<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    <title>Pingree on Security - Security</title>
    <link>http://www.lawrencepingree.com/</link>
    <description>A security focused blog</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.2 - http://www.s9y.org/</generator>
    <pubDate>Thu, 10 Jul 2008 18:30:59 GMT</pubDate>

    <image>
        <url>http://www.lawrencepingree.com/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: Pingree on Security - Security - A security focused blog</title>
        <link>http://www.lawrencepingree.com/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>DNS Cache Poisoning again? I thought it died already...</title>
    <link>http://www.lawrencepingree.com/archives/99-DNS-Cache-Poisoning-again-I-thought-it-died-already....html</link>
            <category>Security</category>
    
    <comments>http://www.lawrencepingree.com/archives/99-DNS-Cache-Poisoning-again-I-thought-it-died-already....html#comments</comments>
    <wfw:comment>http://www.lawrencepingree.com/wfwcomment.php?cid=99</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.lawrencepingree.com/rss.php?version=2.0&amp;type=comments&amp;cid=99</wfw:commentRss>
    

    <author>nospam@example.com (Lawrence Pingree)</author>
    <content:encoded>
    &lt;p&gt;&lt;br /&gt;
Apparently a newly discovered vulnerability in DNS allows for cache poisoning yet again. The poisoning is related to essentially brute forcing the transaction ID where some DNS servers don&#039;t use the correct number of bits to make it more difficult to guess. Do the RFC&#039;s need some work now?&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Check the article &lt;a href=&quot;http://www.pcmag.com/article2/0,2817,2325208,00.asp?kc=PCRSS05079TX1K0000992&quot; target=&quot;_blank&quot;&gt;here&lt;/a&gt;&lt;/p&gt;  
    </content:encoded>

    <pubDate>Thu, 10 Jul 2008 11:27:04 -0700</pubDate>
    <guid isPermaLink="false">http://www.lawrencepingree.com/archives/99-guid.html</guid>
    
</item>
<item>
    <title>Free Julie Amero!</title>
    <link>http://www.lawrencepingree.com/archives/98-Free-Julie-Amero!.html</link>
            <category>Security</category>
    
    <comments>http://www.lawrencepingree.com/archives/98-Free-Julie-Amero!.html#comments</comments>
    <wfw:comment>http://www.lawrencepingree.com/wfwcomment.php?cid=98</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.lawrencepingree.com/rss.php?version=2.0&amp;type=comments&amp;cid=98</wfw:commentRss>
    

    <author>nospam@example.com (Lawrence Pingree)</author>
    <content:encoded>
    &lt;br /&gt;
I&#039;m not sure why this court case is still on, since its just obvious to almost any security person that this woman didn&#039;t do anything wrong. Its not like she &amp;quot;intended&amp;quot; to subject the children to smut and porn, its adware silly! Anyhow, I think this case should be dropped. Apparently its still in limbo.... see &lt;a target=&quot;_blank&quot; href=&quot;http://www.theregister.co.uk/2008/07/10/smut_pop_up_teacher_update/&quot;&gt;here&lt;/a&gt;&lt;br /&gt;
  
    </content:encoded>

    <pubDate>Thu, 10 Jul 2008 11:21:53 -0700</pubDate>
    <guid isPermaLink="false">http://www.lawrencepingree.com/archives/98-guid.html</guid>
    
</item>
<item>
    <title>Is the RIAA out of control with enforcement?</title>
    <link>http://www.lawrencepingree.com/archives/97-Is-the-RIAA-out-of-control-with-enforcement.html</link>
            <category>Security</category>
    
    <comments>http://www.lawrencepingree.com/archives/97-Is-the-RIAA-out-of-control-with-enforcement.html#comments</comments>
    <wfw:comment>http://www.lawrencepingree.com/wfwcomment.php?cid=97</wfw:comment>

    <slash:comments>1</slash:comments>
    <wfw:commentRss>http://www.lawrencepingree.com/rss.php?version=2.0&amp;type=comments&amp;cid=97</wfw:commentRss>
    

