<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>

<channel>
	<title>The OPSEC Professional's Association President's Blog</title>
	<atom:link href="http://www.opsecprofessionals.org/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.opsecprofessionals.org/blog</link>
	<description>Straight talk from the OSPA President</description>
	<pubDate>Tue, 29 Dec 2009 17:41:36 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Hiding in plain site</title>
		<link>http://www.opsecprofessionals.org/blog/hiding-in-plain-site/</link>
		<comments>http://www.opsecprofessionals.org/blog/hiding-in-plain-site/#comments</comments>
		<pubDate>Tue, 29 Dec 2009 17:41:36 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[OPSEC]]></category>

		<category><![CDATA[plain site]]></category>

		<guid isPermaLink="false">http://www.opsecprofessionals.org/blog/hiding-in-plain-site/</guid>
		<description><![CDATA[The joke goes something like this:
There was a man who had worked at a factory for twenty years.  Every night when he left the plant, he would push a wheelbarrow full of straw to the guard at the gate.
The guard would look through the straw, and find nothing and pass the man through.
On the [...]


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>The joke goes something like this:</p>
<p>There was a man who had worked at a factory for twenty years.  Every night when he left the plant, he would push a wheelbarrow full of straw to the guard at the gate.<br />
The guard would look through the straw, and find nothing and pass the man through.<br />
On the day of his retirement the man came to the guard as usual but without the wheelbarrow.<br />
Having become friends over the years, the guard asked him, &#8220;Charlie, I&#8217;ve seen you walk out of here every night for twenty years. I know you&#8217;ve been stealing something. Now that you&#8217;re retired, tell me what it is.  It&#8217;s driving me crazy.&#8221;<br />
Charlie simply smiled and replied, &#8220;Okay, wheelbarrows!&#8221;</p>
<p>While wheelbarrow theft may not (or may, who are we to judge?) be your biggest concern, the message certainly is. Sometimes, the biggest threats are hiding in plain sight. Sometimes, what we assume is our biggest concern&#8230; is actually a distraction.</p>
<br/><a href="http://www.socialmarker.com/?link=http://www.opsecprofessionals.org/blog/hiding-in-plain-site/&title=Hiding+in+plain+site&text=The+joke+goes+something+like+this%3A+There+was+a+man+who+had+worked+at+a+factory+for+twenty+years.++Every+night+when+he+left+the+plant%2C+he+would+push+a+wheelbarrow+full+of+straw+to+the+guard+at+the...&tags=the+guard" target="_blank"><img src= "http://www.socialmarker.com/bookmark.gif" border="0" /></a><noscript><a href="http://www.socialmarker.com" >Social Bookmarking</a></noscript><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?&amp;linkurl=http%3A%2F%2Fwww.opsecprofessionals.org%2Fblog%2Fhiding-in-plain-site%2F&amp;linkname=Hiding%20in%20plain%20site"><img src="http://www.opsecprofessionals.org/blog/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Save/Bookmark"/></a>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.opsecprofessionals.org/blog/hiding-in-plain-site/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Shibboleth</title>
		<link>http://www.opsecprofessionals.org/blog/shibboleth/</link>
		<comments>http://www.opsecprofessionals.org/blog/shibboleth/#comments</comments>
		<pubDate>Sun, 06 Dec 2009 06:12:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[case study]]></category>

		<category><![CDATA[history]]></category>

		<guid isPermaLink="false">http://www.opsecprofessionals.org/blog/?p=63</guid>
		<description><![CDATA[A historical OPSEC note


