<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Hannaford Data Breach is Likely Much Worse Than Reported</title>
	<atom:link href="http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/</link>
	<description>tech, science, news and social issues for geeks</description>
	<lastBuildDate>Sun, 08 Nov 2009 08:35:30 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Hannaford Breach Followup: Malware on All of Their Servers</title>
		<link>http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/comment-page-1/#comment-55080</link>
		<dc:creator>Hannaford Breach Followup: Malware on All of Their Servers</dc:creator>
		<pubDate>Tue, 01 Apr 2008 18:06:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/#comment-55080</guid>
		<description>[...] your groceries are belong to us.&#8221; According to a ComputerWorld article, the Hannaford Breach was not just a single keylogger installed at a critical point in the enterprise. Malware was [...]</description>
		<content:encoded><![CDATA[<p>[...] your groceries are belong to us.&#8221; According to a ComputerWorld article, the Hannaford Breach was not just a single keylogger installed at a critical point in the enterprise. Malware was [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Followup: Hannaford Used Rapid7 for Security</title>
		<link>http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/comment-page-1/#comment-51894</link>
		<dc:creator>Followup: Hannaford Used Rapid7 for Security</dc:creator>
		<pubDate>Wed, 19 Mar 2008 16:01:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/#comment-51894</guid>
		<description>[...] Brothers Supermarkets didn&#8217;t know much about cybersecurity, but then again, most companies don&#8217;t.   Companies that don&#8217;t use a full-time infosec [...]</description>
		<content:encoded><![CDATA[<p>[...] Brothers Supermarkets didn&#8217;t know much about cybersecurity, but then again, most companies don&#8217;t.   Companies that don&#8217;t use a full-time infosec [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tony Lawrence</title>
		<link>http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/comment-page-1/#comment-51848</link>
		<dc:creator>Tony Lawrence</dc:creator>
		<pubDate>Wed, 19 Mar 2008 11:07:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/#comment-51848</guid>
		<description>I see Nexpose has already nuked that Google result :-)</description>
		<content:encoded><![CDATA[<p>I see Nexpose has already nuked that Google result :-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BelchSpeak</title>
		<link>http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/comment-page-1/#comment-51816</link>
		<dc:creator>BelchSpeak</dc:creator>
		<pubDate>Wed, 19 Mar 2008 04:55:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/#comment-51816</guid>
		<description>This post here by Attrition may warrant its own follow up post tomorrow.  Until then enjoy the LULZ.

http://attrition.org/security/rant/z/rapid7.html</description>
		<content:encoded><![CDATA[<p>This post here by Attrition may warrant its own follow up post tomorrow.  Until then enjoy the LULZ.</p>
<p><a href="http://attrition.org/security/rant/z/rapid7.html" rel="nofollow">http://attrition.org/security/rant/z/rapid7.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BelchSpeak</title>
		<link>http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/comment-page-1/#comment-51813</link>
		<dc:creator>BelchSpeak</dc:creator>
		<pubDate>Wed, 19 Mar 2008 04:47:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/#comment-51813</guid>
		<description>Actually, they discovered the breach on the 27th of February, Gins.  They reported it 2 and a half weeks later.  They realized that it had been going on since the 7th of Dec.