    <author>nospam@example.com (Lawrence Pingree)</author>
    <content:encoded>
    &lt;p&gt;An &lt;a href=&quot;http://www.securityfocus.com/news/11521?ref=rss&quot; target=&quot;_blank&quot;&gt;interesting article&lt;/a&gt; on how research and enforcement activities of companies trying to ensure their data is not shared illegally can sometimes go awry.&lt;/p&gt;&lt;p&gt;[...]&lt;/p&gt;&lt;p&gt;&lt;span class=&quot;body&quot;&gt;&lt;p&gt;&lt;br /&gt;
While denial-of-service attacks are common occurrences on the Internet,&lt;br /&gt;
Revision3&#039;s investigation found that it was targeted not by&lt;br /&gt;
hard-to-prosecute political hacktivists or criminal groups, but by a&lt;br /&gt;
company known for its aggressive tactics against file sharers,&lt;br /&gt;
anti-piracy firm &lt;a target=&quot;_blank&quot; href=&quot;http://www.mediadefender.com/index.html&quot;&gt;MediaDefender&lt;/a&gt;.&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;&lt;br /&gt;
The company, a subsidiary of music firm ArtistDirect that counts a&lt;br /&gt;
number of record labels and movie studios as its clients, apparently&lt;br /&gt;
discovered that digital pirates had listed illegally-copied content on&lt;br /&gt;
Revision3&#039;s BitTorrent directory, Louderback learned during a&lt;br /&gt;
conference call with the firm this week. Rather than contacting&lt;br /&gt;
Revision3 to divulge the security weakness, however, MediaDefender&lt;br /&gt;
placed fake listings, or torrents, on the online video firm&#039;s servers&lt;br /&gt;
in an attempt to identify people who were downloading illegal content.&lt;/p&gt;&lt;br /&gt;
&lt;p&gt;&lt;br /&gt;
When Revision3 beefed up security last week to prevent others from&lt;br /&gt;
listing content on its tracker server, MediaDefender&#039;s computers&lt;br /&gt;
responded by repeatedly trying to access the files, overwhelming&lt;br /&gt;
Revision3&#039;s network, Louderback told &lt;cite&gt;SecurityFocus&lt;/cite&gt; in an interview.&lt;/p&gt;&lt;p&gt;[...]&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;/span&gt;&lt;/p&gt;&lt;br /&gt;
  
    </content:encoded>

    <pubDate>Sun, 08 Jun 2008 07:24:01 -0700</pubDate>
    <guid isPermaLink="false">http://www.lawrencepingree.com/archives/97-guid.html</guid>
    
</item>
<item>
    <title>Are you being watched at work?</title>
    <link>http://www.lawrencepingree.com/archives/96-Are-you-being-watched-at-work.html</link>
            <category>Security</category>
    
    <comments>http://www.lawrencepingree.com/archives/96-Are-you-being-watched-at-work.html#comments</comments>
    <wfw:comment>http://www.lawrencepingree.com/wfwcomment.php?cid=96</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.lawrencepingree.com/rss.php?version=2.0&amp;type=comments&amp;cid=96</wfw:commentRss>
    

    <author>nospam@example.com (Lawrence Pingree)</author>
    <content:encoded>
    &lt;p&gt;Excellent &lt;a href=&quot;http://www.pcmag.com/article2/0,1759,2308369,00.asp?kc=PCRSS05079TX1K0000992&quot;&gt;PC Mag article&lt;/a&gt; on Employee Monitoring. Personally I&#039;ve worked to monitor employee&#039;s email, web and Instant messaging as part of my Forensic and Investigations work while working at several of my jobs, so this is a very real concern. See an Excerpt below:&lt;/p&gt;&lt;p&gt;[...]&lt;/p&gt;&lt;p&gt;It&#039;s possible that someone has been reading your e-mails, listening to your phone calls, and tracking your Internet use. No, it&#039;s not a foreign spy. It&#039;s not even your ex—it&#039;s your employer. And she doesn&#039;t even need to tell you she&#039;s doing it. &lt;/p&gt;&lt;p&gt;Employers can legally monitor their workers however they want. They can log and review all computer activity as long as they own the machines. The most popular method of keeping tabs on employees is to track Internet use: A whopping 66 percent of companies monitor employee Internet activity, according to a survey released in February by the American Management Association and the ePolicy Institute. What are they looking for? Frequent visits to sexually explicit sites, game sites, and social-networking sites like &lt;a title=&quot;Facebook Inc.&quot; href=&quot;http://www.lawrencepingree.com/topic/0,2944,t=Facebook%20Inc,00.asp&quot;&gt;Facebook &lt;/a&gt;on company time. Almost a third of those who said they monitor their employees have fired someone for inappropriate Web surfing. &lt;/p&gt;&lt;p&gt;[...]&lt;/p&gt;&lt;p /&gt;  
    </content:encoded>

    <pubDate>Tue, 27 May 2008 10:45:56 -0700</pubDate>
    <guid isPermaLink="false">http://www.lawrencepingree.com/archives/96-guid.html</guid>
    
</item>
<item>
    <title>Automated Forex Trading</title>
    <link>http://www.lawrencepingree.com/archives/95-Automated-Forex-Trading.html</link>
            <category>Security</category>
    
