[2134] in Security FYI
[IS&T Security-FYI] SFYI Newsletter, December 21, 2009
daemon@ATHENA.MIT.EDU (Monique Yeaton)
Mon Dec 21 13:36:44 2009
Message-Id: <61144BF7-A452-4668-A25F-0EA7F99C4BA2@mit.edu>
From: Monique Yeaton <myeaton@MIT.EDU>
To: ist-security-fyi@MIT.EDU
Mime-Version: 1.0 (Apple Message framework v936)
Date: Mon, 21 Dec 2009 13:34:51 -0500
Cc: itss@MIT.EDU
Content-Type: multipart/mixed; boundary="===============1876737191=="
Errors-To: ist-security-fyi-bounces@MIT.EDU
--===============1876737191==
Content-Type: multipart/signed; boundary=Apple-Mail-28--354549669; micalg=sha1;
protocol="application/pkcs7-signature"
--Apple-Mail-28--354549669
Content-Type: multipart/alternative;
boundary=Apple-Mail-27--354549729
--Apple-Mail-27--354549729
Content-Type: text/plain;
charset=US-ASCII;
format=flowed;
delsp=yes
Content-Transfer-Encoding: 7bit
In this issue:
1. Adobe Issues
2. The P2P Controversy
--------------------
1. Adobe Issues
--------------------
---- Updates Crashing Your Browser or System? ----
Last week I announced the release of security updates for Adobe Flash
Player and AIR. A reader of this newsletter mentioned that when trying
to download updates from the Adobe site his computer crashes. It is
unclear why this is happening. It may be a problem with Adobe's
compatibility with browser Internet Explorer or Windows XP.
If you have the same experience, hold off on upgrading until this bug
is fixed. In the meantime, you may want to notify Adobe via:
<http://www.adobe.com/support/contact/>.
---- New Flaw Found in Reader and Acrobat ----
There is a recently disclosed critical vulnerability in Adobe Reader
and Adobe Acrobat. The flaw is being actively exploited through
maliciously crafted PDF files to crash vulnerable systems or execute
code.
Adobe plans to release patches for the vulnerability by January 12,
2010. The flaw affects Adobe Reader 9.2 and earlier for Windows, Mac
and Unix and Acrobat 9.2 and earlier for Windows and Mac. Adobe
recommends that, if feasible, users disable JavaScript in both
programs until a fix is available.
Read the full story:
<http://www.theregister.co.uk/2009/12/17/adobe_critical_pdf_flaw/>
------------------------------
2. The P2P Controversy
------------------------------
There has been some discussion within the government recently about
the risks of peer-to-peer (P2P) file sharing to data security.
In November, bill HR 4098, the Secure Federal File Sharing Act, was
introduced in Congress to ban P2P file sharing on US government, and
government contractor computers. Sensitive Defense Department
documents were lost through P2P networks earlier this year, likely
prompting the proposal of this bill.
In higher education the use of P2P software produces a different
reaction than the one mentioned above. As a file sharing tool it has
great potential for playing a positive role in fulfilling the
institutional missions of teaching, research, and the dissemination of
knowledge. However, as we know, it is typically used for illegally
sharing copyright protected music, movies and software.
The bigger issue that Congress is considering, namely ensuring that
sensitive data and personally identifiable information is protected
against leakage via file-sharing networks, also applies to
universities. Is there any reason why computers containing sensitive
data should have such a potentially dangerous application installed on
them?
Since P2P networks are transfer tools, they are vulnerable to exposure
of data and the distribution of malware. Hackers can attack these
networks by changing legitimate files through the installation of
malware, implanting malware into shared directories, exploiting
vulnerabilities in the coding protocol of the network, and creating
denial of service and spamming attacks that attempt to harass the
users of the P2P network.
MIT does not put limits on the use of P2P programs. However, as a
result of the 2008 Higher Education Opportunity Act (HEOA),
regulations were issued and finalized by the Department of Education
in October 2009, with several of these regulations addressing
unauthorized file sharing (and the use of P2P programs) on campus
networks.
We may therefore see some changes when enforcement goes into effect in
July 2010. Changes could include possible restrictions to file sharing
networks, alternatives to illegal downloading, and disclosure to
students describing file sharing and campus policies related to
copyright law.
