<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: broadcast]]></title>
    <link>http://securityratty.com/tag/broadcast</link>
    <description></description>
    <pubDate>Thu, 24 Jul 2008 20:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Aspidistra]]></title>
      <link>http://securityratty.com/article/4adeb47a50e5774a3a549e0fa2c6f85d</link>
      <guid>http://securityratty.com/article/4adeb47a50e5774a3a549e0fa2c6f85d</guid>
      <description><![CDATA[Aspidistra was a World War II man-in-the-middle attack. The vulnerability that made it possible was that German broadcast stations were mostly broadcasting the same content from a central source; but...]]></description>
      <content:encoded><![CDATA[<p><a href="http://en.wikipedia.org/wiki/Aspidistra_(transmitter)">Aspidistra</a> was a World War II man-in-the-middle attack.   The vulnerability that made it possible was that German broadcast stations were mostly broadcasting the same content from a central source; but during air raids, transmitters in the target area were switched off to prevent them being used for radio direction-finding of the target.</p>

<p>The exploit involved the very powerful (500KW) Aspidistra transmitter, coupled to a directional antenna farm.  With that power, they could make it sound like a local station in the target area.</p>

<p>With a staff of fake announcers, a fake German band, and recordings of recent speeches from high-ranking Nazis, they would smoothly switch from merely relaying the German network to emulating it with their own staff.  They could then make modifications to news broadcasts, occasionally creating panic and confusion.</p>

<blockquote>German transmitters were switched off during air raids, to prevent them from being used as navigational aids for bombers. But many were connected into a network and broadcast the same content. When a targeted transmitter switched off, Aspidistra began transmitting on their original frequency, initially retransmitting the German network broadcast as received from a still-active station. As a deception, false content and pro-Allied propaganda would be inserted into the broadcast. The first such "intrusion" was carried out on March 25, 1945, as shown in the operations order at the right.

<p>On March 30, 1945, "Aspidistra" intruded into the Berlin and Hamburg frequencies warning that the Allies were trying to spread confusion by sending false telephone messages from occupied towns to unoccupied towns. On April 8, 1945, "Aspidistra" intruded into the Hamburg and Leipzig channels to warn of forged banknotes in circulation. On April 9, 1945, there were announcements encouraging people to evacuate to seven bomb-free zones in central and southern Germany. All these announcements were false.</p>

<p>The German radio network tried announcing "The enemy is broadcasting counterfeit instructions on our frequencies. Do not be misled by them. Here is an official announcement of the Reich authority." The Aspidistra station made similar announcements, to cause confusion and make the official messages ineffective.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=2KImN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=2KImN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=bbShN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=bbShN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 10 Nov 2008 04:07:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/aspidistra">aspidistra</category>
      <category domain="http://securityratty.com/tag/german network broadcast">german network broadcast</category>
      <category domain="http://securityratty.com/tag/german network">german network</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/aspidistra station">aspidistra station</category>
      <category domain="http://securityratty.com/tag/broadcast">broadcast</category>
      <category domain="http://securityratty.com/tag/german broadcast stations">german broadcast stations</category>
      <category domain="http://securityratty.com/tag/german radio network">german radio network</category>
      <category domain="http://securityratty.com/tag/false">false</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/aspidistra.html">Aspidistra</source>
    </item>
    <item>
      <title><![CDATA[GPS Spoofing]]></title>
      <link>http://securityratty.com/article/301910a8390d678e528ed1556dd2bb4e</link>
      <guid>http://securityratty.com/article/301910a8390d678e528ed1556dd2bb4e</guid>
      <description><![CDATA[Interesting : Jon used a desktop computer attached to a GPS satellite simulator to create a fake GPS signal. Portable GPS satellite simulators can fit in the trunk of a car, and are often used for...]]></description>
      <content:encoded><![CDATA[<p><a href="http://philosecurity.org/2008/09/07/gps-spoofing">Interesting</a>:</p>

<blockquote>Jon used a desktop computer attached to a GPS satellite simulator to create a fake GPS signal. Portable GPS satellite simulators can fit in the trunk of a car, and are often used for testing. They are available as commercial off-the-shelf products. You can also rent them for less than $1K a week -- peanuts to anyone thinking of hijacking a cargo truck and selling stolen goods.

<p>In his first experiments, Jon placed his desktop computer and GPS satellite simulator in the cab of his small truck, and powered them off an inverter. The VAT used a second truck as the victim cargo truck. "With this setup," Jon said, "we were able to spoof the GPS receiver from about 30 feet away. If our equipment could broadcast a stronger signal, or if we had purchased stronger signal amplifiers, we certainly could have spoofed over a greater distance."</p>

