<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: FBI Investigating Theft of $500,000 from NY School District</title>
	<atom:link href="http://krebsonsecurity.com/2010/01/fbi-investigating-theft-of-500000-from-ny-school-district/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2010/01/fbi-investigating-theft-of-500000-from-ny-school-district/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Wed, 23 May 2012 01:40:28 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: BrianKrebs</title>
		<link>http://krebsonsecurity.com/2010/01/fbi-investigating-theft-of-500000-from-ny-school-district/comment-page-1/#comment-12775</link>
		<dc:creator>BrianKrebs</dc:creator>
		<pubDate>Tue, 23 Nov 2010 22:23:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=239#comment-12775</guid>
		<description>Hi Jim. Thanks for your comment. How about commenting on a slightly more recent thread on this topic. Like, say, today&#039;s story: 

http://krebsonsecurity.com/2010/11/escrow-co-sues-bank-over-440k-cyber-theft/

:)</description>
		<content:encoded><![CDATA[<p>Hi Jim. Thanks for your comment. How about commenting on a slightly more recent thread on this topic. Like, say, today&#8217;s story: </p>
<p><a href="http://krebsonsecurity.com/2010/11/escrow-co-sues-bank-over-440k-cyber-theft/" rel="nofollow">http://krebsonsecurity.com/2010/11/escrow-co-sues-bank-over-440k-cyber-theft/</a></p>
<p> <img src='http://krebsonsecurity.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-12775" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('12775', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-12775-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-12775" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('12775', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-12775-down" style="font-size:14px; color:#990033;">2</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: James R. ("Jim") Woodhill</title>
		<link>http://krebsonsecurity.com/2010/01/fbi-investigating-theft-of-500000-from-ny-school-district/comment-page-1/#comment-12774</link>
		<dc:creator>James R. ("Jim") Woodhill</dc:creator>
		<pubDate>Tue, 23 Nov 2010 22:18:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=239#comment-12774</guid>
		<description>I have been trying to find the words that would persuade those who think that online banking funds transfer fraud is the *users&#039;* fault and that Duanesburg School District et. al. should bear the losses that they are wrong.  As Brian has reported in:

http://krebsonsecurity.com/2010/10/bill-would-give-cities-towns-and-schools-same-e-banking-security-guarantees-as-consumers/

It looks like Sen. Chuck Schumer (D, NY/Committee on Banking, Housing, and Urban Affairs/Subcommittee on Financial Services) beat me to it.  Those words, of course, begin with, &quot;Be It Enacted by the Senate and the House of Representatives of the United States of America, in Congress Assembled...&quot;

Just nine months from this incident to the introduction of this legislation.  Not bad as things on the Hill go...

Not that I support this bill as written.  I believe Sen. Schumer has the right problem, but the wrong solution.  A straight extension of Regulation E could drive America&#039;s small- and medium-sized banks out of online banking.  At a minimum, it will force them to divert their time and attention from making loans to becoming cyber-security experts.  Now, there is nothing about cyber-security that is inherently harder than running a community bank, so if our bankers work hard enough they will succeed, but do we really want eastern European cyber-criminal gangs to force America to change the way we do things?  This is about as sensible as allowing a handful of Jihadist crazies to force us to submit to having our private parts patted down every time we fly.</description>
		<content:encoded><![CDATA[<p>I have been trying to find the words that would persuade those who think that online banking funds transfer fraud is the *users&#8217;* fault and that Duanesburg School District et. al. should bear the losses that they are wrong.  As Brian has reported in:</p>
<p><a href="http://krebsonsecurity.com/2010/10/bill-would-give-cities-towns-and-schools-same-e-banking-security-guarantees-as-consumers/" rel="nofollow">http://krebsonsecurity.com/2010/10/bill-would-give-cities-towns-and-schools-same-e-banking-security-guarantees-as-consumers/</a></p>
<p>It looks like Sen. Chuck Schumer (D, NY/Committee on Banking, Housing, and Urban Affairs/Subcommittee on Financial Services) beat me to it.  Those words, of course, begin with, &#8220;Be It Enacted by the Senate and the House of Representatives of the United States of America, in Congress Assembled&#8230;&#8221;</p>
<p>Just nine months from this incident to the introduction of this legislation.  Not bad as things on the Hill go&#8230;</p>
<p>Not that I support this bill as written.  I believe Sen. Schumer has the right problem, but the wrong solution.  A straight extension of Regulation E could drive America&#8217;s small- and medium-sized banks out of online banking.  At a minimum, it will force them to divert their time and attention from making loans to becoming cyber-security experts.  Now, there is nothing about cyber-security that is inherently harder than running a community bank, so if our bankers work hard enough they will succeed, but do we really want eastern European cyber-criminal gangs to force America to change the way we do things?  This is about as sensible as allowing a handful of Jihadist crazies to force us to submit to having our private parts patted down every time we fly.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-12774" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('12774', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-12774-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-12774" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('12774', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-12774-down" style="font-size:14px; color:#990033;">2</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: ChuckD</title>
		<link>http://krebsonsecurity.com/2010/01/fbi-investigating-theft-of-500000-from-ny-school-district/comment-page-1/#comment-1312</link>
		<dc:creator>ChuckD</dc:creator>
		<pubDate>Sun, 31 Jan 2010 21:54:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=239#comment-1312</guid>
		<description>Just posting to subscribe to this. I live within ten miles of this school district and have been in IT since before the internet, have not seen any follow-up on it. Looking forward to it.

