<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: digital]]></title>
    <link>http://securityratty.com/tag/digital</link>
    <description></description>
    <pubDate>Thu, 07 Aug 2008 09:30:03 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Wee-Fi: Houston-Fi, ASCII WPA Passphrases, Green Wi-Fi]]></title>
      <link>http://securityratty.com/article/7f30d96346f66d41619e4abd9bae8e7d</link>
      <guid>http://securityratty.com/article/7f30d96346f66d41619e4abd9bae8e7d</guid>
      <description><![CDATA[Houston flips switch on free downtown Wi-Fi: Dwight Silverman of the Houston Chronicle accidentally discovers the soft launch of the network funded by EarthLink's $5m default fee. (The fee was paid...]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><a href="http://blogs.chron.com/techblog/archives/2008/08/it_lives_city_of_houston_turns_on_free_downto.html"><strong>Houston flips switch on free downtown Wi-Fi:</strong></a> Dwight Silverman of the Houston Chronicle accidentally discovers the soft launch of the network funded by EarthLink's $5m default fee. (The fee was paid when they missed a milestone, and the firm later walked away.) The downtown area now has a limited pilot project that's free; the real effort in Houston is supposed to be at 10 housing projects and in parks where service would be used to bridge the digital divide and improve the quality of life. How, exactly, is part of what's being tested.</p>

<p><a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/08/18/MNH312BTS1.DTL&hw=wi+fi&sn=004&sc=589"><strong>That's ASCII, not hex:</strong></a> An article on wardriving raises security hackles by repeating some slightly overheated statements about Wi-Fi security. The article opens with a 63-character ASCII WPA passphrase, which is later described as "hex." (ASCII passphrases in WPA can be up to 63 "printable" characters - ASCII 32 to 127 - while a hex version of a 256-bit TKIP or AES password is 64 hexadecimal digits long.) The article tries to conflate Wi-Fi attacks that led to the largest set of breaches in retail credit-card systems and wardriving, a hobbyist activity that's never been looked on very favorably by law enforcement. The sense of ennui of wardriving pioneers is pretty clear; when Wi-Fi is everywhere and generally secured, it's far less interesting. The wardriver in the article convinced the reporter that a maximum-length WPA passphrase stored on a USB drive for automatic use was the best way to go. But, really, 20 characters containing letters and punctuation and no words found in a dictionary along with changing your network's SSID (network name) provides all the security you'll ever need for a home or small business. (If you need more, deploy WPA/WPA2 Personal.)</p>

<p><a href="http://www.sfgate.com/cgi-bin/article.cgi?f=/c/a/2008/08/16/BUA712BH1O.DTL&hw=wi+fi&sn=001&sc=1000"><strong>Green Wi-Fi's Senegal efforts hit snags:</strong></a> The folks at Green Wi-Fi are well motivated, and they're running up against all forms of security theater and bureaucracy both here and in Senegal, where they have an active project. The San Francisco Chronicle notes the group's effort to build solar-powered, self-sustaining Internet access via mesh networked nodes. Getting devices out of the country, clearing customs in Senegal, and hooking up their solar system all hit problems they're working through. As with the One Laptop Per Child program, I see a "build it and they will come" mentality in <a href="http://www.green-wifi.org/"><strong>Green Wi-Fi's mission statement</strong></a>: the notion that providing computing power and Internet access will result in good things, rather than an effort to figure out what good things need to be achieved, and whether computers and the Internet will assist. </p>]]></content:encoded>
      <pubDate>Tue, 19 Aug 2008 06:26:25 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/wi-fi attacks">wi-fi attacks</category>
      <category domain="http://securityratty.com/tag/houston">houston</category>
      <category domain="http://securityratty.com/tag/wi-fi security">wi-fi security</category>
      <category domain="http://securityratty.com/tag/free downtown wi-fi">free downtown wi-fi</category>
      <category domain="http://securityratty.com/tag/free">free</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/ascii">ascii</category>
      <category domain="http://securityratty.com/tag/security theater">security theater</category>
      <source url="http://wifinetnews.com/archives/008423.html">Wee-Fi: Houston-Fi, ASCII WPA Passphrases, Green Wi-Fi</source>
    </item>
    <item>
      <title><![CDATA[Review: Eye-Fi Explore Hits the Mark]]></title>
      <link>http://securityratty.com/article/33c4299be29dce33f9010e5f6b251d93</link>
      <guid>http://securityratty.com/article/33c4299be29dce33f9010e5f6b251d93</guid>
