<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Coleman&#8217;s site wasn&#8217;t &#8216;hacked,&#8217; says IT pro who discovered donor breach</title>
	<atom:link href="http://minnesotaindependent.com/28748/colemans-site-wasnt-hacked-says-it-pro-who-discovered-donor-breach/feed" rel="self" type="application/rss+xml" />
	<link>http://minnesotaindependent.com/28748/colemans-site-wasnt-hacked-says-it-pro-who-discovered-donor-breach</link>
	<description>News. Politics. Media.</description>
	<lastBuildDate>Wed, 30 Nov 2011 23:48:28 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
	<item>
		<title>By: Sq</title>
		<link>http://minnesotaindependent.com/28748/colemans-site-wasnt-hacked-says-it-pro-who-discovered-donor-breach/comment-page-1#comment-27952</link>
		<dc:creator>Sq</dc:creator>
		<pubDate>Tue, 31 Mar 2009 14:24:43 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28748#comment-27952</guid>
		<description>With a breach this serious, in this day and age, I am left with 2 exceedingly simple questions:
1) Isn&#039;t this a violation of the USA-Patriot Act? (EVERYTHING ELSE SEEMS TO BE)
and... Wait for it... 
2) Norm Who??</description>
		<content:encoded><![CDATA[<p>With a breach this serious, in this day and age, I am left with 2 exceedingly simple questions:<br />
1) Isn&#8217;t this a violation of the USA-Patriot Act? (EVERYTHING ELSE SEEMS TO BE)<br />
and&#8230; Wait for it&#8230;<br />
2) Norm Who??</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: EK</title>
		<link>http://minnesotaindependent.com/28748/colemans-site-wasnt-hacked-says-it-pro-who-discovered-donor-breach/comment-page-1#comment-27128</link>
		<dc:creator>EK</dc:creator>
		<pubDate>Wed, 18 Mar 2009 03:41:35 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28748#comment-27128</guid>
		<description>Ahh, poor Norm Coleman, the eternal victim.  Those evil techno-hacks are interfering with his noble effort to keep the winner of an election from receiving an election certificate and (God forbid) voting with the Democratic majority in the United States Senate.

Wasn&#039;t noble Norm the guy who turned his campaign into a war against the working class with his &quot;card check&quot; commercials and all the financial help from those right-wing lobbying groups?  The same Norm whose handlers manufactured the phony &quot;Enraged Franken&quot; commercial that was actually Al speaking at the Wellstone memorial service?

It&#039;s all about karma, Norm.  You&#039;re finally getting yours.</description>
		<content:encoded><![CDATA[<p>Ahh, poor Norm Coleman, the eternal victim.  Those evil techno-hacks are interfering with his noble effort to keep the winner of an election from receiving an election certificate and (God forbid) voting with the Democratic majority in the United States Senate.</p>
<p>Wasn&#8217;t noble Norm the guy who turned his campaign into a war against the working class with his &#8220;card check&#8221; commercials and all the financial help from those right-wing lobbying groups?  The same Norm whose handlers manufactured the phony &#8220;Enraged Franken&#8221; commercial that was actually Al speaking at the Wellstone memorial service?</p>
<p>It&#8217;s all about karma, Norm.  You&#8217;re finally getting yours.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Walking Turtle</title>
		<link>http://minnesotaindependent.com/28748/colemans-site-wasnt-hacked-says-it-pro-who-discovered-donor-breach/comment-page-1#comment-26943</link>
		<dc:creator>Walking Turtle</dc:creator>
		<pubDate>Mon, 16 Mar 2009 05:18:00 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28748#comment-26943</guid>
		<description>Oops.  Double out-facing angle brackets do not render as text here.  Apologies.  Should read &quot;left/right and Libertarian/Authoritarian, not all run together like it came out.  (Just go there anywho...)  :)</description>
		<content:encoded><![CDATA[<p>Oops.  Double out-facing angle brackets do not render as text here.  Apologies.  Should read &#8220;left/right and Libertarian/Authoritarian, not all run together like it came out.  (Just go there anywho&#8230;)  :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Walking Turtle</title>
		<link>http://minnesotaindependent.com/28748/colemans-site-wasnt-hacked-says-it-pro-who-discovered-donor-breach/comment-page-1#comment-26942</link>
		<dc:creator>Walking Turtle</dc:creator>
		<pubDate>Mon, 16 Mar 2009 05:14:10 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28748#comment-26942</guid>
		<description>I have been following the Coleman/Franken action for months now.  This paper&#039;s news item (above) turned up in a link on theregister.co.uk; see http://www.theregister.co.uk/2009/03/12/colman_database_leaked/ for a full IT-angled POV+frame-of-reference.

