<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-22055534</id><updated>2011-11-26T13:11:08.297+01:00</updated><title type='text'>Relax Security</title><subtitle type='html'>Freewheeling brainstorm around current internet security news, books, standards and concepts.

Information center for software security architects: Threat Modelling, threat modeling, security engineering, security principles, secure systems, PKI, smart card, Cryptography, Legal aspects of security, other interesting blogs: schneier, Cameron, Guttman,MS ACE Team, ...

Serious and less serious discussions around security and why it never works the way it should</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>45</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-22055534.post-5754208624017649746</id><published>2010-06-28T10:12:00.002+02:00</published><updated>2010-06-28T10:13:15.604+02:00</updated><title type='text'>Still alive and kicking</title><content type='html'>I will soon start to publish again some notes on security standards. Stay tuned&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-5754208624017649746?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/5754208624017649746/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=5754208624017649746' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/5754208624017649746'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/5754208624017649746'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2010/06/still-alive-and-kicking.html' title='Still alive and kicking'/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-7935887679056110825</id><published>2009-04-21T11:34:00.001+02:00</published><updated>2009-04-21T11:38:00.031+02:00</updated><title type='text'>Another "Advanced Message Queuing Protocol" AMQP site</title><content type='html'>www.amqp.org/&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-7935887679056110825?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/7935887679056110825/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=7935887679056110825' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/7935887679056110825'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/7935887679056110825'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2009/04/another-advanced-message-queuing.html' title='Another &quot;Advanced Message Queuing Protocol&quot; AMQP site'/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-403936742737036228</id><published>2009-04-21T11:24:00.001+02:00</published><updated>2009-04-21T11:26:19.834+02:00</updated><title type='text'>Interesting concept: Open reliable messasing in a Web 2.0 world</title><content type='html'>See http://www.imatix.com/for more information&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-403936742737036228?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/403936742737036228/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=403936742737036228' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/403936742737036228'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/403936742737036228'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2009/04/interesting-concept-open-reliable.html' title='Interesting concept: Open reliable messasing in a Web 2.0 world'/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-1675069643479185479</id><published>2007-07-27T14:36:00.001+02:00</published><updated>2007-07-27T14:38:16.018+02:00</updated><title type='text'>electronic Voting</title><content type='html'>Electronic voting is currently deploying at very high speed into both european and US countries, please share your views on this and the possible problems/advantages this could have for democracy.&lt;br /&gt;&lt;br /&gt;questions: should we leave our democratic controls to computers and the govs?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-1675069643479185479?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/1675069643479185479/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=1675069643479185479' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/1675069643479185479'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/1675069643479185479'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2007/07/electronic-voting.html' title='electronic Voting'/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-116306536482575664</id><published>2006-11-09T10:40:00.000+01:00</published><updated>2006-11-09T10:42:44.836+01:00</updated><title type='text'>Viruses - not only for Windows</title><content type='html'>Until now, most, if not all, only plagued the Windows world, leaving other systems' users, like MacOS X, with a warm, comfy feeling of security. They were wrong. Last week, a new proof-of-concept virus that infects MacOS X executables was &lt;a href="http://www.symantec.com/security_response/writeup.jsp?docid=2006-110217-1331-99"&gt;published&lt;/a&gt;. For those who want to get a peek on the technical details, see &lt;a href="http://vx.netlux.org/lib/vrg01.html"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Of course, it's only a proof-of-concept, never to be seen outside the labs, but it proves that a Mac virus is possible. In other, seemingly unrelated news, the &lt;a href="http://projects.info-pull.com/mokb/"&gt;Month of Kernel Bugs project&lt;/a&gt; has started. The first bug, published with proof-of-concept exploit code, attacks the wireless drivers of Mac systems.&lt;br /&gt;&lt;br /&gt;So there you have it: an attack vector, and infection techniques. It's only a matter of time before someone puts the two together. So take the initiative: keep your Mac updated, enable the firewall, and install anti-virus software as soon as possible. It's not too late yet, but it's time...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-116306536482575664?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/116306536482575664/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=116306536482575664' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/116306536482575664'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/116306536482575664'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/11/viruses-not-only-for-windows.html' title='Viruses - not only for Windows'/><author><name>McG</name><uri>http://www.blogger.com/profile/08629649882809500496</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-115627826941578335</id><published>2006-08-22T22:21:00.000+02:00</published><updated>2006-08-22T22:24:42.546+02:00</updated><title type='text'>Additional resources</title><content type='html'>&lt;a href="http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dnpag2/html/SecurityEngIndex.asp"&gt; Security Engineering &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://msdn.com/ThreatModeling/"&gt; Threat Modeling &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://msdn.com/SecurityGuidance/"&gt; Security Guidance Index &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-115627826941578335?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/115627826941578335/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=115627826941578335' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/115627826941578335'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/115627826941578335'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/08/additional-resources.html' title='Additional resources'/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-115506568885798184</id><published>2006-08-08T21:31:00.000+02:00</published><updated>2006-08-08T21:35:34.720+02:00</updated><title type='text'>Microsoft regulatory compliance planning guidance</title><content type='html'>For all those that have to deal with it...&lt;br /&gt;&lt;br /&gt;See &lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.microsoft.com/technet/security/topics/complianceandpolicies/compliance/rcguide/default.mspx?mfr=true"&gt; MS Regulatory guidance &lt;/a&gt; &lt;/li&gt;&lt;br /&gt;&lt;br /&gt;C U &lt;br /&gt;&lt;br /&gt;Freeman&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-115506568885798184?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/115506568885798184/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=115506568885798184' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/115506568885798184'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/115506568885798184'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/08/microsoft-regulatory-compliance.html' title='Microsoft regulatory compliance planning guidance'/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-115506492007879930</id><published>2006-08-08T21:20:00.000+02:00</published><updated>2006-08-08T21:22:00.090+02:00</updated><title type='text'>Vista Security Blog did open this month</title><content type='html'>Hi folks, &lt;br /&gt;&lt;br /&gt;just short notice to mention that a new security blog on vista security just opened this month...nice place to ask questions to MS Vista product management team about the effects of IE7+/Vista virtualization, UAC and the like...&lt;br /&gt;&lt;br /&gt;regards,&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-115506492007879930?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/115506492007879930/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=115506492007879930' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/115506492007879930'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/115506492007879930'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/08/vista-security-blog-did-open-this.html' title='Vista Security Blog did open this month'/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114977070020967745</id><published>2006-06-08T14:43:00.000+02:00</published><updated>2006-06-08T14:45:31.436+02:00</updated><title type='text'>Why phishing works</title><content type='html'>If you only have ten minutes of free time today, spend them reading "&lt;a href="http://people.deas.harvard.edu/~rachna/papers/why_phishing_works.pdf"&gt;Why phishing works&lt;/a&gt;" by Rachna Dhamija, J.D. Tygar and Marti Hearst. These researchers (from Harvard and Berkeley) have conducted an experimental study of people's reactions when faced with potentially fraudulent sites. The test subjects were showed 19 web sites, some of which being legit, while others were taken from phishing sites archives, and they were asked to distinguish which sites were legit or fake. To say that the results are appalling is an understatement.&lt;br /&gt;&lt;br /&gt;On average, 11.6 sites were correctly identified. The worst score was 6 correctly identified sites, and the best was 18. Nobody got full marks. Interviews with the test subjects showed that little to no attention is paid to the security icons and other visual clues given by the browser (padlock icons, color changes when viewing SSL sites, ...). Knowledge of X.509 certificates were of course nil, and unsurprisingly, dialog boxes warning that an SSL certificate did not match the web site (or was self-signed) were clicked through without being understood (when read). Another interesting fact is that two legitimate sites were incorrectly identified as fake in 50 percent of the cases or more.&lt;br /&gt;&lt;br /&gt;The test subjects were not computer illiterate. Some of them spent over 80 hours per week using computers for work or at home. They were just normal computer users, like your aunt Irma or your neighbour. The bottom line is that the current security user interface of browsers is not good. And no amount of pop up dialogs will make things better. There is a real need for a new paradigm in this field, and nobody's got the answer yet. So if you have anything to do with security software development or user interface, send this paper to your UI specialists. This will give them something to chew on.