<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: And then, a stupidity occurs.</title>
	<atom:link href="http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/feed/" rel="self" type="application/rss+xml" />
	<link>http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/</link>
	<description></description>
	<pubDate>Fri, 05 Dec 2008 11:05:47 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.5</generator>
		<item>
		<title>By: Privacy Commissioner Consultation &#171; Balneus</title>
		<link>http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-262006</link>
		<dc:creator>Privacy Commissioner Consultation &#171; Balneus</dc:creator>
		<pubDate>Wed, 16 Apr 2008 04:28:10 +0000</pubDate>
		<guid isPermaLink="false">http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-262006</guid>
		<description>[...] &#8212; Dave Bath   For those following Jacques Chester&#8217;s recent Club Troppo posts (here and here) on our Federal Government&#8217;s cluelessness on IT security and privacy issues, I&#8217;d point [...]</description>
		<content:encoded><![CDATA[<p>[...] &#8212; Dave Bath   For those following Jacques Chester&#8217;s recent Club Troppo posts (here and here) on our Federal Government&#8217;s cluelessness on IT security and privacy issues, I&#8217;d point [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alan</title>
		<link>http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261528</link>
		<dc:creator>Alan</dc:creator>
		<pubDate>Mon, 14 Apr 2008 23:22:33 +0000</pubDate>
		<guid isPermaLink="false">http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261528</guid>
		<description>Blog posts like this one are a clear and present danger to the continued existence of the nation. You are are giving aid and comfort to our enemies by revealing the level of ministerial and official incompetence rampant among the organs of national security. I hope the government will speedily block this gaping hole by legislating that no-one is allowed to read Club Troppo without the previous written consent of the Deputy Prime Minister.</description>
		<content:encoded><![CDATA[<p>Blog posts like this one are a clear and present danger to the continued existence of the nation. You are are giving aid and comfort to our enemies by revealing the level of ministerial and official incompetence rampant among the organs of national security. I hope the government will speedily block this gaping hole by legislating that no-one is allowed to read Club Troppo without the previous written consent of the Deputy Prime Minister.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yobbo</title>
		<link>http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261513</link>
		<dc:creator>Yobbo</dc:creator>
		<pubDate>Mon, 14 Apr 2008 21:18:12 +0000</pubDate>
		<guid isPermaLink="false">http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261513</guid>
		<description>Goddamn zombies always fucking things up. One minute they are reading your emails, the next they are giving birth to zombie babies and eating through your supermarket fortress.</description>
		<content:encoded><![CDATA[<p>Goddamn zombies always fucking things up. One minute they are reading your emails, the next they are giving birth to zombie babies and eating through your supermarket fortress.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gilmae</title>
		<link>http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261512</link>
		<dc:creator>gilmae</dc:creator>
		<pubDate>Mon, 14 Apr 2008 20:57:34 +0000</pubDate>
		<guid isPermaLink="false">http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261512</guid>
		<description>Even if it was being aimed at "terrorism" as Gillard said I think the point would have been trying to safeguard against versions of Kevin Melnick. That is, people who use social hacking to get information from employees of a company.</description>
		<content:encoded><![CDATA[<p>Even if it was being aimed at &#8220;terrorism&#8221; as Gillard said I think the point would have been trying to safeguard against versions of Kevin Melnick. That is, people who use social hacking to get information from employees of a company.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: amphibious</title>
		<link>http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261437</link>
		<dc:creator>amphibious</dc:creator>
		<pubDate>Mon, 14 Apr 2008 14:02:06 +0000</pubDate>
		<guid isPermaLink="false">http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261437</guid>
		<description>Whether they are fools or knaves is not as important as the damage done in ignorance. Pretty soon it'll be 'no-one left to lie to". 
Honestly, when did you last believe a word any politician or bureaucrat said? Any group or organisation beyond a certain size or complexity begins to devote disproportionately more of its resources to its maintenance rather than the ostensible original purpose.</description>
		<content:encoded><![CDATA[<p>Whether they are fools or knaves is not as important as the damage done in ignorance. Pretty soon it&#8217;ll be &#8216;no-one left to lie to&#8221;.<br />
Honestly, when did you last believe a word any politician or bureaucrat said? Any group or organisation beyond a certain size or complexity begins to devote disproportionately more of its resources to its maintenance rather than the ostensible original purpose.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SJ</title>
		<link>http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261435</link>
		<dc:creator>SJ</dc:creator>
		<pubDate>Mon, 14 Apr 2008 14:00:14 +0000</pubDate>
		<guid isPermaLink="false">http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261435</guid>
		<description>Jacques: Many thanks for calling the AG's office. That was well done.</description>
		<content:encoded><![CDATA[<p>Jacques: Many thanks for calling the AG&#8217;s office. That was well done.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dr faustus</title>
		<link>http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261367</link>
		<dc:creator>dr faustus</dc:creator>
		<pubDate>Mon, 14 Apr 2008 05:41:26 +0000</pubDate>
		<guid isPermaLink="false">http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261367</guid>
		<description>&lt;blockquote&gt;The problem is zombies; the problem has been zombies since at least 2002. Zombie problems are not solved by snooping on email, they are solved by getting a more secure operating system and disconnecting exploited machines from the Internet.&lt;/blockquote&gt;