Risks of illegal downloading hit home quite recently. In November a
Boston University student was ordered to pay $675,000 in damages for
illegally downloading songs and sharing them online.
More information can be found here:
HEOA:
<http://www.educause.edu/Resources/Browse/HEOA/34600>
Government ban on P2P:
<http://www.sophos.com/blogs/chetw/g/2009/11/18/congress-ban-p2p-filesharing-companies-follow-suit/
>
Definition of P2P File Sharing:
<http://en.wikipedia.org/wiki/P2P_file_sharing>
Tips on P2P security:
<http://www.onguardonline.gov/topics/p2p-security.aspx>
<http://www.ftc.gov/bcp/edu/pubs/consumer/alerts/alt128.shtm>
Hidden Dangers of P2P:
<http://www.gcn.com/Articles/2009/10/05/Cybereye-P2P-file-sharing-dangers.aspx
>
=
=
=
========================================================================
Find current and older issues of Security FYI Newsletter: <http://kb.mit.edu/confluence/x/ehBB
>
Monique Yeaton
IT Security Awareness Consultant
MIT Information Services & Technology (IS&T)
(617) 253-2715
http://ist.mit.edu/security
--Apple-Mail-27--354549729
Content-Type: text/html;
charset=US-ASCII
Content-Transfer-Encoding: quoted-printable
<html><body style=3D"word-wrap: break-word; -webkit-nbsp-mode: space; =
-webkit-line-break: after-white-space; "><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal =
normal normal 14px/normal Helvetica; min-height: 17px; "><br></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 14px/normal Helvetica; ">In =
this issue:</div><div style=3D"margin-top: 0px; margin-right: 0px; =
margin-bottom: 0px; margin-left: 0px; font: normal normal normal =
14px/normal Helvetica; min-height: 17px; "><br></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 14px/normal Helvetica; ">1. =
Adobe Issues</div><div style=3D"margin-top: 0px; margin-right: 0px; =
margin-bottom: 0px; margin-left: 0px; font: normal normal normal =
14px/normal Helvetica; ">2. The P2P Controversy</div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 14px/normal Helvetica; =
min-height: 17px; "><br></div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal =
normal normal 14px/normal Helvetica; min-height: 17px; "><br></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 14px/normal Helvetica; =
">--------------------</div><div style=3D"margin-top: 0px; margin-right: =
0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal =
14px/normal Helvetica; ">1. Adobe Issues</div><div style=3D"margin-top: =
0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: =
normal normal normal 14px/normal Helvetica; =
">--------------------</div><div style=3D"margin-top: 0px; margin-right: =
0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal =
14px/normal Helvetica; min-height: 17px; "><br></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 14px/normal Helvetica; =
"> ---- Updates Crashing Your Browser or System? ----</div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 14px/normal Helvetica; =
min-height: 17px; "><br></div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal =
normal normal 14px/normal Helvetica; ">Last week I announced the release =
of security updates for Adobe Flash Player and AIR. A reader of this =
newsletter mentioned that when trying to download updates from the Adobe =
site his computer crashes. It is unclear why this is happening. It may =
be a problem with Adobe's compatibility with browser Internet Explorer =
or Windows XP.</div><div style=3D"margin-top: 0px; margin-right: 0px; =
margin-bottom: 0px; margin-left: 0px; font: normal normal normal =
14px/normal Helvetica; min-height: 17px; "><br></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 14px/normal Helvetica; ">If =
you have the same experience, hold off on upgrading until this bug is =
fixed. In the meantime, you may want to notify Adobe =
via: </div><div style=3D"margin-top: 0px; margin-right: 0px; =
margin-bottom: 0px; margin-left: 0px; font: normal normal normal =
14px/normal Arial; "><<a =