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114977070020967745?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114977070020967745/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114977070020967745' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114977070020967745'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114977070020967745'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/06/why-phishing-works.html' title='Why phishing works'/><author><name>McG</name><uri>http://www.blogger.com/profile/08629649882809500496</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114854890958840988</id><published>2006-05-25T11:21:00.000+02:00</published><updated>2006-05-25T11:21:49.600+02:00</updated><title type='text'></title><content type='html'>The Dark Arts are many, varied, ever-changing and eternal. Fighting them is like fighting a many-headed monster, which, each time a neck is severed, sprouts a head even fiercer and cleverer than before. You are fighting that which is unfixed, mutating, indestructible.&lt;br /&gt;&lt;br /&gt;"Your defences must therefore be as flexible and inventive as the Arts you seek to undo."&lt;br /&gt;    - Severus Snape (HBP9)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114854890958840988?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114854890958840988/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114854890958840988' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114854890958840988'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114854890958840988'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/05/dark-arts-are-many-varied-ever.html' title=''/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114641806439758187</id><published>2006-04-30T19:15:00.000+02:00</published><updated>2006-04-30T19:27:53.206+02:00</updated><title type='text'>New challenge for security components providers</title><content type='html'>Hi all, it's been quite a while, got a lot of work to do just like Y'All folks.&lt;br /&gt;&lt;br /&gt;I've come accross some of the papers of a quite good book: Security and Usability-Designing Secure Systems that people can use edited by Simson Garfinkel and Al.. &lt;br /&gt;&lt;br /&gt;Some of the papers are a little bit too academic to be really usable in real world, but at least they show the basic path to our new big challenge: how to make "security things" usable for mortal people while not annoying them with unwanted messages and avoiding them being tricked by "bad guys".&lt;br /&gt;&lt;br /&gt;I think that unless you make your UI business area knowledgeable, this can difficulty be done: to make this understandable to mortal guys, you must make sure that it relates to semantics of the business service they are interacting with. If you don't have this kind of semantic inclusion in user interface, the security system will have to rely on syntaxic concepts that are difficulty "grasped" or can difficulty be verified by the users: URLs with cabalistic signs in it,....&lt;br /&gt;&lt;br /&gt;Just as general purposes application were too tied to the underlying technical infrastructure and had to make huge efforts on usability (remember the editor of the early 90's or the command lines of the 80's ?), secure systems will have to do the same kind of efforts during the coming years.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114641806439758187?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114641806439758187/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114641806439758187' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114641806439758187'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114641806439758187'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/04/new-challenge-for-security-components.html' title='New challenge for security components providers'/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114492885671949671</id><published>2006-04-13T13:44:00.000+02:00</published><updated>2006-04-13T15:12:35.893+02:00</updated><title type='text'>Kernel Mode IRC Bots and of the futility to eradicate malware</title><content type='html'>IRC Bots are a kind of malware that manage to&lt;br /&gt;get installed on your system (installation&lt;br /&gt;vectors range from exploiting browser&lt;br /&gt;vulnerabilities to automatically install, to &lt;br /&gt;ndocumented add-ons to those nifty screensavers&lt;br /&gt;your kids love so much). Once installed, the&lt;br /&gt;malware connects to an IRC channel (IRC is one&lt;br /&gt;of the oldest forms of instant discussion forum),&lt;br /&gt;and waits for orders. Depending on the orders,&lt;br /&gt;the malware then tries to propagate, attack&lt;br /&gt;other systems, relay SPAM, ...&lt;br /&gt;&lt;br /&gt;Until now, these IRC bots runned in user space,&lt;br /&gt;making their detection and eradication&lt;br /&gt;possible. But a researcher has just published&lt;br /&gt;the sources of a proof-of-concept IRC bot that&lt;br /&gt;runs in kernel space [&lt;a href="http://tibbar.blog.co.uk/2006/04/06/kernel_mode_IRCbot~708256"&gt;1&lt;/a&gt;] &amp; [&lt;a href="http://www.rootkit.com/newsread.php?newsid=416"&gt;2&lt;/a&gt;]. What that means&lt;br /&gt;is that, should that kind of bot become widespread,&lt;br /&gt;detection and eradication will become impossible&lt;br /&gt;once the malware is installed.&lt;br /&gt;&lt;br /&gt;Is that news? Well, no. I strongly believe that,&lt;br /&gt;once a system is compromised, the only safe&lt;br /&gt;option is to nuke it from Moon high, and&lt;br /&gt;re-install from a clean image. Even a Microsoft&lt;br /&gt;security official admitted so in &lt;a href="http://www.eweek.com/article2/0,1759,1945782,00.asp"&gt;a recent interview&lt;/a&gt;.&lt;br /&gt;Why is it so? Because there is no way to be&lt;br /&gt;completely sure that your anti-virus has&lt;br /&gt;identified the exact variant of the malware,&lt;br /&gt;and that it has subsequently removed all&lt;br /&gt;instances of infection, all registry entries&lt;br /&gt;or hidden files. And this is not just for&lt;br /&gt;Windows systems: once malware gets installed&lt;br /&gt;on your system, it's not your system anymore.&lt;br /&gt;&lt;br /&gt;This does not mean that anti-viruses are not&lt;br /&gt;necessary: they are just limited in what they can do,&lt;br /&gt;and are just one layer of protection that aims at&lt;br /&gt;preventing malware from installing on your systems&lt;br /&gt;in the first place. So d'ont get rid of them, but&lt;br /&gt;keep them well-updated!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114492885671949671?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114492885671949671/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114492885671949671' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114492885671949671'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114492885671949671'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/04/kernel-mode-irc-bots-and-of-futility.html' title='Kernel Mode IRC Bots and of the futility to eradicate malware'/><author><name>McG</name><uri>http://www.blogger.com/profile/08629649882809500496</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114462873217775871</id><published>2006-04-10T02:22:00.000+02:00</published><updated>2006-04-10T02:25:32.176+02:00</updated><title type='text'>German Postbank Uses e-Signatures to Curb Phishing</title><content type='html'>&lt;a href="http://www.theregister.co.uk/2006/04/07/postbank_curbs_phishing/"&gt;The Register reported&lt;/a&gt; that the German bank Postbank is going to introduce electronic signatures to all email correspondence with its customers in an attempt to curb &lt;a href="http://www.arraydev.com/commerce/JIBC/2005-02/jibc_phishing.HTM"&gt;phishing&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Related posts and articles:&lt;br /&gt;&lt;a href="http://lawjustice.blogspot.com/2005/09/security-as-legal-obligation-sarbanes.html"&gt;Security as a legal obligation. Sarbanes Oxley in the European Union&lt;/a&gt;&lt;br /&gt;&lt;a href="http://blacksun06.blogspot.com/2006/03/dutch-consumer-organisation-wants.html"&gt;Dutch Consumer Organisation Wants Embedded Security in Internet Products and Services&lt;/a&gt;&lt;br /&gt;&lt;a href="http://blacksun06.blogspot.com/2006/03/european-isps-microsoft-and-interpol.html"&gt;European ISPs, Microsoft and Interpol Will Cooperate &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114462873217775871?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114462873217775871/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114462873217775871' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114462873217775871'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114462873217775871'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/04/german-postbank-uses-e-signatures-to.html' title='German Postbank Uses e-Signatures to Curb Phishing'/><author><name>Edwin Jacobs</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114462853271576002</id><published>2006-04-10T02:19:00.000+02:00</published><updated>2006-04-10T02:22:12.873+02:00</updated><title type='text'>Dutch Army Captain Not Prosecuted for Losing USB-Stick</title><content type='html'>A Dutch army captain will not be prosecuted for leaving his USB-stick in a rental car.&lt;br /&gt;More on  &lt;a href="http://www.rechtennieuws.nl/forum/portal/title/Verdachte+militair+in+zaak+verloren+USB-stick+niet+vervolgd/article/7613/?sid=360a61db966d7b24753144159beaa45d"&gt;Rechtennieuws.nl&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114462853271576002?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114462853271576002/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114462853271576002' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114462853271576002'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114462853271576002'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/04/dutch-army-captain-not-prosecuted-for.html' title='Dutch Army Captain Not Prosecuted for Losing USB-Stick'/><author><name>Edwin Jacobs</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114431222001105905</id><published>2006-04-06T10:26:00.000+02:00</published><updated>2006-04-06T10:30:20.026+02:00</updated><title type='text'>Police password database exposed</title><content type='html'>The database of people who had signed up to receive&lt;br /&gt;New South Wales (Australia) Police media releases&lt;br /&gt;has been unwittingly &lt;a href="http://smh.com.au/articles/2006/04/05/1143916569155.html"&gt;exposed on the internet this week&lt;/a&gt;.&lt;br /&gt;This database contained among others the names,&lt;br /&gt;addresses, and passwords of subscribers. This incident&lt;br /&gt;highlights a lot of points that need to be taken care of&lt;br /&gt;when writing and deploying web applications:&lt;br /&gt;&lt;br /&gt;1. The passwords were stored in plain text. This shouldn't&lt;br /&gt;ever, ever happen. Passwords are secrets, and must&lt;br /&gt;remain so! If your application needs passwords, don't&lt;br /&gt;store them, but salted hashes.&lt;br /&gt;&lt;br /&gt;2. The passwords were mostly poorly chose: passwords&lt;br /&gt;like "enforcer" or "diaryy" or just the same as the&lt;br /&gt;username were common. Your application should&lt;br /&gt;prevent users to choose poor passwords. Libraries like&lt;br /&gt;&lt;a href="http://sourceforge.net/projects/cracklib"&gt;cracklib&lt;/a&gt; can be used to detect weak passwords and&lt;br /&gt;eliminate the "low hanging fruits".&lt;br /&gt;&lt;br /&gt;3. The application was probably not meant to be&lt;br /&gt;accessible by everybody. It was found just by following&lt;br /&gt;links present in other pages. This is yet another failed&lt;br /&gt;attempt at security by obscurity. This kind of "protection"&lt;br /&gt;does not work well, and can only be used as one layer,&lt;br /&gt;after all the other protection layers are in place.