It's a trick. Get an axe.

('Botnet' may be no more comprehensible to the average punter, but it's less likely to be confused with a &lt;em&gt;Day of the Dead&lt;/em&gt; style scenario.)

Seriously though, the easy solution to this (media beat-up or not) is to use freely available encryption programs like PGP. They're available for almost every program, and unlike when PGP first came out are actually reasonably useable. Sure, it's not something that everyone can install on their work PC, but those who can, should.

The more encrypted traffic there is coming out of your machine, the less suspicious any given email will be. Even if you aren't doing anything wrong. With all the VPN traffic going across the net these days, pretty soon a packet of gibberish going across a backbone wont cause a single eyebrow to be raised.

The problem I have is that none of my friends or family care sufficiently enough to issue to download and install an encryption program. In the meantime, I do most of my personal emailing via an SSL connection to an off-site email server, meaning that my employer has little opportunity to intercept it. Running something like Gmail over SSL is a pretty good start, from one end, anyway.</description>
		<content:encoded><![CDATA[<blockquote><p>The problem is zombies; the problem has been zombies since at least 2002. Zombie problems are not solved by snooping on email, they are solved by getting a more secure operating system and disconnecting exploited machines from the Internet.</p></blockquote>
<p>It&#8217;s a trick. Get an axe.</p>
<p>(&#8217;Botnet&#8217; may be no more comprehensible to the average punter, but it&#8217;s less likely to be confused with a <em>Day of the Dead</em> style scenario.)</p>
<p>Seriously though, the easy solution to this (media beat-up or not) is to use freely available encryption programs like PGP. They&#8217;re available for almost every program, and unlike when PGP first came out are actually reasonably useable. Sure, it&#8217;s not something that everyone can install on their work PC, but those who can, should.</p>
<p>The more encrypted traffic there is coming out of your machine, the less suspicious any given email will be. Even if you aren&#8217;t doing anything wrong. With all the VPN traffic going across the net these days, pretty soon a packet of gibberish going across a backbone wont cause a single eyebrow to be raised.</p>
<p>The problem I have is that none of my friends or family care sufficiently enough to issue to download and install an encryption program. In the meantime, I do most of my personal emailing via an SSL connection to an off-site email server, meaning that my employer has little opportunity to intercept it. Running something like Gmail over SSL is a pretty good start, from one end, anyway.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kevo of Sydney</title>
		<link>http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261357</link>
		<dc:creator>Kevo of Sydney</dc:creator>
		<pubDate>Mon, 14 Apr 2008 05:05:29 +0000</pubDate>
		<guid isPermaLink="false">http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261357</guid>
		<description>There is some comment that employers should have the right to supervise use of company computers and connections.

But timewasting or nickel-and-diming computer resources is statedly NOT what this mooted law is about.

Ask yourself - who will define what enterprises are classified as critical industries for national security or not, such that this law would apply ?

And what other controls might eventually be put in place once the government designation of "critical industry" is applied ?

And who will read the employee emails in these enterprises looking for terrorist intent ?  Are we going to see security checks on the screeners ?  Will the screeners be trained ?  Will they be required to sit in secure areas for screening purposes ?

Who will they report suspicious activity to - their employer or a government agency ??

Can you imagine the havoc based on the spurious notion that terrorists are going to leave an audit trail on their company email ??  

