<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: terminal]]></title>
    <link>http://securityratty.com/tag/terminal</link>
    <description></description>
    <pubDate>Mon, 14 Jul 2008 09:27:20 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Using Cain to sniff RDP/Remote Desktop/Terminal Server traffic via "Man in the Middle" ]]></title>
      <link>http://securityratty.com/article/78a3462254589b4eccc9869e55c1bfec</link>
      <guid>http://securityratty.com/article/78a3462254589b4eccc9869e55c1bfec</guid>
      <description><![CDATA[New Video: Using Cain to sniff RDP/Remote Desktop/Terminal Server traffic via &quot;Man in the Middle&quot; In this video I'll be showing how Cain can pull off a &quot;Man in the Middle&quot; attack against the Remote...]]></description>
      <content:encoded><![CDATA[New Video: <a href="http://www.irongeek.com/i.php?page=videos/cain-rdp-terminal-server-mitm-sniff">Using Cain to sniff RDP/Remote Desktop/Terminal Server traffic via "Man in the Middle" </a><br/>In this video I'll be showing how Cain can pull off a "Man in the Middle" attack against the Remote Desktop Protocol. While RDP versions 6.0 and later are less susceptible to these attacks because of the verification schemes added, there is still a risk since so many users just click yes to all warning messages.
<p><a href="http://feedads.googleadservices.com/~a/6fZZBLBAVs3MqJF3d7wayCbnEyQ/a"><img src="http://feedads.googleadservices.com/~a/6fZZBLBAVs3MqJF3d7wayCbnEyQ/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~4/-qZpp6ZPda8" height="1" width="1"/>]]></content:encoded>
      <pubDate>Sun, 19 Oct 2008 21:05:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/middle">middle</category>
      <category domain="http://securityratty.com/tag/cain">cain</category>
      <category domain="http://securityratty.com/tag/remote desktop protocol">remote desktop protocol</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/verification schemes">verification schemes</category>
      <category domain="http://securityratty.com/tag/rdp versions">rdp versions</category>
      <category domain="http://securityratty.com/tag/messages">messages</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <source url="http://feedproxy.google.com/~r/IrongeeksSecuritySite/~3/-qZpp6ZPda8/i.php">Using Cain to sniff RDP/Remote Desktop/Terminal Server traffic via "Man in the Middle" </source>
    </item>
    <item>
      <title><![CDATA[Using Cain to sniff RDP/Remote Desktop/Terminal Server traffic via "Man in the Middle" ]]></title>
      <link>http://securityratty.com/article/2bd98a457d29460c1a3990c1341e0e87</link>
      <guid>http://securityratty.com/article/2bd98a457d29460c1a3990c1341e0e87</guid>
      <description><![CDATA[New Video: Using Cain to sniff RDP/Remote Desktop/Terminal Server traffic via &quot;Man in the Middle&quot; In this video I'll be showing how Cain can pull off a &quot;Man in the Middle&quot; attack against the Remote...]]></description>
      <content:encoded><![CDATA[New Video: <a href="http://www.irongeek.com/i.php?page=videos/cain-rdp-terminal-server-mitm-sniff">Using Cain to sniff RDP/Remote Desktop/Terminal Server traffic via "Man in the Middle" </a><br/>In this video I'll be showing how Cain can pull off a "Man in the Middle" attack against the Remote Desktop Protocol. While RDP versions 6.0 and later are less susceptible to these attacks because of the verification schemes added, there is still a risk since so many users just click yes to all warning messages. ]]></content:encoded>
      <pubDate>Sun, 19 Oct 2008 21:05:45 +0000</pubDate>
      <category domain="http://securityratty.com/tag/middle">middle</category>
      <category domain="http://securityratty.com/tag/cain">cain</category>
      <category domain="http://securityratty.com/tag/remote desktop protocol">remote desktop protocol</category>
      <category domain="http://securityratty.com/tag/video">video</category>
      <category domain="http://securityratty.com/tag/verification schemes">verification schemes</category>
      <category domain="http://securityratty.com/tag/rdp versions">rdp versions</category>
      <category domain="http://securityratty.com/tag/messages">messages</category>
      <category domain="http://securityratty.com/tag/attacks">attacks</category>
      <category domain="http://securityratty.com/tag/attack">attack</category>
      <source url="http://www.irongeek.com/i.php?page=videos/cain-rdp-terminal-server-mitm-sniff">Using Cain to sniff RDP/Remote Desktop/Terminal Server traffic via "Man in the Middle" </source>
    </item>
    <item>
      <title><![CDATA[How to Clone and Modify E-Passports]]></title>
      <link>http://securityratty.com/article/d87db1f435de50bdfb362a781b2835de</link>
      <guid>http://securityratty.com/article/d87db1f435de50bdfb362a781b2835de</guid>
      <description><![CDATA[The Hackers Choice has released a tool allowing people to clone and modify electronic passports
The problem is self-signed certificates
A CA is not a great solution: Using a Certification Authority...]]></description>
      <content:encoded><![CDATA[<p>The Hackers Choice has <a href="http://blog.thc.org/index.php?/archives/4-The-Risk-of-ePassports-and-RFID.html">released</a> a tool allowing people to clone and modify electronic passports.</p>