&lt;br /&gt;&lt;br /&gt;4. Google indexed it all. The original web page has been&lt;br /&gt;pulled off, but all the information is still available (at the&lt;br /&gt;time of this writing) by putting the right query in&lt;br /&gt;Google, and asking to view the cached pages. Google and&lt;br /&gt;other search engines happily follow any link they can&lt;br /&gt;find, including from directory indexes if they can get&lt;br /&gt;access to them. First, directory listing should not be&lt;br /&gt;allowed. Second, maybe a robots.txt file will prevent&lt;br /&gt;Google and other "well-behaving" web spiders from&lt;br /&gt;accessing your data. But it will above all tell&lt;br /&gt;"mischievous" web spiders where the juicy data is. If some&lt;br /&gt;information should not be accessible by everybody, protect&lt;br /&gt;it with adequate access control means, like a .htaccess file.&lt;br /&gt;&lt;br /&gt;5. Should you get hit with such problems, Google's&lt;br /&gt;procedures to remove content from its caches can be found&lt;br /&gt;&lt;a href="http://www.google.com/webmasters/remove.html"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114431222001105905?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114431222001105905/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114431222001105905' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114431222001105905'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114431222001105905'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/04/police-password-database-exposed.html' title='Police password database exposed'/><author><name>McG</name><uri>http://www.blogger.com/profile/08629649882809500496</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114370799012547878</id><published>2006-03-30T10:33:00.000+02:00</published><updated>2006-03-30T10:39:50.136+02:00</updated><title type='text'>New Internet Explorer Vulnerability</title><content type='html'>&lt;pre&gt;Late last week, a vulnerability in Internet Explorer&lt;br /&gt;was disclosed: when an html tag contains a great number&lt;br /&gt;of JavaScript event handlers (like 'onClick') Internet&lt;br /&gt;Explorer crashed. It was at first thought that the&lt;br /&gt;result was only a denial of service, but a code&lt;br /&gt;execution exploit appeared after a &lt;a href="http://www.microsoft.com/technet/security/advisory/917077.mspx"&gt;few days&lt;/a&gt;. It looks&lt;br /&gt;like history is hiccupping, because this scenario is&lt;br /&gt;exactly the same as with the &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms06-001.mspx"&gt;Graphics Rendering Engine&lt;br /&gt;vulnerability&lt;/a&gt; at the beginning of the year.&lt;br /&gt;&lt;br /&gt;Just like in January, it looks like the vulnerabilty was&lt;br /&gt;know by the underground for a while, and that it was&lt;br /&gt;(and is still) exploited, by planting malicious pages on&lt;br /&gt;hacked web sites. And again just like in January, third&lt;br /&gt;parties have provided patches for the vulnerability, that&lt;br /&gt;you can install while waiting for Microsoft's official&lt;br /&gt;update (&lt;a href="http://www.eeye.com/html/research/alerts/AL20060324.html"&gt;here&lt;/a&gt; and &lt;a href="http://www.determina.com/security_center/security_advisories/securityadvisory_march272006_1.asp"&gt;here&lt;/a&gt;). The difference is that now there&lt;br /&gt;are two independant patches, instead of just one.&lt;br /&gt;&lt;br /&gt;Now the 100€ question is: should you roll-up those third-&lt;br /&gt;party patches? The short answer is obviously "It depends".&lt;br /&gt;The long answer is of course more convoluted, because&lt;br /&gt;there are a lot of factors to take into account. First,&lt;br /&gt;there is the severity of the vulnerability. Contrary to&lt;br /&gt;the January vulnerability, exploiting this bug doesn't&lt;br /&gt;allow the attacker to execute code with SYSTEM privileges,&lt;br /&gt;but with the privileges of the current user. What are the&lt;br /&gt;privileges of your users? A lot of them are always logged&lt;br /&gt;in with administrator privileges, which gives full&lt;br /&gt;control over the system. So you have to know what are the&lt;br /&gt;commonly used privileges of your users.&lt;br /&gt;&lt;br /&gt;The next factor is: do you trust the people who have&lt;br /&gt;produced the patches? Won't they use the gullibility of&lt;br /&gt;people to make them install their own kind of malware? One&lt;br /&gt;of the patches was developped and published by eEye, which&lt;br /&gt;is a rather well-known security services company, that&lt;br /&gt;employs some very competent people. The other patch was&lt;br /&gt;published by another security services company, though not&lt;br /&gt;as famous. eEye provides source code for their patch,&lt;br /&gt;but how can you be sure that the executable is the product&lt;br /&gt;of the source code you have downloaded? All in all, just&lt;br /&gt;this factor is an interesting dilemma, and your security&lt;br /&gt;policies should give you a good hint for an answer.&lt;br /&gt;&lt;br /&gt;Finally, there is the question of your environment. These&lt;br /&gt;third-party patches have probably been tested as&lt;br /&gt;thoroughly as possible. But do these companies have access&lt;br /&gt;to all the vulnerable versions of Internet Explorer on all&lt;br /&gt;Windows platforms? Probably. In all languages? Maybe. Did&lt;br /&gt;they test them all? Probably not, because that's exactly&lt;br /&gt;what takes the most time to Microsoft: testing the patch&lt;br /&gt;on all combinations of their software. And also in your&lt;br /&gt;environment comes the question of the number of systems to&lt;br /&gt;patch (and from which the patch will have to be&lt;br /&gt;uninstalled when Microsoft publishes an official update),&lt;br /&gt;and the interaction with specific software you may be using.&lt;br /&gt;&lt;br /&gt;So, let's wrap it all up: should you roll-up these third-&lt;br /&gt;party patches? It depends. But should you decide to do it,&lt;br /&gt;first make sure you test the patch of your choosing on&lt;br /&gt;production-like systems before, and test them thoroughly.&lt;br /&gt;And maybe when your tests are done, Microsoft will have&lt;br /&gt;published their own, official and QA-tested patch...&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114370799012547878?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114370799012547878/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114370799012547878' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114370799012547878'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114370799012547878'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/03/new-internet-explorer-vulnerability.html' title='New Internet Explorer Vulnerability'/><author><name>McG</name><uri>http://www.blogger.com/profile/08629649882809500496</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114370155774053875</id><published>2006-03-30T08:51:00.000+02:00</published><updated>2006-03-30T08:52:37.753+02:00</updated><title type='text'>No comments</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/blogger/4444/2238/1600/security.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://photos1.blogger.com/blogger/4444/2238/320/security.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114370155774053875?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114370155774053875/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114370155774053875' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114370155774053875'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114370155774053875'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/03/no-comments.html' title='No comments'/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114366734051224844</id><published>2006-03-29T23:17:00.000+02:00</published><updated>2006-03-29T23:22:20.526+02:00</updated><title type='text'>Prometheus was not a fool...he is right</title><content type='html'>More information click on the "prometheus link".&lt;br /&gt;&lt;br /&gt;Prometheus stole fire from Zeus and gave it to the primitive mortals on the earth. Zeus did not punish Prometheus alone, he punished the entire world for the effrontery of this rebel god.&lt;br /&gt;&lt;br /&gt;[...] &lt;br /&gt;&lt;br /&gt;Zeus had many plans for the reshaping of creation. Zeus said that knowledge and divine gifts would only bring misery to the mortals and he insisted that Prometheus not interfere with his plans.&lt;br /&gt;&lt;br /&gt;Dispite Zeus’ warning, Prometheus took pity on the primitive mortals and again, he deceived Zeus. &lt;br /&gt;&lt;br /&gt;Prometheus gave the mortals all sorts of gifts: brickwork, woodworking, telling the seasons by the stars, numbers, the alphabet (for remembering things), yoked oxen, carriages, saddles, ships and sails. He also gave other gifts: healing drugs, seercraft, signs in the sky, the mining of precious metals, animal sacrifice and all art.&lt;br /&gt;&lt;br /&gt;The gift of divine fire unleashed a flood of inventiveness, productivity and, most of all, respect for the immortal gods in the rapidly developing mortals. Within no time (by Immortal standards), culture, art, and literacy permeated the land around Mount Olympos (Olympus). &lt;br /&gt;&lt;br /&gt;When Zeus realized the deception that Prometheus had fostered, he was furious. &lt;br /&gt;&lt;br /&gt;He had Hephaistos (Hephaestus) shackle Prometheus to the side of a crag, high in the Caucasus mountains. There Prometheus would hang until the fury of Zeus subsided.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114366734051224844?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114366734051224844/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114366734051224844' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114366734051224844'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114366734051224844'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/03/prometheus-was-not-foolhe-is-right.html' title='Prometheus was not a fool...he is right'/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114366642883631681</id><published>2006-03-29T22:46:00.000+02:00</published><updated>2006-03-29T23:07:08.856+02:00</updated><title type='text'>prometheus steal fire to bring it to men</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/blogger/4444/2238/1600/prometheus.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://photos1.blogger.com/blogger/4444/2238/320/prometheus.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114366642883631681?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114366642883631681/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114366642883631681' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114366642883631681'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114366642883631681'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/03/prometheus-steal-fire-to-bring-it-to.html' title='prometheus steal fire to bring it to men'/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114366514021705915</id><published>2006-03-29T22:44:00.000+02:00</published><updated>2006-03-29T22:45:40.230+02:00</updated><title type='text'>The Blacksun</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://photos1.blogger.com/blogger/4444/2238/1600/The_Black_Sun.1.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;" src="http://photos1.blogger.com/blogger/4444/2238/320/The_Black_Sun.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114366514021705915?