<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>/bill's House O Insomnia&lt;img src="http://www.williamgryan.com/images/originalcuckoo.jpg" alt="Bill Ryan" /&gt; : Security</title><link>http://msmvps.com/blogs/williamryan/archive/tags/Security/default.aspx</link><description>Tags: Security</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Singles.org fesses up - sort of</title><link>http://msmvps.com/blogs/williamryan/archive/2009/02/24/singles-org-fesses-up-sort-of.aspx</link><pubDate>Tue, 24 Feb 2009 15:45:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1673506</guid><dc:creator>William</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/williamryan/rsscomments.aspx?PostID=1673506</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/williamryan/commentapi.aspx?PostID=1673506</wfw:comment><comments>http://msmvps.com/blogs/williamryan/archive/2009/02/24/singles-org-fesses-up-sort-of.aspx#comments</comments><description>This place is beyond low. countless email accounts have been breached, several facebook pages, several paypal accounts and much more. As of last night, if was in full free for all mode as more vulnerabilities were found (although vulnerability is a bit...(&lt;a href="http://msmvps.com/blogs/williamryan/archive/2009/02/24/singles-org-fesses-up-sort-of.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1673506" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Singles.org/default.aspx">Singles.org</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Hacking/default.aspx">Hacking</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/db.singles.org/default.aspx">db.singles.org</category></item><item><title>Singles.org - db.singles.org - The Saga Continues</title><link>http://msmvps.com/blogs/williamryan/archive/2009/02/23/singles-org-db-singles-org-the-saga-continues.aspx</link><pubDate>Tue, 24 Feb 2009 01:52:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1673454</guid><dc:creator>William</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/williamryan/rsscomments.aspx?PostID=1673454</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/williamryan/commentapi.aspx?PostID=1673454</wfw:comment><comments>http://msmvps.com/blogs/williamryan/archive/2009/02/23/singles-org-db-singles-org-the-saga-continues.aspx#comments</comments><description>At this point, seeing how pathetic Singles.org is resonding to this, they deserve everything they get. This is all kinda epic except real people are getting hurt. They aren&amp;#39;t the ones paying for it, well, at least until now. I&amp;#39;ll post screen caps...(&lt;a href="http://msmvps.com/blogs/williamryan/archive/2009/02/23/singles-org-db-singles-org-the-saga-continues.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1673454" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Singles.org/default.aspx">Singles.org</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Hacking/default.aspx">Hacking</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/db.singles.org/default.aspx">db.singles.org</category></item><item><title>The hacking of db.singles.org continued</title><link>http://msmvps.com/blogs/williamryan/archive/2009/02/23/the-hacking-of-db-singles-org-continued.aspx</link><pubDate>Mon, 23 Feb 2009 12:38:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1673317</guid><dc:creator>William</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/williamryan/rsscomments.aspx?PostID=1673317</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/williamryan/commentapi.aspx?PostID=1673317</wfw:comment><comments>http://msmvps.com/blogs/williamryan/archive/2009/02/23/the-hacking-of-db-singles-org-continued.aspx#comments</comments><description>Well, I&amp;#39;ve recieved a few comments and emails about this and things are just getting worse. As of 7:38 AM 02.23.2009 they still haven&amp;#39;t put anything on their site indicating anything even happened. Email is clearly not a valid option b/c of the...(&lt;a href="http://msmvps.com/blogs/williamryan/archive/2009/02/23/the-hacking-of-db-singles-org-continued.