<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: results]]></title>
    <link>http://securityratty.com/tag/results</link>
    <description></description>
    <pubDate>Wed, 12 Nov 2008 13:52:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Actns/Swif.T virus found in YouTube videos]]></title>
      <link>http://securityratty.com/article/8eff71f0ca5bfea5ed734ae63e7157fa</link>
      <guid>http://securityratty.com/article/8eff71f0ca5bfea5ed734ae63e7157fa</guid>
      <description><![CDATA[TOOLS FOR FLASH ANALYSIS

Breaking news regarding malicious Flash popping up from YouTube is starting to break all over the Internet
CrunchGear has a bit of a write-up on it
Rather than sound off...]]></description>
      <content:encoded><![CDATA[<span style="font-weight:bold;">TOOLS FOR FLASH ANALYSIS<span style="font-style:italic;"></span></span><br /><br />Breaking news regarding malicious Flash popping up from YouTube is starting to break all over the Internet.<br /><a href="http://www.crunchgear.com/2008/12/02/actnsswift-virus-affecting-embedded-youtube-vids/" target="_blank">CrunchGear</a> has a bit of a write-up on it.<br />Rather than sound off about what will become old news quickly, I'd like to point you to resources I use to analyze (or have the analysis done for me, to be more concise) malicious Flash or JavaScript.<br />I grabbed the evil .swf in question from the URL below via command-line on my trusty Ubuntu box:<br /><span style="font-style:italic;">wget hxxp://www.youtube.com/v/O7tB1pYSNuE&rel=1</span> <br />I then fed l.swf to <a href="http://www.adopstools.com/index.asp" target="_blank">Adops Tools</a> and <a href="http://wepawet.cs.ucsb.edu/" target="_blank">Wepawet</a>.<br />The results from each analysis are below for your review.<br />Note <span style="font-weight:bold;">System.security.allowDomain("*")</span>.<br />Not good. ;-)<br /><a href="http://www.adopstools.com/index.asp?page=richmedia&quicklink=dVs31nEmMXI249x5&section=clickchecker&file=3-l.swf" target="_blank">Adops Tools Results</a><br /><a href="http://wepawet.cs.ucsb.edu/view.php?hash=f579d3692344177fe918405b31e5a383&type=swf" target="_blank">Wepawet Results</a><br />Use in good faith, but always be careful grabbing the evil .swf.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/12/actnsswift-virus-found-in-youtube.html&title=Actns/Swif.T%20virus%20found%20in%20YouTube%20videos " title="Actns/Swif.T virus found in YouTube videos ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/12/actnsswift-virus-found-in-youtube.html" title="Actns/Swif.T virus found in YouTube videos ">digg</a> | <a href="http://slashdot.org/submit.pl?url=http://holisticinfosec.blogspot.com/2008/12/actnsswift-virus-found-in-youtube.html">Submit to Slashdot</a>]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 07:51:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/wepawet results">wepawet results</category>
      <category domain="http://securityratty.com/tag/results">results</category>
      <category domain="http://securityratty.com/tag/adops tools results">adops tools results</category>
      <category domain="http://securityratty.com/tag/adops tools">adops tools</category>
      <category domain="http://securityratty.com/tag/tools">tools</category>
      <category domain="http://securityratty.com/tag/analysis">analysis</category>
      <category domain="http://securityratty.com/tag/youtube">youtube</category>
      <category domain="http://securityratty.com/tag/malicious flash">malicious flash</category>
      <category domain="http://securityratty.com/tag/flash analysis">flash analysis</category>
      <source url="http://holisticinfosec.blogspot.com/2008/12/actnsswift-virus-found-in-youtube.html">Actns/Swif.T virus found in YouTube videos</source>
    </item>
    <item>
      <title><![CDATA[Updated Microsoft Security Assessment Tool]]></title>
      <link>http://securityratty.com/article/b22bf798fdddd9574ca6b43e5006fd66</link>
      <guid>http://securityratty.com/article/b22bf798fdddd9574ca6b43e5006fd66</guid>
      <description><![CDATA[Greetings. In case you havent already read about it, we recently updated the Microsoft Security Assessment Tool (MSAT). Version 4.0 hit the web on 31 October. Its been four years since the initial...]]></description>
      <content:encoded><![CDATA[<p>Greetings. In case you haven’t already read about it, we recently updated the Microsoft Security Assessment Tool (MSAT). Version 4.0 hit the web on 31 October. It’s been four years since the initial release, and two years since the prior version. Between then and now your security world has evolved a lot, and the tool now reflects that.</p>  <p>Read more: <a title="http://technet.microsoft.com/en-us/security/cc185712.aspx" href="http://technet.microsoft.com/en-us/security/cc185712.aspx">http://technet.microsoft.com/en-us/security/cc185712.aspx</a></p>  <p>Download now: <a title="http://www.microsoft.com/downloads/details.aspx?FamilyId=CD057D9D-86B9-4E35-9733-7ACB0B2A3CA1&amp;displaylang=en" href="http://www.microsoft.com/downloads/details.aspx?FamilyId=CD057D9D-86B9-4E35-9733-7ACB0B2A3CA1&amp;displaylang=en">http://www.microsoft.com/downloads/details.aspx?FamilyId=CD057D9D-86B9-4E35-9733-7ACB0B2A3CA1&amp;displaylang=en</a></p>  <p>Take a few moments and give yourself a security checkup. If you have any comments or feedback on the tool, feel free to leave them here on my blog—I’ll make sure the right people see it.</p>  <p>&#160;</p>  <p>From the download page:</p>  <p>The MSAT employs a holistic approach to measuring your security posture by covering topics across people, process, and technology. Findings are coupled with prescriptive guidance and recommended mitigation efforts, including links to more information for additional industry guidance. These resources may assist you in keeping you aware of specific tools and methods that can help change the security posture of your IT environment. </p>  <p>There are two assessments that define the Microsoft Security Assessment Tool: </p>  <ul>   <li>Business Risk Profile Assessment</li>    <li>Defense in Depth Assessment (UPDATED)</li> </ul>  <p>The questions identified in the survey portion of the tool and the associated answers are derived from commonly accepted best practices around security, both general and specific. The questions and the recommendations that the tool offers are based on standards such as ISO 17799 and NIST-800.x, as well as recommendations and prescriptive guidance from Microsoft’s Trustworthy Computing Group and additional security resources valued in the industry.</p>  <p>After completing an Assessment, you will gain access to a detailed report of your results. You may also compare your results with those of your peers (by industry and company size), provided that you upload your results anonymously to the secure MSAT Web server. When you upload your data the application will simultaneously retrieve the most recent data available. To be able to provide this comparative data, we need customers such as you to upload their information. All information is kept strictly confidential and no personally identifiable information whatsoever will be sent.</p><img src="http://blogs.technet.com/aggbug.aspx?PostID=3162703" width="1" height="1">]]></content:encoded>
      <pubDate>Tue, 02 Dec 2008 01:13:03 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security world">security world</category>
      <category domain="http://securityratty.com/tag/additional security resources">additional security resources</category>
      <category domain="http://securityratty.com/tag/tool">tool</category>
      <category domain="http://securityratty.com/tag/security posture">security posture</category>
      <category domain="http://securityratty.com/tag/identifiable information whatsoever">identifiable information whatsoever</category>
      <category domain="http://securityratty.com/tag/assessment">assessment</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/tool offers">tool offers</category>
      <source url="http://blogs.technet.com/steriley/archive/2008/12/01/updated-microsoft-security-assessment-tool.aspx">Updated Microsoft Security Assessment Tool</source>
    </item>
    <item>
      <title><![CDATA[Manage and test firewall changes]]></title>
