-Caveat Lector- www.ctrl.org DECLARATION & DISCLAIMER ========== CTRL is a discussion & informational exchange list. Proselytizing propagandic screeds are unwelcomed. Substance—not soap-boxing—please! These are sordid matters and 'conspiracy theory'—with its many half-truths, mis- directions and outright frauds—is used politically by different groups with major and minor effects spread throughout the spectrum of time and thought. That being said, CTRLgives no endorsement to the validity of posts, and always suggests to readers; be wary of what you read. CTRL gives no credence to Holocaust denial and nazi's need not apply.

Let us please be civil and as always, Caveat Lector. ======================================================================== Archives Available at:

http://www.mail-archive.com/[EMAIL PROTECTED]/ <A HREF="">ctrl</A> ======================================================================== To subscribe to Conspiracy Theory Research List[CTRL] send email: SUBSCRIBE CTRL [to:] [EMAIL PROTECTED]

To UNsubscribe to Conspiracy Theory Research List[CTRL] send email: SIGNOFF CTRL [to:] [EMAIL PROTECTED]

Om

--- Begin Message ---
-Caveat Lector-

http://www.atstake.com/events_news/press_releases/template.html?europe/121603
New Bluetooth Devices Set Up Replay of WiFi Security Crisis, @stake Warns

With a 100m range, Class A devices must be secured "out of the box"

London, December 16th, 2003 - @stake, Inc., (www.atstake.com), the leading
digital security consulting firm, today warned that the mass arrival of
Class 1 Bluetooth devices, with a transmission range of up to 100 metres,
might usher in a security crisis equivalent to that associated with the
introduction of Wireless LANs based on the 802.11b (Wi-Fi) standard. Class 1
devices will appear on everything from laptops to mobile phones, meaning
that rogue third parties may gain access to sensitive information and/or
interfaces without the obstacles of hunting through corporate networks.
Ollie Whitehouse, Director of Security Architecture, @stake, said, "With
this class of devices, wireless transmission of information leaves the
office environment and travels anywhere an employee does. This means that
third parties can access information without penetrating the physical
security of an office or dealing with the problems of circumventing existing
network security. The onus really is on vendors to ensure that all devices
are optimised for security before they are put in the hands of customers."
In a recent White Paper, @stake drew attention to the fact that devices
released as non-discoverable still respond to direct name and services
enquiry and were therefore open to detection and attack. Other common
problems identified included: Windows 2000 hosts that were configured to
connect to all Bluetooth devices; Windows registries that retained details
of all devices to which it had connected; and mobile phones set by their
manufacturers to retain pairing information details when SIM cards are
swapped, meaning that a third party that has access to a phone for even a
few minutes can place a bond upon it and use it as a platform for future
attacks.
Whitehouse continued, "The very real risks of Bluetooth will only multiply
as adoption increases and the drivers vary from their default
configurations. Many vendors release Bluetooth products with a best effort
approach to security that can only compromise the integrity of the
information held on those devices. Vendors should understand these issues
and risks and develop mechanisms for delivering security out of the box.
While it's not a time to panic, it's certainly a time to act."
Two key vulnerabilities potentially exposed by the Bluetooth are associated
with the OBEX standard that deals with vCards and other Personal Information
Manager synchronisation details and the file transfer Protocol which relates
to the transfer of data and applications from the device. This means that
literally any stored personal information or document to which the user has
access can potentially accessed by third parties - both significant
compromises of enterprise security.
About @stake, Inc.
@stake, Inc., the premier digital security consulting firm, helps
corporations secure critical infrastructure and electronic relationships.
Delivering world-class consulting and education through its SmartRisk
methodology and proprietary tools, @stake clients include six of the world's
tops ten financial institutions, four of the world's top ten independent
software companies and seven of the world's top ten telecommunications
carriers. Using the @stake Security BlueprintT, clients keep security
investments in line with business requirements. Headquartered in Cambridge,
MA, @stake has offices in Chicago, London, New York, Raleigh, San Francisco,
and Seattle. For more information, go to www.atstake.com.
For further information Contact:
Brodeur Worldwide
Ghezala Beg (Tel: 0207 298 7063) or Vicki Cook (Tel: 0207 298 7113)


-__ ___ _ ___ __ ___ _ _ _ __
/-_|-0-\-V-/-\|-|-__|-|-|-/-_|
\_-\--_/\-/|-\\-|-_||-V-V-\_-\
|__/_|--//-|_|\_|___|\_A_/|__/

 SPY NEWS is OSINT newsletter and discussion list associated to
Mario's Cyberspace Station - The Global Intelligence News Portal
 http://mprofaca.cro.net

######## CAUTION! #########
 Since you are receiving and reading documents, news stories,
comments and opinions not only from so called (or self-proclaimed)
"reliable sources", but also a lot of possible misinformation collected
by Spy News moderator and subscribers and posted to Spy News
for OSINT purposes - it should be a serious reason (particularly to
journalists and web publishers) to think twice before using it for their
story writing, further publishing or forwarding throughout Cyberspace.

To unsubscribe:
mailto:[EMAIL PROTECTED]

*** FAIR USE NOTICE: This message contains copyrighted material whose use has not been 
specifically authorized by the copyright owner. Spy News is making it available 
without profit to SPY NEWS eGroup members who have expressed a prior interest in 
receiving the included information in their efforts to advance the understanding of 
intelligence and law enforcement organizations, their activities, methods, techniques, 
human rights, civil liberties, social justice and other intelligence related issues, 
for non-profit research and educational purposes only. We believe that this 
constitutes a 'fair use' of the copyrighted material as provided for in section 107 of 
the U.S. Copyright Law. If you wish to use this copyrighted material for purposes of 
your own that go beyond 'fair use,' you must obtain permission from the copyright 
owner.
For more information go to:
http://www.law.cornell.edu/uscode/17/107.shtml

 -----------------------------------------------

 SPY NEWS home page:
 http://groups.yahoo.com/group/spynews

 Mario Profaca
 http://mprofaca.cro.net/

Yahoo! Groups Links

To visit your group on the web, go to:
 http://groups.yahoo.com/group/spynews/

To unsubscribe from this group, send an email to:
 [EMAIL PROTECTED]

Your use of Yahoo! Groups is subject to:
 http://docs.yahoo.com/info/terms/



www.ctrl.org
DECLARATION & DISCLAIMER
==========
CTRL is a discussion & informational exchange list. Proselytizing propagandic
screeds are unwelcomed. Substance—not soap-boxing—please!   These are
sordid matters and 'conspiracy theory'—with its many half-truths, mis-
directions and outright frauds—is used politically by different groups with
major and minor effects spread throughout the spectrum of time and thought.
That being said, CTRLgives no endorsement to the validity of posts, and
always suggests to readers; be wary of what you read. CTRL gives no
credence to Holocaust denial and nazi's need not apply.

Let us please be civil and as always, Caveat Lector.
========================================================================
Archives Available at:

http://www.mail-archive.com/[EMAIL PROTECTED]/
<A HREF="http://www.mail-archive.com/[EMAIL PROTECTED]/">ctrl</A>
========================================================================
To subscribe to Conspiracy Theory Research List[CTRL] send email:
SUBSCRIBE CTRL [to:] [EMAIL PROTECTED]

To UNsubscribe to Conspiracy Theory Research List[CTRL] send email:
SIGNOFF CTRL [to:] [EMAIL PROTECTED]

Om

--- End Message ---

Reply via email to