<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: recovery]]></title>
    <link>http://securityratty.com/tag/recovery</link>
    <description></description>
    <pubDate>Mon, 13 Oct 2008 05:07:51 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Will technology drive global recovery?]]></title>
      <link>http://securityratty.com/article/502ed78c48faadc6c43d4cb84932f872</link>
      <guid>http://securityratty.com/article/502ed78c48faadc6c43d4cb84932f872</guid>
      <description><![CDATA[In achieving these goals we all got sloppy and missed numerous opportunities to utilize technology to benefit society, our county, our daily lives and last but not least our...]]></description>
      <content:encoded><![CDATA[In achieving these goals we all got sloppy and missed numerous opportunities to utilize technology to benefit society, our county, our daily lives and last but not least our employer.]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/benefit society">benefit society</category>
      <category domain="http://securityratty.com/tag/numerous opportunities">numerous opportunities</category>
      <category domain="http://securityratty.com/tag/technology">technology</category>
      <category domain="http://securityratty.com/tag/daily lives">daily lives</category>
      <category domain="http://securityratty.com/tag/employer">employer</category>
      <category domain="http://securityratty.com/tag/sloppy">sloppy</category>
      <category domain="http://securityratty.com/tag/county">county</category>
      <category domain="http://securityratty.com/tag/goals">goals</category>
      <source url="http://www.networkworld.com/columnists/2008/111908-dzubeck.html?fsrc=rss-security">Will technology drive global recovery?</source>
    </item>
    <item>
      <title><![CDATA[Most Spam Came from a Single Web Hosting Firm]]></title>
      <link>http://securityratty.com/article/894b4e87cb13c364abc659a7aab3070a</link>
      <guid>http://securityratty.com/article/894b4e87cb13c364abc659a7aab3070a</guid>
      <description><![CDATA[Really : Experts say the precipitous drop-off in spam comes from Internet providers unplugging McColo Corp., a hosting provider in Northern California that was the home base for machines responsible...]]></description>
      <content:encoded><![CDATA[<p><a href="http://voices.washingtonpost.com/securityfix/2008/11/spam_volumes_drop_by_23_after.html?nav=rss_blog">Really</a>:</p>

<blockquote>Experts say the precipitous drop-off in spam comes from Internet providers unplugging McColo Corp., a hosting provider in Northern California that was the home base for machines responsible for coordinating the sending of roughly 75 percent of all spam each day.</blockquote>

<p>Certainly this won't last:</p>

<blockquote>Bhandari said he expects the spam volume to recover to normal levels in about a week, as the spam operations that were previously hosted at McColo move to a new home.

<p>"We're seeing a slow recovery," Bhandari. "We fully expect this to recover completely, and to go into the highest ever spam period during the upcoming holiday season."</blockquote></p>