<p>During later experiments, Jon and the VAT were able to easily achieve much greater GPS spoofing ranges. They spoofed GPS signals at ranges over three quarters of a mile. "The farthest distance we achieved was 4586 feet, at Los Alamos," said Jon. "When you radiate an RF signal, you ideally want line of sight, but in this case we were walking around buildings and near power lines. We really had a lot of obstruction in the way. It surprised us." An attacker could drive within a half mile of the victim truck, and still override the truck's GPS signals.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=XoEIL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=XoEIL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=JZqYL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=JZqYL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Wed, 17 Sep 2008 03:03:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/gps">gps</category>
      <category domain="http://securityratty.com/tag/fake gps signal">fake gps signal</category>
      <category domain="http://securityratty.com/tag/signal">signal</category>
      <category domain="http://securityratty.com/tag/gps satellite simulator">gps satellite simulator</category>
      <category domain="http://securityratty.com/tag/truck">truck</category>
      <category domain="http://securityratty.com/tag/victim truck">victim truck</category>
      <category domain="http://securityratty.com/tag/victim cargo truck">victim cargo truck</category>
      <category domain="http://securityratty.com/tag/stronger signal amplifiers">stronger signal amplifiers</category>
      <category domain="http://securityratty.com/tag/cargo truck">cargo truck</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/gps_spoofing.html">GPS Spoofing</source>
    </item>
    <item>
      <title><![CDATA[Wee-Fi: Indian Terror over Wi-Fi; Fastest Wireless; Health Fears; Wi-Fi Tub; and More]]></title>
      <link>http://securityratty.com/article/38100bf79f0cedd88c5f6a02e45c5a85</link>
      <guid>http://securityratty.com/article/38100bf79f0cedd88c5f6a02e45c5a85</guid>
      <description><![CDATA[Another terror message sent via open Wi-Fi in India: Credit for terrorist blasts in Delhi was sent by email minutes before the attack took place using a Wi-Fi network owned by a retired engineer's...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://www.telegraphindia.com/1080915/jsp/nation/story_9835144.jsp"><strong>Another terror message sent via open Wi-Fi in India:</strong></a> Credit for terrorist blasts in Delhi was sent by email minutes before the attack took place using a Wi-Fi network owned by a retired engineer's wife. Though articles keep saying the network was "hacked," the Telegraph also notes that the network was "unsecured."</p>

<p>Italian free space optics test hits 1.2 terabits per second (<a href="http://www.corriere.it/scienze_e_tecnologie/08_settembre_11/wifi_pisa_record_3a9bf132-801f-11dd-9f6f-00144f02aabc.shtml">in Italian</a>, <a href="http://translate.google.com/translate?u=http://www.corriere.it/scienze_e_tecnologie/08_settembre_11/wifi_pisa_record_3a9bf132-801f-11dd-9f6f-00144f02aabc.shtml&hl=en&ie=UTF-8&sl=it&tl=en">Google translation</a>): Researchers in Pisa, Italy, along with colleagues from two Japanese institutions, crossed 1.2 Tbps in a test. Free space optics typically uses infrared lasers, and can work over a distance of kilometers. </p>

<p><a href="http://www.canada.com/montrealgazette/news/story.html?id=2e090761-519c-4de6-9ace-4153d6dc71d2"><strong>More Canadian Wi-Fi health fears:</strong></a> This time in an island in Montr&eacute;al. One of the concerned citizens: "This is something that is really under the radar. People do not know that long-term health hazards are associated with wireless technology." They don't know that because all verifiable, repeatable, well-conducted, academic tests so far indicate that there's no such health hazard associated with EMF. The concerned folks are raising an alarm about Wi-Fi being broadcast island wide, but are not paying attention, obviously, to the AM/FM radio, satellite radio, cellular, cordless, and thousand other wireless uses that are bombarding them right now, often at far higher signal levels.</p>

<p><a href="http://www.washingtonpost.com/wp-dyn/content/article/2008/09/13/AR2008091300340.html"><strong>Wi-Fi in a tub:</strong></a> I'm not going to say anything more.</p>

<p><a href="http://www.quickertek.com/products/expresscard.php"><strong>QuickerTek adds antenna to 300 mW ExpressCard for MacBook Pro:</strong></a> Users of Apple's higher-end laptops can drop $200 to get a 300 mW Draft N (802.11n) ExpressCard and 5 dBi external antenna with a mounting clip. That's a lot of power, and it's important to recall that have a louder signal doesn't mean that distant base stations can necessarily hear you better. Draft N devices typically pair better listening (receive sensitivity) with higher transmission power, however.</p>

