<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>But You&#039;re A Girl &#187; Security</title>
	<atom:link href="http://butyoureagirl.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://butyoureagirl.com</link>
	<description>Technology Consultant With A Heart</description>
	<lastBuildDate>Wed, 18 Aug 2010 15:20:01 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Leaving Facebook: Step #2 Deactivate Account</title>
		<link>http://butyoureagirl.com/2010/05/24/leaving-facebook-step-2-deactivate-account/</link>
		<comments>http://butyoureagirl.com/2010/05/24/leaving-facebook-step-2-deactivate-account/#comments</comments>
		<pubDate>Tue, 25 May 2010 05:59:07 +0000</pubDate>
		<dc:creator>Adria Richards</dc:creator>
				<category><![CDATA[Privacy Issues]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[You Vote]]></category>
		<category><![CDATA[Your Data]]></category>

		<guid isPermaLink="false">http://butyoureagirl.com/2010/05/24/leaving-facebook-step-2-deactivate-account/</guid>
		<description><![CDATA[Following Jason Calacanis&#8217; call to action, I am deactivating my Facebook account tonight (with plans to delete it later on). So far: I&#8217;ve made most of my information private, including photos I&#8217;ve run a backup using backupify I have just visited to deactivate my Facebook account facebook.com/deactivate.php Deactivate puts your account into a dormant state [...]]]></description>
			<content:encoded><![CDATA[<p>Following Jason Calacanis&#8217; call to action, I am deactivating my Facebook account tonight (with plans to delete it later on).</p>
<p>So far:</p>
<ul>
<li>I&#8217;ve made most of my information private, including photos</li>
<li>I&#8217;ve run a backup using <a rel="nofollow" href="http://backupify">backupify</a></li>
<li>I have just visited  to deactivate my Facebook account <a rel="nofollow" href="http://www.facebook.com/deactivate.php">facebook.com/deactivate.php</a> Deactivate puts your account into a dormant state but your data isn&#8217;t erased.</li>
</ul>
<p><a rel="nofollow" href="http://www.facebook.com/deactivate.php"></a><a title="photo sharing" href="http://www.flickr.com/photos/adriarichards/4638265972/"><img style="border: solid 2px #000000;" src="http://farm5.static.flickr.com/4001/4638265972_92f2c32433.jpg" alt="" /></a><br />
<em></em></p>
<p><a href="http://www.flickr.com/photos/adriarichards/4638300948/" title="Facebook | Deactivate Account by adria.richards, on Flickr"><img src="http://farm5.static.flickr.com/4011/4638300948_a816d50aaf.jpg" width="500" height="84" alt="Facebook | Deactivate Account" /></a></p>
<p>I am pasting part of Jason&#8217;s post below.  You can read the entire thing at<br />
<a rel="nofollow" href="http://calacanis.com/2010/05/21/im-deleting-my-facebook-page-today/">calacanis.com/2010/05/21/im-deleting-my-facebook-page-today/</a></p>
<p><span id="more-6404"></span></p>
<p>====================<br />
If you&#8217;re going to join me (and folks like Leo Laporte and Peter<br />
Rojas) in leaving Facebook, please consider recording yourself doing<br />
so. Post that video to YouTube saying &#8220;I deleted/deactivated my<br />
Facebook page!&#8221;</p>
<p>As we&#8217;ve discussed, there are better services for you to use from<br />
companies you can trust.</p>
<p>I suggest doing one of three things below with your Facebook account<br />
*after* you back it up.</p>
<p>[ Note: Before taking these steps, I suggest downloading your photos<br />
manually and/or trying Backupify's beta Facebook backup service--which<br />
is free. <a rel="nofollow" href="http://www.backupify.com">www.backupify.com</a>. I'm an angel investor in this amazing<br />
company.]</p>
<p>1. Just stop using Facebook: Don&#8217;t log in, don&#8217;t republish your tweets<br />
to Facebook and don&#8217;t update your status. Turn off all your photos.<br />
This is a basic step that will also get you a lot time back for the<br />
rest of your life. Try NOT logging into Facebook for three days and<br />
see how much better your life is–I&#8217;m sure it will be! Take your<br />
&#8220;Facebook time&#8221; and use it to actually ask a friend or family member<br />
how they are doing. Take the dog or your kids (or yourself!) for a<br />
walk.</p>
<p>The fact is, Facebook sends only a dozen folks to a link when I post<br />
it. Compare that to hundreds to thousands of people clicking through<br />
on Twitter (on a CTR basis Twitter is 10-20x Facebook!). Also, the<br />
content on Twitter it typically valuable to me. The content on<br />
Facebook tends to be &#8220;I&#8217;m playing this game&#8221; or someone &#8220;liking&#8221;<br />
something inane. Get off Facebook and do something more productive.<br />
Nothing important happens on Facebook–nothing.</p>
<p>2. Deactivate your account: This renders your account dormant, but you<br />
can still log in at any time and &#8220;wake it up&#8221; again. Bear in mind,<br />
your information is still stored on Facebook. They still have your<br />
data. Having said that, there is no harm in trying this either…<br />
Deactivate for the rest of the month and see what June 1st feels like<br />
after you wean yourself off the Facebook crack. Just two or three<br />
clicks and you can do it: <a rel="nofollow" href="http://www.facebook.com/deactivate.php">www.facebook.com/deactivate.php</a></p>
<img src="http://butyoureagirl.com/?ak_action=api_record_view&id=6404&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://butyoureagirl.com/2010/05/24/leaving-facebook-step-2-deactivate-account/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>iPhone Jailbreak Software Could Steal Your Passwords</title>
		<link>http://butyoureagirl.com/2009/09/19/iphone-jailbreak-software-could-steal-your-passwords/</link>
		<comments>http://butyoureagirl.com/2009/09/19/iphone-jailbreak-software-could-steal-your-passwords/#comments</comments>
		<pubDate>Sun, 20 Sep 2009 02:07:51 +0000</pubDate>
		<dc:creator>Adria Richards</dc:creator>
				<category><![CDATA[Jailbreak]]></category>
		<category><![CDATA[Protect Your Computer]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Your Data]]></category>
		<category><![CDATA[iPhone]]></category>

		<guid isPermaLink="false">http://butyoureagirl.com/?p=4009</guid>
		<description><![CDATA[it’s never a good idea to download applications and games from P2P filesharing websites because they are often put out there to “lure” people into downloading them so they can actually collect your personal information.]]></description>
			<content:encoded><![CDATA[<p>Want that shiny new iPhone software update on your iPhone?</p>
<p>Would you be willing to give all your passwords away to get it?<br />
<a title="Extraverage | iPhone Wallpapers by extraverage™, on Flickr" href="http://www.flickr.com/photos/extraverage/3192761848/"><img src="http://farm4.static.flickr.com/3107/3192761848_2ff7785f90.jpg" alt="Extraverage | iPhone Wallpapers" width="500" height="268" /></a><br />
<span id="more-4009"></span><br />
That&#8217;s what you risk by downloading iPhone firmware from unknown sources.</p>
<p>Just a reminder it&#8217;s never a good idea to download applications and games from P2P filesharing websites because they are often put out there to &#8220;lure&#8221; people into downloading them so they can actually collect your personal information.</p>
<p>I don&#8217;t see any reason why hackers would not do the same with iPhone firmware.  They could easily insert a keystroke recorder and tiny FTP server that would upload your passwords from the iPhone.</p>
<p><a href="http://www.pixiotech.com/Pixio_-_en/MobileStudio.html">MobileStudio</a> is an iPhone application that boasts a built in FTP server</p>
<p>or just get <a href="http://www.mobile-spy.com/">MobileSpy</a> which can record AND TRANSMIT the following information from your iPhone without you knowing:</p>
<ul>
<li>Incoming and Outgoing phone calls are logged and timestamped</li>
<li>Your GPS location is reported every 30 minutes</li>
<li>Every website URL you enter is captured</li>
<li>All your SMS messages are captured</li>
</ul>
<p>MobileSpy makes it sound very easy to remotely monitor someone&#8217;s iPhone</p>
<blockquote><p>After the software is setup on your phone it will record an array of phone activities and then silently upload the data to your private Mobile Spy account using the Internet. When you want to view results, simply login to the Online Control Panel from any computer and enter your username and password to proceed.</p></blockquote>