Note to Terrorist Central - I doubt too many email scanning persons will be fluent in anything other than Aussie English - write in another tongue.  That'll get 'em going !</description>
		<content:encoded><![CDATA[<p>There is some comment that employers should have the right to supervise use of company computers and connections.</p>
<p>But timewasting or nickel-and-diming computer resources is statedly NOT what this mooted law is about.</p>
<p>Ask yourself - who will define what enterprises are classified as critical industries for national security or not, such that this law would apply ?</p>
<p>And what other controls might eventually be put in place once the government designation of &#8220;critical industry&#8221; is applied ?</p>
<p>And who will read the employee emails in these enterprises looking for terrorist intent ?  Are we going to see security checks on the screeners ?  Will the screeners be trained ?  Will they be required to sit in secure areas for screening purposes ?</p>
<p>Who will they report suspicious activity to - their employer or a government agency ??</p>
<p>Can you imagine the havoc based on the spurious notion that terrorists are going to leave an audit trail on their company email ??  </p>
<p>Note to Terrorist Central - I doubt too many email scanning persons will be fluent in anything other than Aussie English - write in another tongue.  That&#8217;ll get &#8216;em going !</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gummo Trotsky</title>
		<link>http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261356</link>
		<dc:creator>Gummo Trotsky</dc:creator>
		<pubDate>Mon, 14 Apr 2008 05:04:36 +0000</pubDate>
		<guid isPermaLink="false">http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261356</guid>
		<description>&lt;blockquote&gt;I ... reserve the right to chuck an angry wobbly about political ignorance in future.&lt;/blockquote&gt;

That one should go into an Australian Bill of Rights. And it should trump such "offences" as sedition and contempt of the Parliament.</description>
		<content:encoded><![CDATA[<blockquote><p>I &#8230; reserve the right to chuck an angry wobbly about political ignorance in future.</p></blockquote>
<p>That one should go into an Australian Bill of Rights. And it should trump such &#8220;offences&#8221; as sedition and contempt of the Parliament.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ken Parish</title>
		<link>http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261355</link>
		<dc:creator>Ken Parish</dc:creator>
		<pubDate>Mon, 14 Apr 2008 04:58:44 +0000</pubDate>
		<guid isPermaLink="false">http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261355</guid>
		<description>They're not as bad as the Howard government ... They're not as bad as the Howard government ... They're not as bad as the Howard government ... They're not as bad as the Howard government ... They're not as bad as the Howard government ... They're not as bad as the Howard government ... They're not as bad as the Howard government ... They're not as bad as the Howard government ... They're not as bad as the Howard government ... They're not as bad as the Howard government ... They're not as bad as the Howard government ...

If I keep repeating it I might begin to believe it.</description>
		<content:encoded><![CDATA[<p>They&#8217;re not as bad as the Howard government &#8230; They&#8217;re not as bad as the Howard government &#8230; They&#8217;re not as bad as the Howard government &#8230; They&#8217;re not as bad as the Howard government &#8230; They&#8217;re not as bad as the Howard government &#8230; They&#8217;re not as bad as the Howard government &#8230; They&#8217;re not as bad as the Howard government &#8230; They&#8217;re not as bad as the Howard government &#8230; They&#8217;re not as bad as the Howard government &#8230; They&#8217;re not as bad as the Howard government &#8230; They&#8217;re not as bad as the Howard government &#8230;</p>
<p>If I keep repeating it I might begin to believe it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jacques Chester</title>
		<link>http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261354</link>
		<dc:creator>Jacques Chester</dc:creator>
		<pubDate>Mon, 14 Apr 2008 04:56:51 +0000</pubDate>
		<guid isPermaLink="false">http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261354</guid>
		<description>OK. His office say it's all been misrepresented by the media. A media beatup, they reckon. Apparently they're worried that companies who copy emails for virus-scanning purposes might be in contravention of the &lt;em&gt;Telecommunications Interception Act&lt;/em&gt; and they'd like to remove the potential problem.

The functionary at the A-G's office didn't know how the story got started or why Julia Gillard got involved in the way she did -- ie spouting total gibberish.