    <comments>http://www.lawrencepingree.com/archives/95-Automated-Forex-Trading.html#comments</comments>
    <wfw:comment>http://www.lawrencepingree.com/wfwcomment.php?cid=95</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.lawrencepingree.com/rss.php?version=2.0&amp;type=comments&amp;cid=95</wfw:commentRss>
    

    <author>nospam@example.com (Lawrence Pingree)</author>
    <content:encoded>
    &lt;br /&gt;
&lt;p&gt;Off topic, if any of you are interested in automated investments with as little as $1000 and profit potential of 7% per month you should check out &lt;a target=&quot;_blank&quot; href=&quot;http://trademaster.zulutrade.com&quot;&gt;http://trademaster.zulutrade.com&lt;/a&gt; it offers automated signal services that are free to the trader. All you do is fund your account, pick a trade signal provider from their performance page and sit back and watch the trades execute. (Of course past performance is not indicative of future performance based on market conditions). If you want to learn more about the Forex and Trading, I suggest clicking on the &amp;quot;School&amp;quot; section at &lt;a href=&quot;http://www.babypips.com&quot; target=&quot;_blank&quot;&gt;http://www.babypips.com&lt;/a&gt;&lt;/p&gt; &lt;br /&gt;
e &lt;br /&gt;
 
    </content:encoded>

    <pubDate>Sun, 25 May 2008 11:16:53 -0700</pubDate>
    <guid isPermaLink="false">http://www.lawrencepingree.com/archives/95-guid.html</guid>
    
</item>
<item>
    <title>Paypal XSS, ethics and the law</title>
    <link>http://www.lawrencepingree.com/archives/94-Paypal-XSS,-ethics-and-the-law.html</link>
            <category>Security</category>
    
    <comments>http://www.lawrencepingree.com/archives/94-Paypal-XSS,-ethics-and-the-law.html#comments</comments>
    <wfw:comment>http://www.lawrencepingree.com/wfwcomment.php?cid=94</wfw:comment>

    <slash:comments>9</slash:comments>
    <wfw:commentRss>http://www.lawrencepingree.com/rss.php?version=2.0&amp;type=comments&amp;cid=94</wfw:commentRss>
    

    <author>nospam@example.com (Lawrence Pingree)</author>
    <content:encoded>
    &lt;br /&gt;
Today a man by the name of Harry Sintonen announced that the paypal payment processing site was exploitable by an XSS attack. In the back of my mind I was thinking how fitting his last name was &amp;quot;Sin&amp;quot;tonen. Apparently he demonstrated this to a journalist and during the &amp;quot;online interview&amp;quot; executed an XSS attack that exploited the vulnerability on the paypal website and used an alert pop-up to show the issue. The article is &lt;a target=&quot;_blank&quot; href=&quot;http://www.theregister.co.uk/2008/05/16/paypal_page_succumbs_to_xss/&quot;&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;Now, I understand that its important that these types of companies (such as paypal) need to be looking for this type of bug and I&#039;m certain that Paypal has an army of security personnel that are slated to ensure this sort of thing does not happen. What I&#039;d like to take issue with is the fact that the public has no business executing attacks against websites on the internet and the fact that they are doing so is not only unethical but criminal. Its great that people know how to execute attacks, XSS and SQL injections are not that tough, especially given that paros proxy, web scarab and tamperdata for firefox etc allow you to easily push these to websites using your desktop. But just cause you CAN do something doesn&#039;t mean that you should and I feel publicizing this sort of this is just downright irresponsible and if its not illegal in finland, it darned well should be!&lt;/p&gt;  
    </content:encoded>

    <pubDate>Fri, 16 May 2008 15:05:28 -0700</pubDate>
    <guid isPermaLink="false">http://www.lawrencepingree.com/archives/94-guid.html</guid>
    
</item>
<item>
    <title>Interesting Security Poll of users on the street</title>
    <link>http://www.lawrencepingree.com/archives/93-Interesting-Security-Poll-of-users-on-the-street.html</link>
            <category>Security</category>
    
    <comments>http://www.lawrencepingree.com/archives/93-Interesting-Security-Poll-of-users-on-the-street.html#comments</comments>
    <wfw:comment>http://www.lawrencepingree.com/wfwcomment.php?cid=93</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.lawrencepingree.com/rss.php?version=2.0&amp;type=comments&amp;cid=93</wfw:commentRss>
    

    <author>nospam@example.com (Lawrence Pingree)</author>
    <content:encoded>
    &lt;p&gt;One thing that all of us forget is some of the basics in security. The following article is a survey RSA had performed in 2007 which asked security related questions about user activities. I found the numbers somewhat amusing and validated my own thinking in terms of where efforts needed to be focused. I thought it was interesting that Government employee&#039;s seem to be more on top of security (at least physical) than the corporate world.&lt;br /&gt;&lt;br /&gt;Read the article &lt;a href=&quot;http://www.windowsecurity.com/articles/Protecting-Users-Against-Themselves.html&quot; target=&quot;_blank&quot;&gt;here&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;  
    </content:encoded>

