<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Agility Loop &#187; Security</title>
	<atom:link href="http://agilityloop.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://agilityloop.com</link>
	<description>The musings of the agile on the world of tech and government</description>
	<lastBuildDate>Wed, 01 Sep 2010 14:30:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='agilityloop.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/8815df9dd02a5349e4cbc3ebe20123b8?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>Agility Loop &#187; Security</title>
		<link>http://agilityloop.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://agilityloop.com/osd.xml" title="Agility Loop" />
	<atom:link rel='hub' href='http://agilityloop.com/?pushpress=hub'/>
		<item>
		<title>Only Some Special Characters Allowed?</title>
		<link>http://agilityloop.com/2010/08/02/only-some-special-characters-allowed/</link>
		<comments>http://agilityloop.com/2010/08/02/only-some-special-characters-allowed/#comments</comments>
		<pubDate>Mon, 02 Aug 2010 04:07:08 +0000</pubDate>
		<dc:creator>Kevin Heald</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[gaming]]></category>
		<category><![CDATA[passwords]]></category>

		<guid isPermaLink="false">http://agilityloop.com/?p=144</guid>
		<description><![CDATA[So today I decided that I wanted to try and relive ten years ago when Starcraft was released and bought Starcraft II. Go ahead Jiloty&#8230;if you read this feel free to say NERDS! Anyhow, when creating a Battle.net account, I was a bit nonplussed when only certain special characters were allowed for the password for [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=agilityloop.com&amp;blog=7372259&amp;post=144&amp;subd=agilityloop&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>So today I decided that I wanted to try and relive ten years ago when Starcraft was released and bought <a href="http://us.battle.net/sc2/en/">Starcraft II</a>.</p>
<p>Go ahead Jiloty&#8230;if you read this feel free to say NERDS!</p>
<p>Anyhow, when creating a <a href="http://www.battle.net">Battle.net</a> account, I was a bit nonplussed when only certain special characters were allowed for the password for my account.  Huh?  I realize this is probably a limitation of some legacy code or software riding on Battle.net, but this seems like something that should be a thing of the past.  I have run into this on other sites as well, some of which are fairly high end enterprise sites (although Battle.net at this point is pretty damn high end).  By limiting the special characters that can be used for passwords, Blizzard is limiting password strength artificially.  Granted, password strength is a bit overrated when users are probably using pet names or school mascots as passwords&#8230;</p>
<br /> Tagged: <a href='http://agilityloop.com/tag/gaming/'>gaming</a>, <a href='http://agilityloop.com/tag/passwords/'>passwords</a>, <a href='http://agilityloop.com/tag/security/'>Security</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/agilityloop.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/agilityloop.wordpress.com/144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/agilityloop.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/agilityloop.wordpress.com/144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/agilityloop.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/agilityloop.wordpress.com/144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/agilityloop.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/agilityloop.wordpress.com/144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/agilityloop.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/agilityloop.wordpress.com/144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/agilityloop.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/agilityloop.wordpress.com/144/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/agilityloop.wordpress.com/144/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/agilityloop.wordpress.com/144/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=agilityloop.com&amp;blog=7372259&amp;post=144&amp;subd=agilityloop&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://agilityloop.com/2010/08/02/only-some-special-characters-allowed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7052384430b7f7d78ce1dbc5022cdd90?s=96&#38;d=identicon&#38;r=PG" medium="image">
			<media:title type="html">healdkw</media:title>
		</media:content>
	</item>
		<item>
		<title>Web Tidbits #1</title>
		<link>http://agilityloop.com/2010/06/30/web-tidbits-1/</link>
		<comments>http://agilityloop.com/2010/06/30/web-tidbits-1/#comments</comments>
		<pubDate>Wed, 30 Jun 2010 18:09:27 +0000</pubDate>
		<dc:creator>Kevin Heald</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[contracting]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[tokenization]]></category>

		<guid isPermaLink="false">http://agilityloop.com/?p=134</guid>
		<description><![CDATA[I know there are other tools out there to find out what has been interesting on the web over the last week.  However, the overwhelming flow of information on Google Buzz and Twitter sometimes makes it difficult to keep up.  So, I am going to start a weekly post that will highlight some interesting articles [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=agilityloop.com&amp;blog=7372259&amp;post=134&amp;subd=agilityloop&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I know there are other  tools out there to find out what has been interesting on the web over  the last week.  However, the overwhelming flow of information on Google  Buzz and Twitter sometimes makes it difficult to keep up.  So, I am  going to start a weekly post that will highlight some interesting  articles from the web, mostly the blogosphere, in relation to security,  cyber, and government contracting.  Don’t be surprised though if I sneak in a couple of goofy links from time to time.</p>
<p style="padding-left:30px;"><a href="http://cybersecurityreport.nextgov.com/2010/06/continuous_monitoring_excuses.php">Bill Puts  Contractors Out of Work</a> &#8211; NextGov<br />
There a ton of articles that document  the government’s efforts to trim down the contractor workforce.  This  particular article focuses in on how the beltway bandit establishment  are fighting against change that may effect their wallets.</p>