      <description><![CDATA[After spending two weeks with the $130 Eye-Fi Explore Wi-Fi memory card, I'm a fan: The Eye-Fi Explore was introduced in July by the eponymous firm to support geotagging - embedding latitude and...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.eye.fi/products/explore/"><strong>After spending two weeks with the $130 Eye-Fi Explore Wi-Fi memory card, I'm a fan:</strong></a> The Eye-Fi Explore was introduced in July by the eponymous firm to support geotagging - embedding latitude and longitude into photo metadata - and easier uploading of images. The Eye-Fi Explore is a Secure Digital (SD) card with 2 GB of storage, a tiny computer, and a Wi-Fi radio. The Explore uses Skyhook Wireless's Wi-Fi positioning data combined with Wayport's network of 10,000 hotspots, mostly McDonald's, along with revised firmware and software that dramatically improves the experience of uploading photos.</p>

<p>The company shuffled its products into three versions several weeks ago: Eye-Fi Home ($80), which uploads only to a specific computer over a local network; Eye-Fi Share ($100), a rebranded version identical to its first offering last year, which can upload to photo-sharing services or a computer or both; and the Explore. (You can purchase <a href="http://www.amazon.com/gp/redirect.html?ie=UTF8&location=http%3A%2F%2Fwww.amazon.com%2FEye-Fi-Explore-Wireless-Digital-EYE-FI-2EX%2Fdp%2FB001ACXHXE&tag=searchbyisbn&linkCode=ur2&camp=1789&creative=9325">the Eye-Fi Explore from Amazon.com</a><img src="http://www.assoc-amazon.com/e/ir?t=searchbyisbn&amp;l=ur2&amp;o=1" width="1" height="1" border="0" alt="" style="border:none !important; margin:0px !important;" />, as well as the other models.)</p>

<p><img src="http://wifinetnews.com//images/2008/eye-fi_cards_sharer_sm.jpg" alt="eye-fi_cards_sharer_sm.jpg" border="0" width="169" height="250" align="right" />I <a href="http://seattletimes.nwsource.com/html/businesstechnology/2008101745_ptgeotag09.html"><strong>reviewed the Explore as a geotagging system</strong></a> for The Seattle Times this last Saturday; I'd <a href="http://seattletimes.nwsource.com/html/businesstechnology/2004005462_pteyefi10.html"><strong>reviewed the original Eye-Fi</strong></a> (now Eye-Fi Share) for them last year as well. You can read that review for my take on geotagging, or skip to the bottom of this review, as well.</p>

<p>The hardware is apparently the same or nearly so, and it works just as well as it did last year. The biggest improvements, however, are a few workflow tweaks that make it far easier to manage and track uploads of pictures without draining your camera's batteries down to zero.<br />
<br clear="all"></p>]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 08:13:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/eye-fi explore">eye-fi explore</category>
      <category domain="http://securityratty.com/tag/explore">explore</category>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/specific computer">specific computer</category>
      <category domain="http://securityratty.com/tag/eye-fi share">eye-fi share</category>
      <category domain="http://securityratty.com/tag/review">review</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/weeks ago">weeks ago</category>
      <category domain="http://securityratty.com/tag/wi-fi radio">wi-fi radio</category>
      <source url="http://wifinetnews.com/archives/008418.html">Review: Eye-Fi Explore Hits the Mark</source>
    </item>
    <item>
      <title><![CDATA[Again, On Laptops and US Borders]]></title>
      <link>http://securityratty.com/article/2bd5c499e76fb2d415311b593b194e2f</link>
      <guid>http://securityratty.com/article/2bd5c499e76fb2d415311b593b194e2f</guid>
      <description><![CDATA[According to the U.S. Department of Homeland Security (DHS), Customs and Border Protection (CBP) officers can confiscate and detain travelers' laptops at the U.S. border without suspicion of...]]></description>
      <content:encoded><![CDATA["According to the <a href="http://www.dhs.gov/index.shtm" rel="nofollow" target="_blank">U.S. Department of Homeland Security</a> (DHS), Customs and Border Protection (CBP) officers can confiscate and detain travelers' laptops at the U.S. border <span style="font-weight: bold;">without suspicion of wrongdoing. </span>Laptops can be taken to an off-site location for an undisclosed period of time, during which officials may examine the computer's contents and share copies of files with other agencies. This policy applies to any other form of digital or analog storage device, including iPods, cell phones, flash drives, hard drives, and tapes." (<a href="http://www.smartertravel.com/blogs/today-in-travel/your-laptop-may-be-detained-at-border.html?id=2644757&amp;source=rss_today-in-travel">source</a>)<br /><br />"The key to the above paragraph, of course, is "without suspicion of wrongdoing." Indeed, in the <a href="http://www.cbp.gov/linkhandler/cgov/travel/admissability/search_authority.ctt/search_authority.pdf" target="_blank">policy</a> (PDF), DHS says (emphasis mine), "In the course of a border search, and <em>absent individualized suspicion</em>, officers can review and analyze the information transported by any individual attempting to enter, reenter, depart, pass through, or reside in the United States."" (<a href="http://www.smartertravel.com/blogs/today-in-travel/your-laptop-may-be-detained-at-border.html?id=2644757&amp;source=rss_today-in-travel">source</a>)<br /><br />Fun question that was brought by someone on a security mailing list: <span style="font-style: italic;">if your employer-owned laptop is "captured" by DHS, TSA or Customs AND it has regulated information on it (CCs, SSNs, PHUI, etc), do you have to report it as "data loss"?