<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>(-) HatSecurity.com &#187; privacy</title>
	<atom:link href="http://hatsecurity.com/tag/privacy/feed/" rel="self" type="application/rss+xml" />
	<link>http://hatsecurity.com</link>
	<description>../something for all Hats</description>
	<lastBuildDate>Sat, 07 Mar 2009 15:33:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>RIM unable to honor India Gov demand</title>
		<link>http://hatsecurity.com/2008/05/27/rim-unable-to-honor-india-gov-demand/</link>
		<comments>http://hatsecurity.com/2008/05/27/rim-unable-to-honor-india-gov-demand/#comments</comments>
		<pubDate>Tue, 27 May 2008 05:08:13 +0000</pubDate>
		<dc:creator>Tahir</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[opinions]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[RIM]]></category>
		<category><![CDATA[secure email]]></category>

		<guid isPermaLink="false">http://hatsecurity.com/?p=22</guid>
		<description><![CDATA[Canadian wireless device company, Research in Motion (RIM), maker of the popular Blackberry handheld communication device, has finally broken the silence surrounding Indian Government&#8217; demands to handover the &#8220;keys&#8221; to decrypt secure email communications. RIM claims that it not possible to handover the decryption keys and claims setting up a local datacenter would serve no [...]]]></description>
			<content:encoded><![CDATA[<p>Canadian wireless device company, <a href="http://www.rim.com/" target="_self">Research in Motion (RIM)</a>, maker of the popular <a href="http://www.blackberry.com/" target="_blank">Blackberry </a>handheld communication device, has finally broken the silence surrounding Indian Government&#8217; <a href="http://www.telegraphindia.com/1080308/jsp/frontpage/story_8995396.jsp" target="_blank">demands</a> to handover the &#8220;keys&#8221; to decrypt secure email communications.</p>
<p>RIM claims that it not possible to handover the decryption keys and claims setting up a local datacenter would serve no purpose given the end-to-end security deployed in its solution. RIM further declared that its solution architecture is designed in a way that does not allow any third party including RIM to read the email data under any circumstances. <span id="more-22"></span>On the 23rd of May, RIM sent this note to its customers:</p>
<blockquote><p>“The use of strong encryption in wireless technology is not unique to the BlackBerry platform. Strong encryption is used pervasively on the Internet to protect the confidentiality of personal and corporate information. Governments have a wide range of resources and methodologies to satisfy national security and law enforcement needs without compromising commercial security requirements.”</p></blockquote>
<p>This is not to be confused with BlackBerry hosted service for which RIM has <a href="http://economictimes.indiatimes.com/Telecom/Govt_may_get_keys_to_your_BlackBerry_mailbox_soon/articleshow/3041313.cms" target="_blank">probably handed over</a> the decryption keys to the Indian Government.</p>
<p>The BlackBerry enterprise solution architecture is provided below (click to enlarge):</p>
<p style="text-align: center;"><a href="http://hatsecurity.com/wp-content/uploads/2008/05/blackberry_architecture.jpg" target="_blank"><img class="size-medium wp-image-21 aligncenter" style="vertical-align: middle;" title="blackberry_architecture" src="http://hatsecurity.com/wp-content/uploads/2008/05/blackberry_architecture-300x129.jpg" alt="" width="300" height="129" /></a></p>
<p>All communications between the BlackBerry Enterprise Server (BES), located on the corporate network, and the BlackBerry handheld devices are secured using a 256-bit AES cryptosystem. Furthermore, all newer BlackBerry handheld devices contain cryptographic kernel that <a href="http://csrc.nist.gov/groups/STM/cmvp/documents/140-1/140crt/140crt939.pdf" target="_blank">conforms</a> (PDF) to the NIST&#8217;s <a href="http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf" target="_blank">FIPS 140-2 Overall Level 1 standard</a> (PDF) making it the most secure commercially available wireless devices for email communications available today.</p>
