<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule"	>
<channel>
	<title>Comments on: Dave Crooke speaks about the Convio security breach</title>
	<atom:link href="http://www.nonprofittechblog.org/dave-crooke-speaks-about-the-convio-security-breach/feed" rel="self" type="application/rss+xml" />
	<link>http://www.nonprofittechblog.org/dave-crooke-speaks-about-the-convio-security-breach</link>
	<description>Confessions of a Non-Profit Executive Director</description>
	<lastBuildDate>Sat, 13 Mar 2010 11:46:18 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Spike3905</title>
		<link>http://www.nonprofittechblog.org/dave-crooke-speaks-about-the-convio-security-breach/comment-page-1#comment-68441</link>
		<dc:creator>Spike3905</dc:creator>
		<pubDate>Sun, 11 Nov 2007 01:13:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.nonprofittechblog.org/dave-crooke-speaks-about-the-convio-security-breach#comment-68441</guid>
		<description>I have just learned of this security breach. But my non-profit has been a Convio client for two years and we have spend tens of thousands of dollars and received zero benefit. The system isn&#039;t even operational yet because we haven&#039;t been able to get their attention for any extended period of time. Is this company going under?</description>
		<content:encoded><![CDATA[<p>I have just learned of this security breach. But my non-profit has been a Convio client for two years and we have spend tens of thousands of dollars and received zero benefit. The system isn&#8217;t even operational yet because we haven&#8217;t been able to get their attention for any extended period of time. Is this company going under?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: abolla-26730@mypacks</title>
		<link>http://www.nonprofittechblog.org/dave-crooke-speaks-about-the-convio-security-breach/comment-page-1#comment-67834</link>
		<dc:creator>abolla-26730@mypacks</dc:creator>
		<pubDate>Sat, 10 Nov 2007 01:45:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.nonprofittechblog.org/dave-crooke-speaks-about-the-convio-security-breach#comment-67834</guid>
		<description>well, since they took the computer away for forensic analysis, I assumed it was a case of spyware or malware.  I could be wrong.

But it really doesn&#039;t matter.  Convio either:

a) allowed an employee -- who has access to massive amounts of data -- to work from a home computer that did not have adequate protective software installed; OR

b) employed someone who doesn&#039;t know how to recognize and avoid a phishing attack, and gave them access to massive amounts of data.

Either way -- a colossal failure.  Not a technical failure, mind you, but a management failure, to put the right policies in place and enforce them rigorously.</description>
		<content:encoded><![CDATA[<p>well, since they took the computer away for forensic analysis, I assumed it was a case of spyware or malware.  I could be wrong.</p>
<p>But it really doesn&#8217;t matter.  Convio either:</p>
<p>a) allowed an employee &#8212; who has access to massive amounts of data &#8212; to work from a home computer that did not have adequate protective software installed; OR</p>
<p>b) employed someone who doesn&#8217;t know how to recognize and avoid a phishing attack, and gave them access to massive amounts of data.</p>
<p>Either way &#8212; a colossal failure.  Not a technical failure, mind you, but a management failure, to put the right policies in place and enforce them rigorously.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Allan Benamer</title>
		<link>http://www.nonprofittechblog.org/dave-crooke-speaks-about-the-convio-security-breach/comment-page-1#comment-66978</link>
		<dc:creator>Allan Benamer</dc:creator>
		<pubDate>Thu, 08 Nov 2007 14:35:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.nonprofittechblog.org/dave-crooke-speaks-about-the-convio-security-breach#comment-66978</guid>
		<description>@activist -- from what I can tell, the employee might have been phished so spyware and malware would not have helped. I&#039;m more worried by the &quot;download all the passwords&quot; capability. That&#039;s a bit nuts. It was like handing hackers the entire cookie jar. It was not a good kludge and all because they were too unwilling to do an open API. This is a great time to demand an SLA from Convio though. You couldn&#039;t get it before but I&#039;m sure there are lots of demands for SLAs right now coming at Convio.</description>
		<content:encoded><![CDATA[<p>@activist &#8212; from what I can tell, the employee might have been phished so spyware and malware would not have helped. I&#8217;m more worried by the &#8220;download all the passwords&#8221; capability. That&#8217;s a bit nuts. It was like handing hackers the entire cookie jar. It was not a good kludge and all because they were too unwilling to do an open API. This is a great time to demand an SLA from Convio though. You couldn&#8217;t get it before but I&#8217;m sure there are lots of demands for SLAs right now coming at Convio.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Activist</title>
		<link>http://www.nonprofittechblog.org/dave-crooke-speaks-about-the-convio-security-breach/comment-page-1#comment-66974</link>
		<dc:creator>Activist</dc:creator>
		<pubDate>Thu, 08 Nov 2007 14:16:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.nonprofittechblog.org/dave-crooke-speaks-about-the-convio-security-breach#comment-66974</guid>
		<description>Convio&#039;s multiple security failures here are elementary-level and simply inexcusable.