And sorry, I have no contacts there, nor any inside info to offer.

C.</description>
		<content:encoded><![CDATA[<p>Just posting to subscribe to this. I live within ten miles of this school district and have been in IT since before the internet, have not seen any follow-up on it. Looking forward to it.</p>
<p>And sorry, I have no contacts there, nor any inside info to offer.</p>
<p>C.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-1312" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('1312', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-1312-up" style="font-size:14px; color:#009933;">2</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-1312" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('1312', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-1312-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Most just don&#8217;t know</title>
		<link>http://krebsonsecurity.com/2010/01/fbi-investigating-theft-of-500000-from-ny-school-district/comment-page-1/#comment-1210</link>
		<dc:creator>Most just don&#8217;t know</dc:creator>
		<pubDate>Thu, 28 Jan 2010 18:35:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=239#comment-1210</guid>
		<description>[...] hackers are using malware to steal banking information netting millions of dollars from business, schools and [...]</description>
		<content:encoded><![CDATA[<p>[...] hackers are using malware to steal banking information netting millions of dollars from business, schools and [...]</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-1210" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('1210', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-1210-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-1210" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('1210', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-1210-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Cyber Crooks Cooked the Books at Fla. Library &#8212; Krebs on Security</title>
		<link>http://krebsonsecurity.com/2010/01/fbi-investigating-theft-of-500000-from-ny-school-district/comment-page-1/#comment-834</link>
		<dc:creator>Cyber Crooks Cooked the Books at Fla. Library &#8212; Krebs on Security</dc:creator>
		<pubDate>Fri, 22 Jan 2010 17:06:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=239#comment-834</guid>
		<description>[...] strongly suggests that the group that hit Delray Beach Public Library also was responsible for the $3,000,000 fraud perpetrated against Duanesburg Central School District in upstate New York late last year.   var [...]</description>
		<content:encoded><![CDATA[<p>[...] strongly suggests that the group that hit Delray Beach Public Library also was responsible for the $3,000,000 fraud perpetrated against Duanesburg Central School District in upstate New York late last year.   var [...]</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-834" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('834', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-834-up" style="font-size:14px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-834" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('834', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-834-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Gary</title>
		<link>http://krebsonsecurity.com/2010/01/fbi-investigating-theft-of-500000-from-ny-school-district/comment-page-1/#comment-249</link>
		<dc:creator>Gary</dc:creator>
		<pubDate>Sun, 10 Jan 2010 19:35:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=239#comment-249</guid>
		<description>Great Article.</description>
		<content:encoded><![CDATA[<p>Great Article.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-249" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('249', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-249-up" style="font-size:14px; color:#009933;">1</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-249" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('249', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-249-down" style="font-size:14px; color:#990033;">2</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: Rob Lewis</title>
		<link>http://krebsonsecurity.com/2010/01/fbi-investigating-theft-of-500000-from-ny-school-district/comment-page-1/#comment-230</link>
		<dc:creator>Rob Lewis</dc:creator>
		<pubDate>Fri, 08 Jan 2010 19:47:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=239#comment-230</guid>
		<description>Awareness is a good thing, but unfortunately the current security model is so full of holes that there are few pragmatic ways to stop the bleeding, short of abandoning on-line banking. Even with that scenerio, there would be no full-proof guarantee that customer finances would be fully safe in the banks hands, since they are also dependent on vulnerability-centric defenses.</description>
		<content:encoded><![CDATA[<p>Awareness is a good thing, but unfortunately the current security model is so full of holes that there are few pragmatic ways to stop the bleeding, short of abandoning on-line banking. Even with that scenerio, there would be no full-proof guarantee that customer finances would be fully safe in the banks hands, since they are also dependent on vulnerability-centric defenses.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-230" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('230', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-230-up" style="font-size:14px; color:#009933;">3</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-230" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('230', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-230-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: MichaelFigueroa</title>
		<link>http://krebsonsecurity.com/2010/01/fbi-investigating-theft-of-500000-from-ny-school-district/comment-page-1/#comment-211</link>
		<dc:creator>MichaelFigueroa</dc:creator>
		<pubDate>Thu, 07 Jan 2010 20:22:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=239#comment-211</guid>
		<description>Brian - I&#039;ve been following you for years as a security consultant and as a CISO and am glad to see the new site up and active.

