<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: dino]]></title>
    <link>http://securityratty.com/tag/dino</link>
    <description></description>
    <pubDate>Wed, 13 Feb 2008 16:12:03 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Last HOPE Session Videos - Seeded by AoIS]]></title>
      <link>http://securityratty.com/article/75af8ba93084f3c1dbfba377d428d3b6</link>
      <guid>http://securityratty.com/article/75af8ba93084f3c1dbfba377d428d3b6</guid>
      <description><![CDATA[To be honest, 2600s The Last HOPE conference didnt really catch my attention at first. But some of the sessions, especially Crippling Crypto: The Debian OpenSSL Debacle. That presentation, byJacob...]]></description>
      <content:encoded><![CDATA[<p>To be honest, 2600&#8217;s The Last HOPE conference didn&#8217;t really catch my attention at first. But some of the sessions, especially  &#8221;Crippling Crypto: The Debian OpenSSL Debacle&#8221;. That presentation, by Jacob Appelbaum, <a href="http://blog.trailofbits.com/" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://blog.trailofbits.com/');">Dino Dai Zovi</a>, Karsten Nohl is a winner. Not only do they provide a fantastic and detailed description of how OpenSSL&#8217;s random number generator was accidentally lobotomized, they also demonstrate how to leverage cheap cloud computing to generate the set of bad keys that resulted. (All of them!) </p>
<p>At any rate, legit torrents of the video presentations are available from <a href="http://hopetracker.donthax.me/" onclick="javascript:pageTracker._trackPageview('/outbound/article/http://hopetracker.donthax.me/');" target="_blank">The Last HOPE Video Tracker</a>. Art of Information Security is seeding torrents, and plans to do so for the next 10 days.</p>
<p>Check &#8216;em out.</p>
<p>Cheers, Erik</p>
<p></p>
<p><a href="http://artofinfosec.com/96/last-hope-video-seeded-by-aois/" >Last HOPE Session Videos - Seeded by AoIS</a></p>
<img src="http://feeds.feedburner.com/~r/artofinfosec/~4/358009088" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 06 Aug 2008 22:57:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hope session videos">hope session videos</category>
      <category domain="http://securityratty.com/tag/legit torrents">legit torrents</category>
      <category domain="http://securityratty.com/tag/debian openssl debacle">debian openssl debacle</category>
      <category domain="http://securityratty.com/tag/hope video tracker">hope video tracker</category>
      <category domain="http://securityratty.com/tag/torrents">torrents</category>
      <category domain="http://securityratty.com/tag/dino dai zovi">dino dai zovi</category>
      <category domain="http://securityratty.com/tag/bad keys">bad keys</category>
      <category domain="http://securityratty.com/tag/aois">aois</category>
      <category domain="http://securityratty.com/tag/openssls random">openssls random</category>
      <source url="http://feeds.feedburner.com/~r/artofinfosec/~3/358009088/">Last HOPE Session Videos - Seeded by AoIS</source>
    </item>
    <item>
      <title><![CDATA[Missing the Point]]></title>
      <link>http://securityratty.com/article/1306974e422cef843bed7b475dd96f96</link>
      <guid>http://securityratty.com/article/1306974e422cef843bed7b475dd96f96</guid>
      <description><![CDATA[A co-worker passed along this snapshot taken at the Karsten Nohl, Jake Appelbaum, and Dino Dai Zovi talk at HOPE this past weekend. The context, of course, is that the overzealous Debian developer who...]]></description>
      <content:encoded><![CDATA[<p>A co-worker passed along this snapshot taken at the Karsten Nohl, Jake Appelbaum, and Dino Dai Zovi talk at HOPE this past weekend.  The context, of course, is that the overzealous Debian developer who accidentally <a href="http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0166">crippled OpenSSL</a> back in 2006 said he did so because <a href="http://research.swtch.com/2008/05/lessons-from-debianopenssl-fiasco.html">valgrind reported uninitialized memory use</a>.  Click through for the full-size version.</p>