Occasionally salty comments too.  Modern Brits can be right ascerbic with both grace and style when pressed/exasperated.

The thing that strikes me with this particular chain of events is all the comments I have read to the effect that &quot;Republicans Just Don&#039;t GET InfoTech&quot;, &quot;They just don&#039;t understand computers&quot; etc.  This is a sharp contrast from thirty-odd years back.  Remember Reagan&#039;s upset taking of the White House, anyone?  At *THAT* time, it was bruited about in the (still non-consolidated American news press, pre-Internet) that the Repubs had taken the field because they were &quot;good with computers while the Democrats are still stuck on recipe cards for their contact lists&quot; and similar punditry to that effect.

One thinks of petards and the hoisting of their owner(s) thereon.  Also of hubris - have not the Gods made this Coleman fellow and quite some few others of his high-handed ilk more than a little mad, of late?

BTW, www.politicalcompass.org will help one to QUICKLY understand the *entire* sociopolitical &quot;leadership spectrum&quot; as wel as where one fits on it ones&#039; self.  World leaders are mapped-out by laftright (&quot;X&quot; Axis) and libertarian/anarchistAuthoritarian (&quot;Y&quot; Axis) on a gridded color-keyed background.  

I took the test.  IMHO, we NEED MORE GANDHIS and DALAI LAMA TYPES for the sake of BALANCE; the site&#039;s distribution-map makes that much quite objectively clear at last.  But once there, one notices very quickly that there is (thus far) no such animal as a &quot;Libertarian NeoLiberal&quot;(!)  Heaven help us all, should any indeed start to show up and THANK YOU CREATOR that we have none of those today.  (NO, Norm!  Do NOT rebrand yourself that way!)  :)</description>
		<content:encoded><![CDATA[<p>I have been following the Coleman/Franken action for months now.  This paper&#8217;s news item (above) turned up in a link on theregister.co.uk; see <a href="http://www.theregister.co.uk/2009/03/12/colman_database_leaked/" rel="nofollow">http://www.theregister.co.uk/2009/03/12/colman_database_leaked/</a> for a full IT-angled POV+frame-of-reference.</p>
<p>Occasionally salty comments too.  Modern Brits can be right ascerbic with both grace and style when pressed/exasperated.</p>
<p>The thing that strikes me with this particular chain of events is all the comments I have read to the effect that &#8220;Republicans Just Don&#8217;t GET InfoTech&#8221;, &#8220;They just don&#8217;t understand computers&#8221; etc.  This is a sharp contrast from thirty-odd years back.  Remember Reagan&#8217;s upset taking of the White House, anyone?  At *THAT* time, it was bruited about in the (still non-consolidated American news press, pre-Internet) that the Repubs had taken the field because they were &#8220;good with computers while the Democrats are still stuck on recipe cards for their contact lists&#8221; and similar punditry to that effect.</p>
<p>One thinks of petards and the hoisting of their owner(s) thereon.  Also of hubris &#8211; have not the Gods made this Coleman fellow and quite some few others of his high-handed ilk more than a little mad, of late?</p>
<p>BTW, <a href="http://www.politicalcompass.org" rel="nofollow">http://www.politicalcompass.org</a> will help one to QUICKLY understand the *entire* sociopolitical &#8220;leadership spectrum&#8221; as wel as where one fits on it ones&#8217; self.  World leaders are mapped-out by laftright (&#8220;X&#8221; Axis) and libertarian/anarchistAuthoritarian (&#8220;Y&#8221; Axis) on a gridded color-keyed background.  </p>
<p>I took the test.  IMHO, we NEED MORE GANDHIS and DALAI LAMA TYPES for the sake of BALANCE; the site&#8217;s distribution-map makes that much quite objectively clear at last.  But once there, one notices very quickly that there is (thus far) no such animal as a &#8220;Libertarian NeoLiberal&#8221;(!)  Heaven help us all, should any indeed start to show up and THANK YOU CREATOR that we have none of those today.  (NO, Norm!  Do NOT rebrand yourself that way!)  :)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anon</title>
		<link>http://minnesotaindependent.com/28748/colemans-site-wasnt-hacked-says-it-pro-who-discovered-donor-breach/comment-page-1#comment-26907</link>
		<dc:creator>anon</dc:creator>
		<pubDate>Sun, 15 Mar 2009 05:09:43 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28748#comment-26907</guid>