<p><a href="http://networklocationapp.com/"><strong>Mac product ties location settings to Wi-Fi position:</strong></a> Centrix has updated its $29 Mac OS X location preferences program NetworkLocation to take advantage of Skyhook Wireless's Wi-Fi positioning data. You can now tie the package of settings that control what email account you use, iChat status, programs launched, disks mounted, and other factors, to where you're currently at.</p>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 06:03:26 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/wi-fi network owned">wi-fi network owned</category>
      <category domain="http://securityratty.com/tag/wireless">wireless</category>
      <category domain="http://securityratty.com/tag/wi-fi position">wi-fi position</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/skyhook wireless">skyhook wireless</category>
      <category domain="http://securityratty.com/tag/broadcast island wide">broadcast island wide</category>
      <category domain="http://securityratty.com/tag/island">island</category>
      <category domain="http://securityratty.com/tag/dbi external antenna">dbi external antenna</category>
      <source url="http://wifinetnews.com/archives/008439.html">Wee-Fi: Indian Terror over Wi-Fi; Fastest Wireless; Health Fears; Wi-Fi Tub; and More</source>
    </item>
    <item>
      <title><![CDATA[Links List 9.12.08]]></title>
      <link>http://securityratty.com/article/b6c1e13955ab002ad9018715db59c1d8</link>
      <guid>http://securityratty.com/article/b6c1e13955ab002ad9018715db59c1d8</guid>
      <description><![CDATA[HP forgot to knock on wood. The London Stock Exchange , touted in an HP case study as an example of having produced unprecedented levels of performance and reliability crashed on Monday. Seems that...]]></description>
      <content:encoded><![CDATA[<p><a href="http://blog.sciencelogic.com/wp-content/uploads/2008/09/image.png"><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="176" alt="image" src="http://blog.sciencelogic.com/wp-content/uploads/2008/09/image-thumb.png" width="204" align="left" border="0" /></a> HP forgot to &#8220;knock on wood&#8221;. The <a href="http://blogs.wsj.com/biztech/2008/09/09/lesson-from-london-systems-still-crash/" target="_blank">London Stock Exchange</a>, touted in an HP case study as an example of having &#8220;produced unprecedented levels of performance and reliability&#8221; crashed on Monday. Seems that the LSE&#8217;s new trading system, TradElect, could not handle the volume of trades triggered by the Fannie Mae and Freddie Mac news. I&#8217;m sure there will be enough blame to go around &#8211; from the contractor to the contractor&#8217;s <a href="http://blogs.computerworld.com/extra_london_stock_exchange_blame_microsoft" target="_blank">choice of Microsoft</a> SQL Server and .NET.</p>
<p>Following in the footsteps of social networking projects like <a href="https://www.cia.gov/news-information/featured-story-archive/intellipedia-marks-second-anniversary.html">Intellipedia</a>, <a href="http://www.fcw.com/online/news/153673-1.html" target="_blank">A-Space, an online collaboration environment</a> for intelligence analysts, will go live on September 22. A-Space allows analysts to share information, form communities, and work together all under one environment. The analysts from sixteen intelligence agencies will have access to shared and personal workspaces, wikis, blogs, widgets, RSS feeds and other tools, as well as be able to search for content on other agencies&#8217; data sources and even on data that allied countries might share. </p>
<p>Karen Sage, Cisco&#8217;s director of product management for network management, said that it&#8217;s &#8220;actually a good thing when <a href="http://www.networkworld.com/community/node/32369?nlhtnsm=rn_091008&amp;nladname=091008networksystemsmanagemental" target="_blank">network management is struggling, because is say that innovation is really happening at a fast rate</a>&#8221;. </p>
<p>Joe Weinman, Strategic Solutions Sales VP for AT&amp;T Global Business Services, created <a href="http://gigaom.com/2008/09/07/the-10-laws-of-cloudonomics/" target="_blank">The 10 Laws of Cloudonomics</a>. Weinman expands upon his laws by comparing public utility cloud services, traditional data center environments and private enterprise clouds. </p>
<p>I&#8217;m not making this up. <a href="http://blogs.wsj.com/biztech/2008/09/11/h-p-has-a-new-reality-show-too/">HP has a new reality show</a> coming out. &#8220;Engine Room&#8221; will be broadcast on MTV and on the Web and will feature teams of designers from around the world who understake a series of challenges with the help of HP computers. Can&#8217;t hardly wait.</p>
]]></content:encoded>
      <pubDate>Fri, 12 Sep 2008 17:43:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/online collaboration environment">online collaboration environment</category>
      <category domain="http://securityratty.com/tag/agencies data sources">agencies data sources</category>
      <category domain="http://securityratty.com/tag/intelligence analysts">intelligence analysts</category>
      <category domain="http://securityratty.com/tag/analysts">analysts</category>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/network management">network management</category>
      <category domain="http://securityratty.com/tag/environment">environment</category>
      <category domain="http://securityratty.com/tag/strategic solutions sales">strategic solutions sales</category>
      <category domain="http://securityratty.com/tag/freddie mac news">freddie mac news</category>
      <source url="http://blog.sciencelogic.com/links-list-91208/09/2008">Links List 9.12.08</source>
    </item>
    <item>
      <title><![CDATA[Zune Swoon 2.0]]></title>
      <link>http://securityratty.com/article/162d344e703b51b1f9a309987ebdb786</link>
      <guid>http://securityratty.com/article/162d344e703b51b1f9a309987ebdb786</guid>
      <description><![CDATA[Latest Zune firmware, software allows Wi-Fi music purchases, FM tagging: Microsoft confirmed the 16-Sept-2008 release of new Zune firmware and players, allowing users of old and new devices alike to...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.microsoft.com/Presspass/press/2008/sep08/09-08ZuneFallUpdatePR.mspx"><strong>Latest Zune firmware, software allows Wi-Fi music purchases, FM tagging:</strong></a> Microsoft confirmed the 16-Sept-2008 release of new Zune firmware and players, allowing users of old and new devices alike to purchase music over Wi-Fi from the Zune Marketplace. The new firmware also sports FM tagging that uses information that some broadcasters will embed in their analog programming to tag songs for immediate purchase (single track) or download (Zune Pass subscription) over a Wi-Fi hotspot, or to queue for later download.</p>