<p><a href='http://www.veracode.com/blog/wp-content/uploads/2008/07/dangerous.jpg'><center><img src="http://www.veracode.com/blog/wp-content/uploads/2008/07/dangerous-300x225.jpg" alt="" title="dangerous" width="300" height="225" class="aligncenter size-medium wp-image-122 photoborder" /></center></a></p>
<p>So automated software review is <i>dangerous</i> now?  Perhaps that bullet should read &#8220;modifying code you don&#8217;t understand is dangerous.&#8221;</p>
]]></content:encoded>
      <pubDate>Mon, 21 Jul 2008 18:19:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/overzealous debian developer">overzealous debian developer</category>
      <category domain="http://securityratty.com/tag/past weekend">past weekend</category>
      <category domain="http://securityratty.com/tag/dangerous">dangerous</category>
      <category domain="http://securityratty.com/tag/jake appelbaum">jake appelbaum</category>
      <category domain="http://securityratty.com/tag/software review">software review</category>
      <category domain="http://securityratty.com/tag/bullet">bullet</category>
      <category domain="http://securityratty.com/tag/hope">hope</category>
      <category domain="http://securityratty.com/tag/openssl">openssl</category>
      <category domain="http://securityratty.com/tag/context">context</category>
      <source url="http://www.veracode.com/blog/?p=121">Missing the Point</source>
    </item>
    <item>
      <title><![CDATA[DNS Vulnerability Survives Scrutiny of Peer Review]]></title>
      <link>http://securityratty.com/article/9fc8d3f7899f8f693bb1b89afdd9ebc5</link>
      <guid>http://securityratty.com/article/9fc8d3f7899f8f693bb1b89afdd9ebc5</guid>
      <description><![CDATA[The security community is cynical. So much so, that most of the chatter thats taken place over the past 24-36 hours has suggested that Kaminskys DNS vulnerability was little more than a publicity...]]></description>
      <content:encoded><![CDATA[<p>The security community is cynical.  So much so, that most of the chatter that&#8217;s taken place over the past 24-36 hours has suggested that Kaminsky&#8217;s <a href="http://www.kb.cert.org/vuls/id/800113">DNS vulnerability</a> was little more than a publicity stunt and that his BlackHat presentation would be an over-hyped rehash of prior art.  Granted, one has to suspend disbelief to even consider that something monumental would be discovered in DNS &#8212; that&#8217;s <i>the protocol itself</i> &#8212; but hell, it&#8217;s always nice to give a guy the benefit of the doubt.</p>
<p>Faced with nearly a month of criticism and questioning, and understanding the persuasive power of a technical peer review, Dan decided to expand the inner circle, so to speak.  Rich Mogull <a href="http://securosis.com/2008/07/09/more-on-the-dns-vulnerability/">arranged a phone call</a> with Tom Ptacek and Dino Dai Zovi so that Dan could spill the beans and let them decide for themselves whether it was spin or substance.  Turns out <a href="http://www.matasano.com/log/1093/patch-your-non-djbdns-server-now-dan-was-right-i-was-wrong/">there was substance</a>.</p>
<p>Now we sit around and wait until August 6th to cram into a ballroom with a thousand sweaty conference-goers to hear the juicy details.  And Dan&#8217;s presentations are usually packed to the brim even when he&#8217;s <i>not</i> announcing anything.</p>
<p>In the meantime&#8230; how about patching those servers?</p>
]]></content:encoded>
      <pubDate>Wed, 09 Jul 2008 21:30:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/dns">dns</category>
      <category domain="http://securityratty.com/tag/kaminskys dns vulnerability">kaminskys dns vulnerability</category>
      <category domain="http://securityratty.com/tag/technical peer review">technical peer review</category>
      <category domain="http://securityratty.com/tag/dino dai zovi">dino dai zovi</category>