<p>This is the same reason why you don&#8217;t want to download &#8220;Free Microsoft Office&#8221; from a P2P file sharing site.  The .iso or .zip file you download may contain additional applications you don&#8217;t know about.  The iPhone Dev team warns about this too:</p>
<blockquote><p>Please do not put links to custom IPSWs in your comments, because the software in them is copyrighted by Apple.  The Dev Team motto has always been “patch, don’t pirate!”.</p></blockquote>
<p>and</p>
<blockquote><p>We do not check these links or archives and we accept no responsibility with regard to the validity of the files, or with other content these links provide or with the content that is on the linked site.</p></blockquote>
<p>So if you&#8217;re waiting to <a title="How To Upgrade Your Jailbroke iPhone to OS 3.1 [LIVE SHOW]" href="http://butyoureagirl.com/2009/09/19/upgrade-jailbroke-iphone-os-3-1-video/">jailbreak your iPhone to OS 3.1</a>, I suggest you find a friend with a Mac and have them burn a copy of their .ipsw file vs downloading one you find on Rapidshare or Megaupload.</p>
<p>Imagine waking up to find all your social media accounts with horrible things on them, your gmail account inaccessible and your bank account cleaned out.</p>
<p style="text-align: right;">Photo credit: by <a style="color: #0063dc; text-decoration: underline;" title="Link to extraverage™'s photostream" href="http://www.flickr.com/photos/extraverage/3192761848/">extraverage™</a></p>
<img src="http://butyoureagirl.com/?ak_action=api_record_view&id=4009&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://butyoureagirl.com/2009/09/19/iphone-jailbreak-software-could-steal-your-passwords/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How Neighbors Punk Your Open WiFi</title>
		<link>http://butyoureagirl.com/2009/08/13/how-neighbors-punk-your-open-wifi/</link>
		<comments>http://butyoureagirl.com/2009/08/13/how-neighbors-punk-your-open-wifi/#comments</comments>
		<pubDate>Thu, 13 Aug 2009 05:44:17 +0000</pubDate>
		<dc:creator>Adria Richards</dc:creator>
				<category><![CDATA[Adventures in Consulting]]></category>
		<category><![CDATA[Protect Your Computer]]></category>
		<category><![CDATA[Really Bad Ideas]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Wireless Security]]></category>
		<category><![CDATA[Your Data]]></category>

		<guid isPermaLink="false">http://butyoureagirl.com/?p=3530</guid>
		<description><![CDATA[My client had the unpleasant surprise to understand that her wireless connection had been open, for 2 years!  Learn how to protect your WiFi connection with WPA encryption, a router and passwords]]></description>
			<content:encoded><![CDATA[<p>My client had the unpleasant surprise to understand that her wireless connection had been open, for 2 years!</p>
<p><img src="http://farm3.static.flickr.com/2665/3815855485_453bab5da8.jpg" alt="Insecure Wireless Network with 7 &amp;quot;Visitors&amp;quot;" width="500" height="386" /><span id="more-3530"></span><br />
She had <strong>7 strangers </strong>connecting to her SBC AT&amp;T modem!
<p>Of course, I heard the standard response, &#8220;Oh, they (SBC AT&#038;T) said they were setting me up wirelessly and it would be secure&#8221;.
<p>Folks, <strong>what they don&#8217;t tell you</strong> is that most technicians that are dispatched out to your homes and businesses don&#8217;t understand basic principals of computer networking .  In fact, in many cases, they don&#8217;t even work for the company.  In the case of Comcast, their technicians are contract workers so the chance you&#8217;re getting someone who knows their stuff is slim.  Phone support can vary greatly so do your homework to make sure all your personal information isn&#8217;t available to anyone in a 1,000 foot radius.</p>
<p>She&#8217;s ordering a router for me to setup next week to kick these moochers off!</p>
<h2>Why Bother To Secure Your Wireless?</h2>
<ul>
<li>Would you hand over your email passwords to a stranger?</li>
<li>Will you post your social security number in the comments of this post?</li>
<li>How about make photo copies of your tax return and drop them out your car window at random spots throughout town?</li>
</ul>
<p>All of these suggestion seem to lack common sense but people do it all the time with insecure wireless in their home AND in their business.</p>
<h2>How To Keep Your Wireless Safe</h2>
<p>Excerpt from <a href="http://blog.adennetworks.com/2008/08/17/5-ways-to-stop-wireless-hacking/">my August 2008 blog post at Aden Networks</a></p>
<ol>
<li>Purchase your own router</li>
<li>Secure your wireless with tough encryption</li>
<li>Password protect the administrator login</li>
<li>Only share necessary folders on your computer</li>
<li>Get a Mac from the Apple store</li>
</ol>
<h2>Now What?</h2>
<p>I can help you <a href="http://butyoureagirl.com/go/linksyswrt54gl/">purchase a router</a>, set it up remotely, secure it and explain the process.  I have setup hundreds of routers like this.  It&#8217;s nice when I&#8217;m working with clients to not only advise them on website, social media and business technology but to roll up my sleeves and secure their networks as well.</p>
<p>I used to work at American Express and would:</p>
<ol>
<li>Help financial advisors in remote offices order high speed internet</li>
<li>Configure Cisco routers and ship them out</li>
<li>Walk them through the setup process blind (via phone)</li>
<li>Get their VPN connection established</li>
<li>Ensure their financial applications worked</li>
</ol>
<h2>Not sure if you&#8217;re wireless is secure?</h2>
<p>Check out these resources to help you determine if your wireless network is open, using WEP or WPA and how to increase your security:</p>
<p><a href="http://askadria.com/2009/04/02/risks-and-rewards-of-wireless-internet/">Risks and Rewards of Wireless Internet: Protect Yourself</a> &#8211; AskAdria.com [VIDEO]</p>
<p><a href="http://spotlight.getnetwise.org/wireless/wifitips/linksys/linksys-wpa.php">Linksys</a> and <a href="http://spotlight.getnetwise.org/wireless/wifitips/apple/apple-wpa.php">Apple Airport Express</a> Instructions for WPA Encryption - GetNetWise</p>
<p><a title="5 Essential Steps to Secure Your Wireless" href="http://blog.adennetworks.com/2008/08/17/5-ways-to-stop-wireless-hacking/">5 Essential Steps to Secure Your Wireless</a> &#8211; Aden Networks Blog</p>
<p><a href="http://consumerist.com/5057854/the-idiot+proof-way-to-securely-use-public-wi+fi">The Idiot-Proof Way To Securely Use Public Wi-Fi</a> &#8211; Consumerist</p>
<p><span><a title="Guilty Plea in Kinko's Keystroke Caper" href="http://www.securityfocus.com/news/6447">Guilty Plea in Kinko’s Keystroke Caper</a> &#8211; SecurityFocus</span></p>
<p><span> <a title="Hacking Airport Wi-Fi" href="http://www.forbes.com/forbes/2008/1208/052.html">Hacking Airport Wi-Fi</a> &#8211; Forbes</span></p>
<img src="http://butyoureagirl.com/?ak_action=api_record_view&id=3530&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://butyoureagirl.com/2009/08/13/how-neighbors-punk-your-open-wifi/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Network Solutions Screws 573,000 Credit Card Customers On Ecommerce Security</title>
		<link>http://butyoureagirl.com/2009/08/04/network-solutions-screws-573000-credit-card-customers-on-ecommerce-security/</link>
		<comments>http://butyoureagirl.com/2009/08/04/network-solutions-screws-573000-credit-card-customers-on-ecommerce-security/#comments</comments>
		<pubDate>Tue, 04 Aug 2009 22:23:05 +0000</pubDate>
		<dc:creator>Lee Greene</dc:creator>
				<category><![CDATA[Online Payments]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Your Data]]></category>

		<guid isPermaLink="false">http://butyoureagirl.com/?p=3344</guid>
		<description><![CDATA[Folks, I am happy to announce the first guest post on ButYoureAGirl.com! @lhgreene Introducing Lee H. Greene. I met him on Twitter and he&#8217;s a very resourceful and helpful person. If you have questions about technology, electricity, home improvement, security or anything scientific, you should connect with Lee on Twitter All Your Shopping Carts Belong [...]]]></description>
			<content:encoded><![CDATA[<p>Folks, I am happy to announce the first guest post on ButYoureAGirl.com!<br />
<a href="http://twitter.com/lhgreene">@lhgreene</a><br />