      <link>http://securityratty.com/article/84538b01c1d530bd4ed4a768a968f728</link>
      <guid>http://securityratty.com/article/84538b01c1d530bd4ed4a768a968f728</guid>
      <description><![CDATA[Regardless of how you approach firewall management, manage. Configuration changes which appear to work properly can easily produce unwanted results. Only a formalized change and testing process based...]]></description>
      <content:encoded><![CDATA[Regardless of how you approach firewall management, manage.  Configuration changes which appear to work properly can easily produce unwanted results.  Only a formalized change and testing process based on clear strategic objectives can prevent growing cracks in the wall.]]></content:encoded>
      <pubDate>Mon, 01 Dec 2008 10:10:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/approach firewall management">approach firewall management</category>
      <category domain="http://securityratty.com/tag/easily produce">easily produce</category>
      <category domain="http://securityratty.com/tag/process based">process based</category>
      <category domain="http://securityratty.com/tag/strategic objectives">strategic objectives</category>
      <category domain="http://securityratty.com/tag/manage">manage</category>
      <category domain="http://securityratty.com/tag/prevent">prevent</category>
      <category domain="http://securityratty.com/tag/change">change</category>
      <category domain="http://securityratty.com/tag/wall">wall</category>
      <category domain="http://securityratty.com/tag/cracks">cracks</category>
      <source url="http://networking.ittoolbox.com/r/rss.asp?url=http://it.toolbox.com/blogs/adventuresinsecurity/manage-and-test-firewall-changes-28567">Manage and test firewall changes</source>
    </item>
    <item>
      <title><![CDATA[Forensic genomics]]></title>
      <link>http://securityratty.com/article/db4fa79fc51e6d9290abb3a8fd263e3f</link>
      <guid>http://securityratty.com/article/db4fa79fc51e6d9290abb3a8fd263e3f</guid>
      <description><![CDATA[I recently presented a paper on Forensic genomics: kin privacy, driftnets and other open questions (co-authored with Lucia Bianchi, Pietro Liò and Douwe Korff ) at WPES 2008 , the Workshop for...]]></description>
      <content:encoded><![CDATA[<p><a href="http://www.cl.cam.ac.uk/~fms27/">I</a> recently presented a paper on <a href="http://www.cl.cam.ac.uk/~fms27/papers/2008-StajanoBiaLioKor-genomics.pdf"><em>Forensic genomics: kin privacy, driftnets and other open questions</em></a> (co-authored with Lucia Bianchi, <a href="http://www.cl.cam.ac.uk/~pl219/">Pietro Liò</a> and <a href="http://www.londonmet.ac.uk/research-units/hrsj/staff/douwe-korff.cfm">Douwe Korff</a>) at <a href="http://dais.cs.uiuc.edu/wpes08/">WPES 2008</a>, the Workshop for Privacy in the Electronic Society of <a href="http://www.sigsac.org/ccs/CCS2008/">ACM CCS</a>, the ACM Computer and Communication Security</a> conference. Pietro and I also gave a <a href="http://talks.cam.ac.uk/talk/index/13300">related talk</a> here at the Computer Laboratory in Cambridge.</p>
<p>While <a href="http://en.wikipedia.org/wiki/Genetics">genetics</a> is concerned with the observation of specific sections of DNA, genomics is about studying the entire <a href="http://en.wikipedia.org/wiki/Genome">genome </a> of an organism, something that has only become practically possible in recent years. In forensic genetics, which is the technology behind the large national DNA databases being built in several countries including notably UK and USA (<a href="http://www.nature.com/embor/journal/v7/n1s/pdf/7400727.pdf">Wallace&#8217;s outstanding article</a> lucidly exposes many significant issues), investigators compare scene-of-crime samples with database samples by checking if they match, but only on a very small number of specific locations in the genome (e.g. 13 locations according to the <a href="http://en.wikipedia.org/wiki/Codis">CODIS</a> rules). In our paper we explore what might change when forensic analysis moves from genetics to genomics over the next few decades. This is a problem that can only be meaningfully approached from a multi-disciplinary viewpoint and indeed our combined backgrounds cover computer security, bioinformatics and law.</p>
<p><img src="http://upload.wikimedia.org/wikipedia/commons/7/7a/Codis_profile.jpg" alt="CODIS markers" /><em><br />
(Image from <a href="http://en.wikipedia.org/wiki/Image:Codis_profile.jpg">Wikimedia commons</a>, in turn from <a href="http://www.cstl.nist.gov/div831/strbase/fbicore.htm">NIST</a>.)</em></p>
<p>Sequencing the first human genome (2003) cost 2.7 billion dollars and took 13 years. The US&#8217;s National Human Genome Research Institute has <a href="http://www.medicalnewstoday.com/articles/118963.php">offered over 20 M$ worth of grants</a> towards the goal of <a href="http://www.genome.gov/27527584">driving the cost of whole-genome sequencing down to a thousand dollars</a>. This will enable <a href="http://en.wikipedia.org/wiki/Personal_genomics">personalized genomic medicine</a> (e.g. predicting genetic risk of contracting specific diseases) but will also open up a number of ethical and privacy-related problems. Eugenetic abortions, genomic pre-screening as precondition for healthcare (or even just dating&#8230;), (mis)use of genomic data for purposes other than that for which it was collected and so forth. In various jurisdictions there exists legislation (such as the recent <a href="http://www.govtrack.us/congress/billtext.xpd?bill=h110-493&amp;show-changes=0&amp;page-command=print">GINA</a> in the US) that attempts to protect citizens from some of the possible abuses; but how strongly is it enforced? And is it enough? In the forensic context, is the DNA analysis procedure as infallible as we are led to believe? There are many subtleties associated with the interpretation of statistical results; when even professional statisticians disagree, how are the poor jurors expected to reach a fair verdict? Another subtle issue is kin privacy: if the scene-of-crime sample, compared with everyone in the database, partially matches Alice, this may be used as a hint to investigate all her relatives, who aren&#8217;t even in the database; indeed, some 1980s murders were recently solved in this way. &#8220;This raises compelling policy questions about the balance between collective security and individual privacy&#8221; [<a href="http://www.sciencemag.org/cgi/content/full/sci;312/5778/1315">Bieber, Brenner, Lazer, 2006</a>]. Should a democracy allow such a &#8220;driftnet&#8221; approach of suspecting and investigating all the innocents in order to catch the guilty?</p>
<p>This is a paper of questions rather than one of solutions. We believe an informed public debate is needed <em>before</em> the expected transition from genetics to genomics takes place. We want to stimulate discussion and therefore we invite you to read the paper, make up your mind and support what you believe are the right answers.</p>
]]></content:encoded>
      <pubDate>Thu, 27 Nov 2008 12:58:58 +0000</pubDate>
      <category domain="http://securityratty.com/tag/genomics">genomics</category>
      <category domain="http://securityratty.com/tag/forensic genomics">forensic genomics</category>
      <category domain="http://securityratty.com/tag/privacy">privacy</category>
      <category domain="http://securityratty.com/tag/individual privacy">individual privacy</category>
      <category domain="http://securityratty.com/tag/dna">dna</category>
      <category domain="http://securityratty.com/tag/national dna databases">national dna databases</category>
      <category domain="http://securityratty.com/tag/genome">genome</category>
      <category domain="http://securityratty.com/tag/whole-genome">whole-genome</category>
      <category domain="http://securityratty.com/tag/kin privacy">kin privacy</category>
      <source url="http://www.lightbluetouchpaper.org/2008/11/27/forensic-genomics/">Forensic genomics</source>
    </item>
    <item>
      <title><![CDATA[Gmail security and recent phishing activity]]></title>
      <link>http://securityratty.com/article/9a45bb9bbae6a2b37196f35b1390b206</link>
      <guid>http://securityratty.com/article/9a45bb9bbae6a2b37196f35b1390b206</guid>
      <description><![CDATA[Posted by Chris Evans

