<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-13896879</id><updated>2012-01-04T09:52:23.738+08:00</updated><category term='AATL'/><category term='criminal'/><category term='wiki'/><category term='DNS'/><category term='ATM'/><category term='circumvention'/><category term='China'/><category term='Hong Kong'/><category term='CDS'/><category term='domain name'/><category term='CA'/><category term='malware'/><category term='control point'/><category term='privacy'/><category term='VISA'/><category term='McKinsey'/><category term='analytics'/><category term='open source'/><category term='tor'/><category term='investigation'/><category term='Cyberspace'/><category term='ISP'/><category term='PISA'/><category term='wall'/><category term='social capital'/><category term='Railway'/><category term='network identification'/><category term='court'/><category term='SMS payment'/><category term='Certificates'/><category term='Online Payment'/><category term='fraud'/><category term='Adobe'/><category term='Technological Protection Measures'/><category term='WAP'/><category term='Anti-virus'/><category term='ID theft'/><category term='cyber crime'/><category term='PCI'/><category term='Digital Signature'/><category term='Internet'/><category term='web tools'/><category term='homophily'/><category term='security'/><category term='Hong Kong Post'/><category term='legislations'/><category term='TPM'/><category term='Guangdong'/><category term='justice'/><category term='newspaper'/><category term='Cyber security'/><category term='USB'/><category term='Root certificate'/><category term='ICANN'/><category term='copyright'/><category term='Firefox'/><category term='Cotent tracking'/><category term='PKI'/><category term='Symantec'/><category term='economic indicators'/><category term='wireless network'/><category term='Authentication'/><category term='POS'/><category term='RFID'/><category term='web site'/><category term='Web development'/><category term='DDOS'/><category term='P2P'/><category term='Audit'/><category term='IEEE 1667'/><category term='Credit card'/><title type='text'>Tech Risk &amp; Security</title><subtitle type='html'>Thinking threads about technology risk and human behavior.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>65</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-13896879.post-246098577561697554</id><published>2010-05-04T17:50:00.000+08:00</published><updated>2010-05-04T17:50:03.348+08:00</updated><title type='text'>Measuring Overall Effectiveness of Data Security</title><content type='html'>&lt;div style='width:425px;text-align:left'&gt;&lt;object style='margin:0px' width='425' height='355'&gt;&lt;param name='movie' value='http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=adsmay-12729657138237-phpapp02&amp;stripped_title=asia-data-security-forum' /&gt;&lt;param name='allowFullScreen' value='true'/&gt;&lt;param name='allowScriptAccess' value='always'/&gt;&lt;embed src='http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=adsmay-12729657138237-phpapp02&amp;stripped_title=asia-data-security-forum' type='application/x-shockwave-flash' allowscriptaccess='always' allowfullscreen='true' width='425' height='355'&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-246098577561697554?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/246098577561697554/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=246098577561697554&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/246098577561697554'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/246098577561697554'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2010/05/measuring-overall-effectiveness-of-data.html' title='Measuring Overall Effectiveness of Data Security'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-7386085768825342412</id><published>2009-08-30T10:20:00.009+08:00</published><updated>2009-08-30T11:37:13.415+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CA'/><category scheme='http://www.blogger.com/atom/ns#' term='PKI'/><category scheme='http://www.blogger.com/atom/ns#' term='Hong Kong Post'/><category scheme='http://www.blogger.com/atom/ns#' term='Adobe'/><category scheme='http://www.blogger.com/atom/ns#' term='AATL'/><category scheme='http://www.blogger.com/atom/ns#' term='Root certificate'/><category scheme='http://www.blogger.com/atom/ns#' term='Firefox'/><title type='text'>Root Certificate update and software design</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_TiHCHQMiJG0/SpnlpNwTb3I/AAAAAAAAAic/eTy4FR1JTFU/s1600-h/hkpost_1.jpg"&gt;&lt;img style="cursor: pointer; width: 200px; height: 136px;" src="http://3.bp.blogspot.com/_TiHCHQMiJG0/SpnlpNwTb3I/AAAAAAAAAic/eTy4FR1JTFU/s200/hkpost_1.jpg" alt="" id="BLOGGER_PHOTO_ID_5375580126473056114" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Recently, a member of &lt;a href="http://www.pisa.org.hk/"&gt;PISA&lt;/a&gt; (also called Anthony) noticed that when using HK Post office website, FireFox displayed security warning saying the digital certificate used bu HK Post is invalid.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;A detailed study by other PISA members showed that the reason HK Post (once is the root CA for HK) used their own root certificate. Root certificates are usually shipped with the browser installation and HK Post digital certificate was not included in their default software package. Hong Kong Post setup a page to teach users on how to&lt;a href="http://www.hongkongpost.gov.hk/product/download/root/index.html"&gt; add the root certificate to most used browsers &lt;/a&gt;. However, how many users know this link, willing to follow or could follow the instructions !!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;It is quite clear that currently most browsers develop and distributed by US company or US-based community. The interest of adding other root certificates is likely lower than adding new functions.  Having said that,  FireFox developers have a process to add Root Certificates to their software package, for example this link shows &lt;a href="https://wiki.mozilla.org/CA:Root_Certificate_Requests"&gt;the process for adding root certificate&lt;/a&gt;. &lt;a href="http://www.mozilla.org/projects/security/certs/pending/"&gt;In their pending lsit&lt;/a&gt;, China PRC "China Internet Network Information Center (CNNIC)", Hongkong Post and Taiwan Chunghwa Telecom (CHT)  are listed.&lt;br /&gt;Entry for HongKong post was added on 2008-10-08. However, it is interesting to see that Mozilla used their bug tracking system in their handling for Root Certificate Request from CA around the world. &lt;a href="https://bugzilla.mozilla.org/show_bug.cgi?id=408949"&gt;Look at the email trails from e-Mice ( Hong Kong PKI operator) &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The first request was submitted by HK Post Staff back in 2007 Dec and 20 months passed, it was not yet included in the latest FireFox update !! Obviously, FireFox needs to handle request from many different parties but it was a long time.&lt;br /&gt;&lt;br /&gt;Maybe, we could look at the how &lt;a href="http://www.adobe.com/security/approved-trust-list.html"&gt;Adobe do it&lt;/a&gt;. Within their design, "&lt;a href="http://www.adobe.com/security/approved-trust-list.html#supported_products"&gt;Adobe products that support the AATL&lt;/a&gt; will automatically download this file every 90 days.&lt;sup&gt;(&lt;a href="http://www.adobe.com/security/approved-trust-list.html#note1"&gt;1&lt;/a&gt;)&lt;/sup&gt; Before the contents are deposited into the client's Trusted Identity list, the AATL is verified to ensure it came from Adobe. "  The approval process may still take a lot of administration time, roots certificate updates will be 90 days. It is a lot better than waiting for a bug-fix or software release!!&lt;br /&gt;&lt;br /&gt;My comment is all comes down to good design and bad design!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-7386085768825342412?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/7386085768825342412/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=7386085768825342412&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/7386085768825342412'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/7386085768825342412'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2009/08/root-certificate-update-and-software.html' title='Root Certificate update and software design'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_TiHCHQMiJG0/SpnlpNwTb3I/AAAAAAAAAic/eTy4FR1JTFU/s72-c/hkpost_1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-5404437249247009407</id><published>2009-06-10T09:21:00.000+08:00</published><updated>2009-06-10T09:22:16.570+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Guangdong'/><category scheme='http://www.blogger.com/atom/ns#' term='Digital Signature'/><title type='text'>Mutual recognition of electronic signature certificates issued by Guangdong and Hong Kong</title><content type='html'>&lt;a href="http://www.cw.com.hk/content/hk-guangdong-sign-framework-suggestions-e-signature"&gt;http://www.cw.com.hk/content/hk-guangdong-sign-framework-suggestions-e-signature&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-5404437249247009407?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/5404437249247009407/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=5404437249247009407&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/5404437249247009407'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/5404437249247009407'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2009/06/mutual-recognition-of-electronic.html' title='Mutual recognition of electronic signature certificates issued by Guangdong and Hong Kong'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-8557208488533990798</id><published>2009-06-02T11:13:00.002+08:00</published><updated>2009-06-02T11:19:45.689+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cotent tracking'/><category scheme='http://www.blogger.com/atom/ns#' term='newspaper'/><category scheme='http://www.blogger.com/atom/ns#' term='privacy'/><title type='text'>New models on generating revenue from losing newspapers</title><content type='html'>&lt;p&gt;&lt;br /&gt;I read &lt;a href="http://www.imanet.org/technotes/stnewsb2.asp"&gt;an article &lt;/a&gt;about how a group of US newspapers plan to respond to failing revenue.&lt;br /&gt;&lt;br /&gt;1st : considered a “presentation on technology/service to track content on the Web and to extract payments from third-parties and ad networks that have appropriated newspaper content.” If other online formats are stealing your copyrighted content, make them pay for it.&lt;br /&gt;&lt;br /&gt;2nd Collecting enhanced online newspaper user data across newspaper properties and mining that data to aggressively sell target content to specific audience segments across the network.”&lt;br /&gt;&lt;br /&gt;The core tech are tracking content (1st model) or user behavior (2nd model). But it is not technology that matters. It is the law that gives the newspaper to charge or sell these data that affect its success. The copyright law enforcement is tooooo expensive compare to maybe HKD 10 for a single reference. Privacy law is too restrictive for newpapers to sell their DB.&lt;br /&gt;&lt;br /&gt;My personal opinion is that the current legal infrastructure prohibit QUALITY newpapers to profit. Internet enables instant, multi-media and around the clock FACTs reporting. But QUALITY news report need more than FACTs.&lt;br /&gt;&lt;br /&gt;Bloomberg and Reuters are the only successful company as I see it.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-8557208488533990798?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/8557208488533990798/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=8557208488533990798&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/8557208488533990798'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/8557208488533990798'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2009/06/new-models-on-generating-revenue-from.html' title='New models on generating revenue from losing newspapers'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-3578234696592653094</id><published>2009-01-30T22:01:00.001+08:00</published><updated>2009-01-30T22:03:32.956+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='open source'/><category scheme='http://www.blogger.com/atom/ns#' term='CDS'/><title type='text'>Open Source has another dimension --J.P. Morgan's CDS Analytical Engine Available as Open Source</title><content type='html'>SDA Announces Agreement to Make J.P. Morgan's CDS  Analytical Engine&lt;br /&gt;Available as Open Source; Increases Transparency in CDS Pricing&lt;br /&gt;&lt;br /&gt;At the centre of our current financial crisis is the CDS (credit default swap). ISDA is the trade association which draft standard contract for CDS.&lt;br /&gt;&lt;br /&gt;The market was unable to give a reasonable and authority price for CDS in recent months. The open source decision is to make the price of CDS more stable and being open source, each one could validate the price components (market risk, liquidity risk, credit risk, FX risk and&lt;br /&gt;others)&lt;br /&gt;&lt;br /&gt;Open source when taking a transparent perspective could help to stable a market in crisis.&lt;br /&gt;&lt;br /&gt;http://www.isda.org/press/press012909.html&lt;br /&gt;&lt;br /&gt;Antony&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-3578234696592653094?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/3578234696592653094/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=3578234696592653094&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/3578234696592653094'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/3578234696592653094'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2009/01/open-source-has-another-dimension-jp.html' title='Open Source has another dimension --J.P. Morgan&apos;s CDS Analytical Engine Available as Open Source'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-371006197430806831</id><published>2009-01-18T15:26:00.005+08:00</published><updated>2009-01-18T15:51:21.459+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Technological Protection Measures'/><category scheme='http://www.blogger.com/atom/ns#' term='circumvention'/><category scheme='http://www.blogger.com/atom/ns#' term='TPM'/><category scheme='http://www.blogger.com/atom/ns#' term='copyright'/><title type='text'>Circumvention of Technological Protection Measures</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://pisa.org.hk/publication/journal/pisa_j08.pdf"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 148px; height: 200px;" src="http://3.bp.blogspot.com/_TiHCHQMiJG0/SXLfUJXSRVI/AAAAAAAAAfw/v56YP7V_upo/s200/journal8.gif" alt="" id="BLOGGER_PHOTO_ID_5292538049317717330" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Recently, I re-organised my research article on legislation on circumvention of TPM and published in &lt;a href="http://pisa.org.hk/publication/journal/pisa_j08.pdf"&gt;PISA Journal&lt;/a&gt;. In this issue, there was an article on iSCSI Resilience and Security which is a very precise introduction for security professionals.&lt;br /&gt;&lt;br /&gt;Thanks for SC Leung's editions.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://pisa.org.hk/publication/journal/pisa_j08.pdf"&gt;&lt;br /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-371006197430806831?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/371006197430806831/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=371006197430806831&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/371006197430806831'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/371006197430806831'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2009/01/circumvention-of-technological.html' title='Circumvention of Technological Protection Measures'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_TiHCHQMiJG0/SXLfUJXSRVI/AAAAAAAAAfw/v56YP7V_upo/s72-c/journal8.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-7407730381700524208</id><published>2008-06-23T22:28:00.002+08:00</published><updated>2008-06-23T22:35:16.993+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='economic indicators'/><category scheme='http://www.blogger.com/atom/ns#' term='web site'/><category scheme='http://www.blogger.com/atom/ns#' term='analytics'/><title type='text'>Website as an economic indicators</title><content type='html'>A study was conducted to study the correlation between website usages and economy!! We now have all sorts of monitoring devices and data points that enable us to track human behavior.&lt;br /&gt;&lt;br /&gt;It is conveninet to believe some activities (like visiting a particular type of website) will affected by economy. But would this correlation substanitable ? giving the fact that the web content changes constantly and new websites are created daily?&lt;br /&gt;&lt;br /&gt;&lt;a href="http://news.bbc.co.uk/2/hi/technology/7459055.stm"&gt;http://news.bbc.co.uk/2/hi/technology/7459055.stm&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-7407730381700524208?