<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ed The Dev .com &#187; Security</title>
	<atom:link href="http://www.edthedev.com/topics/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.edthedev.com</link>
	<description>Edward Delaporte&#039;s Technical Journal</description>
	<lastBuildDate>Fri, 30 Jul 2010 14:20:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Security policy seen as an economic decision</title>
		<link>http://www.edthedev.com/2010/security-policy-seen-as-an-economic-decision/</link>
		<comments>http://www.edthedev.com/2010/security-policy-seen-as-an-economic-decision/#comments</comments>
		<pubDate>Thu, 22 Jul 2010 15:08:43 +0000</pubDate>
		<dc:creator>Edward Delaporte</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.edthedev.com/?p=11084</guid>
		<description><![CDATA[Courtesy of some research papers that Bruce Schneier found.]]></description>
			<content:encoded><![CDATA[<p>Courtesy of <a href="http://www.schneier.com/blog/archives/2010/07/website_passwor_1.html">some research papers that Bruce Schneier found</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.edthedev.com/2010/security-policy-seen-as-an-economic-decision/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Facebook laughs at Privacy</title>
		<link>http://www.edthedev.com/2010/facebook-laughs-at-privacy/</link>
		<comments>http://www.edthedev.com/2010/facebook-laughs-at-privacy/#comments</comments>
		<pubDate>Tue, 08 Jun 2010 00:02:09 +0000</pubDate>
		<dc:creator>Edward Delaporte</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.edthedev.com/?p=10995</guid>
		<description><![CDATA[The Onion has published a great article about Facebook privacy. I laughed pretty hard when I read it.]]></description>
			<content:encoded><![CDATA[<p>The Onion has published a great article about <a href="http://tinyurl.com/2bghwwa">Facebook privacy</a>. I laughed pretty hard when I read it.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.edthedev.com/2010/facebook-laughs-at-privacy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>LifeLock owner&#8217;s identity stolen 13 times</title>
		<link>http://www.edthedev.com/2010/lifelock-owners-identity-stolen-13-times/</link>
		<comments>http://www.edthedev.com/2010/lifelock-owners-identity-stolen-13-times/#comments</comments>
		<pubDate>Sun, 06 Jun 2010 00:00:40 +0000</pubDate>
		<dc:creator>Edward Delaporte</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.edthedev.com/?p=11011</guid>
		<description><![CDATA[LifeLock is an interesting service, but it actually doesn&#8217;t protect that well. I&#8217;ve seen a lot of articles on the subject, but the one I just linked has the best over-all summary of the trade-offs involved with trying to offer the kind of protection that LifeLock sells.]]></description>
			<content:encoded><![CDATA[<p>LifeLock is an interesting service, but it <a href="http://www.cringely.com/2010/05/lifeblocked/">actually doesn&#8217;t protect that well</a>. I&#8217;ve seen a lot of articles on the subject, but the one I just linked has the best over-all summary of the trade-offs involved with trying to offer the kind of protection that LifeLock sells.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.edthedev.com/2010/lifelock-owners-identity-stolen-13-times/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The new best way to make sure that your browser is safe.</title>
		<link>http://www.edthedev.com/2010/the-new-best-way-to-make-sure-that-your-browser-is-safe/</link>
		<comments>http://www.edthedev.com/2010/the-new-best-way-to-make-sure-that-your-browser-is-safe/#comments</comments>
		<pubDate>Fri, 21 May 2010 03:42:51 +0000</pubDate>
		<dc:creator>Edward Delaporte</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Solutions]]></category>

		<guid isPermaLink="false">http://www.edthedev.com/?p=10979</guid>
		<description><![CDATA[Browser plugins are rapidly becoming the most common way to get a computer virus infection. Normally I lecture people about switching to Firefox, installing NoScript and checking at least monthly that Java and Adobe are up to date. The folks at Mozilla seem to be on a quest to save me from forever repeating those [...]]]></description>
			<content:encoded><![CDATA[<p>Browser plugins are rapidly becoming the most common way to get a computer virus infection.</p>

<p>Normally I lecture people about switching to Firefox, installing NoScript and checking at least monthly that Java and Adobe are up to date. The folks at Mozilla seem to be on a quest to save me from forever repeating those instructions, and I thank them kindly.</p>