We've seen some speculation recently about a purported security vulnerability in Gmail and the theft of several website owners' domains by unauthorized third parties. At Google...]]></description>
      <content:encoded><![CDATA[<span class="byline-author">Posted by Chris Evans</span><br /><br />We've seen some speculation recently about a purported security vulnerability in Gmail and the theft of several website owners' domains by unauthorized third parties. At Google we're committed to providing secure products, and we mounted an immediate investigation. Our results indicate no evidence of a Gmail vulnerability.<br /><br />With help from affected users, we determined that the cause was a phishing scheme, a common method used by malicious actors to trick people into sharing their sensitive information. Attackers sent customized e-mails encouraging web domain owners to visit fraudulent websites such as "google-hosts.com" that they set up purely to harvest usernames and passwords. These fake sites had no affiliation with Google, and the ones we've seen are now offline. Once attackers gained the user credentials, they were free to modify the affected accounts as they desired. In this case, the attacker set up mail filters specifically designed to forward messages from web domain providers.<br /><br />Several news stories referenced a <a title="domain theft from December 2007" href="http://www.davidairey.com/google-gmail-security-hijack/" id="d.kh">domain theft from December 2007</a> that was incorrectly linked to a Gmail CSRF vulnerability</span>. We did have a Gmail CSRF bug reported to us in September 2007 that we fixed and deployed worldwide within 24 hours of private disclosure of the bug details. We know of no affected users. Neither this bug nor any other Gmail bug was involved in the December 2007 domain theft.<br /><br />We recognize how many people depend on Gmail, and we strive to make it as secure as possible. At this time, we'd like to thank the wider security community for working with us to achieve this goal. We're always looking at new ways to enhance Gmail security. For example, we recently gave users the option to <a href="http://gmailblog.blogspot.com/2008/07/making-security-easier.html" id="murn" title="always connect via https">always run their entire session using https</a>.<br /><br />To keep your Google account secure online, we recommend you only ever enter your Gmail sign-in credentials to web addresses starting with https://www.google.com/accounts, and never click-through any warnings your browser may raise about certificates. For more information on how to stay safe from phishing attacks, see our blog post <a href="http://googleblog.blogspot.com/2008/04/how-to-avoid-getting-hooked.html" id="o8q2" title="here">here</a>.<div class="feedflare">
<a href="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?a=5ziOaTxJ"><img src="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?d=41" border="0"></img></a> <a href="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?a=UypYbMp4"><img src="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?i=UypYbMp4" border="0"></img></a>
</div><img src="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~4/jSxgatXB-tY" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 25 Nov 2008 10:22:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/gmail">gmail</category>
      <category domain="http://securityratty.com/tag/bug">bug</category>
      <category domain="http://securityratty.com/tag/bug details">bug details</category>
      <category domain="http://securityratty.com/tag/gmail bug">gmail bug</category>
      <category domain="http://securityratty.com/tag/gmail csrf vulnerability">gmail csrf vulnerability</category>
      <category domain="http://securityratty.com/tag/enhance gmail security">enhance gmail security</category>
      <category domain="http://securityratty.com/tag/gmail csrf bug">gmail csrf bug</category>
      <category domain="http://securityratty.com/tag/gmail sign-in credentials">gmail sign-in credentials</category>
      <category domain="http://securityratty.com/tag/domain theft">domain theft</category>
      <source url="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/jSxgatXB-tY/gmail-security-and-recent-phishing.html">Gmail security and recent phishing activity</source>
    </item>
    <item>
      <title><![CDATA[Fayetteville State University troubleshoots with NAC]]></title>
      <link>http://securityratty.com/article/a634e018dd5e881f06cf567b26c65db4</link>
      <guid>http://securityratty.com/article/a634e018dd5e881f06cf567b26c65db4</guid>
      <description><![CDATA[Since it has implemented ConSentry NAC gear, Fayetteville State University in North Carolina finds that it gives the school better visibility into network traffic that results in using the gear as a...]]></description>
      <content:encoded><![CDATA[Since it has implemented ConSentry NAC gear, Fayetteville State University in North Carolina finds that it gives the school better visibility into network traffic that results in using the gear as a troubleshooting tool.]]></content:encoded>
      <pubDate>Mon, 24 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/gear">gear</category>
      <category domain="http://securityratty.com/tag/consentry nac gear">consentry nac gear</category>
      <category domain="http://securityratty.com/tag/university">university</category>
      <category domain="http://securityratty.com/tag/network traffic">network traffic</category>
      <category domain="http://securityratty.com/tag/north carolina">north carolina</category>
      <category domain="http://securityratty.com/tag/fayetteville">fayetteville</category>
      <category domain="http://securityratty.com/tag/visibility">visibility</category>
      <category domain="http://securityratty.com/tag/tool">tool</category>
      <category domain="http://securityratty.com/tag/school">school</category>
      <source url="http://www.networkworld.com/newsletters/vpn/2008/112408nac1.html?fsrc=rss-security">Fayetteville State University troubleshoots with NAC</source>
    </item>
    <item>
      <title><![CDATA[America's Next Top Hash Function Begins]]></title>
      <link>http://securityratty.com/article/782d55dd167bb0c5193cd7724d7e2313</link>
      <guid>http://securityratty.com/article/782d55dd167bb0c5193cd7724d7e2313</guid>
      <description><![CDATA[You might not have realized it, but the next great battle of cryptography began this month. It's not a political battle over export laws or key escrow or NSA eavesdropping, but an academic battle over...]]></description>
      <content:encoded><![CDATA[<p>You might not have realized it, but the next great battle of cryptography began this month. It's not a political battle over export laws or key escrow or NSA eavesdropping, but an academic battle over who gets to be the creator of the next hash standard.</p>