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<div>Shibboleth.</div>
<div></div>
<div>No, that&#8217;s not a misspelled curse word. It&#8217;s an actual, factual security related concept, and one of particular interest to <span class="il">OPSEC</span>&#8216;ers.</div>
<div></div>
<div>By definition, a Shibboleth is &#8220;is any distinguishing practice which is indicative of one&#8217;s social or regional origin. It usually refers to features of language, and particularly to a word whose pronunciation identifies its speaker as being a member or not a member of a particular group.&#8221;</div>
<div></div>
<div>Certain subtle clues, inferring membership or exclusion from a group, can be of particular importance to a security professional. For instance, during the Battle of the Bulge, American soldiers used baseball trivia and knowledge to determine if others were fellow Americans or if they were infiltrators in American uniform. Another example, based on accents and linguistic capabilities, is when the Dutch used the name of the town Scheveningen to identify Germans.</div>
<div></div>
<div>Of course, we see the same thing when we go home to our children. When they tell their friends that their parents are &#8220;phat phree&#8221;, we might not no whether to thank them or ground them. (pro tip: &#8220;phat phree&#8221; is not a compliment)</div>
<div></div>
<div>However, this only highlights the fact that, sometimes, things just might not &#8220;feel right&#8221;, and you, as well as every employee, should be looking out for that. Every company, office or group has certain in-jokes or unique features, and a lack of knowledge about some elements of common knowledge should certainly be considered suspicious, or at least warrant additional consideration. Of course, this cuts both ways- if someone is able to learn certain &#8220;inside phrases&#8221; or procedures, that shouldn&#8217;t necessitate trust. Gaining trust in this manner is one of the concepts behind social engineering.</div>
<div></div>
<div>Shibboleth. It&#8217;s just another potential clue- another clue for every &#8220;sensor&#8221; (meaning every employee) to determine when something just &#8220;isn&#8217;t right&#8221;.</div>
<br/><a href="http://www.socialmarker.com/?link=http://www.opsecprofessionals.org/blog/shibboleth/&title=Shibboleth&text=Shibboleth.++No%2C+that%26%238217%3Bs+not+a+misspelled+curse+word.+It%26%238217%3Bs+an+actual%2C+factual+security+related+concept%2C+and+one+of+particular+interest+to+OPSEC%26%238216%3Bers.&tags=" target="_blank"><img src= "http://www.socialmarker.com/bookmark.gif" border="0" /></a><noscript><a href="http://www.socialmarker.com" >Social Bookmarking</a></noscript><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?&amp;linkurl=http%3A%2F%2Fwww.opsecprofessionals.org%2Fblog%2Fshibboleth%2F&amp;linkname=Shibboleth"><img src="http://www.opsecprofessionals.org/blog/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Save/Bookmark"/></a>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.opsecprofessionals.org/blog/shibboleth/feed/</wfw:commentRss>
		</item>
		<item>
		<title>OPSEC while &#8220;Home Alone&#8221;</title>
		<link>http://www.opsecprofessionals.org/blog/opsec-while-home-alone/</link>
		<comments>http://www.opsecprofessionals.org/blog/opsec-while-home-alone/#comments</comments>
		<pubDate>Sun, 14 Jun 2009 19:43:47 +0000</pubDate>
		<dc:creator>chris.cox</dc:creator>
		
		<category><![CDATA[indicators]]></category>

		<category><![CDATA[opsec at home]]></category>

		<guid isPermaLink="false">http://www.opsecprofessionals.org/blog/?p=54</guid>
		<description><![CDATA[The first part of this clip from the movie &#8220;Home Alone&#8221; has a few good &#8220;OPSEC&#8217; points.
For starters, Kevin obviously took a quick look at his operation (meaning his situation at home) from the perspective of an adversary- in this case, a burglar. Realizing that the deviation from an established profile (meaning signs of an [...]


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>The first part of this clip from the movie &#8220;Home Alone&#8221; has a few good &#8220;OPSEC&#8217; points.</p>
<p>For starters, Kevin obviously took a quick <strong>look at his operation</strong> (meaning his situation at home) from the <strong>perspective of an adversary</strong>- in this case, a burglar. Realizing that the <strong>deviation from an established profile</strong> (meaning signs of an occupied home) is itself an <strong>indicator </strong>(that something has changed, in this case, that the home is now unoccupied), Kevin <strong>implemented a countermeasure</strong>, which was to simulate a party.</p>
<p>For all appearances, the home was occupied.</p>
<p>Later, in a convenient plot device, Kevin overhears the burglars talking about their plans in very specific detail. Talking about their plan. Within earshot of those involved. Right before zero-hour.</p>
<p>Don&#8217;t you wish is was only the bad guys that do that?</p>
<p><a href="http://www.youtube.com/watch?v=lvqpfRKW7Y4">YouTube - Home Alone Xmas</a>.</p>
<p><object width="425" height="350" data="http://www.youtube.com/v/lvqpfRKW7Y4" type="application/x-shockwave-flash"><param name="wmode" value="transparent" /><param name="src" value="http://www.youtube.com/v/lvqpfRKW7Y4" /></object></p>
<br/><a href="http://www.socialmarker.com/?link=http://www.opsecprofessionals.org/blog/opsec-while-home-alone/&title=OPSEC+while+%26%238220%3BHome+Alone%26%238221%3B&text=The+first+part+of+this+clip+from+the+movie+%26%238220%3BHome+Alone%26%238221%3B+has+a+few+good+%26%238220%3BOPSEC%26%238217%3B+points.&tags=" target="_blank"><img src= "http://www.socialmarker.com/bookmark.gif" border="0" /></a><noscript><a href="http://www.socialmarker.com" >Social Bookmarking</a></noscript><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?&amp;linkurl=http%3A%2F%2Fwww.opsecprofessionals.org%2Fblog%2Fopsec-while-home-alone%2F&amp;linkname=OPSEC%20while%20%26%238220%3BHome%20Alone%26%238221%3B"><img src="http://www.opsecprofessionals.org/blog/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Save/Bookmark"/></a>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.opsecprofessionals.org/blog/opsec-while-home-alone/feed/</wfw:commentRss>
		</item>
		<item>
		<title>US Army allows access to blogs and other Social Media</title>
		<link>http://www.opsecprofessionals.org/blog/us-army-allows-access-to-blogs-and-other-social-media/</link>
		<comments>http://www.opsecprofessionals.org/blog/us-army-allows-access-to-blogs-and-other-social-media/#comments</comments>
		<pubDate>Fri, 12 Jun 2009 15:24:07 +0000</pubDate>
		<dc:creator>chris.cox</dc:creator>
		
