<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: unsafe]]></title>
    <link>http://securityratty.com/tag/unsafe</link>
    <description></description>
    <pubDate>Thu, 05 Jun 2008 10:19:23 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Internet Explorer security levels compared]]></title>
      <link>http://securityratty.com/article/cce1e6c584435126c5c4900522285f44</link>
      <guid>http://securityratty.com/article/cce1e6c584435126c5c4900522285f44</guid>
      <description><![CDATA[A pretty good question came across the newsgroups the other day. Someone was asking what are the differences between IE's &quot;medium&quot; and &quot;medium-high&quot; security settings. I did some digging, and found...]]></description>
      <content:encoded><![CDATA[<p>A pretty good question came across the newsgroups the other day. Someone was asking what are the differences between IE's &quot;medium&quot; and &quot;medium-high&quot; security settings. I did some digging, and found only this on MSDN: <a href="http://msdn.microsoft.com/en-us/library/ms537186(VS.85).aspx" target="_blank">About URL security zone templates</a>. No wonder it's difficult to find -- the terminology is different, and the table is organized by URL actions, not by the text in the dialog.</p>  <p>Someone on the IE security team forwarded me a document that had additional details. So here, for your enjoyment, is a chart listing the default settings for each security level. To answer the newsgroup poster, &quot;medium&quot; and &quot;medium-high&quot; aren't the same.</p>  <p>About the formatting: to get it to fit within the width of the blog's text section, I've made some abbreviations.</p>  <table cellspacing="0" cellpadding="0" width="290" border="0"><tbody>     <tr>       <td valign="top" width="145"><strong><u>Column headings</u></strong></td>        <td valign="top" width="145"><strong><u>Entries</u></strong></td>     </tr>   </tbody></table>  <table cellspacing="0" cellpadding="0" width="290" border="0"><tbody>     <tr>       <td valign="top" width="25">H</td>        <td valign="top" width="120">High</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="120">Disable</td>     </tr>      <tr>       <td valign="top" width="25">MH</td>        <td valign="top" width="120">Medium-high</td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="120">Enable</td>     </tr>      <tr>       <td valign="top" width="25">M</td>        <td valign="top" width="120">Medium</td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="120">Prompt</td>     </tr>      <tr>       <td valign="top" width="25">ML</td>        <td valign="top" width="120">Medium-low</td>        <td valign="top" width="25">&#160;</td>        <td valign="top" width="120">&#160;</td>     </tr>      <tr>       <td valign="top" width="25">L</td>        <td valign="top" width="120">Low</td>        <td valign="top" width="25">&#160;</td>        <td valign="top" width="120">&#160;</td>     </tr>   </tbody></table>  <p>In a few cases, the table shows a number rather than D or E or P; below the table is a description of each such entry.</p>  <p>At the very bottom of this post I've included the settings from the privacy tab, too.</p>  <p>Note: these settings reflect those for Internet Explorer 7 on Vista SP1. Please see the MDSN link above for differences between IE 6 and IE 7.</p>  <p>&#160;</p>  <p><strong>.NET Framework</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Loose XAML</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">XAML browser applications</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">XPS documents</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>   </tbody></table>  <p><strong>.NET Framework-reliant components</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Permissions for components with manifests</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25">1</td>        <td valign="top" width="25">1</td>        <td valign="top" width="25">1</td>        <td valign="top" width="25">1</td>     </tr>      <tr>       <td valign="top" width="325">Run components not signed with Authenticode</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Run components signed with Authenticode</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>   </tbody></table>  <p>&#160;&#160;&#160;&#160; 1 = High safety</p>  <p><strong>ActiveX controls and plug-ins</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Allow previously unused ActiveX controls to run without prompt</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow scriptlets</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Automatic prompting for ActiveX controls</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Binary and script behaviors</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Display video and animation on a Web page that doesn't use an external media player</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>     </tr>      <tr>       <td valign="top" width="325">Download signed ActiveX controls</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Download unsigned ActiveX controls</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Initialize and script ActiveX controls not marked as safe for scripting</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Run ActiveX controls and plug-ins</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Script ActiveX controls marked as safe for scripting</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>   </tbody></table>  <p><strong>Downloads</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Automatic prompting for file downloads</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">File download</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Font download</td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>   </tbody></table>  <p><strong>Enable .NET Framework setup</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Enable .NET Framework setup</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong><font color="#ff0000"></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>   </tbody></table>  <p><strong>Miscellaneous</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Access data sources across domains</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25">P</td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong><font color="#ff0000"></font></td>     </tr>      <tr>       <td valign="top" width="325">Allow META REFRESH</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong><font