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/7407730381700524208/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=7407730381700524208&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/7407730381700524208'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/7407730381700524208'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2008/06/website-as-economic-indicators.html' title='Website as an economic indicators'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-4716464884964214212</id><published>2008-06-23T21:01:00.005+08:00</published><updated>2008-06-23T21:35:09.340+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ICANN'/><category scheme='http://www.blogger.com/atom/ns#' term='domain name'/><title type='text'>Top-level domain name and anthropology</title><content type='html'>I read two news articles today. One on SCMP which reported that Intel hired anthropologist to study user behavior and shape their strategy. One on BBC Technology, which said ICANN plan to open up top-level domain names. The result would be that everyone could register their website name with ending ranging from .bank to .worm.&lt;br /&gt;&lt;br /&gt;They seemed unrelated but I wonder how people respond to an explosive growth top-level domain names. Top level domain names, like .com or .hk are limited and users accumulated a sense of trust after years usages. Will user trust citibank.bank more over citibank.bank ? or will user buy items from toyshop.com or toyshop.shop ?&lt;br /&gt;&lt;br /&gt;What is missing in the current Internet infrastructure, after 10 years of development, is trust? How ICANN's proposal to open up top-level domain is helping to built trust in cyberspace ? The current status of DNS is far from satisfactory and phishing attacks are launched daily exploiting this weakness. Opening up top-level domain name for private registrations will create a new zone of chaos.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-4716464884964214212?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/4716464884964214212/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=4716464884964214212&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/4716464884964214212'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/4716464884964214212'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2008/06/top-level-domain-name-and-anthropology.html' title='Top-level domain name and anthropology'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-426998154025510513</id><published>2008-06-17T23:35:00.001+08:00</published><updated>2008-06-17T23:37:45.221+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ID theft'/><title type='text'>Cost of Identity Theft</title><content type='html'>There is a blog about&lt;a href="http://blog.euclidmanagers.com/home/effects-of-identity-theft-on-individuals.html"&gt; Effects of ID theft. &lt;/a&gt;&lt;br /&gt;It is quite a good reference but the whole process of cleaning up ID theft only after you know your identity was comprised.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-426998154025510513?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/426998154025510513/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=426998154025510513&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/426998154025510513'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/426998154025510513'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2008/06/cost-of-identity-theft.html' title='Cost of Identity Theft'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-6472449262532340452</id><published>2008-06-03T22:24:00.005+08:00</published><updated>2008-06-03T22:37:10.084+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cyberspace'/><category scheme='http://www.blogger.com/atom/ns#' term='wall'/><title type='text'>Building cultural walls in Cyberspace</title><content type='html'>&lt;a href="http://www.bloomberg.com/apps/news?pid=20601109&amp;amp;sid=a0bWH.aj_ZnM&amp;amp;refer=home"&gt;An article from Bloomberg News&lt;/a&gt; discussed how Google adjusted their web services with national cultures. In Thailand, they banned YouTue to show videos which offended King Bhumibol Adulyadej. In China, Google stopped offering Gmail to Chinese Citizen to avoid government demands for messages. To be able to stop user from using a specific web services, Google must rely on the programming codes. Now these codes with geo-sensitive information are used to build walls within Cyberspace, either due to political reason or to respect the natioanl cultures. The multinational enterprise is now taking the duty to fund the building of these walls using their codes.  Cultural walls is not an entirely bad concept since a neigbhood enjoy more harmony when there are walls between them.&lt;br /&gt;&lt;br /&gt;Contrast this to &lt;a href="http://www.blogger.com/www.lessig.org"&gt;Lawrence Lessig's&lt;/a&gt; "Code wants to be free" concept, we could see that multinational enterprises were using codes to control information flow. The force to from multinational enterprises is gaining strengthen because these companies expand their influence by acquiring companies (like Google acquired YouTube and the planning integration of Yahoo &amp;amp; Microsft)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-6472449262532340452?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/6472449262532340452/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=6472449262532340452&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/6472449262532340452'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/6472449262532340452'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2008/06/building-cultural-walls-in-cyberspace.html' title='Building cultural walls in Cyberspace'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-3671727206689090698</id><published>2008-05-28T13:27:00.004+08:00</published><updated>2008-05-28T13:43:42.508+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ISP'/><category scheme='http://www.blogger.com/atom/ns#' term='cyber crime'/><category scheme='http://www.blogger.com/atom/ns#' term='investigation'/><title type='text'>ISP guideline on Cybercrime investigation released</title><content type='html'>I wrote about &lt;a href="http://www.blogger.com/techrisk.blogspot.com/2006/08/us-senate-approval-of-council-of.html#links"&gt;US Senate's approval of Council of Europe Cybercrime Convention &lt;/a&gt;. Recently, the Cybercrime Committee of Council of Europe released a guideline on how ISP and law enforcement agencies should cooperate in cybercrime investigations.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.coe.int/t/dg1/legalcooperation/economiccrime/cybercrime/cy%20activity%20Interface2008/567_prov-d-guidelines_provisional2_3April2008_en.pdf"&gt;Guidelines for law enforcement - service provider cooperation (adopted on 2 April 2008)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;From this document, it could be see that there is a large gap between law enforcement and ISP on obtaining evidences. Both sides need to formalise their procedures (either request or giving evidences). If there is no force from the government or other external factor, I could see no reason for them to incur additional resource in this process.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-3671727206689090698?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/3671727206689090698/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=3671727206689090698&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/3671727206689090698'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/3671727206689090698'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2008/05/isp-guideline-on-cybercrime.html' title='ISP guideline on Cybercrime investigation released'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-4849400926677521773</id><published>2008-05-27T23:42:00.004+08:00</published><updated>2008-05-28T00:34:22.030+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='PISA'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Coming PISA events</title><content type='html'>I have been busy with my LLM study at The Hong Kong University in the past year. All goes well, I will graduate this year. The course I took covers Telecommunication, Cybercrime and IP. Will share about all these topic in the coming posts.&lt;br /&gt;&lt;br /&gt;First, &lt;a href="http://www.pisa.org.hk"&gt;PISA&lt;/a&gt; will has several events in pipeline.&lt;br /&gt;Today, we just finished an Oracle Security Seminar&lt;br /&gt;On 31 May, there will be &lt;a href="http://pisa.org.hk/event/Data%20protection.html"&gt;Data Protection Public Forum&lt;/a&gt;. Speakers from ISACA, ISOC and Privacy Commissioner will share their view on &lt;a href="http://www.news.gov.hk/en/category/lawandorder/080527/html/080527en08002.htm"&gt;recent incidence on data breaches&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Then on 5 June, PISA invited Aloysius Cheang (Head of Security Services for Cable&amp;amp;Wireless Asia-Pacific) to share his experience on malware detections and preventions.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-4849400926677521773?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/4849400926677521773/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=4849400926677521773&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/4849400926677521773'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/4849400926677521773'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2008/05/coming-pisa-events.html' title='Coming PISA events'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-5592832407475228464</id><published>2008-02-21T09:36:00.004+08:00</published><updated>2008-02-21T09:50:37.476+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='homophily'/><category scheme='http://www.blogger.com/atom/ns#' term='social capital'/><title type='text'>homophily part II - Social Capital</title><content type='html'>Below are some extracts from NY Times Blog&lt;br /&gt;&lt;a href="http://freakonomics.blogs.nytimes.com/2008/02/15/is-myspace-good-for-society-a-freakonomics-quorum/"&gt;http://freakonomics.blogs.nytimes.com/2008/02/15/is-myspace-good-for-society-a-freakonomics-quorum/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;"social capital", a concept that describes the benefits individuals receive from their relationships with others.&lt;br /&gt;&lt;br /&gt;Bridging social capital reflects the benefits we receive from our "weak ties" — people we don't know very well but who provide us with useful information and ideas.&lt;br /&gt;&lt;br /&gt;As our social networks are becoming increasingly more geographically fragmented, social network sites are a useful way for us to keep in touch and seek social contact with our friends.&lt;br /&gt;&lt;br /&gt;When many students begin university, they find themselves with a group of ready-made acquaintances. Given people’s preferences for people who are like them, it could be that friendship networks become increasingly homogeneous. Is this a bad thing? It might be if, by choosing potential friends via their Facebook profiles, it means that folk cut themselves off from serendipitous encounters with those who are superficially different from them.&lt;br /&gt;&lt;br /&gt;Social networking sites are affecting the labor market as well, because recruiters evaluating young professionals applying for jobs are now hacking into applicants’ profiles, and making hiring decisions based on profile photos in which applicants are drunk or inappropriately dressed.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;they devalue the meaning of “friend.” Our traditional notion of friendship embraces trust, support, compatible values, etc. On social network sites, a “friend” may simply be someone on whose link you have clicked.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-5592832407475228464?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/5592832407475228464/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=5592832407475228464&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/5592832407475228464'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/5592832407475228464'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2008/02/homophily-part-ii-social-capital.html' title='homophily part II - Social Capital'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-3031691000887805334</id><published>2007-08-19T16:51:00.000+08:00</published><updated>2007-08-19T17:14:59.820+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='network identification'/><category scheme='http://www.blogger.com/atom/ns#' term='wiki'/><category scheme='http://www.blogger.com/atom/ns#' term='tor'/><title type='text'>Anonymous network will be popular</title><content type='html'>There is &lt;a href="http://news.independent.co.uk/sci_tech/article2874112.ece"&gt;a sad but true story&lt;/a&gt; that corporate-PR "corrected" wikipedia pages in order to downplay the mistakes done by company and government organizations. Some of the "corrections" may be a true account of history but there are deliberate censorship.&lt;br /&gt;&lt;br /&gt;Most people think the network address (IP address) are useless and could not reveal the location or identity of individuals. However, most IP address is similar to telephone number and could be traced to specific organizations. This traceability enabled Wikiscanner (mentioned in the article) to find the editor of wiki.&lt;br /&gt;&lt;br /&gt;There are some anonymous networks like &lt;a href="http://tor.eff.org/"&gt;Tor&lt;/a&gt; for people to conceal their identity. I believe the PR will continue their censorship on wikipedia with these anonymous networks.&lt;br /&gt;&lt;br /&gt;It is sad that when truth is the battlefield between individual and large organisations.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-3031691000887805334?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/3031691000887805334/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=3031691000887805334&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/3031691000887805334'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/3031691000887805334'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2007/08/anonymous-network-will-be-popular.html' title='Anonymous network will be popular'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-6860003571554467582</id><published>2007-07-03T21:59:00.000+08:00</published><updated>2007-07-03T22:10:19.167+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='court'/><category scheme='http://www.blogger.com/atom/ns#' term='justice'/><title type='text'>"science may be the main determinant of how a case is resolved"</title><content type='html'>The gap between law and science is ever widening. In the past, the court is a place for justice but now justice is bury among scientific experiments and mathematical calculations.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.usatoday.com/tech/science/ethics/2007-07-02-judges-filter-fake-science_N.htm"&gt;&lt;span class="inside-head"&gt;Judges trained to filter fake science from USA Today&lt;/span&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-6860003571554467582?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/6860003571554467582/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=6860003571554467582&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/6860003571554467582'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/6860003571554467582'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2007/07/science-may-be-main-determinant-of-how.html' title='&quot;science may be the main determinant of how a case is resolved&quot;'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-4203613898738136748</id><published>2007-07-01T10:52:00.000+08:00</published><updated>2007-07-01T11:06:54.474+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Credit card'/><category scheme='http://www.blogger.com/atom/ns#' term='Hong Kong'/><category scheme='http://www.blogger.com/atom/ns#' term='cyber crime'/><category scheme='http://www.blogger.com/atom/ns#' term='wireless network'/><category scheme='http://www.blogger.com/atom/ns#' term='fraud'/><title type='text'>Stealing credit card numbers via home Wifi network</title><content type='html'>The Hong Kong district court heard a computer crime case on 18th June 2007. An African visitor had rented a flat and stole credit card numbers from his neighbor using wireless sniffing, then he used the credit card information to do online shopping. The charge was brought under HK Crime Ordinance &lt;a href="http://www.hklii.org/hk/legis/en/ord/200/s161.html"&gt;Chapter 200 s116 &lt;/a&gt;. More detailed information will be available when the judgment is posted online.&lt;br /&gt;&lt;br /&gt;The 23-year old defendant was caught since he had used his home address for online shopping and the police were able to trace the delivery records. His ignorance of fraud detection systems and traceability of online shopping transactions seems to suggest that he is not a professional criminal. There are lots of ways to use stolen credit card numbers, buying cash coupons and delivering to an unoccupied house's mail box are common.&lt;br /&gt;&lt;br /&gt;According to&lt;a href="http://www.epaynews.com/statistics/fraud.html"&gt; statistics &lt;/a&gt; , credit card fraudis increasing and costs 3 billion USD in 2006, up from 2.7 billion in 2005. Different measures (like adding chips or using an online password) are introduced to protect credit card transactions. However, these new measures are not effective if the network layer is circumvented.