Re: CRIME postings/e-mail from Heidi Henry -mcps@private

From: Toby (toby@private)
Date: Thu Jun 20 2002 - 17:36:11 PDT

  • Next message: Lyle Leavitt: "CRIME Password Security Risk with Local ISP's"

    If I can make an observation- if this were a test of some sort none of the
    responses I've seen would be desirable. Stop complaining about the spam and
    delete it. Stop debating whether Heidi's emails are from her and if you
    REALLY REALLY care that much, call her up and ask her. I'm sure at least
    one person has her contact info. But stop obsessing about it already! 
    Winn Schwartau wrote a book called "Time-based Security" among other
    interesting tenents in it, he suggests that if an attack can get you to
    spend time dealing with false alarms, they win. That is what you are
    seeing.
    Note that we are getting spam, file it for future referenc THEN MOVE ON.
    And stop giving me even more random email to delete.
    
    <in a grumpy mood from having to delete more emails ABOUT spam than spam>
    Toby
    
    Lyle Leavitt writes:
    
    > Do we really know if this is 'real' or is forensicsbox@private a
    > stolen account and the perp is trying to scam this group regarding
    > Heidi's account. The last posts from Heidi appear fairly benign while
    > this post from Wendy is rather bazaar. 
    > 
    > Is this a PRS training exercise to evaluate the CRIME group's ability
    > to respond? What's the proper protocol here. It doesn't seem right to
    > immediately act on Wendy's request to block Heidi's messages. 
    > 
    > Gee, does anyone know what security practices MSN uses regarding
    > passwords on their ISP accounts.  Heidi, when was the last time you
    > changed your password and has anyone from MSN ever asked you for it?
    > Sorry, I just had to ask :)
    > 
    > -Lyle
    > 
    > Wendy Scott wrote:
    > > 
    > >EFFECTIVE IMMEDIATELY:  MCPS@private IS A STOLEN ACCOUNT.  IGNORE/BLOCK ANY MESSAGES SENT FROM THIS E-MAIL >ADDRESS.  Messages are being sent to the list and to other people by whoever has stolen this account.  Who >ever you are, you will be caught.  Heidi Henry is not and has not been posting to the list.
    



    This archive was generated by hypermail 2b30 : Thu Jun 20 2002 - 18:58:23 PDT