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114366514021705915/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114366514021705915' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114366514021705915'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114366514021705915'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/03/blacksun.html' title='The Blacksun'/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114324776587160569</id><published>2006-03-25T01:45:00.000+01:00</published><updated>2006-03-25T01:49:25.883+01:00</updated><title type='text'>European ISPs, Microsoft and Interpol Will Cooperate</title><content type='html'>On line fraud is increasing and the public authorities can't always cope with it. &lt;a href="http://www.interpol.int/Public/TechnologyCrime/default.asp"&gt;Interpol &lt;/a&gt; and the &lt;a href="http://www.euroispa.org/"&gt;European ISPs&lt;/a&gt; (press release in &lt;a href="http://www.euroispa.org/docs/060320_antiphishevent.pdf"&gt;pdf&lt;/a&gt;) and Microsoft (&lt;a href="http://www.microsoft.com/emea/presscentre/topstories/HollowayQA_2032006.mspx"&gt;Microsoft EMEA press release) &lt;/a&gt; announced cooperation in order to combat on line fraud. Their first goal is to reduce phishing.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114324776587160569?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114324776587160569/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114324776587160569' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114324776587160569'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114324776587160569'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/03/european-isps-microsoft-and-interpol.html' title='European ISPs, Microsoft and Interpol Will Cooperate'/><author><name>Edwin Jacobs</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114310979126837658</id><published>2006-03-23T11:26:00.000+01:00</published><updated>2006-03-23T11:30:55.863+01:00</updated><title type='text'>Skype reverse-engineered</title><content type='html'>Researchers have presented a very interesting paper&lt;br /&gt;during the last BlackHat Europe, about &lt;a href="http://www.secdev.org/conf/skype_BHEU06.handout.pdf"&gt;reverse&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.secdev.org/conf/skype_BHEU06.handout.pdf"&gt;engineering Skype&lt;/a&gt;. For those who have lived in a&lt;br /&gt;rocky place far from any network connection during&lt;br /&gt;the last two years, Skype is a Voice over IP application&lt;br /&gt;that can be used for free to communicate between&lt;br /&gt;users of the application. Paid services exist, that allow&lt;br /&gt;people to make calls towards non IP telphone networks.&lt;br /&gt;&lt;br /&gt;Skype works using peer-to-peer technology, using&lt;br /&gt;people's systems and network connections to route calls&lt;br /&gt;within the Skype network, and make a lot of effort to&lt;br /&gt;work through almost any firewall. For systems and&lt;br /&gt;network security administrators, this is worrying. First,&lt;br /&gt;because it turns your networks and systems in call&lt;br /&gt;routers and telephone lines, which may create bandwidth&lt;br /&gt;problems, software instability issues, and everything that&lt;br /&gt;goes in turning an ordinary station into a server.&lt;br /&gt;Two, because telephone calls originating from your&lt;br /&gt;network, maybe holding confidential information, pass&lt;br /&gt;through systems you don't control, and that you can't have&lt;br /&gt;any guarantee on - unlike a phone company's network,&lt;br /&gt;with whom you have a contract. Finally, those same calls&lt;br /&gt;are passed using closed software, over undisclosed,&lt;br /&gt;proprietary protocols.&lt;br /&gt;&lt;br /&gt;That's the reason some people have started to try and&lt;br /&gt;reverse-engineer the program and the protocols it uses, in&lt;br /&gt;order to understand whether call privacy can be ensured,&lt;br /&gt;and provide information on how to block Skype traffic&lt;br /&gt;when it's against your corporate policies. That effort has&lt;br /&gt;been surprisingly difficult. Not only are the protocols&lt;br /&gt;encrypted and proprietary - that was already known - but&lt;br /&gt;the program itself goes to great lengths to prevent reverse-&lt;br /&gt;engineering. The researchers have had to peel layers upon&lt;br /&gt;layers of protection, some very elaborate. During the&lt;br /&gt;process, they also found some pretty serious&lt;br /&gt;vulnerabilities, which could be exploited tu turn the Skype&lt;br /&gt;network in 'the biggest botnet ever' (sic).&lt;br /&gt;&lt;br /&gt;What do your policies say about Skype usage?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114310979126837658?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114310979126837658/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114310979126837658' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114310979126837658'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114310979126837658'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/03/skype-reverse-engineered.html' title='Skype reverse-engineered'/><author><name>McG</name><uri>http://www.blogger.com/profile/08629649882809500496</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114264598804602592</id><published>2006-03-18T02:39:00.000+01:00</published><updated>2006-03-18T02:39:48.056+01:00</updated><title type='text'>Biometrics Are Not Reliable, Says EU Data Protection Expert</title><content type='html'>&lt;a href="http://en.wikipedia.org/wiki/Biometrics"&gt;Biometrics&lt;/a&gt; are not reliable, says EU data protecton expert (source: &lt;a href="http://euobserver.com/22/21139"&gt;EUobserver)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;An EU data protection supervisor, &lt;a href="http://www.edps.eu.int/01_en_sub_membres2.htm"&gt;Peter Hustinx&lt;/a&gt;, has criticised the use of biometrics as unique identifiers for European citizens, saying fingerprint or DNA identifications can be inaccurate. He leads an &lt;a href="http://www.edps.eu.int/01_en_presentation.htm"&gt;independent body that monitors EU data protection&lt;/a&gt;. He says that recent proposals to interconnect important EU data bases - notably to identify suspects in the fight against terrorism - raises a number of questions in relation to data protection.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114264598804602592?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114264598804602592/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114264598804602592' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114264598804602592'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114264598804602592'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/03/biometrics-are-not-reliable-says-eu.html' title='Biometrics Are Not Reliable, Says EU Data Protection Expert'/><author><name>Edwin Jacobs</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114247201588944629</id><published>2006-03-16T02:19:00.000+01:00</published><updated>2006-03-16T02:20:15.890+01:00</updated><title type='text'>IBM B2B Security Survey: German Companies Take Cybercrime Very Seriously</title><content type='html'>According to a &lt;a href="http://www.ibm.com/news/de/de/2006/03/13.html"&gt;recent IBM B2B Security Survey&lt;/a&gt;, 63 percent of IT managers in German companies think that cybercrime is a bigger threat to their company as other crimes. On an international level this percentage is estimated at 40 percent of all companies.&lt;br /&gt;&lt;br /&gt;Some background reading on cybercrime:&lt;br /&gt;&lt;br /&gt;European Network and Information Security Agency, &lt;a href="http://www.enisa.eu.int/index_en.htm"&gt;ENISA&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.euractiv.com/Article?tcmuri=tcm:29-117465-16&amp;type=LinksDossier"&gt;Cybercrime file of EurActiv&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.usdoj.gov/criminal/cybercrime/"&gt;Cybercrime section of the US Department of Justice&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114247201588944629?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114247201588944629/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114247201588944629' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114247201588944629'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114247201588944629'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/03/ibm-b2b-security-survey-german.html' title='IBM B2B Security Survey: German Companies Take Cybercrime Very Seriously'/><author><name>Edwin Jacobs</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114247195214089579</id><published>2006-03-16T02:17:00.000+01:00</published><updated>2006-03-16T02:19:12.156+01:00</updated><title type='text'>New RFID (Radio Frequency Identification Devices) Policy for Europe</title><content type='html'>The EU has a new &lt;a class="blines3" title="Link outside of this blog" href="http://europa.eu.int/information_society/policy/rfid/index_en.htm" target="_blank"&gt;RFID (Radio Frequency Identification Devices) Policy for Europe&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Some background reading about RFID:&lt;br /&gt;&lt;br /&gt;For a critical comment see: &lt;a title="Site: The Brussels Journal - Dutch, English, Quotes, Odds &amp; Ends, Radio Free Brussels" href="http://www.brusselsjournal.com/node/904" target="_blank"&gt;RFID: Europe Wants to Tag You&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Hartmut Pohl, Professor für Informationssicherheit an der Fachhochschule Bonn-Rhein-Sieg is not against RFID points at some privacy issues: "&lt;a href="http://www.welt.de/data/2006/03/14/859398.html"&gt;Keine Anonymität mehr mit RFID-Chips&lt;/a&gt;" (in German in the newspaper Die Welt).&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.rfidjournal.com/"&gt;RFID Journal&lt;/a&gt;&lt;a href="http://en.wikipedia.org/wiki/RFID"&gt;Wikipedia on RFID&lt;/a&gt;, with RFID Legislation, Regulation and standardization&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.technewsworld.com/story/40203.html"&gt;Legal Implications of Using RFID Highlighted&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.vnunet.com/vnunet/news/2149942/legal-worries-hold-back-rfid"&gt;Legal fears hold back RFID adoption&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.theregister.co.uk/2006/03/15/rfid_tags_infected_by_virus/"&gt;RFID tags can be infected with a virus&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114247195214089579?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114247195214089579/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114247195214089579' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114247195214089579'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114247195214089579'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/03/new-rfid-radio-frequency.html' title='New RFID (Radio Frequency Identification Devices) Policy for Europe'/><author><name>Edwin Jacobs</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114236817495010626</id><published>2006-03-14T21:16:00.000+01:00</published><updated>2006-03-16T11:16:56.233+01:00</updated><title type='text'>MS ACE team</title><content type='html'>Microsoft ACE team did make available their new threat modelling tools allowing development team to enhance the global security of their application.&lt;br /&gt;&lt;br /&gt;More information on &lt;a href="http://"&gt;http://blogs.msdn.com/threatmodeling/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;a very good tool in my opinion worthwile taking a serious look at it.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114236817495010626?