<a title="Twitter @lhgreene by adria.richards, on Flickr" href="http://twitter.com/lhgreene"><img src="http://farm3.static.flickr.com/2474/3790328388_34a07faedd.jpg" alt="Twitter @lhgreene" width="500" height="280" /></a><span id="more-3344"></span></p>
<p>Introducing <strong>Lee H. Greene</strong>.  I met him on Twitter and he&#8217;s a very resourceful and helpful person.  If you have questions about technology, electricity, home improvement, security or anything scientific, you should connect with Lee on Twitter</p>
<h2>All Your Shopping Carts Belong To Us</h2>
<p>Merchants whose ecommerce websites are hosted by Network Solutions (NS) recently received notifications from NS that NS&#8217;s servers had been hacked, with &#8220;unauthorized code&#8221; which &#8220;may have been used to transfer data . . .  to servers outside the company.&#8221;</p>
<p>Network Solutions hosts approximately 10,000 ecommerce websites. According to the notice sent to their merchants, approximately 4,343 merchant websites were exposed to the rogue code, affecting &#8220;transactions by approximately 573,928 card holders.&#8221;</p>
<p>Online transactions for the affected ecommerce websites were exposed to the &#8220;unauthorized code&#8221; from March 12, 2009 through June 8, 2009.</p>
<p>The initial notice to each NS merchant provided a link, which the merchants could use to learn whether their ecommerce site was affected and if so, how many transactions were exposed. Those whose websites did have transactions exposed to the data security breach were informed by Network Solutions that &#8220;Under various state statutes, a retailer is to inform its U.S. customers when the security of their personal information is compromised.&#8221;</p>
<p><a title="Network Solutions Security Breach Notice by adria.richards, on Flickr" href="http://www.flickr.com/photos/adriarichards/3790340440/"><img src="http://farm3.static.flickr.com/2642/3790340440_0ffc200bb3_o.jpg" alt="Network Solutions Security Breach Notice" width="584" height="441" /></a></p>
<h2 style="font-size: 1.5em;">Network Solutions Offers Free Credit Monitoring.  Big Whoop</h2>
<p>To try to soften the blow to the affected merchants, NS offered merchants the services of credit reporting bureau, TransUnion, at NS&#8217;s expense, to inform the affected customers that their credit card data had been breached and provide them with a year of free credit monitoring.</p>
<p><a title="Network Solutions Security Breach Notice by adria.richards, on Flickr" href="http://www.flickr.com/photos/adriarichards/3790340408/"><img src="http://farm4.static.flickr.com/3565/3790340408_f3e3d20c60_o.jpg" alt="Network Solutions Security Breach Notice" width="584" height="398" /></a></p>
<h2>Network Solutions Sabotages Online Trust</h2>
<p>Of course, this is an online merchant&#8217;s worst nightmare. Work hard to develop an effective online store, market it, and develop a customer base that is making purchases from the site, do everything right to build an online business &#8211; then have to tell your customers that their personal info and credit card data have been compromised as a result of their purchases from your website. Customer reactions on learning that have tended to be emphatic and unforgiving &#8211; nobody likes the idea of having their credit card info stolen, or wishes to risk that possibility again from a website that has not adequately protected their financial and personal info in the past. Ouch!</p>
<h2>Network Solutions Failed To Protect Customers</h2>
<p>One has to wonder &#8211; how can Network Solutions have failed to protect their servers (and merchants) from this security breach, and worse still, failed to discover it and allowed it to continue for more than three months? If you are a merchant, trying to develop and maintain a successful ecommerce website, can YOU risk having your website hosted by Network Solutions?</p>
<p>&#8211; Lee H. Green</p>
<img src="http://butyoureagirl.com/?ak_action=api_record_view&id=3344&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://butyoureagirl.com/2009/08/04/network-solutions-screws-573000-credit-card-customers-on-ecommerce-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Will TSA Snatch My Electric Toothbrush?</title>
		<link>http://butyoureagirl.com/2009/06/05/will-tsa-snatch-my-electric-toothbrush/</link>
		<comments>http://butyoureagirl.com/2009/06/05/will-tsa-snatch-my-electric-toothbrush/#comments</comments>
		<pubDate>Fri, 05 Jun 2009 11:42:45 +0000</pubDate>
		<dc:creator>Adria Richards</dc:creator>
				<category><![CDATA[Bets]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[travel]]></category>
		<category><![CDATA[TSA]]></category>

		<guid isPermaLink="false">http://butyoureagirl.com/?p=2234</guid>
		<description><![CDATA[photo credit: yoppy I&#8217;m heading to WordCamp Chicago today and mentioned on Twitter that I wasn&#8217;t bringing my electric toothbrush.  I didn&#8217;t want the hassle of TSA making up &#8220;rules&#8221; on the spot and then telling me I&#8217;d have to toss my toothbrush.  @swirlspice suggested I try and get it through TSA so today I will [...]]]></description>
			<content:encoded><![CDATA[<p><a title="R1069262" href="http://www.flickr.com/photos/44124362019@N01/2578600060/" target="_blank"><img src="http://farm4.static.flickr.com/3064/2578600060_f78c1e2ccf.jpg" border="0" alt="R1069262" /></a><br />
<small><a title="Attribution License" href="http://creativecommons.org/licenses/by/2.0/" target="_blank"><img src="http://butyoureagirl.com/wp-content/plugins/photo-dropper/images/cc.png" border="0" alt="Creative Commons License" width="16" height="16" align="absMiddle" /></a> <a href="http://www.photodropper.com/photos/" target="_blank">photo</a> credit: <a title="yoppy" href="http://www.flickr.com/photos/44124362019@N01/2578600060/" target="_blank">yoppy</a></small></p>
<p>I&#8217;m heading to <a href="http://wordcampchicago/">WordCamp Chicago</a> today and mentioned on Twitter that <a href="http://twitter.com/adriarichards/status/2031072401">I wasn&#8217;t bringing my electric toothbrush.</a>  I didn&#8217;t want the hassle of TSA making up &#8220;rules&#8221; on the spot and then telling me I&#8217;d have to toss my toothbrush.  <a href="http://twitter.com/swirlspice">@swirlspice</a> suggested <a href="http://twitter.com/swirlspice/status/2031762048">I try and get it through TSA</a> so today I will attempt to bring my toothbrush with me as carry-on.</p>
<p>I found some interesting experiences on the internet:</p>
<p><a href="http://edcforums.com/index.php?topic=17402.msg213741">Let&#8217;s design a basic, compact, TSA-compliant carry-on &#8220;survival kit&#8221;</a></p>
<blockquote><p>In light of the continuing drama-rama that is the TSA (see <a href="http://edcforums.com/index.php?topic=17300.0" target="_blank">this</a> thread), I propose a project: let&#8217;s design a basic carry-on kit that complies with TSA rules while granting the bearer the most comprehensive array of essentials possible in the event of an emergency (delayed/lost luggage, etc).  The more compact the &#8220;core&#8221; essentials, the more space is left over for items you don&#8217;t want to check (read: &#8220;donate,&#8221; provided they&#8217;re legal to carry onto the plane).</p></blockquote>
<p><a href="http://www.wired.com/wired/archive/11.09/bagscan.html">Confessions of a Baggage Screener</a></p>
<blockquote><p>So far I had seen the machines flag plenty of deodorant sticks, toothpaste tubes, and shoe heels, which showed up on the screen outlined in red. I had handled sex toys, machetes, and pistols (legal in checked bags). But the closest thing I had seen to a bomb were manufactured images on the screen created by the Threat Image Projection System, a software package developed by the government to make sure we were paying attention. Every once in a while, I learned, police let drug dogs find contraband so they don&#8217;t grow discouraged. I didn&#8217;t much care for the implied comparison.</p>
<p>The ticking was real enough, though, and I couldn&#8217;t let the suitcase through until I&#8217;d figured out the origin of the sound. A US Airways supervisor was hovering nearby, and jittery fliers were peeking at us through the breaks in the partitions. I took everything out, stacking clothes on the table. I felt around the lining. I turned the suitcase over once more, noted that the ticking stopped, and saw a bulge in a tiny pocket tucked between the rods for the extendable handle. It was an electric toothbrush that turned on when it pressed against the table but was packed too tight to vibrate.</p></blockquote>
