<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DDoSed.com - An IT security information blog &#187; Privacy</title>
	<atom:link href="http://www.ddosed.com/category/privacy/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ddosed.com</link>
	<description></description>
	<lastBuildDate>Sat, 04 Oct 2008 07:21:19 +0000</lastBuildDate>
	
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Arrest Footage Of Notorious Turkish ATM hacker</title>
		<link>http://www.ddosed.com/2008/10/04/arrest-footage-of-notorious-turkish-atm-hacker/</link>
		<comments>http://www.ddosed.com/2008/10/04/arrest-footage-of-notorious-turkish-atm-hacker/#comments</comments>
		<pubDate>Sat, 04 Oct 2008 07:19:30 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Hardware Hacks]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Spamming & Scamming]]></category>
		<category><![CDATA[arrested]]></category>
		<category><![CDATA[atm fraud]]></category>
		<category><![CDATA[atm hacker chao]]></category>
		<category><![CDATA[atm hacking]]></category>
		<category><![CDATA[cagatay evyapan]]></category>
		<category><![CDATA[chao]]></category>
		<category><![CDATA[cloning atm cards]]></category>
		<category><![CDATA[credit-card-fraud]]></category>
		<category><![CDATA[turkey]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/?p=55</guid>
		<description><![CDATA[A notorious professional ATM hacker from Turkey got busted early last month.
&#8220;ChaO&#8221; (Cagatay Evyapan) was well-known in the underground carding community.  Watch the footage below, you will be very impressed how this fraudster converted his villa into a high profile ATM skimming device production factory.





ChaO&#8217;s fraud devices in action:

The attached skimming device copies all 3 [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">A notorious professional ATM hacker from Turkey got busted early last month.</p>
<p style="text-align: justify;">&#8220;ChaO&#8221; (Cagatay Evyapan) was well-known in the underground carding community.  Watch the footage below, you will be very impressed how this fraudster converted his villa into a high profile ATM skimming device production factory.<br />
</br><br />
<iframe src="http://www.vidomodo.com/play.video.php?id=1650" framespacing="0" frameborder="no" scrolling="no" width="415" height="280"></iframe><br />
</br><br />
<span id="more-55"></span></p>
<p style="text-align: justify;">
<p>ChaO&#8217;s fraud devices in action:<br />
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="src" value="http://www.youtube.com/v/H3Yqd7H08CA&amp;hl=en&amp;fs=1&amp;rel=0&amp;color1=0x006699&amp;color2=0x54abd6" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/H3Yqd7H08CA&amp;hl=en&amp;fs=1&amp;rel=0&amp;color1=0x006699&amp;color2=0x54abd6" allowfullscreen="true"></embed></object></p>
<p style="text-align: justify;">The attached skimming device copies all 3 tracks from the magnetic stripe of a credit/debit card, the keypad captures the PIN.  After is really easy for the fraudster to copy all collected info to  <strong><a title="ISO 7812 " href="http://en.wikipedia.org/wiki/ISO_7812" target="_blank">ISO 7812</a> </strong>blank cards  and eventually be able to cash out the money.</p>
<p>His hacking tips are the following (did not prove to be the best tips in his case):</p>
<blockquote><p><em>* don’t install a skimmer in the morning, because people are more vigilant then;<br />
* determine where a person would have to stand to keep an eye on everything happening on that block;<br />
* avoid blocks where more than 250 people per day walk through, because of the danger of detection;<br />
* don’t install skimmers in towns with fewer than 15,000 people, because people in those towns know what their ATMs look like;<br />
* avoid areas with small shops open 24 hours a day, because there may be surveillance cameras and vigilant shopkeepers;<br />
* don’t set up in areas where a lot of illegal immigrants live;<br />
* places with a lot of tourist traffic are good;<br />
* look for affluent neighborhoods and drive-through ATMs;<br />
* ATMs near cash-only bars are a good bet for lots of customer activity.</em></p></blockquote>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2008%2F10%2F04%2Farrest-footage-of-notorious-turkish-atm-hacker%2F';
  addthis_title  = 'Arrest+Footage+Of+Notorious+Turkish+ATM+hacker';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2008/10/04/arrest-footage-of-notorious-turkish-atm-hacker/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cross-Site Framed?</title>
		<link>http://www.ddosed.com/2007/03/28/cross-site-framed/</link>
		<comments>http://www.ddosed.com/2007/03/28/cross-site-framed/#comments</comments>