<p>Hash functions are the most commonly used cryptographic primitive, and the most poorly understood. You can think of them as fingerprint functions: They take an arbitrary long data stream and return a fixed length, and effectively unique, string. The security comes from the fact that while it's easy to generate the fingerprint from a file, it's infeasible to go the other way and generate a file given a fingerprint. </p>

<p>Originally created to make digital signatures more efficient, hashes are now used to secure the very fundamentals of our information infrastructure: in password logins, secure web connections, encryption key management, virus and malware scanning, and almost every cryptographic protocol in current use. Without cryptographic hash functions, the internet would simply not work. At the same time, there isn't a good theory of hash functions. Unlike encryption algorithms, there are no secret keys involved; this makes it harder to mathematically define exactly what hash functions are.
</p>

<p>
The National Institute of Standards and Technology, NIST, is <a href="http://csrc.nist.gov/groups/ST/hash/sha-3/index.html">holding a competition</a> to replace the SHA family of hash functions. "SHA" stands for "Secure Hash Algorithm." It was developed by the NSA in 1993 to replace the commercial MD4 and MD5 algorithms, and has been updated several times since then. All the SHA algorithms are very similar, and have been <a href="http://www.schneier.com/blog/archives/2005/02/cryptanalysis_o.html">increasingly under attack</a>, so NIST <a href="http://www.schneier.com/blog/archives/2005/10/nist_hash_works_1.html">wants to replace them</a>.</p>

<p>The competition is important because, unlike other technological standards, committee design &#151; balancing the interests of diverse constituents &#151; isn't conducive to good security. Security is best when it's designed by expert teams and then subjected to public review. And cryptography is best when it's chosen by competition.</p>

<p>In 1997, NIST held a <a href="http://en.wikipedia.org/wiki/Advanced_Encryption_Standard_process">competition</a> for a <a href="http://csrc.nist.gov/archive/aes/index.html">block cipher</a> to replace DES. Fifteen candidates and three-and-a-half years later, Rijndael became the new Advanced Encryption Standard &#151; AES. NIST is doing the same thing for what it's calling SHA-3 (not, for some unexplained reason, the Advanced Hash Standard or AHS).</p>