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114236817495010626/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114236817495010626' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114236817495010626'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114236817495010626'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/03/ms-ace-team.html' title='MS ACE team'/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114168715168279442</id><published>2006-03-07T00:17:00.000+01:00</published><updated>2006-03-07T00:19:11.826+01:00</updated><title type='text'>The Future of Privacy</title><content type='html'>Bruce Schneier published a very interesting essay on his blog "&lt;a href="http://www.schneier.com/blog/archives/2006/03/the_future_of_p.html"&gt;The Future of Privacy&lt;/a&gt;" where he also refers to &lt;a href="http://europa.eu.int/comm/justice_home/fsj/privacy/index_en.htm"&gt;privacy legislation in the European Union&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;"(...) We're never going to stop the march of technology, but we can enact legislation to protect our privacy: comprehensive laws regulating what can be done with personal information about us, and more privacy protection from the police. Today, personal information about you is not yours; it's owned by the collector. There are laws protecting specific pieces of personal data -- videotape rental records, health care information -- but nothing like the broad privacy protection laws you find in European countries. That's really the only solution; leaving the market to sort this out will result in even more invasive wholesale surveillance. (...)"&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Read the &lt;a href="http://www.schneier.com/blog/archives/2006/03/the_future_of_p.html"&gt;whole thing here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114168715168279442?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114168715168279442/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114168715168279442' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114168715168279442'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114168715168279442'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/03/future-of-privacy.html' title='The Future of Privacy'/><author><name>Edwin Jacobs</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114133358806703754</id><published>2006-03-02T22:02:00.000+01:00</published><updated>2006-03-02T22:06:28.083+01:00</updated><title type='text'>Dutch Consumer Organisation Wants Embedded Security in Internet Products and Services</title><content type='html'>The Dutch consumer organisation (&lt;a href="http://www.consumentenbond.nl/"&gt;Consumentenbond&lt;/a&gt;) started a &lt;a href="http://www.consumentenbond.nl/acties/3708816/3708924/?ticket=nietlid"&gt;petition&lt;/a&gt; on its website demanding that computer suppliers, Internet providers and companies providing services on the internet must offer secure products and services. They advocate that such suppliers and providers offer embedded security into their products and services, just like car manufacturers offer safe cars and microwave manufacturers sell safe ovens.&lt;br /&gt;&lt;br /&gt;The Dutch consumer organisation argues that consumers increasingly make use of their computer and the Internet for e-banking, e-mail, and e-commerce. However, it seems that their personal data are relatively easy to abuse. Security software (virus scanner, spywarefilter, firewall) is often too complicated for an average consumer. A security software that is “ok” one year isn’t “ok” anymore the next year. According to the consumer organisation this means that the consumer would constantly have to change his security software. They agree that consumers still need to take care of &lt;a href="http://www.webwereld.nl/ref/newsletter/40056"&gt;safe behaviour on the Internet and maintenance&lt;/a&gt; of their security software.&lt;br /&gt;&lt;br /&gt;I think that the discussion about what can be “reasonably expected” from service providers as "good housefather" (“&lt;a href="http://www.financialcryptography.com/mt/archives/000563.html"&gt;bonus pater familias&lt;/a&gt;”), but equally also from customers, is becoming increasingly important. Security is &lt;a href="http://lawjustice.blogspot.com/2005/09/security-as-legal-obligation-sarbanes.html"&gt;not a new legal obligation&lt;/a&gt;: it’s already a legal issue for all EU companies since the early nineties; of course a lot depends on the applicable legislation.&lt;br /&gt;&lt;br /&gt;On the one hand the knowledge of the average consumer about computers and the Internet is increasing. Therefore one can also reasonably expect an increased knowledge of the security issues involved, such as &lt;a href="http://en.wikipedia.org/wiki/Spam_%28electronic%29"&gt;spam&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Hacker"&gt;hacking&lt;/a&gt;, &lt;a href="http://www.arraydev.com/commerce/jibc/2005-02/jibc_phishing.HTM"&gt;phishing&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Pharming"&gt;pharming&lt;/a&gt;, &lt;a href="http://en.wikipedia.org/wiki/Computer_virus"&gt;virus&lt;/a&gt; etc. Private companies such as &lt;a href="http://antivirus.about.com/od/emailscams/ss/phishing_2.htm"&gt;banks&lt;/a&gt;, &lt;a href="http://www.isabel.be/communication/survey/index.php?sid=4"&gt;e-banking&lt;/a&gt; and &lt;a href="http://pages.ebay.com/securitycenter/stopping_online_viruses.html"&gt;e-business&lt;/a&gt; providers are constantly warning their customers for security issues. &lt;a href="http://www.ftc.gov/infosecurity/"&gt;Governments&lt;/a&gt; are also publicly warning for Internet related security issues. Just like the average consumer knows he has to fasten his seat belt when driving his car and knows the “don’t try this at home” stuff, I can imagine that almost every “average consumer” receives spam and phishing e-mails in his mailbox but knows by now that he shouldn’t click on every pop-up, hyperlink or attachment he receives.&lt;br /&gt;&lt;br /&gt;On the other hand the security attacks become &lt;a href="http://www.redherring.com/Article.aspx?a=15013&amp;hed=Top+Security+Trends+for+2006"&gt;more and more sophisticated&lt;/a&gt; and are - as far as I can understand it - sometimes even difficult to spot for professional IT and security people, and the average user is not an IT or security expert. There is also an increase in &lt;a href="http://www.theregister.co.uk/2006/02/27/defacement_report_2005/"&gt;politically motivated attacks&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;So the question is: where is the balance between the “reasonable obligations” of the service/product provider on the one hand and “reasonable obligations” of the user on the other hand?&lt;br /&gt;&lt;br /&gt;I believe we can expect from an average user that he knows the difference between leaded and unleaded gasoline, but can we expect that he really grasps the impact on his engine of the difference between 95 octane and 98 octane? The average user, consumer or professional user, does not want to think about security or technology: what really counts is &lt;a href="http://www.acm.org/ubiquity/views/v7i07_pfeiffer.html"&gt;what the technology does for him&lt;/a&gt;. However, this average user can’t be regarded as a totally security ignorant user either. The “reasonable security awareness” of the average user is increasing, and it should by now. He should understand that he needs a regular update of his security software, just like he goes to his garage to have his car serviced, and he should take care of safe behaviour on the Internet, just like he tries to avoid traffic accidents.&lt;br /&gt;&lt;br /&gt;When there is a breach of security and this breach is the cause of damage for a user, the matter shall be decided on a case-by-case basis. Generally speaking and making abstraction from certain country or sector specific legislation, both service provider and user (consumer and professional user) can then be judged with the concept of “bonus pater familias” in mind. The case doesn’t necessarily have to be tried in court but can also be solved by &lt;a href="http://mediationblog.blogspot.com/"&gt;mediation&lt;/a&gt; or other &lt;a href="http://europa.eu.int/comm/justice_home/ejn/adr/adr_gen_en.htm"&gt;alternative dispute resolution&lt;/a&gt; methods.&lt;br /&gt;&lt;br /&gt;I am not an IT-security expert but I am confident that the &lt;a href="http://www.tcsdaily.com/article.aspx?id=100103D"&gt;private sector will do a good job&lt;/a&gt; of finding a way to reduce security issues. I prefer this instead of more government regulation.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114133358806703754?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114133358806703754/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114133358806703754' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114133358806703754'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114133358806703754'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/03/dutch-consumer-organisation-wants.html' title='Dutch Consumer Organisation Wants Embedded Security in Internet Products and Services'/><author><name>Edwin Jacobs</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114133271875124526</id><published>2006-03-02T21:50:00.000+01:00</published><updated>2006-03-02T21:51:58.763+01:00</updated><title type='text'>AOL Sues Over Identity Thefts, Uses New Law</title><content type='html'>&lt;a href="http://today.reuters.com/news/newsArticle.aspx?&amp;storyID=2006-02-28T103624Z_01_N27331008_RTRUKOC_0_US-MEDIA-AOL-LAWSUIT.xml"&gt;Reuters&lt;/a&gt; : AOL sues over identity thefts, uses new law.&lt;br /&gt;Related: &lt;a href="http://discover.aol.com/aolfeatures.adp?d1=0&amp;amp;d2=8"&gt;America On Line Safety and Security Center&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114133271875124526?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114133271875124526/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114133271875124526' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114133271875124526'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114133271875124526'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/03/aol-sues-over-identity-thefts-uses-new.html' title='AOL Sues Over Identity Thefts, Uses New Law'/><author><name>Edwin Jacobs</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114104533294575723</id><published>2006-02-27T14:01:00.000+01:00</published><updated>2006-02-27T14:02:12.963+01:00</updated><title type='text'>US Federal Trade Commission Settles with CardSystems over Data Breach</title><content type='html'>In September &lt;a href="http://lawjustice.blogspot.com/2005/09/credit-card-companies-need-not-notify.html"&gt;last year a California judge ruled&lt;/a&gt; that &lt;a href="http://www.visa.com/globalgateway/gg_selectcountry.html?retcountry=1"&gt;Visa&lt;/a&gt; and &lt;a href="http://www.mastercard.com/"&gt;MasterCard&lt;/a&gt; did not have to notify individual consumers whose account data was stolen by a hacker in a mass &lt;a href="http://software.silicon.com/security/0,39024655,39131274,00.htm"&gt;cybertheft disclosed by MasterCard&lt;/a&gt; in June last year.&lt;br /&gt;&lt;br /&gt;Now the payment processor CardSystems Solutions, that exposed 40 million credit cards to the risk of fraud when a hacker took advantages of security failures, has agreed to settle US Federal Trade Commission charges. &lt;a href="http://www.theregister.co.uk/2006/02/27/ftc_settles_with_cardsystems/"&gt;The Register&lt;/a&gt; reports that independent security audits will now be required every other year for 20 years. CardSystems Solutions and its successor Solidus Networks (which does business as Pay By Touch) are also obliged to implement a comprehensive information security programme.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114104533294575723?