		<category><![CDATA[Social Media]]></category>

		<category><![CDATA[Army OPSEC]]></category>

		<category><![CDATA[OPSEC social media]]></category>

		<category><![CDATA[OSPEC Blog]]></category>

		<guid isPermaLink="false">http://www.opsecprofessionals.org/blog/?p=51</guid>
		<description><![CDATA[According to Federal Computer Week (http://fcw.com/articles/2009/06/11/army-social-media.aspx?s=fcwdaily_120609), the US Army has directed network managers across the country to stop blocking certain Web 2.0 sites, such as Flickr Twitter, Photobucket, MySpace and Live365. 


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>According to Federal Computer Week (<a href="http://fcw.com/articles/2009/06/11/army-social-media.aspx?s=fcwdaily_120609">http://fcw.com/articles/2009/06/11/army-social-media.aspx?s=fcwdaily_120609</a>), the US Army has directed network managers across the country to stop blocking certain Web 2.0 sites, such as Flickr and Twitter. Photobucket, MySpace and Live365 are to be blocked.</p>
<p>The rationale, as reflected in the order, is that: “The intent of senior Army leaders to leverage social media as a medium to allow soldiers to ‘tell the Army story’ and to facilitate the dissemination of strategic, unclassified information, the social media sites available from the Army homepage will be made accessible from all campus area network.&#8221;</p>
<p>Many of us OPSEC&#8217;ers may have mixed feelings about this. While it is an opportunity to leverage emerging technologies and foster technical development within the military, there always remains the possibility of an inadvertent release of information.</p>
<p>But, at the same time, the reality is that it&#8217;s not the technology that&#8217;s the problem, and it&#8217;s certainly not going away. The problem lies within the users, and a relatively small number at that. The problem, to put it in it&#8217;s most basic terms, is not &#8220;what&#8221; the technology allows, but &#8220;how&#8221; it is used.</p>
<p>So, once again, it comes down to training. And with this recent order, it will be especially critical for all of you &#8220;Army OPSEC&#8217;ers&#8221; out there. Training and awareness are the two greatest tools in an OPSEC professional&#8217;s arsenal, and it&#8217;s the focus and dedication of each one of you that will keep OPSEC effective and relevant to today&#8217;s threats.</p>
<p>While unsung, you&#8217;re the last line of defense between your critical information and an adversary that wants it.</p>
<br/><a href="http://www.socialmarker.com/?link=http://www.opsecprofessionals.org/blog/us-army-allows-access-to-blogs-and-other-social-media/&title=US+Army+allows+access+to+blogs+and+other+Social+Media&text=According+to+Federal+Computer+Week+%28http%3A%2F%2Ffcw.com%2Farticles%2F2009%2F06%2F11%2Farmy-social-media.aspx%3Fs%3Dfcwdaily_120609%29%2C+the+US+Army+has+directed+network+managers+across+the+country+to+stop+blocking+certain...&tags=" target="_blank"><img src= "http://www.socialmarker.com/bookmark.gif" border="0" /></a><noscript><a href="http://www.socialmarker.com" >Social Bookmarking</a></noscript><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?&amp;linkurl=http%3A%2F%2Fwww.opsecprofessionals.org%2Fblog%2Fus-army-allows-access-to-blogs-and-other-social-media%2F&amp;linkname=US%20Army%20allows%20access%20to%20blogs%20and%20other%20Social%20Media"><img src="http://www.opsecprofessionals.org/blog/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Save/Bookmark"/></a>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.opsecprofessionals.org/blog/us-army-allows-access-to-blogs-and-other-social-media/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Back in the saddle again!</title>
		<link>http://www.opsecprofessionals.org/blog/back-in-the-saddle-again/</link>
		<comments>http://www.opsecprofessionals.org/blog/back-in-the-saddle-again/#comments</comments>
		<pubDate>Sun, 07 Jun 2009 07:23:38 +0000</pubDate>
		<dc:creator>chris.cox</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.opsecprofessionals.org/blog/?p=49</guid>
		<description><![CDATA[Well, it&#8217;s been a while since I&#8217;ve blogged here. No good reason, really, sometimes things get busy, and&#8230; well, you just forget that you even have a blog. You know how it goes.
Since my last post, a lot has happened. The National OPSEC Conference was a lot of fun, and OSPA had a very siccessful [...]