<p>What better reason to be worried when the your technology can&#8217;t cope up with anything better than 40-bit encryption?</p>
]]></content:encoded>
			<wfw:commentRss>http://hatsecurity.com/2008/05/27/rim-unable-to-honor-india-gov-demand/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Personal details of over 7m Chileans leaked</title>
		<link>http://hatsecurity.com/2008/05/12/personal-details-of-over-7m-chileans-leaked/</link>
		<comments>http://hatsecurity.com/2008/05/12/personal-details-of-over-7m-chileans-leaked/#comments</comments>
		<pubDate>Mon, 12 May 2008 01:41:38 +0000</pubDate>
		<dc:creator>Tahir</dc:creator>
				<category><![CDATA[general]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[chile]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://hatsecurity.com/?p=4</guid>
		<description><![CDATA[Personal information of almost half the national population of Chile was leaked on the Internet at about 1:30 AM CLT on Saturday, May 10th. The names, addresses, academic and social status information along with other details were uploaded to the popular file-sharing website, rapidshare.com and a Chilean file sharing site, compartelo.cl. The download links to [...]]]></description>
			<content:encoded><![CDATA[<p>Personal information of almost half the national population of Chile was leaked on the Internet at about 1:30 AM CLT on Saturday, May 10th.</p>
<p>The names, addresses, academic and social status information along with other details were uploaded to the popular file-sharing website, rapidshare.com and a Chilean file sharing site, compartelo.cl. The download links to three files were posted on the public forums on <a title="FayerWayer.com" href="http://www.fayerwayer.com/2008/05/alerta-se-filtran-datos-personales-de-6-millones-de-chilenos-via-internet" target="_blank">FayerWayer.com</a>, the popular Chilean technology blog.</p>
<p>The information is reportedly obtained from Government bodies: the Dirección General de Movilización Nacional (Directorate of National Mobilization) &#8211; DGMN, the Servicio Electoral (Electoral Service) &#8211; SERVEL, the Ministry of Education &#8211; Mineduc. It also contains over 2 million telephone records for 849 cities in Chile</p>
<p>According to the conservative Chilean news agency, <a title="El Mercurino" href="http://diario.elmercurio.com/2008/05/11/nacional/nacional/noticias/0F85CC8B-2085-468B-BC5D-1AEA14AB5A18.htm?id=%7B0F85CC8B-2085-468B-BC5D-1AEA14AB5A18%7D" target="_blank">El Mercurio</a>, police are still investigating the leaked information to confirm the hacker&#8217;s claims.</p>
<p><span id="more-4"></span>Although the forum posts on FayerWayer.com were deleted, the pages are accessible from Google&#8217;s cache providing the download links. As of this writing, the files are still accessible from rapidshare.com servers but have been deleted from compartelo.cl servers.</p>
<p>A copy of the text contained in the Readme.txt, included with the three files, is provided below:</p>
<blockquote><p>Bases de Datos de Chile<br />
Formato: CSV (Comma Separated Version)</p>
<p>Intro:<br />
La idea de estas bases de datos es:<br />
a) Mostrar lo mal protegidos que estan los datos en Chile<br />
b) Ya que nadie se esmera en proteger esta informacion, hacerla publica para todo el mundo</p>
<p>Descripcion de los Datos:<br />
a) DGMN:<br />
8.919 Personas &#8211; dgmn.csv</p>
<p>b) Mineduc:<br />
1.211.854 Personas &#8211; mineduc.csv<br />
77.024 Personas &#8211; mineduc_con_folio.csv</p>
<p>c) Servel:<br />
353.588 Personas &#8211; servel1.csv<br />
3.512.091 Personas &#8211; servel2.csv</p>
<p>d) Telefonos:<br />
2.034.191 Personas &#8211; telefonos.csv<br />
849 Ciudades &#8211; ciudades.csv</p>
<p>e) PSU 2005:<br />
4.925 Establecimientos &#8211; ARCHIVO_A_2005.DAT<br />
175.506 Personas &#8211; ARCHIVO_B_2005.DAT</p>
<p>Nota: PSU no es esta en formato CSV. Detalles adjuntos en Requni_2005_v1.pdf</p>