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114104533294575723/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114104533294575723' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114104533294575723'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114104533294575723'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/02/us-federal-trade-commission-settles.html' title='US Federal Trade Commission Settles with CardSystems over Data Breach'/><author><name>Edwin Jacobs</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114097713192208762</id><published>2006-02-26T19:02:00.000+01:00</published><updated>2006-02-26T19:21:40.113+01:00</updated><title type='text'>May common sense avoid us to enable  worlds like these</title><content type='html'>If you have some time to spend...take a look at these films, very interesting how the "security needs" of people can be re-targeted at other aims:&lt;br /&gt;&lt;br /&gt;Gattaca&lt;br /&gt;Equilibrium&lt;br /&gt;Minority Report&lt;br /&gt;&lt;br /&gt;Lots of important things not to forget about when being a security professional, isn't it ?&lt;br /&gt;&lt;br /&gt;What is very interesting in Gattaca and equilibrium is the capability for human to put interpersonal relations above the society system the're living in and to obtain some limited, unknown but important victory against the "disfunctions".&lt;br /&gt;&lt;br /&gt;Emotions can be the drivers of drastic changes in society... money is not everything after all, despites all what is said today around the benefits of some "rigid" society plans draw by a few for all of us....and our children&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114097713192208762?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114097713192208762/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114097713192208762' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114097713192208762'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114097713192208762'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/02/may-common-sense-avoid-us-to-enable.html' title='May common sense avoid us to enable  worlds like these'/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114074054484660843</id><published>2006-02-24T01:21:00.000+01:00</published><updated>2006-02-24T01:22:24.856+01:00</updated><title type='text'>Too Many New Gadgets, Too Much Information at Risk</title><content type='html'>New York Times: &lt;a href="http://www.nytimes.com/2006/02/21/business/businessspecial2/21secure.html?ex=1298178000&amp;en=2285e5824931357e&amp;amp;ei=5090&amp;partner=rssuserland&amp;amp;emc=rss"&gt;Too Many New Gadgets, Too Much Information at Risk&lt;/a&gt;: Loss, theft and viruses are major issues as corporate use of &lt;a href="http://en.wikipedia.org/wiki/Personal_digital_assistant"&gt;PDA's&lt;/a&gt; and pocket PCs increases. Preemptive security options are available however, as this article describes. (Via &lt;a href="http://www.bespacific.com/mt/archives/010537.html#010537"&gt;BeSpacific&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;Related: Risks of Losing Portable Devices (&lt;a href="http://www.schneier.com/blog/archives/2005/07/risks_of_losing.html"&gt;Bruce Schneier&lt;/a&gt;), &lt;a title="Permanent Link to PDA Security Tips" href="http://www.thex.com/security/2005/08/31/pda-security-tips/" rel="bookmark tag"&gt;PDA Security Tips &lt;/a&gt;(Networks and Security).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114074054484660843?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114074054484660843/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114074054484660843' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114074054484660843'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114074054484660843'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/02/too-many-new-gadgets-too-much.html' title='Too Many New Gadgets, Too Much Information at Risk'/><author><name>Edwin Jacobs</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114072710122671734</id><published>2006-02-23T21:28:00.000+01:00</published><updated>2006-02-23T21:39:10.086+01:00</updated><title type='text'>Standard security... A pandora box (second take)</title><content type='html'>Remember my post on the inherent weaknesses of standard  horizontal security providers  vs a proprietary systems that could include some standardized interface but focused on a specific vertical business area ?&lt;br /&gt;&lt;br /&gt;Here is a new proof of it: horizontal cross-markets security doesn't work, because it doesn't use checks that are fine-tuned to the specific business you want to secure and the specific threats that must be addressed by that business to continue to "float".&lt;br /&gt;&lt;br /&gt;Just take a look at: http://isc.sans.org/diary.php?storyid=1118&lt;br /&gt;&lt;br /&gt;Security patterns are only basic security countermeasures.&lt;br /&gt;- What is good in them is that it is low cost, because embedded in the toolkits your receives from you software editor and you don't have to hire very specialized people to obtain a decent security.&lt;br /&gt;&lt;br /&gt;What is bad with them is that:&lt;br /&gt;-  business owners and developpers think it suffices to know what pattern to use and how to call the appropriate "SSL API" to secure a vertical market business system.&lt;br /&gt;- generic attacks work on generic security systems and generic attacks have a better ROI for an attacker.&lt;br /&gt;&lt;br /&gt;Question is : what worth/criticality is your business: A Ford-T or a Rolls-Royce....&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114072710122671734?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114072710122671734/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114072710122671734' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114072710122671734'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114072710122671734'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/02/standard-security-pandora-box-second.html' title='Standard security... A pandora box (second take)'/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114072595521096868</id><published>2006-02-23T20:52:00.000+01:00</published><updated>2006-02-23T21:23:16.403+01:00</updated><title type='text'>Universities are you there?</title><content type='html'>Hi again,&lt;br /&gt;&lt;br /&gt;I was searching on the web for security educational programs that could be followed by young student eager to reinforce the handful of people trying to keep critical infrastructures safe in these troubled times of marketing, outsourcing deregulated and "hype &amp;amp; time to market-led" economy.&lt;br /&gt;&lt;br /&gt;I must confess that what I found focused a lot on:&lt;br /&gt;- Cryptography and the related associated mathematics (number theory, statistics, ...)&lt;br /&gt;- in some case security protocols analysis.&lt;br /&gt;- Basic abstract security models (Bell-Lapadula, ...)&lt;br /&gt;&lt;br /&gt;At the industry educational side, I found a lot of whitepapers and courses around how to design a network and (less often) application firewall architecture,...I found a fair quantity of sites (OWASP, ...) talking of "secure coding rcommendations" and giving threat modelling "checklists"&lt;br /&gt;&lt;br /&gt;but there were very few possibilities for people wishing to understand what are the underlying foundations (and practical limitations of them) of current operating systems and advanced programming languages security models and implementations.&lt;br /&gt;&lt;br /&gt;There was very very few education possibilities for people working in companies whose goal is to conceive and develop "security code" whose goal is to enforce security "building blocks" to pass through all the security development lifecycle steps as described in&lt;br /&gt;&lt;br /&gt;http://msdn.microsoft.com/msdnmag/issues/05/11/SDL/default.aspx&lt;br /&gt;&lt;br /&gt;Maybe a good course to include in universities curriculum.  My opinion is that this kind of subject should be part of a "Computer Science specialisation branch" into "operating systems" and "software engineering". It has been for too long neglected.&lt;br /&gt;&lt;br /&gt;This is a wake up call to our beautiful Belgian Universities...Don't only talk of it during one hour, make security  an "IT curriculum specialization" branch in itself, otherwise there won't be enough man to handle the current challenges.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114072595521096868?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114072595521096868/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114072595521096868' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114072595521096868'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114072595521096868'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/02/universities-are-you-there.html' title='Universities are you there?'/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114068474863660548</id><published>2006-02-23T09:45:00.000+01:00</published><updated>2006-02-23T09:55:08.103+01:00</updated><title type='text'>Mac OS X ripe for picking</title><content type='html'>&lt;pre&gt;First post from me on Prometheus! You'll see that my interests are&lt;br /&gt;mostly in operational security, privacy, and other such light&lt;br /&gt;subjects. This first post is about Mac OS security...&lt;br /&gt;&lt;br /&gt;Lots of Mac OS X users believed that their platform was much more&lt;br /&gt;secure than the rest, and that worms and vulnerabilities would not&lt;br /&gt;reach them. Most security professionals had the intuition that,&lt;br /&gt;while the Mac OS model is sounder than others, it was just a questio&lt;br /&gt;of time and exposure before malicious hackers turn their attention&lt;br /&gt;to the re-emerging platform. This week has proved them right.&lt;br /&gt;&lt;br /&gt;First, a trojan - dubbed &lt;a href="http://vil.nai.com/vil/content/v_138578.htm"&gt;OSX/Leap&lt;/a&gt; - has been slowly spreading via&lt;br /&gt;iChat. This was a proof-of-concept, and users almost had to be&lt;br /&gt;willing to be infected for the worm to work.&lt;br /&gt;&lt;br /&gt;The next day, another worm, &lt;a href="http://www.f-secure.com/v-descs/inqtana_a.shtml"&gt;OSX/Ingtana.A&lt;/a&gt;, showed that a Mac OS&lt;br /&gt;Bluetooth worm was feasible. Once again, it was a proof-of-concept&lt;br /&gt;that barely left the labs.&lt;br /&gt;&lt;br /&gt;And three days ago, Heise published &lt;a href="http://www.heise.de/english/newsticker/news/69862"&gt;an article&lt;/a&gt; on what they&lt;br /&gt;thought was a vulnerability in Apple's Safari web browser. Shortly,&lt;br /&gt;it is possible for a malicious user to disguise a shell script as&lt;br /&gt;any other file - image or movie, for example - and still have the&lt;br /&gt;script executed when the link is followed. Exploitation requires&lt;br /&gt;no user interaction. What was already bad became worse the next&lt;br /&gt;day, when it was realised that the vulnerability was not in&lt;br /&gt;Safari, but &lt;a href="http://www.heise.de/english/newsticker/news/69919"&gt;much deeper in OS X's Finder&lt;/a&gt;, allowing it to be exploited&lt;br /&gt;through other channels, like email.&lt;br /&gt;&lt;br /&gt;There is a workaround for Safari, but not for the rest, and Apple&lt;br /&gt;hasn't published a fix yet. The bottom line is that Mac OS users&lt;br /&gt;are now at the same place as Windows users a few years ago:&lt;br /&gt;their favorite platform can be exploited without any user&lt;br /&gt;interaction, with the root cause being the very user-friendliness&lt;br /&gt;that makes them like their systems. It's very hard to make&lt;br /&gt;ease-of-use and security go hand in hand, and this is one more proof.