<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: UK Telegraph web site compromised</title>
	<atom:link href="http://countermeasures.trendmicro.eu/uk-telegraph-web-site-compromised/feed/" rel="self" type="application/rss+xml" />
	<link>http://countermeasures.trendmicro.eu/uk-telegraph-web-site-compromised/</link>
	<description>Rik Ferguson blogs about current security issues.</description>
	<lastBuildDate>Thu, 11 Mar 2010 04:04:47 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: HackersBlog &#187; Blog Archive &#187; Telegraph.co.uk hacked - when will they learn?</title>
		<link>http://countermeasures.trendmicro.eu/uk-telegraph-web-site-compromised/comment-page-1/#comment-818</link>
		<dc:creator>HackersBlog &#187; Blog Archive &#187; Telegraph.co.uk hacked - when will they learn?</dc:creator>
		<pubDate>Thu, 28 May 2009 15:43:52 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=30#comment-818</guid>
		<description>[...] the one used to log in to telegraph.co.uk . We also recommend to follow the advices listed here:  here. Please read this too if you want to make an article about [...]</description>
		<content:encoded><![CDATA[<p>[...] the one used to log in to telegraph.co.uk . We also recommend to follow the advices listed here:  here. Please read this too if you want to make an article about [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: +++ Telegraph Users Passwords and Emails Hacked +++ - Guy Fawkes' blog</title>
		<link>http://countermeasures.trendmicro.eu/uk-telegraph-web-site-compromised/comment-page-1/#comment-127</link>
		<dc:creator>+++ Telegraph Users Passwords and Emails Hacked +++ - Guy Fawkes' blog</dc:creator>
		<pubDate>Fri, 03 Apr 2009 14:43:44 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=30#comment-127</guid>
		<description>[...] boasting here. Security warning here. The Telegraph, as far as Guido can tell, has not alerted users that their passwords have been [...]</description>
		<content:encoded><![CDATA[<p>[...] boasting here. Security warning here. The Telegraph, as far as Guido can tell, has not alerted users that their passwords have been [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rik Ferguson</title>
		<link>http://countermeasures.trendmicro.eu/uk-telegraph-web-site-compromised/comment-page-1/#comment-32</link>
		<dc:creator>Rik Ferguson</dc:creator>
		<pubDate>Tue, 10 Mar 2009 08:44:01 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=30#comment-32</guid>
		<description>Heh, nice observaration Boris as regards webmail accounts, my recommendation would certainly be to use a local client to store historical mails, especially those containing sensitive information., rather than leaving them in your online account.

I like the idea of encrypting your paswords locally, but I don&#039;t completely understand how that would protect your credentials from being guessed, brute-forced, socially engineered or simply given away....

The other downside to using a locally encrypted password database is of course the fact that you are no longer as mobile (with logins) as you otherwise would be.

Having said that, the email account is always the holy grail of anyone trying to gain illicit access to any service online and should be protected with a very secure, difficult to guess password.</description>
		<content:encoded><![CDATA[<p>Heh, nice observaration Boris as regards webmail accounts, my recommendation would certainly be to use a local client to store historical mails, especially those containing sensitive information., rather than leaving them in your online account.</p>
<p>I like the idea of encrypting your paswords locally, but I don&#8217;t completely understand how that would protect your credentials from being guessed, brute-forced, socially engineered or simply given away&#8230;.</p>
<p>The other downside to using a locally encrypted password database is of course the fact that you are no longer as mobile (with logins) as you otherwise would be.</p>
<p>Having said that, the email account is always the holy grail of anyone trying to gain illicit access to any service online and should be protected with a very secure, difficult to guess password.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Boris Yeltsin</title>
		<link>http://countermeasures.trendmicro.eu/uk-telegraph-web-site-compromised/comment-page-1/#comment-31</link>
		<dc:creator>Boris Yeltsin</dc:creator>
		<pubDate>Tue, 10 Mar 2009 07:14:21 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=30#comment-31</guid>
		<description>You write:
Use the first password as a general one for the majority of sites that require passwords to login. The second password, use for your email account and only your email account, that way, should your email be compromised, you do not have to worry about your other services.

DOH. If your email account is compromised, then why shouldn&#039;t &quot;they&quot; go through your email, find your &quot;sign up&quot; emails and go back to all of those sites asking for passwords to be reset, or to be emailed the password or whatever?