&lt;br /&gt;&lt;br /&gt;When a malicious user has installed hacker tools on a network, the protection mechanism on the online application layer may not work at all. &lt;a href="http://en.wikipedia.org/wiki/Man_in_the_middle_attack"&gt;Man-in-the-middle attacks &lt;/a&gt;using fake servers to intercept Internet traffic were the most dangerous.Traditionally, to set up a man-in-the-middle attack or eavesdropping network traffic, the hacker needs to have access to the victim's physical network. However, with the availability of a wireless  network, this physical constraint is no longer an obstacle. If the victim uses a non-encrypted wireless network (According to 2006 &lt;a href="http://www.pisa.org.hk/projects/wlan2005/wd2005full.pdf"&gt;PISA wireless survey&lt;/a&gt;, 45% of wireless networks were not encrypted ), it is relatively easy to obtain his Internet traffic and the personal information transmitted (credit card information being included).&lt;br /&gt;&lt;br /&gt;If the wireless network is not encrypted and users uses it to carry out online transactions or send credit card number via  email, there is a high risk of stolen credit card information just like the criminal cases described above. If 45% of individually established access points in Hong Kong are not encrypted, what are the percentages of users having wireless security knowledge or awareness?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-4203613898738136748?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/4203613898738136748/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=4203613898738136748&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/4203613898738136748'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/4203613898738136748'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2007/07/stealing-credit-card-numbers-via-home.html' title='Stealing credit card numbers via home Wifi network'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-877769098168050836</id><published>2007-06-19T20:22:00.000+08:00</published><updated>2007-06-19T20:26:48.056+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DDOS'/><category scheme='http://www.blogger.com/atom/ns#' term='Cyber security'/><title type='text'>DDOS attacks are getting more frequent</title><content type='html'>On 7 June, there was a reported case of a &lt;a href="http://www.eweek.com/article2/0,1895,2143566,00.asp"&gt;successful botnet Distributed Denial of Services DDOS &lt;/a&gt;attack. This type of attack was difficult to prevent since current technology could only divert the traffic after the attack has been launched. Due to the fact that the sources of attack are highly distributed, we could never monitor nor stop the DDOS attack. Once the attack is launched, the affected system will be unable to response to normal users. &lt;br /&gt;&lt;br /&gt;DDOS attacks are real and there were even reported cases on &lt;a href="http://www.bloomberg.com/apps/news?pid=20601085&amp;sid=abGseMma5MjU&amp;amp;refer=europe"&gt;DDOS against a national body Estonia&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;The scary thing about DDOS is the growing number of botnet . With the higher penetration of broadband internet, more computers will be connecting to the Internet 24x7. If the management of these computers is not done securely, they will be a breading ground for botnets and viruses. One area to pay special notice to is the growing trend of networked devices. Vetting machines, CD juke boxes and other everyday electronic devices are likely to be connecting to the Internet within the next 3 to 5 years. These devices will have a slim OS, but able to carry-out basic network activities, like ping and HTTP GET command. The sheer amount of these network devices will be a problem if the OS is not hardened.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-877769098168050836?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/877769098168050836/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=877769098168050836&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/877769098168050836'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/877769098168050836'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2007/06/ddos-attacks-are-getting-more-frequent.html' title='DDOS attacks are getting more frequent'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-1976042578724126137</id><published>2007-06-19T11:02:00.000+08:00</published><updated>2007-06-19T11:19:21.128+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Web development'/><category scheme='http://www.blogger.com/atom/ns#' term='web tools'/><title type='text'>Catch up with the Web</title><content type='html'>I saw an article on Yahoo news about "25 Web Sites to Watch " and the web advanced so rapidly that one could never be able to catch up. I grouped some of the web sites according to their features.&lt;br /&gt;&lt;br /&gt;One thing I noticed is that the web is getting specialised and each website is good doing one particular domain. This fragmented development is the result of a distributed web but in history every development will eventually reverse its course.&lt;br /&gt;&lt;br /&gt;" speculated that the Internet will become, in essence, a vast operating system"&lt;br /&gt;&lt;ol&gt;&lt;li&gt; &lt;a href="http://www.popfly.com/" rel="nofollow"&gt;Popfly&lt;/a&gt; &lt;/li&gt;&lt;li&gt; &lt;a href="http://pipes.yahoo.com/" rel="nofollow"&gt;Yahoo Pipes&lt;/a&gt;&lt;/li&gt;&lt;li&gt; &lt;a href="http://www.goowy.com/" rel="nofollow"&gt;Goowy&lt;/a&gt;&lt;/li&gt;&lt;/ol&gt;Data/Opinion Site&lt;br /&gt;&lt;ol&gt;&lt;li&gt; &lt;a href="http://buzzdash.com/" rel="nofollow"&gt;BuzzDash&lt;/a&gt;  &lt;/li&gt;&lt;li&gt; &lt;a href="http://www.swivel.com/" rel="nofollow"&gt;Swivel&lt;/a&gt;&lt;/li&gt;&lt;/ol&gt;Multimedia Web creation tools&lt;br /&gt;&lt;ol&gt;&lt;li&gt; &lt;a href="http://www.splashcastmedia.com/" rel="nofollow"&gt;SplashCast&lt;/a&gt;&lt;/li&gt;&lt;li&gt; &lt;a href="http://www.squidoo.com/" rel="nofollow"&gt;Squidoo&lt;/a&gt; &lt;/li&gt;&lt;li&gt; &lt;a href="http://www.yodio.com/" rel="nofollow"&gt;Yodio&lt;/a&gt; &lt;/li&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-1976042578724126137?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/1976042578724126137/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=1976042578724126137&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/1976042578724126137'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/1976042578724126137'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2007/06/catch-up-with-web.html' title='Catch up with the Web'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-4993825211636360110</id><published>2007-05-29T09:01:00.000+08:00</published><updated>2007-05-29T09:13:30.221+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Guangdong'/><category scheme='http://www.blogger.com/atom/ns#' term='WAP'/><title type='text'>WAP Volumn in China</title><content type='html'>China Internet Network Information Centre released a survey result on the current usage of WAP in China. As of March 2007, there were 39M WAP (Wireless Acccess Protocol) users, about 28% of fixed Internet population in China.&lt;br /&gt;&lt;br /&gt;Not too surprising, Guangdong Province has the large WAP population.&lt;br /&gt;&lt;br /&gt;The report summary could be find &lt;a href="http://www.ce.cn/cysc/tech/szbg/200705/15/t20070515_11362909.shtml"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-4993825211636360110?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/4993825211636360110/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=4993825211636360110&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/4993825211636360110'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/4993825211636360110'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2007/05/wap-volumn-in-china.html' title='WAP Volumn in China'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-7901979208613186538</id><published>2007-05-28T14:57:00.000+08:00</published><updated>2007-05-28T15:04:36.268+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='P2P'/><category scheme='http://www.blogger.com/atom/ns#' term='copyright'/><category scheme='http://www.blogger.com/atom/ns#' term='Hong Kong'/><category scheme='http://www.blogger.com/atom/ns#' term='criminal'/><title type='text'>Transfer files on P2P is an offence in Hong Kong</title><content type='html'>The legal battle on BitTorrent cases reached an end on 18 May 2007 and the full judgement released on &lt;a href="http://www.hklii.hk/hk/jud/en/hkcfa/2007/FACC000003_2007-57111.html"&gt;Hong Kong Legal Information Institute&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;On 12 Jan 2005, officers from HKSAR Custom Department raided thedefendant's (Mr. Chan) home after tracking his address from an online forum. Mr. Chan he had uploaded 3 .torrent files on 10 Jan 2005 and 11 Jan 2005 to the forum and these enabled BT users to download copies ofmovies. In first instance, Mr. Chan was charged by virtue of section118(1)(f) of the Copyright Ordinance, Cap 528 and of obtaining access to a computer with dishonest intent, contrary to section 161(1) (c) ofthe Crimes Ordinance, Cap 200. But in the final judgement in the Court of Final Appeal, the 5 judges unanimously dismissed Mr Chan appeal andhe was convicted of 118(1)(f) of the Copyright Ordinance only.&lt;br /&gt;&lt;br /&gt;This was a high profiled case and the HKSAR government launched propaganda on their determination on combating the copyright battle. Since charges was brought to the court in 2005, the number of BT seeds decreased in Hong Kong. It was a success and a few points must clarify.&lt;br /&gt;&lt;br /&gt;First, back in 2005 the prosecution charged Mr. Chan with "obtaining access to a computer with dishonest intent". This charge was totally wrong and stimulated &lt;a href="http://www.hk-lawyer.com/2005-5/ITPrac.pdf"&gt;many critics &lt;/a&gt;on the legal ground ofthis copyright case. Mr Chan was using his own computer to store andupload BT files. There was no hacking or illegal access on thecomputer he owned. By bring this charges, the prosecution misused the law and most ridiculously was that the judge agreed this charges. In the Court of Final Appeal, both the prosecution and judges corrected this mistake.&lt;br /&gt;&lt;br /&gt;Second, the criminal offence from section 118(1)(f) of the CopyrightOrdinance was enacted before peer-to-peer ever existed and yet this section was able to catch distributing infringed copies via BTnetwork. The major argument by the defendant was that the detail mechanism of P2P does not constitute "distributing" since Mr. Chan was passively waiting owner to locate the media files and there were nophysical medium exchanged, only electronic currents. The judgesdisagreed and said if (1) the infringing copies were created by thedefendant and (2) his action enabled others to obtain the infringingcopies (in any way technologies allows and with full knowledge), then the defendant's action falls into the definition of "distribution"under Copyright Ordinance.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-7901979208613186538?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/7901979208613186538/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=7901979208613186538&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/7901979208613186538'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/7901979208613186538'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2007/05/transfer-files-on-p2p-is-offence-in.html' title='Transfer files on P2P is an offence in Hong Kong'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-683432540632377054</id><published>2007-05-21T08:51:00.000+08:00</published><updated>2007-05-21T08:52:49.181+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Anti-virus'/><category scheme='http://www.blogger.com/atom/ns#' term='China'/><category scheme='http://www.blogger.com/atom/ns#' term='Symantec'/><category scheme='http://www.blogger.com/atom/ns#' term='control point'/><title type='text'>Control points missed in Symantec</title><content type='html'>&lt;p&gt;This morning I heard astounding news about Symantec. It released a faulty virus definition that deleted (or quarantined) two essential files on Windows XP (Simplified Chinese Version). The result was that around 3 millions computers were unable to start and must restore the deleted files from the original Microsoft installation CD.  SANS and Sina confirmed this news. They claimed that only people who downloaded the updates from the Symantec China webpage between 01:00 a.m. and  02:30 p.m. on May 18th  AND have MS06-070 installed on their computer were affected.&lt;/p&gt;&lt;p&gt;This incident has many implications. The one that worries me the most is that people will try to download these files on the web in order to repair their computers. The integrity of these files is in question (if they do not come from an authenticated source). A malicious hacker may plant a virus or backdoor in these system files and offer them in discussion groups.  As an auditor, I always think of process control. There are actually two control points within the release process of a virus definition. The first one is the approval and verification process for adding a system file to their blacklist. System files are high- risk files since they impact the whole system, instead of a single application. The second control point is the testing of the definition before publishing to the public. Does Symantec test all their definitions with all versions of OS? It is an extremely challenging and costly task to release timely virus definitions and, at the same time, to have all OS versions tested (different languages, times, services packs). Although it is a costly testing process, the risk is too great to ignore. &lt;/p&gt;&lt;p&gt;There is always a lesson to be learned from mistakes. Hopefully, the whole anti-virus industry will benefit from Symantec's mistakes.  &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-683432540632377054?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/683432540632377054/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=683432540632377054&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/683432540632377054'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/683432540632377054'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2007/05/control-points-missed-in-symantec.html' title='Control points missed in Symantec'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-8921406536496963684</id><published>2007-05-03T13:16:00.000+08:00</published><updated>2007-05-07T09:00:14.568+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='McKinsey'/><category scheme='http://www.blogger.com/atom/ns#' term='China'/><category scheme='http://www.blogger.com/atom/ns#' term='ATM'/><category scheme='http://www.blogger.com/atom/ns#' term='SMS payment'/><category scheme='http://www.blogger.com/atom/ns#' term='POS'/><title type='text'>The root of China SMS-based Payment</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/_TiHCHQMiJG0/Rj55zY-g8eI/AAAAAAAAAAk/8A9SnUIeUz4/s1600-h/root.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5061616954995962338" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 109px; CURSOR: hand; HEIGHT: 133px" height="172" alt="" src="http://2.bp.blogspot.com/_TiHCHQMiJG0/Rj55zY-g8eI/AAAAAAAAAAk/8A9SnUIeUz4/s200/root.JPG" width="131" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;McKinsey recently &lt;a href="http://www.mckinseyquarterly.com/article_abstract.aspx?ar=2002&amp;l2=22&amp;amp;l3=77&amp;srid=17&amp;amp;gp=0"&gt;released an article on the prospect of a SMS-basedpayment system &lt;/a&gt;in China rural area. The arguments were that China has a low level of non-cash payments when compared to other countries and the Chinese government is keen to develop non-cash payments in order to simulaterural spending. There are both economical and political reasons to have an efficient rural payment system.&lt;br /&gt;&lt;br /&gt;I agree with the article's contention that ATM and POS are not the right products for Chinese farmers. The main reason is cost. While the annual income of the averagefarmer in China is below USD 2000, it is relatively costly to acquire and maintain an ATM or POS, which usually costs more than USD 20000. Apart from cost, there is also a trend in other countries of declining rates of ATM adoption. According to the &lt;a href="http://www.interac.org/en_n2_32_researchfacts.html"&gt;BIS statistics&lt;/a&gt;, the number of automated banking machines per million inhabitants decreased by 1123 in the year 2000to 1069 in 2005.&lt;br /&gt;&lt;br /&gt;However, the picture portrayed by McKinsey seems to be of the distant future. The &lt;a href="www.chinaunionpay.com"&gt;China Union Pay website &lt;/a&gt;reports that there are 86000 ATM and 608000POS installed. In 2005 alone, the transaction volume was more than five billion RMB (USD 670 M). However, there are only 14 cities in China enabled with mobile payment and with only 2.7 million users.&lt;br /&gt;&lt;br /&gt;One major type of money flow in rural China areas is the money transfer from workers in urban cities. Urban city like ShangHai and ShenZhen attract millions of farmer who go to work there and their wages are usually"carried or transferred" back to the villages. This type of transaction is the root of many rural payments. So, the critical success factor may not be in the branches of payments in rural areas, but inthe root of most payments, which is in the cities.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-8921406536496963684?