    <pubDate>Thu, 15 May 2008 09:54:15 -0700</pubDate>
    <guid isPermaLink="false">http://www.lawrencepingree.com/archives/93-guid.html</guid>
    
</item>
<item>
    <title>Intrusion Tolerance replacing intrusion detection?</title>
    <link>http://www.lawrencepingree.com/archives/92-Intrusion-Tolerance-replacing-intrusion-detection.html</link>
            <category>Security</category>
    
    <comments>http://www.lawrencepingree.com/archives/92-Intrusion-Tolerance-replacing-intrusion-detection.html#comments</comments>
    <wfw:comment>http://www.lawrencepingree.com/wfwcomment.php?cid=92</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.lawrencepingree.com/rss.php?version=2.0&amp;type=comments&amp;cid=92</wfw:commentRss>
    

    <author>nospam@example.com (Lawrence Pingree)</author>
    <content:encoded>
    &lt;br /&gt;
&lt;p&gt;Is &amp;quot;Intrusion Tolerance&amp;quot; replacing &amp;quot;Intrusion Detection and Prevention&amp;quot;? I doubt it.&lt;br /&gt;&lt;br /&gt;Reading an &lt;a href=&quot;http://www.darkreading.com/document.asp?doc_id=153621&amp;WT.svl=news2_1&quot; target=&quot;_blank&quot;&gt;article on DarkReading&lt;/a&gt; today about a new project started by &amp;quot;Aron Sood&amp;quot; that he&#039;s dubbed &amp;quot;Intrusion Tolerance&amp;quot;. Basically the approach is simple, his idea was to take a &amp;quot;clean&amp;quot; copy of a web, dns or other server and rotate it into 1st position on the DMZ on a regular interval roughly 1 minute. He commented that this would lower the window of opportunity for a system to become breached and limit the data loss exposure.&lt;br /&gt;&lt;br /&gt;In my humble opinion, Intrusion Detection and Prevention is not going away any time soon and here&#039;s why:&lt;/p&gt;&lt;p&gt;1. Web Servers don&#039;t normally store sensitive data these days (Application Databases do).&lt;br /&gt;2. This does nothing to prevent zero day application exploit via the exposed web server.&lt;br /&gt;3. To infect a system only takes moments and therefore any exposure for even more than 1 second can lead to a breach. Case in point - Place an unpatched Windows XP system on the internet for about 10 minutes and whammo, you&#039;ll have several worms infecting your machine in that timeframe.&lt;br /&gt;&lt;br /&gt;Summary:&lt;/p&gt;&lt;p&gt;Although this technology helps aid us security folks in our endevour, its by no means a panacea. Honestly, this is only one small component that can be added to your overall security strategy and call it a day. Don&#039;t drop your Firewall, Intrustion Detection and Prevention and other compliance technologies on account of someone saying they will &amp;quot;limit&amp;quot; your data loss. I&#039;ll be keeping an eye on this technology as it has some promise if combined with the right complementary technologies. We&#039;ll see.&lt;/p&gt;&lt;p&gt;Read the Article &lt;a target=&quot;_blank&quot; href=&quot;http://www.darkreading.com/document.asp?doc_id=153621&amp;WT.svl=news2_1&quot;&gt;here&lt;/a&gt;&lt;/p&gt;Read about SCIT - Self Cleansing Intrusion Tolerance &lt;a target=&quot;_blank&quot; href=&quot;http://cs.gmu.edu/~asood/scit/&quot;&gt;here&lt;/a&gt;&lt;br /&gt;&lt;p /&gt; &lt;br /&gt;
In&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Tue, 13 May 2008 12:13:14 -0700</pubDate>
    <guid isPermaLink="false">http://www.lawrencepingree.com/archives/92-guid.html</guid>
    
</item>
<item>
    <title>Identity theft and Renault website</title>
    <link>http://www.lawrencepingree.com/archives/89-Identity-theft-and-Renault-website.html</link>
            <category>Security</category>
    
    <comments>http://www.lawrencepingree.com/archives/89-Identity-theft-and-Renault-website.html#comments</comments>
    <wfw:comment>http://www.lawrencepingree.com/wfwcomment.php?cid=89</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.lawrencepingree.com/rss.php?version=2.0&amp;type=comments&amp;cid=89</wfw:commentRss>
    

