing IIR, the computers must be free of malicious code (S. 31 Canada Evidence Act). We often set aside a computer for this purpose after doing some Spring-Cleaning. But how we prepare the machine for the installation of the clean version of the OS and application software is important. We use Darik&#8217;s Boot and [...]]]></description>
			<content:encoded><![CDATA[<p>When doing IIR, the computers must be free of malicious code (<a href="http://laws-lois.justice.gc.ca/eng/acts/C-5/page-10.html" rel="noreferrer" target="_blank">S. 31 Canada Evidence Act</a>). We often set aside a computer for this purpose after doing some <a href="../2008/05/06/power-user-112-spring-cleaning/" target="_blank">Spring-Cleaning</a>. But how we prepare the machine for the installation of the clean version of the OS and application software is important.</p>
<p>We use Darik&#8217;s Boot and Nuke (&#8220;<a href="http://www.dban.org/" target="_blank">DBAN</a>&#8220;) which is a self-contained boot disk that securely wipes the hard disks of most computers. DBAN will automatically and completely delete the contents of any hard disk that it can detect, which also makes it an appropriate utility for bulk or emergency data destruction. DBAN is a means of ensuring due diligence in computer prepartation for IIR. It is also a good way to periodically clean a Microsoft Windows installation of viruses and spyware.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.confidentialresource.com/2012/01/27/the-clean-machine/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Securing Firefox &#8211; Configuration Settings</title>
		<link>http://www.confidentialresource.com/2012/01/23/securing-firefox-configuration-settings/</link>
		<comments>http://www.confidentialresource.com/2012/01/23/securing-firefox-configuration-settings/#comments</comments>
		<pubDate>Mon, 23 Jan 2012 12:00:56 +0000</pubDate>
		<dc:creator>Richard McEachin</dc:creator>
				<category><![CDATA[How to Become a Professional Private Investigator]]></category>
		<category><![CDATA[Methods]]></category>
		<category><![CDATA[Power User Tips]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Private Investigator]]></category>
		<category><![CDATA[Search Leakage]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[The Investigator's Computer]]></category>
		<category><![CDATA[Training & Education]]></category>
		<category><![CDATA[Web Worker]]></category>
		<category><![CDATA[FireFox]]></category>

		<guid isPermaLink="false">http://www.confidentialresource.com/?p=3162</guid>
		<description><![CDATA[This is about stopping the dreaded disease, Data Diarrhea. The websites you visit can leave behind a trail of data on your computer and in their server logs. All of this Data Diarrhea can identify the Investigator and this can complicate the problem he is trying to solve. Lax privacy &#38; configuration settings may also [...]]]></description>
			<content:encoded><![CDATA[<p>This is about stopping the dreaded disease, Data Diarrhea. The websites you visit can leave behind a trail of data on your computer and in their server logs. All of this Data Diarrhea can identify the Investigator and this can complicate the problem he is trying to solve. Lax privacy &amp; configuration settings may also leave the Investigator&#8217;s computer vulnerable to attack by hackers.</p>
<p>This article describes more advanced methods of customizing Mozilla applications, by editing the configuration files.</p>
<h2>about:config entries</h2>
<p><em>about:config</em> is a feature of Mozilla applications which lists application settings (known as <em>preferences</em>) that are read from the profile files <em>prefs.js</em> and<em> user.js</em>, and from application defaults. Many of these preferences are not present in the Options or Preferences dialog. Using about:config is one of several methods of modifying preferences and adding other &#8220;hidden&#8221; ones.</p>
<p>Editing the <em>user.js</em> and<em> prefs.js </em>files are an alternative method of modifying preferences and recommended for very advanced users only. Unless you need a <em>prefs.js</em> and/or <em>user.js</em> file modified for a specific purpose, you should use <em>about:config</em> instead.</p>
<p>This article refers to the Firefox V. 9 edition of the browser. These entries may have adverse effects on Thunderbird and Mozilla Suite/SeaMonkey and older versions of Firefox. These settings will affect all profiles of the browser.</p>
<p>In Firefox, type <strong>about:config</strong> in the Location Bar (address bar) and press Enter to display the list of preferences. You may get a warning page next, just click OK and move on.</p>