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/8921406536496963684/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=8921406536496963684&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/8921406536496963684'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/8921406536496963684'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2007/05/root-of-china-sms-based-payment.html' title='The root of China SMS-based Payment'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_TiHCHQMiJG0/Rj55zY-g8eI/AAAAAAAAAAk/8A9SnUIeUz4/s72-c/root.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-842907133656917804</id><published>2007-05-02T20:08:00.000+08:00</published><updated>2007-05-02T21:09:46.228+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CA'/><category scheme='http://www.blogger.com/atom/ns#' term='China'/><category scheme='http://www.blogger.com/atom/ns#' term='Online Payment'/><category scheme='http://www.blogger.com/atom/ns#' term='VISA'/><category scheme='http://www.blogger.com/atom/ns#' term='Certificates'/><title type='text'>CFCA -- the China next payment infrastruture</title><content type='html'>There was a news about 16 China Banks released a press release about a coordination &lt;a href="http://big5.ce.cn/gate/big5/finance.ce.cn/dissertation/bank/wy/tt/200704/27/t20070427_11189159.shtml"&gt;framewrok between banks against online fraud (網上銀行反欺詐聯動機制)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The banks will share their fraud information with &lt;a href="http://www.cfca.com.cn/"&gt;China Financial Certification Authority CFCA, &lt;/a&gt;which was found by the banks in year 2000. CFCA is a certificate authority (i.e. a PKI service provider) and from &lt;a href="http://www.chinatechnews.com/2005/11/21/3042-25-banks-begin-adopting-digital-certificates/"&gt;ChinaTechNew.com&lt;/a&gt; 25 banks uses their certificates in 2005.&lt;br /&gt;&lt;br /&gt;If this alliance is successful and continues its development, I think CFCA has the potential to be the center of China payment network. A secure PKI is important, especially for using client-side authentications. When the banks establish a cross-banks PKI process and agreements, the payment network may function a bit like VISA in plastic card business. For China, the development and innovations are unlimited.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-842907133656917804?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/842907133656917804/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=842907133656917804&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/842907133656917804'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/842907133656917804'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2007/05/cfca-china-next-payment-infrastruture.html' title='CFCA -- the China next payment infrastruture'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-6849453519554344153</id><published>2007-05-01T22:08:00.000+08:00</published><updated>2007-05-01T22:16:32.437+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='legislations'/><category scheme='http://www.blogger.com/atom/ns#' term='Internet'/><title type='text'>Internet Law -- A US testmonial</title><content type='html'>When we talk about Cyberspace, we usually think of US. Partly due to there technology innovations and partly due to their obsession about Internet. Then it is not surprise to know US has many legislations on regulating the Internet and citizens' cyber-activities. &lt;br /&gt;&lt;br /&gt;Below is an snapshot of the status of Internet regulations in US and quite interesting.&lt;br /&gt;&lt;a href="http://www.imanet.org/technotes/stnewsb.asp"&gt;http://www.imanet.org/technotes/stnewsb.asp&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-6849453519554344153?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/6849453519554344153/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=6849453519554344153&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/6849453519554344153'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/6849453519554344153'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2007/05/internet-law-us-testmonial.html' title='Internet Law -- A US testmonial'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-3013446501579610949</id><published>2007-04-29T21:48:00.000+08:00</published><updated>2007-04-29T21:53:11.155+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='copyright'/><category scheme='http://www.blogger.com/atom/ns#' term='Hong Kong'/><category scheme='http://www.blogger.com/atom/ns#' term='legislations'/><title type='text'>When there is no choice .. ...</title><content type='html'>I joined a &lt;a href="http://www.sinchungkai.org.hk/demo/eng/meet_with_voter/event_DA_Forum.html"&gt;discussion forum&lt;/a&gt; oragnised by Legislator CK SIn on 26 Apr at HKPC where a group of industry leaders are invited to express their view on Hong Kong Government consultation paper on new copyright legislations.&lt;br /&gt;&lt;br /&gt;The speakers concentrated on two major themes:&lt;br /&gt;1 Criminalisation of infringing downloading&lt;br /&gt;2 Requiring ISP to keep IP-to-Physical Address records&lt;br /&gt;&lt;br /&gt;One important discussion item was that almost everyone acknowledged the fact that a viable business model is needed for substantial development of online contents. But when there is no widely adopted business model, legislations are considered necessary.  &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;PISA is monitoring these developments and will submit our views to the government.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-3013446501579610949?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/3013446501579610949/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=3013446501579610949&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/3013446501579610949'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/3013446501579610949'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2007/04/when-there-is-no-choice.html' title='When there is no choice .. ...'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-1195407347192347809</id><published>2007-04-21T15:14:00.000+08:00</published><updated>2007-04-21T15:22:05.088+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Authentication'/><category scheme='http://www.blogger.com/atom/ns#' term='USB'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='IEEE 1667'/><title type='text'>IEEE 1667</title><content type='html'>The IEEE is working on a standard for USB and other flash authentications. The new protocol is a standardization on how a USB disk could authenticate against a computer. That is how you could limit which portable disk to be able to store your data. It is a long-waited protocol and is vital for protection against data-theft.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.computer.org/portal/site/computer/index.jsp?pageID=computer_level1_article&amp;TheCat=1060&amp;amp;path=computer/homepage/April07&amp;file=security.xml&amp;amp;xsl=article.xsl"&gt;&lt;span style="text-decoration: underline;"&gt;Authentication in Transient Storage Device Attachments&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The standard will be published in June 2007&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-1195407347192347809?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/1195407347192347809/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=1195407347192347809&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/1195407347192347809'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/1195407347192347809'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2007/04/ieee-1667.html' title='IEEE 1667'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-6807204138945899122</id><published>2007-04-15T23:22:00.000+08:00</published><updated>2007-04-16T00:03:05.345+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='China'/><category scheme='http://www.blogger.com/atom/ns#' term='Railway'/><category scheme='http://www.blogger.com/atom/ns#' term='RFID'/><title type='text'>RFID ticket in China</title><content type='html'>I saw some puzzling situations when I traveled to GuangZhou (southern China) this weekend. &lt;a href="http://www.gsrc.com/en/index.jsp"&gt;GuangShen Railway&lt;/a&gt; installed a RFID ticketing system and all tickets are embedded with a electronic circuit (photo 1). RFID application on train ticket is quite advance. In last winter,I traveled to UK and Sweden but did not see any RFID application in transportation system (even airlines).&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_TiHCHQMiJG0/RiJG5Bymy9I/AAAAAAAAAAU/trGeKyMoULo/s1600-h/0414_134301.jpg"&gt;&lt;br /&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 234px; height: 254px;" src="http://3.bp.blogspot.com/_TiHCHQMiJG0/RiJG5Bymy9I/AAAAAAAAAAU/trGeKyMoULo/s320/0414_134301.jpg" alt="photo1" id="BLOGGER_PHOTO_ID_5053679677410298834" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;What puzzling me is the ticket-checking in Photo 2. You could see there are two railway staff standing behind a gate to check passengers ticket. The narrow opening is to prevent people from passing the gate. Except the tickets embedded with a electronic circuit, very little has changed. The railway staff still need to validate passenger's ticket one by one. When a few hundred passengers passing through the small gate, one can image the chaos it created!&lt;br /&gt;&lt;p&gt;&lt;br /&gt;&lt;br /&gt;China being late in infrastructure investment projects are applying advance technologies but this example shows that the benefit of technology may not be realized.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_TiHCHQMiJG0/RiJJxhymy-I/AAAAAAAAAAc/9nuzsOoUBK0/s1600-h/0414_204152.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 238px; height: 240px;" src="http://1.bp.blogspot.com/_TiHCHQMiJG0/RiJJxhymy-I/AAAAAAAAAAc/9nuzsOoUBK0/s320/0414_204152.png" alt="" id="BLOGGER_PHOTO_ID_5053682847096163298" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Another puzzling issue is why do they need a RFID ticket for a one hour journey where 99% of passengers do not check-in their luggages !!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-6807204138945899122?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/6807204138945899122/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=6807204138945899122&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/6807204138945899122'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/6807204138945899122'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2007/04/rfid-ticket-in-china.html' title='RFID ticket in China'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_TiHCHQMiJG0/RiJG5Bymy9I/AAAAAAAAAAU/trGeKyMoULo/s72-c/0414_134301.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-549268567325740970</id><published>2007-04-13T14:10:00.000+08:00</published><updated>2007-04-19T22:41:29.371+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Credit card'/><category scheme='http://www.blogger.com/atom/ns#' term='Audit'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='PCI'/><title type='text'>PCI Industry standard audit checklist</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/_TiHCHQMiJG0/Rh8fnRymy8I/AAAAAAAAAAM/LUcOyJt0I4k/s1600-h/PCI_cover_small.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5052792066584005570" style="margin: 0px 10px 10px 0px; float: left;" alt="" src="http://1.bp.blogspot.com/_TiHCHQMiJG0/Rh8fnRymy8I/AAAAAAAAAAM/LUcOyJt0I4k/s320/PCI_cover_small.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;IT Compliance Institute just released &lt;a href="http://www.itcinstitute.com/display.aspx?id=2499"&gt;PCI Industry standard audit checklist&lt;/a&gt;. It also include a self-assessment questionniare. &lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-549268567325740970?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/549268567325740970/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=549268567325740970&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/549268567325740970'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/549268567325740970'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2007/04/pci-industry-standard-audit-checklist.html' title='PCI Industry standard audit checklist'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_TiHCHQMiJG0/Rh8fnRymy8I/AAAAAAAAAAM/LUcOyJt0I4k/s72-c/PCI_cover_small.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-8563207524559734303</id><published>2007-03-18T20:03:00.000+08:00</published><updated>2007-03-18T20:36:28.381+08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DNS'/><category scheme='http://www.blogger.com/atom/ns#' term='Hong Kong'/><title type='text'>Poorly regulated DNS services</title><content type='html'>For most of the telecom service (from dial-up, broadband, network TV), the services are regulated by country government. Consumers depend on the government to ensure proper operation of telecom services since these services affect a large scope of the society and the services are very technical.&lt;br /&gt;&lt;br /&gt;However, domain-name registrars are poorly regulated according &lt;a href="http://www.businessweek.com/magazine/content/07_13/b4027077.htm?chan=rss_topStories_ssi_5"&gt;Business-Week.&lt;/a&gt; Not that government-regulation must be good; it could be self-regulated (like the industry-associations). The current state of DNS is worrying.&lt;br /&gt;&lt;br /&gt;This phenomena is not unique in US. In HK, &lt;a href="https://www.hkdnr.hk/company_info/abouthkirc_hkdnr.jsp"&gt;Hong Kong Internet Registration Corporation Limited&lt;/a&gt; is also a commercial organisation but the government sent one senior official to sit on its broad.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-8563207524559734303?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/8563207524559734303/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=8563207524559734303&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/8563207524559734303'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/8563207524559734303'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2007/03/poorly-regulated-dns-services.html' title='Poorly regulated DNS services'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-4031728443221701699</id><published>2007-02-24T18:47:00.000+08:00</published><updated>2007-02-24T18:54:54.303+08:00</updated><title type='text'>User education is missing !</title><content type='html'>The reports on China as a centre of Cybercrime and SPAM is appearing. In this Western media article, cybercrime problem is associated with use counterfeit software ! I think more importantly is that the user educations is weak.&lt;br /&gt;The OGCIO has radio drama to teach HK people to protect against phising and other online risk. But do we have similar radio broadcast or media attentions in China! Is there a government division work on user educations!!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.businessweek.com/globalbiz/content/feb2007/gb20070221_774722.htm?link_position=link2"&gt;http://www.businessweek.com/globalbiz/content/feb2007/gb20070221_774722.htm?link_position=link2&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-4031728443221701699?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/4031728443221701699/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=4031728443221701699&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/4031728443221701699'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/4031728443221701699'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2007/02/user-education-is-missing.html' title='User education is missing !'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-116912477101629233</id><published>2007-01-18T20:36:00.000+08:00</published><updated>2007-01-18T20:52:51.036+08:00</updated><title type='text'>Anti-Online Game Addiction System implemeted in China (country-wide)</title><content type='html'>I am not in the online game industry and not sure about the statistics about online game addiction. But China government is serious about stopping online game to become a social problem.&lt;br /&gt;&lt;br /&gt;According the Chinese article below, a country-wide anti online game addiction system will go live in Jan 2007.  The system will monitor user activity in RPG games. When a user spend more than 3 hours per day playing games, their gaming-scores will reduced to 50%. All online game company will need to modify their system to enable the monitoring.&lt;br /&gt;&lt;br /&gt;China is not leak of innovation when it comes to online monitoring and controls.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.ce.cn/cysc/tech/yw/200701/18/t20070118_10130593.shtml"&gt;http://www.ce.cn/cysc/tech/yw/200701/18/t20070118_10130593.shtml&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-116912477101629233?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/116912477101629233/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=116912477101629233&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/116912477101629233'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/116912477101629233'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2007/01/anti-online-game-addiction-system.html' title='Anti-Online Game Addiction System implemeted in China (country-wide)'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-116821814983022868</id><published>2007-01-08T08:58:00.000+08:00</published><updated>2007-01-08T09:02:29.843+08:00</updated><title type='text'>Internet Blackout Seminar @ PISA</title><content type='html'>2 weeks after the earthquake strike Taiwan, Hong Kong is still suffering slow internet surfing, although 70% of website is not accessible.