    <author>nospam@example.com (Lawrence Pingree)</author>
    <content:encoded>
    I hate to say it but it bothers me when people send the wrong message to the public regarding identity theft. Simply having someone&#039;s name, address and phone number is not enough to perform identity theft. I believe the media has a tendancy to embelish the idea of stealing someone&#039;s information and then having free reign to charge it up on the person&#039;s credit as &lt;a href=&quot;http://www.theregister.co.uk/2008/05/08/renault_compo_data_leak/&quot; target=&quot;_blank&quot;&gt;this article&lt;/a&gt; suggests. The article says it can be used to perform phishing which is accurate and can help someone perform such a technique, but the data in question that has been so called &amp;quot;leaked&amp;quot; is public data with possibly the exception of the email address. Just trying to keep us all honest.   
    </content:encoded>

    <pubDate>Thu, 08 May 2008 11:30:28 -0700</pubDate>
    <guid isPermaLink="false">http://www.lawrencepingree.com/archives/89-guid.html</guid>
    
</item>
<item>
    <title>Social Security and Personal information on Riverside Court</title>
    <link>http://www.lawrencepingree.com/archives/88-Social-Security-and-Personal-information-on-Riverside-Court.html</link>
            <category>Security</category>
    
    <comments>http://www.lawrencepingree.com/archives/88-Social-Security-and-Personal-information-on-Riverside-Court.html#comments</comments>
    <wfw:comment>http://www.lawrencepingree.com/wfwcomment.php?cid=88</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.lawrencepingree.com/rss.php?version=2.0&amp;type=comments&amp;cid=88</wfw:commentRss>
    

    <author>nospam@example.com (Lawrence Pingree)</author>
    <content:encoded>
    &lt;br /&gt;
I was just reading an &lt;a target=&quot;_blank&quot; href=&quot;http://www.networkworld.com/news/2008/050208-privacy-advocates-court-posting-personal.html?fsrc=rss-security&quot;&gt;article&lt;/a&gt; on the Riverside court, essentially anything disclosed in a court case is considered a matter of public record in california courts. So its important that people know that what they disclose to courts gets input into imaging software or databases and sometimes (&lt;a target=&quot;_blank&quot; href=&quot;http://www.networkworld.com/news/2008/050208-privacy-advocates-court-posting-personal.html?fsrc=rss-security&quot;&gt;like this case&lt;/a&gt;) can be viewed online. My suggestion to the public is to ensure that your documents obfiscate certain personal information that can be used incorrectly when obtained. I also would encourage local officials to pass legislation to bar courts from posting documents containing PII onto the internet. Its bad enough that we have a PII problem on system&#039;s within corporations, but having the court disclose it is a breach that should be treated the same way as a corporate breach. Of course this makes too much sense for regulators.&lt;br /&gt;
  
    </content:encoded>

    <pubDate>Fri, 02 May 2008 13:29:12 -0700</pubDate>
    <guid isPermaLink="false">http://www.lawrencepingree.com/archives/88-guid.html</guid>
    
</item>
<item>
    <title>Trust</title>
    <link>http://www.lawrencepingree.com/archives/86-Trust.html</link>
            <category>Security</category>
    
    <comments>http://www.lawrencepingree.com/archives/86-Trust.html#comments</comments>
    <wfw:comment>http://www.lawrencepingree.com/wfwcomment.php?cid=86</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.lawrencepingree.com/rss.php?version=2.0&amp;type=comments&amp;cid=86</wfw:commentRss>
    