<p>The problem is self-signed certificates.</p>

<p>A CA is not a great solution:</p>

<blockquote>Using a Certification Authority (CA) could solve the attack but at the same time introduces a new set of attack vectors:

<ol><li>The CA becomes a single point of failure. It becomes the juicy/high-value target for the attacker. Single point of failures are not good. Attractive targets are not good.

<p>Any person with access to the CA key can undetectably fake passports. Direct attacks, virus, misplacing the key by accident (the UK government is good at this!) or bribery are just a few ways of getting the CA key.</p>

<p><li>The single CA would need to be trusted by all governments. This is not practical as this means that passports would no longer be a national matter.</p>

<p><li>Multiple CA's would not work either. Any country could use its own CA to create a valid passport of any other country. Read this sentence again: Country A can create a passport data set of Country B and sign it with Country A's CA key. The terminal will validate and display the information as data from Country B.This option also multiplies the number of 'juicy' targets. It makes it also more likely for a CA key to leak.</p>

<p>Revocation lists for certificates only work when a leak/loss is detected. In most cases it will not be detected.</ol></p>

<p>So what's the solution? We know that humans are good at Border Control. In the end they protected us well for the last 120 years. We also know that humans are good at pattern matching and image recognition. Humans also do an excellent job 'assessing' the person and not just the passport. Take the human part away and passport security falls apart.</blockquote></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=UYU6L"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=UYU6L" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=z7bQL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=z7bQL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Tue, 30 Sep 2008 08:24:51 +0000</pubDate>
      <category domain="http://securityratty.com/tag/passports">passports</category>
      <category domain="http://securityratty.com/tag/passport">passport</category>
      <category domain="http://securityratty.com/tag/passport security falls">passport security falls</category>
      <category domain="http://securityratty.com/tag/passport data set">passport data set</category>
      <category domain="http://securityratty.com/tag/set">set</category>
      <category domain="http://securityratty.com/tag/electronic passports">electronic passports</category>
      <category domain="http://securityratty.com/tag/country">country</category>
      <category domain="http://securityratty.com/tag/key">key</category>
      <category domain="http://securityratty.com/tag/undetectably fake passports">undetectably fake passports</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/how_to_clone_an.html">How to Clone and Modify E-Passports</source>
    </item>
    <item>
      <title><![CDATA[$20M Cameras at New York's Freedom Tower are Pretty Sophisticated]]></title>
      <link>http://securityratty.com/article/1854e20c6c17653e3ad8d28eb7bdb765</link>
      <guid>http://securityratty.com/article/1854e20c6c17653e3ad8d28eb7bdb765</guid>
      <description><![CDATA[They're trying to detect anomalies : If you have ever wondered how security guards can possibly keep an unfailingly vigilant watch on every single one of dozens of television monitors, each depicting...]]></description>
      <content:encoded><![CDATA[<p>They're trying to <a href="http://cityroom.blogs.nytimes.com/2008/09/24/unblinking-eyes-for-20-million-at-freedom-tower/">detect anomalies</a>:</p>