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>Well, it&#8217;s been a while since I&#8217;ve blogged here. No good reason, really, sometimes things get busy, and&#8230; well, you just forget that you even have a blog. You know how it goes.</p>
<p>Since my last post, a lot has happened. The National OPSEC Conference was a lot of fun, and OSPA had a very siccessful presence. As a result, OSPA has started working with the UN, NATO, several Law Enforcement Agencies, and a few Neighborhood Watch groups. It&#8217;s great to see OPSEC spreading like it is!</p>
<p>Updated the home page- it was time for another change!</p>
<p>Anyways, thanks for reading; more soon!</p>
<p>Chris</p>
<br/><a href="http://www.socialmarker.com/?link=http://www.opsecprofessionals.org/blog/back-in-the-saddle-again/&title=Back+in+the+saddle+again%21&text=Well%2C+it%26%238217%3Bs+been+a+while+since+I%26%238217%3Bve+blogged+here.+No+good+reason%2C+really%2C+sometimes+things+get+busy%2C+and%26%238230%3B+well%2C+you+just+forget+that+you+even+have+a+blog.+You+know+how+it+goes.&tags=" target="_blank"><img src= "http://www.socialmarker.com/bookmark.gif" border="0" /></a><noscript><a href="http://www.socialmarker.com" >Social Bookmarking</a></noscript><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?&amp;linkurl=http%3A%2F%2Fwww.opsecprofessionals.org%2Fblog%2Fback-in-the-saddle-again%2F&amp;linkname=Back%20in%20the%20saddle%20again%21"><img src="http://www.opsecprofessionals.org/blog/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Save/Bookmark"/></a>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.opsecprofessionals.org/blog/back-in-the-saddle-again/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Security Warning: Internet Explorer</title>
		<link>http://www.opsecprofessionals.org/blog/security-warning-internet-explorer/</link>
		<comments>http://www.opsecprofessionals.org/blog/security-warning-internet-explorer/#comments</comments>
		<pubDate>Tue, 16 Dec 2008 18:03:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Internet]]></category>

		<category><![CDATA[Microsoft]]></category>

		<category><![CDATA[Security Warning]]></category>

		<guid isPermaLink="false">http://www.opsecprofessionals.org/blog/?p=47</guid>
		<description><![CDATA[If you&#8217;re currently using Internet Explorer, please be aware that Microsoft has issued a warning about a current security flaw in all versions that is currently affecting around 2 Million users.
According to PC World Magazine, &#8220;So far most of the attacks have been geographically centered on China and have been used for the purposes of [...]


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;re currently using Internet Explorer, please be aware that Microsoft has issued a warning about a current security flaw in all versions that is currently affecting around 2 Million users.</p>
<p>According to PC World Magazine, &#8220;So far most of the attacks have been geographically centered on China and have been used for the purposes of stealing computer game passwords. But with a flaw as gap-toothed as this, the possibilities of nefarious action could include the massive theft of personal information such as administrative computer passwords and financial data.&#8221;</p>
<p>Although workarounds are available, Microsoft has suggested using an alternate browser, such as Firefox, in the meantime. For certain government systems, which are still required to use Internet Explorer, workarounds are available. Your IT/IMO staff should have more information.</p>
<p>Please see http://www.washingtonpost.com/wp-dyn/content/article/2008/12/16/AR2008121601022.html for more information.</p>
<br/><a href="http://www.socialmarker.com/?link=http://www.opsecprofessionals.org/blog/security-warning-internet-explorer/&title=Security+Warning%3A+Internet+Explorer&text=If+you%26%238217%3Bre+currently+using+Internet+Explorer%2C+please+be+aware+that+Microsoft+has+issued+a+warning+about+a+current+security+flaw+in+all+versions+that+is+currently+affecting+around+2+Million...&tags=" target="_blank"><img src= "http://www.socialmarker.com/bookmark.gif" border="0" /></a><noscript><a href="http://www.socialmarker.com" >Social Bookmarking</a></noscript><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?&amp;linkurl=http%3A%2F%2Fwww.opsecprofessionals.org%2Fblog%2Fsecurity-warning-internet-explorer%2F&amp;linkname=Security%20Warning%3A%20Internet%20Explorer"><img src="http://www.opsecprofessionals.org/blog/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Save/Bookmark"/></a>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.opsecprofessionals.org/blog/security-warning-internet-explorer/feed/</wfw:commentRss>
		</item>
		<item>
		<title>General Patton and OPSEC</title>
		<link>http://www.opsecprofessionals.org/blog/general-patton-and-opsec/</link>
		<comments>http://www.opsecprofessionals.org/blog/general-patton-and-opsec/#comments</comments>
		<pubDate>Wed, 26 Nov 2008 23:10:52 +0000</pubDate>
		<dc:creator>chris.cox</dc:creator>
		