<p>But with all the talk of massive botnets sending spam, it's interesting that most of it still comes from hosting services.  You'd think this would make the job of detecting spam a lot easier.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=dOYuN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=dOYuN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=HEDZN"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=HEDZN" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 02:11:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/spam volume">spam volume</category>
      <category domain="http://securityratty.com/tag/spam period">spam period</category>
      <category domain="http://securityratty.com/tag/spam operations">spam operations</category>
      <category domain="http://securityratty.com/tag/recover">recover</category>
      <category domain="http://securityratty.com/tag/recover completely">recover completely</category>
      <category domain="http://securityratty.com/tag/home">home</category>
      <category domain="http://securityratty.com/tag/home base">home base</category>
      <category domain="http://securityratty.com/tag/machines responsible">machines responsible</category>
      <source url="http://www.schneier.com/blog/archives/2008/11/most_spam_came.html">Most Spam Came from a Single Web Hosting Firm</source>
    </item>
    <item>
      <title><![CDATA[Lenovo Introduces Protection and Data Recovery Services]]></title>
      <link>http://securityratty.com/article/e12a66b1c096257f775c4a8ed40f8840</link>
      <guid>http://securityratty.com/article/e12a66b1c096257f775c4a8ed40f8840</guid>
      <description><![CDATA[Lenovo Friday introduced two new service offerings -- PC protection service that insures Lenovo notebooks from accidental damage and Data Recovery Service that rescues users' data from a faulty hard...]]></description>
      <content:encoded><![CDATA[Lenovo Friday introduced two new service offerings -- PC protection service that insures Lenovo notebooks from accidental damage and Data Recovery Service that rescues users' data from a faulty hard disk.]]></content:encoded>
      <pubDate>Thu, 13 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/data recovery service">data recovery service</category>
      <category domain="http://securityratty.com/tag/faulty hard disk">faulty hard disk</category>
      <category domain="http://securityratty.com/tag/insures lenovo notebooks">insures lenovo notebooks</category>
      <category domain="http://securityratty.com/tag/lenovo friday">lenovo friday</category>
      <category domain="http://securityratty.com/tag/service offerings">service offerings</category>
      <category domain="http://securityratty.com/tag/rescues users">rescues users</category>
      <category domain="http://securityratty.com/tag/protection service">protection service</category>
      <category domain="http://securityratty.com/tag/accidental damage">accidental damage</category>
      <source url="http://www.networkworld.com/news/2008/111408-lenovo-introduces-protection-and-data.html?fsrc=rss-security">Lenovo Introduces Protection and Data Recovery Services</source>
    </item>
    <item>
      <title><![CDATA[i365 offers new backup capabilities for SMBs]]></title>
      <link>http://securityratty.com/article/fe20ce798a5509144f198717b778b09c</link>
      <guid>http://securityratty.com/article/fe20ce798a5509144f198717b778b09c</guid>
      <description><![CDATA[Data backup vendor i365 is adding enterprise-class data backup and infrastructure disaster recovery capabilities to its products aimed at small and midsized...]]></description>
      <content:encoded><![CDATA[Data backup vendor i365 is adding enterprise-class data backup and infrastructure disaster recovery capabilities to its products aimed at small and midsized businesses.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:f4e394e8fec7ecbd0bd8afa1195d556c:MdCYTZnY4iRk4nZBF8RCUgQuf93XfMMxTnT%2F0wGMaJATAxDaE5wiBsK4W%2BPmnD76wx50ppN1YSGA'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:7cb584dcef37b5c2c48f0d567964a829:7F%2BrwDtSXFXfW%2FrisjIU%2B%2FZggeXrGznl3b5SAmBt98lb%2BuWW0LuyJXF%2Be7k9t%2BME5bmYqPGvK97brA%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:0183f6883519b11aa1881c4149ee0171:NtL6SSbpcGLcTEzhF8zeelVBU%2F4OQa%2FlW9JiNU9jry%2FoDDyromfKZjjKuq5fXyiRIVCWgO1QuNXFmg%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:596d867e79aed42938d43b0ec4bab318:qb3IjYE%2BuzUhNGfhLslY%2BAxXtCTOqG0oH6OPpahC4QbQX8K8yTq0CCpRJ2VLUpmuR9TmdGupp8v4zQ%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=5506fd12da68e45db740c1ed1634ed62" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=5506fd12da68e45db740c1ed1634ed62" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 13 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data backup">data backup</category>
      <category domain="http://securityratty.com/tag/products aimed">products aimed</category>