<p style="text-align: left;"><strong>about:config &gt; browser.display.use_document_fonts &gt; change value to 0</strong></p>
<p><strong>0</strong>: Never use document&#8217;s fonts<br />
<strong>1</strong>: Allow documents to specify fonts to use<br />
<strong>2</strong>: Always use document&#8217;s fonts (deprecated)</p>
<p>Don&#8217;t let the site access to the fonts on your computer. That grants too much access that can be abused.</p>
<p style="text-align: left;"><strong>about:config &gt; browser.sessionhistory.max_entries &gt; change value to 2</strong></p>
<p>The maximum number of pages in the browser&#8217;s session history, i.e. the maximum number of URLs you can traverse purely through the Back/Forward buttons. Default value is <strong>50</strong>.  Set it to 2 so that the site you visit can&#8217;t see where you have been during your Investigative Internet Research (IIR) assignment.</p>
<p style="text-align: left;"><strong>about:config &gt; dom.storage.enabled &gt; double click to false</strong></p>
<p>dom.storage.enabled is a mechanism allowing web pages to store information with a web browser (similar to cookies) called “client-side session and persistent storage.” Although use of session storage is subject to a user’s cookie preferences, this preference allows it to be disabled entirely.</p>
<p style="text-align: left;"><strong>about:config &gt; geo.enabled &gt; double click to false</strong></p>
<p>True is location aware browsing enabled. Default is true. You want to disable this. See <a title="http://www.mozilla.com/en-US/firefox/geolocation/" href="http://www.mozilla.com/en-US/firefox/geolocation/" rel="nofollow">http://www.mozilla.com/en-US/firefox/geolocation/</a> for details of geolocation in Firefox.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.confidentialresource.com/2012/01/23/securing-firefox-configuration-settings/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Securing Firefox &#8211; General Privacy Settings</title>
		<link>http://www.confidentialresource.com/2012/01/20/securing-firefox-general-privacy-settings/</link>
		<comments>http://www.confidentialresource.com/2012/01/20/securing-firefox-general-privacy-settings/#comments</comments>
		<pubDate>Fri, 20 Jan 2012 12:00:55 +0000</pubDate>
		<dc:creator>Richard McEachin</dc:creator>
				<category><![CDATA[How to Become a Professional Private Investigator]]></category>
		<category><![CDATA[Methods]]></category>
		<category><![CDATA[Private Investigator]]></category>
		<category><![CDATA[Search Leakage]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[The Investigator's Computer]]></category>
		<category><![CDATA[Training & Education]]></category>
		<category><![CDATA[Web Worker]]></category>
		<category><![CDATA[FireFox]]></category>

		<guid isPermaLink="false">http://www.confidentialresource.com/?p=3143</guid>
		<description><![CDATA[General Firefox Privacy Settings The basic privacy settings in general settings, are found in the options bar in Firefox 9.0 (Firefox &#62; Options &#62; Options) or for iOS, Preferences. Content: Enable block popup windows and disable Javascript when it isn&#8217;t needed. Privacy: Enable the DNT (Do-Not-Track). For History, use custom settings. &#8220;Always use private browsing [...]]]></description>
			<content:encoded><![CDATA[<h2>General Firefox Privacy Settings</h2>
<p>The basic privacy settings in general settings, are found in the options bar in Firefox 9.0 (Firefox &gt; Options &gt; Options) or for iOS, Preferences.</p>
<ol>
<li>Content: Enable block popup windows and disable Javascript when it isn&#8217;t needed.</li>
<li>Privacy: Enable the DNT (Do-Not-Track). For History, use custom settings. &#8220;Always use private browsing mode&#8221; should be enabled. &#8220;Remember my browsing history&#8221;, &#8220;Remember download history&#8221; and &#8220;Remember search and form history&#8221; should be turned off. &#8220;Accept cookies from sites&#8221;, but un-check &#8220;Accept third party cookies&#8221; as they aren&#8217;t needed often. Location bar: select &#8220;Suggest nothing&#8221;.</li>
<li>Security: Enable &#8220;Warn me when sites try to install add-ons&#8221;, &#8220;Block reported attack sites&#8221; and &#8220;Block reported web forgeries&#8221;. Under Passwords, disable &#8220;Remember passwords for sites&#8221; and use a master password.</li>
<li>Advanced &#8211; General &#8211; System Defaults: Disable &#8220;Submit crash reports and performance data&#8221;.</li>
<li>Advanced &#8211; Network &#8211; Offline Storage: Check &#8220;Override automatic cache management and limit cache to 0MB space&#8221;. Further—you can un-check &#8220;Tell me when a website asks to store data for offline storage use&#8221;.</li>
