<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Coleman camp&#8217;s claim about January data breach is &#8216;bullshit,&#8217; tech expert says</title>
	<atom:link href="http://minnesotaindependent.com/28793/bruce-schneier-on-coleman-database-breach/feed" rel="self" type="application/rss+xml" />
	<link>http://minnesotaindependent.com/28793/bruce-schneier-on-coleman-database-breach</link>
	<description>News. Politics. Media.</description>
	<lastBuildDate>Wed, 30 Nov 2011 23:48:28 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
	<item>
		<title>By: MJB784533</title>
		<link>http://minnesotaindependent.com/28793/bruce-schneier-on-coleman-database-breach/comment-page-1#comment-27643</link>
		<dc:creator>MJB784533</dc:creator>
		<pubDate>Wed, 25 Mar 2009 17:14:17 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28793#comment-27643</guid>
		<description>The question of whether the site was hacked or if any card data was published on the web is no longer the main point. This information discloses that the Coleman campaign retained the verification code numbers that are usually on the back of the card. The mere fact that they retained these code numbers is itself a violation of Minnesota law AND the agreement contracts with the credit card organizations. Forget about the possible hacking, forget about who might have done or not done it. The fact remains that the retention of these code numbers alone puts the Coleman campaign in violation of the law.

“No person or entity conducting business in Minnesota… shall retain the card security code data, the PIN verification code data, or the full contents of any track of magnetic stripe data,” says state statute 325E.64. “A person or entity is in violation of this section if its service provider retains such data subsequent to the authorization of the transaction.”</description>
		<content:encoded><![CDATA[<p>The question of whether the site was hacked or if any card data was published on the web is no longer the main point. This information discloses that the Coleman campaign retained the verification code numbers that are usually on the back of the card. The mere fact that they retained these code numbers is itself a violation of Minnesota law AND the agreement contracts with the credit card organizations. Forget about the possible hacking, forget about who might have done or not done it. The fact remains that the retention of these code numbers alone puts the Coleman campaign in violation of the law.</p>
<p>“No person or entity conducting business in Minnesota… shall retain the card security code data, the PIN verification code data, or the full contents of any track of magnetic stripe data,” says state statute 325E.64. “A person or entity is in violation of this section if its service provider retains such data subsequent to the authorization of the transaction.”</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tim Barsness</title>
		<link>http://minnesotaindependent.com/28793/bruce-schneier-on-coleman-database-breach/comment-page-1#comment-26886</link>
		<dc:creator>Tim Barsness</dc:creator>
		<pubDate>Sat, 14 Mar 2009 18:39:13 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28793#comment-26886</guid>
		<description>Looks to me like Coleman canned his staff and just left the lights on in the website with no one
home.   Reminds me of the MN Dept. of Vehicle Services doing the same thing, to save money
in a Pawlenty state worker cut all the admins at DVS were canned.  When the leg. auditor came by no recommended security work was done to secure the credit card payment for car plate tabs.   There were no people in charge. The site was shut down before any known breach.  Made the front page of the old fashioned &quot;newspapers&quot; for a week.

Pawlenty recovered nicely by a no bid cost plus monopoly contract for all state credit card payments through US Bank. His pals all made out great and the campaign money flowed like a Red River flood.

Does not look like that will happen for Norm, just a kick in the pants and maybe jail.</description>
		<content:encoded><![CDATA[<p>Looks to me like Coleman canned his staff and just left the lights on in the website with no one<br />
home.   Reminds me of the MN Dept. of Vehicle Services doing the same thing, to save money<br />
in a Pawlenty state worker cut all the admins at DVS were canned.  When the leg. auditor came by no recommended security work was done to secure the credit card payment for car plate tabs.   There were no people in charge. The site was shut down before any known breach.  Made the front page of the old fashioned &#8220;newspapers&#8221; for a week.</p>
<p>Pawlenty recovered nicely by a no bid cost plus monopoly contract for all state credit card payments through US Bank. His pals all made out great and the campaign money flowed like a Red River flood.</p>
<p>Does not look like that will happen for Norm, just a kick in the pants and maybe jail.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PJN2112</title>
		<link>http://minnesotaindependent.com/28793/bruce-schneier-on-coleman-database-breach/comment-page-1#comment-26855</link>
		<dc:creator>PJN2112</dc:creator>
		<pubDate>Fri, 13 Mar 2009 23:41:05 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28793#comment-26855</guid>
		<description>Karen:

WHOIS shows that the registrant and admin for colemanforsenate.com has been Brandon Grey Internet Services (dba namejuice.com) since at least May 2008 (the last time the whois was updated).