    <author>nospam@example.com (Lawrence Pingree)</author>
    <content:encoded>
    &lt;br /&gt;
  Main Entry:&lt;div class=&quot;entry misc&quot;&gt;&lt;dl&gt;&lt;dd class=&quot;hwrd&quot;&gt;&lt;span class=&quot;variant&quot;&gt;&lt;sup&gt;1&lt;/sup&gt;trust&lt;/span&gt; &lt;/dd&gt;&lt;dt class=&quot;pron&quot;&gt;Pronunciation:&lt;/dt&gt;&lt;dd class=&quot;pron&quot;&gt;&lt;br /&gt;
      &lt;span class=&quot;pronchars&quot;&gt;\&lt;span class=&quot;unicode&quot;&gt;?&lt;/span&gt;tr?st\&lt;/span&gt;&lt;br /&gt;
    &lt;/dd&gt;&lt;dt class=&quot;func&quot;&gt;Function:&lt;/dt&gt;&lt;dd class=&quot;func&quot;&gt;&lt;em&gt;noun&lt;/em&gt; &lt;/dd&gt;&lt;dt class=&quot;ety&quot;&gt;Etymology:&lt;/dt&gt;&lt;dd class=&quot;ety&quot;&gt;Middle English, probably of Scandinavian origin; akin to Old Norse &lt;em&gt;traust&lt;/em&gt; trust; akin to Old English &lt;em&gt;tr?owe&lt;/em&gt; faithful — more at &lt;a class=&quot;lookup&quot; href=&quot;http://www.merriam-webster.com/dictionary/true&quot;&gt;true&lt;/a&gt;&lt;/dd&gt;&lt;dt class=&quot;date&quot;&gt;Date:&lt;/dt&gt;&lt;dd class=&quot;date&quot;&gt;13th century&lt;/dd&gt;&lt;/dl&gt;&lt;br /&gt;
  &lt;div class=&quot;defs&quot;&gt;&lt;span class=&quot;sense_break&quot;&gt;&lt;span class=&quot;sense_label start&quot;&gt;1 a&lt;/span&gt;&lt;span class=&quot;sense_content&quot;&gt;&lt;strong&gt;:&lt;/strong&gt; assured reliance on the character, ability, strength, or truth of someone or something&lt;/span&gt; &lt;span class=&quot;sense_label&quot;&gt;b&lt;/span&gt;&lt;span class=&quot;sense_content&quot;&gt;&lt;strong&gt;:&lt;/strong&gt; one in which confidence is placed&lt;/span&gt;&lt;span class=&quot;sense_break&quot;&gt;&lt;span class=&quot;sense_label start&quot;&gt;&lt;br /&gt;2 &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;sense_break&quot;&gt;&lt;span class=&quot;sense_break&quot;&gt;&lt;span class=&quot;sense_label start&quot;&gt;a&lt;/span&gt;&lt;span class=&quot;sense_content&quot;&gt;&lt;strong&gt;:&lt;/strong&gt; dependence on something future or contingent &lt;strong&gt;:&lt;/strong&gt; &lt;a class=&quot;lookup&quot; href=&quot;http://www.merriam-webster.com/dictionary/hope&quot;&gt;hope&lt;/a&gt;&lt;/span&gt; &lt;span class=&quot;sense_label&quot;&gt;b&lt;/span&gt;&lt;span class=&quot;sense_content&quot;&gt;&lt;strong&gt;:&lt;/strong&gt; reliance on future payment for property (as merchandise) delivered &lt;strong&gt;:&lt;/strong&gt; &lt;a class=&quot;lookup&quot; href=&quot;http://www.merriam-webster.com/dictionary/credit&quot;&gt;credit&lt;/a&gt;  &lt;span class=&quot;vi&quot;&gt;&amp;lt;bought furniture on &lt;em&gt;trust&lt;/em&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;sense_break&quot;&gt;&lt;span class=&quot;sense_label start&quot;&gt;&lt;br /&gt;3 a&lt;/span&gt;&lt;span class=&quot;sense_content&quot;&gt;&lt;strong&gt;:&lt;/strong&gt; a property interest held by one person for the benefit of another&lt;/span&gt; &lt;span class=&quot;sense_label&quot;&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;sense_break&quot;&gt;&lt;span class=&quot;sense_break&quot;&gt;&lt;span class=&quot;sense_break&quot;&gt;&lt;span class=&quot;sense_label&quot;&gt;b&lt;/span&gt;&lt;span class=&quot;sense_content&quot;&gt;&lt;strong&gt;:&lt;/strong&gt; a combination of firms or corporations formed by a legal agreement&lt;/span&gt;&lt;span class=&quot;sense_content&quot;&gt;; &lt;em&gt;especially&lt;/em&gt;&lt;/span&gt; &lt;span class=&quot;sense_content&quot;&gt;&lt;strong&gt;:&lt;/strong&gt; one that reduces or threatens to reduce competition&lt;/span&gt;&lt;span class=&quot;sense_break&quot;&gt;&lt;span class=&quot;sense_label start&quot;&gt;&lt;br /&gt;4&lt;/span&gt;&lt;em&gt;archaic&lt;/em&gt; &lt;span class=&quot;sense_content&quot;&gt;&lt;strong&gt;:&lt;/strong&gt; &lt;a class=&quot;lookup&quot; href=&quot;http://www.merriam-webster.com/dictionary/trustworthiness&quot;&gt;trustworthiness&lt;/a&gt;&lt;/span&gt;&lt;span class=&quot;sense_break&quot;&gt;&lt;span class=&quot;sense_label&quot;&gt;&lt;br /&gt;5 a &lt;/span&gt;&lt;span&gt;&lt;span class=&quot;sense_label subsense&quot;&gt;(1)&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;sense_content&quot;&gt;&lt;strong&gt;:&lt;/strong&gt; a charge or duty imposed in faith or confidence or as a condition of some relationship&lt;/span&gt; &lt;span&gt;&lt;span class=&quot;sense_label subsense&quot;&gt;(2)&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;sense_content&quot;&gt;&lt;strong&gt;:&lt;/strong&gt; something committed or entrusted to one to be used or cared for in the interest of another&lt;/span&gt; &lt;span class=&quot;sense_label&quot;&gt;b&lt;/span&gt;&lt;span class=&quot;sense_content&quot;&gt;&lt;strong&gt;:&lt;/strong&gt; responsible charge or office&lt;/span&gt; &lt;span class=&quot;sense_label&quot;&gt;c&lt;/span&gt;&lt;span class=&quot;sense_content&quot;&gt;&lt;strong&gt;:&lt;/strong&gt; &lt;a class=&quot;lookup&quot; href=&quot;http://www.merriam-webster.com/dictionary/care&quot;&gt;care&lt;/a&gt;,   &lt;a class=&quot;lookup&quot; href=&quot;http://www.merriam-webster.com/dictionary/custody&quot;&gt;custody&lt;/a&gt;  &lt;span class=&quot;vi&quot;&gt;&amp;lt;the child committed to her &lt;em&gt;trust&lt;/em&gt;&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
  &lt;div class=&quot;run_on&quot;&gt; — &lt;span class=&quot;variant&quot;&gt;in trust&lt;/span&gt;   &lt;div class=&quot;defs variant&quot;&gt;&lt;span class=&quot;sense_content&quot;&gt;&lt;strong&gt;:&lt;/strong&gt; in the care or possession of a trustee&lt;br /&gt;&lt;br /&gt;SOURCE: &lt;/span&gt;&lt;a href=&quot;http://www.merriam-webster.com/info/copyright.htm&quot;&gt;Merriam-Webster, Incorporated&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;defs variant&quot;&gt;&lt;span class=&quot;sense_content&quot;&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;br /&gt;
  