</span>  The chances of that info being lost are definitely much, much higher now AND the control over such data is clearly not in your hands anymore... Niiiiice.<div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=HfDTPK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=HfDTPK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=0fuf5K"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=0fuf5K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=RHgWqK"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=RHgWqK" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/363162188" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 12 Aug 2008 07:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/border protection">border protection</category>
      <category domain="http://securityratty.com/tag/laptops">laptops</category>
      <category domain="http://securityratty.com/tag/border">border</category>
      <category domain="http://securityratty.com/tag/data loss">data loss</category>
      <category domain="http://securityratty.com/tag/homeland security">homeland security</category>
      <category domain="http://securityratty.com/tag/analog storage device">analog storage device</category>
      <category domain="http://securityratty.com/tag/policy applies">policy applies</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/suspicion">suspicion</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/363162188/again-on-laptops-and-us-borders.html">Again, On Laptops and US Borders</source>
    </item>
    <item>
      <title><![CDATA[Digital Cash in Iraq]]></title>
      <link>http://securityratty.com/article/84493590b736c33ff0c22bfa1fc5590a</link>
      <guid>http://securityratty.com/article/84493590b736c33ff0c22bfa1fc5590a</guid>
      <description><![CDATA[Smart cards have still never quite taken off across the US, and at this point its fair to wonder if they will or if they will be eclipsed by phones or some such, but smart cards sure are big outside...]]></description>
      <content:encoded><![CDATA[<p>Smart cards have still never quite taken off across the US, and at this point its fair to wonder if they will or if they will be eclipsed by phones or some such, but smart cards sure are big outside the US. One of the most interesting applications is of course digital cash and transaction processing. <a href="http://www.aplitec.co.za/">Net1 UEPS</a>&#160;(ticker: <a href="http://finance.google.com/finance?q=ueps">UEPS</a>) out of South Africa appears to be the leader here having built a $1.2B business out of this model. there are lots of regions in the world where people are underbanked or unbanked altogether and where its dangerous to have too much cash. I blogged about this earlier on <a href="http://1raindrop.typepad.com/1_raindrop/2007/08/beer-shotguns-a.html">Beer, Shotguns and Digital Cash</a>.&#160;</p><br /><div>Now <a href="http://biz.yahoo.com/iw/080804/0421781.html">Net1 UEPS is in Iraq as well</a>:</div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: arial; line-height: normal; ">The first UEPS transaction was performed on Sunday, August 3, 2008, in Baghdad, Iraq, during the official launch of the UEPS smart card technology with the two state banks namely, Rafidain Bank and Rasheed Bank.</span></p></blockquote><div><span style="font-family: arial; line-height: normal;"><br /></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: arial; line-height: normal; ">The official launch, attended by invitees from Rafidain Bank, Rasheed Bank, the Iraqi Government, War Victim Ministry and Martyrdom Ministry, demonstrated smart card registration, biometric enrolment and issuing of UEPS cards, offline loading of wage payments and government grants to the UEPS cards and dispensing of cash.</span><br /><span style="font-family: arial; line-height: normal; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: arial; line-height: normal; ">The pilot project involving 100,000 beneficiaries is now ready for implementation across selected bank branches and will enable the distribution and payment of government grants to war victims and martyrdom beneficiaries, as well as salary and wage distribution and payment to employees of the two state banks.