<p>Apple added access for iPhone and iPod touch users to a subset of its iTunes Store over Wi-Fi--the awkwardly named iTunes Wi-Fi Music Store--more than a year ago, along with the ability to access that store at no cost from handhelds and laptops <a href="http://www.apple.com/itunes/starbucks/"><strong>via Starbucks outlets</strong></a> in New York, Seattle, and throughout the San Francisco Bay Area. (Chicago and Los Angeles have been "coming soon" for a year, but the new AT&T/Starbucks deal may have delayed opening up those markets.)</p>

<p><img src="http://wifinetnews.com//images/2008/zune_tagging.jpg" alt="zune_tagging.jpg" border="0" width="175" height="385" align="right" hspace="5" />Terrestrial AM/FM radio stations would like to figure out how to remain meaningful in a world of streaming Internet radio. Their latest strategy is to embed information that allows a listener to mark a song they want, potentially getting a piece of music sold in this fashion. With FM tagging, Zune players tap into an existing very low-data-rate encoding protocols that allow stations to push out their call letters and current song information. By adding a very short code, broadcasters can allow Zunes to look up the appropriate song.</p>

<p>At launch, 450 stations from major networks, including Clear Channel, Entercom, and others, will broadcast tagging details. Note that Microsoft includes KEXP, a Seattle independent and alternative radio station, in its sample image, for the new models. KEXP, given a boost a few years ago through significant short-term funding by Paul Allen--funding that involved changing its call letters to his Experience Music Project museum initials--has an enormous listenership over the Internet ironically enough. KEXP will be a programming partner creating channels of music for the subscription-based Zune Pass service. (Zune Pass is $15 per month, all you can eat.)</p>

<p>This option could allow Microsoft to ink partnerships with hotspot networks to brand them with Zune compatibility, lets radio stations promote something other than iPods that they would have a direct relationship with (and, potentially, some kind of revenue stream from?), and may be part of breaking Apple's digital music hegemony. <em>May be.</em> Nobody's gotten rich betting against Apple for the last several years. (Details of revenue sharing with radio stations hasn't been discussed.)</p>

<p>Apple opted for a partnership with HD Radio broadcasters and equipment makers that has a relatively elaborate process of tagging songs. HD Radio is digital AM/FM, a patented and licensed method that has provoked a lot of controversy, and has lagged enormously in the marketplace, despite well over 1,000 stations (including many public radio stations) broadcasting in this digital format, some for over three years. </p>

<p>HD Radio tagging requires an HD radio receiver with a Tag button; pressing that button stores the song's tag information. The radio must also have an iPod dock. Docking an iPod syncs the tag information, and the next time the iPod is sync with iTunes, you can see which songs were tagged. Kind of tedious compared to "press a button while listening to an FM station and buy the song over Wi-Fi." (I've been writing about HD Radio for years, and even launched a blog that's gone moribund; the technology is interesting, but Internet radio on mobile devices coupled with on-demand music purchasing over cell and Wi-Fi may simply make HD Radio unnecessary for listeners.)</p>