      <category domain="http://securityratty.com/tag/businesses">businesses</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=5506fd12da68e45db740c1ed1634ed62">i365 offers new backup capabilities for SMBs</source>
    </item>
    <item>
      <title><![CDATA[Barracuda bites into backup and disaster recovery]]></title>
      <link>http://securityratty.com/article/5b0fecc23e41a16c0cae222d5c5b503d</link>
      <guid>http://securityratty.com/article/5b0fecc23e41a16c0cae222d5c5b503d</guid>
      <description><![CDATA[Security appliance vendor Barracuda Networks has bought BitLeap, a seller of backup and disaster recovery...]]></description>
      <content:encoded><![CDATA[Security appliance vendor Barracuda Networks has bought BitLeap, a seller of backup and disaster recovery services.]]></content:encoded>
      <pubDate>Wed, 05 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/disaster recovery services">disaster recovery services</category>
      <category domain="http://securityratty.com/tag/backup">backup</category>
      <category domain="http://securityratty.com/tag/seller">seller</category>
      <category domain="http://securityratty.com/tag/bitleap">bitleap</category>
      <source url="http://www.networkworld.com/news/2008/110608-barracuda-bites-into-backup-and.html?fsrc=rss-security">Barracuda bites into backup and disaster recovery</source>
    </item>
    <item>
      <title><![CDATA[Hardware Keyloggers use detection and mitigation Phreaknic Presentation slides posted]]></title>
      <link>http://securityratty.com/article/a4ffb7265555883a6ec1791fa2e0813f</link>
      <guid>http://securityratty.com/article/a4ffb7265555883a6ec1791fa2e0813f</guid>
      <description><![CDATA[Phreaknic was a great time this year, as always. I've posted the slides from my hardware key loggers presentation at the above link. I'd like to thank the following people
Sky Dog and crew for making...]]></description>
      <content:encoded><![CDATA[<a href="http://www.phreaknic.info">Phreaknic</a> was a great time this year, as always. I've posted the slides from my hardware key loggers presentation at the above link. <br/>I'd like to thank the following people: 
<p>Sky Dog and crew for making it happen.<br/><a href="http://dailyduino.com/">Droops/Morgellon</a> for their presentation on <a href="http://dailyduino.com/">Arduino</a>, time for some hardware hacking. <br/>Sorteal for showing me the LiVes Open Source video editor.<br/>Marie for the dance and conversation.<br/><a href="http://www.digome.com/">TRiP</a> for an excellent talk on the legalities of wardriving.<br/>HandGrip/Buttstock for the Open Source AK-47 talk.<br/>All the folks who let me interview them.<br/>DOSman and Zack form being DOSman and Zack.<br/><a href="http://leebaird.com/Me/Hacking.html">Lee Baird</a> and John Skinner for comparing mobile hacking notes with me (Yippy <a href="http://leebaird.com/Me/Hacking.html">hacking with the iPhone / iPwn</a>).<br/><a href="http://www.offensive-security.com/">Ziplock</a> for the encouragement. <br/><a href="http://dualcoremusic.com/nerdcore/">Int 80</a> for the <a href="http://dualcoremusic.com/nerdcore/">Nercore</a> entertainment. <br/>Scott Moulton for the talk "At Least TEN things you didn't know about your hard drive!" Go check out his <a href="http://www.myharddrivedied.com/presentations.html">forensics and hard drive recovery videos</a>. <br/><a href="http://hackerpimps.com/">Nathan Hamiel/Shawn Moyer</a> for "Satan is on my Friends List: Attacking Social Networks", looks like I need to get into some CSRF. <br/><a href="http://www.hak5.org/">Darren, Shannon and Mubix of Hak5 </a>for the interview.<br/><a href="http://www.rmccurdy.com/">operat0r</a> for the Ettercap ideas.<br/>Brian for driving me down.</p>
<p>And everyone else I'm forgetting. It was a great weekend.</p>
<p><a href="http://feedads.googleadservices.com/~a/RAlOYBqvOeWovKvsjMCQ5RgneeA/a"><img src="http://feedads.googleadservices.com/~a/RAlOYBqvOeWovKvsjMCQ5RgneeA/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/yXBkWYheSAg" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 26 Oct 2008 13:26:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/source ak-47 talk">source ak-47 talk</category>
      <category domain="http://securityratty.com/tag/talk">talk</category>
      <category domain="http://securityratty.com/tag/zack form">zack form</category>
      <category domain="http://securityratty.com/tag/zack">zack</category>
      <category domain="http://securityratty.com/tag/nathan hamielshawn moyer">nathan hamielshawn moyer</category>
      <category domain="http://securityratty.com/tag/excellent talk">excellent talk</category>
      <category domain="http://securityratty.com/tag/source video editor">source video editor</category>
      <category domain="http://securityratty.com/tag/slides">slides</category>
      <category domain="http://securityratty.com/tag/ettercap ideas">ettercap ideas</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/yXBkWYheSAg/keyloggers.pptx">Hardware Keyloggers use detection and mitigation Phreaknic Presentation slides posted</source>