		<pubDate>Wed, 28 Mar 2007 02:59:34 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Security News]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/03/28/cross-site-framed/</guid>
		<description><![CDATA[Have you heard of cross-site framing? The past few days I saw listed on our archive, several websites vulnerable to cross-site framing &#8211; listed as frame redirection. I will briefly describe a possible exploitation scenario, concluding with more emphasis on the negative impact that this type of vulnerability can have to the privacy of innocent [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Have you heard of cross-site framing? The past few days I saw listed on our <a href="http://www.xssed.com/archive">archive</a>, several websites vulnerable to cross-site framing &#8211; listed as frame redirection. I will briefly describe a possible exploitation scenario, concluding with more emphasis on the negative impact that this type of vulnerability can have to the privacy of innocent individuals who are users of the affected websites.</p>
<p align="justify"><span id="more-49"></span></p>
<p align="justify">Using google-dorks, the attackers can search for frame scripts allowing the inclusion of any url. This search reveals thousands of results with too many websites vulnerable to cross-site framing:</p>
<p><a href="http://www.google.com/search?hl=us&amp;q=allinurl%3A%22url%3Dhttp%22+%22frame%22">allinurl:&#8221;url=http&#8221; &#8220;frame&#8221;</a></p>
<p><a href="http://www.google.com/search?hl=us&amp;q=inurl%3Aframe+filetype%3Aasp+inurl%3A%22url%3D%22">inurl:frame filetype:asp  inurl:&#8221;url=&#8221;</a><br />
<a href="http://www.google.com/search?hl=us&amp;q=inurl%3Aframe+filetype%3Aaspx+inurl%3A%22url%3D%22">inurl:frame filetype:aspx inurl:&#8221;url=&#8221;</a><br />
<a href="http://www.google.com/search?hl=us&amp;q=inurl%3Aframe+filetype%3Aphp+inurl%3A%22url%3D%22">inurl:frame filetype:php  inurl:&#8221;url=&#8221;</a><br />
<a href="http://www.google.com/search?hl=us&amp;q=inurl%3Aframe+filetype%3Acfm+inurl%3A%22url%3D%22">inurl:frame filetype:cfm  inurl:&#8221;url=&#8221;</a></p>
<p><a href="http://www.google.com/search?hl=us&amp;q=inurl%3Aiframe+filetype%3Aasp++inurl%3A%22url%3D%22">inurl:iframe filetype:asp  inurl:&#8221;url=&#8221;</a><br />
<a href="http://www.google.com/search?hl=us&amp;q=inurl%3Aiframe+filetype%3Aaspx++inurl%3A%22url%3D%22">inurl:iframe filetype:aspx inurl:&#8221;url=&#8221;</a><br />
<a href="http://www.google.com/search?hl=us&amp;q=inurl%3Aiframe+filetype%3Aphp++inurl%3A%22url%3D%22">inurl:iframe filetype:php  inurl:&#8221;url=&#8221;</a><br />
<a href="http://www.google.com/search?hl=us&amp;q=inurl%3Aiframe+filetype%3Acfm++inurl%3A%22url%3D%22">inurl:iframe filetype:cfm  inurl:&#8221;url=&#8221;</a></p>
<p><a href="http://www.google.com/search?hl=us&amp;q=allinurl%3Ahttp+frame.asp">allinurl:http frame.asp</a><br />
<a href="http://www.google.com/search?hl=us&amp;q=allinurl%3Ahttp+frame.aspx">allinurl:http frame.aspx</a><br />
<a href="http://www.google.com/search?hl=us&amp;q=allinurl%3Ahttp+frame.php">allinurl:http frame.php</a><br />
<a href="http://www.google.com/search?hl=us&amp;q=allinurl%3Ahttp+frame.cfm">allinurl:http frame.cfm</a></p>
<p><a href="http://www.google.com/search?hl=us&amp;q=allinurl%3Aframe.php%3Furl%3Dhttp">allinurl:frame.php?url=http</a><br />
<a href="http://www.google.com/search?hl=us&amp;q=allinurl%3Aframe.asp%3Furl%3Dhttp">allinurl:frame.asp?url=http</a></p>
<p align="justify">Phishing and other scams are now easier to perform due to cross-site framing.<br />
Having found such frame scripts, allows the attackers to include a webpage which is hosted somewhere else. This webpage can be designed to look like the original website and can be any cross-platform server-side script. It can contain a fake login form which on submit parses the inputted usernames and passwords and sends them to the attacker&#8217;s mailbox in cleartext format.</p>
<p align="justify">It is also possible to perform XSS attacks as in most cases there is no filtering of special characters, script or other common tags in the URL parameter.</p>
<p align="justify">Daniel Hugh mailed us about a cross-site framing and scripting vulnerability affecting <a href="http://www.gov.mt/">Gov.MT</a> (Official website of the Government of Malta):</p>
<p><a href="http://www.xssed.com/mirror/4987/">Gov.MT with Frame Redirect and XSS</a></p>
<p align="justify">The XSS vulnerabilities affecting websites can also be used to perform frame redirects, but not the contrary. So if you <a href="http://www.xssed.com/submit">submit </a>a website vulnerable to cross-site framing along with a XSS attack vector, we will publish it as XSS.</p>