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1673317" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Singles.org/default.aspx">Singles.org</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Hacking/default.aspx">Hacking</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/db.singles.org/default.aspx">db.singles.org</category></item><item><title>The Hacking of http://db.singles.org</title><link>http://msmvps.com/blogs/williamryan/archive/2009/02/22/the-hacking-of-http-db-singles-org.aspx</link><pubDate>Sun, 22 Feb 2009 23:03:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1673181</guid><dc:creator>William</dc:creator><slash:comments>25</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/williamryan/rsscomments.aspx?PostID=1673181</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/williamryan/commentapi.aspx?PostID=1673181</wfw:comment><comments>http://msmvps.com/blogs/williamryan/archive/2009/02/22/the-hacking-of-http-db-singles-org.aspx#comments</comments><description>I was hesitant to write about this b/c I&amp;#39;ve been threatened pretty seriously about my role in it. But it&amp;#39;s important for people to understand a few things about the state of security today. What occurred was so pathetic, the result of such rampant...(&lt;a href="http://msmvps.com/blogs/williamryan/archive/2009/02/22/the-hacking-of-http-db-singles-org.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1673181" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Singles.org/default.aspx">Singles.org</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Hacking/default.aspx">Hacking</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/db.singles.org/default.aspx">db.singles.org</category></item><item><title>Using Facebook to launch a Botnet army</title><link>http://msmvps.com/blogs/williamryan/archive/2008/09/06/using-facebook-to-launch-a-botnet-army.aspx</link><pubDate>Sat, 06 Sep 2008 17:07:41 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1647010</guid><dc:creator>William</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/williamryan/rsscomments.aspx?PostID=1647010</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/williamryan/commentapi.aspx?PostID=1647010</wfw:comment><comments>http://msmvps.com/blogs/williamryan/archive/2008/09/06/using-facebook-to-launch-a-botnet-army.aspx#comments</comments><description>&lt;p&gt;&lt;a href="http://blog.wired.com/27bstroke6/2008/09/researchers-use.html"&gt;Wired has a piece talking about how easy this would be to do.&lt;/a&gt;&amp;nbsp; It&amp;#39;s not entirely speculative since researchers built such a beast.&amp;nbsp; I think the hype is a bit much though.&amp;nbsp; The argument they make could be made for any mechanism that can get people to install software on their own computers.&amp;nbsp; But unlike most other means, such an attack seems really easy to countermeasures.&amp;nbsp; It wouldn&amp;#39;t take long to figure it out and Facebook could easily send out a notice telling you to uninstall it. Much like human viruses, computer viruses and botnets are only really effective if they are allowed to exist in the infected host for a period of time, at least long enough to spread in the case of viruses, or long enough to be used in the case of botnets.&amp;nbsp; I&amp;#39;m not so naive to think that some Facebook users aren&amp;#39;t all that computer savvy, but overall I think it&amp;#39;s a demographic that&amp;#39;s fairly sophisticated. And they talk to each other a lot. Even if every facebook users downloaded the app (something really hard to fathom), it seems it would be pretty easy to eradicate. The more popular and more pernicious the bots, the more buzz there would be.&amp;nbsp; That&amp;#39;s not to say they don&amp;#39;t raise some good points and that Facebook shouldn&amp;#39;t try to prevent such things from happening, but it seems like it&amp;#39;s only worrisome in the theoretical sense.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1647010" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/williamryan/archive/tags/News/default.aspx">News</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Mindless+Babbling/default.aspx">Mindless Babbling</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Misc+Technology/default.aspx">Misc Technology</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Privacy/default.aspx">Privacy</category></item><item><title>I'd just close the hole...</title><link>http://msmvps.com/blogs/williamryan/archive/2008/03/08/i-d-just-close-the-hole.aspx</link><pubDate>Sun, 09 Mar 2008 02:15:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1537958</guid><dc:creator>William</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/williamryan/rsscomments.aspx?PostID=1537958</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/williamryan/commentapi.aspx?PostID=1537958</wfw:comment><comments>http://msmvps.com/blogs/williamryan/archive/2008/03/08/i-d-just-close-the-hole.aspx#comments</comments><description>&lt;p&gt;There are often times that I read something, typically involving a lawsuit, that I&amp;#39;m shocked people push. Often they are so embarassing, I&amp;#39;d probably pay extortion money to keep the crap quiet if someone threatened to go public about something I did.