    </item>
    <item>
      <title><![CDATA[Hardware Keyloggers use detection and mitigation Phreaknic Presentation slides posted]]></title>
      <link>http://securityratty.com/article/e9f6c48276a2b3f0f66121e4f7c467f1</link>
      <guid>http://securityratty.com/article/e9f6c48276a2b3f0f66121e4f7c467f1</guid>
      <description><![CDATA[Phreaknic was a great time this year, as always. I've posted the slides from my hardware key loggers presentation at the above link. I'd like to thank the following people
Sky Dog and crew for making...]]></description>
      <content:encoded><![CDATA[<a href="http://www.phreaknic.info">Phreaknic</a> was a great time this year, as always. I've posted the slides from my hardware key loggers presentation at the above link. <br/>I'd like to thank the following people: 
<p>Sky Dog and crew for making it happen.<br/><a href="http://dailyduino.com/">Droops/Morgellon</a> for their presentation on <a href="http://dailyduino.com/">Arduino</a>, time for some hardware hacking. <br/>Sorteal for showing me the LiVes Open Source video editor.<br/>Marie for the dance and conversation.<br/><a href="http://www.digome.com/">TRiP</a> for an excellent talk on the legalities of wardriving.<br/>HandGrip/Buttstock for the Open Source AK-47 talk.<br/>All the folks who let me interview them.<br/>DOSman and Zack form being DOSman and Zack.<br/><a href="http://leebaird.com/Me/Hacking.html">Lee Baird</a> and John Skinner for comparing mobile hacking notes with me (Yippy <a href="http://leebaird.com/Me/Hacking.html">hacking with the iPhone / iPwn</a>).<br/><a href="http://www.offensive-security.com/">Ziplock</a> for the encouragement. <br/><a href="http://dualcoremusic.com/nerdcore/">Int 80</a> for the <a href="http://dualcoremusic.com/nerdcore/">Nercore</a> entertainment. <br/>Scott Moulton for the talk "At Least TEN things you didn't know about your hard drive!" Go check out his <a href="http://www.myharddrivedied.com/presentations.html">forensics and hard drive recovery videos</a>. <br/><a href="http://hackerpimps.com/">Nathan Hamiel/Shawn Moyer</a> for "Satan is on my Friends List: Attacking Social Networks", looks like I need to get into some CSRF. <br/><a href="http://www.hak5.org/">Darren, Shannon and Mubix of Hak5 </a>for the interview.<br/><a href="http://www.rmccurdy.com/">operat0r</a> for the Ettercap ideas.<br/>Brian for driving me down.</p>
<p>And everyone else I'm forgetting. It was a great weekend.</p>]]></content:encoded>
      <pubDate>Sun, 26 Oct 2008 13:26:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/source ak-47 talk">source ak-47 talk</category>
      <category domain="http://securityratty.com/tag/talk">talk</category>
      <category domain="http://securityratty.com/tag/zack form">zack form</category>
      <category domain="http://securityratty.com/tag/zack">zack</category>
      <category domain="http://securityratty.com/tag/nathan hamielshawn moyer">nathan hamielshawn moyer</category>
      <category domain="http://securityratty.com/tag/excellent talk">excellent talk</category>
      <category domain="http://securityratty.com/tag/source video editor">source video editor</category>
      <category domain="http://securityratty.com/tag/slides">slides</category>
      <category domain="http://securityratty.com/tag/ettercap ideas">ettercap ideas</category>
      <source url="http://www.irongeek.com/security/keyloggers.pptx">Hardware Keyloggers use detection and mitigation Phreaknic Presentation slides posted</source>
    </item>
    <item>
      <title><![CDATA[Ex-Pentagon Geek Plots Disaster Relief 2.0]]></title>
      <link>http://securityratty.com/article/86d205862d5745877a8f1cd004eb2ed7</link>
      <guid>http://securityratty.com/article/86d205862d5745877a8f1cd004eb2ed7</guid>
      <description><![CDATA[Linton Wells used to be one of the Pentagon geeks-in-chief. Now, he's trying to encourage the Defense Department to network with relief agencies, civic organizations and the private sector in order to...]]></description>
      <content:encoded><![CDATA[Linton Wells used to be one of the Pentagon geeks-in-chief. Now, he's trying to encourage the Defense Department to network with relief agencies, civic organizations and the private sector in order to reboot disaster recovery.