<blockquote>If you have ever wondered how security guards can possibly keep an unfailingly vigilant watch on every single one of dozens of television monitors, each depicting a different scene, the answer seems to be (as you suspected): they can't.

<p>Instead, they can now rely on computers to constantly analyze the patterns, sizes, speeds, angles and motion picked up by the camera and determine -- based on how they have been programmed -- whether this constitutes a possible threat. In which case, the computer alerts the security guard whose own eyes may have been momentarily diverted. Or shut.</p>

<p>An alarm can be raised, for instance, if the computer discerns a vehicle that has been standing still for too long (say, a van in the drop-off lane of an airport terminal) or a person who is loitering while everyone else is in motion. By the same token, it will spot the individual who is moving rapidly while everyone else is shuffling along. It can spot a package that has been left behind and identify which figure in the crowd abandoned it. Or pinpoint the individual who is moving the wrong way down a one-way corridor.</p>

<p>Because one person's "abnormal situation" is another person's "hot dog vendor attracting a small crowd," the computers can be programmed to discern between times of the day and days of the week.</blockquote></p>

<p>Certainly interesting.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=y6WlL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=y6WlL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=IzyVL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=IzyVL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 25 Sep 2008 02:32:08 +0000</pubDate>
      <category domain="http://securityratty.com/tag/person">person</category>
      <category domain="http://securityratty.com/tag/hot dog vendor">hot dog vendor</category>
      <category domain="http://securityratty.com/tag/security guards">security guards</category>
      <category domain="http://securityratty.com/tag/individual">individual</category>
      <category domain="http://securityratty.com/tag/unfailingly vigilant">unfailingly vigilant</category>
      <category domain="http://securityratty.com/tag/constantly analyze">constantly analyze</category>
      <category domain="http://securityratty.com/tag/security guard">security guard</category>
      <category domain="http://securityratty.com/tag/detect anomalies">detect anomalies</category>
      <category domain="http://securityratty.com/tag/television monitors">television monitors</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/20m_cameras_at.html">$20M Cameras at New York's Freedom Tower are Pretty Sophisticated</source>
    </item>
    <item>
      <title><![CDATA[Movie Plot Threats in The Guardian ]]></title>
      <link>http://securityratty.com/article/44fad18176882cd40d3a3632e2971eda</link>
      <guid>http://securityratty.com/article/44fad18176882cd40d3a3632e2971eda</guid>
      <description><![CDATA[We spend far more effort defending our countries against specific movie-plot threats, rather than the real, broad threats. In the US during the months after the 9/11 attacks, we feared terrorists with...]]></description>
      <content:encoded><![CDATA[<p>We spend far more effort defending our countries against specific movie-plot threats, rather than the real, broad threats. In the US during the months after the 9/11 attacks, we feared terrorists with scuba gear, terrorists with crop dusters and terrorists contaminating our milk supply. Both the UK and the US fear terrorists with small bottles of liquid. Our imaginations run wild with vivid specific threats. Before long, we're envisioning an entire movie plot, without Bruce Willis saving the day. And we're scared.</p>

<p>It's not just terrorism; it's any rare risk in the news. The big fear in Canada right now, following a particularly gruesome incident, is random decapitations on intercity buses. In the US, fears of school shootings are much greater than the actual risks. In the UK, it's child predators. And people all over the world mistakenly fear flying more than driving. But the very definition of news is something that hardly ever happens. If an incident is in the news, we shouldn't worry about it. It's when something is so common that its no longer news - car crashes, domestic violence - that we should worry. But that's not the way people think.</p>