<p>Microsoft has a more compelling "marketing story" for this feature than Apple, that's for sure. On the other hand, do you really need to tag songs from stations that play only the most popular music in a given format?</p>]]></content:encoded>
      <pubDate>Mon, 08 Sep 2008 12:39:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/public radio stations">public radio stations</category>
      <category domain="http://securityratty.com/tag/stations">stations</category>
      <category domain="http://securityratty.com/tag/radio stations promote">radio stations promote</category>
      <category domain="http://securityratty.com/tag/radio">radio</category>
      <category domain="http://securityratty.com/tag/radio unnecessary">radio unnecessary</category>
      <category domain="http://securityratty.com/tag/radio receiver">radio receiver</category>
      <category domain="http://securityratty.com/tag/internet radio">internet radio</category>
      <category domain="http://securityratty.com/tag/radio stations">radio stations</category>
      <category domain="http://securityratty.com/tag/wi-fi music purchases">wi-fi music purchases</category>
      <source url="http://wifinetnews.com/archives/008432.html">Zune Swoon 2.0</source>
    </item>
    <item>
      <title><![CDATA[Thoughts on Token Security]]></title>
      <link>http://securityratty.com/article/e520684c06df65bce8e1084919798c74</link>
      <guid>http://securityratty.com/article/e520684c06df65bce8e1084919798c74</guid>
      <description><![CDATA[RSnake has a piece up on Token Security which raises some good points, but also misses some perspective. Firstly any article that makes a serious attempt at mitigating FUD is most welcome, especially...]]></description>
      <content:encoded><![CDATA[<p>RSnake has a piece up on <a href="http://www.darkreading.com/blog.asp?blog_sectionid=403">Token Security</a> which raises some good points, but also misses some perspective. Firstly any article that makes a serious attempt at mitigating FUD is most welcome, especially in a space that is as overloaded as identity. That <span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">said, I think RSnake is taking too narrow of a view, specifically B2C, on federation and tokens</span><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">. It is true that works on the web eventually filters into the enterprise, but it is also true that sometimes that things that start out as enterprise technologies later become cost effective on the web. So I would not assume that the current status quo on the web will hold. I don&#39;t think it will, the identity problems are too big and there is too much money at stake.</span></p><div><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div><div><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">I encourage you to read his article, here are some of my thoughts<br /></span><div><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;consumers hate tokens.&quot;</span></p></blockquote><div><div><span style="font-size: 12px; line-height: normal; "><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">
</span><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Except that people use atm cards every day. Consumers will absolutely be inconvenienced, if there is some value created. The problem today is not the token, its the lack of a value proposition to the person you are inconveniencing.&#160;</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
</span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;Everyone wants to be the single federation platform for everyone else.&quot;</span></p></blockquote><div><div><span style="font-size: 12px; line-height: normal; "><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">
</span><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">This will never work. and that&#39;s a good thing. i think most companies already realize this though. I think the walled garden model has gone the way of the dodo.</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
</span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;Federation will never work. It won’t work because the single most important consumer Web applications in the world are scared of it. Banks hate the concept because it becomes a weakest link in the chain problem.&quot;</span></p></blockquote><div><div><span style="font-size: 12px; line-height: normal; "><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">
</span><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Federation works quite well. have a look at google for one example. The reason banks hate federation is that their infosec people have a </span><a href="http://1raindrop.typepad.com/1_raindrop/2008/08/mainframe-mindset.html"><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">mainframe mindset</span></a><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">, they are focused only on resource protection. the problem is they dont run mainframes on closed networks, they went and connected it to the web and so now they need to think about subject and claim security not just resource security. its not hatred its a lack of understanding stemming from a legacy mindset.</span></p><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"></p><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Linking up identity providers and relying parties into a federation has been a solved problem for quite some time.</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
</span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;Tokens don’t actually solve most security problems, like man-in-the-middle, phishing, and keystroke-logging malware.&quot;</span></p></blockquote><div><div><span style="font-size: 12px; line-height: normal; "><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">
</span><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Rule 1. there are no silver bullets in security</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Rule 2. dont forget rule 1</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">but...</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">...there is a rule 3</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">rule 3. just because a security mechanism doesnt solve all of our problems doesnt mean its worthless.</span></p><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"></p><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">I see this with security consultants all the time, they playa hate on static analysis or some scanning tool where they can find hundreds of things the tool doesn&#39;t. Fair point except 99.9999% of IT can&#39;t and won&#39;t find them. Engineering is about solving one incremental problem at a time.</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
</span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;Oh yes, and finally, consumers are going to have to carry around 13 of them just to make sure they can log into whatever they need to log into since no one will federate.&quot;</span></p></blockquote><div><div><span style="font-size: 12px; line-height: normal; "><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">
</span><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">This misses the point of federation. i carry around one atm card its up to banks, Visa, Cirrus and so on to make sure i get my cash. the funny thing about banks not understanding federation is that they have the bet example right in front of their noses, the problem is its in a different department so they never see it.</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
</span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;Global federation is nowhere near a solid concept in the consumer space, despite what the vendors will try to sell you.&quot;</span></p></blockquote><div><div><span style="font-size: 12px; line-height: normal; "><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">