&lt;br /&gt;&lt;br /&gt;To understand the impact of this event to our society, PISA organized a seminar and invite industry experts.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pisa.org.hk/event/internet-blackout-2006.htm"&gt;Panel Discussion: Internet Blackout - Lesson Learned from Large Scale Network Disruption &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Date 20-Jan-2007 (Sat)&lt;br /&gt;Time 2:00pm - 5:00pm&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-116821814983022868?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/116821814983022868/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=116821814983022868&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/116821814983022868'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/116821814983022868'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2007/01/internet-blackout-seminar-pisa.html' title='Internet Blackout Seminar @ PISA'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-116727170270136743</id><published>2006-12-28T09:01:00.000+08:00</published><updated>2006-12-28T10:14:51.280+08:00</updated><title type='text'>Undersea cable damage bring an issue of operantion risk in Basel</title><content type='html'>The earthquake stoke southern Taiwan on 26 Dec caused a major disruption of &lt;a href="www.info.gov.hk/gia/general/200612/27/P200612270198.htm"&gt;network communication in Hong Kong&lt;/a&gt;. It is believed that several cable connecting Taiwan, Japan and US were damaged and the restoration will take days.&lt;br /&gt;&lt;br /&gt;As banks and stocker brokers rely heavily on electronic settlement and straight though system, their operation are affected. Especially cross country trading, i.e. accepting oversea order to be executed in Hong Kong Exchange and at the same time, placing order to the US market. One of my broker in HK informed me that they will not be able to accept buy order until the network is restored (sell order is possible since they will execute instruction with telephone).&lt;br /&gt;&lt;br /&gt;The real issue is with STP system, there is a timeout value for each data transmissions and the timeout value is usually set to a reasonable time under normal network connections. The system may retry after timeout but the number of retry will only create more traffic on an already congested network.&lt;br /&gt;&lt;br /&gt;There are many issues with this kind of disruptions but I like concentrate on the &lt;a href="www.info.gov.hk/hkma/eng/bank/spma/attach/OR-1.pdf"&gt;operation risk&lt;/a&gt; of Basel. Banks intended to use the Advanced Measurement Approach  (AMA) will need to calculate their regulatory requirement as the sum of expected loss (EL) and unexpected loss (UL). In order to do accurately calculate, the bank must track relevant event linked to their operations, technology process and settlements are one of them.&lt;br /&gt;&lt;br /&gt;Network disruption due to services provider unable to meet SLA may be classified as one loss. But it is not the biggest one. I am thinking of the sudden increase of manual settlements and the inability of pricing provider to provide accurate pricing.&lt;br /&gt;&lt;br /&gt;It will be a lesson for regulators and banks to learn how AMA of operation risk will work under extraordinary conditions. The lesson is not finished yet as the network connections will not restore to normal for a few days .&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-116727170270136743?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/116727170270136743/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=116727170270136743&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/116727170270136743'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/116727170270136743'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2006/12/undersea-cable-damage-bring-issue-of.html' title='Undersea cable damage bring an issue of operantion risk in Basel'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-116663202881868583</id><published>2006-12-21T00:14:00.000+08:00</published><updated>2006-12-21T00:27:08.863+08:00</updated><title type='text'>Latest developments in digital media distribution</title><content type='html'>These two days a bunch of news related to the digital media distribution appears across the globe. These news seems unrelated and did not go to the frontpage but their total effect will shape our future and the economy.&lt;br /&gt;&lt;br /&gt;Companies are committed to protect and capitalize their intellectual properties. An regulations is one of the way.&lt;br /&gt;&lt;a href="http://news.bbc.co.uk/2/hi/technology/6194929.stm"&gt;&lt;br /&gt;Sony BMG settles suit over CDs &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://news.bbc.co.uk/2/hi/technology/6194929.stm"&gt;BBC moves to file-sharing sites &lt;/a&gt;&lt;br /&gt;&lt;a href="http://news.bbc.co.uk/2/hi/technology/6194929.stm"&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.citb.gov.hk/cib/ehtml/pdf/consultation/Consultation_document.pdf"&gt;The HKSAR Government CITB announced yesterday the following consultation paper which discussed a lot of Internet related copyright issues. &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-116663202881868583?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/116663202881868583/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=116663202881868583&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/116663202881868583'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/116663202881868583'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2006/12/latest-developments-in-digital-media.html' title='Latest developments in digital media distribution'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-116520059696274890</id><published>2006-12-04T10:45:00.000+08:00</published><updated>2006-12-04T10:49:56.993+08:00</updated><title type='text'>UK banned DOS</title><content type='html'>I wrote an article in &lt;a href="http://www.pisa.org.hk/publication/journal/index.htm"&gt;PISA Journal &lt;/a&gt;about UK proposed legislation in banning Denial of Services (DOS). Last week UK enacted a law of similarnature, you can read the comments and full legislation below.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.theregister.com/2006/11/12/uk_bans_denial_of_service_attacks/"&gt;UK enacted Police And Justice Act  2006&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The definition of a criminal offence is broad and includes "hinder access" !&lt;br /&gt;"(a) to impair the operation of any computer,&lt;br /&gt;(b) to prevent or hinder access to any program or data held in any computer, or&lt;br /&gt;(c) to impair the operation of any such program or the reliability ofany such data,"&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-116520059696274890?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/116520059696274890/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=116520059696274890&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/116520059696274890'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/116520059696274890'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2006/12/uk-banned-dos.html' title='UK banned DOS'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-116372685674015902</id><published>2006-11-17T09:18:00.000+08:00</published><updated>2006-11-17T09:27:36.756+08:00</updated><title type='text'>US Release guidance data discovery in civil litigation.</title><content type='html'>There are many discussions/articles on the web about the US Federal Rules of Civil Procedure (FRCP) Rule 26, 33, or 34.&lt;br /&gt;&lt;br /&gt;Below is a good summary. The rule set a 90 days period for lawyers of both parties to agree what needs to be prepared for the court. After this 90-days period, any data discovery request will likely be rejected by US court.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.itcinstitute.com/display.aspx?id=2616"&gt;New E-discovery Rules &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-116372685674015902?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/116372685674015902/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=116372685674015902&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/116372685674015902'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/116372685674015902'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2006/11/us-release-guidance-data-discovery-in.html' title='US Release guidance data discovery in civil litigation.'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-116342756504294790</id><published>2006-11-13T22:18:00.000+08:00</published><updated>2006-11-13T22:21:20.440+08:00</updated><title type='text'>Cybersecurity Workshop at Singapore</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/blogger/4692/1240/1600/koji_net_mon.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://photos1.blogger.com/blogger/4692/1240/320/koji_net_mon.png" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;p&gt;I attended a Cybersecurity on 31 Oct and 1 Nov and the presentations are available online now. &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.itsc.org.sg/downloads/presentations.html" target="_blank"&gt;http://www.itsc.org.sg/downloa&lt;wbr&gt;ds/presentations.html&lt;/a&gt;&lt;span style="font-family:verdana;"&gt;.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;The presentation from Koji on Monitoring Cyber Attacks showed many 3D visualization of attack patterns. &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-116342756504294790?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/116342756504294790/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=116342756504294790&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/116342756504294790'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/116342756504294790'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2006/11/cybersecurity-workshop-at-singapore.html' title='Cybersecurity Workshop at Singapore'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-116322143391529812</id><published>2006-11-11T12:59:00.000+08:00</published><updated>2006-11-11T13:03:53.936+08:00</updated><title type='text'>A New Blog</title><content type='html'>&lt;span style="font-family: verdana;"&gt;I have been quiet in the Blogsphere since I was busy with &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.din.de/ni/sc27/"&gt;ISO SC27&lt;/a&gt;&lt;span style="font-family: verdana;"&gt; activities and also PISA.&lt;br /&gt;&lt;br /&gt;PISA has a new blog created for discussion of local IT security matters.&lt;br /&gt;Take a look at &lt;/span&gt;&lt;a href="http://pisa-security.blogspot.com/" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)"&gt;http://pisa-security.blogspot&lt;wbr&gt;.com/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-116322143391529812?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/116322143391529812/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=116322143391529812&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/116322143391529812'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/116322143391529812'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2006/11/new-blog.html' title='A New Blog'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-115665427099535606</id><published>2006-08-27T12:20:00.000+08:00</published><updated>2006-08-27T12:51:36.886+08:00</updated><title type='text'>Spammers manipulate stock markets</title><content type='html'>A news appear in BBC technology section and it is another trend that changed the unguarded world. Some people still believe email is an authenticated way of communication and trust the message it carries.  But most email we received today are sent by machines! &lt;br /&gt;&lt;br /&gt;&lt;a href="http://news.bbc.co.uk/2/hi/technology/5284618.stm"&gt;E-mails typically promote penny shares in the hope of convincing people to buy into a company to raise its price. People who respond to the "pump and dump" scam can lose 8% of their investment in two days.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-115665427099535606?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/115665427099535606/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=115665427099535606&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/115665427099535606'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/115665427099535606'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2006/08/spammers-manipulate-stock-markets.html' title='Spammers manipulate stock markets'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-115553301237406786</id><published>2006-08-14T13:09:00.000+08:00</published><updated>2006-08-15T13:26:22.273+08:00</updated><title type='text'>US Senate approval of Council of Europe Cybercrime</title><content type='html'>I have been following the news about US Senate approval of Council of Europe Cybercrime Treaty. It is a milestone in both Internet law enforcement and Internet Governance. The most comprehensive article about this development was by &lt;a href="http://www.zdnetasia.com/news/security/0,39044215,39380399,00.htm"&gt;ZDnet Asia&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;There are a lot of Bloggers discussing how Americans is affected by this Cybercrime Treaty. From this blogs, I found most negative comments are worries out of ignorance. Their comments do not quote or make reference to the Treaty, most of the time are just suspicions.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Treaty Article 19 – Search and seizure of stored computer data&lt;/b&gt;, US government may establish new provisions to seize individual data. But there are already lots of other American laws giving US government the right to do so. The Treaty only specifies the principles and each country is required to implement their own procedures.&lt;br /&gt;&lt;br /&gt;Below are some comments from the Blogsphere :&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;a href="http://www.orinkerr.com/2006/08/07/senate-ratifies-cybercrime-treaty/"&gt;entirely symbolic&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://libertycafe.blogspot.com/2006/08/senator-lugar-subjects-americans-to.html"&gt;expand Big Government powers&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://yro.slashdot.org/article.pl?sid=06/08/04/2243249&amp;from=rss"&gt;American ISPs would be obliged to obey other jurisdictions' requests&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.gcn.com/online/vol1_no1/41579-1.html?topic=security&amp;amp;CMP=OTC-RSS"&gt;to obtain assistance from other countries in the investigation &lt;/a&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-115553301237406786?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/115553301237406786/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=115553301237406786&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/115553301237406786'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/115553301237406786'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2006/08/us-senate-approval-of-council-of.html' title='US Senate approval of Council of Europe Cybercrime'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-115243683090337492</id><published>2006-07-09T17:13:00.000+08:00</published><updated>2006-07-09T17:26:41.786+08:00</updated><title type='text'>Unsolicited Electronic Messages Bill</title><content type='html'>&lt;ol&gt;&lt;li&gt;&lt;a href="http://photos1.blogger.com/blogger/4692/1240/1600/address-book-new.png"&gt;&lt;img style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" height="53" alt="" src="http://photos1.blogger.com/blogger/4692/1240/320/address-book-new.png" width="55" border="0" /&gt;&lt;/a&gt;Hong Kong after months of public consultations is proposing an &lt;a href="http://www.legco.gov.hk/yr05-06/english/bills/brief/b35_brf.pdf"&gt;Unsolicited Electronic Messages Bill. &lt;/a&gt;This proposed bill has the following major features:&lt;br /&gt;1. Enforce Opt-out (One needs to check before sending)&lt;br /&gt;2. Technology Neutral (cover SMS, FAX and Email)&lt;br /&gt;3. Prohibit address harvesting&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Generally, HK Government's effort is appreciated and the bill is comprehensive. There is not loophole the drafted bill does not quite get it.&lt;br /&gt;Under this bill, government propose to empower the Telecommunications Authority (TA) to set up "do-not-call registers", "which would be to facilitate recipients to opt out from receiving further commercial electronic messages from all electronic marketers and for senders of commercial electronic messages to ascertain the electronic addresses to which they should not send further commercial electronic messages unless they have specific consents. "This kind of register is very likely to be abused by malicious person to validate email addresses. To address this potential abuse, "We propose to make it an offence for an electronic marketer using those information from the TA for any purpose other than for ascertaining whether a registered user of an electronic address does not wish to receive unsolicited commercial electronic messages"&lt;br /&gt;&lt;/span&gt;&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;span style="font-family:arial;"&gt;Criminalizing this act seems to be effective at first glance. But if you consider 90% of spam are not HK-originated, the new offence is meaningless, at least 90% of the time.