</span><br /><span style="font-family: arial; line-height: normal; "><br /></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: arial; line-height: normal; ">Brenda Stewart, Net1 Senior Vice President Sales and Marketing, said, &quot;From the entire team at Net1, we congratulate the Iraqi consortium on this historic achievement and look forward to the successful implementation of the various projects already identified for implementation, as well as the projects currently in business development. Net1 is proud that the development of its core technology, from which it creates end-user products that satisfy the requirements of its customers, can change the way business is conducted leading to the improvement of people&#39;s lives. We share the belief of our Iraqi partners that our technology can play a fundamental role in the upliftment of the economy. The success of any technology should be measured, not only by the profits it generates for its inventors, suppliers and users, but also by the difference that it makes to the lives of people,&quot; Stewart concluded.</span></p></blockquote><div><span style="font-family: arial; line-height: normal;"><p>I think there are lessons to be learned here wrt data and message level security. Net1 UEPS is a good example a of system carrying valuable assets across hostile terrain, web security architecture can learn a lot from this model.</p><p>P.S. If you are a <a href="http://en.wikipedia.org/wiki/Joel_Greenblatt">Joel Greenblatt</a> geek - UEPS is a <a href="http://www.magicformulainvesting.com/">magic formula stock</a>&#160;(meaning they make cash and are priced cheaply) last time I checked.</p><p></p></span></div>]]></content:encoded>
      <pubDate>Mon, 11 Aug 2008 08:53:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/ueps cards">ueps cards</category>
      <category domain="http://securityratty.com/tag/ueps">ueps</category>
      <category domain="http://securityratty.com/tag/digital cash">digital cash</category>
      <category domain="http://securityratty.com/tag/cash">cash</category>
      <category domain="http://securityratty.com/tag/net1 ueps">net1 ueps</category>
      <category domain="http://securityratty.com/tag/bank">bank</category>
      <category domain="http://securityratty.com/tag/net1">net1</category>
      <category domain="http://securityratty.com/tag/rafidain bank">rafidain bank</category>
      <category domain="http://securityratty.com/tag/ueps transaction">ueps transaction</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/digital-cash-in-iraq.html">Digital Cash in Iraq</source>
    </item>
    <item>
      <title><![CDATA[Experts: Passwords May Not Be a Good Online Defense]]></title>
      <link>http://securityratty.com/article/280bac440f99e1ea6da852e1a0accd91</link>
      <guid>http://securityratty.com/article/280bac440f99e1ea6da852e1a0accd91</guid>
      <description><![CDATA[Tired of creating and changing website passwords? Many experts propose dropping passwords entirely for a security system based on cryptography. For example, machines have a cryptographically encoded...]]></description>
      <content:encoded><![CDATA[Tired of creating and changing website passwords? Many experts propose dropping passwords entirely for a security system based on cryptography. For example, machines have a cryptographically encoded conversation to establish both parties’ authenticity, using digital keys that we, as users, have no need to see.]]></content:encoded>
      <pubDate>Mon, 11 Aug 2008 02:00:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/passwords">passwords</category>
      <category domain="http://securityratty.com/tag/security system based">security system based</category>
      <category domain="http://securityratty.com/tag/website passwords">website passwords</category>
      <category domain="http://securityratty.com/tag/parties authenticity">parties authenticity</category>
      <category domain="http://securityratty.com/tag/experts propose">experts propose</category>
      <category domain="http://securityratty.com/tag/digital keys">digital keys</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/cryptography">cryptography</category>
      <category domain="http://securityratty.com/tag/conversation">conversation</category>
      <source url="http://digg.com/security/Experts_Passwords_May_Not_Be_a_Good_Online_Defense">Experts: Passwords May Not Be a Good Online Defense</source>
    </item>
    <item>
      <title><![CDATA[Squadron of Justice: protecting the digital realms for America]]></title>
      <link>http://securityratty.com/article/1497dd2cd0a3d03d5451e6c2ea545426</link>
      <guid>http://securityratty.com/article/1497dd2cd0a3d03d5451e6c2ea545426</guid>
      <description><![CDATA[A team of superheroes known as &quot;the Squadron of Justice&quot; protect America with their awesomeness and superpowers
Finally, a team of heroes has decided to defend all that is good and just on our...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><a href="http://www.stillsecureafteralltheseyears.com/photos/uncategorized/2008/08/10/squadron_of_justice.jpg"><img class="image-full" alt="Squadron_of_justice" title="Squadron_of_justice" src="http://www.stillsecureafteralltheseyears.com/photos/uncategorized/2008/08/10/squadron_of_justice.jpg" border="0"  /></a>


<h2>
A team of superheroes known as &quot;the Squadron of Justice&quot; protect America with their awesomeness and superpowers!</h2>

<p>Finally, a team of heroes has decided to defend all that is good and just on our networks. It's not anymore Marty Roesch of Snorting fame, it's not Markus Ranum, it's not Thomas Ptacek, it's not me either.</p>