First, as mentioned before, there&#039;s the unencrypted passwords issue.  

But secondly, from what I&#039;ve been reading about this, the GetActive and Convio network security was laughable.  An employee was allowed to work from home, on a non-secure PC, without the latest spyware &amp; malware protections?  And this employee was someone with the priveleges to administratively access ALL 150 accounts that were affected or almost affected?  Why does one employee need to be able to access 150 accounts?  And this is at a company that is supposed to handle millions upon millions of records of data safely and securely?

A basic security audit would have pointed these vulnerabilities out -- but I guess Convio didn&#039;t want to bother with that.  

I wonder how the potential of millions and millions of dollars of liabilities from this incident will affect Convio&#039;s planned IPO...</description>
		<content:encoded><![CDATA[<p>Convio&#8217;s multiple security failures here are elementary-level and simply inexcusable.</p>
<p>First, as mentioned before, there&#8217;s the unencrypted passwords issue.  </p>
<p>But secondly, from what I&#8217;ve been reading about this, the GetActive and Convio network security was laughable.  An employee was allowed to work from home, on a non-secure PC, without the latest spyware &amp; malware protections?  And this employee was someone with the priveleges to administratively access ALL 150 accounts that were affected or almost affected?  Why does one employee need to be able to access 150 accounts?  And this is at a company that is supposed to handle millions upon millions of records of data safely and securely?</p>
<p>A basic security audit would have pointed these vulnerabilities out &#8212; but I guess Convio didn&#8217;t want to bother with that.  </p>
<p>I wonder how the potential of millions and millions of dollars of liabilities from this incident will affect Convio&#8217;s planned IPO&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Allan Benamer</title>
		<link>http://www.nonprofittechblog.org/dave-crooke-speaks-about-the-convio-security-breach/comment-page-1#comment-66024</link>
		<dc:creator>Allan Benamer</dc:creator>
		<pubDate>Tue, 06 Nov 2007 14:15:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.nonprofittechblog.org/dave-crooke-speaks-about-the-convio-security-breach#comment-66024</guid>
		<description>No, not really. You&#039;re relying on a security through obscurity model. And knowing a network architecture is different from trying to penetrate it. I&#039;m not asking them to tell me what version of IOS is running on their Cisco router. I just want to know that they have multiple backups and that they have people doing decent admin on those routers.

I&#039;ve always wanted to double-check just the basics: Do they use a firewall? What are the points of failure? Where are the servers situated? Who are their hosting providers? Who are they peered with? Where are the backups happening?

These days, if I knew who a vendor&#039;s hosting provider was, I&#039;d set an RSS subscription that would be searching on keywords just so I could suss out any issues in nearer to real-time.</description>
		<content:encoded><![CDATA[<p>No, not really. You&#8217;re relying on a security through obscurity model. And knowing a network architecture is different from trying to penetrate it. I&#8217;m not asking them to tell me what version of IOS is running on their Cisco router. I just want to know that they have multiple backups and that they have people doing decent admin on those routers.</p>
<p>I&#8217;ve always wanted to double-check just the basics: Do they use a firewall? What are the points of failure? Where are the servers situated? Who are their hosting providers? Who are they peered with? Where are the backups happening?</p>
<p>These days, if I knew who a vendor&#8217;s hosting provider was, I&#8217;d set an RSS subscription that would be searching on keywords just so I could suss out any issues in nearer to real-time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Zeidman</title>
		<link>http://www.nonprofittechblog.org/dave-crooke-speaks-about-the-convio-security-breach/comment-page-1#comment-65975</link>
		<dc:creator>David Zeidman</dc:creator>
		<pubDate>Tue, 06 Nov 2007 11:37:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.nonprofittechblog.org/dave-crooke-speaks-about-the-convio-security-breach#comment-65975</guid>
		<description>&quot;I would always try to ask for a network diagram just so I would understand how secure their systems were. They would never give one to me which always made me feel uncomfortable.&quot;

From a security point isn&#039;t that a good thing that they never gave out their network diagrams? If they had said &quot;sure take a look so that you can work out for yourself where we are vulnerable&quot; then I would have been very concerned.

David</description>
		<content:encoded><![CDATA[<p>&#8220;I would always try to ask for a network diagram just so I would understand how secure their systems were. They would never give one to me which always made me feel uncomfortable.&#8221;</p>
<p>From a security point isn&#8217;t that a good thing that they never gave out their network diagrams? If they had said &#8220;sure take a look so that you can work out for yourself where we are vulnerable&#8221; then I would have been very concerned.</p>
<p>David</p>
]]></content:encoded>
	</item>
</channel>
</rss>