<p>The deadline was October 31, and NIST received 64 submissions. This isn't surprising &#151; I <a href="http://www.schneier.com/blog/archives/2008/10/the_skein_hash.html">predicted</a> 80 &#151; as most of the 15 AES submitters were professors, whose students at the time have become professors themselves, with their own students. (If NIST does a stream cipher competition in another ten years, they should expect about 256 submissions.) These submissions came from academia, from industry, and from hobbyists. <cite><a href="http://www.cio.com/article/461164/Amateurs_and_Pros_Vie_to_Build_New_Crypto_Standard">CIO magazine</a></cite> recently interviewed one of the submitters, who is 15. Twenty-eight submissions have been made <a href="http://ehash.iaik.tugraz.at/wiki/The_SHA-3_Zoo">public</a> by the submitters, and six of those have been broken.  </p>

<p>NIST is going through all the submissions right now, making sure they are complete and proper. Their goal is to publish all accepted submissions by the end of November, in advance of the <a href="http://csrc.nist.gov/groups/ST/hash/timeline.html">First Hash Function Candidate Conference</a>, to be held in Belgium right after the <a href="https://www.cosic.esat.kuleuven.be/fse2009/index.shtml">Fast Software Encryption workshop</a> in February.  </p>

<p>The group expects to quickly make a first cut of algorithms &#151; hopefully to about a dozen &#151; and give the community a year of cryptanalysis before making a second cut in 2010. After another year of cryptanalysis, NIST will choose a winner in 2011. Expect a final standard by 2012.</p>

<p>My advice for software developers is to let the process run its course. While it's tempting to use the new cool algorithms in your designs, it's far too soon to trust any of them. This process is likely to result in all sorts of new research results in hash function security, and some real cryptanalytic surprises.  Give the community a few years to figure out which ones are good and which aren't.</p>

<p>I've previously called this sort of thing a cryptographic demolition derby: The last one left standing wins. But that's only partially true. Certainly all the groups will spend the next few years trying to cryptanalyze each other, but in the end there will be a bunch of unbroken algorithms. NIST will select one based on performance and features.</p>

<p>NIST has stated that the goal of this process is not to choose the best standard but to choose a good standard. I think that's smart; in this process, the best is the enemy of the good. While there's no rush to choose a new standard &#151; the SHA-2 algorithms will remain secure for the foreseeable future &#151; we don't want to analyze the candidates forever.</p>

<p>Personally, I was part of a group of eight cryptographers that submitted <a href="http://www.schneier.com/skein.html">Skein</a> to the competition. A decade ago, writing <a href="http://www.schneier.com/twofish.html">Twofish</a> and participating in the AES process was the most fun I had ever had in cryptography. These next few years promise to be even more fun.</p>