color="#ff0000"></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow scripting of Internet Explorer Web browser control</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong><font color="#ff0000"><strong></strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow script-initiated windows without size or position constraints</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow web pages to use restricted protocols for active content</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow web sites to open windows without address or status bars</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Display mixed content</td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Don't prompt for client certificate selection when no certificates or only one certificate exists</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Drag and drop or copy and paste files</td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Include local directory path when uploading files to a server</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Installation of desktop items</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Launching applications and unsafe files</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Launching programs and files in an IFRAME</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Navigate sub-frames across different domains</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Open files based on content, not file extension</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Software channel permissions</td>        <td valign="top" width="25">1</td>        <td valign="top" width="25">2</td>        <td valign="top" width="25">2</td>        <td valign="top" width="25">2</td>        <td valign="top" width="25">3</td>     </tr>      <tr>       <td valign="top" width="325">Submit non-encrypted form data</td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Use phishing filter</td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>     </tr>      <tr>       <td valign="top" width="325">Use pop-up blocker</td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>     </tr>      <tr>       <td valign="top" width="325">Userdata persistence</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Web sites in less privileged content zone can navigate into this zone</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>     </tr>   </tbody></table>  <p>&#160;&#160;&#160;&#160; 1 = Prohibit downloads from software update channels    <br />&#160;&#160;&#160;&#160; 2 = Cache content downloaded from software update channels     <br />&#160;&#160;&#160;&#160; 3 = Automatically install software updates</p>  <p><strong>Scripting</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Active scripting</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong><font color="#ff0000"></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow programmatic clipboard access</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow status bar updates via script</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow Web sites to prompt for information using scripted windows</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Scripting of Java applets</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>   </tbody></table>  <p><strong>User authentication</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Logon</td>        <td valign="top" width="25">1</td>        <td valign="top" width="25">2</td>        <td valign="top" width="25">2</td>        <td valign="top" width="25">2</td>        <td valign="top" width="25">3</td>     </tr>   </tbody></table>  <p>&#160;&#160;&#160;&#160; 1 = Prompt the user for name and password    <br />&#160;&#160;&#160;&#160; 2 = Automatic logon only in intranet zone     <br />&#160;&#160;&#160;&#160; 3 = Automatic logon with current user name and password</p>  <p>&#160;</p>  <p><strong>Privacy settings (on the &quot;Privacy&quot; tab)</strong></p>  <table cellspacing="0" cellpadding="0" width="550" border="1"><tbody>     <tr>       <td valign="top" width="325">&#160;</td>        <td valign="top" width="25">H</td>        <td valign="top" width="25">MH</td>        <td valign="top" width="25">M</td>        <td valign="top" width="25">ML</td>        <td valign="top" width="25">L</td>     </tr>      <tr>       <td valign="top" width="325">Allow persistent cookies</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow per-session cookies</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow third-party persistent cookies</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#0000ff">P</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>      <tr>       <td valign="top" width="325">Allow third-party session cookies</td>        <td valign="top" width="25"><font color="#ff0000"><strong>D</strong></font></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>        <td valign="top" width="25"><strong><font color="#00ff00">E</font></strong></td>     </tr>   </tbody></table><img src="http://blogs.technet.com/aggbug.aspx?PostID=3124973" width="1" height="1">]]></content:encoded>
      <pubDate>Tue, 16 Sep 2008 20:19:36 +0000</pubDate>
      <category domain="http://securityratty.com/tag/script behaviors">script behaviors</category>
      <category domain="http://securityratty.com/tag/script">script</category>
      <category domain="http://securityratty.com/tag/script activex controls">script activex controls</category>
      <category domain="http://securityratty.com/tag/activex controls">activex controls</category>
      <category domain="http://securityratty.com/tag/net framework">net framework</category>
      <category domain="http://securityratty.com/tag/net">net</category>
      <category domain="http://securityratty.com/tag/zone">zone</category>
      <category domain="http://securityratty.com/tag/content zone">content zone</category>
      <category domain="http://securityratty.com/tag/content">content</category>
      <source url="http://blogs.technet.com/steriley/archive/2008/09/16/internet-explorer-security-levels-compared.aspx">Internet Explorer security levels compared</source>
    </item>
    <item>
      <title><![CDATA[Google's New Browser]]></title>
      <link>http://securityratty.com/article/ad7dafb059c5f7fab0dc5f23e779270c</link>
      <guid>http://securityratty.com/article/ad7dafb059c5f7fab0dc5f23e779270c</guid>
      <description><![CDATA[So, Google have released a new browser called Chrome