<p style="padding-left:30px;"><a href="http://www.securosis.com/blog/understanding-and-selecting-a-tokenization-solution-introduction/">Understanding and  Selecting a Tokenization Solution: Introduction</a> &#8211; Securosis Blog<br />
An in-depth  introduction to tokenization in enterprise applications.  I actually  stumbled upon this blog a couple of weeks ago and it is well worth  following.  They cover a variety of security topics including log  management, network data flow, and secure application development.</p>
<p style="padding-left:30px;"><a href="http://cybersecurityreport.nextgov.com/2010/06/paying_for_classified_security.php">Paying for  Classified Security</a> &#8211; NextGov<br />
An article that details the $$$s spent by the  federal government on information security.  Ironically enough the  costs were actually down between 2008 and 2009, although the number is  still at $4.26 billion dollars&#8230;not including what the intelligence  community spends.</p>
<p style="padding-left:30px;"><a href="http://www.kforcegov.com/Services/IS/NightWatch.aspx">Nightwatch</a><br />
This less about an  article and more about Nightwatch overall.  Great feed to follow to read  in-depth goings on in the rest of the world.  Most updates feature  editor commentary that give greater insight into situation such as the  North Korean/South Korean submarine debacle.</p>
<p style="padding-left:30px;"><a href="http://www.schneier.com/blog/archives/2010/06/cryptography_su.html">Cryptography  Success Story</a> &#8211; Schneier on Security<br />
A link to an article showcasing where  encryption of a hard drive actually foiled both Brazilian authorities  and the FBI.  Certainly a good thing from a protection perspecitve, but  maybe not so good from an inteligence collecting angle.  The comments on  Schneier’s blogs are always insightful (and entertaining) as well.</p>
<br /> Tagged: <a href='http://agilityloop.com/tag/contracting/'>contracting</a>, <a href='http://agilityloop.com/tag/encryption/'>encryption</a>, <a href='http://agilityloop.com/tag/government-2/'>government</a>, <a href='http://agilityloop.com/tag/security/'>Security</a>, <a href='http://agilityloop.com/tag/tokenization/'>tokenization</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/agilityloop.wordpress.com/134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/agilityloop.wordpress.com/134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/agilityloop.wordpress.com/134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/agilityloop.wordpress.com/134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/agilityloop.wordpress.com/134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/agilityloop.wordpress.com/134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/agilityloop.wordpress.com/134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/agilityloop.wordpress.com/134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/agilityloop.wordpress.com/134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/agilityloop.wordpress.com/134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/agilityloop.wordpress.com/134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/agilityloop.wordpress.com/134/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/agilityloop.wordpress.com/134/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/agilityloop.wordpress.com/134/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=agilityloop.com&amp;blog=7372259&amp;post=134&amp;subd=agilityloop&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://agilityloop.com/2010/06/30/web-tidbits-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7052384430b7f7d78ce1dbc5022cdd90?s=96&#38;d=identicon&#38;r=PG" medium="image">
			<media:title type="html">healdkw</media:title>
		</media:content>
	</item>
		<item>
		<title>Jack Goldsmith and Melissa Hathaway &#8211; The cybersecurity changes we need</title>
		<link>http://agilityloop.com/2010/05/29/jack-goldsmith-and-melissa-hathaway-the-cybersecurity-changes-we-need/</link>
		<comments>http://agilityloop.com/2010/05/29/jack-goldsmith-and-melissa-hathaway-the-cybersecurity-changes-we-need/#comments</comments>
		<pubDate>Sat, 29 May 2010 14:33:11 +0000</pubDate>
		<dc:creator>Kevin Heald</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[government]]></category>

		<guid isPermaLink="false">http://agilityloop.com/?p=125</guid>
		<description><![CDATA[In today&#8217;s post, Jack Goldsmith and Melissa Hathaway contributed an article entitled &#8220;The cybersecurity changes we need&#8220;.  The authors criticize the current administration in their approach to cybersecurity and state that it is focusing on short term gains rather than the long term. I have become a little exasperated by all of the sword rattling [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=agilityloop.com&amp;blog=7372259&amp;post=125&amp;subd=agilityloop&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>In today&#8217;s post, Jack Goldsmith and Melissa Hathaway contributed an article entitled<a href="http://www.washingtonpost.com/wp-dyn/content/article/2010/05/28/AR2010052803698.html?hpid=opinionsbox1"> &#8220;The cybersecurity changes we need</a>&#8220;.  The authors criticize the current administration in their approach to cybersecurity and state that it is focusing on short term gains rather than the long term.</p>
<p>I have become a little exasperated by all of the <a href="http://www.wired.com/dangerroom/2010/05/cyberwar-cassandras-get-400-million-in-conflict-cash/?utm_source=feedburner&amp;utm_medium=feed&amp;utm_campaign=Feed%3A+wired%2Findex+%28Wired%3A+Index+3+%28Top+Stories+2%29%29&amp;utm_content=Google+Feedfetcher">sword rattling</a> and cheesy <a href="http://www.umuc.edu/umucmedia/press/news312.shtml">commercials</a> using the public&#8217;s fear of &#8220;taking down the power grid&#8221;.   I had hope for the article when it started:</p>
<blockquote><p><em>The news is filled with scary stories about the insecurity of the  computer and telecommunication systems on which our nation&#8217;s prosperity  depends: malicious software planted in electricity-grid computers;  rampant state-sponsored and criminal cyber-espionage and theft; and the  possibility of cyberattacks on banking and transportation systems.</em></p></blockquote>