</span><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font: normal normal normal 12px/normal Helvetica; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">rule 4. do your own due diligence</span></p><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><div><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Tokens and federation are important building blocks for our digital future. I will leave you with a </span><a href="http://1raindrop.typepad.com/1_raindrop/2007/01/integrated_tran.html"><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">story</span></a><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "> that</span><a href="http://en.wikipedia.org/wiki/Robert_Morris_%28cryptographer%29"><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "> Robert Morris Sr.</span></a><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "> told at Defcon several years ago:</span></div><span style="line-height: normal; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;This is a long term problem. If you work on it and make any progress against it, you&#39;ll find yourself much smarter at the far end, than you were at the near end.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">When I was in Norway about 5 years ago, I was there very close to the summer solstice. I was wandering around town at 2 o&#39;clock in the morning and there was plenty of light out. You come to a sign that says New Minsk about 60 km and it points south.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">And I ask the lady &quot;what country is this?&quot;</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">She scratched her head for a bit, and said &quot;well I think its Norway&quot;</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">I said &quot;well who plows the roads?&quot;</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">&quot;well Norway does, but he have to pay them.&quot;</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">There is a triple boundary in this town that I was in between Norway, Finland and Russia.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">But what I did there, was, I had a card about wallet size, I stuck it into a machine, I punched in four digits, and it gave me about 2,000 krone, whatever the hell that is.</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">Now there are a lot of participants in that transaction. When I put a card into that machine, punch in a pin, and it gurgles for awhile, and finally gives me, a fairly large amount of money. There are a lot of participants in that transaction. The bank that owned the machine that gave me the money, it gave some money away -- that bank wants it back. The pin is necessary to convince my own bank that I&#39;m me. But I don&#39;t want my pin to be broadcast all over the world. My bank in the us, it hasn&#39;t really given out or taken in any money, really. But there is a lot of credits involved here. Somebody needs to charge somebody else for having more money&#160;available. Even though there was actually no cash transfer.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">And the problem that I have in mind is</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">- who are all the participants in an ATM transaction?</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">- what do those participants need to satisfy their problems?</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">- how is that in fact done?</span><span style="font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 19px; font-size: 13px; font-family: &#39;Trebuchet MS&#39;; ">In a general way, does the atm system actually work in some reasonable sense? To which the answer is by the way: yes. The atm system damn well works. With extremely high reliability and accuracy. It surprises me. Its quite a bit different than voting machines.</span></p></blockquote>]]></content:encoded>
      <pubDate>Tue, 26 Aug 2008 12:35:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/global federation">global federation</category>
      <category domain="http://securityratty.com/tag/federation">federation</category>
      <category domain="http://securityratty.com/tag/single federation platform">single federation platform</category>
      <category domain="http://securityratty.com/tag/security mechanism">security mechanism</category>
      <category domain="http://securityratty.com/tag/resource security">resource security</category>
      <category domain="http://securityratty.com/tag/security consultants">security consultants</category>
      <category domain="http://securityratty.com/tag/consumer web applications">consumer web applications</category>
      <category domain="http://securityratty.com/tag/web">web</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/thoughts-on-token-security.html">Thoughts on Token Security</source>
    </item>
    <item>
      <title><![CDATA[Links List 8.8.08]]></title>
      <link>http://securityratty.com/article/e04889523cd12799c82bedae1e2f93f6</link>
      <guid>http://securityratty.com/article/e04889523cd12799c82bedae1e2f93f6</guid>
      <description><![CDATA[Peace Corps meets long-term next-generation global leadership development meets really long-term international business development. IBMs new Corporate Service Corps program is assisting numerous...]]></description>
      <content:encoded><![CDATA[<p>Peace Corps meets long-term next-generation global leadership development meets really long-term international business development. IBM’s new Corporate Service Corps program is assisting numerous nonprofits and companies across the globe to <a href="http://online.wsj.com/article/SB121779236200008095.html?mod=djemTECH" target="_blank">become more efficient and more computer-savvy</a>. In a span of three years, over 600 of IBM’s employees will spend month-long projects in countries where it wants a bigger footprint by donating their time and services. A reason (besides getting to work with <a href="http://dougmcclure.net" target="_blank">Doug McClure</a>) to work for IBM.
<p>Buying a lemon is always a bad thing – but when you pay $1 billion for it?! Back in 2005, Google bought a <a href="http://blogs.zdnet.com/BTL/?p=9601" target="_blank">5% stake in AOL for $1 billion</a> and now is calling that investment <a href="http://legal-dictionary.thefreedictionary.com/impaired" target="_blank">“impaired”.</a> That’s one way of putting it, so it’s a good thing Google has money to burn.
<p>At LinuxWorld this week, Bob Sutor, VP of open source and standards at IBM, said that the next <a href="http://www.infoworld.com/article/08/08/07/IBM_exec_on_Linux_apps_Im_tired_of_waiting_1.html?source=NLC-Daily&amp;gcd=2008-08-08" target="_blank">10 years is “do or die”</a> for open source software designed for specific industries. 10 years? That’s like 70 years in open source development time.
<p>And finally…8/8/08…the <a href="http://www.nbcolympics.com/" target="_blank">Olympics</a> are here! Network administrators around the world, except for <a href="http://blog.sciencelogic.com/top-10-signs-your-network-admin-has-gone-rogue/07/2008" target="_blank">Terry Childs</a>, will be eyeing office network bandwidth closely as people go online to watch streaming video of the games. NBC and Microsoft will offer <a href="http://www.bcs.org/server.php?show=ConWebDoc.20432" target="_blank">2,200 hours of live video coverage</a> with up to 20 simultaneous live streams of different events. Plus <a href="http://www.nbcolympics.com/" target="_blank">NBCOlympics.com</a> will offer 3,000 hours of on-demand video content. The time difference means that much of the primetime events will be broadcast while the Western hemisphere is supposed to be hard at work. Me – I’m just glad it’s the weekend, and I can get the Olympics fix I’ve been waiting years for.</p>
]]></content:encoded>
      <pubDate>Fri, 08 Aug 2008 15:03:05 +0000</pubDate>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/time difference">time difference</category>
      <category domain="http://securityratty.com/tag/on-demand video content">on-demand video content</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/source software">source software</category>
      <category domain="http://securityratty.com/tag/source development time">source development time</category>
      <category domain="http://securityratty.com/tag/live video coverage">live video coverage</category>
      <category domain="http://securityratty.com/tag/ibms">ibms</category>
      <source url="http://blog.sciencelogic.com/links-list-8808/08/2008">Links List 8.8.08</source>
    </item>
    <item>
      <title><![CDATA[Meru Networks erects a "cone of silence"]]></title>
      <link>http://securityratty.com/article/2b9b51efaeb059be63332e84e9b51781</link>
      <guid>http://securityratty.com/article/2b9b51efaeb059be63332e84e9b51781</guid>
      <description><![CDATA[Who doesn't remember the cone of silence from the original Get Smart TV series. Whenever Max and the Chief had something important to discuss they would lower the cone of silence so that no one else...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><a onclick="window.open(this.href, '_blank', 'width=376,height=261,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://www.stillsecureafteralltheseyears.com/.shared/image.html?/photos/uncategorized/2008/07/30/coneofsilence.jpg"><img title="Coneofsilence" height="173" alt="Coneofsilence" src="http://www.stillsecureafteralltheseyears.com/ashimmy/images/2008/07/30/coneofsilence.jpg" width="249" border="0" style="FLOAT: right; MARGIN: 0px 0px 5px 5px" /></a> Who doesn't remember <a class="zem_slink" title="Cone of Silence" href="http://en.wikipedia.org/wiki/Cone_of_Silence" rel="wikipedia">the cone of silence</a> from the original Get Smart TV series.&nbsp; Whenever Max and the Chief had something important to discuss they would lower the cone of silence so that no one else could hear them or eavesdrop. So it is only fitting with the recent release of the <a class="zem_slink" title="Get Smart (film)" href="http://getsmartmovie.warnerbros.com/" rel="homepage">Get Smart movie</a>, <a href="http://news.zdnet.co.uk/communications/0,1000000085,39453788,00.htm">Meru Networks has released a wireless cone of silence</a>. </p>