<p>It's the Squadron of Justice.&nbsp; Stay tuned.</p></div>

<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=pbcFKu"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=pbcFKu" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=1pBh6K"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=1pBh6K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=KslSrK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=KslSrK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=7KRRzK"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=7KRRzK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=RK0p4K"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=RK0p4K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=RR3cdk"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=RR3cdk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=7WDARk"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=7WDARk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/361005748" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 10 Aug 2008 01:53:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/squadron">squadron</category>
      <category domain="http://securityratty.com/tag/justice">justice</category>
      <category domain="http://securityratty.com/tag/anymore marty roesch">anymore marty roesch</category>
      <category domain="http://securityratty.com/tag/thomas ptacek">thomas ptacek</category>
      <category domain="http://securityratty.com/tag/stay tuned">stay tuned</category>
      <category domain="http://securityratty.com/tag/protect america">protect america</category>
      <category domain="http://securityratty.com/tag/markus ranum">markus ranum</category>
      <category domain="http://securityratty.com/tag/team">team</category>
      <category domain="http://securityratty.com/tag/fame">fame</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/361005748/squadron-of-jus.html">Squadron of Justice: protecting the digital realms for America</source>
    </item>
    <item>
      <title><![CDATA[Researchers Crack Medeco High-Security Locks With Plastic Keys]]></title>
      <link>http://securityratty.com/article/94154b427162231204ac9e07b536bb3a</link>
      <guid>http://securityratty.com/article/94154b427162231204ac9e07b536bb3a</guid>
      <description><![CDATA[Security researchers figure out how to cut a key from a credit card to open ostensibly ultra-high-security Medeco locks, using just a digital photo of a real key. The researchers are showing off the...]]></description>
      <content:encoded><![CDATA[Security researchers figure out how to cut a key from a credit card to open ostensibly ultra-high-security Medeco locks, using just a digital photo of a real key. The researchers are showing off the trick Friday at the DefCon hacker convention in Las Vegas, where last year they showed that different Medeco locks were pickable.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=5f1124ee8260fb0f2adb792cb34970ad" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=5f1124ee8260fb0f2adb792cb34970ad" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=GhZawK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=GhZawK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=7fi2Tk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=7fi2Tk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=eiIDTk"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=eiIDTk" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=tXcETK"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=tXcETK" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=CLlsQK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=CLlsQK" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=nusClk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=nusClk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=xzMiNk"><img src="http://feeds.wired.com/~f/wired/politics/security?i=xzMiNk" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=Cg6XzK"><img src="http://feeds.wired.com/~f/wired/politics/security?i=Cg6XzK" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/359736304" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/359736658" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 08 Aug 2008 14:19:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/researchers">researchers</category>
      <category domain="http://securityratty.com/tag/security researchers figure">security researchers figure</category>
      <category domain="http://securityratty.com/tag/medeco locks">medeco locks</category>
      <category domain="http://securityratty.com/tag/real key">real key</category>
      <category domain="http://securityratty.com/tag/defcon hacker convention">defcon hacker convention</category>
      <category domain="http://securityratty.com/tag/key">key</category>
      <category domain="http://securityratty.com/tag/las vegas">las vegas</category>
      <category domain="http://securityratty.com/tag/digital photo">digital photo</category>