<p>However, rather than make suggestions on what should be done, they take the rest of the article to criticize the administration for paying lip service  to cybersecurity and policies that have been established.  I don&#8217;t necessarily disagree with that thought, but I also think it is always more useful for all if a plan, even a high level one, is proposed.  <em></em></p>
<p>Cybersecurity (or insecurity) is DEFINITELY a threat as we all become increasingly &#8220;plugged in&#8221;.  BUT, like most topics that have billions associated with it, they hype can become quickly overblown into fears that the Chinese are hacking into the power grid on a regular basis.  A plan is all well and good, but a lack of high level influence within the administration has been a deterrent to actually getting things done.  The establishment of a cyber command, although somewhat scary due to its ties to the NSA, is a good first step.  One thing that I have learned while working in the military is that when shit hits the fan, it actually gets done.</p>
<br /> Tagged: <a href='http://agilityloop.com/tag/cyber/'>cyber</a>, <a href='http://agilityloop.com/tag/cybersecurity/'>cybersecurity</a>, <a href='http://agilityloop.com/tag/government-2/'>government</a>, <a href='http://agilityloop.com/tag/security/'>Security</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/agilityloop.wordpress.com/125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/agilityloop.wordpress.com/125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/agilityloop.wordpress.com/125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/agilityloop.wordpress.com/125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/agilityloop.wordpress.com/125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/agilityloop.wordpress.com/125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/agilityloop.wordpress.com/125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/agilityloop.wordpress.com/125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/agilityloop.wordpress.com/125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/agilityloop.wordpress.com/125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/agilityloop.wordpress.com/125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/agilityloop.wordpress.com/125/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/agilityloop.wordpress.com/125/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/agilityloop.wordpress.com/125/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=agilityloop.com&amp;blog=7372259&amp;post=125&amp;subd=agilityloop&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://agilityloop.com/2010/05/29/jack-goldsmith-and-melissa-hathaway-the-cybersecurity-changes-we-need/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7052384430b7f7d78ce1dbc5022cdd90?s=96&#38;d=identicon&#38;r=PG" medium="image">
			<media:title type="html">healdkw</media:title>
		</media:content>
	</item>
		<item>
		<title>Blippy Credit Card Data Breach</title>
		<link>http://agilityloop.com/2010/04/23/blippy-credit-card-data-breach/</link>
		<comments>http://agilityloop.com/2010/04/23/blippy-credit-card-data-breach/#comments</comments>
		<pubDate>Fri, 23 Apr 2010 18:48:39 +0000</pubDate>
		<dc:creator>Kevin Heald</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[web2.0]]></category>

		<guid isPermaLink="false">http://agilityloop.com/?p=111</guid>
		<description><![CDATA[Blippy,  a company that enables users to share their credit card purchases, today provided details on a breach of credit card information.  Turns out that four credit card numbers were searchable via Google.  The beginning of their response: Today someone discovered a Google search that displays the credit card numbers of 4 Blippy users. We [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=agilityloop.com&amp;blog=7372259&amp;post=111&amp;subd=agilityloop&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.blippy.com">Blippy</a>,  a company that enables users to share their credit card purchases, today provided <a href="http://techcrunch.com/2010/04/23/blippys-response-to-credit-card-data-breach-its-a-lot-less-bad-than-it-looks/">details</a> on a breach of credit card information.  Turns out that four credit card numbers were searchable via Google.  The beginning of their response:</p>
<blockquote><p><em>Today someone discovered a Google search that displays the credit card numbers of 4 Blippy users.</em></p>
<p><em>We take security seriously and want to assure Blippy users that this was an isolated incident from many months ago in our beta test, and doesn’t affect current users.</em></p>
<p><em><strong>While it looks super-scary and certainly sucks for those few people who were affected, and is embarrassing to us, it’s a lot less bad than it looks.</strong></em></p></blockquote>
<p>Although I feel a &#8220;less bad&#8221; for these four folks, WHAT THE !@!$@!$ DID YOU EXPECT?  It is one thing to use your credit card online for purchases, but it is a whole new level of voyeurism that drives you to share your credit card number for the purposes of telling the world what you are buying.</p>
<p>&#8220;Hello world&#8230;I just bought an fully capable inflatable sheep for $19.99.  I promise it is just as a gag&#8230;honest.&#8221;</p>
<br /> Tagged: <a href='http://agilityloop.com/tag/cyber/'>cyber</a>, <a href='http://agilityloop.com/tag/security/'>Security</a>, <a href='http://agilityloop.com/tag/web2-0/'>web2.0</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/agilityloop.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/agilityloop.wordpress.com/111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/agilityloop.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/agilityloop.wordpress.com/111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/agilityloop.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/agilityloop.wordpress.com/111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/agilityloop.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/agilityloop.wordpress.com/111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/agilityloop.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/agilityloop.wordpress.com/111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/agilityloop.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/agilityloop.wordpress.com/111/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/agilityloop.wordpress.com/111/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/agilityloop.wordpress.com/111/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=agilityloop.com&amp;blog=7372259&amp;post=111&amp;subd=agilityloop&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://agilityloop.com/2010/04/23/blippy-credit-card-data-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7052384430b7f7d78ce1dbc5022cdd90?s=96&#38;d=identicon&#38;r=PG" medium="image">