My partners and I have been debating who should be responsible for these attacks.  On one hand, you can blame the banks for having poor business processes that do not account for the potential for misuse.  On the other hand, you have the organizations themselves who have ignorant users who provide access to banking credentials.

Since I think that the argument can go either way (or both ways, which would be the reality), I think that it would be really interesting if you were to put up a &quot;Wall of Education&quot; page that lists the affected banks and organizations, sorted by dollar value of the attack.  It would be interesting to see how many times individual banks start popping up.</description>
		<content:encoded><![CDATA[<p>Brian &#8211; I&#8217;ve been following you for years as a security consultant and as a CISO and am glad to see the new site up and active.</p>
<p>My partners and I have been debating who should be responsible for these attacks.  On one hand, you can blame the banks for having poor business processes that do not account for the potential for misuse.  On the other hand, you have the organizations themselves who have ignorant users who provide access to banking credentials.</p>
<p>Since I think that the argument can go either way (or both ways, which would be the reality), I think that it would be really interesting if you were to put up a &#8220;Wall of Education&#8221; page that lists the affected banks and organizations, sorted by dollar value of the attack.  It would be interesting to see how many times individual banks start popping up.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-211" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('211', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-211-up" style="font-size:14px; color:#009933;">3</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-211" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('211', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-211-down" style="font-size:14px; color:#990033;">2</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: infosec_pro</title>
		<link>http://krebsonsecurity.com/2010/01/fbi-investigating-theft-of-500000-from-ny-school-district/comment-page-1/#comment-160</link>
		<dc:creator>infosec_pro</dc:creator>
		<pubDate>Thu, 07 Jan 2010 00:04:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=239#comment-160</guid>
		<description>@BrianKrebs - thanks for sharing that email, and thanks to the author for being willing to have it shared.  I think it should give a good argument against those who continue to blame the victims, that organization probably knows more about securing systems than most of your readers and still took big losses despite strong motivation to protect themselves with best in class measures.  If they couldn&#039;t stop the bleeding how is a local school district going to do so?

btw I served on a local (regional) school board for a few years, comparable in size to Duanesburg.  Our entire IT budget would not have covered my present salary, and that&#039;s probably true for most of the knowledgeable readers on here.  It takes time and effort and diligent competence to properly manage and secure systems, that&#039;s why it is so seldom done right.  If local governments and schools spend money to get the resources they need to do the job right they get slammed by taxpayers and/or cut back in mission critical areas.  

@ TheGeezer, &quot;Parkinson Construction is not in the computer business.&quot;  Exactly the problem.  It takes so much competence and diligence to properly secure desktop PCs that almost anyone not in the IT business cannot justify the expense to do it right, especially with the need for expertise so outstripping the available supply.</description>
		<content:encoded><![CDATA[<div style="background-color:#FFFFCC !important"><p>@BrianKrebs &#8211; thanks for sharing that email, and thanks to the author for being willing to have it shared.  I think it should give a good argument against those who continue to blame the victims, that organization probably knows more about securing systems than most of your readers and still took big losses despite strong motivation to protect themselves with best in class measures.  If they couldn&#8217;t stop the bleeding how is a local school district going to do so?</p>
<p>btw I served on a local (regional) school board for a few years, comparable in size to Duanesburg.  Our entire IT budget would not have covered my present salary, and that&#8217;s probably true for most of the knowledgeable readers on here.  It takes time and effort and diligent competence to properly manage and secure systems, that&#8217;s why it is so seldom done right.  If local governments and schools spend money to get the resources they need to do the job right they get slammed by taxpayers and/or cut back in mission critical areas.  </p>
<p>@ TheGeezer, &#8220;Parkinson Construction is not in the computer business.&#8221;  Exactly the problem.  It takes so much competence and diligence to properly secure desktop PCs that almost anyone not in the IT business cannot justify the expense to do it right, especially with the need for expertise so outstripping the available supply.</p>
</div><div class="CommentRating">Well-loved. Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-160" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('160', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-160-up" style="font-size:14px; color:#009933;">5</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-160" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('160', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-160-down" style="font-size:14px; color:#990033;">0</span></div>]]></content:encoded>
	</item>
	<item>
		<title>By: TheGeezer</title>
		<link>http://krebsonsecurity.com/2010/01/fbi-investigating-theft-of-500000-from-ny-school-district/comment-page-1/#comment-152</link>
		<dc:creator>TheGeezer</dc:creator>
		<pubDate>Wed, 06 Jan 2010 18:12:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=239#comment-152</guid>
		<description>You are right Rick that the registration is after the fact of installing the malware.
However, the malware is often accessed via a registered domain name.