      <category domain="http://securityratty.com/tag/credit card">credit card</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/359736658/medeco-locks-cr.html">Researchers Crack Medeco High-Security Locks With Plastic Keys</source>
    </item>
    <item>
      <title><![CDATA[DMCA Does Not Apply to U.S. Government]]></title>
      <link>http://securityratty.com/article/4607cbfc396b405c40749fe3293fc5b2</link>
      <guid>http://securityratty.com/article/4607cbfc396b405c40749fe3293fc5b2</guid>
      <description><![CDATA[According to a recent court ruling , we are all subject to the provisions of the DMCA, but the government is not: he Court of Federal Claims that first heard the case threw it out, and the new...]]></description>
      <content:encoded><![CDATA[<p>According to a <a href="http://arstechnica.com/news.ars/post/20080804-air-force-cracks-software-carpet-bombs-dmca.html">recent court ruling</a>, we are all subject to the provisions of the DMCA, but the government is not:</p>

<blockquote>he Court of Federal Claims that first heard the case threw it out, and the new Appellate ruling upholds that decision. The reasoning behind the decisions focuses on the US government's sovereign immunity, which the court describes thusly: "The United States, as [a] sovereign, 'is immune from suit save as it consents to be sued . . . and the terms of its consent to be sued in any court define that court's jurisdiction to entertain the suit.'"

<p>In the case of copyright law, the US has given up much of its immunity, but the government retains a few noteworthy exceptions. The one most relevant to this case says that when a government employee is in a position to induce the use of the copyrighted material, "[the provision] does not provide a Government employee a right of action 'where he was in a position to order, influence, or induce use of the copyrighted work by the Government.'" Given that Davenport used his position as part of the relevant Air Force office to get his peers to use his software, the case fails this test.</p>

<p>But the court also addressed the DMCA claims made by Blueport, and its decision here is quite striking. "The DMCA itself contains no express waiver of sovereign immunity," the judge wrote, "Indeed, the substantive prohibitions of the DMCA refer to individual persons, not the Government." Thus, because sovereign immunity is not explicitly eliminated, and the phrasing of the statute does not mention organizations, the DMCA cannot be applied to the US government, even in cases where the more general immunity to copyright claims does not apply.</p>

<p>It appears that Congress took a "do as we say, not as we need to do" approach to strengthening digital copyrights.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=ocBrYK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=ocBrYK" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=zuCddK"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=zuCddK" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Fri, 08 Aug 2008 07:32:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/government">government</category>
      <category domain="http://securityratty.com/tag/dmca">dmca</category>
      <category domain="http://securityratty.com/tag/government retains">government retains</category>
      <category domain="http://securityratty.com/tag/court">court</category>
      <category domain="http://securityratty.com/tag/court define">court define</category>
      <category domain="http://securityratty.com/tag/government employee">government employee</category>
      <category domain="http://securityratty.com/tag/sovereign">sovereign</category>
      <category domain="http://securityratty.com/tag/sovereign immunity">sovereign immunity</category>
      <category domain="http://securityratty.com/tag/immunity">immunity</category>
      <source url="http://www.schneier.com/blog/archives/2008/08/dmca_does_not_a.html">DMCA Does Not Apply to U.S. Government</source>
    </item>
    <item>
      <title><![CDATA[Apptis and USNS Mercy Monitoring on the High Seas]]></title>
      <link>http://securityratty.com/article/32ab3189b54d8e46b467ebbf87db32e0</link>
      <guid>http://securityratty.com/article/32ab3189b54d8e46b467ebbf87db32e0</guid>
      <description><![CDATA[Meet Mike Lawson, Pre-Sales Engineer at Apptis, a leading system integrator and ScienceLogic partner that has deployed EM7 to meet the network, systems and application management needs of several...]]></description>
      <content:encoded><![CDATA[<p><img style="border-right: 0px; border-top: 0px; margin: 0px 10px 10px 0px; border-left: 0px; border-bottom: 0px" height="244" alt="mike2 (Small)" src="http://blog.sciencelogic.com/wp-content/uploads/2008/08/mike2-small.jpg" width="204" align="left" border="0"> Meet Mike Lawson, Pre-Sales Engineer at Apptis, a leading system integrator and ScienceLogic partner that has deployed EM7 to meet the network, systems and application management needs of several customers. We thought Mike would have an interesting perspective to share on EM7, having recently come from the “customer side” and already with a few deployments under his belt.