&amp;nbsp; But instead of trying to keep it quiet and just fixing it, they involve lawyers and threats.&amp;nbsp; NewsFlash - threatening bloggers and web sites backfires.&amp;nbsp; I can say unequivocally, if I was the one that created something &lt;a href="http://news.yahoo.com/s/ap/20080307/ap_on_hi_te/mobitv_web_leak"&gt;this widely used, that brough in this much money and had such a glaring security flaw&lt;/a&gt;&amp;nbsp;, I would just fix it quietly.&amp;nbsp; I wouldn&amp;#39;t want my name associated with something this moronic and sloppy.&amp;nbsp; I&amp;#39;d be paying bribes to the owner of &lt;a href="http://www.howardforums.com/"&gt;HowardForums&lt;/a&gt;&amp;nbsp;to have him keep it quiet, not threatening him and attracting attention.&amp;nbsp; Actually, I&amp;#39;d do neither. I&amp;#39;d thank him for helping me create a more secure system (then I&amp;#39;d fall on my sword in ritual suicide b/c Gawd this is embarassing)&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1537958" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/williamryan/archive/tags/News/default.aspx">News</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Misc+Technology/default.aspx">Misc Technology</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Mobility/default.aspx">Mobility</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Security/default.aspx">Security</category></item><item><title>Privacy is an outdated notion</title><link>http://msmvps.com/blogs/williamryan/archive/2008/02/10/privacy-is-an-outdated-notion.aspx</link><pubDate>Mon, 11 Feb 2008 01:16:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1507309</guid><dc:creator>William</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/williamryan/rsscomments.aspx?PostID=1507309</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/williamryan/commentapi.aspx?PostID=1507309</wfw:comment><comments>http://msmvps.com/blogs/williamryan/archive/2008/02/10/privacy-is-an-outdated-notion.aspx#comments</comments><description>&lt;p&gt;That&amp;#39;s not to say that I like that fact, or that I don&amp;#39;t lament it, but if you really think about it, it&amp;#39;s hard to deny.&amp;nbsp; After 9/11, I was reading a Wall Street Journal aritcle discussing the national id card.&amp;nbsp; Larry Ellison was a big supporter of it (and more cynical people believed his motivations were financial in that Oracle databases were the most likely ones to be used to implement such a scheme) and countered the privacy objections by saying something to the effect of &amp;quot;privacy is an illusion, you don&amp;#39;t have any&amp;quot;. He went on to point out that we get filmed x hundred times a day without even knowing it most of the time. All of our cell calls are logged. SMS messages are all logged. Same for email. And since we decreasingly use cash, most of our purchases are tracked as well.&amp;nbsp; So his point is that we&amp;#39;d gain security and give up little to no liberty, so why not?&amp;nbsp; I really hate this fact, but it&amp;#39;d be hard to disagree with him - at least in his assessment of the &amp;#39;problem&amp;#39;, there are many objections against the solution.&lt;/p&gt;
&lt;p&gt;&lt;a href="http://www.popsci.com/scitech/article/2008-02/anonymity-experiment"&gt;This post&lt;/a&gt;&amp;nbsp;won&amp;#39;t come as a surprise to anyone and I bet to some extent, we&amp;#39;ve all done this to ourselves already, but it does drive the point home.&amp;nbsp; I remember reading a book called &lt;a href="http://www.amazon.com/How-Be-Invisible-Essential-Protecting/dp/0312319061/ref=pd_bbs_sr_1?ie=UTF8&amp;amp;s=books&amp;amp;qid=1202692889&amp;amp;sr=8-1"&gt;How to Be Invisible&lt;/a&gt;&amp;nbsp;several years ago and really liked it. It might sound like one of those Paladin Press &amp;quot;Never pay taxes again&amp;quot; types of books, but it&amp;#39;s not.&amp;nbsp; In fact, the author is quite militant when it comes to people using his suggestions to break the law.