<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CW San Diego &#187; Security</title>
	<atom:link href="http:///category/security/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>The Global Ink &#38; Toner Experts</description>
	<lastBuildDate>Thu, 18 Nov 2010 23:53:08 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.2</generator>
		<item>
		<title>Fax machines can expose personal information</title>
		<link>/2010/11/09/fax-machines-can-expose-personal-information/</link>
		<comments>/2010/11/09/fax-machines-can-expose-personal-information/#comments</comments>
		<pubDate>Tue, 09 Nov 2010 20:52:56 +0000</pubDate>
		<dc:creator>CW</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[fax]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[Personally identifiable information]]></category>

		<guid isPermaLink="false">/?p=1687</guid>
		<description><![CDATA[We have quite a few customers who use fax machine that take the type of film roll shown below. Film is a fairly common medium used in fax machines. There are machines that use ink or toner cartridges but they are less common. Panasonic and Brother both still use film in their fax machines. The [...]]]></description>
			<content:encoded><![CDATA[<p>We have quite a few customers who use fax machine that take the type of film roll shown below. <a rel="attachment wp-att-1688" href="/2010/11/09/fax-machines-can-expose-personal-information/fax_film/"><img class="alignright size-medium wp-image-1688" title="fax_film" src="/wp-content/uploads/2010/11/fax_film-300x144.jpg" alt="" width="300" height="144" /></a></p>
<p>Film is a fairly common medium used in fax machines. There are machines that use ink or toner cartridges but they are less common. Panasonic and Brother both still use film in their fax machines.</p>
<p>The film rolls are convenient and easy to install. You can either buy them as a single roll mounted on a frame or two rolls with no frame. The frames are reusable, so once you&#8217;ve purchased a frame and roll combo save the frame and buy the 2-pack from then on. This is more economical since both the one-roll-plus-frame and the two-roll pack are usually the same price.</p>
<p>There is one serious problem with film fax machines that users of ink or laser-based fax machines don&#8217;t have to worry about, and that&#8217;s the potential of these films to compromise your personal information.</p>
<p>Think of this film as a roll of carbon paper. Those of you too young to remember what carbon paper is, ask someone from my generation. While fax film isn&#8217;t composed of the same materials as carbon paper, the manner in which it transfers an image onto paper is nearly identical. The black coating on the film is transfered to the paper to create the faxed image or words. This means that everywhere the coating has been transfered to the paper the clear film backing is exposed. This produces what in effect is a negative image of every fax your machine has printed out. Read from the back the film preserves a perfectly readable copy of each printed fax. If you have ever exchanged faxes with your mortgage broker or bank your account numbers, Social Security number, address, phone number, the names of your family members, all sorts of personal information will be easily readable on the film. Fished out of your trash, this would be a goldmine of information to a would-be identity thief.</p>
<p>We are still looking into methods to destroy these rolls of film once they have been used completely. So far we haven&#8217;t come up with a fool-proof method. If you have any suggestions we&#8217;d love to hear them in the comments. For now our best advice is to keep the used rolls in a bag or shoebox, stored away from the prying eyes of crooks.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://boxofmeat.net/post/1027279148/faxphish">threatpost: Anti-Phishing Group Targeting Fax-Based Scams</a> (boxofmeat.net)</li>
<li class="zemanta-article-ul-li"><a href="http://www.brighthub.com/environment/green-computing/articles/85336.aspx">Thermal vs. Laser Printing: Which is Greener?</a> (brighthub.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Enhanced by Zemanta" href="http://www.zemanta.com/"><img class="zemanta-pixie-img" style="border: none; float: right;" src="http://img.zemanta.com/zemified_e.png?x-id=cc7fdf1c-bb2a-44b2-a0fd-bdf5688d7232" alt="Enhanced by Zemanta" /></a><span class="zem-script more-related more-info pretty-attribution"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>/2010/11/09/fax-machines-can-expose-personal-information/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Digital copiers put personal information at risk</title>