href=3D"http://www.adobe.com/support/contact/">http://www.adobe.com/suppor=
t/contact/</a>>. </div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal =
normal normal 14px/normal Helvetica; min-height: 17px; "><br></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 14px/normal Helvetica; =
min-height: 17px; "><br></div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal =
normal normal 14px/normal Helvetica; "> ---- New Flaw Found in =
Reader and Acrobat ----</div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal =
normal normal 14px/normal Helvetica; min-height: 17px; "><br></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 14px/normal Arial; ">There =
is a recently disclosed critical vulnerability in Adobe Reader and Adobe =
Acrobat. The flaw is being actively exploited through maliciously =
crafted PDF files to crash vulnerable systems or execute code. =
</div><div style=3D"margin-top: 0px; margin-right: 0px; =
margin-bottom: 0px; margin-left: 0px; font: normal normal normal =
14px/normal Arial; min-height: 16px; "><br></div><div style=3D"margin-top:=
0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: =
normal normal normal 14px/normal Arial; ">Adobe plans to release patches =
for the vulnerability by January 12, 2010. The flaw affects Adobe =
Reader 9.2 and earlier for Windows, Mac and Unix and Acrobat 9.2 and =
earlier for Windows and Mac. Adobe recommends that, if feasible, users =
disable JavaScript in both programs until a fix is available.</div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 14px/normal Helvetica; =
min-height: 17px; "><br></div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal =
normal normal 14px/normal Helvetica; ">Read the full story:</div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 14px/normal Helvetica; =
"><<a =
href=3D"http://www.theregister.co.uk/2009/12/17/adobe_critical_pdf_flaw/">=
http://www.theregister.co.uk/2009/12/17/adobe_critical_pdf_flaw/</a>></=
div><div style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: =
0px; margin-left: 0px; font: normal normal normal 14px/normal Helvetica; =
min-height: 17px; "><br></div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal =
normal normal 14px/normal Helvetica; min-height: 17px; "><br></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 14px/normal Helvetica; =
">------------------------------</div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal =
normal normal 14px/normal Helvetica; ">2. The P2P Controversy</div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 14px/normal Helvetica; =
">------------------------------</div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal =
normal normal 14px/normal Helvetica; min-height: 17px; "><br></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 14px/normal Helvetica; =
">There has been some discussion within the government recently about =
the risks of peer-to-peer (P2P) file sharing to data =
security. </div><div style=3D"margin-top: 0px; margin-right: 0px; =
margin-bottom: 0px; margin-left: 0px; font: normal normal normal =
14px/normal Helvetica; min-height: 17px; "><br></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 14px/normal Arial; ">In =
November, bill HR 4098, the Secure Federal File Sharing Act, was =
introduced in Congress to ban P2P file sharing on US government, and =
government contractor computers. Sensitive Defense Department documents =
were lost through P2P networks earlier this year, likely prompting the =
proposal of this bill.</div><div style=3D"margin-top: 0px; margin-right: =
0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal =
14px/normal Arial; min-height: 16px; "><br></div><div style=3D"margin-top:=
0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: =
normal normal normal 14px/normal Arial; ">In higher education the use of =
P2P software produces a different reaction than the one mentioned above. =
As a file sharing tool it has great potential for playing a positive =