<p>My instructions are now a bit simpler:</p>

<ol>
<li><p>Switch to Firefox</p></li>
<li><p>Use this website to make sure that you are safe.
<a href="https://www.mozilla.com/en-US/plugincheck/" target="_blank">https://www.mozilla.com/en-US/plugincheck/</a></p></li>
<li><p>Check back with the website weekly.</p></li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://www.edthedev.com/2010/the-new-best-way-to-make-sure-that-your-browser-is-safe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Facebook privacy issues</title>
		<link>http://www.edthedev.com/2010/facebook-privacy-issues/</link>
		<comments>http://www.edthedev.com/2010/facebook-privacy-issues/#comments</comments>
		<pubDate>Sat, 15 May 2010 07:03:01 +0000</pubDate>
		<dc:creator>Edward Delaporte</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.edthedev.com/?p=10953</guid>
		<description><![CDATA[The article is a little reactionary, but it does serve to highlight the things about Facebook that you should be concerned about. Maybe it&#8217;s time to join me over at Google Buzz? All seven Google Buzz users are looking forward to your company.]]></description>
			<content:encoded><![CDATA[<p>The article is a little reactionary, but it does serve to highlight the <a href="http://www.wired.com/epicenter/2010/05/facebook-rogue/">things about Facebook that you should be concerned about</a>.</p>

<p>Maybe it&#8217;s time to join me over at Google Buzz? All seven Google Buzz users are looking forward to your company. <img src='http://www.edthedev.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.edthedev.com/2010/facebook-privacy-issues/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cory Doctrow on Phishing</title>
		<link>http://www.edthedev.com/2010/cory-doctrow-on-phishing/</link>
		<comments>http://www.edthedev.com/2010/cory-doctrow-on-phishing/#comments</comments>
		<pubDate>Wed, 12 May 2010 14:59:52 +0000</pubDate>
		<dc:creator>Edward Delaporte</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.edthedev.com/?p=10951</guid>
		<description><![CDATA[Cory Doctrow, author of Little Brother, wrote an excellent article about being taken by a phishing attack. Cory has a unique talent for making security concepts accessible.]]></description>
			<content:encoded><![CDATA[<p>Cory Doctrow, author of <a href="http://craphound.com/littlebrother/download/">Little Brothe</a>r, wrote an excellent <a href="http://www.locusmag.com/Perspectives/2010/05/cory-doctorow-persistence-pays-parasites/">article about being taken by a phishing attack</a>. Cory has a unique talent for making security concepts accessible.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.edthedev.com/2010/cory-doctrow-on-phishing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mozilla protects you from serious Java vulnerabilities</title>
		<link>http://www.edthedev.com/2010/mozilla-protects-you-from-serious-java-vulnerabilities/</link>
		<comments>http://www.edthedev.com/2010/mozilla-protects-you-from-serious-java-vulnerabilities/#comments</comments>
		<pubDate>Thu, 22 Apr 2010 12:22:23 +0000</pubDate>
		<dc:creator>Edward Delaporte</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.edthedev.com/?p=10876</guid>
		<description><![CDATA[If you think your internet browsing experience is safer just because you&#8217;re using Mozilla Firefox, (and you have it set to update itself automatically); then you&#8217;re absolutely correct: java.sun.com/javase/6/webnotes/6u20.html Update: It&#8217;s probably also worth clarifying for anyone who found the article too long to read &#8211; the actions of both Oracle and Mozilla are making [...]]]></description>
			<content:encoded><![CDATA[<p>If you think your internet browsing experience is safer just because you&#8217;re using Mozilla Firefox, (and you have it set to update itself automatically); then you&#8217;re absolutely correct:

<a href="http://blogs.pcmag.com/securitywatch/2010/04/mozilla_disables_insecure_java.php</p>&#8221; title=&#8221;http://blogs.pcmag.com/securitywatch/2010/04/mozilla_disables_insecure_java.php</p>&#8221; target=&#8221;_blank&#8221;>blogs.pcmag.com/securitywatch/2010/04/mozilla_disables_insecure_java.php</p></a>

<p>Disabling another system&#8217;s &#8216;feature&#8217; is always a debatable move. But as someone who watches the vulnerability reports from <a href="http://Secunia.com" title="http://Secunia.com" target="_blank">Secunia.com</a>, I applaud Mozilla&#8217;s decision to fix what Sun/Oracle hasn&#8217;t been willing to fix.</p>

<p>Java&#8217;s standard behavior is to leave the vulnerable Java version installed in case a (possibly malicious) website asks for it. Mozilla is now turning off access to all but the latest installed version of Java. It&#8217;s a breakdown in cooperation between the two organizations, but I approve anyway because it will drastically reduce drive by download virus infection rates.</p>

<p>Update: My buddy Rob points out that the specific vulnerability that spurred Mozilla to this action has already been patched by Oracle/Sun: 

<a href="http://java.sun.com/javase/6/webnotes/6u20.html</p>&#8221; title=&#8221;http://java.sun.com/javase/6/webnotes/6u20.html</p>&#8221; target=&#8221;_blank&#8221;>java.sun.com/javase/6/webnotes/6u20.html</p></a>