<li>Advanced &#8211; Encryption: Ensure both &#8220;Use SSL 3.0 and Use TLS 1.0&#8243; are enabled. Then click validation &gt; check &#8220;When an OCSP server connection fails, treat the certificate as invalid&#8221;.</li>
</ol>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.confidentialresource.com/2012/01/20/securing-firefox-general-privacy-settings/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Security &amp; Privacy Add-ons for Firefox</title>
		<link>http://www.confidentialresource.com/2012/01/13/security-privacy-add-ons-for-firefox/</link>
		<comments>http://www.confidentialresource.com/2012/01/13/security-privacy-add-ons-for-firefox/#comments</comments>
		<pubDate>Fri, 13 Jan 2012 12:00:25 +0000</pubDate>
		<dc:creator>Richard McEachin</dc:creator>
				<category><![CDATA[Methods]]></category>
		<category><![CDATA[Power User Tips]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Private Investigator]]></category>
		<category><![CDATA[Search Leakage]]></category>
		<category><![CDATA[Search Strategies]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[FireFox]]></category>

		<guid isPermaLink="false">http://www.confidentialresource.com/?p=3166</guid>
		<description><![CDATA[Firefox is the online researcher&#8217;s best friend. No other browser gives so much control to the user as Firefox. It is more customizable than either Google Chrome or Internet Explorer. Like any browser, you must be aware of what data you are releasing when you visit a Web site. The following add-ons help eliminate two [...]]]></description>
			<content:encoded><![CDATA[<p>Firefox is the online researcher&#8217;s best friend. No other browser gives so much control to the user as Firefox. It is more customizable than either Google Chrome or Internet Explorer.</p>
<p>Like any browser, you must be aware of what data you are releasing when you visit a Web site. The following add-ons help eliminate two serious security threats that occur when doing Investigative Internet Research (IIR).</p>
<p><a href="https://addons.mozilla.org/en-US/firefox/addon/betterprivacy/" rel="nofollow" target="_blank">BetterPrivacy</a>—This add-on is pretty basic, but a must have. BetterPrivacy deletes flash cookies (<a href="http://en.wikipedia.org/wiki/Local_shared_object" target="_blank">LSOs/SuperCookies</a>).</p>
<p><a href="http://null-byte.wonderhowto.com/blog/defend-from-keyloggers-firefox-with-keystroke-encryption-0132263/">KeyScrambler</a>—Check out <a href="http://null-byte.wonderhowto.com/blog/defend-from-keyloggers-firefox-with-keystroke-encryption-0132263/" target="_blank">Alex Long&#8217;s post</a> from Null Byte for information about what KeyScrambler is and how it works.</p>
<p>I have already written about:</p>
<ul>
<li><a href="http://noscript.net/" rel="nofollow" target="_blank">NoScript</a>— NoScript allows JavaScript, Java and other executable content to run only from trusted domains of your choice, e.g. your home-banking web site, and guards the “trust boundaries” against cross-site scripting attacks (XSS). Such a preemptive approach prevents exploitation of security vulnerabilities (known and even unknown!). This is a must-have for IIR.</li>
<li><a href="https://www.eff.org/https-everywhere" rel="nofollow" target="_blank">HTTPS Everywhere</a>—This is a must-have add-on provided by the Electronic Frontier Foundation. HTTPS Everywhere enables a secure connection on pages that have SSLCertificates.  For example, when you use Google search most people use the unencrypted version. This add-on will force Google to deploy its SSL certificate. The <a href="http://duckduckgo.com/" target="_blank">DuckDuckGo</a> (DDG) <a href="http://www.confidentialresource.com/2011/04/06/duckduckgo/" target="_blank">search engine</a> also uses a version of this.</li>
</ul>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.confidentialresource.com/2012/01/13/security-privacy-add-ons-for-firefox/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Temporary Email Addresses</title>
		<link>http://www.confidentialresource.com/2011/11/02/temporary-email-addresses/</link>
		<comments>http://www.confidentialresource.com/2011/11/02/temporary-email-addresses/#comments</comments>
		<pubDate>Wed, 02 Nov 2011 15:43:23 +0000</pubDate>
		<dc:creator>Richard McEachin</dc:creator>
				<category><![CDATA[How to Become a Professional Private Investigator]]></category>
		<category><![CDATA[Methods]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Private Investigator]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.confidentialresource.com/?p=2650</guid>