<p>Psychologically, this makes sense. We are a species of storytellers. We have good imaginations and we respond more emotionally to stories than to data. We also judge the probability of something by how easy it is to imagine, so stories that are in the news feel more probable - and ominous - than stories that are not. As a result, we overreact to the rare risks we hear stories about, and fear specific plots more than general threats.</p>

<p>The problem with building security around specific targets and tactics is that its only effective if we happen to guess the plot correctly. If we spend billions defending the Underground and terrorists bomb a school instead, we've wasted our money. If we focus on the World Cup and terrorists attack Wimbledon, we've wasted our money.</p>

<p>It's this fetish-like focus on tactics that results in the security follies at airports. We ban guns and knives, and terrorists use box-cutters. We take away box-cutters and corkscrews, so they put explosives in their shoes. We screen shoes, so they use liquids. We take away liquids, and they're going to do something else. Or they'll ignore airplanes entirely and attack a school, church, theatre, stadium, shopping mall, airport terminal outside the security area, or any of the other places where people pack together tightly.</p>

<p>These are stupid games, so let's stop playing. Some high-profile targets deserve special attention and some tactics are worse than others. Airplanes are particularly important targets because they are national symbols and because a small bomb can kill everyone aboard. Seats of government are also symbolic, and therefore attractive, targets. But targets and tactics are interchangeable.</p>

<p>The following three things are true about terrorism. One, the number of potential terrorist targets is infinite. Two, the odds of the terrorists going after any one target is zero. And three, the cost to the terrorist of switching targets is zero.</p>

<p>We need to defend against the broad threat of terrorism, not against specific movie plots. Security is most effective when it doesn't require us to guess. We need to focus resources on intelligence and investigation: identifying terrorists, cutting off their funding and stopping them regardless of what their plans are. We need to focus resources on emergency response: lessening the impact of a terrorist attack, regardless of what it is. And we need to face the geopolitical consequences of our foreign policy.</p>

<p>In 2006, UK police arrested the liquid bombers not through diligent airport security, but through intelligence and investigation. It didn't matter what the bombers' target was. It didn't matter what their tactic was. They would have been arrested regardless. That's smart security. Now we confiscate liquids at airports, just in case another group happens to attack the exact same target in exactly the same way. That's just illogical.</p>

