<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Jesper Johansson's Blog : Security Pontification</title><link>http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx</link><description>Tags: Security Pontification</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Fake Anti-Malware is Apparently Microsoft's Fault</title><link>http://msmvps.com/blogs/jesper/archive/2009/10/24/fake-anti-malware-is-apparently-microsoft-s-fault.aspx</link><pubDate>Sat, 24 Oct 2009 17:20:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1734828</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>Munir Kotadia, an IT Journalist in Australia, has finally managed to figure out how to blame Microsoft for the fake anti-malware epidemic. Apparently, the reason is that &amp;quot;Microsoft could save the world from fake security applications by introducing...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2009/10/24/fake-anti-malware-is-apparently-microsoft-s-fault.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1734828" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>Web Of Trust: RIP</title><link>http://msmvps.com/blogs/jesper/archive/2009/10/14/web-of-trust-rip.aspx</link><pubDate>Wed, 14 Oct 2009 05:16:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1732277</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>It&amp;#39;s official. I just received an e-mail from Thawte notifying me that, as of November 16, 2009, the most innovative and useful idea in PKI since its inception, the Web of Trust , will die. Thawte was founded 14 years ago by Mark Shuttleworth. The...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2009/10/14/web-of-trust-rip.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1732277" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Thinking+differently/default.aspx">Thinking differently</category></item><item><title>And finally, standard user malware</title><link>http://msmvps.com/blogs/jesper/archive/2009/09/01/and-finally-standard-user-malware.aspx</link><pubDate>Tue, 01 Sep 2009 06:21:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1719824</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>Today I finally got wind of my first piece of true standard user malware. MS Antispyware 2008 has turned standard user. The version in question installs the binaries in c:\documents and settings\all users\application data\&amp;lt;something&amp;gt;, and makes...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2009/09/01/and-finally-standard-user-malware.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1719824" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Least+Privilege/default.aspx">Least Privilege</category></item><item><title>Is it ActiveX that is the problem?</title><link>http://msmvps.com/blogs/jesper/archive/2009/08/09/is-it-activex-that-is-the-problem.aspx</link><pubDate>Sun, 09 Aug 2009 20:04:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1714573</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>Last week, an expert from Verizon, nee Cybertrust, posted a note about the Active Template Library (ATL) security vulnerability over on the Verizon Business Security Blog . For home users, the phone company now advises you to use a different browser,...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2009/08/09/is-it-activex-that-is-the-problem.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1714573" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>Please do not e-mail my social security number</title><link>http://msmvps.com/blogs/jesper/archive/2009/01/27/please-do-not-e-mail-my-social-security-number.aspx</link><pubDate>Wed, 28 Jan 2009 05:38:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1666496</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>Recently I had a very interesting incident. I wrote an article some time in 2008 and the publisher paid me a little bit of money for it. That means the publisher must send a report to the Internal Revenue Service (IRS - the U.S. tax department) reporting...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2009/01/27/please-do-not-e-mail-my-social-security-number.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1666496" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>Kip Hawley: "No, the TSA is Necessary Because This is War!"</title><link>http://msmvps.com/blogs/jesper/archive/2008/12/24/kip-hawley-quot-no-the-tsa-is-necessary-because-this-is-war-quot.aspx</link><pubDate>Wed, 24 Dec 2008 10:44:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1657653</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>CBS News did a story a few days ago on the Transportation Security Administration (TSA). Basically it was a tit-for-tat between Bruce Schneier , security pontificator extraordinaire, and Kip Hawley, the administrator of the TSA. Mr. Hawley&amp;#39;s maintans...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/12/24/kip-hawley-quot-no-the-tsa-is-necessary-because-this-is-war-quot.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1657653" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>One "Hacker" Attempts to Rule The World</title><link>http://msmvps.com/blogs/jesper/archive/2008/12/24/one-quot-hacker-quot-attempts-to-rule-the-world.aspx</link><pubDate>Wed, 24 Dec 2008 10:40:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1657654</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>Wired, always a source for amusement and interesting literature, just carried a story on a &amp;quot;hacker&amp;quot; (the magazine&amp;#39;s use of the term equates to &amp;quot;criminal&amp;quot;) who attempted to dominate the market in stolen credit cards. It&amp;#39;s a...