<p>Meru is one of few stand alone wireless companies still hanging on out there.&nbsp; So they need to be innovative to survive.&nbsp; Their latest product, RF Barrier puts antennas around a physical plant to dampen and make it impossible to to listen in on wireless data exchanges.&nbsp; They claim this is a first of its kind.&nbsp; Thinking about it though, I don't see a big barrier to other companies having similar technology. I don't think you have to be a genius to broadcast traffic that puts out &quot;noise&quot; to hide legit traffic. I think the real special sauce is that this works in conjunction with Meru's other security products like wireless firewalls and secure access points.</p>

<p>With Motorola's recent purchase of AirDefense is having wireless IPS soon going to be table stakes in the wireless provider game?&nbsp; I think it is and while Meru's RF barrier is a nice story, they are going to need to have some sort of IDS/IPS in their product line to keep up.</p>

<fieldset class="zemanta-related"><legend class="zemanta-related-title">Related articles by Zemanta</legend><ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a href="http://www.itweek.co.uk/itweek/news/2222765/motorola-acquire-airdefense">Motorola to acquire AirDefense</a></li>

<li class="zemanta-article-ul-li"><a href="http://www.itweek.co.uk/itweek/news/2222643/meru-locks-car-park-hackers">Meru locks out car park hackers</a></li></ul></fieldset> <div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/5a77977d-6e3b-40f2-b9f2-737ba115b05b/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=5a77977d-6e3b-40f2-b9f2-737ba115b05b" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>
]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 04:05:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/meru">meru</category>
      <category domain="http://securityratty.com/tag/meru networks">meru networks</category>
      <category domain="http://securityratty.com/tag/cone">cone</category>
      <category domain="http://securityratty.com/tag/silence">silence</category>
      <category domain="http://securityratty.com/tag/meru locks">meru locks</category>
      <category domain="http://securityratty.com/tag/wireless cone">wireless cone</category>
      <category domain="http://securityratty.com/tag/product line">product line</category>
      <category domain="http://securityratty.com/tag/hide legit traffic">hide legit traffic</category>
      <category domain="http://securityratty.com/tag/wireless provider game">wireless provider game</category>
      <source url="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/07/meru-networks-e.html">Meru Networks erects a "cone of silence"</source>
    </item>
    <item>
      <title><![CDATA[Meru Networks erects a "cone of silence"]]></title>
      <link>http://securityratty.com/article/b76f30b52c9fc47905da9e8e714fa2b2</link>
      <guid>http://securityratty.com/article/b76f30b52c9fc47905da9e8e714fa2b2</guid>
      <description><![CDATA[Who doesn't remember the cone of silence from the original Get Smart TV series. Whenever Max and the Chief had something important to discuss they would lower the cone of silence so that no one else...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p><a onclick="window.open(this.href, '_blank', 'width=376,height=261,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://www.stillsecureafteralltheseyears.com/.shared/image.html?/photos/uncategorized/2008/07/30/coneofsilence.jpg"><img title="Coneofsilence" height="173" alt="Coneofsilence" src="http://www.stillsecureafteralltheseyears.com/ashimmy/images/2008/07/30/coneofsilence.jpg" width="249" border="0" style="FLOAT: right; MARGIN: 0px 0px 5px 5px" /></a> Who doesn't remember <a class="zem_slink" title="Cone of Silence" href="http://en.wikipedia.org/wiki/Cone_of_Silence" rel="wikipedia">the cone of silence</a> from the original Get Smart TV series.&nbsp; Whenever Max and the Chief had something important to discuss they would lower the cone of silence so that no one else could hear them or eavesdrop. So it is only fitting with the recent release of the <a class="zem_slink" title="Get Smart (film)" href="http://getsmartmovie.warnerbros.com/" rel="homepage">Get Smart movie</a>, <a href="http://news.zdnet.co.uk/communications/0,1000000085,39453788,00.htm">Meru Networks has released a wireless cone of silence</a>. </p>

