Posts in Kudos, Opinions and Rants
Page Content
Google 419, Part II
[tags]Google, spam, 419[/tags]
I recently blogged about some unsolicited email I received from a recruiter at Google. Much to my surprised, I was shortly thereafter contacted by two senior executives at Google (both of whom I know). Each apologized for the contact I had received; one assured me he would put in a positive recommendation if I wanted that sys admin position. :-)
I have been assured that there will be some re-examination made of how these contacts are made. So, score one for my blog changing the world! Or something like it.
[posted with ecto]
Google learning from the Nigerians?
[tags]Google, spam[/tags]
Today I received email from a google.com address. The sender said he had found me by doing a search on the WWW. He indicated he hoped I wasn't offended by his sending unsolicited email. However, he had a great offer for me, one that I was uniquely qualified for, and then offered a couple of URLs.
Does that sound familiar?
My first thought was that it was a 419 scam (the usual “I am the son of the crown prince of Nigeria...” letters). However, after checking out the mail headers and the enclosed URLs, it appears to be a (semi) legit letter from a Google recruiter. He was asking if I was open to considering a new, exciting position with Google.
And what exciting new position does the Google recruiter think I'm ideally suited for? Starting system administrator.....
And by the way, sending email to “abuse@google.com” gets an automated response that states, in no uncertain terms, that Google never sends spam and that I should take my complaints elsewhere.
Gee, think this is a new career possibility for me?
[posted with ecto]
The gutting of cybersecurity
I strongly urge you to read Jim Horning's blog entry about a recent Congressional hearing on cyber security research -- his blog is Nothing is as simple as we hope it will be. (Jim posts lots of interesting items -- you should add his blog to your list.)
I have been visiting Federal offices and speaking before Congress for almost 20 years trying to raise some awareness of the importance of addressing information security research. More recently, I was a member of the President's Information Technology Advisory Committee (PITAC). We studied the current funding of cybersecurity research and the magnitude of the problem. Not only was our report largely ignored by both Congress and the President, the PITAC was disbanded. For whatever reason, the current Administration is markedly unsupportive of cyber security research, and might even be classed as hostile to those who draw attention to this lack of support.
Of course, there are many other such reports from other august groups that state basically the same as the PITAC report. No matter who has issued the reports, Congress and the Executive Branch have largely failed to address the issues.
Thus, it is heartening to read of Chairman Langevin's comments. However, I'm not going to get my hopes up.
Be sure to also read Dan Geer's written testimony. It touches on many of the same themes he has spoken about in recent years, including his closing keynote at our annual CERIAS Security Symposium (save the dates -- March 19 & 20, 2008 -- for the next symposium).
Copyright © 2007 by E. H. Spafford
[posted with ecto]
This Week at CERIAS
CERIAS Reports & Papers
-
30 April 2007, 7:00 pm
-
29 April 2007, 7:00 pm
-
28 April 2007, 7:00 pm
-
28 April 2007, 7:00 pm
CERIAS Weblogs
-
3 May 2007, 3:10 pm
-
1 May 2007, 1:11 pm
-
27 April 2007, 1:27 pm
“Verified by VISA” Issues
- I was unexpectedly requested to register my card after doing some shopping online on a site that allowed customer comments, and had forced me to turn on JavaScript.
- I knew nothing about this program, and the request was presented in an authoritative manner, implying that I *had* to register or else my purchase would be denied. (Bull! Even though I closed my browser without completing the registration, my purchase went through)
- I was asked for the last 4 digits of my SSN as proof of identity (!), along with information I had just provided to the online merchant (CC number, phone number, etc...)
- There was no explanation or link to an explanation of what was going on, why VISA would want me to register my card and what was this program.