So I retract my claim that they're worse than Alston, but reserve the right to chuck an angry wobbly about political ignorance in future.</description>
		<content:encoded><![CDATA[<p>OK. His office say it&#8217;s all been misrepresented by the media. A media beatup, they reckon. Apparently they&#8217;re worried that companies who copy emails for virus-scanning purposes might be in contravention of the <em>Telecommunications Interception Act</em> and they&#8217;d like to remove the potential problem.</p>
<p>The functionary at the A-G&#8217;s office didn&#8217;t know how the story got started or why Julia Gillard got involved in the way she did &#8212; ie spouting total gibberish.</p>
<p>So I retract my claim that they&#8217;re worse than Alston, but reserve the right to chuck an angry wobbly about political ignorance in future.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jacques Chester</title>
		<link>http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261352</link>
		<dc:creator>Jacques Chester</dc:creator>
		<pubDate>Mon, 14 Apr 2008 04:52:25 +0000</pubDate>
		<guid isPermaLink="false">http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261352</guid>
		<description>Her office has referred me to A-G Robert McClellan's office.</description>
		<content:encoded><![CDATA[<p>Her office has referred me to A-G Robert McClellan&#8217;s office.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jacques Chester</title>
		<link>http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261349</link>
		<dc:creator>Jacques Chester</dc:creator>
		<pubDate>Mon, 14 Apr 2008 04:48:23 +0000</pubDate>
		<guid isPermaLink="false">http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261349</guid>
		<description>Just rang my local member. They said to ring Julia Gillard's office.


Ah, democracy at work.</description>
		<content:encoded><![CDATA[<p>Just rang my local member. They said to ring Julia Gillard&#8217;s office.</p>
<p>Ah, democracy at work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave Bath</title>
		<link>http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261342</link>
		<dc:creator>Dave Bath</dc:creator>
		<pubDate>Mon, 14 Apr 2008 04:34:23 +0000</pubDate>
		<guid isPermaLink="false">http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261342</guid>
		<description>Hmmmm.
The "National Security" argument is just plain dumb.

The real threat to critical industries is actually the lack of awareness by managers over simple things like patch management (the May 2001 horror stories in US and Oz were mainly due to long-known and patchable sendmail weaknesses).  If they are critical, they should be up to DSD ACSI 33 standards for that level of criticality, and up to PSM standards for incident investigations.

If the gov was serious, they'd make all executives in all agencies, subcontractors to agencies, and critical industries get at least "idiots guide" certificates in risk management (AS4360), information classification, DSD services, the PSM incident post-mortem procedures and ISO 27000 series before being allowed to make any decision on information management.</description>
		<content:encoded><![CDATA[<p>Hmmmm.<br />
The &#8220;National Security&#8221; argument is just plain dumb.</p>
<p>The real threat to critical industries is actually the lack of awareness by managers over simple things like patch management (the May 2001 horror stories in US and Oz were mainly due to long-known and patchable sendmail weaknesses).  If they are critical, they should be up to DSD ACSI 33 standards for that level of criticality, and up to PSM standards for incident investigations.</p>
<p>If the gov was serious, they&#8217;d make all executives in all agencies, subcontractors to agencies, and critical industries get at least &#8220;idiots guide&#8221; certificates in risk management (AS4360), information classification, DSD services, the PSM incident post-mortem procedures and ISO 27000 series before being allowed to make any decision on information management.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fleeced</title>
		<link>http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261336</link>
		<dc:creator>Fleeced</dc:creator>
		<pubDate>Mon, 14 Apr 2008 04:19:46 +0000</pubDate>
		<guid isPermaLink="false">http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261336</guid>
		<description>&lt;em&gt;&lt;blockquote&gt;Now Richard Alston actually looks good by comparison&lt;/blockquote&gt;&lt;/em&gt;

Well, I'm not sure I'd go that far... wasn't he the nimrod who, after banning internet gambling sites in Australia, declared people weren't very likely to use off-shore internet gambling sites because of the costs of long distance calls?</description>
		<content:encoded><![CDATA[<p><em><br />
<blockquote>Now Richard Alston actually looks good by comparison</p></blockquote>
<p></em></p>
<p>Well, I&#8217;m not sure I&#8217;d go that far&#8230; wasn&#8217;t he the nimrod who, after banning internet gambling sites in Australia, declared people weren&#8217;t very likely to use off-shore internet gambling sites because of the costs of long distance calls?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrick</title>
		<link>http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261335</link>
		<dc:creator>Patrick</dc:creator>
		<pubDate>Mon, 14 Apr 2008 04:17:19 +0000</pubDate>
		<guid isPermaLink="false">http://clubtroppo.com.au/2008/04/14/and-then-a-stupidity-occurs/#comment-261335</guid>
		<description>Actually, it has been obvious for a long time that Labor's IT policy is stuck in the same era as the CFMEU.</description>
		<content:encoded><![CDATA[<p>Actually, it has been obvious for a long time that Labor&#8217;s IT policy is stuck in the same era as the CFMEU.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