<p>This essay <a href="http://www.guardian.co.uk/technology/2008/sep/04/terrorism.terrorismandtravel">originally appeared</a> in <i>The Guardian</i>.  Nothing I haven't already said elsewhere.</p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=BZifEL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=BZifEL" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/schneier/fulltext?a=YYA7cL"><img src="http://feeds.feedburner.com/~f/schneier/fulltext?i=YYA7cL" border="0"></img></a>
</div>]]></content:encoded>
      <pubDate>Thu, 04 Sep 2008 01:56:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/terrorists bomb">terrorists bomb</category>
      <category domain="http://securityratty.com/tag/bomb">bomb</category>
      <category domain="http://securityratty.com/tag/threats">threats</category>
      <category domain="http://securityratty.com/tag/terrorists">terrorists</category>
      <category domain="http://securityratty.com/tag/terrorists attack wimbledon">terrorists attack wimbledon</category>
      <category domain="http://securityratty.com/tag/specific targets">specific targets</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/targets">targets</category>
      <category domain="http://securityratty.com/tag/security follies">security follies</category>
      <source url="http://www.schneier.com/blog/archives/2008/09/movie_plot_thre_2.html">Movie Plot Threats in The Guardian </source>
    </item>
    <item>
      <title><![CDATA[A hopefully terminal delay in enhanced advertising]]></title>
      <link>http://securityratty.com/article/d14c307d08374610ecd650e3e3df1da7</link>
      <guid>http://securityratty.com/article/d14c307d08374610ecd650e3e3df1da7</guid>
      <description><![CDATA[NebuAd, an advertising service that tracks users' Web activities, is feeling the heat from Congress and...]]></description>
      <content:encoded><![CDATA[NebuAd, an advertising service that tracks users' Web activities, is feeling the heat from Congress and others.]]></content:encoded>
      <pubDate>Sun, 17 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tracks users">tracks users</category>
      <category domain="http://securityratty.com/tag/web activities">web activities</category>
      <category domain="http://securityratty.com/tag/heat">heat</category>
      <category domain="http://securityratty.com/tag/nebuad">nebuad</category>
      <category domain="http://securityratty.com/tag/congress">congress</category>
      <category domain="http://securityratty.com/tag/service">service</category>
      <source url="http://www.networkworld.com/columnists/2008/081808bradner.html?fsrc=rss-security">A hopefully terminal delay in enhanced advertising</source>
    </item>
    <item>
      <title><![CDATA[Mainframe Mindset]]></title>
      <link>http://securityratty.com/article/fd258564c92d60a0ba9f7e4c10df7ee6</link>
      <guid>http://securityratty.com/article/fd258564c92d60a0ba9f7e4c10df7ee6</guid>
      <description><![CDATA[You might think a mature industry like mainframes means low growth, but IBM is still selling mainframes like hotcakes. IBM said its mainframe business rose 32% in the second quarter compared to...]]></description>
      <content:encoded><![CDATA[<p>You might think a mature industry like mainframes means low growth, but IBM is still selling mainframes like hotcakes. IBM said its mainframe business rose 32% in the second quarter compared to overall sales growth of 13%. How many 1960s technologies are putting up these numbers in 2008? The reality is that what mainframes do, they do well. While some companies invest 8 figures in moving to a supposed latest and greatest ERP or CRM solution, many would be better served by putting a Web services gateway in front of the mainframe to address the mainframe&#39;s chief weakness - distribution.</p><br /><div>From a security point of view, mainframes are interesting because they were designed for a closed environment. Their advocates generally talk about the beauty of RACF and so on, and that is all well and good until people go and put them on the web! Approaches vary, but it usually amounts to MQ Series with not authentication, sitting in front of the mainframe with a J2EE server talking to the queues. What happens then is a major shift, because the mainframe security model is designed (rightly for its time) to be focused on the resource owner (remember the R in RACF). There is a minimal effort on securing the subject, the claim and so on.</div><br /><div>Again the mindset is fine when its your own employees in a room using a terminal, but its another thing altogether when you are integrating with a distributed system. This is where we need more focus on securing the subject and the claim, not just the resource. This is of course where new standards and technologies &#160;such as SAML and Information Cards come in. Its not enough to protect the object resource and assume a benign controlled (or controllable) subject and claim, you have to add layers of protection to the subject and claim as well.&#160;</div>]]></content:encoded>
      <pubDate>Wed, 13 Aug 2008 17:18:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mainframe">mainframe</category>
      <category domain="http://securityratty.com/tag/mainframe security model">mainframe security model</category>
      <category domain="http://securityratty.com/tag/mainframe business">mainframe business</category>
      <category domain="http://securityratty.com/tag/object resource">object resource</category>
      <category domain="http://securityratty.com/tag/resource">resource</category>
      <category domain="http://securityratty.com/tag/subject">subject</category>