role in fulfilling the institutional missions of teaching, research, and =
the dissemination of knowledge. However, as we know, it is typically =
used for illegally sharing copyright protected music, movies and =
software.</div><div style=3D"margin-top: 0px; margin-right: 0px; =
margin-bottom: 0px; margin-left: 0px; font: normal normal normal =
14px/normal Arial; min-height: 16px; "><br></div><div style=3D"margin-top:=
0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: =
normal normal normal 14px/normal Arial; ">The bigger issue that Congress =
is considering, namely ensuring that sensitive data and personally =
identifiable information is protected against leakage via file-sharing =
networks, also applies to universities. Is there any reason why =
computers containing sensitive data should have such a potentially =
dangerous application installed on them?</div><div style=3D"margin-top: =
0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: =
normal normal normal 14px/normal Arial; min-height: 16px; =
"><br></div><div style=3D"margin-top: 0px; margin-right: 0px; =
margin-bottom: 0px; margin-left: 0px; font: normal normal normal =
14px/normal Arial; ">Since P2P networks are transfer tools, they are =
vulnerable to exposure of data and the distribution of malware. Hackers =
can attack these networks by changing legitimate files through the =
installation of malware, implanting malware into shared directories, =
exploiting vulnerabilities in the coding protocol of the network, and =
creating denial of service and spamming attacks that attempt to harass =
the users of the P2P network.</div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal =
normal normal 14px/normal Arial; min-height: 16px; "><br></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 14px/normal Arial; ">MIT =
does not put limits on the use of P2P programs. However, as a result of =
the 2008 Higher Education Opportunity Act (HEOA), regulations were =
issued and finalized by the Department of Education in October 2009, =
with several of these regulations addressing unauthorized file sharing =
(and the use of P2P programs) on campus networks.</div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 14px/normal Arial; =
min-height: 16px; "><br></div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal =
normal normal 14px/normal Arial; ">We may therefore see some changes =
when enforcement goes into effect in July 2010. Changes could include =
possible restrictions to file sharing networks, alternatives to illegal =
downloading, and disclosure to students describing file sharing and =
campus policies related to copyright law.</div><div style=3D"margin-top: =
0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: =
normal normal normal 14px/normal Arial; min-height: 16px; =
"><br></div><div style=3D"margin-top: 0px; margin-right: 0px; =
margin-bottom: 0px; margin-left: 0px; font: normal normal normal =
14px/normal Arial; ">Risks of illegal downloading hit home quite =
recently. In November a Boston University student was ordered to pay =
$675,000 in damages for illegally downloading songs and sharing them =
online.</div><div style=3D"margin-top: 0px; margin-right: 0px; =
margin-bottom: 0px; margin-left: 0px; font: normal normal normal =
14px/normal Arial; min-height: 16px; "><br></div><div style=3D"margin-top:=
0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: =
normal normal normal 14px/normal Arial; ">More information can be found =
here:</div><div style=3D"margin-top: 0px; margin-right: 0px; =
margin-bottom: 0px; margin-left: 0px; font: normal normal normal =
14px/normal Arial; min-height: 16px; "><br></div><div style=3D"margin-top:=
0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: =
normal normal normal 14px/normal Arial; ">HEOA: </div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 14px/normal Arial; "><<a =
href=3D"http://www.educause.edu/Resources/Browse/HEOA/34600">http://www.ed=