		<description>So, Coleman and his campaign are not lying, just speaking about things they don&#039;t know enough about to state the truth?  That does not explain their paranoia and false accusations though.</description>
		<content:encoded><![CDATA[<p>So, Coleman and his campaign are not lying, just speaking about things they don&#8217;t know enough about to state the truth?  That does not explain their paranoia and false accusations though.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Norm Coleman is a sleazy weasel &#171; Later On</title>
		<link>http://minnesotaindependent.com/28748/colemans-site-wasnt-hacked-says-it-pro-who-discovered-donor-breach/comment-page-1#comment-26852</link>
		<dc:creator>Norm Coleman is a sleazy weasel &#171; Later On</dc:creator>
		<pubDate>Fri, 13 Mar 2009 22:56:43 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28748#comment-26852</guid>
		<description>[...] IT and web-security professionals interviewed by The Minnesota Independent and other media outlets, the site wasn’t hacked. Minneapolis-based IT consultant Adria Richards, who first discovered the database Jan. 28, said [...]</description>
		<content:encoded><![CDATA[<p>[...] IT and web-security professionals interviewed by The Minnesota Independent and other media outlets, the site wasn’t hacked. Minneapolis-based IT consultant Adria Richards, who first discovered the database Jan. 28, said [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The BRAD BLOG : Coleman Exposes Credit Cards of His Website Donors: 'Hannity' Reacts to Latest MN Scandal...</title>
		<link>http://minnesotaindependent.com/28748/colemans-site-wasnt-hacked-says-it-pro-who-discovered-donor-breach/comment-page-1#comment-26767</link>
		<dc:creator>The BRAD BLOG : Coleman Exposes Credit Cards of His Website Donors: 'Hannity' Reacts to Latest MN Scandal...</dc:creator>
		<pubDate>Thu, 12 Mar 2009 23:19:05 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28748#comment-26767</guid>
		<description>[...] Imagine if Al Franken&#039;s campaign, as opposed to Norm Coleman&#039;s, had now been found to have disclosed the names and credit card numbers of their donors on their own website, where they also inappropriately stored the unencrypted three-digit security codes of contributor credit cards, violated state law by failing to notify anybody about it, and then lied about it. [...]</description>
		<content:encoded><![CDATA[<p>[...] Imagine if Al Franken&#8217;s campaign, as opposed to Norm Coleman&#8217;s, had now been found to have disclosed the names and credit card numbers of their donors on their own website, where they also inappropriately stored the unencrypted three-digit security codes of contributor credit cards, violated state law by failing to notify anybody about it, and then lied about it. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mcfail</title>
		<link>http://minnesotaindependent.com/28748/colemans-site-wasnt-hacked-says-it-pro-who-discovered-donor-breach/comment-page-1#comment-26724</link>
		<dc:creator>mcfail</dc:creator>
		<pubDate>Thu, 12 Mar 2009 16:51:05 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28748#comment-26724</guid>
		<description>Oh wow another republican that doesnt know anything about the internet???? Didnt see that one coming</description>
		<content:encoded><![CDATA[<p>Oh wow another republican that doesnt know anything about the internet???? Didnt see that one coming</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://minnesotaindependent.com/28748/colemans-site-wasnt-hacked-says-it-pro-who-discovered-donor-breach/comment-page-1#comment-26714</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Thu, 12 Mar 2009 15:24:53 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28748#comment-26714</guid>
		<description>What is the funniest about the campaign making a HUGE deal out of this, is that it appears the database included the 3 digit security codes. This is flatly against the PCI-DSS (3.2.2) standards for credit card processing. These 3 digits are supposed to only be transitory and NEVER retained by any application processing credit cards. They have opened themselves to significant fines by VISA, MC, etc, as well as, MN statute restitution for anyone who&#039;s card was breached. Someone should be shining the light on THAT incompetence, as well as, the web security aspect. 