<p>---</p>

<p><i>Bruce Schneier is chief security technology officer of BT. His new book is </i>Schneier on Security<i>.</i></p><br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=3fb55453a3600c210940457d550e67ec" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=3fb55453a3600c210940457d550e67ec" style="display: none;" border="0" height="1" width="1" alt=""/><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=AfuoN"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=AfuoN" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=1WcCn"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=1WcCn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=dcuSn"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=dcuSn" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/wired/politics/privacy?a=6jt5N"><img src="http://feeds.feedburner.com/~f/wired/politics/privacy?i=6jt5N" border="0"></img></a>
 <a href="http://feeds.wired.com/~f/wired/politics/security?a=yYWDN"><img src="http://feeds.wired.com/~f/wired/politics/security?i=yYWDN" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=yrdIn"><img src="http://feeds.wired.com/~f/wired/politics/security?i=yrdIn" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=CF0Rn"><img src="http://feeds.wired.com/~f/wired/politics/security?i=CF0Rn" border="0"></img></a> <a href="http://feeds.wired.com/~f/wired/politics/security?a=l83kN"><img src="http://feeds.wired.com/~f/wired/politics/security?i=l83kN" border="0"></img></a> </div><img src="http://feeds.feedburner.com/~r/wired/politics/privacy/~4/459059854" height="1" width="1"/><img src="http://feeds.wired.com/~r/wired/politics/security/~4/459059855" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 19 Nov 2008 23:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/hash function">hash function</category>
      <category domain="http://securityratty.com/tag/sha">sha</category>
      <category domain="http://securityratty.com/tag/sha-3">sha-3</category>
      <category domain="http://securityratty.com/tag/algorithms">algorithms</category>
      <category domain="http://securityratty.com/tag/cool algorithms">cool algorithms</category>
      <category domain="http://securityratty.com/tag/sha family">sha family</category>
      <category domain="http://securityratty.com/tag/nist held">nist held</category>
      <category domain="http://securityratty.com/tag/unlike encryption algorithms">unlike encryption algorithms</category>
      <category domain="http://securityratty.com/tag/nist">nist</category>
      <source url="http://feeds.wired.com/~r/wired/politics/security/~3/459059855/securitymatters_1120">America's Next Top Hash Function Begins</source>
    </item>
    <item>
      <title><![CDATA[Links List 11.17.08]]></title>
      <link>http://securityratty.com/article/85b0ee0a0390b793b97cc896d3067a94</link>
      <guid>http://securityratty.com/article/85b0ee0a0390b793b97cc896d3067a94</guid>
      <description><![CDATA[Wow. I think we all know that we can take or leave surveys numbers dont mean a lot without context. In this case the context is the current economic meltdown. The Society for Information Management...]]></description>
      <content:encoded><![CDATA[<p>Wow. I think we all know that we can take or leave surveys – numbers don’t mean a lot without context. In this case the “context” is the current economic meltdown. The Society for Information Management (SIM) released the results of their 2008 IT Trends Survey – predicting an “upbeat” forecast for IT jobs; the HUGE caveat here is that the study was conducted before all the recent economic woes. Apparently organizations are using IT to <a href="http://blogs.zdnet.com/BTL/?p=10765" target="_blank">drive efficiencies, streamline operations, and cut costs</a> rather than just slashing the IT budget to save money during the downturn. What would be a nice follow-up: a quick second survey comparing responses before and after. Regardless Jerry Luftman, SIM vice president of academic affairs, still says the survey results demonstrate “that the overall state of IT remains very strong.”</p>
<p><img style="margin: 5px" src="http://images.google.com/url?q=http://disney-clipart.com/Chicken-Little/Disney-Chicken-Little.jpg&amp;usg=AFQjCNGA4kajmvy1h_lrcRnuywgV7_X0aQ" alt="" width="198" height="201" align="left" />The sky is falling! Trip Chowdhry, the analyst with Global Equities Research who claimed Red Hat was ‘rubbish and the entire LAMP stack is potty, too’ published some eye-opening predictions, predominantly negative, about tech business in Silicon Valley. Now <a href="http://news.cnet.com/8301-13505_3-10094221-16.html?part=rss&amp;subj=news&amp;tag=2547-1_3-0-20" target="_blank">Chowdhry claims that “almost every VC funded open-source company</a> is struggling and will run out of money within the next six months.” (Probably not the most unbiased guy about open source) Matt Asay argues that organizations in general are struggling, but open-source companies are not that high on the list. (But are they high on the VC “axe” list??) He notes Alfresco, Pentaho and JasperSoft are some of the players with ‘millions in the bank and growing revenue.’ Asay also says Chowdhry has a responsibility to do real due diligence and not create myths. Take that, Chicken Little! (<a href="http://disney-clipart.com/Chicken-Little/Disney-Chicken-Little.jpg" target="_blank"><em>img from Disney-Clipart</em></a>)</p>
<p>We’re not as far behind as we thought we were. Google presented the results of a study they conducted about how IPv6- capable “ordinary users” are at the RIPE meeting in Dubai a few weeks ago. Turns out Apple Macs drive IPv6 penetration in the US. <a href="http://arstechnica.com/news.ars/post/20081113-google-more-macs-mean-higher-ipv6-usage-in-us.html" target="_blank">Fifty-two percent of all IPv6 users in the U.S. own a Mac</a> and use 6to4 (creating IPv6 addresses from an IPv4 address and tunneling packets) – making the US fifth in the list of countries using IPv6. Russia and France took first and second place with .76 and .65 percent IPv6-enabled traffic . The US is at .45 percent. Worldwide, 0.238 percent of Google users’ systems are IPv6-enabled and prefer to use IPv6 over IPv4.</p>
<p>Obama’s win = Google’s win? Apparently Google <a href="http://blogs.cioinsight.com/biztech30/content/2008_campaign/google_vs_microsoft_the_obama_factor.html?kc=rss" target="_blank">CEO Eric Schmidt and President-Elect Obama are very good buddies</a> and “this terrifies Microsoft”. Now competitors are more on guard against Google’s growing empire and popularity. Although Schmidt was mentioned as a possible candidate for the country’s new national CTO position, he said he would not accept the post if asked. I guess that’s one less thing Microsoft has to worry about.</p>
]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 19:35:52 +0000</pubDate>
      <category domain="http://securityratty.com/tag/list">list</category>
      <category domain="http://securityratty.com/tag/survey results">survey results</category>