ucause.edu/Resources/Browse/HEOA/34600</a>></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 14px/normal Arial; =
min-height: 16px; "><br></div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal =
normal normal 14px/normal Arial; ">Government ban on =
P2P: </div><div style=3D"margin-top: 0px; margin-right: 0px; =
margin-bottom: 0px; margin-left: 0px; font: normal normal normal =
14px/normal Arial; "><<a =
href=3D"http://www.sophos.com/blogs/chetw/g/2009/11/18/congress-ban-p2p-fi=
lesharing-companies-follow-suit/">http://www.sophos.com/blogs/chetw/g/2009=
/11/18/congress-ban-p2p-filesharing-companies-follow-suit/</a>></div><d=
iv style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 14px/normal Arial; =
min-height: 16px; "><br></div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal =
normal normal 14px/normal Arial; ">Definition of P2P File =
Sharing: </div><div style=3D"margin-top: 0px; margin-right: 0px; =
margin-bottom: 0px; margin-left: 0px; font: normal normal normal =
14px/normal Arial; "><<a =
href=3D"http://en.wikipedia.org/wiki/P2P_file_sharing">http://en.wikipedia=
.org/wiki/P2P_file_sharing</a>></div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal =
normal normal 14px/normal Arial; min-height: 16px; "><br></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 14px/normal Arial; ">Tips =
on P2P security: </div><div style=3D"margin-top: 0px; margin-right: =
0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal =
14px/normal Arial; "><<a =
href=3D"http://www.onguardonline.gov/topics/p2p-security.aspx">http://www.=
onguardonline.gov/topics/p2p-security.aspx</a>></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 14px/normal Arial; "><<a =
href=3D"http://www.ftc.gov/bcp/edu/pubs/consumer/alerts/alt128.shtm">http:=
//www.ftc.gov/bcp/edu/pubs/consumer/alerts/alt128.shtm</a>></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 14px/normal Arial; =
min-height: 16px; "><br></div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal =
normal normal 14px/normal Arial; ">Hidden Dangers of =
P2P: </div><div style=3D"margin-top: 0px; margin-right: 0px; =
margin-bottom: 0px; margin-left: 0px; font: normal normal normal =
14px/normal Arial; "><<a =
href=3D"http://www.gcn.com/Articles/2009/10/05/Cybereye-P2P-file-sharing-d=
angers.aspx">http://www.gcn.com/Articles/2009/10/05/Cybereye-P2P-file-shar=
ing-dangers.aspx</a>></div><div style=3D"margin-top: 0px; =
margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal =
normal normal 14px/normal Arial; min-height: 16px; "><br></div><div =
style=3D"margin-top: 0px; margin-right: 0px; margin-bottom: 0px; =
margin-left: 0px; font: normal normal normal 14px/normal Arial; =
">=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D</div><div style=3D"margin-top: 0px; margin-right: 0px; =
margin-bottom: 0px; margin-left: 0px; font: normal normal normal =
14px/normal Arial; min-height: 16px; "><br></div><div style=3D"margin-top:=
0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: =
normal normal normal 14px/normal Arial; ">Find current and older issues =
of Security FYI Newsletter: <<a =
href=3D"http://kb.mit.edu/confluence/x/ehBB"><span =
style=3D"text-decoration: underline ; color: =
#2151aa">http://kb.mit.edu/confluence/x/ehBB</span></a>></div><div><fon=
t class=3D"Apple-style-span" face=3D"Arial"><br></font></div><br><div =
apple-content-edited=3D"true"><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
Calibri; font-size: medium; font-style: normal; font-variant: normal; =
font-weight: normal; letter-spacing: normal; line-height: normal; =
orphans: 2; text-align: auto; text-indent: 0px; text-transform: none; =
white-space: normal; widows: 2; word-spacing: 0px; =
-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: =
0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px; "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; "><span class=3D"Apple-style-span" =
style=3D"border-collapse: separate; color: rgb(0, 0, 0); font-family: =