As far as doublespeak goes, this is what it means:  2.5 weeks were spent determining their liability and how to continue their business and plug the holes at the same time.  This is not so bad-  every business has to be able to do this in case it happens.  The real question is:  Did they have a working plan in place for such a disaster?  Probably not, which caused part of the delay in reporting.</description>
		<content:encoded><![CDATA[<p>Actually, they discovered the breach on the 27th of February, Gins.  They reported it 2 and a half weeks later.  They realized that it had been going on since the 7th of Dec.</p>
<p>As far as doublespeak goes, this is what it means:  2.5 weeks were spent determining their liability and how to continue their business and plug the holes at the same time.  This is not so bad-  every business has to be able to do this in case it happens.  The real question is:  Did they have a working plan in place for such a disaster?  Probably not, which caused part of the delay in reporting.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kiltak</title>
		<link>http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/comment-page-1/#comment-51804</link>
		<dc:creator>Kiltak</dc:creator>
		<pubDate>Wed, 19 Mar 2008 02:34:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/#comment-51804</guid>
		<description>There&#039;s nothing amusing in this post my friend :)</description>
		<content:encoded><![CDATA[<p>There&#8217;s nothing amusing in this post my friend :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Poppy</title>
		<link>http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/comment-page-1/#comment-51801</link>
		<dc:creator>Poppy</dc:creator>
		<pubDate>Wed, 19 Mar 2008 02:15:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/#comment-51801</guid>
		<description>I am not amused.</description>
		<content:encoded><![CDATA[<p>I am not amused.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gins</title>
		<link>http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/comment-page-1/#comment-51772</link>
		<dc:creator>Gins</dc:creator>
		<pubDate>Tue, 18 Mar 2008 22:53:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/#comment-51772</guid>
		<description>They knew didn&#039;t contain it for 3 months? What does that mean in doublespeak?
GAH that pisses me off....the only reason I have used my card there is when I went to see my daughter and bought her groceries. Def within that time period.</description>
		<content:encoded><![CDATA[<p>They knew didn&#8217;t contain it for 3 months? What does that mean in doublespeak?<br />
GAH that pisses me off&#8230;.the only reason I have used my card there is when I went to see my daughter and bought her groceries. Def within that time period.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PatB</title>
		<link>http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/comment-page-1/#comment-51755</link>
		<dc:creator>PatB</dc:creator>
		<pubDate>Tue, 18 Mar 2008 21:34:50 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/#comment-51755</guid>
		<description>Its been a while, but I still see the 7-11&#039;s in my area using old cisco boxes for vpn back to corporate.  Same with automotive companies from sam&#039;s used cars to bill&#039;s new chevys.</description>
		<content:encoded><![CDATA[<p>Its been a while, but I still see the 7-11&#8217;s in my area using old cisco boxes for vpn back to corporate.  Same with automotive companies from sam&#8217;s used cars to bill&#8217;s new chevys.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tony Lawrence</title>
		<link>http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/comment-page-1/#comment-51752</link>
		<dc:creator>Tony Lawrence</dc:creator>
		<pubDate>Tue, 18 Mar 2008 21:31:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/#comment-51752</guid>
		<description>:-)

Ayup.  I&#039;ve been in the &quot;router/bathroom&quot; rooms.. more often for reasons having to do with the router.. 

I also love the &quot;We don&#039;t know where it is&quot; places.. the wires disappear into the wall and it can be such fun finding the source..  and what&#039;s this &quot;Cisco&quot; you mention? I think you are more likely to find a $50 Linksys..</description>
		<content:encoded><![CDATA[<p>:-)</p>
<p>Ayup.  I&#8217;ve been in the &#8220;router/bathroom&#8221; rooms.. more often for reasons having to do with the router.. </p>
<p>I also love the &#8220;We don&#8217;t know where it is&#8221; places.. the wires disappear into the wall and it can be such fun finding the source..  and what&#8217;s this &#8220;Cisco&#8221; you mention? I think you are more likely to find a $50 Linksys..</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PatB</title>
		<link>http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/comment-page-1/#comment-51749</link>
		<dc:creator>PatB</dc:creator>
		<pubDate>Tue, 18 Mar 2008 21:26:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/#comment-51749</guid>
		<description>They also typically place their tiny cisco routers or DSL boxes in the back rooms adjacent to the bathrooms too.  No physical security at all.</description>
		<content:encoded><![CDATA[<p>They also typically place their tiny cisco routers or DSL boxes in the back rooms adjacent to the bathrooms too.  No physical security at all.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tony Lawrence</title>
		<link>http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/comment-page-1/#comment-51748</link>
		<dc:creator>Tony Lawrence</dc:creator>
		<pubDate>Tue, 18 Mar 2008 21:24:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.geeksaresexy.net/2008/03/18/hannaford-data-breach-is-likely-much-worse-than-reported/#comment-51748</guid>
		<description>Actually, TJX didn&#039;t surprise me - I did some consulting for them years ago and didn&#039;t think much of their IT department then.. I bet there have been some big shakeups now..

The little jiffy mart is a good example.  It&#039;s probably a chain, and it probably operates on tight margins.. which could mean weak and underpaid/understaffed/highly stressed IT with a crappy budget..  nice target..</description>
		<content:encoded><![CDATA[<p>Actually, TJX didn&#8217;t surprise me &#8211; I did some consulting for them years ago and didn&#8217;t think much of their IT department then.. I bet there have been some big shakeups now..</p>
<p>The little jiffy mart is a good example.  It&#8217;s probably a chain, and it probably operates on tight margins.. which could mean weak and underpaid/understaffed/highly stressed IT with a crappy budget..  nice target..</p>
]]></content:encoded>
	</item>
</channel>
</rss>