      <category domain="http://securityratty.com/tag/results">results</category>
      <category domain="http://securityratty.com/tag/ipv6 addresses">ipv6 addresses</category>
      <category domain="http://securityratty.com/tag/ipv6">ipv6</category>
      <category domain="http://securityratty.com/tag/percent">percent</category>
      <category domain="http://securityratty.com/tag/open-source company">open-source company</category>
      <category domain="http://securityratty.com/tag/source">source</category>
      <category domain="http://securityratty.com/tag/fifty-two percent">fifty-two percent</category>
      <source url="http://blog.sciencelogic.com/links-list-111708/11/2008">Links List 11.17.08</source>
    </item>
    <item>
      <title><![CDATA[Hosting Meets the Cloud Debate Part II]]></title>
      <link>http://securityratty.com/article/3a3393b304f09ea17d212e2f5b730d65</link>
      <guid>http://securityratty.com/article/3a3393b304f09ea17d212e2f5b730d65</guid>
      <description><![CDATA[I have to say that Part II of this session was much anticipated after the lively interaction yesterday. It turned out to be less of a debate and more like a fireside chat. (image from pro.corbis.com...]]></description>
      <content:encoded><![CDATA[<p><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="220" alt="clip_image002" src="http://blog.sciencelogic.com/wp-content/uploads/2008/11/clip-image0024.jpg" width="323" align="left" border="0" />I have to say that Part II of this session was much anticipated after the lively interaction yesterday. It turned out to be less of a debate and more like a fireside chat. <a href="http://pro.corbis.com/images/CB042667.jpg?size=572&amp;uid=%7bDA13F798-FDA1-4B54-BFA9-4B15492E024F%7d" target="_blank">(image from pro.corbis.com)</a></p>
<p>The analysts paired up today:   <br />Antonio Piraino (<a href="http://www.t1r.com/" target="_blank">Tier1 Research</a>)    <br /><a href="http://the451group.com/about/bio_detail.php?eid=113" target="_blank">William Fellows</a> (<a href="http://the451group.com/" target="_blank">The 451 Group</a>)</p>
<p><em>My usual disclaimers on live-blogging: doesn&#8217;t include everything covered (just what was most interesting to me) and had to paraphrase some answers because I simply cannot type that fast. </em></p>
<p><strong>Quick definition of Cloud Computing     <br /></strong><strong>WF:</strong> The cloud is a continuum of grid, virtualization and utility done right. It is about provisioning services instead of servers; flexible computing instead of fixed assets. Done right, the cloud abstracts users from the complexity of grid. <a href="http://www.the451group.com/images/content/ice/ice_iceberg.jpg">Cloud computing is IT as a service</a>. Cloud computing is the Third Way &#8211; not entirely in-house or outsourced, but an optimized hybridized version of both. In light of the Goldman Sachs report out resetting IT spending forecast from up 6% to down 1%, don&#8217;t underestimate the ability for enterprises to move from capex to opex by buying cloud computing instead of building it themselves.</p>
<p>The 451 Group conducted a survey on cloud computing in March, and then revisited it a month ago. Some interesting results:</p>
<ul>
<li>84% have no plans to develop an internal cloud. 5% had no answer to this question. And for the 10% who did answer &#8211; the uses for a private/internal cloud were the same as those for a public cloud. </li>
<li>Top 6 vendors they look to help them develop an internal cloud: <a href="http://www.alleyinsider.com/2008/11/microsoft-s-smart-cloud-catch-up-plan-three-years-of-free-software-msft-" target="_blank">Microsoft</a>, <a href="http://topnews.in/ibm-expand-its-cloud-computing-efforts-285364" target="_blank">IBM</a>, Cisco, HP, Oracle, VMware </li>
</ul>
<p><strong><em>Is it all &#8220;upside&#8221; when it comes to cloud computing?       <br /></em></strong><strong>     <br />WF:</strong> Watch out for the Trojan horse, the red flag. What about the software needed to manage all this stuff? Any management software needs to take a holistic approach to solve the problem.</p>
<p><strong>AP:</strong> Increased management requirements and capability &#8211; this is actually a great story for managed hosters who can hold your hand while getting you up into the cloud. Hosters alleviate the pain points, and this is why we&#8217;re going to see continued growth and focus in the managed hosting sector.</p>
<p><strong>WF:</strong> I would argue that they&#8217;re too expensive. <a href="http://tech.blorge.com/Structure:%20/2008/10/25/amazons-ec2-cloud-moves-into-production/" target="_blank">Look at Amazon</a> &#8211; 10 cents a hit adds up.</p>
<p><strong>AP:</strong> It&#8217;s almost impossible to do an apples-to-apples comparison between cloud providers. One reason is that they charge differently. I&#8217;d say that when you&#8217;re talking about the big cloud providers, you are right &#8211; that they are expensive over the long-term, but for use in the short-term, they can be optimal.</p>
<p><strong>WF:</strong> The cloud is setting big expectations. Can IT deliver? It&#8217;s nice to talk about &#8220;shared resources for the greater good&#8221; but in any organization, you will still run into issues of power and control! Plus it&#8217;s still early days for resolution of regulatory issues and compliance around the cloud.</p>
<p><strong>Final Thoughts</strong></p>
<p><strong>AP:</strong> Think of the opportunities of using cloud computing resources in the areas of testing and pre-production &#8211; short-term use/environment (quick up/quick down), inexpensive, opex not capex. We&#8217;re already seeing the cloud fostering much innovation.</p>
<p><strong>WF:</strong> &#8220;It&#8217;s okay to fall in love with the term.&#8221; It is real but keep the expectations lower and realistic.</p>
<p><strong>AP:</strong> I agree with you. The reality is that the cloud is driving a very fundamental underlying platform change. This is not just a term or something that will fall out of fashion. There&#8217;s a real need to build trust in the cloud and leveraging shared resources in this way &#8211; so use the cloud computing term cautiously; don&#8217;t abuse it and make the cloud seem like IT&#8217;s new toy.</p>
]]></content:encoded>
      <pubDate>Wed, 12 Nov 2008 18:35:55 +0000</pubDate>
      <category domain="http://securityratty.com/tag/cloud">cloud</category>
      <category domain="http://securityratty.com/tag/public cloud">public cloud</category>
      <category domain="http://securityratty.com/tag/cloud providers">cloud providers</category>
      <category domain="http://securityratty.com/tag/cloud abstracts users">cloud abstracts users</category>
      <category domain="http://securityratty.com/tag/privateinternal cloud">privateinternal cloud</category>
      <category domain="http://securityratty.com/tag/internal cloud">internal cloud</category>
      <category domain="http://securityratty.com/tag/term">term</category>