<p>Meru is one of few stand alone wireless companies still hanging on out there.&nbsp; So they need to be innovative to survive.&nbsp; Their latest product, RF Barrier puts antennas around a physical plant to dampen and make it impossible to to listen in on wireless data exchanges.&nbsp; They claim this is a first of its kind.&nbsp; Thinking about it though, I don't see a big barrier to other companies having similar technology. I don't think you have to be a genius to broadcast traffic that puts out &quot;noise&quot; to hide legit traffic. I think the real special sauce is that this works in conjunction with Meru's other security products like wireless firewalls and secure access points.</p>

<p>With Motorola's recent purchase of AirDefense is having wireless IPS soon going to be table stakes in the wireless provider game?&nbsp; I think it is and while Meru's RF barrier is a nice story, they are going to need to have some sort of IDS/IPS in their product line to keep up.</p>

<fieldset class="zemanta-related"><legend class="zemanta-related-title">Related articles by Zemanta</legend><ul class="zemanta-article-ul"><li class="zemanta-article-ul-li"><a href="http://www.itweek.co.uk/itweek/news/2222765/motorola-acquire-airdefense">Motorola to acquire AirDefense</a></li>

<li class="zemanta-article-ul-li"><a href="http://www.itweek.co.uk/itweek/news/2222643/meru-locks-car-park-hackers">Meru locks out car park hackers</a></li></ul></fieldset> <div class="zemanta-pixie" style="MARGIN-TOP: 10px; HEIGHT: 15px"><a class="zemanta-pixie-a" title="Zemified by Zemanta" href="http://reblog.zemanta.com/zemified/06efb3dd-b510-48f6-9ae4-02c84dfa1733/"><img class="zemanta-pixie-img" alt="Zemanta Pixie" src="http://img.zemanta.com/reblog_e.png?x-id=06efb3dd-b510-48f6-9ae4-02c84dfa1733" style="BORDER-RIGHT: medium none; BORDER-TOP: medium none; FLOAT: right; BORDER-LEFT: medium none; BORDER-BOTTOM: medium none" /></a></div></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=SgUnLX"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=SgUnLX" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=wTWkpJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=wTWkpJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=lUKurJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=lUKurJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=dT8cBJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=dT8cBJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=FZVwRJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=FZVwRJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=D6AdHj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=D6AdHj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=ZLCydj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=ZLCydj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/350429290" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 03:05:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/meru">meru</category>
      <category domain="http://securityratty.com/tag/meru networks">meru networks</category>
      <category domain="http://securityratty.com/tag/cone">cone</category>
      <category domain="http://securityratty.com/tag/silence">silence</category>
      <category domain="http://securityratty.com/tag/meru locks">meru locks</category>
      <category domain="http://securityratty.com/tag/wireless cone">wireless cone</category>
      <category domain="http://securityratty.com/tag/product line">product line</category>
      <category domain="http://securityratty.com/tag/hide legit traffic">hide legit traffic</category>
      <category domain="http://securityratty.com/tag/wireless provider game">wireless provider game</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/350429290/meru-networks-e.html">Meru Networks erects a "cone of silence"</source>
    </item>
    <item>
      <title><![CDATA[Envysion adds collaboration to managed video service]]></title>
      <link>http://securityratty.com/article/d6d6b4de0ad1de2193149ae5f645ade6</link>
      <guid>http://securityratty.com/article/d6d6b4de0ad1de2193149ae5f645ade6</guid>
      <description><![CDATA[Envysion, a Louisville, Colo.-based video software-as-a-service company, announced a new, collaborative Web-based broadcast service that corporations can use for making video clips available as a kind...]]></description>
      <content:encoded><![CDATA[Envysion, a Louisville, Colo.-based video software-as-a-service company, announced a new, collaborative Web-based broadcast service that corporations can use for making video clips available as a kind of private YouTube. The firm also says this month it passed a Level 1 Payment Card Industry compliance audit of its network operations.]]></content:encoded>
      <pubDate>Thu, 24 Jul 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/video clips">video clips</category>
      <category domain="http://securityratty.com/tag/broadcast service">broadcast service</category>
      <category domain="http://securityratty.com/tag/envysion">envysion</category>
      <category domain="http://securityratty.com/tag/network operations">network operations</category>
      <category domain="http://securityratty.com/tag/collaborative">collaborative</category>
      <category domain="http://securityratty.com/tag/month">month</category>
      <category domain="http://securityratty.com/tag/firm">firm</category>
      <category domain="http://securityratty.com/tag/corporations">corporations</category>
      <source url="http://www.networkworld.com/news/2008/072508-envysion-adds-collaboration.html?fsrc=rss-security">Envysion adds collaboration to managed video service</source>
    </item>
  </channel>
</rss>