    </content:encoded>

    <pubDate>Thu, 24 Apr 2008 22:36:20 -0700</pubDate>
    <guid isPermaLink="false">http://www.lawrencepingree.com/archives/86-guid.html</guid>
    
</item>
<item>
    <title>Using credit statistics to determine who is most trustworthy</title>
    <link>http://www.lawrencepingree.com/archives/85-Using-credit-statistics-to-determine-who-is-most-trustworthy.html</link>
            <category>Security</category>
    
    <comments>http://www.lawrencepingree.com/archives/85-Using-credit-statistics-to-determine-who-is-most-trustworthy.html#comments</comments>
    <wfw:comment>http://www.lawrencepingree.com/wfwcomment.php?cid=85</wfw:comment>

    <slash:comments>1</slash:comments>
    <wfw:commentRss>http://www.lawrencepingree.com/rss.php?version=2.0&amp;type=comments&amp;cid=85</wfw:commentRss>
    

    <author>nospam@example.com (Lawrence Pingree)</author>
    <content:encoded>
    I was cruising different ways to invest and I came across some &lt;a href=&quot;http://www.ericscc.com/index.php?page=borrower_segments&quot; target=&quot;_New&quot;&gt;statistics&lt;/a&gt; for a service that I use to lend people money. The statistics show the different types of job categories, the amount lent to the categories and the % late each of them are. The thing that I found interesting is that Clergy and Lawyers were the least likely to be late on loans. The stats are taken from &lt;a href=&quot;http://www.prosper.com/referrals/borrower.aspx?referrer=geekguy&amp;utm_source=referrer-geekguy&amp;utm_medium=referral-button&amp;utm_content=borrower_dark-120x60&amp;utm_campaign=referrals-borrower&quot; target=&quot;_New&quot;&gt;prosper.com&lt;/a&gt;, a P2P lending service. It then occurred to me... is it possible to tell how trustworthy a person is by the way that they pay their bills? I mean, isn&#039;t a loan a promise to repay a debt, so if we were to expand this somewhat to trust, is it such a stretch? I&#039;m sure some would disagree, but interesting none the less. Check the &lt;a href=&quot;http://www.ericscc.com/index.php?page=borrower_segments&quot; target=&quot;_New&quot;&gt;following stats&lt;/a&gt; and make your own conclusions.   
    </content:encoded>

    <pubDate>Mon, 07 Apr 2008 21:46:25 -0700</pubDate>
    <guid isPermaLink="false">http://www.lawrencepingree.com/archives/85-guid.html</guid>
    
</item>
<item>
    <title>Consumers on the hook for security in UK banking</title>
    <link>http://www.lawrencepingree.com/archives/84-Consumers-on-the-hook-for-security-in-UK-banking.html</link>
            <category>Security</category>
    