		<category><![CDATA[OPSEC awareness]]></category>

		<category><![CDATA[case study]]></category>

		<category><![CDATA[patton]]></category>

		<category><![CDATA[WWII]]></category>

		<guid isPermaLink="false">http://www.opsecprofessionals.org/blog/?p=45</guid>
		<description><![CDATA[With Thanksgiving right around the corner, it makes me think of my family when I was coming up. We’d spend all day cooking the turkey, and the yams with those tiny marshmallows, and then we’d all sit around the table and watch George C. Scott in Patton.
 
No, not really. But it was a convenient way [...]


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Times New Roman;">With Thanksgiving right around the corner, it makes me think of my family when I was coming up. We’d spend all day cooking the turkey, and the yams with those tiny marshmallows, and then we’d all sit around the table and watch George C. Scott in Patton.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Times New Roman;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Times New Roman;">No, not really. But it was a convenient way to segue into an incident that was briefly covered in the movie, but required a great deal of complexity in order to be successful, and an excellent example of OPSEC (and strategic misinformation!) in action. </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Times New Roman;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Times New Roman;">If you’ve seen the movie, you’re familiar with the “slapping incident” of 1943, in which General Patton slapped a Soldier by the name of Charles Kuhl who was weeping in the infirmary. (For history buffs, it turned out that Kuhl had malaria at the time. Dispite the incident, however, he later recounted Patton as a “Great General”)</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Times New Roman;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Times New Roman;">When the stateside public and press learned of the incident, President Eisenhower was pressured to send Patton home in disgrace. However, Eisenhower and George Marshall came up with an alternate plan.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Times New Roman;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Times New Roman;">Patton was removed from any major command, but kept in theater. The German High Command was familiar with (and some say afraid of) Patton, so his location was closely watched for any sign of impending attack. As such, his extended stay in Sicily was seen as clear indicator of an upcoming invasion through France. At a later time, his visit to Cairo caused additional resources to be misdirected towards repelling an attack from the Balkans.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Times New Roman;">.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Times New Roman;">In the months before the 1944 Normandy Invasion, Allied forces launched “Operation Fortitude”, which was a major military disinformation campaign that involved controlled leaks of information, fake (even inflatable!) military equipment, message traffic and double agents. Perhaps most effective, however, was Patton’s public leadership of the (non-existent) First US Army Group (FUSAG). </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Times New Roman;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Times New Roman;">A culmination of this effort, and a memorable event for all involved, was when Patton shouted across a crowded reception hall to Eisenhower, “I’ll see you in Calais!”, which surely upset those that weren’t in on the ruse.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Times New Roman;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Times New Roman;">The efforts were highly successful and turned the tide of the war. The German Army had everything that they needed, and the Allies appeared to be practicing very poor OPSEC. This story applies today. Remember that when something seems “too perfect” or “obvious”… It just might be intentional.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Times New Roman;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-size: small; font-family: Times New Roman;">…And now you know… The rest of the story.</span></p>
<br/><a href="http://www.socialmarker.com/?link=http://www.opsecprofessionals.org/blog/general-patton-and-opsec/&title=General+Patton+and+OPSEC&text=With+Thanksgiving+right+around+the+corner%2C+it+makes+me+think+of+my+family+when+I+was+coming+up.+We%26%238217%3Bd+spend+all+day+cooking+the+turkey%2C+and+the+yams+with+those+tiny+marshmallows%2C+and+then...&tags=patton" target="_blank"><img src= "http://www.socialmarker.com/bookmark.gif" border="0" /></a><noscript><a href="http://www.socialmarker.com" >Social Bookmarking</a></noscript><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?&amp;linkurl=http%3A%2F%2Fwww.opsecprofessionals.org%2Fblog%2Fgeneral-patton-and-opsec%2F&amp;linkname=General%20Patton%20and%20OPSEC"><img src="http://www.opsecprofessionals.org/blog/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Save/Bookmark"/></a>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.opsecprofessionals.org/blog/general-patton-and-opsec/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Guest post- The Information Age and OPSEC</title>
		<link>http://www.opsecprofessionals.org/blog/guest-post-the-information-age-and-opsec/</link>
		<comments>http://www.opsecprofessionals.org/blog/guest-post-the-information-age-and-opsec/#comments</comments>
		<pubDate>Wed, 10 Sep 2008 20:47:18 +0000</pubDate>
		<dc:creator>chris.cox</dc:creator>
		
		<category><![CDATA[OPSEC awareness]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.opsecprofessionals.org/blog/?p=43</guid>
		<description><![CDATA[The Information Age and OPSEC
By Victor Duckarmenn
 
In 1941, we had our first real computer called the Z-3.  By 1971, we had E-mail, in 1989, the world- wide -web, (WWW) and wireless devices by the year 2000. Additional wonders of technology increase every decade. What are the consequences of all this “progress” and technological change?  Did [...]