&lt;br /&gt;&lt;br /&gt;I think the Telecommunications Authority should have strict rules on how the public access "do-not-call registers". At least the person accessing this "do-not-call registers" should have a valid business registration number or ID card number.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="http://www.caslon.com.au/donotcallnote2.htm"&gt;&lt;span style="font-family:arial;"&gt;More information on how Australia is doing can be found here.&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-115243683090337492?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/115243683090337492/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=115243683090337492&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/115243683090337492'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/115243683090337492'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2006/07/unsolicited-electronic-messages-bill.html' title='Unsolicited Electronic Messages Bill'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-115190401181623646</id><published>2006-07-03T13:12:00.000+08:00</published><updated>2006-07-03T13:26:22.940+08:00</updated><title type='text'>National firewall weakness</title><content type='html'>&lt;p&gt;A member from PISA posted an article on how the China Firewall works and how to circumvent it. Basically, there is one weakness of China national firewall that the web hosting company could exploit. &lt;/p&gt;&lt;p&gt;This is another example of "Technology wants to be free". &lt;/p&gt;&lt;p&gt;================================================&lt;/p&gt;&lt;p&gt;Abstract. The so-called "Great Firewall of China" operates, in part,by inspecting TCP packets for keywords that are to be blocked. If thekeyword is present, TCP reset packets (viz: with the RST ag set) aresent to both endpoints of the connection, which then close. However,because the original packets are passed through the rewall unscathed,if the endpoints completely ignore the rewall's resets, then theconnection will proceed unhindered.&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.cl.cam.ac.uk/~rnc1/ignoring.pdf" target="_blank"&gt;http://www.cl.cam.ac.uk/~rnc1/ignoring.pdf&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-115190401181623646?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/115190401181623646/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=115190401181623646&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/115190401181623646'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/115190401181623646'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2006/07/national-firewall-weakness.html' title='National firewall weakness'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-115021089483181494</id><published>2006-06-13T22:40:00.000+08:00</published><updated>2006-06-13T23:01:35.813+08:00</updated><title type='text'>Another War in the technology standard</title><content type='html'>&lt;p class="MsoNormal"&gt;IEEE was and is affecting everyone by defining how bit and bytes transmit.  Without a standard, no two machines could talk to each other. &lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="inside-copy"&gt;In the past, US company were pioneer of technology standard and they were the only voice in standard setting committees. Now &lt;st1:country-region st="on"&gt;&lt;st1:place st="on"&gt;China&lt;/st1:place&gt;&lt;/st1:country-region&gt; wants to play the game and proposed WAPI standard. However, &lt;a href="http://www.usatoday.com/tech/news/2006-06-11-china-encryption_x.htm?csp=34"&gt;“In March, delegates representing standard bodies from 25 countries voted in favor of the IEEE's version over WAPI.China appealed the &lt;st1:stockticker st="on"&gt;ISO&lt;/st1:stockticker&gt; decision and demanded an apology from the IEEE which it accused of "dirty tricks" in lobbying for its standard, Xinhua said.”&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;I am glad to see &lt;st1:country-region st="on"&gt;&lt;st1:place st="on"&gt;China&lt;/st1:place&gt;&lt;/st1:country-region&gt; government is actively protecting national manufacturers (although most of them are still state-owned) by going to international forum like IEEE. If IEEE does not adopt China-backed WAPI, I believe &lt;st1:country-region st="on"&gt;&lt;st1:place st="on"&gt;China&lt;/st1:place&gt;&lt;/st1:country-region&gt; will not step down. There will be two standards for wireless transmission. Just like &lt;st1:place st="on"&gt;&lt;st1:country-region st="on"&gt;Japan&lt;/st1:country-region&gt;&lt;/st1:place&gt; has their &lt;st1:stockticker st="on"&gt;PHS&lt;/st1:stockticker&gt; mobile phone system. &lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-115021089483181494?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/115021089483181494/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=115021089483181494&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/115021089483181494'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/115021089483181494'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2006/06/another-war-in-technology-standard.html' title='Another War in the technology standard'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-114956884480453117</id><published>2006-06-06T11:57:00.000+08:00</published><updated>2006-06-06T12:40:44.850+08:00</updated><title type='text'>A blackhole in Cyber Law Enforcement</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/blogger/4692/1240/1600/glbk021.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://photos1.blogger.com/blogger/4692/1240/200/glbk021.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://software.silicon.com/malware/0,3800003100,39159282,00.htm"&gt;Local Police is not investigating the reported ransomware case as it &lt;st1:stockticker st="on"&gt;MAY&lt;/st1:stockticker&gt; fall in the remit of the National High Tech Crime Unit (NHTCU), which was amalgamated into the Serious and Organised Crime Agency (Soca) in April.&lt;/a&gt;    &lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;After reading this news article, I have no clue when or who will investigate this case. It seems in &lt;st1:country-region st="on"&gt;&lt;st1:place st="on"&gt;UK&lt;/st1:place&gt;&lt;/st1:country-region&gt; the law enforcement have not keep up with cyber crime. The local police said it is international crime and they do not have resources to investigate. The Soca seems only investigate large and organized crimes. &lt;/p&gt;            &lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;So when a crime involves international transactions and not organized, citizen in &lt;st1:country-region st="on"&gt;&lt;st1:place st="on"&gt;UK&lt;/st1:place&gt;&lt;/st1:country-region&gt; does not have any protection from their government even they report it to police. I believe what happens in &lt;st1:country-region st="on"&gt;&lt;st1:place st="on"&gt;UK&lt;/st1:place&gt;&lt;/st1:country-region&gt; is similar to elsewhere in the world. Police forces are not ready or willing to surf the wave of cybercrime.&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;The resource to investigate is huge. There may be some wrongly reported cases. The legislation and prosecution is difficult. All are the reasons that police feel powerless.&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;The issue revealed by the article is alarming as this un-patrolled area of cybercrime is definitely growing. &lt;span style=""&gt; &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-114956884480453117?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/114956884480453117/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=114956884480453117&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/114956884480453117'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/114956884480453117'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2006/06/blackhole-in-cyber-law-enforcement.html' title='A blackhole in Cyber Law Enforcement'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-114946305198585860</id><published>2006-06-05T07:02:00.000+08:00</published><updated>2006-06-05T07:17:31.996+08:00</updated><title type='text'>Anti-Ransomware</title><content type='html'>A counter-action of last blog :&lt;br /&gt;&lt;a href="http://www.boingboing.net/2006/06/01/ransomware_viruss_pa.html"&gt;The password for unlocking hijacked-files by Ransomware are widely available online now.  &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;One nature of encryption is that there is a one-to-one match of general used encryption softwares/tools. When a hacker distribute his ransomware to the victim, there is one key for encrypting files. There is also one key to unlock these files.&lt;br /&gt;&lt;br /&gt;Each release of ransomware will share the same unlocking key and this is the weakness of ransomware. When the password is publicly available, the ransomware is useless.&lt;br /&gt;&lt;br /&gt;However, there maybe multiple releases with different keys. In such case, the hacker will need to keep track of which key corresponding which release. The logistics maybe overwhleming.&lt;br /&gt;&lt;br /&gt;One direction of development is there is a pattern of generating keys (like using a master key and the username, ip address or computer service patch number). Then the variant of keys of each releases will be multiplied.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-114946305198585860?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/114946305198585860/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=114946305198585860&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/114946305198585860'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/114946305198585860'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2006/06/anti-ransomware.html' title='Anti-Ransomware'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-114911838840328215</id><published>2006-06-01T07:30:00.000+08:00</published><updated>2006-06-01T07:33:08.443+08:00</updated><title type='text'>Another case of computer crime</title><content type='html'>From BBC&lt;br /&gt;&lt;a href="http://news.bbc.co.uk/2/hi/uk_news/england/manchester/5034384.stm"&gt;&lt;span style="font-size:85%;"&gt;&lt;b&gt;A woman from Greater Manchester has become a victim of an internet scam in which hackers hijack computer files and blackmail owners to get them back.&lt;/b&gt;&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Do anyone have a glue on how to translate ransomware in Chinese ?&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-114911838840328215?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/114911838840328215/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=114911838840328215&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/114911838840328215'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/114911838840328215'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2006/06/another-case-of-computer-crime.html' title='Another case of computer crime'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-114890812385814709</id><published>2006-05-29T20:17:00.000+08:00</published><updated>2006-05-29T21:17:23.140+08:00</updated><title type='text'>US data retention law  (to be)</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/blogger/4692/1240/1600/monitor.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://photos1.blogger.com/blogger/4692/1240/320/monitor.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://news.zdnet.com/2100-1009_22-6077654.html?part=rss&amp;tag=feed&amp;amp;subj=zdnn"&gt;U.S. Attorney General said Internet service providers should retain subscriber information and network data for two years. &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Previously, I blogged about China's legislation on keeping user Internet-activity by ISP. Now US is going the same direction. When I was skeptical about Chinese government uses of IP address log, US government is doing it in the name of child pornography .&lt;br /&gt;I am more concern about the possible uses of these IP address. In &lt;a href="http://asia.news.yahoo.com/060509/afp/060509171218hightech.html"&gt;HK &lt;/a&gt;and &lt;a href="http://www.riaj.or.jp/e/whatsnew/20041116.html"&gt;Japan&lt;/a&gt;, cases has been brought by music companies to request ISPs to disclose IP address logs and their correspondents. These information was used for copyright infringements.&lt;br /&gt;&lt;br /&gt;Once the detail user activity is kept. The uses of it will be unlimited and it is scary. There is nothing wrong for music company to sue for infringements. But if music company could use these logs, what will stop someone to bring civil cases against you and request ISP to disclose your internet activity. Recently, &lt;a href="http://www.hkeaa.edu.hk/doc/isd/press20060519_eng.pdf"&gt;the Hong Kong Examination Authority used web server logs to investigate reported cheating cases.&lt;/a&gt;(PDF)&lt;br /&gt;&lt;br /&gt;When log are kept for good reason, the use of it must also be good reason.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-114890812385814709?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/114890812385814709/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=114890812385814709&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/114890812385814709'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/114890812385814709'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2006/05/us-data-retention-law-to-be.html' title='US data retention law  (to be)'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-114791658053502957</id><published>2006-05-18T09:37:00.000+08:00</published><updated>2006-05-18T23:31:41.020+08:00</updated><title type='text'>One source of poverty</title><content type='html'>&lt;a href="http://biz.yahoo.com/bizj/060517/1289680.html?.v=2"&gt;&lt;span style="font-family:arial;"&gt;A study focused on the effects of Wal-Mart stores on poverty rates found that an estimated 20,000 families nationwide have fallen below the official poverty line as a result of the chain's expansion.&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;Although I have not read the whole report nor the article confirmed the research method is scientific, I agree with the author that "found that one of the greatest effects of a Wal-Mart opening is the closing of mom-and-pop-type operations."&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:Arial;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-114791658053502957?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/114791658053502957/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=114791658053502957&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/114791658053502957'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/114791658053502957'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2006/05/one-source-of-poverty.html' title='One source of poverty'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-114697693262845946</id><published>2006-05-07T12:31:00.000+08:00</published><updated>2006-05-07T12:42:13.486+08:00</updated><title type='text'>Promoting Chinese using Internet</title><content type='html'>BBC posted a new on China government is &lt;a href="http://news.bbc.co.uk/chinese/simp/low/newsid_4960000/newsid_4961400/4961432.stm"&gt;promoting Chinese using the Internet&lt;/a&gt;. Chinese is getting more attentions now.&lt;br /&gt;&lt;br /&gt;This brings me to think the process I learn English. Reading storybooks was the major part of it. Animal Farm , The Tale of Two Cities and Sophia were those I read. Those books were written not for learning English as a second language but they are interesting even after centuries.&lt;br /&gt;&lt;br /&gt;Chinese has some great storybooks too and I hope these books will enable people to understand Chinese culture. I am interested in knowing which books or stories will China government uses to educate Chinese to the world.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-114697693262845946?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/114697693262845946/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=114697693262845946&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/114697693262845946'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/114697693262845946'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2006/05/promoting-chinese-using-internet.html' title='Promoting Chinese using Internet'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-114665931067050003</id><published>2006-05-03T20:27:00.000+08:00</published><updated>2006-05-06T22:16:36.113+08:00</updated><title type='text'>IP address logging has many faces</title><content type='html'>A council question on whether IP should be treated as Personal Data as defined in &lt;a href="http://www.hklii.hk/hk/legis/en/ord/486/s2.html"&gt;Section 2&lt;/a&gt; of Personal Data (Privacy) Ordiance was asked by &lt;a href="http://www.sinchungkai.org.hk/"&gt;CK Sin&lt;/a&gt;. This issue was raised because Yahoo Hong Kong gave Internet usage information to China official and resulted in &lt;a href="http://news.com.com/2061-10811_3-6056498.html"&gt;some arrestments&lt;/a&gt; in China.&lt;br /&gt;&lt;br /&gt;In reading the reply from government, I notice that government official referred to EU Directives but not China’s Law despite the fact that both EU and China adopt civil law legal system and HK is common law. I believe it is the intuitive reaction for HK government official to look for guidance from EU on privacy matters and it is this intuitive distinguish HK from other China cities. How will HK change to more like China cities or China cities changes to more like HK? I am not totally sure.