<p><b>ScienceLogic: Mike, what’s your background working with network and management system tools?</b>
<p><b>Mike Lawson: </b>Before joining Apptis, I worked for the Air Force, mainly in satellite communications for almost nine years. I’m probably most familiar with HP OpenView and BMC Remedy. I managed a team that used them but wasn’t involved in tool selection; like many other federal IT workers, we didn’t have a choice of tools because there were existing enterprise licenses and maintenance contracts.
<p>I also saw a large systems integrator do a full Remedy/Crystal Systems/OpenView installation. It took 6 weeks to stand up and customize to meet just the basic monitoring requirements, and it cost something like half a million dollars. At the time, I thought that wasn’t bad and was a pretty typical experience.
<p><b>ScienceLogic: Coming from where you did, what’s your take on EM7?</b>
<p><strong>Mike Lawson:</strong> Honestly, I didn’t believe that EM7 could really do all that it claimed. In many ways, it was the complete opposite of what I had seen first-hand with other monitoring solutions. Could it really cover that much functionality? At relatively much lower cost to the customer and without the licensing nightmare?
<p>That quickly changed when I needed to understand the system enough to run it at a customer’s site. I went back over the training docs I received during my initial training class and jumped in; now, 6 months later, I’m the EM7 expert and can tell you that it delivers on all those promises. (But I still need to show people to get them to believe it too)
<p>I preach the “EM7 gospel” and when anyone wants to talk monitoring, I ask about the universal pain points: cost, maintenance contracts and licensing, and then I explain EM7. The cost difference is real; the solution is based on capacity, so there’s no licensing and it’s easy to use. They are shocked to learn that they can buy multiple EM7 appliances and years of maintenance for what they paid for most other tools.
<p><b>ScienceLogic: Apptis won the contract for monitoring aboard the USNS Mercy. We love that you’re using EM7 for one of the Navy’s hospital ships. Can you tell us more?</b>
<p><strong>Mike Lawson:</strong> The USNS Mercy is a Military Sealift Command hospital ship. <a href="http://www.navy.mil/navydata/fact_display.asp?cid=4400&amp;tid=400&amp;ct=4" target="_blank">Some stats</a>:
<ul>
<li>849 feet long (nearly the size of a football field)
<li>12 fully-equipped operating rooms, a 1,000 bed hospital facility, digital radiological services, a diagnostic and clinical laboratory, a pharmacy, an optometry lab, a CAT scan and two oxygen producing plants
<li>Crew: 61 civilian mariners, 956 Naval medical staff, and 259 Naval support staff</li>
</ul>
<p>The USNS recently departed on a five-month humanitarian mission in the Western Pacific and Southeast Asia in support of Pacific Partnership 2008. The partnership provides international medical, dental and engineering teams this summer to provide humanitarian support and conduct joint, combined, and cooperative Civil-Military Operations in order to improve regional stability and build partner capacity to respond to natural disasters and pandemic.
<p>For the most part, the ship’s network is self-contained, but can also use a landline when docked. The network covers 400 devices, including Windows/Exchange servers and VMware for server virtualization. Prior to using EM7, none of the monitoring was integrated; each system was independently monitored through individual vendor-specific consoles.
<p>Out of the box, EM7 provided integrated systems, application and network management for all network gear, applications and virtual machines in one solution. We didn’t have to do a lot of customization – EM7 includes best-practice based thresholds, event and monitoring templates and this covered what USNS Mercy needed to monitor.
<p><b>ScienceLogic: You’re a systems integrator with a very useful “customer point of view” when it comes to looking at tools. From that perspective, can you share what you think are the biggest benefits that EM7 provides?</b>
<p><strong>Mike Lawson:</strong> First of all, EM7 stands up right away. We’re talking days, not weeks. In contrast to the lengthy installation of OpenView and Remedy I witnessed during my military career, I was able to configure, customize, and implement the EM7 solution for the USNS Mercy in three days.
<p>Second, it’s easy to train people on and the support is outstanding. This judgment is from first-hand experience. Right before the USNS Mercy departed on its latest voyage, the system administrator I had trained on EM7 left, so I had all of a day to train some new EM7 admins. I prepared a seven-page “cheat sheet” and over a 3-hour conference call, we walked through the entire EM7 solution; I haven’t gotten a support call since.