<p><a href="http://www.tsa.gov/press/happenings/common_items_extraordinary_threat.shtm">Common Items, Extraordinary Threat (TSA Blog)</a></p>
<blockquote><p>Authorities overseas also found an electric toothbrush, similar to one the TSA showed ABC News, which was actually re-engineered to detonate a plastic explosive that could be hidden in the lining of a briefcase.</p></blockquote>
<img src="http://butyoureagirl.com/?ak_action=api_record_view&id=2234&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://butyoureagirl.com/2009/06/05/will-tsa-snatch-my-electric-toothbrush/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Where Do We Go From Here Norm?</title>
		<link>http://butyoureagirl.com/2009/03/29/where-do-we-go-from-here-norm/</link>
		<comments>http://butyoureagirl.com/2009/03/29/where-do-we-go-from-here-norm/#comments</comments>
		<pubDate>Mon, 30 Mar 2009 02:50:14 +0000</pubDate>
		<dc:creator>Adria Richards</dc:creator>
				<category><![CDATA[How I Work]]></category>
		<category><![CDATA[Politics]]></category>
		<category><![CDATA[Reflections]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[The Big Picture]]></category>
		<category><![CDATA[The Environment]]></category>
		<category><![CDATA[The Gas Crisis]]></category>
		<category><![CDATA[Your Data]]></category>
		<category><![CDATA[norm coleman]]></category>

		<guid isPermaLink="false">http://butyoureagirl.com/?p=2058</guid>
		<description><![CDATA[I&#8217;ve decided to write a summary to give you my perspective two months after putting up the Norm Coleman database blog post. I created the Norm Coleman blog post to answer the questions I began to receive the night this all happened. I started ButYoureAGirl.com to help people understand technology. I like to document things [...]]]></description>
			<content:encoded><![CDATA[<p><a title="st pauls &amp;amp; millenium bridge by Daveybot, on Flickr" href="http://www.flickr.com/photos/davemorris/2701476/"><img class="alignright" src="http://farm1.static.flickr.com/3/2701476_92f300fec0.jpg" alt="st pauls &amp;amp; millenium bridge" width="404" height="303" /></a>I&#8217;ve decided to write a summary to give you my perspective two months after putting up the <a href="http://butyoureagirl.com/2009/01/28/did-norm-coleman-fake-his-own-website-death/">Norm Coleman database</a> blog post.</p>
<p>I created the Norm Coleman blog post to answer the questions I began to receive the night this all happened.  I started ButYoureAGirl.com to help people understand technology.</p>
<p>I like to document things (my Inner Nerd at work).  You can see a <a href="http://butyoureagirl.com/2008/10/11/how-to-turn-off-aviras-annoying-antivir-popups-in-xp-home/">similar example regarding Avira antivirus</a>.</p>
<p>What happened next regarding Wikileaks and going on national television never crossed my mind as a possible outcome of following my geeky curiosity and documenting screenshots.
<p></p>
<pre style="text-align: right;">Photo Credit: <a title="Link to Daveybot's photostream" rel="dc:creator cc:attributionURL" href="http://www.flickr.com/photos/davemorris/2701476/">Daveybot</a></pre>
<h3>Summary</h3>
<p><strong>Political Views</strong><br />
What I didn&#8217;t know at the time was how this issue was snowballing between the Democrats and Republicans.  I don&#8217;t own a television and don&#8217;t follow politics.  I sold my TV on Craigslist in 2006 as a part of <a title="Giving Up TV" href="http://www.stevepavlina.com/blog/2006/06/giving-up-tv/">&#8220;the great experiment&#8221;</a> I was reading about on Steve Palina&#8217;s blog.  I never really was a big fan of commercials anyway.  I use <a href="http://tinyurl.com/bookGTDdavidallen">David Allen&#8217;s Getting Things done</a> (GTD) method of productivity to turn my dreams into reality.  Every reporter asked me if I was &#8220;partisan&#8221;.  I actually had to ask the what that was but figured it had to do with being strongly associated to a political party.  Now don&#8217;t get me wrong, I have beliefs on things like education, the environment, the death penalty, the legal system, oil dependency, health care and taxes.  It&#8217;s just that none of <strong>that</strong> had to do with <strong>this</strong>.</p>
<p><strong>The Media</strong><br />
I started to see traffic spikes on my humble blog March 10th, 2009.  By March 11th, more than 1,000 people had stopped by!  My average number of daily visitors before then was about 40.  Then the calls started.  Reporters were calling and asking me to tell them what happened.  Being a techie, I thought I was helping them; I now realize many were looking to sensationalize the story and twist my words to make things sound more exciting.  I&#8217;m now wiser about the media and their &#8220;angles&#8221;.  For those of you who work in technology, you know it can be a challenge to keep someone&#8217;s attention as you explain the benefits of data backups that utilize incremental, off-site and image based options.  We find it fascinating but non technical people start to &#8220;glaze over&#8221;.</p>
<p><strong>Where Do We Go From Here?</strong><br />
I want to share that I&#8217;m working on something exciting!  I&#8217;ve been meeting and talking with security consultants around the US.  I&#8217;ve also talked with people in the data privacy field.  I&#8217;m working to put together a resource that will bring security and business people together in a way that makes sense.  I myself am not a security consultant; rather an IT consultant who values security.  I would like to utilize this event to help people connect on this issue and access accurate information on what they need to do to secure their data, networks and websites.</p>
<p><strong>Thank You For Your Support</strong><br />
I appreciate all the words of encouragement, support, suggestions, personal stories from people on the list, research efforts and most importantly, technical folks speaking up to this.  The first question I received from a reporter was, &#8220;Do you want to go the record about this?&#8221;.  That reminded me that many people working in the IT field would have not feel comfortable talking about something like this for fear of the backlash.  As an independent consultant, I understand I have more flexibility that those working full-time for someone.  I also understand that what I do outside of my work does reflect on my work.  My clients have been supportive about this issue and I thank them as well; Democrat and Republicans alike.  After appearing on The Rachel Maddow Show, I really saw an increase in mentions about me across the Internet (I use <a title="Google Alerts" href="http://www.google.com/alerts">Google Alerts</a> to track this).  My <a href="http://feeds.technorati.com/blogs/butyoureagirl.com">Technorati rank for this blog</a> doubled.  Some blogs were even referring to me as &#8220;Dr. Adria Richards&#8221;!  Doh!  I stopped by many sites and left comments to help answer people&#8217;s questions and to indicate I did not hold a doctorate degree.</p>
<p><strong>The Haters</strong><br />
There have been people who voiced their opinions on what I did, how I did it, why I did it and so on.  I can&#8217;t change what I did (looking into the Coleman fake website crash, taking screenshots, writing a blog post about it).  I am a person who takes action.  Some people are just angry people looking for targets.  Some people feel they know what other people should do with their lives.  I decided that I wasn&#8217;t going to <a title="Internet Troll" href="http://en.wikipedia.org/wiki/Internet_troll">feed the trolls</a>.</p>
<p><strong>How You Can Help</strong><br />
That said, if you are interested in helping with this upcoming project to bridge the gap between unsafe data storage in the business world and best practice data security audits, training and education, <a title="Contact Adria Richards" href="http://butyoureagirl.com/contact">contact me</a>.</p>
<p><strong>Stay tuned&#8230;</strong></p>
<img src="http://butyoureagirl.com/?ak_action=api_record_view&id=2058&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://butyoureagirl.com/2009/03/29/where-do-we-go-from-here-norm/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Interview on Rachel Maddow Show for Norm Coleman Database</title>
		<link>http://butyoureagirl.com/2009/03/14/interview-on-rachel-maddow-show-for-norm-coleman-database/</link>