<p>Update: It&#8217;s probably also worth  clarifying for anyone who found the article too long to read &#8211; the actions of both Oracle and Mozilla are making your web browser safer without reducing it&#8217;s feature set. So you win all around, if you&#8217;re a Firefox user.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.edthedev.com/2010/mozilla-protects-you-from-serious-java-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8216;Privacy&#8217; is not the same as &#8216;secret&#8217;.</title>
		<link>http://www.edthedev.com/2010/privacy-is-not-the-same-as-secret/</link>
		<comments>http://www.edthedev.com/2010/privacy-is-not-the-same-as-secret/#comments</comments>
		<pubDate>Wed, 07 Apr 2010 03:08:08 +0000</pubDate>
		<dc:creator>Edward Delaporte</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.edthedev.com/?p=10804</guid>
		<description><![CDATA[Bruce Schneier says that keeping things private is not the same thing as keeping them secret. http://www.schneier.com/blog/archives/2010/04/privacy_and_con.html]]></description>
			<content:encoded><![CDATA[<p>Bruce Schneier says that keeping things private is not the same thing as keeping them secret.</p>

<p>http://www.schneier.com/blog/archives/2010/04/privacy_and_con.html</p>
]]></content:encoded>
			<wfw:commentRss>http://www.edthedev.com/2010/privacy-is-not-the-same-as-secret/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>$180 million per year scam software company</title>
		<link>http://www.edthedev.com/2010/180-million-per-year-scam-software-company/</link>
		<comments>http://www.edthedev.com/2010/180-million-per-year-scam-software-company/#comments</comments>
		<pubDate>Fri, 26 Mar 2010 02:24:49 +0000</pubDate>
		<dc:creator>Edward Delaporte</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.edthedev.com/?p=10748</guid>
		<description><![CDATA[A company earned $180 million in a year by publishing scare-ware scam software. From the article, this company had a human resources department, a dedicated IT team, and a full call center. Evil software is now a large and profitable business: www.reuters.com/article/idUSTRE62N29T20100324 As this trend continues, it&#8217;s going to get harder to tell the online [...]]]></description>
			<content:encoded><![CDATA[<p>A company earned $180 million in a year by publishing scare-ware scam software. 
From the article, this company had a human resources department, a dedicated IT team, and a full call center.
Evil software is now a large and profitable business: <a href="http://www.reuters.com/article/idUSTRE62N29T20100324" title="http://www.reuters.com/article/idUSTRE62N29T20100324" target="_blank">www.reuters.com/article/idUSTRE62N29T20100324</a>
As this trend continues, it&#8217;s going to get harder to tell the online bad guys apart from legitimate businesses. Maybe the public will finally learn how to use the trust technologies that have been available for many years.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.edthedev.com/2010/180-million-per-year-scam-software-company/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WPA on Ubuntu at Illinois</title>
		<link>http://www.edthedev.com/2009/wpa-on-ubuntu-at-illinois/</link>
		<comments>http://www.edthedev.com/2009/wpa-on-ubuntu-at-illinois/#comments</comments>
		<pubDate>Mon, 14 Dec 2009 03:55:56 +0000</pubDate>
		<dc:creator>Edward Delaporte</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Solutions]]></category>
		<category><![CDATA[Free Software]]></category>

		<guid isPermaLink="false">http://www.edthedev.com/?p=10571</guid>
		<description><![CDATA[Continuing with articles about connecting to the network at the University of Illinois from an Ubuntu computer, here&#8217;s a hint about connecting to the UiWpa2 / IllinoisNet Wireless:  Ubuntu may not automatically choose a certificate authority for you; you may need to browse for a CA certificate. Choose the Thawte Premium Server CA &#8211; it [...]]]></description>
			<content:encoded><![CDATA[<p>Continuing with articles about connecting to the network at the University of Illinois from an Ubuntu computer, here&#8217;s a hint about connecting to the UiWpa2 / IllinoisNet Wireless:  Ubuntu may not automatically choose a certificate authority for you; you may need to browse for a CA certificate.</p>

<p>Choose the Thawte Premium Server CA &#8211; it will work at Illinois (and quite a lot of other places, actually):
/etc/ssl/certs/Thawte_Premium_Server_CA.pem</p>

<p>As usual, enter your NetId for your username, and you can use your Active Directory password.</p>

<p>If you&#8217;re still having trouble getting online, check out the <a href="http://cites.illinois.edu" target="_blank">CITES Homepage</a> for more information on Illinois network resources.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.edthedev.com/2009/wpa-on-ubuntu-at-illinois/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