      <category domain="http://securityratty.com/tag/persuasive power">persuasive power</category>
      <category domain="http://securityratty.com/tag/blackhat presentation">blackhat presentation</category>
      <category domain="http://securityratty.com/tag/dan">dan</category>
      <category domain="http://securityratty.com/tag/tom ptacek">tom ptacek</category>
      <category domain="http://securityratty.com/tag/substance">substance</category>
      <source url="http://www.veracode.com/blog/?p=119">DNS Vulnerability Survives Scrutiny of Peer Review</source>
    </item>
    <item>
      <title><![CDATA[Who Are the Information Security Experts?]]></title>
      <link>http://securityratty.com/article/f4f9c8ed56a1b5e4d34585b0c64fb0e0</link>
      <guid>http://securityratty.com/article/f4f9c8ed56a1b5e4d34585b0c64fb0e0</guid>
      <description><![CDATA[Recently an executive at HP claimed that his company now employs 9 out of the top 11 security people due to HPs acquisition of SPI Dynamics
Nine out of the worlds top 11 security hackers came to HP...]]></description>
      <content:encoded><![CDATA[<p>Recently an <a href="http://www.informationweek.com/news/showArticle.jhtml?articleID=206105145">executive at HP claimed</a> that his company now employs 9 out of the top 11 security people due to HP&#8217;s acquisition of SPI Dynamics:</p>
<blockquote><p>
&#8220;Nine out of the world&#8217;s top 11 security hackers came to HP through the SPI Dynamics acquisition, he boasts, although it&#8217;s not immediately clear who ranked those top 11.&#8221;<br />
-  Mark Potts, CTO of Software, Hewlett-Packard</p>
</blockquote>
<p>Now eWeek has produced a list of the <a href="http://www.eweek.com/c/a/Security/The-15-Most-Influential-People-in-Security-Today/">15 most influential people in security today</a>. Here is the quick non-multimedia version:</p>
<ol>
<li>Tavis Ormandy, Google Security Team</li>
<li>Ivan Krstic, One Laptop Per Child</li>
<li>Chris Paget, IOActive</li>
<li>Bunnie Huang, Bunnie Studios</li>
<li>Michal Zalewski, Google</li>
<li>Window Snyder</li>
<li>The MOAB Hackers</li>
<li>Dino Dai Zovi</li>
<li>Michael Howard, Microsoft</li>
<li>HD Moore, Metasploit</li>
<li>Dave Aitel, Immunity</li>
<li>Bronwen Matthews, Microsoft</li>
<li>John Pescatore, Gartner</li>
<li>Rob Thomas and Team Cymru</li>
<li>Stefan Esser, Hardened PHP Project</li>
</ol>
<p></p>
<p>I don&#8217;t see any SPI Dynamics or HP people on this arguably less biased list.  I do see 3 of my former collegues from @stake: Dave Aitel, Dino Dai Zovi, and Window Snyder.  Seeing that giants Microsoft and Google only got 2 each on the list and @stake has 3 it lends credence that <a href="http://searchsecurity.techtarget.com/news/interview/0,289202,sid14_gci1296604,00.html">@stake was the place to be</a> for hard core security people.</p>
<p>Wikipedia has a nice large list of <a href="http://en.wikipedia.org/wiki/Category:Computer_security_specialists">computer security specialists</a>.</p>
]]></content:encoded>
      <pubDate>Wed, 13 Feb 2008 16:12:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security hackers">security hackers</category>
      <category domain="http://securityratty.com/tag/computer security specialists">computer security specialists</category>
      <category domain="http://securityratty.com/tag/security people due">security people due</category>
      <category domain="http://securityratty.com/tag/spi dynamics">spi dynamics</category>
      <category domain="http://securityratty.com/tag/spi dynamics acquisition">spi dynamics acquisition</category>
      <category domain="http://securityratty.com/tag/people">people</category>
      <category domain="http://securityratty.com/tag/google security team">google security team</category>
      <category domain="http://securityratty.com/tag/dino dai zovi">dino dai zovi</category>
      <source url="http://www.veracode.com/blog/?p=79">Who Are the Information Security Experts?</source>
    </item>
  </channel>
</rss>