What does that mean from an Information Security perspective

Not very much and a lot, depending if you are looking at the short term or long...]]></description>
      <content:encoded><![CDATA[So, Google have released a new browser called Chrome...<br /><br />What does that mean from an Information Security perspective?<br /><br />Not very much and a lot, depending if you are looking at the short term or long term.<br /><br />So, lets get into the short term - there is a new browser. It will have bugs and vulnerabilities. These will be exploited.<br /><br />Most of the browser is based on webkit which is sorta what kde uses and sorta what safari uses and sorta what a number of cell phones use. It is becoming browser number 4 after IE, mozilla/firefox and opera. This means that hackers (online criminals) will start to notice the browser (if they haven't already). Assuming that the open source promise (many eyes make fewer bugs) stands true and that Google will be quick with patches then this is merely part of the daily application vulnerability race. And if Google is quick with paches then this browser should not be any more unsafe than the others.<br /><br />There are a few extra security features in this browser - that is always a good thing. For more information read <a href="http://www.tssci-security.com/archives/2008/09/02/google-chrome-first-look/">here</a>. Of course the feature that is most interesting - "each-tab-running-separately" has been compromised.<br /><br />So short term - move along, nothing to see here. Lets move on to the long term...<br /><br />What is most important in my mind for the long term is the "why" of this browser - why would Google want to jump into a market where they can't be the biggest or the best or even a very effective niche player? Especially since they have a good relationship with Firefox and their product is almost entirely webkit? And their browser is essentially all open source so all the good bits will be analysed and added to Firefox anyhow or improved upon and added to Firefox.<br /><br />The answer is simple - Google want their browser to fail.<br /><br />Huh?<br /><br />Well, that may a bit unfair but they really don't care either way.<br /><br />Google is the search engine leader. They are also slowly <span style="font-style: italic;">becoming</span> the Internet. This blog is hosted by Google, its feed is hosted by Google. If I need to host video, pictures, sound etc then I would probably choose Google - they are really good at hosting and why bother looking elsewhere when I already have a Google account?<br /><br />So, almost all of my public information is hosted by Google. What about my private information?<br /><br />Well... no.<br /><br />That is all stored safely on my laptop for four reasons -<br /><br /><ol><li>I don't trust Google.</li><li>I don't trust the Internet.</li><li>The tools for creating private documents are so much better than the online ones.</li><li>I can get to my documents when I am offline.</li><li>The Internet is too slow. </li></ol><br />But a lot of my computer day is spent in Microsoft Office. That is a lot of advertising opportunity lost. And if Google can access my personal files then they will have a better idea of what adverts to send my way. Which in turn will make their advertisers happier and Google stock go up.<br /><br />And all it would take is sorting out the above 5 points.<br /><br />I was going to go into each one but this post is already getting quite long. Just note that the three features that are most important in Chrome are:<br /><br /><ul><li>Security and stability</li><li>Offline application mode</li><li>Fast running and standards based application engine</li></ul>In other words - helping making it easier to use Google's online applications. Most of the factors are going to be taken care of with Chrome and its kids.<br /><br />What will happen is that Firefox will catch up with Chrome but Google won't care what you use to access their online applications - just as long as you access them. And that is their game plan.<br /><br />What this leaves is the final question - all things being equal - is your information more at risk on Google's servers or on you laptop at home?<br /><br />That is a good question but one we should be looking at.<img src="http://feeds.feedburner.com/~r/SecurityThoughts/~4/388678608" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 03 Sep 2008 06:59:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/trust">trust</category>
      <category domain="http://securityratty.com/tag/trust google">trust google</category>
      <category domain="http://securityratty.com/tag/browser">browser</category>
      <category domain="http://securityratty.com/tag/google account">google account</category>
      <category domain="http://securityratty.com/tag/google stock">google stock</category>
      <category domain="http://securityratty.com/tag/choose google">choose google</category>
      <category domain="http://securityratty.com/tag/information security perspective">information security perspective</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <source url="http://feeds.feedburner.com/~r/SecurityThoughts/~3/388678608/googles-new-browser.html">Google's New Browser</source>
    </item>
    <item>
      <title><![CDATA[While I Was Out: Compendium of the Last Week's News]]></title>
      <link>http://securityratty.com/article/9b2e491a24c669b08b8cfdf0d0df0b47</link>
      <guid>http://securityratty.com/article/9b2e491a24c669b08b8cfdf0d0df0b47</guid>
      <description><![CDATA[You wouldn't listen, but continued to generate products, news stories, and analysis about wireless networking in my absence: Here's the run down of the last week or so's Wi-Fi and wireless stories....]]></description>
      <content:encoded><![CDATA[<p><img src="http://wifinetnews.com/images/weefi.jpg" align="right" border="0" hspace="5" /><strong>You wouldn't listen, but continued to generate products, news stories, and analysis about wireless networking in my absence:</strong> Here's the run down of the last week or so's Wi-Fi and wireless stories. (Yes, I enjoyed my time off.)</p>