No, get a simple encryption app to protect a database of different passwords. It should be secured using a master password that is not used anywhere else. Use a virus/trojan scanner if you&#039;re using Windows so you don&#039;t get keylogged. Use Steel for Mac, or KeyPass for Windows.</description>
		<content:encoded><![CDATA[<p>You write:<br />
Use the first password as a general one for the majority of sites that require passwords to login. The second password, use for your email account and only your email account, that way, should your email be compromised, you do not have to worry about your other services.</p>
<p>DOH. If your email account is compromised, then why shouldn&#8217;t &#8220;they&#8221; go through your email, find your &#8220;sign up&#8221; emails and go back to all of those sites asking for passwords to be reset, or to be emailed the password or whatever?</p>
<p>No, get a simple encryption app to protect a database of different passwords. It should be secured using a master password that is not used anywhere else. Use a virus/trojan scanner if you&#8217;re using Windows so you don&#8217;t get keylogged. Use Steel for Mac, or KeyPass for Windows.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Telegraph site attacked, claim hackers</title>
		<link>http://countermeasures.trendmicro.eu/uk-telegraph-web-site-compromised/comment-page-1/#comment-30</link>
		<dc:creator>Telegraph site attacked, claim hackers</dc:creator>
		<pubDate>Tue, 10 Mar 2009 00:59:47 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=30#comment-30</guid>
		<description>[...] email addresses and more worryingly, passwords in clear text,&#8221; according to Rik Ferguson on Trend Micro&#8217;s security blog. If that means you, you should change your password on that and perhaps other sites. His post adds: [...]</description>
		<content:encoded><![CDATA[<p>[...] email addresses and more worryingly, passwords in clear text,&#8221; according to Rik Ferguson on Trend Micro&#8217;s security blog. If that means you, you should change your password on that and perhaps other sites. His post adds: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Telegraph site attacked, claim hackers &#124; PTC07NEWS</title>
		<link>http://countermeasures.trendmicro.eu/uk-telegraph-web-site-compromised/comment-page-1/#comment-27</link>
		<dc:creator>Telegraph site attacked, claim hackers &#124; PTC07NEWS</dc:creator>
		<pubDate>Mon, 09 Mar 2009 14:37:29 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=30#comment-27</guid>
		<description>[...] email addresses and more worryingly, passwords in clear text,&#8221; according to Rik Ferguson on Trend Micro&#8217;s security blog. If that means you, you should change your password on that and perhaps other sites. His post adds: [...]</description>
		<content:encoded><![CDATA[<p>[...] email addresses and more worryingly, passwords in clear text,&#8221; according to Rik Ferguson on Trend Micro&#8217;s security blog. If that means you, you should change your password on that and perhaps other sites. His post adds: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rik Ferguson</title>
		<link>http://countermeasures.trendmicro.eu/uk-telegraph-web-site-compromised/comment-page-1/#comment-25</link>
		<dc:creator>Rik Ferguson</dc:creator>
		<pubDate>Mon, 09 Mar 2009 11:26:36 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=30#comment-25</guid>
		<description>Thanks Kate, I have updated the original blog post to include the Telegraph&#039;s response, Well done on reacting so rapidly to this!</description>
		<content:encoded><![CDATA[<p>Thanks Kate, I have updated the original blog post to include the Telegraph&#8217;s response, Well done on reacting so rapidly to this!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kate Day</title>
		<link>http://countermeasures.trendmicro.eu/uk-telegraph-web-site-compromised/comment-page-1/#comment-24</link>
		<dc:creator>Kate Day</dc:creator>
		<pubDate>Mon, 09 Mar 2009 10:46:58 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=30#comment-24</guid>
		<description>This did not affect the main Telegraph.co.uk site or Telegraph blogs and My Telegraph. For the full story please &lt;a href=&quot;http://blogs.telegraph.co.uk/shane_richmond/blog/2009/03/09/hackersblog_and_telegraphcouk&quot; rel=&quot;nofollow&quot;&gt; see here &lt;/a&gt;. Thanks.</description>
		<content:encoded><![CDATA[<p>This did not affect the main Telegraph.co.uk site or Telegraph blogs and My Telegraph. For the full story please <a href="http://blogs.telegraph.co.uk/shane_richmond/blog/2009/03/09/hackersblog_and_telegraphcouk" rel="nofollow"> see here </a>. Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hackersblog and Telegraph.co.uk &#124; News in brief</title>
		<link>http://countermeasures.trendmicro.eu/uk-telegraph-web-site-compromised/comment-page-1/#comment-23</link>
		<dc:creator>Hackersblog and Telegraph.co.uk &#124; News in brief</dc:creator>
		<pubDate>Mon, 09 Mar 2009 10:13:18 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=30#comment-23</guid>
		<description>[...] you may have read elsewhere, Telegraph.co.uk was targeted by hackers at the end of last week. The main part of our website are not affected, nor are the accounts of My [...]</description>
		<content:encoded><![CDATA[<p>[...] you may have read elsewhere, Telegraph.co.uk was targeted by hackers at the end of last week. The main part of our website are not affected, nor are the accounts of My [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Telegraph.co.uk hacked &#124; Developer Oracles</title>
		<link>http://countermeasures.trendmicro.eu/uk-telegraph-web-site-compromised/comment-page-1/#comment-22</link>
		<dc:creator>Telegraph.co.uk hacked &#124; Developer Oracles</dc:creator>
		<pubDate>Mon, 09 Mar 2009 10:09:13 +0000</pubDate>
		<guid isPermaLink="false">http://countermeasures.trendmicro.eu/?p=30#comment-22</guid>
		<description>[...] after the hacker reported his success, TrendMicro re-confirmed the event and informed that they already reported the attack to the Telegraph. They [...]</description>
		<content:encoded><![CDATA[<p>[...] after the hacker reported his success, TrendMicro re-confirmed the event and informed that they already reported the attack to the Telegraph. They [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