		<comments>http://butyoureagirl.com/2009/03/14/interview-on-rachel-maddow-show-for-norm-coleman-database/#comments</comments>
		<pubDate>Sat, 14 Mar 2009 09:26:57 +0000</pubDate>
		<dc:creator>Adria Richards</dc:creator>
				<category><![CDATA[Media Coverage]]></category>
		<category><![CDATA[Online]]></category>
		<category><![CDATA[Online Payments]]></category>
		<category><![CDATA[Politics]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Television]]></category>
		<category><![CDATA[YouTube]]></category>
		<category><![CDATA[Your Data]]></category>
		<category><![CDATA[norm coleman]]></category>
		<category><![CDATA[Rachel Maddow]]></category>

		<guid isPermaLink="false">http://butyoureagirl.com/?p=1842</guid>
		<description><![CDATA[3/13/2009 MSNBC Interview with Rachel Maddow Friday evening! This is tied to my original post about Norm Coleman&#8217;s website being insecure. Thank you to EVERYONE who has given words of encouragement and support. I know a lot of people would not have done what I did. I am angry of seeing families dealing with identity [...]]]></description>
			<content:encoded><![CDATA[<p>3/13/2009 MSNBC Interview with Rachel Maddow Friday evening!<br />
<p><a href="http://butyoureagirl.com/2009/03/14/interview-on-rachel-maddow-show-for-norm-coleman-database/"><em>Click here to view the embedded video.</em></a></p></p>
<p>This is tied to my <a href="http://butyoureagirl.com/2009/01/28/did-norm-coleman-fake-his-own-website-death/">original post</a> about Norm Coleman&#8217;s website being insecure.</p>
<p><span id="more-1842"></span>Thank you to EVERYONE who has given words of encouragement and support.  I know a lot of people would not have done what I did.  I am angry of seeing families dealing with identity theft.  I&#8217;m upset that companies are put at risk by other companies that don&#8217;t follow guidelines on security.</p>
<p><a title="Guest on Rachel Maddock Show for Norm Coleman Database by adria.richards, on Flickr" href="http://www.flickr.com/photos/adriarichards/3354453432/"><img src="http://farm4.static.flickr.com/3567/3354453432_1e047db266.jpg" alt="Guest on Rachel Maddock Show for Norm Coleman Database" width="500" height="375" /></a></p>
<p><a title="Guest on Rachel Maddock Show for Norm Coleman Database by adria.richards, on Flickr" href="http://www.flickr.com/photos/adriarichards/3353631837/"><img src="http://farm4.static.flickr.com/3635/3353631837_2fbf19899b.jpg" alt="Guest on Rachel Maddock Show for Norm Coleman Database" width="500" height="375" /></a></p>
<p><a title="Guest on Rachel Maddock Show for Norm Coleman Database by adria.richards, on Flickr" href="http://www.flickr.com/photos/adriarichards/3353631009/"><img src="http://farm4.static.flickr.com/3158/3353631009_e471d4147d.jpg" alt="Guest on Rachel Maddock Show for Norm Coleman Database" width="500" height="375" /></a></p>
<p><a title="Guest on Rachel Maddock Show for Norm Coleman Database by adria.richards, on Flickr" href="http://www.flickr.com/photos/adriarichards/3354454164/"><img src="http://farm4.static.flickr.com/3547/3354454164_b3f9da8c0c.jpg" alt="Guest on Rachel Maddock Show for Norm Coleman Database" width="500" height="375" /></a></p>
<img src="http://butyoureagirl.com/?ak_action=api_record_view&id=1842&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://butyoureagirl.com/2009/03/14/interview-on-rachel-maddow-show-for-norm-coleman-database/feed/</wfw:commentRss>
		<slash:comments>16</slash:comments>
		</item>
		<item>
		<title>Hey Bob, I&#039;ve Got Something For You&#8230;Re: Norm Coleman Database</title>
		<link>http://butyoureagirl.com/2009/03/13/hey-bob-ive-got-something-for-youre-norm-coleman-database/</link>
		<comments>http://butyoureagirl.com/2009/03/13/hey-bob-ive-got-something-for-youre-norm-coleman-database/#comments</comments>
		<pubDate>Fri, 13 Mar 2009 07:16:38 +0000</pubDate>
		<dc:creator>Adria Richards</dc:creator>
				<category><![CDATA[Passwords]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tech Tasty]]></category>
		<category><![CDATA[YouTube]]></category>
		<category><![CDATA[Your Data]]></category>
		<category><![CDATA[feedback]]></category>
		<category><![CDATA[norm coleman]]></category>

		<guid isPermaLink="false">http://butyoureagirl.com/?p=1823</guid>
		<description><![CDATA[This is a reading of a comment left on my blog post about Norm Coleman&#8217;s Website Database Leak. Update 1: Enelson has posted an article expanding on this comment: Norm Coleman and Identity Theft Gate: Is Your Online Donation to Norm Coleman Safe? Update 2: Edited a bit of grammar at request of poster (homonyms, [...]]]></description>
			<content:encoded><![CDATA[<p>This is a reading of a comment left on my blog post about Norm Coleman&#8217;s Website Database Leak.</p>
<p><p><a href="http://butyoureagirl.com/2009/03/13/hey-bob-ive-got-something-for-youre-norm-coleman-database/"><em>Click here to view the embedded video.</em></a></p><br />
<strong>Update 1:</strong> Enelson has posted an article expanding on this comment:<br />
<a href="http://www.opednews.com/articles/Norm-Coleman-and-Identity-by-E-Nelson-090313-191.html">Norm Coleman and Identity Theft Gate: Is Your Online Donation to Norm Coleman Safe?</a></p>
<p>
<strong>Update 2: </strong>Edited a bit of grammar at request of poster (homonyms, commas, spelling, semicolon, spacing, referring to Adria as a generalized type of person vs an individual</p>
<blockquote><p><span class="commentAuthor">E Nelson<img style="float: left;margin-right: 10px" src="http://www.gravatar.com/avatar/95f4d605833e5ae996e188b8127f0fb8?rating=X&amp;default=identicon" alt="No Gravatar" width="40" height="40" /></span><br />
<a href="http://butyoureagirl.com/2009/01/28/did-norm-coleman-fake-his-own-website-death/#comment-888">March 12th, 2009</a></p>
<p>Okay, I couldn’t take it anymore after reading all the ignorant comments  attacking Adria. I am a fellow IT consultant and I deal with security issues  every day. I see hackers scanning my clients sites EVERY day looking for  potential openings and exploits. These hackers are using untraceable zombie  networks from all over the world. Chinese hackers; Romanian hackers; and yes many  pre-teen US hackers.</p>
<p>Just because Bob and the rest of the computer illiterate posters here have no clue about technology, it does not mean that anyone else should remain as clueless as they are. The fact of the matter is, as an IT consultant responsible for my  client’s web technology and any sensitive information associated with their websites, I ABSOLUTELY want &#8220;an Adria&#8221; to point this out as quickly as possible so that I can act on it rather than have multiple GIGANTIC security holes remain exposed for weeks, with hundreds of untraceable IP connections downloading the  information. All of these security breaches can be easily found AUTOMATICALLY with internet scanners very similar to what Google uses to index the entire  internet. I hate to break this to you, Bob, but I can almost guarantee you that there are Chinese and Eastern European hackers that have had this information well before Adria found it. And if you think they are going to call up Norm and let him know, I have some oceanfront property in Iowa to sell you.</p>
<p>The fact of the matter is that Norm Coleman and the people working for him are either completely incompetent or blatantly negligent. Adria was not the  first person to alert the Norm Coleman campaign to the potential problems and  yet they continued to ignore their duties to A) FIX THE PROBLEM B) Alert the  donors of their mistake and C) TAKE THE DAMN SITE DOWN. It takes 2 minutes to do this until you can figure out what the problem is. Instead, the Coleman campaign claimed their site was hacked for political purposes, claimed they contacted the  Secret Service to investigate and who then unbelievably and incorrectly said that no sensitive information had leaked out.</p>
<p>So the question should be, Bob, as a donor, would you not want Norm or someone else to alert you to the fact that your credit card information has most assuredly fallen into the hands of international hackers?</p></blockquote>
<p>Enelson, thank for taking the time to write such a detailed comment from your perspective on this.  I was so moved that I wanted to give a voice to your words.</p>
<img src="http://butyoureagirl.com/?ak_action=api_record_view&id=1823&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://butyoureagirl.com/2009/03/13/hey-bob-ive-got-something-for-youre-norm-coleman-database/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Who is Searching Google for Norm Coleman&#039;s Database?</title>