<p><a href="http://www.informationweek.com/news/services/data/showArticle.jhtml?articleID=210200880"><strong>Fourth US airline to go Wi-Fi:</strong></a> Aircell says they have a fourth airline--after American, Delta, and Virgin America--on board for its in-flight Wi-Fi service. The aerial broadband provider's latest partner will be announced soon. Aircell's service went live in 15 American Airlines planes two weeks ago, and there's been a surprising lack of reporting from regular travelers or journalists since the big splash at the launch.</p>

<p><a href="http://seattlepi.nwsource.com/business/376308_software25.html"><strong>Microsoft, two universities research methods for better Wi-Fi handoff for vehicles:</strong></a> The researchers developed a method they call Vi-Fi, writes the Seattle Post-Intelligencer's Todd Bishop, which allows a system to maintain connections with several base stations at once, using a primary access point for traffic until a discontinuity is predicted or encountered. This allows seamless handoffs and continuous voice conversations. </p>

<p><a href="http://www.nytimes.com/2008/08/24/technology/24digi.html?_r=1&oref=slogin"><strong>Speaking of autos and Wi-Fi, concerns raised about Chrysler's in-car Wi-Fi option:</strong></a> Randall Stross wrote nearly two weeks ago in The New York Times about the problem of distraction. With the Internet at your fingertips, can you restrain yourself? The only problem with the humorous and accurate analysis is that millions of business travelers have 3G access via laptop cards already, so you'd think we'd already be seeing the bad effects of automotive area networks.</p>