			<media:title type="html">healdkw</media:title>
		</media:content>
	</item>
		<item>
		<title>Hacintosh?</title>
		<link>http://agilityloop.com/2010/02/19/hacintosh/</link>
		<comments>http://agilityloop.com/2010/02/19/hacintosh/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 12:51:36 +0000</pubDate>
		<dc:creator>Kevin Heald</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://agilityloop.com/?p=102</guid>
		<description><![CDATA[A article over at PCWorld yesterday entitled Hacking Impresario: &#8216;Windows Safer Than Mac&#8217; quotes the organizer of Pwn2Own stating that Windows 7 is more secure than Snow Leopard. Contest organizer Aaron Portnoy, who is the security research team lead with 3Com TippingPoint, the sponsor of Pwn2Own, told Computerworld&#8217;s Gregg Keizer that: &#8220;Safari will be the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=agilityloop.com&amp;blog=7372259&amp;post=102&amp;subd=agilityloop&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>A article over at PCWorld yesterday entitled <a href="http://www.pcworld.com/article/189760/hacking_impresario_windows_safer_mac.html?tk=rss_news">Hacking Impresario: &#8216;Windows Safer Than Mac&#8217;</a> quotes the organizer of <a href="http://dvlabs.tippingpoint.com/blog/2009/02/25/pwn2own-2009">Pwn2Own</a> stating that Windows 7 is more secure than Snow Leopard.</p>
<blockquote><p>Contest organizer Aaron Portnoy, who is the security research team lead with 3Com TippingPoint, the sponsor of Pwn2Own, <a href="http://www.computerworld.com/s/article/9157898/Apple_s_Safari_to_fall_first_in_hacking_contest_..._again">told Computerworld&#8217;s Gregg Keizer </a>that:</p>
<p>&#8220;Safari will be the first to go. [Safari will] be on Snow Leopard, which isn&#8217;t on the same level as Windows 7.&#8221;</p></blockquote>
<p>Of course this stance is disputed by other security impresarios (talk about an author using a thesaurus).</p>
<p>Microsoft has been THE target of hackers for so long that they had to have learned.  Mac has had the privilege of being under the radar for a long time since they were the plucky underdog.  However, as their sales rise, more hackers will start targeting the platform.</p>
<p>And it also shows that marketing is a really king.  For years I have said that a large part of Microsoft&#8217;s rise as been marketing.  Mac has been touting its security and I even hear my parent&#8217;s telling me Mac&#8217;s are more secure!  I doubt this will perception will change any time soon, but it is a little vindicating to see reality starting to bubble up in the press.</p>
<br /> Tagged: <a href='http://agilityloop.com/tag/mac/'>mac</a>, <a href='http://agilityloop.com/tag/microsoft/'>Microsoft</a>, <a href='http://agilityloop.com/tag/security/'>Security</a>, <a href='http://agilityloop.com/tag/windows/'>Windows</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/agilityloop.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/agilityloop.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/agilityloop.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/agilityloop.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/agilityloop.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/agilityloop.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/agilityloop.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/agilityloop.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/agilityloop.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/agilityloop.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/agilityloop.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/agilityloop.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/agilityloop.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/agilityloop.wordpress.com/102/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=agilityloop.com&amp;blog=7372259&amp;post=102&amp;subd=agilityloop&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://agilityloop.com/2010/02/19/hacintosh/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7052384430b7f7d78ce1dbc5022cdd90?s=96&#38;d=identicon&#38;r=PG" medium="image">
			<media:title type="html">healdkw</media:title>
		</media:content>
	</item>
		<item>
		<title>Weak Passwords</title>
		<link>http://agilityloop.com/2010/02/17/weak-passwords/</link>
		<comments>http://agilityloop.com/2010/02/17/weak-passwords/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 22:20:53 +0000</pubDate>
		<dc:creator>Kevin Heald</dc:creator>
				<category><![CDATA[Identity]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[password]]></category>

		<guid isPermaLink="false">http://agilityloop.com/?p=96</guid>
		<description><![CDATA[President Skroob: [enters after the interrogation of King Roland] Well? Did it work? Where&#8217;s the king? Dark Helmet: It worked, sir. We have the combination. President Skroob: Great. Now we can take every last breath of fresh air from planet Druidia. What&#8217;s the combination? Dark Helmet: 1 2 3 4 5. President Skroob: 1 2 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=agilityloop.com&amp;blog=7372259&amp;post=96&amp;subd=agilityloop&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="padding-left:30px;"><em><a href="http://agilityloop.files.wordpress.com/2010/02/21082009986582160-17920.gif"><img class="size-thumbnail wp-image-97 alignright" title="21082009986582160-17920" src="http://agilityloop.files.wordpress.com/2010/02/21082009986582160-17920.gif?w=150&#038;h=112" alt="" width="150" height="112" /></a>President Skroob: [enters after the interrogation of King Roland] Well? Did it work? Where&#8217;s the king?<br />
Dark Helmet: It worked, sir. We have the combination.<br />
President Skroob: Great. Now we can take every last breath of fresh air from planet Druidia. What&#8217;s the combination?<br />