The 12 aspects of the PCI-DSS (with violations highlighted) are:

Build and Maintain a Secure Network

Requirement 1: Install and maintain a firewall configuration to protect cardholder data (VIOLATED)
Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters (password? What password? VIOLATED)

Protect Cardholder Data

Requirement 3: Protect stored cardholder data (VIOLATED)
  3.2.2 Do not store the card-verification code or value (three-digit or four-digit number printed on the front or back of a payment card) used to verify card-not-present transations.
Requirement 4: Encrypt transmission of cardholder data across open, public networks (not having seen the data, I cannot state absolutely, however, it does appear VIOLATED)

Maintain a Vulnerability Management Program

Requirement 5: Use and regularly update anti-virus software
Requirement 6: Develop and maintain secure systems and applications (VIOLATED)

Implement Strong Access Control Measures

Requirement 7: Restrict access to cardholder data by business need-to-know (VIOLATED)
Requirement 8: Assign a unique ID to each person with computer access (VIOLATED)
Requirement 9: Restrict physical access to cardholder data

Regularly Monitor and Test Networks

Requirement 10: Track and monitor all access to network resources and cardholder data (clearly VIOLATED)
Requirement 11: Regularly test security systems and processes (again, clearly VIOLATED)

Maintain an Information Security Policy

Requirement 12: Maintain a policy that addresses information security (again, VIOLATED)</description>
		<content:encoded><![CDATA[<p>What is the funniest about the campaign making a HUGE deal out of this, is that it appears the database included the 3 digit security codes. This is flatly against the PCI-DSS (3.2.2) standards for credit card processing. These 3 digits are supposed to only be transitory and NEVER retained by any application processing credit cards. They have opened themselves to significant fines by VISA, MC, etc, as well as, MN statute restitution for anyone who&#8217;s card was breached. Someone should be shining the light on THAT incompetence, as well as, the web security aspect. </p>
<p>The 12 aspects of the PCI-DSS (with violations highlighted) are:</p>
<p>Build and Maintain a Secure Network</p>
<p>Requirement 1: Install and maintain a firewall configuration to protect cardholder data (VIOLATED)<br />
Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters (password? What password? VIOLATED)</p>
<p>Protect Cardholder Data</p>
<p>Requirement 3: Protect stored cardholder data (VIOLATED)<br />
  3.2.2 Do not store the card-verification code or value (three-digit or four-digit number printed on the front or back of a payment card) used to verify card-not-present transations.<br />
Requirement 4: Encrypt transmission of cardholder data across open, public networks (not having seen the data, I cannot state absolutely, however, it does appear VIOLATED)</p>
<p>Maintain a Vulnerability Management Program</p>
<p>Requirement 5: Use and regularly update anti-virus software<br />
Requirement 6: Develop and maintain secure systems and applications (VIOLATED)</p>
<p>Implement Strong Access Control Measures</p>
<p>Requirement 7: Restrict access to cardholder data by business need-to-know (VIOLATED)<br />
Requirement 8: Assign a unique ID to each person with computer access (VIOLATED)<br />
Requirement 9: Restrict physical access to cardholder data</p>
<p>Regularly Monitor and Test Networks</p>
<p>Requirement 10: Track and monitor all access to network resources and cardholder data (clearly VIOLATED)<br />
Requirement 11: Regularly test security systems and processes (again, clearly VIOLATED)</p>
<p>Maintain an Information Security Policy</p>
<p>Requirement 12: Maintain a policy that addresses information security (again, VIOLATED)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: jim mann</title>
		<link>http://minnesotaindependent.com/28748/colemans-site-wasnt-hacked-says-it-pro-who-discovered-donor-breach/comment-page-1#comment-26709</link>
		<dc:creator>jim mann</dc:creator>
		<pubDate>Thu, 12 Mar 2009 14:40:38 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28748#comment-26709</guid>
		<description>Mr Colman looks sick to me,if he cant control credit cards he shoud shut his mouth even MN people say he is sorry loser and he still is a fraud on $75000 he got from tx  wrong afgainst the law he will be charged with that as soon as thsi BS is over with,He is usless and a abig cry baby if talbes were turned he would still be a TOP jerk dont nedd that in senate  have enough JERKS hahah</description>
		<content:encoded><![CDATA[<p>Mr Colman looks sick to me,if he cant control credit cards he shoud shut his mouth even MN people say he is sorry loser and he still is a fraud on $75000 he got from tx  wrong afgainst the law he will be charged with that as soon as thsi BS is over with,He is usless and a abig cry baby if talbes were turned he would still be a TOP jerk dont nedd that in senate  have enough JERKS hahah</p>
]]></content:encoded>
	</item>
</channel>
</rss>