<p align="justify">The above news were written in order to heighten the awareness of potential privacy threats to users of the web.</p>
<p align="justify">You can also access this blog post  from XSSed.com &#8211; a project I run with Kevin Fernandez.</p>
<p align="justify">Here is the link:</p>
<p align="justify"><a href="http://www.xssed.com/news/26/Cross-site_framed/">http://www.xssed.com/news/26/Cross-site_framed/</a></p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F03%2F28%2Fcross-site-framed%2F';
  addthis_title  = 'Cross-Site+Framed%3F';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/03/28/cross-site-framed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Main Issues Of Privacy With Respect To The Possible Introduction Of RFID Chips As Stock Trackers</title>
		<link>http://www.ddosed.com/2007/01/22/main-issues-of-privacy-rfid-stock-trackers/</link>
		<comments>http://www.ddosed.com/2007/01/22/main-issues-of-privacy-rfid-stock-trackers/#comments</comments>
		<pubDate>Mon, 22 Jan 2007 15:52:14 +0000</pubDate>
		<dc:creator>D1m</dc:creator>
				<category><![CDATA[Privacy]]></category>
		<category><![CDATA[RFID]]></category>
		<category><![CDATA[Security Articles]]></category>

		<guid isPermaLink="false">http://www.ddosed.com/2007/01/22/main-issues-of-privacy-with-respect-to-the-possible-introduction-of-rfid-chips-as-stock-trackers/</guid>
		<description><![CDATA[Radio Frequency Identification or RFID chips come in many different sizes and shapes, such as cards and tags. They are already in use all around us and one of the most notable uses of RFID is that of pet chipping. These are usually tiny chips that can be embedded in almost everything and are able [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Radio Frequency Identification or RFID chips come in many different sizes and shapes, such as cards and tags. They are already in use all around us and one of the most notable uses of RFID is that of pet chipping. These are usually tiny chips that can be embedded in almost everything and are able to identify living beings and a huge number of objects along with their properties, by transmitting the in chip stored information about them. [2]</p>
<p align="justify"> A large number of retailers worldwide hope that RFID will replace the less-precise barcode. This is for a number of advantages, including the automation of stock tracking for cutting costs for them and for the manufacturers. [2] Despite the advantages for the retailers and the parties involved in the supply chain, the possible near future implementation of RFID chips as stock trackers raises specific privacy issues for the consumers.</p>
<p align="justify"> This essay discusses these privacy issues with respect to the possible introduction of RFID chips as stock trackers. I will also provide a few notable examples of successes and failures in the RFID marketplace and possible solutions for mitigating privacy issues involved in stock tracking.</p>
<p><span id="more-16"></span></p>
<p><strong>SPECIFIC PRIVACY ISSUES &amp; MITIGATION APPROACHES</strong></p>
<p align="justify">&nbsp;</p>
<p align="justify"> Various groups of privacy advocates watchdog the RFID technology for anything they consider as an infringement of privacy rights. The scenarios that annoy them the most are the item-level tagging of consumer products that end up in consumer’s possession and the tagging or tracking of individuals. [4]</p>
<p align="justify">Today for example, if an individual purchases a pack of hand rolling tobacco in Reading, UK, its barcode would be identical to the same brand and type of hand rolling tobacco sold in Brighton, UK.  If the tobacco company chooses in the future to implement item-level tagging and the individual purchases a product with a loyalty card or credit card, it would be possible to tie the unique ID of the product to the ID of the purchaser. This creates a serious privacy issue for the consumers because they could then be tracked if they ever purchased from the same shop again or from any other shops capable of reading RFID tags [2].</p>
<p align="justify">&nbsp;</p>
<p align="justify"> RFID tags can be read at a certain distance without the knowledge of the individual. This means that when the individual enters a shop with his RFID tagged tobacco pack; the RFID reader in the shop can identify the brand of his tobacco, the shop that he purchased it from, the exact time and date of the purchase, how frequently he comes into the shop or even the time that he spent before coming to a decision whether to purchase it or not.</p>