&amp;nbsp; His whole concept is how to keep yourself off the grid while living legally - that there are many cases of people being stalked, killed, or just bothered b/c of publicly available information so it pays to keep yourself off the grid. After 9/11 he said many of his suggestions should no longer be used b/c trying to keep things private took on a new meaning.&amp;nbsp; I remember the book&amp;#39;s opening quote &amp;quot;Government&amp;#39;s keep secrets from people, why then should people not be allowed to keep secrets from government&amp;quot;&amp;nbsp; I still paruse his &lt;a href="http://www.howtobeinvisible.com/"&gt;http://www.howtobeinvisible.com/&lt;/a&gt;&amp;nbsp;and this sort of stuff makes me think I ought to go through and read the updated book again.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1507309" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Privacy/default.aspx">Privacy</category></item><item><title>Mujihadeen Secrets II</title><link>http://msmvps.com/blogs/williamryan/archive/2008/02/10/mujihadeen-secrets-ii.aspx</link><pubDate>Mon, 11 Feb 2008 00:25:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1507262</guid><dc:creator>William</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/williamryan/rsscomments.aspx?PostID=1507262</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/williamryan/commentapi.aspx?PostID=1507262</wfw:comment><comments>http://msmvps.com/blogs/williamryan/archive/2008/02/10/mujihadeen-secrets-ii.aspx#comments</comments><description>&lt;p&gt;Increasingly, I read stuff in &amp;#39;serious&amp;#39; publications and have to wonder if it wasn&amp;#39;t supposed to be posted to the Onion instead.&amp;nbsp; &lt;a href="http://blogs.csoonline.com/a_gift_from_the_islamic_faithful_network_mujahedeen_secrets_2_program"&gt;This is a perfect example&lt;/a&gt;&amp;nbsp; .&amp;nbsp; The map of their &amp;#39;locations&amp;#39; is priceless.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1507262" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Privacy/default.aspx">Privacy</category></item><item><title>The Bill of Rights in 2007</title><link>http://msmvps.com/blogs/williamryan/archive/2007/12/18/the-bill-of-rights-in-2007.aspx</link><pubDate>Wed, 19 Dec 2007 03:31:21 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1404641</guid><dc:creator>William</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/williamryan/rsscomments.aspx?PostID=1404641</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/williamryan/commentapi.aspx?PostID=1404641</wfw:comment><comments>http://msmvps.com/blogs/williamryan/archive/2007/12/18/the-bill-of-rights-in-2007.aspx#comments</comments><description>&lt;p&gt;So often when I hear talking heads pontificate about constitutional issues, I hear two basic sides.&amp;nbsp; The first is the strict constructionist interpretation where they claim the constitution is clear as day hence end of discussion.&amp;nbsp; On the other side you have the &amp;#39;living constitution&amp;#39; side that often acts like anything that is inconsistent with their agenda should just be interpreted away.&amp;nbsp; Whichever side one buys in to, it&amp;#39;s hard to argue that rapid technological advances don&amp;#39;t really complicate many legal issues.&amp;nbsp; &lt;a href="http://volokh.com/posts/1198012793.shtml" target="_blank"&gt;Orrin Kerr examines the United States vs King.&lt;/a&gt;&amp;nbsp; &lt;/p&gt; &lt;p&gt;In short, a contractor in Saudi Arabia was connected to a military network.&amp;nbsp; While doing routine patrols of the network, an analyst found some porn and happened to notice a folder named Pedophilia.&amp;nbsp; That prompted him to look further and as it turns out, the folder was accurately labeled.&amp;nbsp; King was arrested and charged.&amp;nbsp; His defense was that the search was illegal. Personally, all normal legal issues aside, i think he should be thrown in jail for being a sick SOB and stupid enough to plug&amp;nbsp; a computer with highly illegal material on it into a military network.&amp;nbsp; It&amp;#39;s not like that&amp;#39;s material you bring to work to show your buddies and you&amp;#39;d have to know that&amp;nbsp;a military network is likely to be subject to a higher degree of scrutiny than your average office. I know, there are tons of examples of amazing security lapses and incompetence on govt networks, but counting on the fact security might currently be lax is really foolish b/c just b/c it&amp;#39;s lax now, who&amp;#39;s the say that the next network guy they hire won&amp;#39;t be competent?