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: Times New Roman;">The Information Age and OPSEC</span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: Times New Roman;">By Victor Duckarmenn</span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: Times New Roman;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: Times New Roman;">In 1941, we had our first real computer called the Z-3.<span style="mso-spacerun: yes;">  </span>By 1971, we had E-mail, in 1989, the world- wide -web, (WWW) and wireless devices by the year 2000. Additional wonders of technology increase every decade. What are the consequences of all this “progress” and technological change?<span style="mso-spacerun: yes;">  </span>Did personal or mission related information become more secure?<span style="mso-spacerun: yes;">  </span>Did space operations Essential Elements of Friendly Information (EEFI) become more or less important or just disappear in the advent of our space business?<span style="mso-spacerun: yes;">  </span>I am afraid our technical information, space mission secrets, our personal and space system data are all under attack every moment of the day.<span style="mso-spacerun: yes;">  </span>What information do you need to protect?<span style="mso-spacerun: yes;">  </span>Let’s look at critical information and its nature.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: Times New Roman;">The nature of critical information is defined in one word “vulnerable”.<span style="mso-spacerun: yes;">  </span>With advancing technology we find ourselves bracing for insider and hacker-cracker attacks, our systems are open to increased access via commercial Off -The -Shelf (COT) purchases without the need identified to protect our internal information.<span style="mso-spacerun: yes;">  </span>Identity theft activity is on the rise. The crime of 21<sup>st</sup> century will obviously be the theft of personal information. <span style="mso-spacerun: yes;"> </span>Data-mining, war-driving, and the lack of attention to our privacy and 1972 Privacy Act, has become the “white noise” behind our wireless vulnerabilities.<span style="mso-spacerun: yes;">  </span>Consider if you will, the tempo of information flow today.<span style="mso-spacerun: yes;">  </span>There is so much information available on the “net” or “grid” it scares Information Assurance (IA), Operations Security (OPSEC), computer security (COMPUSEC) and Info-Security (INFOSEC) subject matter experts (SME) to death.<span style="mso-spacerun: yes;">  </span>What are the “points of information contact” we need to watch for?<span style="mso-spacerun: yes;">  </span>What are the four OPSEC arenas in the information protection battle?<span style="mso-spacerun: yes;">  </span>They are the physical, administrative, action and technical. In 1941 we began the information age and the <span style="mso-spacerun: yes;"> </span>“Info-war”. <span style="mso-spacerun: yes;"> </span>What can you, the information warrior do? Let’s look at generic measures in the four OPSEC arenas.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: Times New Roman;">In order to combat the physical issues in protecting space operations information it is very simple, lock up mission sensitive, controlled unclassified, “For Official Use Only” (FOUO) and Privacy Act information. <span style="mso-spacerun: yes;"> </span>Implement double locks where possible to eliminate corporate and individual liabilities. The lack of consequences for our failures in the past for violations of the Privacy Act, or leaving mission critical controlled unclassified in the trash caused the death of this very simple measure.<span style="mso-spacerun: yes;">  </span>Apathy and complacency is your adversary’s tools in the information war. I call them the “gruesome two-some”. What about administration?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: Times New Roman;">Don’t leave your private information, recall rosters or sensitive data out in the open, on your desk or transmit it into the airwaves for all to receive. <span style="mso-spacerun: yes;"> </span>Administration has many natural controls to include 100% cross cut shredding, both and home and at work, the sanitization of the voice mail and out of office replies. <span style="mso-spacerun: yes;"> </span>Just a simple clean desk policy without posting retirement orders or system information could win the OPSEC “info-war”.<span style="mso-spacerun: yes;">  </span>What about actions?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: Times New Roman;">Conversations are a form of action. Stopping off base conversations about the mission failure or success, which can also be electronic, or talking out loud where local people do not have a “need to know” can be key to the denial of information to your intelligence enemies. <span style="mso-spacerun: yes;"> </span>What about the technical area?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: Times New Roman;"> </span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: Times New Roman;">One recommendation is to ensure success in the technical arena is to simply restrict your wireless usage during government business. Use a landline to discuss command and control information. <span style="mso-spacerun: yes;"> </span>A cell phone or personal assistant device (PAD) is like lighting up a cave with a halogen flashlight – the bats know you’re in the cave!<span style="mso-spacerun: yes;">  </span>It is important not to lose a cell phone or government thumb drive that is filled with critical information.<span style="mso-spacerun: yes;">  </span>So what?</span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: Times New Roman;">The information age is still growing and the value of protecting our space operations information is more “value added” everyday.<span style="mso-spacerun: yes;">  </span>Protect your wingman’s personal information.<span style="mso-spacerun: yes;">  </span>Protect your missions’ operation information. Your personal OPSEC has come of age; the information age!</span></p>
<br/><a href="http://www.socialmarker.com/?link=http://www.opsecprofessionals.org/blog/guest-post-the-information-age-and-opsec/&title=Guest+post-+The+Information+Age+and+OPSEC&text=The+Information+Age+and+OPSEC+By+Victor+Duckarmenn+%26%23160%3B+In+1941%2C+we+had+our+first+real+computer+called+the+Z-3.%26%23160%3B+By+1971%2C+we+had+E-mail%2C+in+1989%2C+the+world-+wide+-web%2C+%28WWW%29+and+wireless...&tags=the+information%2C+information+age%2C+and+the%2C+information%2C+space%2C+personal%2C+opsec%2C+mission" target="_blank"><img src= "http://www.socialmarker.com/bookmark.gif" border="0" /></a><noscript><a href="http://www.socialmarker.com" >Social Bookmarking</a></noscript><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?&amp;linkurl=http%3A%2F%2Fwww.opsecprofessionals.org%2Fblog%2Fguest-post-the-information-age-and-opsec%2F&amp;linkname=Guest%20post-%20The%20Information%20Age%20and%20OPSEC"><img src="http://www.opsecprofessionals.org/blog/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Save/Bookmark"/></a>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.opsecprofessionals.org/blog/guest-post-the-information-age-and-opsec/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Playing with OPSEC</title>
		<link>http://www.opsecprofessionals.org/blog/playing-with-opsec/</link>
		<comments>http://www.opsecprofessionals.org/blog/playing-with-opsec/#comments</comments>
		<pubDate>Mon, 08 Sep 2008 22:12:06 +0000</pubDate>
		<dc:creator>chris.cox</dc:creator>
		