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=35c874083dabfe5100866e3f87af9c66" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=35c874083dabfe5100866e3f87af9c66" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=nuupM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=nuupM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=PKODm"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=PKODm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=CpZUm"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=CpZUm" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=XABnM"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=XABnM" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=SELYM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=SELYM" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=TjgXm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=TjgXm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=c1UUm"><img src="http://feeds.wired.com/~f/wired/politics/security?i=c1UUm" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=S3HRM"><img src="http://feeds.wired.com/~f/wired/politics/security?i=S3HRM" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/423093477" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/423093481" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 16 Oct 2008 14:04:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/reboot disaster recovery">reboot disaster recovery</category>
      <category domain="http://securityratty.com/tag/pentagon geeks-in-chief">pentagon geeks-in-chief</category>
      <category domain="http://securityratty.com/tag/civic organizations">civic organizations</category>
      <category domain="http://securityratty.com/tag/relief agencies">relief agencies</category>
      <category domain="http://securityratty.com/tag/defense department">defense department</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/sector">sector</category>
      <category domain="http://securityratty.com/tag/linton">linton</category>
      <category domain="http://securityratty.com/tag/encourage">encourage</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/423093481/fast-cheap-and.html">Ex-Pentagon Geek Plots Disaster Relief 2.0</source>
    </item>
    <item>
      <title><![CDATA[Symantec details grand product-integration scheme]]></title>
      <link>http://securityratty.com/article/13ecf075d3e8fdc048f72c73066a13c3</link>
      <guid>http://securityratty.com/article/13ecf075d3e8fdc048f72c73066a13c3</guid>
      <description><![CDATA[Symantec's Open Collaborative Architecture is an ongoing project that combines its endpoint security suite and backup and recovery products with asset management offerings obtained via the Altiris...]]></description>
      <content:encoded><![CDATA[Symantec's Open Collaborative Architecture is an ongoing project that combines its endpoint security suite and backup and recovery products with asset management offerings obtained via the Altiris acquisition late last year.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:249185b20aac71f3027b7ffd7a44fa7a:9k534hmETp6nRLsKS%2BiaiJdlPk6XpxkYIEFtEiWWDoDA9sFj4AsDGp%2BiSBHUbyZwTKAazcPGR3r7'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:d9ede13e3b6f046e952dd3393b205097:NaopefQ3TJhTH7Q1oZcZhp5olEWRKTt32Haye%2B5%2FNPPT3H3SeIGk0Pt1bRh2POOnU5LzlO2qdTIeIw%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:de332f6869b162a2a318dadabb803cf1:pO%2BEP757PwF3k%2FE2atiIVscaUeG2MJMk%2BmzWVrrG5oSaIG%2BjzV%2FNABZRoa9qGngXmp6YCfmh7at3GA%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:29d8cf09f411b0ae1136f340dee609ee:gyGvzZ92hk9dJeYDdC0QN1NdDwEkhpugDectTaa9VEFOf0eopgCirQVz3WICx42807kKZ2Ws170uZw%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=021b9c32c42a5d25ca5c5f214fd8ad7a" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=021b9c32c42a5d25ca5c5f214fd8ad7a" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 15 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/asset management offerings">asset management offerings</category>
      <category domain="http://securityratty.com/tag/endpoint security suite">endpoint security suite</category>
      <category domain="http://securityratty.com/tag/symantec">symantec</category>
      <category domain="http://securityratty.com/tag/altiris acquisition">altiris acquisition</category>
      <category domain="http://securityratty.com/tag/collaborative architecture">collaborative architecture</category>
      <category domain="http://securityratty.com/tag/recovery products">recovery products</category>
      <category domain="http://securityratty.com/tag/project">project</category>
      <category domain="http://securityratty.com/tag/combines">combines</category>
      <category domain="http://securityratty.com/tag/backup">backup</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=021b9c32c42a5d25ca5c5f214fd8ad7a">Symantec details grand product-integration scheme</source>
    </item>
    <item>
      <title><![CDATA[Debunking the Latest Fear Mongering News on WPA security]]></title>
      <link>http://securityratty.com/article/db5c2f6d20bfbc204064e7ebc539557c</link>
      <guid>http://securityratty.com/article/db5c2f6d20bfbc204064e7ebc539557c</guid>
      <description><![CDATA[I had been meaning to write about recent exaggerated claims that WPA security had been hacked, but George Ou beat me to it . The buzz comes from Elcomsoft's Distributed Password Recovery . The...]]></description>
      <content:encoded><![CDATA[I had been meaning to write about recent exaggerated claims that WPA security had been hacked, but <a href="http://www.formortals.com/Home/tabid/36/EntryID/119/Default.aspx">George Ou beat me to it</a>.