Dark Helmet: 1 2 3 4 5.<br />
President Skroob: 1 2 3 4 5? That&#8217;s amazing! I&#8217;ve got the same combination on my luggage! Prepare Spaceball 1 for immediate departure!<br />
Dark Helmet: Yes, sir!<br />
President Skroob: And change the combination on my luggage!</em></p>
<p>It may seem like a juvenile comparison, but the above is actually not too far off when it comes to the passwords people use.  Almost a month ago, a security firm called iMPERVA analyzed the passwords of the 32 million accounts that were exposed in a recent <a id="usc6" title="hack" href="http://techcrunch.com/2009/12/14/rockyou-hacked/">hack</a> of the RockYou service (full report in this <a href="http://www.imperva.com/docs/WP_Consumer_Password_Worst_Practices.pdf">pdf</a>).  As <a id="asu4" title="Ars Technica" href="http://arstechnica.com/security/news/2010/01/32-million-passwords-show-most-users-careless-about-security.ars?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=rss">Ars Technica</a> highlights, the results were not pretty.</p>
<blockquote><p><em>…about a third are less than six characters, and half are vulnerable to dictionary attacks. The most common password was 123456, and it was followed by 12345, 123456789, and Password. iMPERVA estimates that someone with a slow DSL connection could access one account a second using a dictionary attack.</em></p></blockquote>
<p><em> </em></p>
<p>To exacerbate the problem, it appeared that RockYou was pretty amateurish in their approach to security.  So not only were the passwords weak, it was just as easy to expose the entire password database.  In other words, many sites either don&#8217;t care, or don&#8217;t care to spend money, on making sure you are secure.</p>
<p>So what constitutes a strong password?  There is plenty of guidance out there.  The report quotes NASA Recommendations, which are fairly consistent with other recommendations.  These are probably the same recommendations some of you deal with at work.</p>
<ol>
<li>The password should be at least eight characters</li>
<li>It should contain a mix of four different types of characters – upper case letters, lower case letters, numbers, and special characters such as !@#$%^&amp;*.</li>
<li>It should not be a name, a slang word, or any word in the dictionary. It should not include any part of your name or your e-mail address.</li>
</ol>
<p>The report goes further by recommending you use different strong passwords for each site you visit.  Although this sounds great from a security perspecitive, it is also unrealistic.</p>
<p>Typically my approach is to use a similar password (with slightly different combinations of case and special characters) for sites that I consider throw away.  Yes, they may have some of privacy information, but nothing too damaging.  Think WashingtonPost.com or Slate.  HOWEVER, for important sites like banking and email, I do use a different unique password.  These sites are simply too important if they are compromised.  One <a href="http://www.guardian.co.uk/technology/2008/nov/13/internet-passwords">technique</a> is to use a sentence to create a password such as “This little piggy went to market” might become &#8220;tlpWENT2m&#8221;.  That nine-character password won&#8217;t be in anyone&#8217;s dictionary.”</p>
<p>And of course you need a strong password for Facebook to prevent Statusjacking.</p>
<p>Of course then you have to remember all the different passwords.  There are some apps out there that actually do <a href="http://windowssecrets.com/links/$P20d/8bc127h/?url=www.windowssecrets.com%2F2008%2F09%2F18%2F04-Password-managers-keep-your-login-data-handy">help with this</a>.  I am going to take some time this week to take a look at solutions that will work on my PC and my Droid.</p>
<p>The real solution is to get rid of passwords completely and adopt stronger forms of authentication.  I blogged about awhile ago, that will only really happen until it becomes <a href="http://agilityloop.com/2009/05/19/seat-belts-and-the-password-problem/">prohibitively expensive and painful</a> for banks, credit card companies, etc to support just passwords.</p>
<br /> Tagged: <a href='http://agilityloop.com/tag/authentication/'>authentication</a>, <a href='http://agilityloop.com/tag/password/'>password</a>, <a href='http://agilityloop.com/tag/security/'>Security</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/agilityloop.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/agilityloop.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/agilityloop.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/agilityloop.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/agilityloop.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/agilityloop.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/agilityloop.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/agilityloop.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/agilityloop.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/agilityloop.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/agilityloop.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/agilityloop.wordpress.com/96/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/agilityloop.wordpress.com/96/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/agilityloop.wordpress.com/96/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=agilityloop.com&amp;blog=7372259&amp;post=96&amp;subd=agilityloop&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://agilityloop.com/2010/02/17/weak-passwords/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7052384430b7f7d78ce1dbc5022cdd90?s=96&#38;d=identicon&#38;r=PG" medium="image">
			<media:title type="html">healdkw</media:title>
		</media:content>

		<media:content url="http://agilityloop.files.wordpress.com/2010/02/21082009986582160-17920.gif?w=150" medium="image">
			<media:title type="html">21082009986582160-17920</media:title>
		</media:content>
	</item>
		<item>
		<title>The Certificate Revocation List Distribution Point</title>
		<link>http://agilityloop.com/2009/06/26/the-certificate-revocation-list-distribution-point/</link>
		<comments>http://agilityloop.com/2009/06/26/the-certificate-revocation-list-distribution-point/#comments</comments>
		<pubDate>Fri, 26 Jun 2009 12:47:08 +0000</pubDate>
		<dc:creator>Kevin Heald</dc:creator>
				<category><![CDATA[PKI]]></category>