WHOIS for namejuice.com lists the registrar, admin, and techincal contact as Brandon Grey who is located in Markham, Ontario, Canada.

Granted, just because the domain is registered to a Canadian doesn&#039;t mean that the same individual is responsible for the maintenance of the website - Prior reporting on crashgate mentioned that Coleman&#039;s name servers are located at Minneapolis-based VISI.com, so one could probably assume that Coleman&#039;s website is hosted in VISI&#039;s data center probably on one of their servers which also hosts sites for other VISI clients. VISI&#039;s NOC would be responsible for the upkeep of the server but not for the website - Judging from the problems Norm&#039;s had with his website I think it&#039;s safe to say that he more than likely didn&#039;t hire outside professionals to manage his site (assuming any professional worth paying wouldn&#039;t be quite as careless and stupid about doing their jobs as to leave an archived site backup in the webroot) so it&#039;s likely that someone working directly for the campaign handled the website admin chores.  If it&#039;s a salaried employee of the campaign, you wouldn&#039;t find that out from a FEC report.</description>
		<content:encoded><![CDATA[<p>Karen:</p>
<p>WHOIS shows that the registrant and admin for colemanforsenate.com has been Brandon Grey Internet Services (dba namejuice.com) since at least May 2008 (the last time the whois was updated).</p>
<p>WHOIS for namejuice.com lists the registrar, admin, and techincal contact as Brandon Grey who is located in Markham, Ontario, Canada.</p>
<p>Granted, just because the domain is registered to a Canadian doesn&#8217;t mean that the same individual is responsible for the maintenance of the website &#8211; Prior reporting on crashgate mentioned that Coleman&#8217;s name servers are located at Minneapolis-based VISI.com, so one could probably assume that Coleman&#8217;s website is hosted in VISI&#8217;s data center probably on one of their servers which also hosts sites for other VISI clients. VISI&#8217;s NOC would be responsible for the upkeep of the server but not for the website &#8211; Judging from the problems Norm&#8217;s had with his website I think it&#8217;s safe to say that he more than likely didn&#8217;t hire outside professionals to manage his site (assuming any professional worth paying wouldn&#8217;t be quite as careless and stupid about doing their jobs as to leave an archived site backup in the webroot) so it&#8217;s likely that someone working directly for the campaign handled the website admin chores.  If it&#8217;s a salaried employee of the campaign, you wouldn&#8217;t find that out from a FEC report.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PJN2112</title>
		<link>http://minnesotaindependent.com/28793/bruce-schneier-on-coleman-database-breach/comment-page-1#comment-26853</link>
		<dc:creator>PJN2112</dc:creator>
		<pubDate>Fri, 13 Mar 2009 23:17:12 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28793#comment-26853</guid>
		<description>Aaron - Fair enough explanation. Since the link you provided in that update is 404 I assumed that nothing came of it. That won&#039;t stop the partisans on the other side from giving Adria grief.  She did mention that the database contained credit card info - So she either found this out via an unmentioned source who passed this revelation on to her or she did indeed open the file. Whatever the case, she kind of plopped herself into the spotlight by reporting what she found - Granted, she did it with a benevolent purpose (to bring the breach to light), she&#039;ll still be an target. Republicans love to torment whistleblowers, especially ones who do their whistling on Progressive sites.</description>
		<content:encoded><![CDATA[<p>Aaron &#8211; Fair enough explanation. Since the link you provided in that update is 404 I assumed that nothing came of it. That won&#8217;t stop the partisans on the other side from giving Adria grief.  She did mention that the database contained credit card info &#8211; So she either found this out via an unmentioned source who passed this revelation on to her or she did indeed open the file. Whatever the case, she kind of plopped herself into the spotlight by reporting what she found &#8211; Granted, she did it with a benevolent purpose (to bring the breach to light), she&#8217;ll still be an target. Republicans love to torment whistleblowers, especially ones who do their whistling on Progressive sites.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Karen Lee</title>
		<link>http://minnesotaindependent.com/28793/bruce-schneier-on-coleman-database-breach/comment-page-1#comment-26850</link>
		<dc:creator>Karen Lee</dc:creator>
		<pubDate>Fri, 13 Mar 2009 22:49:50 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28793#comment-26850</guid>
		<description>Have you checked Coleman&#039;s campaign FINANCE REPORTS for its web creator culprit?