		<link>http://butyoureagirl.com/2009/03/11/who-is-searching-google-for-norm-colemans-database/</link>
		<comments>http://butyoureagirl.com/2009/03/11/who-is-searching-google-for-norm-colemans-database/#comments</comments>
		<pubDate>Wed, 11 Mar 2009 17:16:33 +0000</pubDate>
		<dc:creator>Adria Richards</dc:creator>
				<category><![CDATA[Politics]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[clicky]]></category>
		<category><![CDATA[google analytics]]></category>
		<category><![CDATA[norm coleman]]></category>

		<guid isPermaLink="false">http://butyoureagirl.com/?p=1771</guid>
		<description><![CDATA[I had a few hundred visitors by 10am so I decided to create a list of the vistors to my blog post on the Norm Coleman Database Leak. For my own safety and to show how EASY it is to track visitors so if my little blog can handle 1,000 visitors in 24 hours, Norm&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>I had a few hundred visitors by 10am so I decided to create a list of the vistors to my blog post on the Norm Coleman Database Leak. For my own safety and to show how EASY it is to track visitors so if my little blog can handle 1,000 visitors in 24 hours, Norm&#8217;s office should cough up the numbers that crushed their website server.</p>
<p><a href="http://butyoureagirl.com/2009/01/28/did-norm-coleman-fake-his-own-website-death/"><strong>Norm Coleman Website Crash Exposes Database and Email Lists</strong></a></p>
<p>So far, we&#8217;ve got the Mayo Foundation, Hennepin County, First Bank, Wells Fargo, Best Buy&#8230;</p>
<p>Are these companies where people who <a href="http://minnesotaindependent.com/28806/coleman-donors-express-extreme-anger-fear-worry-after-breach">donated to Norm Coleman</a> and checking the site from work?</p>
<p>Are they needing to cut up their credit cards?</p>
<p><strong>I will be adding it throughout the day</strong></p>
<p style="text-align: left">University of Alabama<br />
College of St. Catherine<br />
Minnesota Public Radio (You never know)<br />
National Institute of Health<br />
American Medical Response<br />
US Department of State<br />
City of New York<br />
Ecolab<br />
West Publishing Corporation<br />
American Medical Response<br />
National Institute of Health<br />
University of Alabama<br />
Massachusetts Institute of Art (very awesome MIT would stop by)<br />
University of California<br />
University of Illinois<br />
University of Minnesota<br />
St. Olaf College<br />
Datacard Corporation<br />
U.S. Senate Sergent At<br />
Medical College of Wisconsin<br />
University of Wisconsin<br />
Fingerhut Direct Marketing (Why are you stopping by my blog?)<br />
Western Illinois University<br />
Faegre &amp; Benson LLP (Lawyers? uh oh)<br />
Dorsey &amp; Whitney (Why is it so popular with lawyers to name law firms like this?)<br />
Cargill<br />
Valley Office Partners<br />
Marvin Windows and Doors<br />
TCF Financial Corporation<br />
Research Triangle Institute (Interesting)<br />
Target Corporation<br />
U.S. House of Representatives<br />
Knight Ridder &lt;- Media company (Thanks redwing!)<br />
IBM<br />
Star Tribune Newspaper<br />
Harland Financial<br />
Academy of Art University<br />
Renolds and Renolds<br />
Mc Miller Company<br />
American Civil Liberties Union (sweet! Hello there!)<br />
General Mills<br />
Amazon.com<br />
Trw Space and Defense<br />
De Castro, West, Chodorow (lawyers again?)<br />
Edina Reality</p>
<p><img src="http://farm4.static.flickr.com/3653/3347193598_6c4dbc30e1_o.png" alt="Who is searching for Norm Coleman's Database?" /><br />
<img src="http://farm4.static.flickr.com/3091/3347934626_20cb7f7e87_o.png" alt="" /></p>
<p><img src="http://farm4.static.flickr.com/3456/3348764024_9fb8e3446f_o.png" alt="" /></p>
<p><img src="http://farm4.static.flickr.com/3580/3348805800_a18ae2c5eb_o.png" alt="" /></p>
<p><img src="http://farm4.static.flickr.com/3660/3348809620_b5986f7d21_o.png" alt="" /></p>
<p><img src="http://farm4.static.flickr.com/3578/3347976999_14487445d5_o.png" alt="" /></p>
<p><img src="http://farm4.static.flickr.com/3639/3348819218_257b377dab_o.png" alt="" /></p>
<pre style="text-align: right">These website visitor traffic stats are being collected with <a href="http://tinyurl.com/clickystats">Clicky</a>.
It's like Google Analytics but you don't have to wait 24 hours.</pre>
<img src="http://butyoureagirl.com/?ak_action=api_record_view&id=1771&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://butyoureagirl.com/2009/03/11/who-is-searching-google-for-norm-colemans-database/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Norm Coleman Website Crash Exposes Database and Email Lists</title>
		<link>http://butyoureagirl.com/2009/01/28/did-norm-coleman-fake-his-own-website-death/</link>
		<comments>http://butyoureagirl.com/2009/01/28/did-norm-coleman-fake-his-own-website-death/#comments</comments>
		<pubDate>Thu, 29 Jan 2009 02:51:15 +0000</pubDate>
		<dc:creator>Adria Richards</dc:creator>
				<category><![CDATA[Cover Your Butt]]></category>
		<category><![CDATA[Politics]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tech Tasty]]></category>
		<category><![CDATA[Troubleshooting]]></category>
		<category><![CDATA[YouTube]]></category>
		<category><![CDATA[norm coleman]]></category>

		<guid isPermaLink="false">http://butyoureagirl.com/?p=1555</guid>
		<description><![CDATA[What's worse than losing a Minnesota Sentate race?  Losing your website's entire database, that's what.  I found a database with 205mb worth of information is available from Norm Coleman's website.  Wowza.  I sure hope there isn't financial information in that database.]]></description>
			<content:encoded><![CDATA[<p>Post Updated: 3/29/2009</p>
<p>First off, I would like to thank to everyone.</p>
<p>I&#8217;ve decided to write a summary to give you my perspective two months after putting up this blog post.  I have continued to add to it in hopes of making the big picture more clear for people who want to understand what happened.</p>
<p>I talk about why I put up the post, the political power struggle I didn&#8217;t want to be a part of, how the media took what I said and turned it into what they wanted and what I&#8217;m working on to bring about actual change so personal and financial data will be safer in the future.</p>
<p><a href="http://butyoureagirl.com/2009/03/29/where-do-we-go-from-here-norm/"><strong>Continue reading the summary</strong></a></p>
<hr />How ironic is this?  I was on <a title="Download of the Day: Eraser" href="http://lifehacker.com/software/downloads/download-of-the-day-eraser-125289.php">Lifehacker</a> today looking for the article about <a title="Eraser Secure data removal tool for Windows. (Open Source)" href="http://www.heidi.ie/eraser/">Eraser</a> (program that securely wipes out files) and saw that <strong><a title="It's Data Privacy Day: Do You Know Where Your Data Is?" href="http://lifehacker.com/5141106/its-data-privacy-day-do-you-know-where-your-data-is">January 28th is Data Privacy Day</a></strong>!  What are the chances of a security breach regarding data privacy being discovered on the very day that has been selected to raise awareness of data privacy?  Geeze!</p>
<p>Did <a title="Senator Coleman's Database Debacle" href="http://www.pjtv.com/video/PJTV_Daily/Senator_Coleman%27s_Database_Debacle/1598/">interview with PJTV</a>, conservative focused online media site (PajamasTV)</p>
<p>Article at ChannelWeb, <a title="Serious Security Flaw Discovered In Less Than 2 Minutes On U.S. Senator's Web Site" href="http://www.crn.com/security/215901459">Serious Security Flaw Discovered In Less Than 2 Minutes On U.S. Senator&#8217;s Web Site</a></p>
<p>Excerpt from <a href="http://www.timbarsness.com/resume.html">resume of website developer</a> who created Colemanforsenate.com website:</p>
<blockquote><p>ColemanForSenate.com<br />
* Developed a custom content management system from the ground up in PHP</p></blockquote>
<p>New Video is up!  <a href="http://askadria.com/2009/03/14/live-coleman-question-and-answer-3142009-1245am/">Live: Coleman Question and Answer after The Rachel Maddow Show 3/14/2009 12:45am CST</a></p>
<p>Interview with Rachel Maddow Friday evening 3/13/2009 MSNBC<br />
<p><a href="http://butyoureagirl.com/2009/01/28/did-norm-coleman-fake-his-own-website-death/"><em>Click here to view the embedded video.</em></a></p></p>