		<link>/2010/04/23/digital-copiers-put-personal-information-at-risk/</link>
		<comments>/2010/04/23/digital-copiers-put-personal-information-at-risk/#comments</comments>
		<pubDate>Fri, 23 Apr 2010 17:50:55 +0000</pubDate>
		<dc:creator>CW</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[CBS News]]></category>
		<category><![CDATA[copiers]]></category>
		<category><![CDATA[digital copiers]]></category>
		<category><![CDATA[hard drive]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[National Security Agency]]></category>

		<guid isPermaLink="false">http://cwsandiego.com/?p=644</guid>
		<description><![CDATA[We&#8217;ve mentioned on our blog how fax machines that use a film roll, primarily Brother and Panasonic fax machines that use film in place of a laser or ink cartridge, keep what is essentially a carbon copy of every fax that goes through the machine. This can put personal information, both yours and your customer&#8217;s, [...]]]></description>
			<content:encoded><![CDATA[<p>We&#8217;ve <a href="http://cwsandiego.com/2009/12/30/423/">mentioned  on our blog</a> how fax machines that use a film roll, primarily Brother  and Panasonic fax machines that use film in place of a laser or ink  cartridge, keep what is essentially a carbon copy of every fax that goes  through the machine. This can put personal information, both yours and  your customer&#8217;s, at risk of exposure to identity thieves.</p>
<p>Now  CBS News shows how digital copiers can pose a similar risk. <img class="alignright" title="digital copier" src="http://cwsandiego.com/wp-content/uploads/2010/01/digitalcopier.jpg" alt="" width="188" height="200" /></p>
<blockquote><p>At a warehouse in New Jersey, 6,000 used  copy machines sit ready to be sold. CBS News chief investigative  correspondent Armen Keteyian reports almost every one of them holds a  secret.</p>
<p>Nearly every digital copier built since 2002 contains a  hard drive &#8211; like the one on your personal computer &#8211; storing an image  of every document copied, scanned, or emailed by the machine.</p>
<p>In  the process, it&#8217;s turned an office staple into a digital time-bomb  packed with highly-personal or sensitive data.</p>
<p>If you&#8217;re in the  <a class="zem_slink freebase/en/identity_theft" title="Identity Theft" rel="wikinvest" href="http://www.wikinvest.com/concept/Identity_Theft">identity theft</a> business it seems this would be a pot of gold.</p>
<p>&#8220;The  type of information we see on these machines with the social security  numbers, birth certificates, bank records, income tax forms,&#8221; John  Juntunen said, &#8220;that information would be very valuable.&#8221;</p>
<p>&#8220;Nobody  wants to step up and say, &#8216;we see the problem, and we need to solve  it,&#8217;&#8221; Juntunen said.</p>
<p>This past February, CBS News went with  Juntunen to a warehouse in New Jersey, one of 25 across the country, to  see how hard it would be to buy a used copier loaded with documents. It  turns out &#8230; it&#8217;s pretty easy.</p>
<p>Juntunen picked four machines  based on price and the number of pages printed. In less than two hours  his selections were packed and loaded onto a truck. The cost? About $300  each.</p>
<p>Until we unpacked and plugged them in, we had no idea  where the copiers came from or what we&#8217;d find.</p>
<p>We didn&#8217;t even  have to wait for the first one to warm up. One of the copiers had  documents still on the copier glass, from the Buffalo, N.Y., Police Sex  Crimes Division.</p>
<p>It took Juntunen just 30 minutes to pull the  hard drives out of the copiers. Then, using a forensic software program  available for free on the Internet, he ran a scan &#8211; downloading tens of  thousands of documents in less than 12 hours.</p>
<p>The results were  stunning: from the sex crimes unit there were detailed domestic violence  complaints and a list of wanted sex offenders. On a second machine from  the Buffalo Police Narcotics Unit we found a list of targets in a major  drug raid.</p>
<p>The third machine, from a New York construction  company, spit out design plans for a building near Ground Zero in  Manhattan; 95 pages of pay stubs with names, addresses and social  security numbers; and $40,000 in copied checks.</p>