&amp;nbsp; Having experience on two military installations, from what I saw, security was very tight.&amp;nbsp; So much so, that our standard operating policy was &amp;quot;Don&amp;#39;t do anything on that network that you wouldn&amp;#39;t be ok with if it showed up on the front page of tomorrow&amp;#39;s newspaper.&amp;quot;&amp;nbsp; And for God&amp;#39;s sake, if you&amp;#39;re doing something illegal (as well as something that you can rest assured will seriously anger just about any sane human being on Earth), why would you use the naming conventions he did?&amp;nbsp; &lt;/p&gt; &lt;p&gt;All that aside, the case is mighty interesting and &lt;a href="http://volokh.com/posts/1198012793.shtml" target="_blank"&gt;such issues are only going to become more and more frequent.&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1404641" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/williamryan/archive/tags/News/default.aspx">News</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Life+in+General/default.aspx">Life in General</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Misc+Technology/default.aspx">Misc Technology</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Security/default.aspx">Security</category></item><item><title>Crypto stuff</title><link>http://msmvps.com/blogs/williamryan/archive/2007/12/08/crypto-stuff.aspx</link><pubDate>Sat, 08 Dec 2007 22:51:58 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1387471</guid><dc:creator>William</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/williamryan/rsscomments.aspx?PostID=1387471</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/williamryan/commentapi.aspx?PostID=1387471</wfw:comment><comments>http://msmvps.com/blogs/williamryan/archive/2007/12/08/crypto-stuff.aspx#comments</comments><description>&lt;p&gt;I had a little extra time to catch up on life this weekend and found myself slowly getting sucked into stuff on &lt;a href="http://www.schneier.com/blog/" target="_blank"&gt;Bruce&amp;#39;s site that I&amp;#39;ve missed over time&lt;/a&gt;.&amp;nbsp; Ever since I picked up Applied Cryptography (and my Borland C++ compiler), I&amp;#39;ve appreciated how much butt he kicks.&amp;nbsp; I&amp;#39;ve used &lt;a href="http://sourceforge.net/projects/passwordsafe/" target="_blank"&gt;Password Safe&lt;/a&gt;&amp;nbsp;for a while and toy with the idea of porting it to the compact framework, but each time I get overwhelmed with the feeling that most of the stuff I work on is lame and unimportant.&amp;nbsp; Even on &amp;#39;cooler&amp;#39; projects involving WCF and WF, at the end of the day, it&amp;#39; still sort of the same stuff different day.&lt;/p&gt; &lt;p&gt;How do you read &lt;a href="http://www.schneier.com/essay-188.html" target="_blank"&gt;something like this&lt;/a&gt; and not feel jealous that there&amp;#39;s a lot cooler stuff out there than writing line of business apps?&lt;/p&gt; &lt;p&gt;&lt;em&gt;&amp;quot;I had a client once who desperately wanted to design his own encryption algorithm. He had no cryptographic training, no experience analyzing other algorithms. He was a designer, he said, not an analyst. So Counterpane did his analysis for him, and we broke his algorithm in a day. He fixed it and sent it back, and we broke it in two days. He fixed it and sent it back again, and we broke it again. Finally, the fourth version of his algorithm resisted our attempts at cryptanalysis...at least for the full 40 hours our contract specified. The client was happy; finally, he had a secure algorithm.&amp;quot;&lt;/em&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1387471" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Security/default.aspx">Security</category></item><item><title>Wordpress Vulnerability</title><link>http://msmvps.com/blogs/williamryan/archive/2007/11/29/wordpress-vulnerability.aspx</link><pubDate>Thu, 29 Nov 2007 20:22:04 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1369953</guid><dc:creator>William</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/williamryan/rsscomments.aspx?PostID=1369953</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/williamryan/commentapi.aspx?PostID=1369953</wfw:comment><comments>http://msmvps.com/blogs/williamryan/archive/2007/11/29/wordpress-vulnerability.aspx#comments</comments><description>&lt;p&gt;When I saw &lt;a href="http://www.schneier.com/blog/archives/2007/11/using_google_to.html" target="_blank"&gt;Bruce&amp;#39;s post on using Google crack MD5 Hashes for you&lt;/a&gt;, I had to chuckle.