&lt;br /&gt;Maybe systems should be a bit less user-friendly, and users better&lt;br /&gt;trained?&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114068474863660548?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114068474863660548/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114068474863660548' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114068474863660548'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114068474863660548'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/02/mac-os-x-ripe-for-picking.html' title='Mac OS X ripe for picking'/><author><name>McG</name><uri>http://www.blogger.com/profile/08629649882809500496</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114003820376394879</id><published>2006-02-15T22:12:00.000+01:00</published><updated>2006-02-15T22:24:37.393+01:00</updated><title type='text'>Tired of security...drink wine..same headache ... but better taste</title><content type='html'>&lt;a href="http://photos1.blogger.com/blogger/4444/2238/1600/arniston.0.jpg"&gt;&lt;br /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114003820376394879?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114003820376394879/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114003820376394879' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114003820376394879'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114003820376394879'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/02/tired-of-securitydrink-winesame.html' title='Tired of security...drink wine..same headache ... but better taste'/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-114003739808358969</id><published>2006-02-15T22:01:00.000+01:00</published><updated>2006-02-15T22:08:57.763+01:00</updated><title type='text'>Customer Care Depts be ready: IE 7 is coming at light speed</title><content type='html'>Quite a day:It's been a bunch of Microsoft announcements around IE7 changes...impressive from a "I want to protect my PC viewpoint".&lt;br /&gt;&lt;br /&gt;Question is: will the community and the users be capable to digest so radical evolutions ?&lt;br /&gt;&lt;br /&gt;Customers had problems to understand what a certificate was all about.&lt;br /&gt;&lt;br /&gt;Now there is yet another concept "higher assurance" website and other (low assurance ? ex high assurance) website certificates....&lt;br /&gt;&lt;br /&gt;it becomes more and more complex to develop something coherent and understandable in a specific business context using a browser as "application container".Security warning messages are differents between each IE releases, infocards come in, etc =&gt; how will independent software vendors explain this to their customer base.I know some that could be tempted to say well maybe Fat clients were not so clunky after all and at least customer experience was stable, controlled by the application developper and uniform in a specific business context.&lt;br /&gt;&lt;br /&gt;when using it, I saw strange differences between IE 7 beta 1 and IE 7 beta 2 when clicking on the "SSL lock" (the one just on the right of the URL bar).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;In IE 7 beta 1: Displayed certificate information summary seem logical to me:&lt;br /&gt;&lt;br /&gt;it indicate the CN of the certification authority that did issue the ssl website certificate.This is inline with the "issued by" display when you double click on a certificate in earlier versions of the "view certificate details" .&lt;br /&gt;&lt;br /&gt;IE 7 beta 1 displayed text is&lt;br /&gt;"SSL secure (128 bits) you should send confidential information only if you trust the organization listed what is a certificate ?&lt;br /&gt;&lt;br /&gt;Certificate information followed by :&lt;br /&gt;&lt;br /&gt;- the "O=" information of the website ssl cert&lt;br /&gt;- the "C=" inforomation of the website ssl certWebsite certification&lt;br /&gt;&lt;br /&gt;provided by : CN field of the X509 certificate of the issuing CA.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;In IE 7 beta 2, everything seems to have changed, clicking on the "SSL lock" (the one just on the right of the URL bar), I have:&lt;br /&gt;&lt;br /&gt;Secure connection&lt;br /&gt;&lt;br /&gt;"O=" field of the issuing CA has identified this site as "CN of the website ssl "&lt;br /&gt;cert Owner unverified&lt;br /&gt;Location unverified.&lt;br /&gt;&lt;br /&gt;Limited information about this website is available. You should send confidential information only if you trust this website.&lt;br /&gt;What is a certificate.&lt;br /&gt;&lt;br /&gt;It took a long time to educate customer/users to check the "issued by" field of the certificate details (= CN of the issuing CA cert), why now change the field identifying a Certification authority to the "O= " field ?&lt;br /&gt;&lt;br /&gt;I think the IE 7 beta 1 "security message" is better because it relies on several years of education to customer and users for a lot of companies offering services on the internet and remains inline with past versions of windows and IE making easier the understanding for customer....simplicity in security communication to users is of primary importance here...&lt;br /&gt;&lt;br /&gt;What is "owner" in this security message ?&lt;br /&gt;What is "location" in this security message ?&lt;br /&gt;to which X509 website and issuing certificate field does these "semantic notions" correspond ?&lt;br /&gt;What is "security semantics and policies" around these items ?&lt;br /&gt;&lt;br /&gt;Well ...if you have some ideas about how Ms implemented distinction between "higher assurance" ssl cert websites and "normal what we used until now" ssl cert websites...&lt;br /&gt;&lt;br /&gt;pls enlighten me&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-114003739808358969?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/114003739808358969/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=114003739808358969' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114003739808358969'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/114003739808358969'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/02/customer-care-depts-be-ready-ie-7-is.html' title='Customer Care Depts be ready: IE 7 is coming at light speed'/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-113987512034422208</id><published>2006-02-14T00:24:00.000+01:00</published><updated>2006-02-14T01:03:20.783+01:00</updated><title type='text'>EU Safer Internet Day and Filtering Software</title><content type='html'>On 7th February 2006 the &lt;a href="http://www.saferinternet.org/ww/en/pub/insafe/index.htm"&gt;Safer Internet Day&lt;/a&gt; was celebrated by 95 organisations in 36 countries across the world, including 24 EU countries, Russia, Argentina, New Zealand and the USA. Organised under the patronage of the &lt;a href="http://europa.eu.int/rapid/pressReleasesAction.do?reference=IP/06/126&amp;format=HTML&amp;amp;amp;amp;aged=0&amp;language=EN&amp;amp;guiLanguage=en"&gt;EU Information Society&lt;/a&gt; and Media Commissioner Viviane Reding, Safer Internet Day 2006, featured a &lt;a href="http://blog.eun.org/insafe/english/"&gt;blogathon&lt;/a&gt; or “blog-marathon” during which wide range of organisations and special guests promoted internet safety by making postings and inviting comments from visitors, children, schools and parents.&lt;br /&gt;&lt;br /&gt;The European Commission’s safer Internet programme can be found &lt;a href="http://europa.eu.int/information_society/activities/sip/index_en.htm"&gt;here&lt;/a&gt;. Part of this programme is a study aiming at an independent &lt;a href="http://europa.eu.int/information_society/activities/sip/news_events/project_news/sip_bench/index_en.htm"&gt;assessment of the filtering software&lt;/a&gt; and services. By "filtering" is apparently meant "parental control and spam filtering products or services" and not something like &lt;a href="http://news.bbc.co.uk/2/hi/programmes/click_online/4587622.stm"&gt;this&lt;/a&gt;...&lt;br /&gt;&lt;br /&gt;For more, see (already from October 2003 but some parts are still relevant) &lt;a href="http://cyber.law.harvard.edu/filtering/"&gt;Documentation of Internet Filtering Worldwide&lt;/a&gt; by &lt;a href="http://cyber.law.harvard.edu/zittrain.html"&gt;Jonathan Zittrain&lt;/a&gt; and &lt;a href="http://cyber.law.harvard.edu/edelman.html"&gt;Benjamin Edelman&lt;/a&gt; at the &lt;a href="http://cyber.law.harvard.edu/"&gt;Berkman Center for Internet &amp;amp; Society&lt;/a&gt; - &lt;a href="http://www.law.harvard.edu/"&gt;Harvard Law School&lt;/a&gt;. They provide country-specific studies and other studies like e.g. about IP addresses, Google.&lt;br /&gt;&lt;br /&gt;For a more recent update and overview visit &lt;a href="http://www.opennetinitiative.net/index.php"&gt;OpenNet Initiative&lt;/a&gt; with of course lots of case studies and also a small &lt;a href="http://opennetinitiative.net/docs/Legal_Implications.pdf"&gt;pdf&lt;/a&gt; on the legal implications of Internet filtering.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-113987512034422208?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/113987512034422208/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=113987512034422208' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/113987512034422208'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/113987512034422208'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/02/eu-safer-internet-day-and-filtering.html' title='EU Safer Internet Day and Filtering Software'/><author><name>Edwin Jacobs</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-113978248945177667</id><published>2006-02-12T23:12:00.000+01:00</published><updated>2006-02-12T23:14:49.460+01:00</updated><title type='text'>Lawyers: Beware Google's desktop search</title><content type='html'>&lt;a href="http://www.legaline.com/2006/02/lawyers-beware-googles-desktop-search.html"&gt;Robert J. Ambrogi&lt;/a&gt; writes that the version 3.0 of &lt;a href="http://desktop.google.com/"&gt;Google Desktop Search&lt;/a&gt; could be a significant headache for lawyers. Is client confidentiality threatened?&lt;br /&gt;&lt;br /&gt;A new feature of the 3.0 version is that it allows to search across multiple computers provided they are all tied to a Google account. Google temporarily stores copies of the indexed files on its servers and the data is stored temporarily to allow the new index information to be sent to the other computer. Admittedly, after a period of time, Google automatically deletes the data.&lt;br /&gt;&lt;br /&gt;Taking into account the &lt;a href="http://www.zdnet.com.au/news/software/soa/Google_stands_up_to_US_government_porn_probe/0,2000061733,39234228,00.htm"&gt;recent attempts of the US government&lt;/a&gt; to obtain personal information stored by Google and other search companies, even temporary storage of a lawyer's files on Google's servers could &lt;a href="http://arstechnica.com/news.ars/post/20060209-6145.html"&gt;threaten client confidentiality&lt;/a&gt;. Robert J. Ambrogi concludes: given this, go ahead and download the latest toolbar, but think twice before enabling its ability to search across multiple computers.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-113978248945177667?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/113978248945177667/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=113978248945177667' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/113978248945177667'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/113978248945177667'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/02/lawyers-beware-googles-desktop-search.html' title='Lawyers: Beware Google&apos;s desktop search'/><author><name>Edwin Jacobs</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-113978093334764010</id><published>2006-02-12T22:35:00.000+01:00</published><updated>2006-02-12T22:48:53.356+01:00</updated><title type='text'>Security and Legal Issues</title><content type='html'>On this blog you'll also find some posts about legal issues related to security. A first appetizer can be found &lt;a href="http://www.arraydev.com/commerce/JIBC/2005-08/security.htm"&gt;here&lt;/a&gt;. It's about "Security as a legal obligation. About EU legislation related to security and Sarbanes Oxley in the European Union."