      <category domain="http://securityratty.com/tag/claim">claim</category>
      <category domain="http://securityratty.com/tag/web services gateway">web services gateway</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/08/mainframe-mindset.html">Mainframe Mindset</source>
    </item>
    <item>
      <title><![CDATA[SSO Summit Day One Morning Session]]></title>
      <link>http://securityratty.com/article/500327e2eca382c04451c330dcc1e875</link>
      <guid>http://securityratty.com/article/500327e2eca382c04451c330dcc1e875</guid>
      <description><![CDATA[I am at the SSO Summit , high in the Colorado mountains (9200 feet elevation to be exact), the I-70 West sign is one of my favorite road signs. Ping Identity has done a great job putting this...]]></description>
      <content:encoded><![CDATA[<div>I am at the <a href="http://www.ssosummit.com/">SSO Summit</a>, high in the Colorado mountains (9200 feet elevation to be exact), the I-70 West sign is one of my favorite road signs. <a href="http://www.pingidentity.com/">Ping Identity</a> has done a great job putting this together. It is the perfect size around 125 people. Most of the best conferences I have been to have been around 60-150 people. There are a *lot* of enterprises involved here. </div><br><div>John Haggard who has an extensive background in SSO and lately is at Passfaces kicked off the sessions with a SSO history talk. Going through a lot of mainframe centric SSO protocols from the 80s and 90s, I am no expert in these areas and it was fascinating to see the way things vacillated between strength and weakness of SSO protocols.</div><br><div>A couple of points from the presentation:</div><br><div><blockquote><p>The history of SSO is a story of extreme complexities, compromises, vulnerabilities and unintended consequences.</p></blockquote></div><div><blockquote><br></blockquote></div><div><blockquote><p>SSO is a story of one simple objective - to spin off units of computation work to execute on behalf of an authenticated user without requiring the original user's password.</p></blockquote></div><div><blockquote><br></blockquote></div><div><blockquote><p>Phishing has always been completely avoidable</p></blockquote></div><br><div>He went through the various incarnations of mainframe SSO from logon id through things like ACF2, VTAM Session managers, terminal emulators, multiplatform access to web access through facades. The implication he drew from this last step are well worth repeating: "Time to rethink everything." Problem is - of course, people don't rethink, they put MQ Series in front of the mainframe and hook a web app in front of that and go. </div><br><div>Finally, he connected some interesting dots to SAML and SOA security issues. </div><br><div><blockquote><p>SSO without strong auth is and always will be simply nuts</p></blockquote></div><div><blockquote><br></blockquote></div><div><blockquote><p>SAML gets its right</p></blockquote></div><div>His points around common weaknesses in integration in SOA and Web 2.0 technologies for companies that are *not* using SAML were excellent. Of course, I will go into some more details on this tomorrow.</div><br><div>Ping's CTO Patrick Harding took the stage and gave an overview of the next generation of SSO options from Kerberos to present and as is his wont demonstrated various real world strengths and weaknesses, quoted a Gartner analyst (shock!) saying OpenID is the hare and Cardspace is the tortoise. Nice.</div><br><div>Andrew Cameron from GM is speaking now on GM's experiences implementing SSO, and there are a lot of real world lessons learned in his presentation.  Plus my favorite identity architecture, user has Kerberos, services speak SAML. very nice, very scalable. All in all, its my starting point for how to identity in an enterprise. He also spoke about a pet peeve of mine - how to globalize authorization. This is not a problem that vendors have historically attacked with relish. They are very happy to help you solve authentication, but they are perfectly happy to keep their authorization internal either for vendor lock in reasons and/or for sloppy authorization design. This will take a LIberty-esque consortium of enterprises to resolve. </div><br><div>So many conferences are dominated by vendors and consultants who conspire to what I call the "sacred church of things YOU should be doing." Instead this conference is bringing together a great mix of real world in the trenches practitioners who have problems to solve today, with rubber meets the road deployable solutions and an eye towards longer term strategy for SSO and identity.</div>]]></content:encoded>
      <pubDate>Thu, 24 Jul 2008 09:35:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/sso">sso</category>
      <category domain="http://securityratty.com/tag/sso history talk">sso history talk</category>
      <category domain="http://securityratty.com/tag/sso summit">sso summit</category>
      <category domain="http://securityratty.com/tag/mainframe sso">mainframe sso</category>
      <category domain="http://securityratty.com/tag/sso options">sso options</category>
      <category domain="http://securityratty.com/tag/sso protocols">sso protocols</category>
      <category domain="http://securityratty.com/tag/real world">real world</category>
      <category domain="http://securityratty.com/tag/real world lessons">real world lessons</category>
      <category domain="http://securityratty.com/tag/authorization internal">authorization internal</category>
      <source url="http://1raindrop.typepad.com/1_raindrop/2008/07/sso-summit-day-one-morning-session.html">SSO Summit Day One Morning Session</source>