The registrar&#039;s role is therefore VERY important! 
And yes, we can claim to not know how this happened. Was it again a fraudulently registered domain that should have been detected by the registrar? Or was it an employee downloading &#039;free&#039; software? We don&#039;t know how this happened. &quot;not having a clue about operating systems and system security&quot; is not the answer.

Let&#039;s look at the example of the small business in D.C., Parkinson Construction, which fell victim to the Social Security Administration exploit which Brian reported on early december.
http://voices.washingtonpost.com/securityfix/2009/12/who_says_pay-per-click_revenue.html

The Zeus botnet SSA exploit was running in late November using the ccTLD of &#039;.be&#039;.
It should have been clear to any registrar that the US Social Security Administration does not register with DNS.be and does not use a fast-flux server. The registrar is in the computer business.
They should be able to see this and respond. Parkinson Construction is not in the computer business.
If this registrar had shown the same responsibility demonstrated by some others, Parkinson Construction would have received a &#039;Host Not Found&#039; error message rather than a trojan.

The personal computer has become a necessary but dangerous appliance for most people and certainly for business.
No one is required to know electronics to be guaranteed safety from electrical shock from their dvd player.
You should not have to be a computer guru to avoid &#039;software shock&#039; from your computer either.

The registrars need to have their focus redirected from bragging about how many domains they&#039;ve registered to how few malevolent domains they&#039;ve registered. They are the ones who should be the computer gurus, not victims like Mr. Parkinson and Duanesburg Central School District.
It doesn&#039;t take much of a computer guru to know that the IRS and SSA are not located in Chili or Argentina. 
Let the Registrar be responsible for the research. That would prevent the majority of these incidents.</description>
		<content:encoded><![CDATA[<p>You are right Rick that the registration is after the fact of installing the malware.<br />
However, the malware is often accessed via a registered domain name.</p>
<p>The registrar&#8217;s role is therefore VERY important!<br />
And yes, we can claim to not know how this happened. Was it again a fraudulently registered domain that should have been detected by the registrar? Or was it an employee downloading &#8216;free&#8217; software? We don&#8217;t know how this happened. &#8220;not having a clue about operating systems and system security&#8221; is not the answer.</p>
<p>Let&#8217;s look at the example of the small business in D.C., Parkinson Construction, which fell victim to the Social Security Administration exploit which Brian reported on early december.<br />
<a href="http://voices.washingtonpost.com/securityfix/2009/12/who_says_pay-per-click_revenue.html" rel="nofollow">http://voices.washingtonpost.com/securityfix/2009/12/who_says_pay-per-click_revenue.html</a></p>
<p>The Zeus botnet SSA exploit was running in late November using the ccTLD of &#8216;.be&#8217;.<br />
It should have been clear to any registrar that the US Social Security Administration does not register with DNS.be and does not use a fast-flux server. The registrar is in the computer business.<br />
They should be able to see this and respond. Parkinson Construction is not in the computer business.<br />
If this registrar had shown the same responsibility demonstrated by some others, Parkinson Construction would have received a &#8216;Host Not Found&#8217; error message rather than a trojan.</p>
<p>The personal computer has become a necessary but dangerous appliance for most people and certainly for business.<br />
No one is required to know electronics to be guaranteed safety from electrical shock from their dvd player.<br />
You should not have to be a computer guru to avoid &#8216;software shock&#8217; from your computer either.</p>
<p>The registrars need to have their focus redirected from bragging about how many domains they&#8217;ve registered to how few malevolent domains they&#8217;ve registered. They are the ones who should be the computer gurus, not victims like Mr. Parkinson and Duanesburg Central School District.<br />
It doesn&#8217;t take much of a computer guru to know that the IRS and SSA are not located in Chili or Argentina.<br />
Let the Registrar be responsible for the research. That would prevent the majority of these incidents.</p>
<div class="CommentRating">Like or Dislike: <img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-152" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('152', 'add', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_');" title="Thumb up" /> <span id="karma-152-up" style="font-size:14px; color:#009933;">4</span>&nbsp;<img style="padding: 0px; margin: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-152" src="http://krebsonsecurity.com/wp-content/plugins/comment-rating-pro/images/1_16_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('152', 'subtract', 'krebsonsecurity.com/wp-content/plugins/comment-rating-pro/', '1_16_')" title="Thumb down" /> <span id="karma-152-down" style="font-size:14px; color:#990033;">1</span></div>]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 3/18 queries in 0.004 seconds using memcached
Object Caching 951/957 objects using memcached

Served from: krebsonsecurity.com @ 2012-05-22 23:51:29 -->