&lt;br /&gt;Don't worry. We will avoid the "legal mumbo jumbo" or keep it to a strict minimum ;-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-113978093334764010?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/113978093334764010/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=113978093334764010' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/113978093334764010'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/113978093334764010'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/02/security-and-legal-issues.html' title='Security and Legal Issues'/><author><name>Edwin Jacobs</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-113978032418730820</id><published>2006-02-12T22:00:00.000+01:00</published><updated>2006-02-12T23:03:15.330+01:00</updated><title type='text'>Is standardized security "a pandora box" ?</title><content type='html'>Quite Tired today, so don't be too hard on me for my "hectic" way of writing.... I'll do better in future posts, promised   :-)&lt;br /&gt;&lt;br /&gt;I did read last week a very cool paper today that helps a lot understand windows access control.&lt;br /&gt;&lt;br /&gt;http://www.cs.princeton.edu/~sudhakar/papers/winval.pdf&lt;br /&gt;&lt;br /&gt;It left me under the impression that current evolution of adding more and more access controls layers  only adds to the difficulty to developpers to understand how to protect their application/services and their customer's PC and maybe benefits more to "security certification" provider than to application security enhancements.&lt;br /&gt;&lt;br /&gt;Windows OS ACLs were complex, no problems folks...let's add .net CLR and managed code or JVM with administrator configurations, user account protections that make things even more complex... their security behaviours are driven by obcure registry settings....&lt;br /&gt;&lt;br /&gt;Developpers created "service-focused fat clients" that they mastered quite well...Today "hype" push them to use "browser based applications" where they're forced to trust the browser with all the hidden registry settings, extensions and APIs.&lt;br /&gt;&lt;br /&gt;These have huge consequences for the security of application or the services accessed via the browser.&lt;br /&gt;&lt;br /&gt;Generic middleware in a specific business context doesn't know which security decision to take because it is too generic and not focused on the specific application security needs...&lt;br /&gt;&lt;br /&gt;These middleware leave the "security decision" to:&lt;br /&gt;&lt;br /&gt;- the unspecialised user using "generic messages" that don't allow the user to understand the real consequence of the warning message for the current business application he is working with (banking, health, ...)&lt;br /&gt;&lt;br /&gt;- the "new mighty god" aka "the system administrator", that most of the time as only an "empirical knowledge" of his art and is not the one that really does understand what is to be protected because he doesn't own the business or did develop the application that directly serves a specific business.&lt;br /&gt;&lt;br /&gt;The more your applications depends on third party middleware, the most you take the risk that this middleware options, security messages, ....can open your business application and services to new types of attacks...&lt;br /&gt;&lt;br /&gt;Security is about control of what is happening in an application. When a lot of the application security rely more and more on external and complex systems, it can only be made weaker.&lt;br /&gt;&lt;br /&gt;Example:  Who still know what "BrowseNewProcess" registry settings means for the security of a cookie based system..any idea anyone ?&lt;br /&gt;&lt;br /&gt;"Think Track": what do we protect when using OS vendors "security best practices" ? The customer PC, well maybe...&lt;br /&gt;&lt;br /&gt;but, hey,  it is realistic to think that a "generic security model" protecting the PC is valid  and efficient whatever the service accessed by the PC?  Isn't the standardisation now showing clearly its limits? How to secure something standard where all the details would be known by would be attackers?&lt;br /&gt;&lt;br /&gt;Interesting background paper on this:&lt;br /&gt;http://www.ccianet.org/papers/cyberinsecurity.pdf&lt;br /&gt;&lt;br /&gt;What must the service provider (and service developper) really do ? protect the PC or protect his service from attacks that would be launched from the customer PC that would have been taken over ? Both ?&lt;br /&gt;&lt;br /&gt;Threat modelling is some very powerful tool: by identifying first what the service provider (business owner) wants to protect, it can lead the security architect to the conclusion that maybe what is protected by OS vendors security best practices is not what does really matter for the service provider and that maybe the application security architect should strictly limit the trust he puts in the OS, browser and other middleware standard security.&lt;br /&gt;&lt;br /&gt;Why ? simply because standardisation of the security in these elements allows also for would be attackers to standardise their attacks and have a bigger ROI because it can be launched at massive scale.&lt;br /&gt;&lt;br /&gt;Must we come back to an age of proprietary security systems and protocols ? Is "security through obscurity buried or is it coming back very quickly simply because it would force the attacker to target a specific system (higher cost for him) and will limit the scale of attacks (limited only to that specifically targetted system)?&lt;br /&gt;&lt;br /&gt;Worth thinking about it ..no ?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-113978032418730820?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/113978032418730820/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=113978032418730820' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/113978032418730820'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/113978032418730820'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/02/is-standardized-security-pandora-box.html' title='Is standardized security &quot;a pandora box&quot; ?'/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-113958965112346088</id><published>2006-02-10T17:34:00.000+01:00</published><updated>2006-02-10T17:40:51.123+01:00</updated><title type='text'>Two good books</title><content type='html'>Started reading two books lately.... Real Digital Forensics from Keith T. Jones and "Core Security Patterns"  from Christopher Steel and al. Both are quite interesting....anyone in mood of launching "books discussion here" ?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-113958965112346088?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/113958965112346088/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=113958965112346088' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/113958965112346088'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/113958965112346088'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/02/two-good-books.html' title='Two good books'/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-113951741624599913</id><published>2006-02-09T21:35:00.000+01:00</published><updated>2006-02-09T21:37:12.180+01:00</updated><title type='text'></title><content type='html'>Today, I completed the blog with very interesting links treating of software security architecture and engineering.&lt;br /&gt;&lt;br /&gt;I also renamed it "Prometheus".&lt;br /&gt;&lt;br /&gt;Prometheus was a rebel god; in defiance of Zeus, he gave fire and other comforts to the mortals on the earth.&lt;br /&gt;&lt;br /&gt;Prometheus means also "thinking in advance" and "consideration for the future". This is one of the quality of any security architect.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-113951741624599913?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/113951741624599913/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=113951741624599913' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/113951741624599913'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/113951741624599913'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/02/today-i-completed-blog-with-very.html' title=''/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-113943437376419937</id><published>2006-02-08T22:26:00.000+01:00</published><updated>2006-02-08T22:34:49.626+01:00</updated><title type='text'>On the difficulty of finding "real security architects"</title><content type='html'>&lt;span style="font-family:times new roman;"&gt;Wow... today was a security architect "hiring quest".&lt;br /&gt;&lt;br /&gt;Finding someone with:&lt;br /&gt;- real IT security architecture knowledge&lt;br /&gt;- understanding of what is a security protocols and attacks on it&lt;br /&gt;- having knowledge of what a smart card is&lt;br /&gt;- understanding "system and middleware security"&lt;br /&gt;- being capable of have a criticize look at standards.&lt;br /&gt;&lt;br /&gt;without only relying on "prefab" assimilated information is becomes harder than ever...&lt;br /&gt;&lt;br /&gt;IT Security industry has never had more certifications but has still less and less real secure systems conceptors....&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-113943437376419937?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/113943437376419937/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=113943437376419937' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/113943437376419937'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/113943437376419937'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/02/on-difficulty-of-finding-real-security.html' title='On the difficulty of finding &quot;real security architects&quot;'/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-22055534.post-113925899290323251</id><published>2006-02-06T21:43:00.000+01:00</published><updated>2006-02-06T21:49:52.913+01:00</updated><title type='text'>Standard middleware security or not</title><content type='html'>So...ok, first time to blog in my life...&lt;br /&gt;&lt;br /&gt;just came accross some interesting papers on SAML 2.0 and the more I read, the more I think that when things become so difficult to grasp, their complexity make them inherently insecure and difficult to maintain...main problem is the fact that they attempts to covers a too large scope and are focusing on too many options.&lt;br /&gt;&lt;br /&gt;Occam razor should drive security architect and engineers....&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/22055534-113925899290323251?l=blacksun06.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blacksun06.blogspot.com/feeds/113925899290323251/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=22055534&amp;postID=113925899290323251' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/113925899290323251'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/22055534/posts/default/113925899290323251'/><link rel='alternate' type='text/html' href='http://blacksun06.blogspot.com/2006/02/standard-middleware-security-or-not.html' title='Standard middleware security or not'/><author><name>Blacksun</name><uri>http://www.blogger.com/profile/12329769301517442227</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