Calibri; font-size: 14px; font-style: normal; font-variant: normal; =
font-weight: normal; letter-spacing: normal; line-height: normal; =
orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; =
widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; =
-webkit-border-vertical-spacing: 0px; =
-webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: =
auto; -webkit-text-stroke-width: 0px; "><div style=3D"word-wrap: =
break-word; -webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space; "><div><div><span class=3D"Apple-style-span" =
style=3D"font-size: medium;"><br></span><div>Monique Yeaton</div><div>IT =
Security Awareness Consultant</div><div>MIT Information Services & =
Technology (IS&T)</div><div>(617) 253-2715</div><div><a =
href=3D"http://ist.mit.edu/security">http://ist.mit.edu/security</a></div>=
<div><br></div><br></div></div><br></div></span><br =
class=3D"Apple-interchange-newline"></div></span><br =
class=3D"Apple-interchange-newline"> </div><br></body></html>=
--Apple-Mail-27--354549729--
--Apple-Mail-28--354549669
Content-Disposition: attachment;
filename=smime.p7s
Content-Type: application/pkcs7-signature;
name=smime.p7s
Content-Transfer-Encoding: base64
MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIDwjCCA74w
ggMnoAMCAQICEQCgVkmJt2RPZFjUToeFtLUNMA0GCSqGSIb3DQEBBQUAMGwxCzAJBgNVBAYTAlVT
MRYwFAYDVQQIEw1NYXNzYWNodXNldHRzMS4wLAYDVQQKEyVNYXNzYWNodXNldHRzIEluc3RpdHV0
ZSBvZiBUZWNobm9sb2d5MRUwEwYDVQQLEwxDbGllbnQgQ0EgdjEwHhcNMDkwNzA3MTkwNzQ1WhcN
MTAwNzMxMTkwNzQ1WjCBpTELMAkGA1UEBhMCVVMxFjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxLjAs
BgNVBAoTJU1hc3NhY2h1c2V0dHMgSW5zdGl0dXRlIG9mIFRlY2hub2xvZ3kxFTATBgNVBAsTDENs
aWVudCBDQSB2MTEXMBUGA1UEAxMOTW9uaXF1ZSBZZWF0b24xHjAcBgkqhkiG9w0BCQEWD215ZWF0
b25ATUlULkVEVTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAL5YyEmHtimNf2l9Swh7
azen1VDYTAHPef/hu8pDiEdf51i6i/1uiI7RCvzmGt8SRR3gwx1MuJt3TCKKX7kedPK8owWHRDO1
SQTG+RJHEKa8IeG/7Fk8kXFJqBYbk5sA8YOQOwmlG2x5ssMhfoPAxc44rh9tk4VfDgASGZXQITa+
8SwLG2JSFgUlnvEJAOrw8XRXRX78mgPwkydJQNhfK+ikYm2JtyqM5cSwgLxHh0XldWAI7P4csM79
LQcG4HQZRmTCVeMuy67KgNjtg/94O5AfwLkbP6hwvqsDsfr8aTwhbrhkayJnvXeY0L2X4i9AasVP
aAC4apVYBbIQr5mW4S8CAwEAAaOBoTCBnjAJBgNVHRMEAjAAMBEGCWCGSAGG+EIBAQQEAwIFoDAd
BgNVHSUEFjAUBggrBgEFBQcDBAYIKwYBBQUHAwIwCwYDVR0PBAQDAgXgMB0GA1UdDgQWBBRfbDIy
HJrY3A0bf+451r8D8oZXGjAzBgNVHR8ELDAqMCigJqAkhiJodHRwOi8vY2EubWl0LmVkdS9jYS9t
aXRjbGllbnQuY3JsMA0GCSqGSIb3DQEBBQUAA4GBAIa1unH8mI8xbBDdr0Iqub03tHeb4/VWpsPq
GmhYH9vXRI6x7B+dAIwghm4gKo9y4d8qlgcx+1sLjRQ8DkZcXacX52a1eb1qYzXhzNGkxp4EEZIq
xYCHWJRYuitl+cpqVbS0Dxh/+gC5KL4LkMRJjQ6kP1ns99bdK132BxmyNX1+MYIDNjCCAzICAQEw
gYEwbDELMAkGA1UEBhMCVVMxFjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxLjAsBgNVBAoTJU1hc3Nh
Y2h1c2V0dHMgSW5zdGl0dXRlIG9mIFRlY2hub2xvZ3kxFTATBgNVBAsTDENsaWVudCBDQSB2MQIR
AKBWSYm3ZE9kWNROh4W0tQ0wCQYFKw4DAhoFAKCCAYkwGAYJKoZIhvcNAQkDMQsGCSqGSIb3DQEH
ATAcBgkqhkiG9w0BCQUxDxcNMDkxMjIxMTgzNDUyWjAjBgkqhkiG9w0BCQQxFgQUZQI19jXotZxK
3nIcSKe6ZuWeqFgwgZIGCSsGAQQBgjcQBDGBhDCBgTBsMQswCQYDVQQGEwJVUzEWMBQGA1UECBMN
TWFzc2FjaHVzZXR0czEuMCwGA1UEChMlTWFzc2FjaHVzZXR0cyBJbnN0aXR1dGUgb2YgVGVjaG5v
bG9neTEVMBMGA1UECxMMQ2xpZW50IENBIHYxAhEAoFZJibdkT2RY1E6HhbS1DTCBlAYLKoZIhvcN
AQkQAgsxgYSggYEwbDELMAkGA1UEBhMCVVMxFjAUBgNVBAgTDU1hc3NhY2h1c2V0dHMxLjAsBgNV
BAoTJU1hc3NhY2h1c2V0dHMgSW5zdGl0dXRlIG9mIFRlY2hub2xvZ3kxFTATBgNVBAsTDENsaWVu
dCBDQSB2MQIRAKBWSYm3ZE9kWNROh4W0tQ0wDQYJKoZIhvcNAQEBBQAEggEAhbJa5EVw7LdgjXcq
9Ct+Pt5fsyhcCzUTg+yawyzdklhJ/p7hDjFGFaXUwsKHyTv9BdEfqgb7ZnT9u41c2vWZeFTkqn2v
sFt71bTomNig/2lfAqu3BJJFY8a5M8IrPeDH6KZCvEjuOKnN5Q7TP+OdDH4BNLwUiBKwxxQ80kzg
nW5oa0aIdfK7JiAj4DGNUW1ZjaZ1Kfez5s+SfH/+7JUnJZ7DXyzvdlMRiFzJ19YPyE+JrJBa5Ifb
OFGo9Z/bYQDbfiofDfFDkK4wA2oQHoN+zkKE1vlcBWljJ0B9QZzy1dJqwpEOdUUGAgQEqbu9rWlR
EMBp4BCigPE+PfnJJg8D+QAAAAAAAA==
--Apple-Mail-28--354549669--
--===============1876737191==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
ist-security-fyi mailing list
ist-security-fyi@mit.edu
To Unsubscribe http://mailman.mit.edu/mailman/listinfo/ist-security-fyi
--===============1876737191==--