The buzz comes from <a href="http://www.elcomsoft.com/edpr.html">Elcomsoft's Distributed Password Recovery</a>. The innovation is that they use NVIDIA GPU acceleration for password cracking and can distribute the crack across a network to multiple clients and their NVIDIA GPUs. The GPU acceleration, they claim, "reduces password recovery time by a factor of 20."

They also take the unfortunate approach, <a href="http://www.elcomsoft.com/PR/edpr_081009_en.pdf">in a press release</a>, of massive gains in cracking WPA and WPA2 protection, and that they can "...break Wi-Fi encryption up to 100 times faster than by using CPU only."

100 times! 2 orders of magnitude! That must be a lot, right? Well, probably not. This is where George Ou calls shenanigans.

First, he points out that this only affects password protection systems that rely on password complexity, and that, as a general rule, the time involved is proportional to the complexity of the password. So if your password would normally take a million years to crack, it would take 10,000 years with this system. Draw your own conclusions.

He also points out, just to get past the WPA buzzwordism, that this is a more general attack mechanism and could, for example, be used against certain VPN systems.

With respect to WPA/WPA2 specifically, the attack is generally useful only against home users, because they are generally the ones using PSK (Private Shared Key) authentication. "It has zero affect enterprise mode WPA deployments which use TLS protected authentication such as PEAP or EAP-TLS. Internal LAN authentication schemes such as NTLM and LDAP are also significantly weakened.  SSL authentication schemes are not vulnerable to this particular attack."

If you are relying on password complexity for protection then his advice, and mine, is old news: first, if you're a business, perhaps you should be using a TLS-based authentication system. Also, you should make sure that your passwords are sufficiently complex and changed often enough. Ou has some specific advice about this in his column, but as he says, there are usually easier ways to get passwords (like offering people chocolate for them) than to spend years cracking them with thousands of dollars of computing power.
<p><a href="http://feedads.googleadservices.com/~a/OvpRctfZEnjDyyEg3MByesn2KpY/a"><img src="http://feedads.googleadservices.com/~a/OvpRctfZEnjDyyEg3MByesn2KpY/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/zhaPa_33ZEQ" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 13 Oct 2008 05:07:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wpa">wpa</category>
      <category domain="http://securityratty.com/tag/password">password</category>
      <category domain="http://securityratty.com/tag/password recovery">password recovery</category>
      <category domain="http://securityratty.com/tag/password complexity">password complexity</category>
      <category domain="http://securityratty.com/tag/authentication">authentication</category>
      <category domain="http://securityratty.com/tag/authentication system">authentication system</category>
      <category domain="http://securityratty.com/tag/complexity">complexity</category>
      <category domain="http://securityratty.com/tag/wpa security">wpa security</category>
      <category domain="http://securityratty.com/tag/nvidia gpu acceleration">nvidia gpu acceleration</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/zhaPa_33ZEQ/debunking_the_latest_fear_mongering_news_on_wpa_security.html">Debunking the Latest Fear Mongering News on WPA security</source>
    </item>
  </channel>
</rss>