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/12/24/one-quot-hacker-quot-attempts-to-rule-the-world.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1657654" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>Believe it or not; DRM for Zune is down!</title><link>http://msmvps.com/blogs/jesper/archive/2008/12/16/believe-it-or-not-drm-for-zune-is-down.aspx</link><pubDate>Tue, 16 Dec 2008 06:21:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1656836</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>Shocking, yes, I know, but in only four hours this evening Microsoft has managed to alienate over 150 additional customers with its insistence on Digital Rights Management (DRM). This time it is the DRM component of the Zune store that is down, according...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/12/16/believe-it-or-not-drm-for-zune-is-down.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1656836" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>What do you think, should I do it?</title><link>http://msmvps.com/blogs/jesper/archive/2008/11/16/what-do-you-think-should-i-do-it.aspx</link><pubDate>Sun, 16 Nov 2008 16:44:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1654260</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>I get a fair bit of blog spam - comments advertising everything from sexual enhancers to fake anti-malware. This one just came in this morning: Sweet! I can turn off all the blog spam just by e-mailing the criminals? Or, could it possibly be that this...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/11/16/what-do-you-think-should-i-do-it.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1654260" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>Fun Experiences at Airport Security</title><link>http://msmvps.com/blogs/jesper/archive/2008/11/15/fun-experiences-at-airport-security.aspx</link><pubDate>Sat, 15 Nov 2008 16:13:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1654207</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>For a while I&amp;#39;ve been thinking about writing something about interesting times I&amp;#39;ve had at various airport security checkpoints; security theater, as they have come to be known. There is the obvious shoe removal arguments and the ill-defined rules...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/11/15/fun-experiences-at-airport-security.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1654207" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>Is MS08-067 Wormable?</title><link>http://msmvps.com/blogs/jesper/archive/2008/11/04/is-ms08-067-wormable.aspx</link><pubDate>Tue, 04 Nov 2008 12:14:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1653027</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>A couple of weeks ago Microsoft released an out-of-band security update in bulletin MS08-067 . Looking at the type of vulnerability and the fact that the issue was already being exploited in the wild at the time, this was a good decision. If you have...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/11/04/is-ms08-067-wormable.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1653027" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Thinking+differently/default.aspx">Thinking differently</category></item><item><title>Security is About Passwords and Credit Cards, Part 3</title><link>http://msmvps.com/blogs/jesper/archive/2008/08/10/security-is-about-passwords-and-credit-cards-part-3.aspx</link><pubDate>Sun, 10 Aug 2008 06:14:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1644123</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>The final installment in my series called &amp;quot; Security is About Passwords and Credit Cards &amp;quot; is now up on TechNet Magazine. This part of the series discusses updating technologies, including how not to abuse them, messaging about security, and...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/08/10/security-is-about-passwords-and-credit-cards-part-3.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1644123" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>Security is About Passwords and Credit Cards Part 2</title><link>http://msmvps.com/blogs/jesper/archive/2008/07/03/security-is-about-passwords-and-credit-cards-part-2.aspx</link><pubDate>Thu, 03 Jul 2008 21:32:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1639294</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>The second part of my &amp;quot; Security is About Passwords and Credit Cards &amp;quot; article just hit the web. This installment looks at logon processes, misleading security eye candy, and insecure communications with customers. As always, I&amp;#39;d love your...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/07/03/security-is-about-passwords-and-credit-cards-part-2.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1639294" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>Security is About Passwords and Credit Cards</title><link>http://msmvps.com/blogs/jesper/archive/2008/06/20/security-is-about-passwords-and-credit-cards.aspx</link><pubDate>Fri, 20 Jun 2008 21:27:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1636202</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>Security is About Passwords and Credit Cards. That&amp;#39;s what a very nice lady told me a few months ago. At first I shrugged it off. Of course security is so much more than that. As I started to process it though I realized that is exactly what it is...