<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No good deed goes unpunished in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/No-good-deed-goes-unpunished/m-p/33340#M2422</link>
    <description>&amp;gt; dcontesti (Community Champion) posted a new topic in Tech Talk on 03-03-2020&lt;BR /&gt;&lt;BR /&gt;&amp;gt; &lt;A href="https://www.cbc.ca/news/canada/hamilton/jackson-square-dental-hacking-1.5471071" target="_blank"&gt;https://www.cbc.ca/news/canada/hamilton/jackson-square-dental-hacking-1.5471071&lt;/A&gt;?&lt;BR /&gt;&amp;gt; fbclid=IwAR0Y3tH_n-DosPr8EPIibVF5BdecrZY5YJTTqH_IEy-lB9AEswRIo4WMQCI &amp;nbsp; So he&lt;BR /&gt;&amp;gt; says he was only trying to help....... &amp;nbsp; Thoughts? &amp;nbsp; d &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Notes for those not wanting to be called hackers:&lt;BR /&gt;&lt;BR /&gt;- don't wait for all staff to exit the room and then intract with the device without&lt;BR /&gt;permission&lt;BR /&gt;&lt;BR /&gt;- if you find out where the password field is, just point it out to the staff and don't&lt;BR /&gt;ask them for the password&lt;BR /&gt;&lt;BR /&gt;- if you *do* enter the password, don't do any searches, even for your own name&lt;BR /&gt;&lt;BR /&gt;- best not to touch the device at all, just make some suggestions (if you've already&lt;BR /&gt;asked if the staff want help) (Actually, I've found this last to be a cardinal rule for&lt;BR /&gt;assisting people use their systems or training. It may take a while, but just doing it&lt;BR /&gt;yourself usually leaves out some important part of the process.)&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;Dance like nobody's watching. Love like you've never been hurt.&lt;BR /&gt;Develop software like the end user has your home address.&lt;BR /&gt;&lt;A href="http://twitter.com/#!/RobertFischer/status/69117740622950400" target="_blank"&gt;http://twitter.com/#!/RobertFischer/status/69117740622950400&lt;/A&gt;&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
    <pubDate>Tue, 03 Mar 2020 20:15:53 GMT</pubDate>
    <dc:creator>rslade</dc:creator>
    <dc:date>2020-03-03T20:15:53Z</dc:date>
    <item>
      <title>No good deed goes unpunished</title>
      <link>https://community.isc2.org/t5/Tech-Talk/No-good-deed-goes-unpunished/m-p/33337#M2420</link>
      <description>&lt;P&gt;&lt;A href="https://www.cbc.ca/news/canada/hamilton/jackson-square-dental-hacking-1.5471071?fbclid=IwAR0Y3tH_n-DosPr8EPIibVF5BdecrZY5YJTTqH_IEy-lB9AEswRIo4WMQCI" target="_blank"&gt;https://www.cbc.ca/news/canada/hamilton/jackson-square-dental-hacking-1.5471071?fbclid=IwAR0Y3tH_n-DosPr8EPIibVF5BdecrZY5YJTTqH_IEy-lB9AEswRIo4WMQCI&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So he says he was only trying to help.......&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thoughts?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 19:52:44 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/No-good-deed-goes-unpunished/m-p/33337#M2420</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2020-03-03T19:52:44Z</dc:date>
    </item>
    <item>
      <title>Re: No good deed goes unpunished</title>
      <link>https://community.isc2.org/t5/Tech-Talk/No-good-deed-goes-unpunished/m-p/33340#M2422</link>
      <description>&amp;gt; dcontesti (Community Champion) posted a new topic in Tech Talk on 03-03-2020&lt;BR /&gt;&lt;BR /&gt;&amp;gt; &lt;A href="https://www.cbc.ca/news/canada/hamilton/jackson-square-dental-hacking-1.5471071" target="_blank"&gt;https://www.cbc.ca/news/canada/hamilton/jackson-square-dental-hacking-1.5471071&lt;/A&gt;?&lt;BR /&gt;&amp;gt; fbclid=IwAR0Y3tH_n-DosPr8EPIibVF5BdecrZY5YJTTqH_IEy-lB9AEswRIo4WMQCI &amp;nbsp; So he&lt;BR /&gt;&amp;gt; says he was only trying to help....... &amp;nbsp; Thoughts? &amp;nbsp; d &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Notes for those not wanting to be called hackers:&lt;BR /&gt;&lt;BR /&gt;- don't wait for all staff to exit the room and then intract with the device without&lt;BR /&gt;permission&lt;BR /&gt;&lt;BR /&gt;- if you find out where the password field is, just point it out to the staff and don't&lt;BR /&gt;ask them for the password&lt;BR /&gt;&lt;BR /&gt;- if you *do* enter the password, don't do any searches, even for your own name&lt;BR /&gt;&lt;BR /&gt;- best not to touch the device at all, just make some suggestions (if you've already&lt;BR /&gt;asked if the staff want help) (Actually, I've found this last to be a cardinal rule for&lt;BR /&gt;assisting people use their systems or training. It may take a while, but just doing it&lt;BR /&gt;yourself usually leaves out some important part of the process.)&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;Dance like nobody's watching. Love like you've never been hurt.&lt;BR /&gt;Develop software like the end user has your home address.&lt;BR /&gt;&lt;A href="http://twitter.com/#!/RobertFischer/status/69117740622950400" target="_blank"&gt;http://twitter.com/#!/RobertFischer/status/69117740622950400&lt;/A&gt;&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Tue, 03 Mar 2020 20:15:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/No-good-deed-goes-unpunished/m-p/33340#M2422</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2020-03-03T20:15:53Z</dc:date>
    </item>
    <item>
      <title>Re: No good deed goes unpunished</title>
      <link>https://community.isc2.org/t5/Tech-Talk/No-good-deed-goes-unpunished/m-p/33370#M2428</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/715155969"&gt;@dcontesti&lt;/a&gt;&amp;nbsp;&amp;nbsp; The golden rule:&amp;nbsp; Never touch the keyboard unless you want to own the situation, keep a forensic log with date/time of actions and have been given formal permission to carry the required tasks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Plus make sure you ask the requestor, whether they want to make a criminal investigation or charge, should the results of the review indicate there is sufficient evidence.&amp;nbsp; Make sure you get a written confirmation of their decision, do not depend on a verbal one, which can be rescinded.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are not a court recognised forensic investigator, walk away, do not touch the keyboard and tell the requester to seek a recognised qualified forensic investigator, who can take the case to court, if they wish.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;People, get fed up with this attitude, but it saves one a whole heap of trouble.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 23:16:52 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/No-good-deed-goes-unpunished/m-p/33370#M2428</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2020-03-04T23:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: No good deed goes unpunished</title>
      <link>https://community.isc2.org/t5/Tech-Talk/No-good-deed-goes-unpunished/m-p/33401#M2432</link>
      <description>&lt;P&gt;Kinda did it to himself.&amp;nbsp; By contacting the office, he created a formal record requiring a formal "management" response and a resultant change in demeanor from everyone in the office.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the US, medical privacy laws by default prohibit my dentist from even confirming that my spouse or adult child is a patient, despite the fact that we often arrive together. Even allowing the patient to see search results for their last name risks a privacy violation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not surprised the office is separating themselves as far as possible from the situation.&amp;nbsp; After all, in addition to patient-privacy, there probably were also some disciplinary actions that can neither be&amp;nbsp; confirmed nor denied.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 01:12:56 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/No-good-deed-goes-unpunished/m-p/33401#M2432</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2020-03-06T01:12:56Z</dc:date>
    </item>
  </channel>
</rss>