		<category><![CDATA[opsec at home]]></category>

		<category><![CDATA[playstation]]></category>

		<category><![CDATA[video games]]></category>

		<category><![CDATA[xbox]]></category>

		<guid isPermaLink="false">http://www.opsecprofessionals.org/blog/?p=41</guid>
		<description><![CDATA[



By now, we&#8217;ve all taught our children what it&#8217;s &#8220;safe&#8221; to say, and what they should avoid
saying, when they&#8217;re using the computer. They probably know what chat rooms to avoid and
to be aware that &#8220;Sweet16girlie&#8221; might be more accurately described as &#8220;Unwashed46Man&#8221;.
So you&#8217;ve got the OPSEC for your family computer down pat.
What about the Playstation? [...]


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<table border="0" cellspacing="3" width="100%">
<tbody>
<tr>
<td class="text">
<div class="fixed leftAlign">By now, we&#8217;ve all taught our children what it&#8217;s &#8220;safe&#8221; to say, and what they should avoid<br />
saying, when they&#8217;re using the computer. They probably know what chat rooms to avoid and<br />
to be aware that &#8220;Sweet16girlie&#8221; might be more accurately described as &#8220;Unwashed46Man&#8221;.</p>
<p>So you&#8217;ve got the OPSEC for your family computer down pat.</p>
<p>What about the Playstation? What about the X-Box? Many families pay a monthly<br />
subscription fee to add network gameplay to these gaming consoles, which also allows for<br />
chat and even file transfer.</p>
<p>Make sure to talk to your kids about OPSEC and gaming consoles. Not only children play<br />
video games!</p></div>
</td>
</tr>
</tbody>
</table>
<br/><a href="http://www.socialmarker.com/?link=http://www.opsecprofessionals.org/blog/playing-with-opsec/&title=Playing+with+OPSEC&text=++++By+now%2C+we%26%238217%3Bve+all+taught+our+children+what+it%26%238217%3Bs+%26%238220%3Bsafe%26%238221%3B+to+say%2C+and+what+they+should+avoid+saying%2C+when+they%26%238217%3Bre+using+the+computer.&tags=" target="_blank"><img src= "http://www.socialmarker.com/bookmark.gif" border="0" /></a><noscript><a href="http://www.socialmarker.com" >Social Bookmarking</a></noscript><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?&amp;linkurl=http%3A%2F%2Fwww.opsecprofessionals.org%2Fblog%2Fplaying-with-opsec%2F&amp;linkname=Playing%20with%20OPSEC"><img src="http://www.opsecprofessionals.org/blog/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Save/Bookmark"/></a>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.opsecprofessionals.org/blog/playing-with-opsec/feed/</wfw:commentRss>
		</item>
		<item>
		<title>&#8220;The deposit box is out of order&#8221;</title>
		<link>http://www.opsecprofessionals.org/blog/the-deposit-box-is-out-of-order/</link>
		<comments>http://www.opsecprofessionals.org/blog/the-deposit-box-is-out-of-order/#comments</comments>
		<pubDate>Mon, 01 Sep 2008 04:15:33 +0000</pubDate>
		<dc:creator>chris.cox</dc:creator>
		