<p align="justify"> If the individual used a loyalty card or credit card to purchase tobacco, the tobacco company and the store could tie the identified information to the individual’s name, address and e-mail. Then the individual could receive targeted advertisements by tobacco companies as he walks through the mall or mailings through his e-mail about special offers and other products [2]. This scenario is not far from the one in the “Minority Report” movie…</p>
<p align="justify">Several manufacturers and retailers, including TESCO in UK, Wal-Mart in USA and Prada, expect that the RFID tagging of their product range will aid significantly in the management of the supply-chain, from manufacturing to shipping of their products and to stocking their store shelves. [1]</p>
<p align="justify">&nbsp;</p>
<p>With the implementation of RFID technology, retailers and shops can build up an individual personal log of their customer’s shopping habits. [2] The monitoring of purchases may or may not involve personal information, because information on consumer shopping habits could be created without associating details with identified individuals. Consumer profiling is considered intrusive enough by many consumer’s standards and privacy advocates. Companies that want to keep track of the popularity of their products will not necessarily require the profiling of data about specific customer’s shopping habits. [1]</p>
<p align="justify"> In the UK, according to the Data Protection Act 1998 (“the Act”) [1], retailers and stores collecting personal information with RFID readers, must adhere to the fair processing requirements of the Act. This means that they must notify their customers about the presence of RFID tags on products and RFID readers, and explain them the possible implications [1]. They must inform their customers what personal information is being collected, by whom, and for what purpose. In case consumer profiles are used for direct marketing, retailers and stores should provide customers with a means of opting out of such direct marketing.  It is also necessary to explain to the customers how to remove or disable RFID tags from a product after purchase [1]. The Act applies where personal information is collected, generated or disclosed using RFID either directly or indirectly.</p>
<p align="justify">When companies decide to use RFID tags, must implement, operate and manage the RFID technology with special consideration to the data protection principles of use limitation, data quality, data retention and security [1]. This set of principles assures to a high percent the protection of the customer’s personal privacy, the improved operation of the company and thus the good relationship with the customers; but do not eliminate potential risks of privacy infringement.</p>
<p align="justify"> Use limitation means that personal information should only be collected by companies for legal purposes [1].<br />
Data quality means that companies should ensure that RFID collected personal information is valid, accurate and kept up to date. Only personal information necessary for specific purposes of the company should be collected [1].<br />
Data retention means that personal information should not be stored by the companies for longer than is necessary for a specified purpose [1].</p>
<p>Security means that the companies have the responsibility to ensure the security of any personal information stored or on them or linked to them [1].</p>
<p align="justify"> A few supermarkets have been using RFID tags in order to track how often certain products are removed from the shelves. Such information is usually general and do not relate to individuals. However, if this information were to be associated with identified individuals, would become personal information.</p>
<p align="justify"> Privacy advocates and civil liberties organizations worry that companies, retailers and shops using RFID are able to track consumers long after a purchase of a product [5]. For example, an apparel designing company can scan a fashion event for the number of people wearing its trousers.</p>
<p align="justify"> Most of the privacy concerns are based around the fact that RFID tags can still fully function after the tagged products have been taken home and even survive years of washing, drying and wearing! [3] They can be used for surveillance, corporate espionage and other utterly immoral purposes unrelated to their supply-chain stock functions.</p>
<p align="justify"> Large retailers such as the Wal-Mart in the USA sees it as an advantage to be able to track consumer shopping habits and stock as it improves their supply-chain efficiency and cuts significant costs.</p>