<p>But it wasn&#8217;t  until hitting &#8220;print&#8221; on the fourth machine &#8211; from Affinity Health Plan,  a New York insurance company, that we obtained the most disturbing  documents: 300 pages of individual medical records. They included  everything from drug prescriptions, to blood test results, to a cancer  diagnosis. A potentially serious breach of federal privacy law.</p>
<p>&#8220;You&#8217;re  talking about potentially ruining someone&#8217;s life,&#8221; said Ira Winkler.  &#8220;Where they could suffer serious social repercussions.&#8221;</p>
<p>Winkler  is a former analyst for the National Security Agency and a leading  expert on digital security.</p>
<p>&#8220;You have to take some basic  responsibility and know that these copiers are actually computers that  need to be cleaned up,&#8221; Winkler said.</p></blockquote>
<p>If you own a digital  copier you owe it to yourself and your customers to <a href="http://www.cbsnews.com/stories/2010/04/19/eveningnews/main6412439.shtml">read the full article</a>. Don&#8217;t let your electronics  compromise your security.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://ducknetweb.blogspot.com/2010/04/409000-members-notified-of-potential.html">409,000 Members Notified of Potential Security Breach &#8211; Copy Machine Hard Drive</a> (ducknetweb.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://minx.cc/?post=300848">Oh Goody, A New Security Threat</a> (minx.cc)</li>
<li class="zemanta-article-ul-li"><a href="http://feldmanfile.blogspot.com/2010/04/copiers-make-more-copies-than-you-think.html">Copiers make more copies than you think</a> (feldmanfile.blogspot.com)</li>
<li class="zemanta-article-ul-li"><a href="http://www.cbsnews.com/8301-31727_162-20002830-10391695.html">The Danger of Digital Copiers &#8211; Who Knew?</a> (cbsnews.com)</li>
<li class="zemanta-article-ul-li"><a href="http://news.cnet.com/8301-1009_3-20002904-83.html?part=rss&amp;subj=news&amp;tag=2547-1_3-0-20">Second-hand copiers can spill secrets</a> (news.cnet.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/51d643dc-d6ff-471c-9776-486f7b717ef0/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=51d643dc-d6ff-471c-9776-486f7b717ef0" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related more-info pretty-attribution"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>/2010/04/23/digital-copiers-put-personal-information-at-risk/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Recycle Safely</title>
		<link>/2009/12/30/423/</link>
		<comments>/2009/12/30/423/#comments</comments>
		<pubDate>Wed, 30 Dec 2009 23:57:26 +0000</pubDate>
		<dc:creator>CW</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[destruction]]></category>
		<category><![CDATA[Hard disk drive]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[Paper shredder]]></category>
		<category><![CDATA[Recycling]]></category>

		<guid isPermaLink="false">http://cwsandiego.com/?p=423</guid>
		<description><![CDATA[Did Santa bring you a new fax machine or computer for Christmas? Are you planning on recycling or donating your old machine? Here are a couple of security-related issues for your consideration. Fax machines that use a film, as opposed to an ink or toner cartridge, retain an image of every fax the machine has [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img" style="margin: 1em; display: block;">
<div class="wp-caption alignright" style="width: 220px"><a href="http://commons.wikipedia.org/wiki/Image:Carbon_paper.jpg"><img class=" " title="carbon paper" src="http://upload.wikimedia.org/wikipedia/commons/thumb/f/f7/Carbon_paper.jpg/300px-Carbon_paper.jpg" alt="carbon paper" width="210" height="265" /></a><p class="wp-caption-text">Image via Wikipedia</p></div>
</div>
<p>Did Santa bring you a new fax machine or computer for Christmas? Are you planning on recycling or donating your old machine?</p>
<p>Here are a couple of security-related issues for your consideration.</p>
<p>Fax machines that use a film, as opposed to an ink or toner cartridge, retain an image of every fax the machine has reproduced. Think of the film as a long roll of carbon paper (those of you, like me, old enough to remember carbon paper). A perfectly readable image of every received fax is preserved on that roll of film. A discarded fax film is a goldmine for identity thieves.</p>