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/06/20/security-is-about-passwords-and-credit-cards.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1636202" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>Thoughts on Security by Obscurity</title><link>http://msmvps.com/blogs/jesper/archive/2008/05/13/thoughts-on-security-by-obscurity.aspx</link><pubDate>Tue, 13 May 2008 17:46:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1623093</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>This has not really been that normal a week for me, but at least another article made it into print. The June 2008 issue of TechNet Magazine is headlined by an article I wrote with my friend Roger Grimes, Security Adviser for Infoworld , on Security by...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/05/13/thoughts-on-security-by-obscurity.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1623093" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Thinking+differently/default.aspx">Thinking differently</category></item><item><title>Warning! Don't run Anti-Malware Software on Your Research Machine</title><link>http://msmvps.com/blogs/jesper/archive/2008/05/01/warning-don-t-run-anti-malware-software-on-your-research-machine.aspx</link><pubDate>Thu, 01 May 2008 19:20:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1611050</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>I do not run any anti-malware software on my primary workstation. It&amp;#39;s a habit I got into way back when I was doing penetration assessments. I showed up at the site, fired up ye olde laptop, and went to run some tool. ...went to run some tool. Hey...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/05/01/warning-don-t-run-anti-malware-software-on-your-research-machine.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1611050" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>Quantum Security</title><link>http://msmvps.com/blogs/jesper/archive/2008/04/22/quantum-security.aspx</link><pubDate>Wed, 23 Apr 2008 01:37:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1600383</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>The May 2008 issue of TechNet Magazine is out. It has an article in it that I have been wanting to write for a long time, called Quantum Security . In it I posit the argument that there are some fundamental laws of security, similar to the laws of physics...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/04/22/quantum-security.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1600383" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category><category domain="http://msmvps.com/blogs/jesper/archive/tags/Thinking+differently/default.aspx">Thinking differently</category></item><item><title>How to remove the security warning, or should you?</title><link>http://msmvps.com/blogs/jesper/archive/2008/04/21/how-to-remove-the-security-warning-or-should-you.aspx</link><pubDate>Mon, 21 Apr 2008 18:10:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1598527</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>This morning there was an interesting question in the Windows Vista Security Newsgroup . The poster had written an application that users were downloading. However, when they ran the application they received a warning dialog, like this one: The poster...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/04/21/how-to-remove-the-security-warning-or-should-you.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1598527" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>Regulatory Silliness</title><link>http://msmvps.com/blogs/jesper/archive/2008/03/10/regulatory-silliness.aspx</link><pubDate>Mon, 10 Mar 2008 17:30:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1539295</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>Susan just pointed me to a &amp;quot; Self-assessment questionnaire &amp;quot; for the Payment Card Industry Data Security Standard (PCI/DSS). While, on the whole, the intent of that standard is good, there are some areas of it that, as usual, stray into the...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/03/10/regulatory-silliness.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1539295" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item><item><title>Measuring Identity Theft</title><link>http://msmvps.com/blogs/jesper/archive/2008/02/29/measuring-identity-theft.aspx</link><pubDate>Fri, 29 Feb 2008 23:20:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1528845</guid><dc:creator>Jesper's Blog</dc:creator><slash:comments>0</slash:comments><description>Chris Hoofnagle, of the Berkeley Center for Law And Technology just published a fascinating report entitled &amp;quot; Measuring Identity Theft at Top Banks .&amp;quot; If you have not already, and you are at all interested in security and privacy, you owe it...(&lt;a href="http://msmvps.com/blogs/jesper/archive/2008/02/29/measuring-identity-theft.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1528845" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/jesper/archive/tags/Security+Pontification/default.aspx">Security Pontification</category></item></channel></rss>