<p align="justify"> In early 2003, the Procter &amp; Gamble Co. and Wal-Mart in order to test RFID, tagged packages of lipstick in an Oklahoma shop and were able to track the customers as they took the lipstick off the shelves. This test raised the anger of privacy advocates worldwide for the obvious privacy issues.</p>
<p align="justify"> Stock tracking from the point that stock leaves the manufacturer to the location of where the product will be supplied for sale, is an acceptable use of RFID according to consumer privacy and civil liberties organizations [4]. Stealing and loss of stock as they move through the supply-chain should be prevented with the placement of RFID tags to the outside of the packaging and not embedded in the products.  The tags should be permanently destroyed before the shops put the products on the shelf. With that way consumers won’t have to worry much about their personal privacy, although there is always the risk of hidden placement of RFID tags and hidden RFID readers.</p>
<p align="justify"> Other acceptable uses of RFID are that of detecting items that contain toxic substances when they are delivered to the waste disposal area and that of tracking pharmaceuticals [4].</p>
<p><strong>FAILURES IN THE RFID MARKETPLACE &amp; LESSONS LEARNED</strong></p>
<p><strong>Metro Group</strong></p>
<p><strong> </strong>A notable failure is that of the Metro Group, a large retailer based in Germany. [7]</p>
<p align="justify"> In 2004, the company tagged its store loyalty card with RFID chips, without disclosing any information to consumers. When the privacy advocates found out, protested and threatened to strike against the company. Eventually, seeing so many angry privacy advocates and concerned consumers, the company put an end to RFID tagging of their loyalty cards and announced that they would replace existing cards with non-chipped ones. However, having established its “Future Store” for displaying and testing of new technologies, the company still continues to research innovative uses of RFID and other technologies. It has also created its own mandate, which requires RFID tagging of the pallet and case level for distribution and supply-chain purposes.</p>
<p><strong>Benetton<br />
</strong></p>
<p align="justify">In 2003, the Philips semiconductor manufacturing company publicized that it would supply RFID tags to the Benetton apparel company [6].</p>
<p align="justify">When the news reached the public worldwide, groups of privacy advocates called for a boycott of Benetton’s products. They even set up a web site (<a href="http://www.boycottbenetton.com/">www.boycottbenetton.com</a>) to show the whole world not to buy clothing with embedded RFID tags. In the website they included the slogan, “I’d rather go naked [than wear clothes with spychips].”  This call for a boycott created too many privacy concerned consumers and made Benetton announce a few weeks later that its products would not eventually be tagged with RFID.</p>
<p>There are a few lessons that can be learned from the above examples of failures in the RFID marketplace. [7]</p>
<p align="justify"> Prior to the implementation of RFID technologies, companies, retailers and shops must anticipate privacy concerns. Understanding the privacy concerns of the consumers regarding RFID tags can help for a better and more secure operation of a business. Both the customers and the companies will be happy.</p>
<p align="justify"> Companies must also find ways to mitigate privacy intrusion issues. They can, for instance, place RFID tags on consumer’s products that have a kill switch along with instructions on how to remove the tags.</p>
<p align="justify"> They must demonstrate the steps being taken to protect the privacy of the consumers and make sure that they get their message out to the public for specific educational awareness resulting to the decreased frequency of privacy issues.<br />
Metro Group did not even disclose that was going to use RFID tags in its loyalty cards. Consequently, it couldn’t defend to continue using the tags because when many privacy advocates and consumers found out about the matter, company got immediately disadvantaged in public relations.</p>
<p align="justify">&nbsp;</p>
<p><strong>SUCCESSES IN THE RFID MARKETPLACE</strong><strong><br />
</strong></p>
<p align="justify">Other retailers, including the UK Marks &amp; Spencer, are successfully continuing to use item-level tagging and to include trials of RFID tagging to a variety of its clothing lines.</p>