<p>We strongly recommend you destroy the used fax film. However, we have not yet identified the most effective way to do that. I’m not sure that feeding it through a paper shredder would work; in fact it may jam the cutting teeth of the shredder. Burning it is probably not an option, at least in the incorporated parts of San Diego. If your business uses the services of a document destruction company, I would suggest adding your fax roll to the bags of documents awaiting destruction. If that is not an option, perhaps soaking the roll of film in a can of gasoline or bleach will make it unreadable.</p>
<p>If anyone can offer a better or more practical solution, please let us all know in the comments.</p>
<p>It is perhaps more obvious that if you plan on recycling your old computer, you should first remove and then destroy the hard drive, unless you plan on using that drive again in your new computer or as an external drive (cases for this can be purchased from retailers like geeks.com for less than $20).</p>
<p>What may not be as obvious is that simply deleting the content on your hard drive isn’t sufficient. It’s not all that hard to reconstruct deleted data from a hard drive.</p>
<p>This is because when you delete something, you aren’t actually erasing that content. You’re merely erasing the marker that tells the operating system where to find that data on the disk. It’s as if you removed all the house numbers from a block of houses. The houses are still there but an individual house would now be hard to find if all you had to go on was the address. Forensic software can even recover data that has been over-written. There are software companies that sell applications that promise to delete your data “to military specifications”. Sounds pretty good, but the military doesn’t have a single set of specifications for data destruction.</p>
<p style="padding-left: 30px;">• Clearing: Eradicating data to the extent that information cannot be retrieved through normal operation but may be salvaged in a laboratory.</p>
<p style="padding-left: 30px;">•Sanitizing/purging: Removing data to a degree that it is beyond the reach of all ordinary and most laboratory recovery methods. This includes degaussing, which employs a special coil tool to demagnetize a drive&#8217;s magnetic media, scrambling all contents in the disk.</p>
<p style="padding-left: 30px;">•Destroying: Disintegrate, incinerate, pulverize, shred, or melt.</p>
<p>Software and/or hardware can perform either of the first two types of deletion, but why spend $30 or more when you can perform that last type of data destruction yourself? All you need is a hammer. The other advantage to this technique is that it’s a great stress reliever. Remove the hard drive from the computer, place it on concrete or some other resistant material and smash the case as much as you can. Your goal is to break the disks inside the case. That should make the drive completely unreadable by even the most advanced forensic software. Then the drive should be safe to recycle with other electronics.</p>
<p>One last suggestion for protecting your information as 2010 rolls around: I know several people who celebrate New Years by shredding all their old paperwork, receipts, bills and correspondence. They keep 3-5 years of archived paperwork and everything older gets shredded. But even shredded paper can be reconstructed by someone determined to do so. If you throw shredded documents out in the trash, consider pouring some liquid into the bag with it to cause the ink to run and make each strip harder to read, or use that bag for used kitty litter. Put the trash out just before pickup to deny someone the chance to get access to it. In most states, once you put your trash can on the curb you no longer have property rights over it. Anyone can go through your trash looking for personal data that will let them borrow your identity.</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://consumerist.com/5360714/grab-your-old-statements-were-going-to-the-shred+a+thon">Grab Your Old Statements, We&#8217;re Going To The Shred-A-Thon! [Identity Theft]</a> (consumerist.com)</li>
<li class="zemanta-article-ul-li"><a href="http://r.zemanta.com/?u=http%3A//www.newswire.ca/en/releases/archive/October2009/28/c3457.html&amp;a=8994884&amp;rid=8562d40d-2f5d-4ce3-a251-6fd4b21f3e6e&amp;e=fac16b93991f718eef6da2dbcf1f7436">PostNet partners with Shred-it to provide industry-leading document destruction business solutions</a> (newswire.ca)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/8562d40d-2f5d-4ce3-a251-6fd4b21f3e6e/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=8562d40d-2f5d-4ce3-a251-6fd4b21f3e6e" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>/2009/12/30/423/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Malware alert: Gumblar</title>