<p><a href="http://www.omaha.com/index.php?u_page=2798&u_sid=10415031"><strong>A Wi-Fi booster can't post availability signs on highway:</strong></a> The Nebraska town of Louisville has free Wi-Fi downtown, and wanted to post "Visitor Wi-Fi" on a highway sign as another amenity. The state highway department has a policy that doesn't allow the promotion of Wi-Fi, because they believe they'd be inundated. A resident who runs a local Internet firm installed his own signs on the highway; the roads department removed them; he remounted them; they were removed again. The idea of zoning and mounting a billboard apparently hasn't come to the city officials' minds (or perhaps they're prohibited).</p>

<p><a href="http://www.lisburntoday.co.uk/news/PRIMARY-PULLS-PLUG-ON-WIFI.4435678.jp"><strong>The folks spreading misinformation about Wi-Fi health effects cause Ulster school to disable network:</strong></a> I can understand why non-technical folks might think that Wi-Fi has been proven to be unsafe, given the kind of information that's available on the Internet about wireless safety. While there are ongoing studies about the safety of cellular signals--and I'm convinced at this point there's no increased risk to an adult's health by using a cell phone--there is no specific and credible research linked to Wi-Fi, which broadcasts signals at a far lower level than a cell phone, most of the time in most uses.</p>

<p><a href="http://blog.seattlepi.nwsource.com/thebigblog/archives/147374.asp"><strong>Washington state shuts down rest-area Wi-Fi:</strong></a> The $3 for 15 minutes, $7 per day, or $30 per month Wi-Fi service at 28 of Washington's 42 rest areas has been turned off after a year for lack of use. Figures. The fees charged by Parsons and Road Connect aren't unreasonable for a nationally scoped plan, but are ridiculous for limited use. States should either bite the bullet and offer these service for free, partner with national roaming operators who can resell service into large networks of business travelers, or use ads to support the service. Highways in remote areas can typically pick up cell data networks, and ongoing costs should be minimal to operate such networks.</p>

<p><a href="http://www.techworld.com/news/index.cfm?RSS&NewsID=103501"><strong>IEEE approves fast-roaming standard, 802.11r:</strong></a> This new standard is designed to improve the handoff of devices between base stations. This is accomplished in part by allowing base stations to communicate security and quality of service information so that a VoIP over WLAN phone can immediately reassociate without the delay of authentication and other handshaking.</p>

<p><a href="http://www.marketwatch.com/news/story/freefi-networks-releases-figures-wi-fi/story.aspx?guid={5252EF0E-2563-42B7-8A95-2F893580E6F6}&dist=hppr"><strong>Denver airport sees 7,000 connections on a single day last week due to Democratic National Convention:</strong></a> FreeFi released the usage figures recently to show how their service is operating. The network started with about 600 daily users when the switchover from fee to free happened 10 months ago, and now carries about 3,500 daily connections.</p>

<p><a href="http://www.centredaily.com/living/travel/story/804003.html"><strong>Coffee Bean & Tea Leaf goes free:</strong></a> The chain of about 700 cafes will have free Wi-Fi installed by now in all its company-owned stores (about 300).</p>]]></content:encoded>
      <pubDate>Tue, 02 Sep 2008 10:55:47 +0000</pubDate>
      <category domain="http://securityratty.com/tag/free wi-fi">free wi-fi</category>
      <category domain="http://securityratty.com/tag/wi-fi">wi-fi</category>
      <category domain="http://securityratty.com/tag/in-car wi-fi option">in-car wi-fi option</category>
      <category domain="http://securityratty.com/tag/wi-fi handoff">wi-fi handoff</category>
      <category domain="http://securityratty.com/tag/free wi-fi downtown">free wi-fi downtown</category>
      <category domain="http://securityratty.com/tag/month wi-fi service">month wi-fi service</category>
      <category domain="http://securityratty.com/tag/rest-area wi-fi">rest-area wi-fi</category>
      <category domain="http://securityratty.com/tag/wi-fi booster">wi-fi booster</category>
      <category domain="http://securityratty.com/tag/in-flight wi-fi service">in-flight wi-fi service</category>
      <source url="http://wifinetnews.com/archives/008428.html">While I Was Out: Compendium of the Last Week's News</source>
    </item>
    <item>
      <title><![CDATA[Keyczar: Safe and Simple Cryptography]]></title>
      <link>http://securityratty.com/article/d7aad095f44d95efad0e3a3210dc4625</link>
      <guid>http://securityratty.com/article/d7aad095f44d95efad0e3a3210dc4625</guid>
      <description><![CDATA[Written by Steve Weis