By law, every expenditure made by a political campaign MUST BE ITEMIZED in their campaign finance reports.
HAS ANYBODY RESEARCHED what firm(s) were used to create the Coleman website as well as monthly monitoring of the Coleman server, etc. &gt;????</description>
		<content:encoded><![CDATA[<p>Have you checked Coleman&#8217;s campaign FINANCE REPORTS for its web creator culprit?</p>
<p>By law, every expenditure made by a political campaign MUST BE ITEMIZED in their campaign finance reports.<br />
HAS ANYBODY RESEARCHED what firm(s) were used to create the Coleman website as well as monthly monitoring of the Coleman server, etc. &gt;????</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron</title>
		<link>http://minnesotaindependent.com/28793/bruce-schneier-on-coleman-database-breach/comment-page-1#comment-26849</link>
		<dc:creator>Aaron</dc:creator>
		<pubDate>Fri, 13 Mar 2009 22:48:04 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28793#comment-26849</guid>
		<description>PJN2112-

I did post that, but I was incorrect. Adria Richards did not broadcast the contents -- she just broadcasted what she did and the screenshots as described.</description>
		<content:encoded><![CDATA[<p>PJN2112-</p>
<p>I did post that, but I was incorrect. Adria Richards did not broadcast the contents &#8212; she just broadcasted what she did and the screenshots as described.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PJN2112</title>
		<link>http://minnesotaindependent.com/28793/bruce-schneier-on-coleman-database-breach/comment-page-1#comment-26844</link>
		<dc:creator>PJN2112</dc:creator>
		<pubDate>Fri, 13 Mar 2009 21:10:00 +0000</pubDate>
		<guid isPermaLink="false">http://minnesotaindependent.com/?p=28793#comment-26844</guid>
		<description>If, as Schneier says, “People have been convicted for this. … It’s possible you would’ve been prosecuted.” with regards to simply clicking the file&#039;s link and viewing it&#039;s contents then Adria Richards might be at risk. Aaron Landry at &lt;a href=&quot;http://mnpublius.com/2009/01/coleman-allows-donor-and-supporter-database-to-leak/&quot; rel=&quot;nofollow&quot;&gt;MNPublius&lt;/a&gt; wrote a post on January 29th that included as an update this:

&lt;a href=&quot;http://tinyurl.com/askadriaustream&quot; rel=&quot;nofollow&quot;&gt;Adria Richards will broadcast the contents of Coleman&#8217;s database at 3:30 PM CT&#160;today.&lt;/a&gt;</description>
		<content:encoded><![CDATA[<p>If, as Schneier says, “People have been convicted for this. … It’s possible you would’ve been prosecuted.” with regards to simply clicking the file&#8217;s link and viewing it&#8217;s contents then Adria Richards might be at risk. Aaron Landry at <a href="http://mnpublius.com/2009/01/coleman-allows-donor-and-supporter-database-to-leak/" rel="nofollow">MNPublius</a> wrote a post on January 29th that included as an update this:</p>
<p><a href="http://tinyurl.com/askadriaustream" rel="nofollow">Adria Richards will broadcast the contents of Coleman&#8217;s database at 3:30 PM CT&nbsp;today.</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>