		<category><![CDATA[crl]]></category>
		<category><![CDATA[crldp]]></category>
		<category><![CDATA[revocation]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://agilityloop.com/?p=60</guid>
		<description><![CDATA[The Certificate Revocation List Distribution Point (CRLDP or CDP) is the attribute in a PKI certificate that tells a relying party where to retrieve the signed binary file that contains a list of revoked certificates (there are other reason codes that can be used, be most clients essentially still interpret those certificates as revoked).  This [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=agilityloop.com&amp;blog=7372259&amp;post=60&amp;subd=agilityloop&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://tools.ietf.org/html/rfc3280#page-42">Certificate Revocation List Distribution Point</a> (CRLDP or CDP) is the attribute in a PKI certificate that tells a relying party where to retrieve the signed binary file that contains a list of revoked certificates (there are other reason codes that can be used, be most clients essentially still interpret those certificates as revoked).  This file is generated by the Certificate Authority (CA) on a regular basis.  This is one way that applications and systems can verify the revocation status of a certificate (there are other <a href="http://agilityloop.com/2009/06/24/revocation-checking-in-pki/">methods</a> as well).</p>
<p>The challenge associated with CRLs, and the CRLDP for that matter, is getting those files down to each relying party.  This is mainly a problem is larger PKIs.  In smaller PKIs, the CRLs are small enough that clients and server shouldn&#8217;t have too much trouble downloading the files (although some CRL retrieval implementations are very brittle).  For larger PKIs, this becomes more and more of problem as the PKI grows.  The CRL files get larger, and since each CA issues a CRL and larger PKIs may have multiple CAs, there may be multiple files to contend with.  As your users use your PKI more, more relying parties have to verify those certificates.  The bandwidth demands can grow exponentially, stressing your infrastructure and potentially preventing some relying parties from actually retrieving the information.</p>
<p>Early on in PKI, <a href="http://en.wikipedia.org/wiki/Ldap">LDAP</a> was used for many CRLDPs.  However, LDAP is actually blocked at some firewalls.  In addition, as LDAP is an older protocol, it doesn&#8217;t offer you the same advantages as using a HTTP reference.  By using HTTP in the CRLDP, you can take full advantage of HTTP 1.1 enhancements like resumption and compression.</p>
<p>However, one must be cautious to not get too fancy on how they actually serve the CRL content.  Most PKI implementations on the relying party side are fairly simple.  There is typically no user interaction when retrieving the CRL&#8230;it happens in the background.</p>
<p>In my experience, it is best to take advantage of what web servers do best&#8230;serve static content.  It is tempting to make use of scripts or applets in serving CRLs.  One not make the reference a &#8220;dynamic&#8221; URL that includes the passing of a parameter to Java App?  That is certainly an option, but I truly believe that in PKI where you can make it simple, keep it simple. In addition, many web proxies will actually not be able to cache this content without manual intervention (although to be fair, many PKI implementations use http conventions like <em>pragma: no cache</em> to force the retrieval of the freshest CRL).</p>
<p>So instead of <a title="In case you are wondering, this is a fake url" href="http://pki.company.com/crls/CA11.crl">http://pki.company.com/crlscript?CA11</a>, use <a title="Oh, and this is a fake URL too." href="http://pki.company.com/crls/CA11.crl">http://pki.company.com/crls/CA11.crl</a>.  Local users and networks can then easily replicate this directory through mirroring using standard scripts, FTP clients, and/ordownload managers.  By locally caching the content, the Infrastructure piece of your PKI will incur less bandwidth stress and you&#8217;ll have less headaches.</p>
<br /> Tagged: crl, crldp, PKI, revocation, Security <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/agilityloop.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/agilityloop.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/agilityloop.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/agilityloop.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/agilityloop.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/agilityloop.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/agilityloop.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/agilityloop.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/agilityloop.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/agilityloop.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/agilityloop.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/agilityloop.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/agilityloop.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/agilityloop.wordpress.com/60/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=agilityloop.com&amp;blog=7372259&amp;post=60&amp;subd=agilityloop&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://agilityloop.com/2009/06/26/the-certificate-revocation-list-distribution-point/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7052384430b7f7d78ce1dbc5022cdd90?s=96&#38;d=identicon&#38;r=PG" medium="image">
			<media:title type="html">healdkw</media:title>
		</media:content>
	</item>
		<item>
		<title>Seat Belts and the Password Problem</title>
		<link>http://agilityloop.com/2009/05/19/seat-belts-and-the-password-problem/</link>
		<comments>http://agilityloop.com/2009/05/19/seat-belts-and-the-password-problem/#comments</comments>
		<pubDate>Tue, 19 May 2009 22:23:47 +0000</pubDate>
		<dc:creator>Kevin Heald</dc:creator>
				<category><![CDATA[PKI]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[identity management]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[dod]]></category>
		<category><![CDATA[Identity]]></category>

		<guid isPermaLink="false">http://agilityloop.wordpress.com/?p=31</guid>