<p>Interview with  MPR <a href="http://minnesota.publicradio.org/display/web/2009/03/11/colemandonors/">Coleman warns donors after data breach</a> (audio of me from the radio)</p>
<p>Blog Post MN Independent <a title="Permanent Link to Coleman donors express ‘extreme anger,’ fear, worry after breach" rel="bookmark" href="http://minnesotaindependent.com/28806/coleman-donors-express-extreme-anger-fear-worry-after-breach">Coleman donors express ‘extreme anger,’ fear, worry after breach</a></p>
<p>YouTube video: <strong><a href="http://www.youtube.com/watch?v=9qknKAz9LUU">How I Found Norm Coleman&#8217;s Website Database in 2 Minutes</a></strong></p>
<p>Best quote to me on the phone: &#8220;I just hung on the secret service to talk to you&#8221; &#8212; unnamed reporter</p>
<p>Lifestream video : I <a href="http://askadria.com/2009/03/11/norm-colemans-database-revisited-and-website-development-choices/">explain what went wrong and answer questions</a> about the Norm Coleman&#8217;s website</p>
<p>Interview with MN Independent <a class="title" title="Permanent Link to Coleman’s site wasn’t ‘hacked,’ says IT pro who discovered donor breach" rel="bookmark" href="http://minnesotaindependent.com/28748/colemans-site-wasnt-hacked-says-it-pro-who-discovered-donor-breach">Coleman’s site wasn’t ‘hacked,’ says IT pro who discovered donor breach </a></p>
<p>Blog Post at MN Independent <a class="StoryLink" title="Coleman’s unsecured donor database revealed on Wikileaks" rel="bookmark" href="http://minnesotaindependent.com/28711/breaking-colemans-unsecured-donorbase-to-be-revealed-on-wikileaks">Breaking: Coleman’s unsecured donor database revealed on Wikileaks </a></p>
<p>Blog Post Here <a href="../2009/03/11/who-is-searching-google-for-norm-colemans-database/">Who  is Searching Google for Norm Coleman’s Database? </a></p>
<p>So, it sounds like <a href="http://wikileaks.org/wiki/The_Big_Bad_Database_of_Senator_Norm_Coleman">Wikileaks.org is putting Norm Coleman&#8217;s business</a> out on the Internet.</p>
<hr />
<h3>What&#8217;s worse than losing a Minnesota Senate race?</h3>
<p>Losing your website&#8217;s entire database, that&#8217;s what.  As if claiming your website was brought down by too much traffic wasn&#8217;t bad enough, Norm Coleman&#8217;s website received a second round of criticism when I found a database file sitting in a directory that anyone could download&#8230;</p>
<p>I first picked up this story from <a href="http://twitter.com/Chuckumentary/status/1157088036">@Chuckumentary</a> on Twitter about Norm Coleman&#8217;s office saying their website had been <strong>“inundated by tens of thousands of hits today – temporarily crashing the website.”</strong> Of course that got me curious as an IT consultant and I went to check it out.  Aaron Landry broke this story because <a href="http://mnpublius.com/2009/01/team-coleman-fakes-website-crash">previous website traffic reports and the location of the domain name</a> didn&#8217;t match up.  Paul Schmelzer at the Minnesota Independent <a href="http://minnesotaindependent.com/24761/disenfranchised-voters-crash-colemans-site-unlikely-says-blogger">picked up</a> the story which is where I first saw it.</p>
<p><strong>Norm Coleman&#8217;s website crash revealing a database full of supporters is now known as Crashgate.</strong></p>
<p>Curious, I wanted to see where the domain was currently pointing.  I used <a href="http://www.opendns.com/support/cache">OpenDNS.com&#8217;s cache check</a> to identify the current ip address of <span class="linkification-ext">208.42.168.251</span> and then loaded that address into my web browser.<strong></strong></p>
<p><strong><a title="Screenshot of opendns.com information for colemanforsenate.com by adria.richards, on Flickr" href="http://www.flickr.com/photos/adriarichards/3234808005/"><img src="http://farm4.static.flickr.com/3089/3234808005_59f3f0ff43.jpg" alt="Screenshot of opendns.com information for colemanforsenate.com" width="500" height="281" /><br />
</a></strong></p>
<p>I had to see what all the fuss was about.  Was there really an attempt to bring down the website due to political unrest with these ballots in my state?  Were the allegations of a poorly coded website true?</p>
<p>What I got instead was a plain text listing of directories&#8230;</p>
<h3>The Database of Norm Coleman</h3>
<p>Wowza.  As I was tooling around in the directories, I saw a database file.  I thought, &#8220;That&#8217;s not right.&#8221;  I <strong>began taking screenshots</strong> and <a href="http://flickr.com/search/?q=norm%20coleman&amp;w=28694005%40N07">uploading them to Flickr</a>.  I didn&#8217;t know what the database contained but hoped there wasn&#8217;t financial information in that database.  I figured it was a list of email addresses for Norm Coleman supporters and staff but I did not download it find out.  <strong>Did you download the database? </strong></p>
<p><a href="http://butyoureagirl.com/2009/01/28/did-norm-coleman-fake-his-own-website-death/"><em>Click here to view the embedded video.</em></a></p>
<p>There is a term known as &#8220;<a href="http://www.ethicalhacker.net/content/view/41/2/">Google Hacking</a>&#8221; where you can actually search for files that people have on sites and ftp areas that have names like &#8220;passwords.txt&#8221;, &#8220;backup.tar.gz&#8221;.  Eeek!  Backups should be stored above the &#8220;root&#8221; folder that is shared out to the internet.  This is showing up because the server located at <a class="linkification-ext" title="http://208.42.168.251" href="http://208.42.168.251">http://208.42.168.251</a> was not told to restrict directories from the web.</p>
<p><strong>All photos are licensed under Creative Commons.<br />
<a href="http://www.flickr.com/search/?q=coleman&amp;w=28694005%40N07">Norm Coleman database photos on Flickr</a></strong></p>
<p><strong><a title="I wonder how much user information is in this database at colemanforsenate.com? by adria.richards, on Flickr" href="http://www.flickr.com/photos/adriarichards/3234833407/"><img src="http://farm4.static.flickr.com/3094/3234833407_3e38bc24a2_o.jpg" alt="I wonder how much user information is in this database at colemanforsenate.com?" /></a></strong></p>
<p>I began posting links to the photos on the blogs of the Minnesota Independent and Minpublius to bring awareness to what I had found.  Would I have done the same if this were a democrat?  Probably.  For me, it&#8217;s about computer security and data privacy, not about political affliation.</p>
<h3>You can become Norm Coleman&#8217;s Website Admin</h3>
<p>I will give them the benefit of the doubt and assume I was only able to get here because the website is not functioning.  Below you can see that I could enter an email address, name and password and if this site was working, it would create an administrator in the database.  I found similar files to edit and delete records as well.  Being able to write to the database like this from a form should require an authenticated and active session but I can&#8217;t see the code so I don&#8217;t know.</p>
<p><strong><a title="wow, is it this easy to create an admin account at colemanforsenate.com? by adria.richards, on Flickr" href="http://www.flickr.com/photos/adriarichards/3234818883/"><img src="http://farm4.static.flickr.com/3362/3234818883_d9ba0a2b3e.jpg" alt="wow, is it this easy to create an admin account at colemanforsenate.com?" width="500" height="273" /></a></strong></p>
<h3>Indexing of directories is turned on</h3>
<p>This is a security risk.  I would hope they have .htaccess files in place to restrict access to the admin directory and that index listings are turned off for the current site.</p>
<p><strong><a title="directory of colemanforsenate.com at ip address 208.42.168.251 by adria.richards, on Flickr" href="http://www.flickr.com/photos/adriarichards/3234810551/"><img src="http://farm4.static.flickr.com/3399/3234810551_9298638b42.jpg" alt="directory of colemanforsenate.com at ip address 208.42.168.251" width="500" height="257" /></a></strong></p>
<h3>Website errors show you configuration file locations</h3>
<p>You see errors like this a lot on Joomla websites when there is a problem connecting to the database, there is a permissions issue on a file or when files are missing.</p>