		<description><![CDATA[An email address is often required to download or activate any registration page.  Unfortunately, that email address often becomes the target of spam. Perhaps you don&#8217;t want anybody to know you have registered for use of that site.  A solution to these problems is a temporary email address. Mailinator Mailinator requires no sign-up. Send email [...]]]></description>
			<content:encoded><![CDATA[<p>An email address is often required to download or  activate any registration page.  Unfortunately, that email address often becomes the target of spam. Perhaps you don&#8217;t want anybody to know you have registered for use of that site.  A solution to these problems is a temporary email address.</p>
<h2>Mailinator</h2>
<p><a href="http://www.mailinator.com/" target="_blank">Mailinator </a>requires no sign-up. Send email to a name, and the account is created automatically. You cannot send mail from this. Visit mailinator.com and type in the email name where it says &#8220;Check your inbox!&#8221;, then click &#8220;Go!&#8221;,     and Mailinator will display the list of email waiting. there is no password.  The mailbox will only hold 10 messages at once. All attachments &#8211; pictures, binary files,     etc. &#8211; are stripped out. The mailbox doesn&#8217;t disappear on any set schedule.</p>
<p>Use this for items that don&#8217;t require a high level of security.  Create your Mailinator address using an email account only accessed via <a href="http://www.confidentialresource.com/2009/02/02/the-anonymous-investigator/" target="_blank">Tor</a> and only for signing-up to things like Mailinator.</p>
<h2>10 Minute Mail</h2>
<p>Go to <a href="http://10minutemail.com/10MinuteMail/index.html" target="_blank">10 Minute Mail</a> and copy the e-mail address to your clipboard 		and use it for registration.  Your e-mail address will expire in 10 minutes.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.confidentialresource.com/2011/11/02/temporary-email-addresses/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ChangeIP Proxy</title>
		<link>http://www.confidentialresource.com/2011/08/01/changeip-proxy/</link>
		<comments>http://www.confidentialresource.com/2011/08/01/changeip-proxy/#comments</comments>
		<pubDate>Mon, 01 Aug 2011 11:00:47 +0000</pubDate>
		<dc:creator>Richard McEachin</dc:creator>
				<category><![CDATA[Communication]]></category>
		<category><![CDATA[Methods]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Private Investigator]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ChangeIP Proxy]]></category>

		<guid isPermaLink="false">http://www.confidentialresource.com/?p=2362</guid>
		<description><![CDATA[ChangeIP, states that its Private Proxy is an encrypted change IP proxy that not only changes your IP address, but also encrypts your Internet browsing sessions to keep you safe and protected. Perhaps this is better than Zerobank, but perhaps not, I have not tried it yet.  It may offer some utility over TOR in [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.change-ip-proxy.com/index.html" target="_blank">ChangeIP</a>, states that its Private Proxy is an encrypted <strong>change IP proxy</strong> that not only <strong>changes your IP address</strong>, but also <strong>encrypts your Internet browsing</strong> sessions to keep you safe and protected.</p>
<p>Perhaps this is better than <a href="http://www.confidentialresource.com/2009/03/27/xerobank-zero-customer-service/" target="_blank">Zerobank</a>, but perhaps not, I have not tried it yet.  It may offer some utility over <a href="https://www.torproject.org/" target="_blank">TOR</a> in that it may allow viewing YouTube and similar video content, but I doubt it will offer the anonymity of TOR.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.confidentialresource.com/2011/08/01/changeip-proxy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CPIC Not Updated in a Timely Fashion</title>
		<link>http://www.confidentialresource.com/2011/06/13/cpic-not-updated-in-a-timely-fashion/</link>
		<comments>http://www.confidentialresource.com/2011/06/13/cpic-not-updated-in-a-timely-fashion/#comments</comments>
		<pubDate>Mon, 13 Jun 2011 11:00:47 +0000</pubDate>
		<dc:creator>Richard McEachin</dc:creator>
				<category><![CDATA[Canada]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Auditor-General]]></category>
		<category><![CDATA[CPIC]]></category>
		<category><![CDATA[criminal record]]></category>
		<category><![CDATA[RCMP]]></category>

		<guid isPermaLink="false">http://www.confidentialresource.com/?p=2223</guid>
		<description><![CDATA[The most recent Auditor-General report reveals some problems at the RCMP that I have suspected for years. Auditor-General reports going back to 2000 have criticized the CPIC system (see 7.86) regarding timely delivery of criminal record data. The problem we encounter most often is the backlog of criminal records that has seen the updating of [...]]]></description>
