<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: feltens]]></title>
    <link>http://securityratty.com/tag/feltens</link>
    <description></description>
    <pubDate>Mon, 28 Aug 2006 14:05:36 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[My Princeton Experience and Optimism for Encryption]]></title>
      <link>http://securityratty.com/article/c2c493f4153280102edc15d4eff80f97</link>
      <guid>http://securityratty.com/article/c2c493f4153280102edc15d4eff80f97</guid>
      <description><![CDATA[As we all know by now, Ed Felten and his research group at Princeton have announced yet another landmark result in the realm of data security. For systems ranging from Java VMs to digital rights...]]></description>
      <content:encoded><![CDATA[As we all know by now, <a href="http://www.cs.princeton.edu/~felten/">Ed Felten</a> and his research group at <a href="http://www.princeton.edu/">Princeton</a> have announced yet <a href="http://citp.princeton.edu/memory/">another landmark result</a> in the realm of data security.  For systems ranging from Java VMs to digital rights management to electronic voting machines – and now to disk encryption – the research group has shown that foundations for a secure world remain elusive to the industry.<br /><br />I enjoyed the opportunity to collaborate with Dr. Felten on the <a href="http://www.cs.princeton.edu/sip/sdmi/faq.html">SDMI cracking effort</a> while I was at Princeton.  The recent paper on disk encryption vulnerabilities cites work based on <a href="http://palms.ee.princeton.edu/PALMSopen/mcgregor04protecting.pdf">part</a> of my <a href="http://palms.ee.princeton.edu/PALMSopen/McGregor_PhD_Thesis.pdf">Ph.D. thesis</a> (which explored next-generation security architectures) as a long-term solution.  Indeed, for laptop encryption and trusted systems to truly realize their promise, hardware and software must be engineered with security at the core, not at the periphery.   <br /><br />The exposed flaws in many disk encryption solutions are yet another set of disquieting examples of how difficult it is to engineer security systems for our impatient and diverse world.  Routinely, software developers – as opposed to trained security architects – are being asked to design cryptographic systems with complex design parameters and even more complex security implications.  The various attacks described in Felten’s recent paper show that security designers must improve their modeling of human behavior (and physics) when poised in front of their whiteboards.   <br /><br />Security is hard, but it is attainable!  I’m optimistic that security engineering methodology will advance over time.  Fortunately, today, a few companies are embracing a truly proactive approach for modeling threats and designing security systems. <br /><br />This week, <a href="http://www.bitarmor.com/">BitArmor</a> will be making some key technical announcements on the strength of BitArmor software against attacks described in the Felten paper and beyond.  Keep your eyes on this space...<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/BitArmor1?a=Je1GCpE"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=Je1GCpE" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=v7rCdve"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=v7rCdve" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/BitArmor1?a=ir2YGyE"><img src="http://feeds.feedburner.com/~f/BitArmor1?i=ir2YGyE" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/BitArmor1/~4/241312588" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 26 Feb 2008 02:56:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security systems">security systems</category>
      <category domain="http://securityratty.com/tag/engineer security systems">engineer security systems</category>
      <category domain="http://securityratty.com/tag/systems">systems</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/complex security implications">complex security implications</category>
      <category domain="http://securityratty.com/tag/security architects">security architects</category>
      <category domain="http://securityratty.com/tag/feltens recent paper">feltens recent paper</category>
      <category domain="http://securityratty.com/tag/recent paper">recent paper</category>
      <category domain="http://securityratty.com/tag/data security">data security</category>
      <source url="http://feeds.feedburner.com/~r/BitArmor1/~3/241312588/my-princeton-experience-and-optimism.html">My Princeton Experience and Optimism for Encryption</source>
    </item>
    <item>
      <title><![CDATA[Show 009 - An Interview with Bruce Schneier]]></title>
      <link>http://securityratty.com/article/87e2ecc3ba0a60b529ce42462bbd00b0</link>
      <guid>http://securityratty.com/article/87e2ecc3ba0a60b529ce42462bbd00b0</guid>
      <description><![CDATA[In the ninth episode of The Silver Bullet Podcast, Gary interviews Bruce Schneier. Bruce is the founder and CTO of Counterpane and is regarded as the uber-guru of computer security. He has written...]]></description>
      <content:encoded><![CDATA[<p><img align="right" alt="Bruce Schneier" title="Bruce Schneier" src="http://www.cigital.com/silverbullet/bschneier-123.jpg" /></p>
<p style="margin-top: 5px">In the ninth episode of The Silver Bullet Podcast, Gary interviews Bruce Schneier.  Bruce is the founder and CTO of Counterpane and is regarded as the &#8220;uber-guru&#8221; of computer security.  He has written eight bestselling books, most recently <em>Beyond Fear: Thinking Sensibly About Security in an Uncertain World</em> and is the editor of the massively popular Cryptogram mailing list.  In this episode, Gary and Bruce discuss the connection between physical security its technological component, the idea of risk management, the intersection of economics and security, and the ideas of &#8220;wholesale surveillance&#8221; and &#8220;security theater.&#8221;  They also discuss patch Tuesday, hack Wednesday, and Microsoft&#8217;s approach to software security.</p>