		<link>/2009/06/04/malware-alert-gumblar/</link>
		<comments>/2009/06/04/malware-alert-gumblar/#comments</comments>
		<pubDate>Thu, 04 Jun 2009 21:52:34 +0000</pubDate>
		<dc:creator>CW</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[Google search]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://cwsandiego.com/?p=232</guid>
		<description><![CDATA[Image via Wikipedia More than 1,500 Web Sites have been Attacked. Severity: High Risk What is it? Gumblar is currently targeting users of IE and Google search, delivering malware through compromised sites that infect a user&#8217;s PC and subsequently intercepts traffic between the user and the visited sites. This means that once infected, anything the [...]]]></description>
			<content:encoded><![CDATA[<div class="zemanta-img zemanta-action-dragged" style="margin: 1em; display: block;">
<div>
<dl class="wp-caption alignright" style="width: 266px;">
<dt class="wp-caption-dt"><a href="http://en.wikipedia.org/wiki/Image:Internet_Explorer_7_Logo.png"><img title="Windows Internet Explorer" src="http://upload.wikimedia.org/wikipedia/en/1/10/Internet_Explorer_7_Logo.png" alt="Windows Internet Explorer" width="256" height="256" /></a></dt>
<dd class="wp-caption-dd zemanta-img-attribution" style="font-size: 0.8em;">Image via <a href="http://en.wikipedia.org/wiki/Image:Internet_Explorer_7_Logo.png">Wikipedia</a></dd>
</dl>
</div>
</div>
<p><em>More than 1,500 Web Sites have been Attacked.</em><br />
Severity: <span style="text-decoration: underline;">High Risk</span></p>
<p><strong>What is it?</strong><br />
Gumblar is currently targeting users of IE and Google search, delivering <a class="zem_slink" title="Malware" rel="wikipedia" href="http://en.wikipedia.org/wiki/Malware">malware</a> through compromised sites that infect a user&#8217;s PC and subsequently intercepts traffic between the user and the visited sites. This means that once infected, anything the victim types could be monitored and used to commit <a class="zem_slink" title="Identity Theft" rel="wikinvest" href="http://www.wikinvest.com/concept/Identity_Theft">identity theft</a>, such as stealing credit card numbers, passwords or other sensitive data. Visitors encountering the compromised website also risk having their subsequent search results replaced with links that point to other malicious websites. The malware can also steal <a class="zem_slink" title="File Transfer Protocol" rel="wikipedia" href="http://en.wikipedia.org/wiki/File_Transfer_Protocol">FTP</a> credentials from the victim&#8217;s computer and use them to infect more sites, thus increasing the spread of this threat.</p>
<p><strong>Who is at risk?</strong><br />
Users of <a class="zem_slink" title="Internet Explorer" rel="wikipedia" href="http://en.wikipedia.org/wiki/Internet_Explorer">Internet Explorer</a> and Google&#8217;s search engine.</p>
<p><strong>Prevention</strong><br />
Make sure you anti-virus definitions are up-to-date and practice caution when sharing your personal information online. Make sure you only do so on secure sites (<em>https</em>://)</p>
<p>(information courtesy of <a href="http://www.zonealarm.com/security/en-us/home.htm?lid=en-us">Zone Alarm</a> via Gmail)</p>
<h6 class="zemanta-related-title" style="font-size: 1em;">Related articles by Zemanta</h6>
<ul class="zemanta-article-ul">
<li class="zemanta-article-ul-li"><a href="http://chris.pirillo.com/managing-your-passwords-protection-from-phishing-identity-theft/"> Managing your Passwords: Protection from Phishing / Identity Theft </a> (chris.pirillo.com)</li>
<li class="zemanta-article-ul-li"><a href="http://thenextweb.com/2009/06/04/google-serves-top-10-sites-avoid-costs/"> Google serves up the Top 10 sites to avoid at all costs </a> (thenextweb.com)</li>
</ul>
<div class="zemanta-pixie" style="margin-top: 10px; height: 15px;"><a class="zemanta-pixie-a" title="Reblog this post [with Zemanta]" href="http://reblog.zemanta.com/zemified/2c381243-0948-4bc3-b1fe-17e822d51dbf/"><img class="zemanta-pixie-img" style="border: medium none; float: right;" src="http://img.zemanta.com/reblog_e.png?x-id=2c381243-0948-4bc3-b1fe-17e822d51dbf" alt="Reblog this post [with Zemanta]" /></a><span class="zem-script more-related pretty-attribution"><script src="http://static.zemanta.com/readside/loader.js" type="text/javascript"></script></span></div>
]]></content:encoded>
			<wfw:commentRss>/2009/06/04/malware-alert-gumblar/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