      <category domain="http://securityratty.com/tag/pre-production short-term useenvironment">pre-production short-term useenvironment</category>
      <category domain="http://securityratty.com/tag/short-term">short-term</category>
      <source url="http://blog.sciencelogic.com/hosting-meets-the-cloud-debate-part-ii/11/2008">Hosting Meets the Cloud Debate Part II</source>
    </item>
    <item>
      <title><![CDATA[XSS Comedy III: Tax Cheats with Small Equipment]]></title>
      <link>http://securityratty.com/article/231bdf97af3811aa73d852717e216a77</link>
      <guid>http://securityratty.com/article/231bdf97af3811aa73d852717e216a77</guid>
      <description><![CDATA[As part of an ongoing series, if I may I, the third in a series on the absurd, inane, and perhaps even funny. Lest you forget: the first and second in the series
I don't know about you, but I enjoy...]]></description>
      <content:encoded><![CDATA[As part of an ongoing series, if I may I, the third in a series on the absurd, inane, and perhaps even funny. Lest you forget: the <a href="http://holisticinfosec.blogspot.com/2008/06/xss-comedy-at-mcafee-secures-expense.html" target="_blank">first</a> and <a href="http://holisticinfosec.blogspot.com/2008/09/xss-fortune-cookie.html" target="_blank">second</a> in the series.<br />I don't know about you, but I enjoy occasionally watching offerings like the History Channel, AMC, or the Military Channel. I'm a 40ish, white male and as such I likely fit the general demographic as perceived by the marketing geniuses who buy the late evening advertising blocks on these channels. <br />That does NOT mean that I cheat of my taxes and thus need the services of a plethora of scam artists selling tax relief. Nor does it mean that I have any interest in "enhancement" opportunities like Enzyte or ExtenZe. <br />I just love people who choose to skip out on a primary obligation of citizenship that most of us choose to meet, and expect to magically turn $100,000 in tax debt into $999. Then there are the "businesses" who exploit these folks and willingly convince them of their "success" via the power of advertising, at which point my patience just snaps, as it did last night. <br />Thus, part one of this rant is a mighty <span style="font-weight:bold;">bugger off</span> to all the "tax relief" companies. To their patrons, may I suggest simply paying taxes like the rest of us?<br />Here's an XSS vulnerability in the Freedom Financial Network, "as seen on TV", designed to express precisely how I feel: <br /><br /><a href="http://www.freedomfinancialnetwork.com/tax_debt.php?pid=ffn+go&key=%22%3E%3Cmarquee%3E%3Ch1%3ENOTHING_IS_FREE!%3C%2Fh1%3E%3C%2Fmarquee%3E" target="_blank">http://www.freedomfinancialnetwork.com/tax_debt.php?pid=ffn+go&key=%22%3E%3Cmarquee%3E%3Ch1%3ENOTHING_IS_FREE!%3C%2Fh1%3E%3C%2Fmarquee%3E</a><br /><br />If and when they fix this issue, here's the <a href="http://holisticinfosec.org/video/freedomtaxrelief/nothingisfree.html" target="_blank">video</a> for posterity.<br /><br />Part two of this rant will get you more bang for your buck, and I'm not talking enhancement.<br />Thanks to my utter disdain for the endlessly annoying advertising I went to the ExtenZe site to see what might be broken which immediately led me to discover an entire platform vulnerability in the ColdFusion application built by <a href="http://www.internet-direct-response.com/portfolio.html" target="_blank">Internet Direct Response (IDR)</a>, the wankers who proudly bring you Maxoderm, Vivaxa, Vazomyne, Smoke Away, and Hydroxydrene; all such reputable products, and all repetitively wearing me out via DirectTV. At the ExtenZe site I spotted a variable that seemed worthy of building a <a href="http://www.google.com/search?hl=en&q=inurl:%22microppcsite%22&start=0&sa=N" target="_blank">Googledork</a> from, and I soon discovered that it was a consistent variable in most of the sites pimping this crap; specifically, <span style="font-style:italic;">microppcsite</span>. You can follow all the search results back to our friends at IDR. <br />A little experimentation and I quickly discovered that the similar <span style="font-style:italic;">microppcterm</span> variable was vulnerable to entertaining XSS exploitation so I started with:<br /><br /><a href="http://www.extenzeforlife.com/?microppcsite=google&microppcterm=%22%3E%3Cmarquee%3E%3Ch1%3EToo_short,_Morningwood?%3C%2Fh1%3E%3C%2Fmarquee%3E&gclid=CJ3T2NXH8JYCFQQCagod7xyBrA" target="_blank">http://www.extenzeforlife.com/?microppcsite=google&microppcterm=%22%3E%3Cmarquee%3E%3Ch1%3EToo_short,_Morningwood?%3C%2Fh1%3E%3C%2Fmarquee%3E&gclid=CJ3T2NXH8JYCFQQCagod7xyBrA</a><br /><br />Pick your poison, it works on most IDR gems.<br /><br /><a href="http://www.enzyte-male-enhancement.com/google/?microppcsite=google&microppcterm=%22%3E%3Cmarquee%3E%3Ch1%3EBob_just_wants_your_money.%3C%2Fh1%3E%3C%2Fmarquee%3E" target="_blank">http://www.enzyte-male-enhancement.com/google/?microppcsite=google&microppcterm=%22%3E%3Cmarquee%3E%3Ch1%3EBob_just_wants_your_money.%3C%2Fh1%3E%3C%2Fmarquee%3E</a><br /><br />Again, a <a href="http://holisticinfosec.org/video/enhancement/enhancement.html" target="_blank">video</a>, should IDR choose to fix their app.<br /><br />And now, the grand prize for pathetic: The ExtenZe site is <a href="https://www.mcafeesecure.com/RatingVerify?ref=www.extenzeforlife.com" target="_blank">McAfee Secure</a>. <br /><br />I couldn't make this stuff up if I tried.<br />You thought www stood for world wide web. Try wee willy wankers. *sigh*<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/11/xss-comedy-iii-tax-cheats-with-small.html&title=XSS%20Comedy%20III:%20Tax%20Cheats%20with%20Small%20Equipment " title="XSS Comedy III: Tax Cheats with Small Equipment ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/11/xss-comedy-iii-tax-cheats-with-small.html" title="XSS Comedy III: Tax Cheats with Small Equipment ">digg</a> | <a href="http://slashdot.org/submit.pl?url=http://holisticinfosec.blogspot.com/2008/11/xss-comedy-iii-tax-cheats-with-small.html">Submit to Slashdot</a>]]></content:encoded>
      <pubDate>Wed, 12 Nov 2008 13:52:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/idr">idr</category>
      <category domain="http://securityratty.com/tag/idr choose">idr choose</category>
      <category domain="http://securityratty.com/tag/extenze site">extenze site</category>
      <category domain="http://securityratty.com/tag/extenze">extenze</category>
      <category domain="http://securityratty.com/tag/variable">variable</category>
      <category domain="http://securityratty.com/tag/consistent variable">consistent variable</category>
      <category domain="http://securityratty.com/tag/wankers">wankers</category>
      <category domain="http://securityratty.com/tag/choose">choose</category>
      <category domain="http://securityratty.com/tag/tax relief">tax relief</category>
      <source url="http://holisticinfosec.blogspot.com/2008/11/xss-comedy-iii-tax-cheats-with-small.html">XSS Comedy III: Tax Cheats with Small Equipment</source>
    </item>
  </channel>
</rss>