<ul>
<li><a href="http://en.wikipedia.org/wiki/Bruce_Schneier">Bruce&#8217;s Wikipedia entry</a></li>
<li><a href="http://www.amazon.com/s/104-2577668-4903944?ie=UTF8&#038;index=books&#038;rank=-relevance%2C%2Bavailability%2C-daterank&#038;field-author-exact=Schneier%2C%20Bruce">Bruce&#8217;s books</a></li>
<li><a href="http://pd.startribune.com/sp?aff=3&#038;keywords=schneier">Bruce&#8217;s recent restaurant reviews</a></li>
<li><a href="http://www.counterpane.com/">Counterpane</a></li>
<li><a href="http://crypto-gram.libsyn.com/">Crypto-Gram security podcast</a>
<li><a href="http://www.freedom-to-tinker.com/?p=1052">Property Rights Management</a> - Ed Felten&#8217;s discussion of PRM, mentioned on the show</li>
<li><a href="http://www.techdirt.com/articles/20051205/2345233.shtml">Copyright Mythbusters: Believe It or Not, Fair Use Exists</a> - a look at the &#8220;fair use doesn&#8217;t exist&#8221; argument</li>
<li><a href="http://news.bbc.co.uk/2/hi/uk_news/politics/4806948.stm">BBC plans attacked for &#8216;TV tax&#8217;</a> (March 14, 2006)</li>
<li>Bruce&#8217;s suggestion for &#8220;cheap&#8221; wines: <a href="http://www.thewinedoctor.com/regionalguides/loire.shtml">Loire wines</a>, <a href="http://www.beyond.fr/wine/provencewines.html">Provence Wines</a>, <a href="http://www.rhonerangers.org/html/wines.html">Southern Rhone wines</a></li>
</ul>
]]></content:encoded>
      <pubDate>Thu, 14 Dec 2006 08:45:53 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security theater">security theater</category>
      <category domain="http://securityratty.com/tag/software security">software security</category>
      <category domain="http://securityratty.com/tag/crypto-gram security podcast">crypto-gram security podcast</category>
      <category domain="http://securityratty.com/tag/bruce">bruce</category>
      <category domain="http://securityratty.com/tag/computer security">computer security</category>
      <category domain="http://securityratty.com/tag/physical security">physical security</category>
      <category domain="http://securityratty.com/tag/property rights management">property rights management</category>
      <category domain="http://securityratty.com/tag/bruces wikipedia entry">bruces wikipedia entry</category>
      <source url="http://www.cigital.com/silverbullet/show-009/">Show 009 - An Interview with Bruce Schneier</source>
    </item>
    <item>
      <title><![CDATA[Show 005 - An Interview with Ed Felten]]></title>
      <link>http://securityratty.com/article/b49f3f791876f5a4d0e80238a5ca10dc</link>
      <guid>http://securityratty.com/article/b49f3f791876f5a4d0e80238a5ca10dc</guid>
      <description><![CDATA[The fifth edition of the Silver Bullet Security Podcast features Ed Felten , Professor of Computer Science and Public Affairs at Princeton University and the Director of the Center for Information...]]></description>
      <content:encoded><![CDATA[<p><img align="right" alt="Ed Felten" title="Ed Felten" src="http://www.cigital.com/silverbullet/efelten-125.jpg" /></p>
<p style="margin-top: 5px">The fifth edition of the Silver Bullet Security Podcast features <a href="http://www.cs.princeton.edu/~felten">Ed Felten</a>, Professor of Computer Science and Public Affairs at Princeton University and the Director of the <a href="http://itpolicy.princeton.edu/">Center for Information Technology Policy</a>.  Gary and Ed take a look at Ed&#8217;s predictions for 2006 and how he&#8217;s faring so far and then discuss Ed&#8217;s relationship with his former adversaries.  They also talk about how to discuss difficult technology issues with lawmakers and the importance of public policy and the law to computer scientists.  Ed also outlines the challenges of raising a bright 11-year-old.</p>
<ul>
<li><a href="http://www.cigital.com/silverbullet/shows/silverbullet-005-efelten.pdf">A partial transcript of the interview in <em>IEEE Security &amp; Privacy</em></a></li>
<li><a href="http://www.freedom-to-tinker.com/">Freedom to Tinker</a> - Ed Felten&#8217;s blog</li>
<li><a href="http://www.freedom-to-tinker.com/?p=953">Ed&#8217;s Predictions for 2006</a></li>
<li><a href="http://en.wikipedia.org/wiki/Series_of_tubes">Wikipedia: Series of Tubes</a></li>
<li><a href="http://www.computer.org/security/bsisub">Subscribe to <em>IEEE Security &amp; Privacy</em></a></li>
</ul>
]]></content:encoded>
      <pubDate>Mon, 28 Aug 2006 14:05:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/eds predictions">eds predictions</category>
      <category domain="http://securityratty.com/tag/ieee security">ieee security</category>
      <category domain="http://securityratty.com/tag/discuss eds relationship">discuss eds relationship</category>
      <category domain="http://securityratty.com/tag/information technology policy">information technology policy</category>
      <category domain="http://securityratty.com/tag/bright 11-year-old">bright 11-year-old</category>
      <category domain="http://securityratty.com/tag/feltens blog">feltens blog</category>
      <category domain="http://securityratty.com/tag/privacy">privacy</category>
      <category domain="http://securityratty.com/tag/computer scientists">computer scientists</category>
      <category domain="http://securityratty.com/tag/public policy">public policy</category>
      <source url="http://www.cigital.com/silverbullet/show-005/">Show 005 - An Interview with Ed Felten</source>
    </item>
  </channel>
</rss>