<p>And when a problem did crop up with a device being discovered incorrectly, ScienceLogic was very responsive. We contacted ScienceLogic support on a Saturday and they created and emailed us a video to help troubleshoot the same day. Within 30 seconds of watching the video, the problem was resolved.
<p>Finally, EM7 helps us be good stewards of the government’s money. This is very important to me personally and to Apptis as a company. Because EM7 is cheaper and deploys so quickly and easily, you might think that it’s just the opposite of what a system integrator would want to use. But that’s short-term thinking. We believe in deliver the most value for customers every time. It’s what creates trust and long-term relationships with our customers. Instead of that half million spent on standing up the solution and basic setup, I’d much rather (and I know the customer would rather) spend that on fine-tuning or extending the solution to do much, much more.
<p>As a former government employee, I know what it’s like to use a tool that doesn’t fit my needs. EM7 proves that the best solution can totally break the old model of costly, lengthy installations. EM7 has the right model: the right solution and the right price delivered as an appliance that is easy to deploy, train on and use. </p>
<p><a href="http://sharethis.com/item?&wp=abc&amp;publisher=ea11358c-69de-4e80-9804-e964a8930b70&amp;title=Apptis+and+USNS+Mercy+%26ndash%3B+Monitoring+on+the+High+Seas&amp;url=http%3A%2F%2Fblog.sciencelogic.com%2Fapptis-and-usns-mercy-monitoring-on-the-high-seas%2F08%2F2008">ShareThis</a></p>]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 11:59:40 +0000</pubDate>
      <category domain="http://securityratty.com/tag/solution">solution</category>
      <category domain="http://securityratty.com/tag/entire em7 solution">entire em7 solution</category>
      <category domain="http://securityratty.com/tag/em7">em7</category>
      <category domain="http://securityratty.com/tag/em7 gospel">em7 gospel</category>
      <category domain="http://securityratty.com/tag/em7 proves">em7 proves</category>
      <category domain="http://securityratty.com/tag/em7 admins">em7 admins</category>
      <category domain="http://securityratty.com/tag/multiple em7 appliances">multiple em7 appliances</category>
      <category domain="http://securityratty.com/tag/em7 solution">em7 solution</category>
      <category domain="http://securityratty.com/tag/explain em7">explain em7</category>
      <source url="http://blog.sciencelogic.com/apptis-and-usns-mercy-monitoring-on-the-high-seas/08/2008">Apptis and USNS Mercy Monitoring on the High Seas</source>
    </item>
    <item>
      <title><![CDATA[E-Passports Can Be Hacked and Cloned in Minutes]]></title>
      <link>http://securityratty.com/article/105ebc05ca29d986171344b815ea53c9</link>
      <guid>http://securityratty.com/article/105ebc05ca29d986171344b815ea53c9</guid>
      <description><![CDATA[A computer researcher proved it by cloning the chips in two British passports and then implanting digital images of Osama bin Laden and a suicide bomber. Both passports passed as genuine by UN...]]></description>
      <content:encoded><![CDATA[A computer researcher proved it by cloning the chips in two British passports and then implanting digital images of Osama bin Laden and a suicide bomber. Both passports passed as genuine by UN approved passport reader software. The entire process took less than an hour.]]></content:encoded>
      <pubDate>Thu, 07 Aug 2008 09:30:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/passports">passports</category>
      <category domain="http://securityratty.com/tag/british passports">british passports</category>
      <category domain="http://securityratty.com/tag/passport reader software">passport reader software</category>
      <category domain="http://securityratty.com/tag/osama bin">osama bin</category>
      <category domain="http://securityratty.com/tag/computer researcher">computer researcher</category>
      <category domain="http://securityratty.com/tag/digital images">digital images</category>
      <category domain="http://securityratty.com/tag/suicide bomber">suicide bomber</category>
      <category domain="http://securityratty.com/tag/entire process">entire process</category>
      <category domain="http://securityratty.com/tag/hour">hour</category>
      <source url="http://digg.com/security/E_Passports_Can_Be_Hacked_and_Cloned_in_Minutes">E-Passports Can Be Hacked and Cloned in Minutes</source>
    </item>
  </channel>
</rss>