<p>Como Usar (Basico):<br />
Importe estos datos con Microsoft Access o OpenOffice Base y utilicelos. Puede generar formularios para una presentacion mas user-friendly de estos.</p>
<p>Como Usar (Avanzado):<br />
Altamente recomendable subir estos datos a una Base de Datos antes de trabajar con ellos.<br />
MySQL o Postgres se comportan mas que bien con este volumen de datos.<br />
Para busquedas en campos de textos, muy recomendable utilizar FullText Index (disponible en MySQL y como plugin externo (unstable creo) en Postgres).</p>
<p>Futuro:<br />
La idea seria que si alguien encuentra un lugar de donde recolectar datos publicos, haga un script que los baje y una vez recolectados los datos, los guarde en un archivo CSV, lo firme digitalmente (pero con un pseudonimo si lo desea) y lo agrege a la recompilacion de datos.</p>
<p>Ideas para los Geeks:<br />
a) Comprobar la consistencia de los datos (mismo rut, mismo nombre)<br />
b) Generar un archivo KML para mostrar en Google Earth / Google Maps / Otro para ver graficamente en el mapa donde vive cada persona. Asi tambien se puede conocer los nombres de los vecinos o quienes viven en ciertos lugares.<br />
c) Hacer un Front-End para la base de datos, que sea extensible y haga busquedas en todas las tablas. Esperable que sea CrossPlatform (Java, C++) y que soporte Plugins. Features Posibles: Click en una persona y si tiene su direccion, que la muestre en el mapa. Si tiene su folio del pase escolar, que muestre sus recorridos segun los datos del TarjetaBip.cl.<br />
d) Descubrir estadisticas y datos freak. (Ej: La hija de Bachelet tiene pase escolar, aun cuando a mucha gente no se lo dan porque sus padres ganan mas de una cierta cantidad).</p>
<p>Tips Para Recolectar nuevos Datos:</p>
<p>a) Si van a sacar datos de un servidor, recomendable hacer un script que se conecte no directamente al servidor, sino que a traves de TOR + Privoxy (o proxys anonimos).<br />
b) No ocupen su conexion a Internet, para eso nuestros queridos vecinos dejan sus redes WiFi abiertas.<br />
c) Tengan todo en discos encriptados. Recomendable: TrueCrypt, dm-crypt (o algun full disk encryption para su distribucion de Linux).<br />
d) Solo tengan los datos y programas necesarios para recolectar datos en una maquina virtual, sin ningun datos personal ni email.<br />
e) No se caliente la cabeza a la hora de hacer sus programas, para eso estan los lenguajes de scripting: perl, php y python.<br />
f) www.servel.cl todavia deja obtener datos</p>
<p>Saludos !</p>
<p>a) &#8220;Until they become conscious they will never rebel, and until after they have rebelled they cannot become conscious.&#8221;<br />
b) &#8220;La nada, la que con su ausencia lo llena todo.&#8221;</p></blockquote>
<p>The hacker identified himself as &#8220;Cobarde Anonimo&#8221; (Anonymous Coward) and claims that the records were leaked &#8220;to demonstrate how poorly protected the data in Chile is, and how nobody works to protect it&#8221;.</p>
<p>What does the Chilean Government have to say about this? Below is a Google <a href="http://translate.google.com" target="_blank">translation</a> of a statement from <a title="Francisco Vidal" href="http://www.chileangovernment.cl/index.php?option=com_content&amp;task=view&amp;id=1068&amp;Itemid=5" target="_blank">Francisco Vidal</a>, the Chile Minister of Government Affairs as quoted <a href="http://www.fayerwayer.com/2008/05/gobierno-comienza-investigacion-de-filtracion-de-datos-personales-de-6-millones-de-chilenos/" target="_blank">here:</a></p>
<blockquote><p><span style="background-color: #e6ecf9;" onmouseover="_tipon(this)" onmouseout="_tipoff()">&#8220;I do not understand anything of computing, just know that there is something called hacker.</span> <span onmouseover="_tipon(this)" onmouseout="_tipoff()">[…] To Mr hacker must Pill. &#8220;</span></p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://hatsecurity.com/2008/05/12/personal-details-of-over-7m-chileans-leaked/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