&lt;br /&gt;&lt;br /&gt;Back to the real issue. I always think absolute anonymity is a fake concept in the Internet since each and every bytes transferred can be recorded with little incremental cost. ISPs have both the ability and capacity to record every IP address used by their customer. Logging may be for good reasons like troubleshooting or security or for surveillance. No one knows how the log will be used after it is stored. Regulation on this area is needed, not only in Hong Kong.&lt;br /&gt;&lt;br /&gt;Apart from Human Right and censorship, I recently finished Cyber Regulation course at &lt;a href="http://www.hku.hk"&gt;HKU&lt;/a&gt; Law Faculty and our lecturer &lt;a href="http://www3.hku.hk/law/staffHomepage.php?id=56"&gt;Maurushat Alana&lt;/a&gt; discussed another aspect of IP surveillance. Due to the emerging of Digital Right Managements (DRM) in the entertainment industry, many software is developed to control and monitor user usage of music or movie. Monitoring devices will sometimes log the IP addresses, data/time and OS platform information. There is a danger for DRM software recording and sending information silently to the entertainment companies. One day, some government officials may request Sony Music or Warner Brothers to provide Internet activity report for criminal or activists.&lt;br /&gt;&lt;br /&gt;The issue of IP address logging and privacy is just a start of how Internet governance that will affect everyone life.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-114665931067050003?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/114665931067050003/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=114665931067050003&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/114665931067050003'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/114665931067050003'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2006/05/ip-address-logging-has-many-faces.html' title='IP address logging has many faces'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-114645785198406697</id><published>2006-05-01T12:06:00.000+08:00</published><updated>2006-05-01T12:33:06.690+08:00</updated><title type='text'>Ransom, the 21th centrury story</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/blogger/4692/1240/1600/ransomware.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://photos1.blogger.com/blogger/4692/1240/320/ransomware.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&lt;br /&gt;&lt;br /&gt;Two ransomware cases were reported recently, both involved a Trojan control access to computer. The trend of cybersecurity is going from phishing to ransomware and it is alarming as these ransomware will cause real damages.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pcworld.com/news/article/0,aid,125108,00.asp"&gt;16 March PCworld &lt;/a&gt;&lt;br /&gt;&lt;a href="http://news.yahoo.com/s/pcworld/20060427/tc_pcworld/125569;_ylt=AsWFmCPq6jiuSvjUD922ersOSLMF;_ylu=X3oDMTA5aHJvMDdwBHNlYwN5bmNhdA--"&gt;27 April  Yahoo News &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;As I am working in a bank, I notice that both cases relied on money transfer company(Western Uinion &amp;amp; e-Gold) for their operations. The convenient e-payment infrastructure is one of the factors for this type security incidence. The Torjan instructed victims to deposit money via this money transfer company and their computer/file will be unlocked. If the criminals are able to open a large amount of money transfer account for large scale operation, it will be a real danger to the Internet.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-114645785198406697?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/114645785198406697/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=114645785198406697&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/114645785198406697'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/114645785198406697'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2006/05/ransom-21th-centrury-story.html' title='Ransom, the 21th centrury story'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-114337914775713279</id><published>2006-03-26T20:47:00.000+08:00</published><updated>2006-03-26T21:19:07.790+08:00</updated><title type='text'>China Internet Security Law and WTO!?</title><content type='html'>&lt;p class="MsoNormal"&gt;&lt;br /&gt;There is a new Law effective in &lt;st1:country-region st="on"&gt;&lt;st1:place st="on"&gt;China&lt;/st1:place&gt;&lt;/st1:country-region&gt; being 1 March 2006.&lt;br /&gt;A brief outline is here http://news.xinhuanet.com/it/2005-12/29/content_3986087.htm&lt;br /&gt;The full legislation is here &lt;a href="http://www.legaldaily.com.cn/misc/2006-02/21/content_269468.htm"&gt;&lt;b&gt;&lt;span style="font-family: 新細明體;" lang="ZH-TW"&gt;互联网安全保护技术措施规定&lt;/span&gt; . &lt;/b&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;There are some interesting observations from an IT security perspective: &lt;/p&gt;  &lt;p class="MsoNormal"&gt;1. This regulation is under the regime of China Police Force.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;2. Article 7.1.2 requires ISPs to have disaster recovery ability for vital database and system equipments.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;3. Most of the regulation requires ISP or who operate internet services (loosely defined at Article 18) to record and store users login time, IP address, user account information and system logs. &lt;/p&gt;  &lt;p class="MsoNormal"&gt;4. ISP has to maintain records if they find any illegal materials being distributed to the public. (“What means by illegal in the &lt;st1:place st="on"&gt;&lt;st1:country-region st="on"&gt;China&lt;/st1:country-region&gt;&lt;/st1:place&gt;?” is a mystery). &lt;/p&gt;  &lt;p class="MsoNormal"&gt;5. China Police could punish entity if they fail to perform Article 7 to 14. But there is no indication of what kinds of punishment should be. &lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;      &lt;p class="MsoNormal"&gt;First, as a security professional, I appreciate &lt;st1:country-region st="on"&gt;&lt;st1:place st="on"&gt;China&lt;/st1:place&gt;&lt;/st1:country-region&gt; government is working on legal protection of their Internet Infrastructures. But it seems stress on monitoring measures more than preventive measures. And the amount/details of information to be recorded by ISP have little to do with Internet security. The fact that it is under the regime of Police force made me think that it is more a surveillance measure for &lt;st1:country-region st="on"&gt;&lt;st1:place st="on"&gt;China&lt;/st1:place&gt;&lt;/st1:country-region&gt; government.&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;If this regulation is enforced strictly, China ISP will be the biggest buyer of storage devices. Imagine the sheer amount of data generated every second. But this regulation does not specify how long the data should be kept! &lt;span style=""&gt; &lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;Just by reading this regulation, I believe even &lt;st1:country-region st="on"&gt;&lt;st1:place st="on"&gt;China&lt;/st1:place&gt;&lt;/st1:country-region&gt; open telecommunication industry to foreign companies, no sensible company will enter the ISP market!&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-114337914775713279?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/114337914775713279/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=114337914775713279&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/114337914775713279'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/114337914775713279'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2006/03/china-internet-security-law-and-wto.html' title='China Internet Security Law and WTO!?'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-114320757936950283</id><published>2006-03-24T21:31:00.000+08:00</published><updated>2006-03-24T21:39:39.386+08:00</updated><title type='text'>A war ! and who wins</title><content type='html'>I read story(case study) about Britannica transforming from books to CD and their need to change business model in Internet Age.&lt;br /&gt;&lt;br /&gt;Now the same company face another challenge : Wikipedia, which has been a phenomena now.&lt;br /&gt;BBC reported a study comparing their accuracy :&lt;br /&gt;&lt;a href="http://news.bbc.co.uk/2/hi/technology/4840340.stm"&gt;Wikipedia study 'fatally flawed'&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;It seems Britannica always face challenges from "new media" and this time they choose to begin a war!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-114320757936950283?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/114320757936950283/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=114320757936950283&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/114320757936950283'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/114320757936950283'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2006/03/war-and-who-wins.html' title='A war ! and who wins'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-114274341525061529</id><published>2006-03-19T12:23:00.000+08:00</published><updated>2006-03-19T12:46:29.256+08:00</updated><title type='text'>Web 2.0 &amp; Democratization of Media</title><content type='html'>&lt;p class="MsoNormal"&gt;&lt;br /&gt;When I go to class at HKU, two separate seminars bring a thinking threads&lt;br /&gt;to the current Web2.0 discussion.&lt;br /&gt;&lt;br /&gt;Professor Bebo White spoke of &lt;b&gt;user empowerments&lt;/b&gt; at&lt;br /&gt;&lt;a href="http://www.ecom-icom.hku.hk/seminar/past2005.asp"&gt;Web 2.0 and the Future of Social Networking and Online Communities&lt;/a&gt;.  And this &lt;span class="ueviewtitle"&gt;&lt;span id="Title"&gt;empowerment results in &lt;/span&gt;&lt;b&gt;&lt;a href="http://hkuems1.hku.hk/hkuems/ec_hdetail.aspx?guest=Y&amp;UEID=4224"&gt;&lt;span id="Title"&gt;Democratization of Media&lt;/span&gt;&lt;/a&gt;. &lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;br /&gt;&lt;!--[if !supportLineBreakNewLine]--&gt;&lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;      &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;Web 2.0 is still in a developingstage but the decentralized publishing is really changing how the society works. &lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;br /&gt;My view is once the media is effectively decentralized and people being to information from the democratized media (like blog, wiki and off-line chat) for decision making, the result will be a collaborated decision making. &lt;span style=""&gt; &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;        &lt;p class="MsoNormal"&gt;&lt;span style=""&gt;&lt;o:p&gt; &lt;/o:p&gt;The other think thread is the influence of each individual to the world will be greater since the voice will be heard (either collectively or individually). &lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;br /&gt;However, all this has to be based on a trustworthy web. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;span class="UEViewTitle" id="Title"&gt;&lt;span style="font-weight: bold;"&gt;P.S. &lt;/span&gt;&lt;/span&gt;&lt;img src="http://www.yackpack.com/images/logo2.gif" alt="Yackpack" /&gt; take a look at &lt;a href="http://www.yackpack.com/"&gt;www.yackpack.com&lt;/a&gt; a offline chat services&lt;br /&gt;&lt;br /&gt;&lt;span class="UEViewTitle" id="Title"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-114274341525061529?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/114274341525061529/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=114274341525061529&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/114274341525061529'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/114274341525061529'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2006/03/web-20-democratization-of-media.html' title='Web 2.0 &amp; Democratization of Media'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-114060005591892426</id><published>2006-02-22T17:18:00.000+08:00</published><updated>2006-02-22T17:20:55.930+08:00</updated><title type='text'>2006 Spring (open source and collaborations)</title><content type='html'>On cyber space, I was hibernated for last winter. In real world, lots of new ideas and works.&lt;br /&gt;During this time, I extend my horizon from IT security to a larger world ; open source and web 2.0. And now I am sure I can't handle all these new concepts coming in.&lt;br /&gt;&lt;br /&gt;Mostly the time were spent on understanding the open source world. It has been evolving at a pace, no one alone can understand the impact of it. In Chinese, bamboo after spring rain.&lt;br /&gt;&lt;br /&gt;Will have more thinking threads along these new lines.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-114060005591892426?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/114060005591892426/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=114060005591892426&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/114060005591892426'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/114060005591892426'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2006/02/2006-spring-open-source-and.html' title='2006 Spring (open source and collaborations)'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-112952685772106346</id><published>2005-10-17T13:24:00.000+08:00</published><updated>2005-10-17T13:27:37.730+08:00</updated><title type='text'>MS 05-51 buggy patch</title><content type='html'>My computer did not show any network connection after I installed my computer with all 9 security patches. After some search, MS also noticed this problem and the update is below.&lt;br /&gt;http://support.microsoft.com/?kbid=909444&lt;br /&gt;&lt;br /&gt;This experience prompt me for 2 issues (one technical , one management)&lt;br /&gt;&lt;br /&gt;1. MS recommend one setting "Everyone group should have Bypass Traverse Checking permission".&lt;br /&gt;But this violated the default server built standard at some companies. The servers before put into production was hardened and this permission was changed to Domain User or Authenticated User.&lt;br /&gt;Should we ask ourselves "Are we doing too much security hardening?" or "Why Everyone is need this permission?"&lt;br /&gt;&lt;br /&gt;2. While it took 5 days for malicious hacker to publish exploit code, MS took 4 days to resolve their buggy patch. How IT admin is going to manage their internet facing server if running MS IIS ?&lt;br /&gt;Patch too soon, we are at risk of MS bug.&lt;br /&gt;Patch too late, we are at risk of exploit code.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-112952685772106346?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/112952685772106346/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=112952685772106346&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/112952685772106346'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/112952685772106346'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2005/10/ms-05-51-buggy-patch.html' title='MS 05-51 buggy patch'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-112877837397876500</id><published>2005-10-08T21:25:00.000+08:00</published><updated>2005-10-08T21:32:53.983+08:00</updated><title type='text'>Message from the court</title><content type='html'>BBC news reported two twenty-something were convinced for 3 and 6 months. What alter me is that the judge by putting them behind bars was sending message to other young people.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;“Young men, like you, have to be deterred from committing this kind of offence.” By Judge Beatrice Bolton&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://news.bbc.co.uk/1/hi/england/4319942.stm"&gt;http://news.bbc.co.uk/1/hi/england/4319942.stm&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-112877837397876500?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/112877837397876500/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=112877837397876500&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/112877837397876500'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/112877837397876500'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2005/10/message-from-court.html' title='Message from the court'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-112533006189316402</id><published>2005-08-29T23:28:00.000+08:00</published><updated>2005-08-29T23:41:01.926+08:00</updated><title type='text'>Behavior becomes mainstream</title><content type='html'>Reading of this weeks Economist on mandatory pension (page 63), quote below&lt;br /&gt;" Given the choice between $1000 in now and $1100 next year, an individual may well take the money at once ... ... Behavioral finance also shows the surprising extent to which people are swayed by the way that choices are framed. "&lt;br /&gt;&lt;br /&gt;Behavior economy is going mainstream.&lt;br /&gt;As a security professional, I usually encountered people (even myself) taking risks just because it is convenient! And security professional should make use of behavior to control IT related risks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-112533006189316402?