    <comments>http://www.lawrencepingree.com/archives/84-Consumers-on-the-hook-for-security-in-UK-banking.html#comments</comments>
    <wfw:comment>http://www.lawrencepingree.com/wfwcomment.php?cid=84</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.lawrencepingree.com/rss.php?version=2.0&amp;type=comments&amp;cid=84</wfw:commentRss>
    

    <author>nospam@example.com (Lawrence Pingree)</author>
    <content:encoded>
    Well, I knew it was coming but now it has come and we&#039;re entering a new phase of accountability at the consumer endpoint. Now consumer&#039;s  in the UK are being held accountable to have properly updated AV, Firewalls and Anti-Spyware... What a concept! I&#039;m assuming this will soon be coming to the USA. I&#039;m fairly certain that any lawsuit involving an end consumer would be defensible in this way in the USA already but I&#039;m not a lawyer. I&#039;m also not sure if any bank wants this type of PR yet, but we&#039;ll see. Check the article &lt;a href=&quot;http://www.theregister.co.uk/2008/04/04/banking_code_2008/&quot; target=_New&gt;here&lt;/a&gt;  
    </content:encoded>

    <pubDate>Mon, 07 Apr 2008 06:11:02 -0700</pubDate>
    <guid isPermaLink="false">http://www.lawrencepingree.com/archives/84-guid.html</guid>
    
</item>
<item>
    <title>Assembly Bill 1298 Extends California's SB1386</title>
    <link>http://www.lawrencepingree.com/archives/83-Assembly-Bill-1298-Extends-Californias-SB1386.html</link>
            <category>Security</category>
    
    <comments>http://www.lawrencepingree.com/archives/83-Assembly-Bill-1298-Extends-Californias-SB1386.html#comments</comments>
    <wfw:comment>http://www.lawrencepingree.com/wfwcomment.php?cid=83</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://www.lawrencepingree.com/rss.php?version=2.0&amp;type=comments&amp;cid=83</wfw:commentRss>
    

    <author>nospam@example.com (Lawrence Pingree)</author>
    <content:encoded>
    I&#039;m not sure if everyone is aware of this, but in January, SB1386 was extended to include medical information and medical insurance information breached requires notification. A copy of the law is located &lt;a href=&quot;http://www.leginfo.ca.gov/pub/07-08/bill/asm/ab_1251-1300/ab_1298_bill_20071014_chaptered.pdf&quot; target=_New&gt;here&lt;/a&gt; coupled with other notification laws, doing business in California means that businesses must be more responsible than ever, requirements that should have existed for years in my opinion.&lt;br /&gt;
&lt;br /&gt;
  
    </content:encoded>

    <pubDate>Mon, 07 Apr 2008 05:45:05 -0700</pubDate>
    <guid isPermaLink="false">http://www.lawrencepingree.com/archives/83-guid.html</guid>
    
</item>
<item>
    <title>Interesting HIPAA Study on Dentists</title>
    <link>http://www.lawrencepingree.com/archives/82-Interesting-HIPAA-Study-on-Dentists.html</link>
            <category>Security</category>
    
    <comments>http://www.lawrencepingree.com/archives/82-Interesting-HIPAA-Study-on-Dentists.html#comments</comments>
    <wfw:comment>http://www.lawrencepingree.com/wfwcomment.php?cid=82</wfw:comment>

    <slash:comments>1</slash:comments>
    <wfw:commentRss>http://www.lawrencepingree.com/rss.php?version=2.0&amp;type=comments&amp;cid=82</wfw:commentRss>
    

    <author>nospam@example.com (Lawrence Pingree)</author>
    <content:encoded>
    An interesting survey of 18 dentists was conducted to assess the compliance to HIPAA. The Health Insurance Portability and Accountability act of 1996 defines some of the protections necessary for patient confidentiality and privacy. The dentists were given 10 compliance questions by Darrell Pruitt D.D.S. &lt;br /&gt;
&lt;br /&gt;
Quote:&lt;br /&gt;
&quot;The range of compliancy was found to be from 0% for the requirement of a written workstation policy to 88% for that of password security. The average was 49%, meaning that less than half of the requirements are being respected by the dentists in this sample.&quot;&lt;br /&gt;
&lt;br /&gt;
Read the article &lt;a href=&quot;http://dentistcom.wordpress.com/2008/04/06/the-hipaa-rule-and-dentistry-a-survey-of-dentists-%E2%80%93-a-pilot-study/&quot; target=_New&gt;here&lt;/a&gt;  
    </content:encoded>

    <pubDate>Mon, 07 Apr 2008 05:20:46 -0700</pubDate>
    <guid isPermaLink="false">http://www.lawrencepingree.com/archives/82-guid.html</guid>
    
</item>

</channel>
</rss>