&amp;nbsp;Here&amp;#39;s a link to the &lt;a href="http://www.lightbluetouchpaper.org/2007/11/16/google-as-a-password-cracker/" target="_blank"&gt;article Bruce is referencing.&lt;/a&gt;&amp;nbsp; Once again, it shows a pretty good case of the damage that can happen by overlooking the seemingly obvious. (Would you want to be the developer that told your boss &amp;quot;Don&amp;#39;t worry about it their Chief,&amp;nbsp;our security is pimped&amp;nbsp;out .&amp;nbsp; We got those passwords hashed and locked down&amp;quot; only to read&amp;nbsp;some guy&amp;#39;s blog showing you blew&amp;nbsp;it?)&amp;nbsp; Whenever someone thinks their security is breached, you often hear complex impressive sounding explanations of the exploit, but in reality, what usually happens is either they were wrong about being hacked in the first place, or they or someone else actually gave away information and didn&amp;#39;t realize it.&amp;nbsp; I remember reading 2600 back in the day, then reading &lt;a href="http://www.kevinmitnick.com/" target="_blank"&gt;Kevin Mitnick&amp;#39;s&lt;/a&gt; book and&amp;nbsp;&lt;a href="http://en.wikipedia.org/wiki/Kevin_Mitnick" target="_blank"&gt;Mitnick&amp;#39;s&lt;/a&gt; whole game was&amp;nbsp;&lt;a href="http://en.wikipedia.org/wiki/Social_engineering_(computer_security)" target="_blank"&gt;Social Engineering&lt;/a&gt; and using people (the weakest link in the chain) to handle business)&amp;nbsp; I would&amp;nbsp; guess that creating a strong password and changing it regularly would protect you from a lot of things. Keeping the password to yourself and learning enough about your software that you can manage basic functions yourself probably doesn&amp;#39;t hurt either.&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;On a less serious note&amp;nbsp;(There&amp;#39;s a blogger who&amp;#39;s loves trashing Community Server and digs Wordpress.&amp;nbsp; Now I know the mere mention of the name Anthony or Wordpress, is enough to fan the flames of &lt;a href="http://blog.charlescarroll.com/chazblog/?s=Anthony" target="_blank"&gt;of any love-struck fool&amp;#39;s man-crush&lt;/a&gt;&amp;nbsp;so my apologies if I got anyone excited. the mere mention of &lt;a href="http://blog.charlescarroll.com/chazblog/?s=Anthony" target="_blank"&gt;Anthony&lt;/a&gt;&amp;nbsp;is enough to make the poor guy start babbling about Ryan O pulling off exploits that would make the KGB jealous.&amp;nbsp; RO&amp;#39;s hacking skills are about as real as&amp;nbsp; A&amp;nbsp;&amp;amp; Mel&amp;#39;s wedding date (&amp;nbsp;although CC doesn&amp;#39;t get complains about how RO won&amp;#39;t ever get himself some hacking skills&amp;nbsp;so maybe my analogy isn&amp;#39;t so good).&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1369953" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Mindless+Babbling/default.aspx">Mindless Babbling</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Misc+Technology/default.aspx">Misc Technology</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Security/default.aspx">Security</category></item><item><title>Protecting your laptop data like a Pro</title><link>http://msmvps.com/blogs/williamryan/archive/2007/11/29/protecting-your-laptop-data-like-a-pro.aspx</link><pubDate>Thu, 29 Nov 2007 17:47:50 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1369386</guid><dc:creator>William</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/williamryan/rsscomments.aspx?PostID=1369386</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/williamryan/commentapi.aspx?PostID=1369386</wfw:comment><comments>http://msmvps.com/blogs/williamryan/archive/2007/11/29/protecting-your-laptop-data-like-a-pro.aspx#comments</comments><description>&lt;p&gt;&lt;a href="http://www.wired.com/politics/security/commentary/securitymatters/2007/11/securitymatters_1129" target="_blank"&gt;Nothing too shocking if you take protecting your data seriously&lt;/a&gt;, but a good read nonetheless.&amp;nbsp; These days, depending on what you do, a stolen laptop could make front page news, a little precaution goes a long way&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1369386" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Misc+Technology/default.aspx">Misc Technology</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Mobility/default.aspx">Mobility</category><category domain="http://msmvps.com/blogs/williamryan/archive/tags/Security/default.aspx">Security</category></item></channel></rss>