		<category><![CDATA[OPSEC awareness]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[social engineering]]></category>

		<guid isPermaLink="false">http://www.opsecprofessionals.org/blog/?p=37</guid>
		<description><![CDATA[
The Oregon Newspaper “The Oregonian” reported the following on August 19, 2008:
Two men made off with hundreds of dollars in cash by dressing as security guards, standing outside a bank&#8217;s night deposit slot and persuading people to hand over their money because the slot was broken.
The men offered to make the deposits for customers at [...]


No related posts.

Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.]]></description>
			<content:encoded><![CDATA[<p><!--[endif]--></p>
<p class="MsoNormal">The Oregon Newspaper “The Oregonian” reported the following on August 19, 2008:</p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Courier New&quot;;">Two men made off with hundreds of dollars in cash by dressing as security guards, standing outside a bank&#8217;s night deposit slot and persuading people to hand over their money because the slot was broken.</span></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Courier New&quot;;">The men offered to make the deposits for customers at the Washington Square branch of Wells Fargo Bank the next day when the bank reopened, said Jim Wolf, a Tigard Police Department spokesman.</span></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Courier New&quot;;">&#8220;Wells Fargo had absolutely no idea who these men were,&#8221; Wolf said. </span></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Courier New&quot;;">He said the men wore uniforms and had badges and guns. The night deposit slot was covered by a blue engraved sign saying it was out of order.</span></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Courier New&quot;;">The men offered to collect the deposits by putting them in a black box they had, Wolf said. The deposits came from businesses that normally use the slot to deposit the day&#8217;s receipts from their tills.</span></p>
<p class="MsoNormal" style="margin-bottom: 0.0001pt; line-height: normal;"><span style="font-size: 10pt; font-family: &quot;Courier New&quot;;">Two people who gave deposits to the men said the sign over the slot read &#8220;Out of Service.&#8221; </span></p>
<p class="MsoNoSpacing">
<p class="MsoNoSpacing">These men had many factors in their favor. Generally, people trust those that appear to have authority. Also, many people consider it “rude” to question someone who’s “just doing their job”, and many people have very low standards for correlation; in this case, the sign said the deposit box was out of order, and there was a guard nearby- “it must be true!”</p>
<p class="MsoNoSpacing">
<p class="MsoNoSpacing">The same threats exist against your organization. A “Social Engineer” will rely on those same assumptions, and several more, when attempting to infiltrate or obtain information to which they wouldn’t normally have access. Remember that enforcing security isn’t “rude”, and following proper procedures isn’t being “paranoid”!</p>
<p class="MsoNormal">
<br/><a href="http://www.socialmarker.com/?link=http://www.opsecprofessionals.org/blog/the-deposit-box-is-out-of-order/&title=%26%238220%3BThe+deposit+box+is+out+of+order%26%238221%3B&text=+The+Oregon+Newspaper+%26%238220%3BThe+Oregonian%26%238221%3B+reported+the+following+on+August+19%2C+2008%3A+Two+men+made+off+with+hundreds+of+dollars+in+cash+by+dressing+as+security+guards%2C+standing+outside+a...&tags=said+the%2C+people" target="_blank"><img src= "http://www.socialmarker.com/bookmark.gif" border="0" /></a><noscript><a href="http://www.socialmarker.com" >Social Bookmarking</a></noscript><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?&amp;linkurl=http%3A%2F%2Fwww.opsecprofessionals.org%2Fblog%2Fthe-deposit-box-is-out-of-order%2F&amp;linkname=%26%238220%3BThe%20deposit%20box%20is%20out%20of%20order%26%238221%3B"><img src="http://www.opsecprofessionals.org/blog/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share/Save/Bookmark"/></a>

<p>No related posts.</p>
<p>Related posts brought to you by <a href='http://mitcho.com/code/yarpp/'>Yet Another Related Posts Plugin</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://www.opsecprofessionals.org/blog/the-deposit-box-is-out-of-order/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