		<description><![CDATA[I actually used WordPress&#8217;s &#8220;Tag Surfer&#8221; feature for the first time today, and stumbled upon a post on Identity Blogger.   In his post, Jeff Bohren discusses the challenge of getting users to adopt passwords.  He also references a post by Mark Dixon on the same topic. I think both articles make good points&#8230;intellectually it makes [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=agilityloop.com&amp;blog=7372259&amp;post=31&amp;subd=agilityloop&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I actually used WordPress&#8217;s &#8220;Tag Surfer&#8221; feature for the first time today, and stumbled upon a <a href="http://idlogger.wordpress.com/2009/05/14/cheap-and-easy/">post</a> on Identity Blogger.   In his post, Jeff Bohren discusses the challenge of getting users to adopt passwords.  He also references a <a href="http://blogs.sun.com/identity/entry/seat_belts_and_passwords_and">post</a> by Mark Dixon on the same topic.</p>
<p>I think both articles make good points&#8230;intellectually it makes a TON of sense to get rid of passwords.  Mark actually makes an interesting point that passwords are like seatbelts.</p>
<blockquote><p><em>It was ease of use, not a technology-driven obsession with safety,  that led to wide adoption of the seat belt.</em></p></blockquote>
<p>What I do not agree with is <strong>why </strong>seat belts were adopted.  I don&#8217;t think it is just because seat belts are easy to use and they make us safer.  A lot of the reason that I think a lot of people started to use seat belts is it because it became law.  States started <a href="http://wiki.answers.com/Q/What_year_did_seat_belts_become_mandatory">mandating</a> seat belt use in 1984, and very quickly the states all fell in line and start adopting it.  So instead of <strong>choosing</strong><em> </em>to use seat belts, people were <strong>required<em> </em></strong>to use seat belts or they broke the law.  A fortunate side effect to making this a law is that now for generations that drive after this law was enacted (like my own), wearing seat belts is second nature.</p>
<p>I believe that a similar kind of action is going to be needed for web applications and enterprises to get off passwords.  However, it may not be the Government that actually steps in to mandate this&#8230;at least not directly.  As it stands now, banks and credit card companies have the ability to write off fraud when accounts are stolen.  So the cost is really passed on&#8230;they aren&#8217;t really paying the $40 billion plus in fraud every year.  But what would happen if banks and credit card companies were limited in how much fraud they could actually write off?  I think that all of a sudden you would see a HUGE uptake in the use of improved identity technologies and the discontinued use of passwords.  Users would be forced to stop using passwords b/c the banks and credit cards would be financially dis-incentivized to support them any longer.  Of course the financial institutions would still find a way to pass the costs onto the consumer or the government&#8230;</p>
<p>A quick and dirty case study for you.  DoD has been issuing smart cards to their population of 4+ million for years.  The primary use for a long time was secure email.  It wasn&#8217;t until it was mandated by DoD that the cards be used for log on to networks and applications that passwords finally started going away.  Sure it was painful, but the networks are now more secure b/c of it.</p>
<p>In my experience, people don&#8217;t necessarily change b/c it is good for them or b/c it is easy.  They do it b/c there is a dis-incentive to continue the status quo.</p>
<br /> Tagged: authentication, dod, Identity, Security <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/agilityloop.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/agilityloop.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/agilityloop.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/agilityloop.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/agilityloop.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/agilityloop.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/agilityloop.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/agilityloop.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/agilityloop.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/agilityloop.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/agilityloop.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/agilityloop.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/agilityloop.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/agilityloop.wordpress.com/31/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=agilityloop.com&amp;blog=7372259&amp;post=31&amp;subd=agilityloop&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://agilityloop.com/2009/05/19/seat-belts-and-the-password-problem/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7052384430b7f7d78ce1dbc5022cdd90?s=96&#38;d=identicon&#38;r=PG" medium="image">
			<media:title type="html">healdkw</media:title>
		</media:content>
	</item>
		<item>
		<title>HSIN Hacked</title>
		<link>http://agilityloop.com/2009/05/15/hsin-hacked/</link>
		<comments>http://agilityloop.com/2009/05/15/hsin-hacked/#comments</comments>
		<pubDate>Fri, 15 May 2009 19:32:55 +0000</pubDate>
		<dc:creator>Kevin Heald</dc:creator>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[dhs]]></category>
		<category><![CDATA[hsin]]></category>

		<guid isPermaLink="false">http://agilityloop.wordpress.com/?p=26</guid>
		<description><![CDATA[Tidbit from a recent article on FCW detailing on the Homeland Security Information Network (HSIN) was recently hacked. The hacker or hackers gained access to the data by getting into the HSIN account of a federal employee or contractor, McDavid said. And some quick details on the sophisitcation of the hack: McDavid said he did [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=agilityloop.com&amp;blog=7372259&amp;post=26&amp;subd=agilityloop&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Tidbit from a recent <a href="http://fcw.com/Articles/2009/05/13/Web-DHS-HSIN-intrusion-hack.aspx">article</a> on FCW detailing on the Homeland Security Information Network (HSIN) was recently hacked.</p>
<blockquote><p><em>The hacker or hackers gained access to the data by getting into the HSIN account of a federal employee or contractor, McDavid said.</em></p></blockquote>
<p>And some quick details on the sophisitcation of the hack:</p>