    </item>
    <item>
      <title><![CDATA[When your flight is DOA]]></title>
      <link>http://securityratty.com/article/b20039e8962dada3959083c6efb19eb1</link>
      <guid>http://securityratty.com/article/b20039e8962dada3959083c6efb19eb1</guid>
      <description><![CDATA[Last night I wrote about my first day of this weeks road trip and my hotel which doubled as a funeral parlor. Now it is Wed night and I am live blogging from the runway of DC Regan-National airport,...]]></description>
      <content:encoded><![CDATA[<p>Last night <a href="http://www.stillsecureafteralltheseyears.com/ashimmy/2008/07/when-your-hotel.html">I wrote about my first day</a> of this weeks road trip and my hotel which doubled as a funeral parlor. Now it is Wed night and I am live blogging from the runway of DC Regan-National airport, on board a Delta flight which has been on this same runway and not moved for the past 2 and a half hours.  </p>  <p>I say I am live blogging this, but of course you are not live reading this.  That is because I have no way to upload this to my server.  You see the iPhone 3G for all the coolness, has no Internet sharing that I am aware of. My old windows mobile phone had Internet sharing and if I still had that you would be reading this live right now.  But no, not with the iPhone.  </p>  <p>I was scheduled to connect in Cincinnati right about now.  I am obviously missing that connection.  I was flying from there to Columbus and driving about an hour and half from Columbus.  I have a 9am meeting tomorrow.  So unless I feel like renting a car and driving 4 hours whenever it is I land, I am pretty much missing my meeting tomorrow as well.  </p>  <p>What to do?  a). Should I break out of this plane, run to the terminal and try to get on a flight home to Florida  b). Go postal or c). Grin and bear it and try to remember that I love what I do and that is what flying in the summer is all about (actually that summer thing is full of beans, it is no better in winter with weather either!).</p>  <p>So here is the update, we sat on the runway for 4 hours!  Finally took off and landed in Cincinnati at midnight. I had no connection.  Could not get a flight out in the morning, not rent a car and most hotels sold out. I am writing this from the coffee shop of the lovely (and I do mean lovely) Drawbridge Inn. I will miss my meeting in the morning and am booked on a flight home tomorrow.  Ah, the life of a road warrior!</p>
<p><a href="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?a=ItKb09"><img src="http://feeds.feedburner.com/~a/StillsecureAfterAllTheseYears?i=ItKb09" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=g86LVJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=g86LVJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=t2RL7J"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=t2RL7J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=bFQwgJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=bFQwgJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=0r84gJ"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=0r84gJ" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=MNglIj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=MNglIj" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?a=iuBfaj"><img src="http://feeds.feedburner.com/~f/StillsecureAfterAllTheseYears?i=iuBfaj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~4/344254723" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 23 Jul 2008 20:04:46 +0000</pubDate>
      <category domain="http://securityratty.com/tag/flight">flight</category>
      <category domain="http://securityratty.com/tag/flight home tomorrow">flight home tomorrow</category>
      <category domain="http://securityratty.com/tag/flight home">flight home</category>
      <category domain="http://securityratty.com/tag/tomorrow">tomorrow</category>
      <category domain="http://securityratty.com/tag/half">half</category>
      <category domain="http://securityratty.com/tag/half hours">half hours</category>
      <category domain="http://securityratty.com/tag/hours">hours</category>
      <category domain="http://securityratty.com/tag/live">live</category>
      <category domain="http://securityratty.com/tag/windows mobile phone">windows mobile phone</category>
      <source url="http://feeds.feedburner.com/~r/StillsecureAfterAllTheseYears/~3/344254723/when-your-fligh.html">When your flight is DOA</source>
    </item>
    <item>
      <title><![CDATA[The most insecure banking/sales terminal]]></title>
      <link>http://securityratty.com/article/35f1d465db02d6745fa91cf03800c59f</link>
      <guid>http://securityratty.com/article/35f1d465db02d6745fa91cf03800c59f</guid>
      <description><![CDATA[Can you imagine an ATM running Windows XP Home Edition and being connected to the Internet or a Point of Sale terminal running Tetris ? Unlikely! Why then is allowing a customer to use any computer on...]]></description>
      <content:encoded><![CDATA[<p>Can you imagine an <a href="http://www.youtube.com/watch?v=FAnmuRHYamc">ATM running Windows</a> XP Home Edition and being connected to the Internet or a Point of Sale <a href="http://www.youtube.com/watch?v=wWTzkD9M0sU">terminal running Tetris</a>? &ndash; Unlikely! Why then is allowing a customer to use any computer on the Internet to connect to the banking system, and transfer much more money than you can take out of a cash machine, a good idea? Why did arguably the most conservative organisations in the world &ndash; the banks &ndash; agree to lower their defenses so low that they practically invited the criminals in?</p>