<p><strong><a title="Incorrectly configured Linux server to blame? colemanforsenate.com by adria.richards, on Flickr" href="http://www.flickr.com/photos/adriarichards/3234816307/"><img src="http://farm4.static.flickr.com/3355/3234816307_77ff329fbd.jpg" alt="Incorrectly configured Linux server to blame? colemanforsenate.com" width="500" height="348" /></a></strong></p>
<h3>Missing log files</h3>
<p>This directory is empty.  It doesn&#8217;t mean there are no log files (deleted?)</p>
<p><strong><a title="why is this directory for log files empty on the colemanforsenate.com website? by adria.richards, on Flickr" href="http://www.flickr.com/photos/adriarichards/3235661804/"><img src="http://farm4.static.flickr.com/3460/3235661804_194029b045.jpg" alt="why is this directory for log files empty on the colemanforsenate.com website?" width="500" height="209" /></a></strong></p>
<h3>Site is down again</h3>
<p>So, the site is being reported by OpenDNS.com as down again and I am getting the same info at <a href="http://private.dnsstuff.com/tools/traversal.ch?domain=colemaneforsenate.com&amp;type=A&amp;token=11a0aba66da33b3d25d2b49601999019">DNSStuff.com</a> too.</p>
<p><strong><a title="colemanforsenate.com is back down again accordin to OpenDNS.com by adria.richards, on Flickr" href="http://www.flickr.com/photos/adriarichards/3234884877/"><img src="http://farm4.static.flickr.com/3498/3234884877_194085762d.jpg" alt="colemanforsenate.com is back down again accordin to OpenDNS.com" width="500" height="286" /></a></strong></p>
<p>The moral of the story is that you should hire computer and website professionals who understand technology.  You should plan and develop a strategy for downtime and problems.  Don&#8217;t put all your eggs into one basket with one website programmer.  If he or she is hit by a truck (or something goes wrong on the website and they have no recourse to help you.</p>
<p><a name="resources-protect"></a></p>
<h3>Resources to protect your data</h3>
<p>Minnesota Law on Data Security Breach Notification, Statute 325E.61 &#8211; This describes <a href="https://www.revisor.leg.state.mn.us/statutes/?id=325E.61">what needs to be lost for a company to notify you and how they must go about doing it</a>.  Unfortunately, it seems a company can lose your full name, address, income, number of children and previous purchases BUT not be required to tell you.  (Disclaimer: I am not a lawyer)</p>
<p><a href="http://www.privacyrights.org/ar/ChronDataBreaches.htm#2009">Data Security Breaches</a> in the US <a href="http://www.privacyrights.org/ar/ChronDataBreaches.htm#2005">2005</a>, <a href="http://www.privacyrights.org/ar/ChronDataBreaches.htm#2006">2006</a>, <a href="http://www.privacyrights.org/ar/ChronDataBreaches.htm#2007">2007</a>, <a href="http://www.privacyrights.org/ar/ChronDataBreaches.htm#2008">2008</a>, <a href="http://www.privacyrights.org/ar/ChronDataBreaches.htm#2009">2009</a> &#8211; Check to see if a school you attended, a doctor you saw, an employer, your local Veterans office, your bank, your utility company, your library or even a hotel you stayed at is listed here.</p>
<h3><a name="resources-website-security"></a>Resources for website security</h3>
<p><a href="http://www.acunetix.com/websitesecurity/application-scanning-wp.htm">The Importance of Web Application Scanning</a> &#8211; Acunetix makes an application that can scan websites for vulnerabilities.  There is a <a href="http://www.acunetix.com/cross-site-scripting/scanner.htm">free version</a> that will check for XSS (Think back to when Barack Obama&#8217;s website <a href="http://news.netcraft.com/archives/2008/04/21/hacker_redirects_barack_obamas_site_to_hillaryclintoncom.html">redirected</a> to Hillary Clinton&#8217;s).</p>
<p><a href="http://uis.georgetown.edu/web/hosting/securityexamples.html">3 Common Website Security Problems</a> &#8211; This article from Georgetown University  summarizes how issues on Norm Coleman’s site could have been addressed before “Crashgate”, especially this one on unsecured files and databases:</p>
<blockquote><p>Unsecured files and databases</p>
<p>When setting up your web site or application, make sure that any files that contain data that is not intended to be public (such as information about people) are not located in public web folders. Do not place such files in folders with the belief that because you are not linking to them, a user cannot find them.</p>
<ul>
<li>Files (such as Access databases) that are datasources for your application must be located in a non-web-accessible folder (the web_datasources folder in your hosting account).</li>
<li>Other files that contain data used by the application should also be located in a non-web-accessible folder.</li>
<li>Other files that contain non-public information should be placed in a folder that is access restricted using a .htaccess file or other web server access restriction.</li>
</ul>
</blockquote>
<p><strong>Update 12:12am 1/29/2009</strong></p>
<p style="padding-left: 30px">Folks, the directory listing for colemanforsenator.com has been replaced with a login box.  But&#8230;we know what&#8217;s behind the curtain now.</p>
<p style="padding-left: 30px"><a title="Login box replaces 205mb database on colemanforsenate.com by adria.richards, on Flickr" href="http://www.flickr.com/photos/adriarichards/3236163136/"><img src="http://farm4.static.flickr.com/3082/3236163136_2527847dfb.jpg" alt="Login box replaces 205mb database on colemanforsenate.com" width="500" height="220" /></a></p>
<p><strong>Update 5:40pm 1/29/2009</strong></p>
<p style="padding-left: 30px">Stay tuned for video posting from the 1/29/2009 lifestream:</p>
<p>&#8220;Norm Coleman&#8217;s Database&#8221;</p>
<ul>
<li>why the database was available</li>
<li>what it contained</li>
<li>how website developers and companies can work to prevent this from happening</li>
<li>and take questions from viewers</li>
</ul>
<p><strong>Update 11:11pm 1/29/2009</strong></p>
<p style="padding-left: 30px">Number of hits to the post 54</p>
<p style="padding-left: 30px">Photo stats for the post<br />
<a href="http://flickr.com/photos/adriarichards/3234833407/stats/">I wonder how much user information is in this database at colemanforsenate.com? </a> 1,458 views<br />
<a href="http://flickr.com/photos/adriarichards/3234818883/stats/">You can become Norm Coleman&#8217;s Website Administrator at colemanforsenate.com </a> 290 views</p>
<p style="padding-left: 30px">Current rumors<br />
The database contains social security numbers<br />
The database contains credit card information (POST data)<br />
<a name="updates"></a><br />
Update 6:54pm 1/30/2009</p>
<p style="padding-left: 30px">Number of hits to the post 610<br />
In-Progress Video of &#8220;Norm Coleman&#8217;s Database: What Happened and Why&#8221;</p>
<p style="padding-left: 30px">Post picked up on:<br />
<a href="http://www.politicsinminnesota.com/index.php?q=2009/jan30/1770/epic-recount-website-fail-one-dot-one-dot-one-dot-one">Politics in Minnesota &#8211; Epic recount website fail: One Dot One Dot One Dot One</a></p>
<p><em>Thanks to Ben for picking out the incorrect use of &#8220;then&#8221; when I should have used &#8220;than&#8221; in the header &#8220;What&#8217;s worse than losing a Minnesota Sentate race?&#8221;</em></p>
<p><strong></strong></p>
<h3><strong>FYI:  If you enter a fake looking email address with your comment, I will probably not approve it.  If you want to share something with me offline, use the contact page.  Thanks!</strong></h3>
<p><strong></strong></p>
<p><strong>Question from Dennis</strong><br />
What does &#8220;Awaiting Moderation Mean?  Where&#8217;s my comment?</p>
<p><strong>Answer</strong><br />
I did not publish your comment because there was NOTHING technical in it.  I have published comments that:</p>
<ul> * indicate how they feel about the info being released<br />
* indicate how they feel about what I did as an IT person doing this<br />
* ask questions related to the technology aspect of the Norm Coleman database<br />
* share personal stories on how this affected them<br />
* thank me for my efforts<br />
* support me for taking initiative<br />
* judge, criticize and blame me for making the wrong choice</ul>
<p>If you just want to harp on Democrats vs Republicans and Norm Coleman vs Al Franken, you should go to a political blog and do that.</p>
<img src="http://butyoureagirl.com/?ak_action=api_record_view&id=1555&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://butyoureagirl.com/2009/01/28/did-norm-coleman-fake-his-own-website-death/feed/</wfw:commentRss>
		<slash:comments>92</slash:comments>
		</item>
	</channel>
</rss>