<blockquote><p><em>McDavid said he did not know of other successful hacks into the platform. He called the tactics used to gain access to the user account “very sophisticated.” However, he said the amount of data accessed was relatively minor and that officials have been able to map exactly what files were accessed.</em></p></blockquote>
<p>Any bets on whether or not this was really just a simple password or social engineering hack?</p>
<br /> Tagged: dhs, hsin, Security <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/agilityloop.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/agilityloop.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/agilityloop.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/agilityloop.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/agilityloop.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/agilityloop.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/agilityloop.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/agilityloop.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/agilityloop.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/agilityloop.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/agilityloop.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/agilityloop.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/agilityloop.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/agilityloop.wordpress.com/26/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=agilityloop.com&amp;blog=7372259&amp;post=26&amp;subd=agilityloop&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://agilityloop.com/2009/05/15/hsin-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7052384430b7f7d78ce1dbc5022cdd90?s=96&#38;d=identicon&#38;r=PG" medium="image">
			<media:title type="html">healdkw</media:title>
		</media:content>
	</item>
		<item>
		<title>Cellcrypt &#8211; Secure Voice for the Blackberry</title>
		<link>http://agilityloop.com/2009/05/15/cellcrypt-secure-voice-for-the-blackberry/</link>
		<comments>http://agilityloop.com/2009/05/15/cellcrypt-secure-voice-for-the-blackberry/#comments</comments>
		<pubDate>Fri, 15 May 2009 12:14:34 +0000</pubDate>
		<dc:creator>Kevin Heald</dc:creator>
				<category><![CDATA[Mobile]]></category>
		<category><![CDATA[PKI]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[blackberry]]></category>
		<category><![CDATA[fips]]></category>
		<category><![CDATA[voice]]></category>

		<guid isPermaLink="false">http://agilityloop.wordpress.com/?p=23</guid>
		<description><![CDATA[Saw a couple of posts throughout the Blackberry blogosphere in relation to a product called Cellcrypt that was presented at this past WES.  Cellcrypt enables users to make secure phone calls on their Blackberry.  The calls are encrypted using AES and the product is currently undergoing FIPS 140-2 certification. I took a quick look at [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=agilityloop.com&amp;blog=7372259&amp;post=23&amp;subd=agilityloop&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Saw a couple of posts throughout the Blackberry blogosphere in relation to a product called <a href="http://www.cellcrypt.com">Cellcrypt</a> that was presented at this past <a href="http://www.attendwes.com/">WES</a>.  Cellcrypt enables users to make secure phone calls on their Blackberry.  The calls are encrypted using AES and the product is currently undergoing <a href="http://en.wikipedia.org/wiki/FIPS_140">FIPS</a> 140-2 certification.</p>
<p>I took a quick look at the <a href="http://www.cellcrypt.com/details.html">tech overview</a> on their website.  To oversimplify, Cellcrypt is essentially SSL for voice on a mobile platform.  When the client is installed, a key is generated for that phone so a key doesn&#8217;t have to be installed.  Although this is certainly convenient, I wonder if it is possible to import a key or even use a smart card?  This would make this an even better solution for enterprises like DoD who already have a robust PKI.</p>
<p>I can envision that if this works as advertised, that an enterprise could stand up the solution for their &#8220;important&#8221; mobile users.  It is not clear how the address book is managed, but as long as this is robust, why couldn&#8217;t a place like DoD roll this out for the enterprise and their DoD users?</p>
<p>Lastly, it is solutions like this that have to make you re-consider the viability of the SME-PED and other such custom secure devices.  Yes, the crypto on these devices is likely a bit more robust (and secret), but who is to say that a chip couldn&#8217;t be swapped in a commercial Blackberry to enable the higher level security?  Even more so, is a solution like Cellcrypt good enough for a lot of the transactions a govt agency uses?  SSL is relied on constantly.</p>
<p>Anyhow, love to see some more geeky details on this product.  Definitely has promise!</p>
<br /> Tagged: blackberry, fips, PKI, Security, voice <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/agilityloop.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/agilityloop.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/agilityloop.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/agilityloop.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/agilityloop.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/agilityloop.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/agilityloop.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/agilityloop.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/agilityloop.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/agilityloop.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/agilityloop.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/agilityloop.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/agilityloop.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/agilityloop.wordpress.com/23/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=agilityloop.com&amp;blog=7372259&amp;post=23&amp;subd=agilityloop&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://agilityloop.com/2009/05/15/cellcrypt-secure-voice-for-the-blackberry/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7052384430b7f7d78ce1dbc5022cdd90?s=96&#38;d=identicon&#38;r=PG" medium="image">
			<media:title type="html">healdkw</media:title>
		</media:content>
	</item>
	</channel>
</rss>