Cryptography is notoriously hard to get right and if improperly used, can create serious security holes. Common mistakes include using the wrong cipher modes or obsolete...]]></description>
      <content:encoded><![CDATA[<span class="byline-author">Written by Steve Weis</span><br /><br /><img style="margin: 0pt 0pt 10px 10px; float: right;" src="http://2.bp.blogspot.com/_LMSk7hTEaIE/SKCABPuzeVI/AAAAAAAAhXc/nyKwkCyDdwQ/s200/keyczar_logo.jpg" alt="" id="BLOGGER_PHOTO_ID_5233323525895584082" border="0" />Cryptography is notoriously hard to get right and if improperly used, can create serious security holes. Common mistakes include using the wrong cipher modes or obsolete algorithms, composing primitives in an unsafe manner, hard-coding keys in source code, or failing to anticipate the need for future key rotation. With these risks in mind, we're pleased to announce the open-source release of <a href="http://www.keyczar.org/">Keyczar</a>.<br /><br />Keyczar is a cryptographic toolkit that supports encryption and authentication for both symmetric and public-key algorithms. It addresses some of the aforementioned issues by choosing safe defaults, tagging outputs with key version information, and providing a simple application programming interface. Keyczar's key versioning system makes it easy to rotate and revoke keys, without worrying about backward compatibility or making any changes to source code.<br /><br />We look forward to working with the open source community and continuing to make cryptography safer and easier to use. To download Keyczar or for more information, please visit our <a href="http://code.google.com/p/keyczar">Google Code project</a> and <a href="http://groups.google.com/group/keyczar-discuss">discussion group</a>.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?a=Xmjn2K"><img src="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?i=Xmjn2K" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?a=G4qbKk"><img src="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?i=G4qbKk" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/362162234" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 11 Aug 2008 07:06:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/keyczar">keyczar</category>
      <category domain="http://securityratty.com/tag/key">key</category>
      <category domain="http://securityratty.com/tag/future key rotation">future key rotation</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/key version information">key version information</category>
      <category domain="http://securityratty.com/tag/cryptography">cryptography</category>
      <category domain="http://securityratty.com/tag/download keyczar">download keyczar</category>
      <category domain="http://securityratty.com/tag/source code">source code</category>
      <category domain="http://securityratty.com/tag/cryptography safer">cryptography safer</category>
      <source url="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~3/362162234/keyczar-safe-and-simple-cryptography.html">Keyczar: Safe and Simple Cryptography</source>
    </item>
    <item>
      <title><![CDATA[Keyczar: Safe and Simple Cryptography]]></title>
      <link>http://securityratty.com/article/fc4cc2f3a00f05e285c35e9511665c7c</link>
      <guid>http://securityratty.com/article/fc4cc2f3a00f05e285c35e9511665c7c</guid>
      <description><![CDATA[Written by Steve Weis