<p>The answer is simple &ndash; the same reasons why even risk-averse investors were chasing after every Internet company in the late 90s  &ndash; the attractiveness of the global scale and reduced costs of e-channels. </p>

<p>Over the years, payments and savings have always been a subject of the most advanced protection:</p>

<ul>
  <li>Banknotes have watermarks and other security features to resist counterfeiting</li>


  <li>Cheques require the account holder's signature</li>


  <li>ATMs require both your card and your PIN, run secure software, and are physically tamper-resistant</li>


  <li>Point of Sale terminals in your favourite supermarket are protected from tampering and use dedicated secure connections to the payment processing network</li>


</ul>


<p>These are all very sensible measures that work (to one degree or another) to protect customers' and banks' money.</p>

<p>Today, however, there is a huge imbalance between the value of electronically accessible funds and their security. This is being very effectively exploited by criminals and the banks are looking for a solution. Personal computers are not tamper proof sales terminals, therefore it is unfeasible to rely on the customer to keep them 100% secure. No one can take away online banking but banks can deploy new security measures, and  solving this problem requires a new innovative approach that can equally address security, ease of use, and cost.</p>

<p>At Cronto, we identified this imbalance years ago. We also correctly predicted that the only <a href="http://blog.cronto.com/index.php?title=transaction_verification_can_protect_aga">solution to address this problem is transaction authentication</a> (where the customer confirms each banking instruction). We then developed an innovative visual transaction signing solution. Based on our unique <a href="http://www.cronto.com/visual_cryptogram.htm">Visual Cryptogram</a>, the Cronto solution supports multiple end user options allowing the bank to choose what is right for their customers whilst maintaining consistency in their backend systems.</p>]]></content:encoded>
      <pubDate>Mon, 14 Jul 2008 09:27:20 +0000</pubDate>
      <category domain="http://securityratty.com/tag/address">address</category>
      <category domain="http://securityratty.com/tag/address security">address security</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/secure">secure</category>
      <category domain="http://securityratty.com/tag/security features">security features</category>
      <category domain="http://securityratty.com/tag/banks">banks</category>
      <category domain="http://securityratty.com/tag/banks agree">banks agree</category>
      <category domain="http://securityratty.com/tag/secure software">secure software</category>
      <category domain="http://securityratty.com/tag/internet company">internet company</category>
      <source url="http://blog.cronto.com/index.php?title=most_insecure_banking_sales_terminal&amp;more=1&amp;c=1&amp;tb=1&amp;pb=1">The most insecure banking/sales terminal</source>
    </item>
  </channel>
</rss>