			<content:encoded><![CDATA[<p>The most recent Auditor-General report reveals some problems at the RCMP that I have suspected for years. Auditor-General <a href="http://www.oag-bvg.gc.ca/internet/English/parl_oag_200004_07_e_11194.html#0.2.2Z141Z1.HAVW4L.JMF3SF.H9" target="_blank">reports going back to 2000 have criticized the CPIC system</a> (see 7.86) regarding timely delivery of criminal record data.</p>
<p>The problem we encounter most often is the backlog of criminal records that has seen the updating of some records taking 3 years.</p>
<p>The Auditor-General estimates that the RCMP takes an average of 14 months to update an English criminal record in CPIC. The French updates take an average of 36 months. The stated goal is updating a record in 24 hours. <a href="http://www.oag-bvg.gc.ca/internet/English/parl_oag_201106_05_e_35373.html#ex9" target="_blank">Unfortunately, reality is an average time of 334 working days</a> (see 5.60).</p>
<p>At some point this is going to result in tragedy. Even more unfortunate, is the fact that the RCMP and the government is judgment-proof for this negligent behaviour. The investigation company used by employers and  their insurance companies aren&#8217;t as lucky. Even if a claim is rejected by the courts, the legal expenses may destroy the company for reporting in good faith what was on CPIC.</p>
<p>How will this play out when a sex offender is hired to work with vulnerable people. What will happen when that same offender follows his natural instincts and victimizes someone.</p>
<p>It is also conceivable that this situation will also thicken our border with the U.S.A. as  their authorities start to act upon their distrust of CPIC. Frequent border-crossers, such as truck drivers, will be subjected to additional delays. If that extends to airports we can expect more security searches, questioning, and delays.</p>
<p>The problems we see with CPIC should be a warning about all supposedly trusted and sole source systems. All such systems break-down!</p>
<p>When we are forced to trust one system, especially a critical system, and that system fails, we are all vulnerable. It doesn&#8217;t matter it is health care or CPIC, without reliable alternatives, people will be hurt.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.confidentialresource.com/2011/06/13/cpic-not-updated-in-a-timely-fashion/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Android Phone Security Risk</title>
		<link>http://www.confidentialresource.com/2011/05/17/android-phone-security-risk/</link>
		<comments>http://www.confidentialresource.com/2011/05/17/android-phone-security-risk/#comments</comments>
		<pubDate>Tue, 17 May 2011 15:28:57 +0000</pubDate>
		<dc:creator>Richard McEachin</dc:creator>
				<category><![CDATA[Communication]]></category>
		<category><![CDATA[Identity Fraud]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Android]]></category>

		<guid isPermaLink="false">http://www.confidentialresource.com/?p=2202</guid>
		<description><![CDATA[Android handsets &#8216;leak&#8217; personal data Many applications installed on Android phones interact with Google services by asking for an authentication token &#8230; Sometimes, found the researchers, these tokens are sent in plain text over wireless networks. This makes the tokens easy to spot&#8230; Armed with the token, criminals would be able to pose as a [...]]]></description>
			<content:encoded><![CDATA[<h2><a href="http://www.bbc.co.uk/news/technology-13422308" target="_blank">Android handsets &#8216;leak&#8217; personal data</a></h2>
<blockquote><p>Many applications installed on Android phones interact with Google  services by asking for an authentication token &#8230;</p>
<p>Sometimes, found the researchers, these tokens are sent in  plain text over wireless networks. This makes the tokens easy to spot&#8230;</p>
<p>Armed with the token, criminals would be able to pose as a particular user and get at their personal information.</p>
<p>Even worse, found the researchers, tokens are not bound to  particular phones or time of use so they can be used to impersonate a  handset almost anywhere.</p></blockquote>
<p>Now what might an unscrupulous person do with this? Might one be able to observe a person using his Android phone, capture the  token, then use it to find-out more about the person?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.confidentialresource.com/2011/05/17/android-phone-security-risk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