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/112533006189316402/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=112533006189316402&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/112533006189316402'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/112533006189316402'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2005/08/behavior-becomes-mainstream.html' title='Behavior becomes mainstream'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-112481251326197974</id><published>2005-08-23T23:38:00.000+08:00</published><updated>2005-08-29T22:48:43.670+08:00</updated><title type='text'>Windows Online Crash Analsysis (OCA) Security</title><content type='html'>&lt;a href="http://photos1.blogger.com/blogger/4692/1240/1600/aug232.GIF"&gt;&lt;img style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://photos1.blogger.com/blogger/4692/1240/320/aug232.GIF" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://photos1.blogger.com/blogger/4692/1240/1600/OCA1.GIF"&gt;&lt;img style="FLOAT: left; MARGIN: 0px 10px 10px 0px; CURSOR: hand" alt="" src="http://photos1.blogger.com/blogger/4692/1240/320/OCA1.GIF" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://photos1.blogger.com/blogger/4692/1240/1600/OCA.gif"&gt;&lt;/a&gt;&lt;br /&gt;&lt;a href="http://photos1.blogger.com/blogger/4692/1240/1600/aug231.GIF"&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://photos1.blogger.com/blogger/4692/1240/1600/aug231.GIF"&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;br /&gt;Today when I was using MS word to edit a document, I encountered an error which hangs my application. By forcing it to quit, Windows XP started Microsoft Online Crash Analsysis (OCA) and asked me to send an error report to Microsoft. OCA has been with us for sometimes and I usually clicked on “OK” with an urge to start working as soon as possible. However, &lt;a href="http://photos1.blogger.com/blogger/4692/1240/1600/OCA.gif"&gt;&lt;/a&gt;today I looked into what was happening behind the simple click and found something unexpected.&lt;br /&gt;&lt;br /&gt;Opening 5MB file generated by OCA with a notepad, I was stunned to find my entire document appear in plain text (see the figure below). The error-reporting module actually transfers the document I am editing to Microsoft. Immediately, I checkout their privacy website to find out if is declared and it is (see the red circle).&lt;br /&gt;&lt;br /&gt;At this moment, a lot of questions pop up&lt;br /&gt;1. Most importantly, are the document content necessary for the error investigations?&lt;br /&gt;2. I believe with million of error reporting, Microsoft and their staff will not have the resources to look at the content. But what is their retention policy?&lt;br /&gt;3. Should Microsoft display a more clear warning message? Instead of in a privacy statement with small fonts.&lt;br /&gt;&lt;br /&gt;I believe companies should disable OCA or use firewall to block this type of traffic. More studies need to be done on FireFox quality feedback program.&lt;br /&gt;&lt;br /&gt;Below is Microsoft Privacy Statement&lt;br /&gt;&lt;a href="http://oca.microsoft.com/en/dcp20.asp"&gt;http://oca.microsoft.com/en/dcp20.asp&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-112481251326197974?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/112481251326197974/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=112481251326197974&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/112481251326197974'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/112481251326197974'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2005/08/windows-online-crash-analsysis-oca.html' title='Windows Online Crash Analsysis (OCA) Security'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-112452344400200579</id><published>2005-08-20T15:34:00.000+08:00</published><updated>2005-08-20T15:41:57.436+08:00</updated><title type='text'>Growing game indsutry ... ...</title><content type='html'>&lt;a href="http://blogs.technet.com/michand/archive/2005/08/17/409332.aspx"&gt;A highly contaminated network&lt;br /&gt;&lt;/a&gt;"About 6000 machines connected to the network... of these 1100 were infected...no less than 400 000 different species of your least favorite malware were identified! "&lt;br /&gt;&lt;br /&gt;A read of this Blog shows how immediate pleasure overshadowed the risk of virus infections. While firewall and patches will keep the computer safe, PC gamers who are afraid of speed deterioration let themselves open for real world attacks.&lt;br /&gt;&lt;br /&gt;The figure shows 18.3% of gaming PCs are vulnerable. With the ever-growing PC game industry, the family of Zombie machines is also growing. Again, IT security is more on human behavior than technology.&lt;br /&gt;&lt;br /&gt;My advice is to have the machine dual-boot, one for productive work and one for adventures. (A side question is do we need 2 OS licenses for a dual boot machine?)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-112452344400200579?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/112452344400200579/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=112452344400200579&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/112452344400200579'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/112452344400200579'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2005/08/growing-game-indsutry.html' title='Growing game indsutry ... ...'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-112221794806960118</id><published>2005-07-24T23:03:00.000+08:00</published><updated>2005-07-24T23:13:12.303+08:00</updated><title type='text'>How the Security Breach Occurred</title><content type='html'>Below is the testimony from CEO of Cardsystem, which can be found at &lt;a href="http://financialservices.house.gov/media/pdf/072105jmp.pdf"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;It seems an insider job (knowing which file to look for and can bypass FW setups). It is very difficult to uncover a script on a server if it is plant by an insider. BUT having this script running for 8 months is another thing. Security Audits, periodic port scanning and health check should uncover this abnormality of the systems.&lt;br /&gt;&lt;br /&gt;If one look into the root cause of this problem, it is the credit card data is stored for incomplete transactions. I believe lots of other card processing companies also store these type of data for manual settlements.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;How the Security Breach Occurred&lt;/strong&gt;&lt;br /&gt;In September 2004, an unauthorized party placed a script (a sequence of instructions interpreted or carried out by another program) on the CardSystems platform (an underlying computer system on which application programs run) through an internet-facing application that is used by our customers to access data. In contrast to scripts, viruses and worms are programs or programming code that replicate indiscriminately and may result in file destruction. This script ran on our system and caused records to be extracted, zipped into a file, and exported to an FTP site (similar to a web address). It was a sophisticated script that targeted a particular file type, and was scheduled to run every four days. Based on all of&lt;br /&gt;the forensic investigaions conducted externally, by independent scans and investigations and by the payment card providers, we know of only one confirmed instance in which any data was exported, and that is the May 22 incident that has brought us here today.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Why the data is stored&lt;/strong&gt;&lt;br /&gt;The data stored in the files that were confirmed to have been exported by the script consisted of transactions which were not completed for a variety of reasons. This data was stored for research purposes in order to determine why these transactions did not successfully complete. As we have repeatedly acknowledged, our error was that the data was kept in readable form in violation of Visa and MasterCard security standards. As of May 27, 2005, track data is no longer stored by CardSystems.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-112221794806960118?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/112221794806960118/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=112221794806960118&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/112221794806960118'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/112221794806960118'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2005/07/how-security-breach-occurred.html' title='How the Security Breach Occurred'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-112161360158975428</id><published>2005-07-17T23:01:00.000+08:00</published><updated>2005-07-18T00:08:38.216+08:00</updated><title type='text'>Security for phy impaired</title><content type='html'>In HK, one of the largest banks enchanced their eBanking security by giving each online banking customer with a &lt;a href="http://www.hsbc.com.hk/hk/personal/security/security_device.htm"&gt;security token&lt;/a&gt;, about the size of a battery with smal 6-digit LCD display.&lt;br /&gt;&lt;br /&gt;The device fits for carrying around. BUT after its release, some people with poor vision is complaining their access to online banking is made more difficult if not impossible. The one-time password display is just too small for them.&lt;br /&gt;&lt;br /&gt;When we talk about security, it is usually for the "normal" man working on the street. As security is becoming a commonplace, we will face the challenge of meeting the demand of everyman on the street.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-112161360158975428?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/112161360158975428/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=112161360158975428&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/112161360158975428'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/112161360158975428'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2005/07/security-for-phy-impaired.html' title='Security for phy impaired'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-112014512723059459</id><published>2005-06-30T23:12:00.000+08:00</published><updated>2005-06-30T23:25:27.233+08:00</updated><title type='text'>Softside of security</title><content type='html'>&lt;p&gt;Yesterday, &lt;a href="http://www.pisa.org.hk"&gt;PISA &lt;/a&gt;invited security experts to have a discussion forum and share the challenges in management IT security. 3 keynotes speakers are coming from banking, telecom and public organization respectively. &lt;/p&gt;&lt;p&gt;&lt;br /&gt;Below are the key points of the 2 hours discussions:&lt;/p&gt;&lt;p&gt;Both banking and telecom are highly regulated industries. IT security planning and management are driven by regulators. And both security managers in these industries believe more regulation will come!! Be prepared. But WHY the regulator wants more regulations? (An interesting question although knowing the answer will not stop them)&lt;/p&gt;&lt;p&gt;&lt;br /&gt;IT security managers sometimes need to educate business manager about risk and sometimes need to control them. It is a delicate relationship. In other word, IT security manager need to control our customer. The following were shared:&lt;/p&gt;&lt;ol&gt;&lt;li&gt;One organization has a security steering committee and it is a collective decision on whether to implement a control. Security manager’s role is to advice and advocate about risk. The decision to venture a risky operation or system does not rest on IT security manager or business manager. &lt;/li&gt;&lt;li&gt;The key point in IT risk management is to deliver the message to the Top Management. In cost conscious economy like now, management attentions are the key. If IT security manager direct report to CEO, meaning by passing CIO, things will be very different. &lt;/li&gt;&lt;li&gt;IT Auditor sometimes is friends to IT security manager as they helps delivery message to the board level and balance the risk control culture. &lt;/li&gt;&lt;/ol&gt;&lt;p&gt; &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-112014512723059459?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/112014512723059459/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=112014512723059459&amp;isPopup=true' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/112014512723059459'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/112014512723059459'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2005/06/softside-of-security.html' title='Softside of security'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-111996154628257318</id><published>2005-06-28T20:23:00.000+08:00</published><updated>2005-06-28T20:34:00.100+08:00</updated><title type='text'>Blackhole for network security</title><content type='html'>There is a few paper on the net discuss how to divert and mitigate the damages caused by network attacks, in particular DDOS. Both papers describe a means to create a “black hole” on the network.&lt;br /&gt;&lt;br /&gt;One is on the network layer and one is on the web server layer&lt;br /&gt;&lt;a href="http://www.cisco.com/warp/public/732/Tech/security/docs/blackhole.pdf"&gt;Cisco Black Hole Filtering&lt;/a&gt;&lt;br /&gt;Cisco's paper explain a specifically built infrastructure can help ISP to route malicious packets to a null interface(blackhole filtering).&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/technetmag/issues/2005/01/hackerbasher/default.aspx"&gt;Microsoft Beat Hackers At Their Own Game With A Hackerbasher Site &lt;/a&gt;&lt;br /&gt;Utilizing the principle that all vistors must know my name. This method divert incoming traffic using IP address not hostname.&lt;br /&gt;&lt;br /&gt;These papers give a good illustration that security can be achieved by thoughtful design. All the tools and technology is available to everyone or what they call built-in. By good designing, we increase the effectiveness of our security investment.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-111996154628257318?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/111996154628257318/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=111996154628257318&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/111996154628257318'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/111996154628257318'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2005/06/blackhole-for-network-security.html' title='Blackhole for network security'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-13896879.post-111953859009046752</id><published>2005-06-23T22:04:00.000+08:00</published><updated>2005-06-23T23:17:51.456+08:00</updated><title type='text'>Risk on Radio</title><content type='html'>This morning I joined a talk show on &lt;a href="http://www.rthk.org.hk"&gt;RTHK&lt;/a&gt; and discussed risk of usnig credit cards. Media attendtion is high after the recent security breach at Cardsystems. The story was uncovered on 17 June 2005, but after 6 days it is still lingering on. WHY?&lt;br /&gt;&lt;br /&gt;First, I believe this incident is huge in terms of people affected. 40 million card numbers were lost. Secondly, it was uncovered on SAT. I am not joking. One of my lectures in a Crisis Management class told his student in class that when reporters are hungry for news, even lost of a penny can be headline news. On Saturday, when reporters unable to find new story, a incident like this one will be reported by every newspaper.&lt;br /&gt;&lt;br /&gt;Back to the talk show, there were few people called in. And one mentioned that when he visited a Indian online shop and was diverted to a HSBC credit card website. This website asked him to enter his personal information like birthday and passport number. He worried this may be fraudulent website and asked for advice.&lt;br /&gt;&lt;br /&gt;As a banking guy, I know the credit card website is part of the process called "Verified by VISA" and definitely not fraudulent. This “Verified by VISA” process enables the card issuing bank to authenticate the online transactions. Banks invested a lot to enable this technology. However, the general public is scared about things tooooooo new.&lt;br /&gt;&lt;br /&gt;If you think &lt;strong&gt;positively&lt;/strong&gt;, this person is risk aversive and phishng is not going to catch him.&lt;br /&gt;If you think &lt;strong&gt;negative&lt;/strong&gt;, it is a lost/lost/lost situation. The credit card holder cannot buy his goods. The online cannot sell. The bank’s investment on new technology is gone.&lt;br /&gt;&lt;br /&gt;I am on the negative side.&lt;br /&gt;&lt;br /&gt;Click here to &lt;a href="http://www.rthk.org.hk/rthk/radio3/backchat/20050623.html"&gt;Hong Kong Backchat&lt;/a&gt; talk show.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/13896879-111953859009046752?l=techrisk.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://techrisk.blogspot.com/feeds/111953859009046752/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=13896879&amp;postID=111953859009046752&amp;isPopup=true' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/111953859009046752'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13896879/posts/default/111953859009046752'/><link rel='alternate' type='text/html' href='http://techrisk.blogspot.com/2005/06/risk-on-radio.html' title='Risk on Radio'/><author><name>Antony</name><uri>http://www.blogger.com/profile/00214786592533777396</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='27' height='32' src='http://1.bp.blogspot.com/-7Ex5B9cg850/TwOt2zJUZCI/AAAAAAAAArQ/MlpOiEXqEAI/s220/ma_photo.jpg'/></author><thr:total>4</thr:total></entry></feed>