<p align="justify"> In 2003, Delta Air Lines in the USA tagged 40,000 customer bags in order to reduce baggage losses and make it easier to route bags if customers change flight. [3]</p>
<p align="justify"> The United States Department of Defense (DoD) is currently using RFID chips in order to track military shipments. It has also placed RFID tags on 270,000 cargo containers and is able to track all those shipments throughout 40 countries! [3]</p>
<p align="justify"> More and more businesses are interested in item-level tagging because it helps retailers and shops to keep the best selling products in stock and the stock moving. It benefits significantly the retailers because multiple products that comes in multiple sizes and colors are difficult to keep them stocked. With item-level tagging is not, because staff can find which products are in which boxes.</p>
<p><strong>CONCLUSION</strong><strong><br />
</strong></p>
<p align="justify">Despite the number of successes in the RFID marketplace, it will be years before we see individual item-level tagging on a widespread basis.</p>
<p align="justify"> Today, only a small number of retailers and manufacturers are piloting item-level tagging, although dozens more are evaluating its possible use. There is still a lot of research to be done in security, privacy and implementation issues.</p>
<p align="justify"> Most manufacturers and retailers that are currently using the RFID technology, are used to privacy intrusion issues. They will continue to use the technology and to deal closely with the consumer’s privacy concerns, mitigate the privacy intrusions, manage communications, and avoid a public relations nightmare like in the Metro Group case. [7] Correct implementation of RFID tags can have a huge advantage in the near future.</p>
<h2></h2>
<p><strong>REFERENCES</strong></p>
<p>[1] Information Commissioner&#8217;s Office &#8211; Data Protection Technical Guidance V1.0/09.08.06 &#8211; Radio Frequency Identification</p>
<p><a href="http://www.ico.gov.uk/upload/documents/library/data_protection/detailed_specialist_guides/radio_frequency_indentification_tech_guidance.pdf">http://www.ico.gov.uk/upload/documents/library/data_protection/detailed_specialist_guides/radio_frequency_indentification_tech_guidance.pdf</a></p>
<p>[2] Scottie Hawksworth &#8211; RFID Privacy and You</p>
<p><a href="http://ezinearticles.com/?RFID-Privacy-and-You&amp;id=30853">http://ezinearticles.com/?RFID-Privacy-and-You&amp;id=30853</a></p>
<p>[3] Scott Grannerman &#8211; SecurityFocus.com &#8211; RFID Chips Are Here</p>
<p><a href="http://www.securityfocus.com/columnists/169">http://www.securityfocus.com/columnists/169</a></p>
<p>[4] RFID Position Statement of Consumer Privacy and Civil Liberties Organizations</p>
<p><a href="http://www.privacyrights.org/ar/RFIDposition.htm#1">http://www.privacyrights.org/ar/RFIDposition.htm#1</a></p>
<p>[5] RFID and privacy: Debate heating up in Washington</p>
<p><a href="http://www.infoworld.com/article/04/05/28/HNrfidprivacy_1.html">http://www.infoworld.com/article/04/05/28/HNrfidprivacy_1.html</a></p>
<p>[6] Boycott Benetton &#8211; No RFID tracking chips in clothing!</p>
<p><a href="http://www.boycottbenetton.com/">http://www.boycottbenetton.com/</a></p>
<p>[7] METRO AG</p>
<p><a href="http://www.metrogroup.de/servlet/PB/menu/1014671_l2/">http://www.metrogroup.de/servlet/PB/menu/1014671_l2/</a></p>
<p align="justify">[8]  RFID Security &#8211; Protect the supply chain &#8211; Syngress Publications &#8211;  (ISBN:1597490474)</p>
<p>Buy the book from <a href="http://www.amazon.com/RFID-Security-Frank-Thornton/dp/1597490474/ref=pd_bbs_sr_1/103-8984035-8460628?ie=UTF8&amp;s=books&amp;qid=1173995804&amp;sr=8-1" title="RFID Security - Syngress - Amazon.com" target="_blank">Amazon.com</a> (Apr 2006 publication)</p>
<p>OR</p>
<p>from <a href="http://www.amazon.co.uk/RFID-Security-Peter-Lindstrom/dp/1597490474/ref=sr_1_3/203-3396222-3472710?ie=UTF8&amp;s=books&amp;qid=1173995931&amp;sr=8-3" title="RFID Security - Syngress - Amazon.co.uk" target="_blank">Amazon.co.uk</a> (Nov 2005 publication)</p>
<script type="text/javascript">
  addthis_url    = 'http%3A%2F%2Fwww.ddosed.com%2F2007%2F01%2F22%2Fmain-issues-of-privacy-rfid-stock-trackers%2F';
  addthis_title  = 'Main+Issues+Of+Privacy+With+Respect+To+The+Possible+Introduction+Of+RFID+Chips+As+Stock+Trackers';
  addthis_pub    = 'dpan';
</script><script type="text/javascript" src="http://s7.addthis.com/js/addthis_widget.php?v=12" ></script>
]]></content:encoded>
			<wfw:commentRss>http://www.ddosed.com/2007/01/22/main-issues-of-privacy-rfid-stock-trackers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