Cryptography is notoriously hard to get right and if improperly used, can create serious security holes. Common mistakes include using the wrong cipher modes or obsolete...]]></description>
      <content:encoded><![CDATA[<span class="byline-author">Written by Steve Weis</span><br /><br /><img style="margin: 0pt 0pt 10px 10px; float: right;" src="http://2.bp.blogspot.com/_LMSk7hTEaIE/SKCABPuzeVI/AAAAAAAAhXc/nyKwkCyDdwQ/s200/keyczar_logo.jpg" alt="" id="BLOGGER_PHOTO_ID_5233323525895584082" border="0" />Cryptography is notoriously hard to get right and if improperly used, can create serious security holes. Common mistakes include using the wrong cipher modes or obsolete algorithms, composing primitives in an unsafe manner, hard-coding keys in source code, or failing to anticipate the need for future key rotation. With these risks in mind, we're pleased to announce the open-source release of <a href="http://www.keyczar.org/">Keyczar</a>.<br /><br />Keyczar is a cryptographic toolkit that supports encryption and authentication for both symmetric and public-key algorithms. It addresses some of the aforementioned issues by choosing safe defaults, tagging outputs with key version information, and providing a simple application programming interface. Keyczar's key versioning system makes it easy to rotate and revoke keys, without worrying about backward compatibility or making any changes to source code.<br /><br />We look forward to working with the open source community and continuing to make cryptography safer and easier to use. To download Keyczar or for more information, please visit our <a href="http://code.google.com/p/keyczar">Google Code project</a> and <a href="http://groups.google.com/group/keyczar-discuss">discussion group</a>.<div class="feedflare">
<a href="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?a=6ODRtEpO"><img src="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?d=41" border="0"></img></a> <a href="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?a=agNjL0Me"><img src="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?i=agNjL0Me" border="0"></img></a>
</div><img src="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~4/iXt3UNU0ZIg" height="1" width="1"/>]]></content:encoded>
      <pubDate>Mon, 11 Aug 2008 07:06:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/keyczar">keyczar</category>
      <category domain="http://securityratty.com/tag/key">key</category>
      <category domain="http://securityratty.com/tag/future key rotation">future key rotation</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/key version information">key version information</category>
      <category domain="http://securityratty.com/tag/cryptography">cryptography</category>
      <category domain="http://securityratty.com/tag/download keyczar">download keyczar</category>
      <category domain="http://securityratty.com/tag/source code">source code</category>
      <category domain="http://securityratty.com/tag/cryptography safer">cryptography safer</category>
      <source url="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/iXt3UNU0ZIg/keyczar-safe-and-simple-cryptography.html">Keyczar: Safe and Simple Cryptography</source>
    </item>
    <item>
      <title><![CDATA[Meet ratproxy, our passive web security assessment tool]]></title>
      <link>http://securityratty.com/article/bc78dd4116c64ea5b3a05fa82e188ff7</link>
      <guid>http://securityratty.com/article/bc78dd4116c64ea5b3a05fa82e188ff7</guid>
      <description><![CDATA[Posted by Michal Zalewski

We're happy to announce that we've just open-sourced ratproxy , a passive web application security assessment tool that we've been using internally at Google. This utility,...]]></description>
      <content:encoded><![CDATA[<span class="byline-author">Posted by Michal Zalewski</span><br /><br />We're happy to announce that we've just open-sourced <a href="http://code.google.com/p/ratproxy">ratproxy</a>, a passive web application security assessment tool that we've been using internally at Google. This utility, developed by our information security engineering team, is designed to transparently analyze legitimate, browser-driven interactions with a tested web property and automatically pinpoint, annotate, and prioritize potential flaws or areas of concern.  <br /><br />The proxy analyzes problems such as cross-site script inclusion threats, insufficient cross-site request forgery defenses, caching issues, cross-site scripting candidates, potentially unsafe cross-domain code inclusion schemes and information leakage scenarios, and much more. (A more-detailed discussion of these features and information on securing vulnerable applications is provided <a href="http://code.google.com/p/ratproxy/wiki/RatproxyDoc">here</a>.) Compared with more-traditional active crawlers, or with fully manual request inspection and modification frameworks, this approach offers several significant advantages in terms of minimized overhead; marginalized risk of site disruptions; high coverage of complex, client-driven application states in web 2.0 solutions; and insight into dynamic cross-domain trust models.<br /><br />We decided to make this tool freely available as open source because we feel it will be a valuable contribution to the information security community, helping advance the community's understanding of security challenges associated with contemporary web technologies. We believe that responsible security research brings a net overall benefit to the safety of the Web as a whole, and have released this tool explicitly to support that kind of research.<br /><br />To download the proxy, please visit this <a href="http://ratproxy.googlecode.com/files/ratproxy-1.50.tar.gz">page</a>. Also, please keep in mind that the proxy is designed solely to highlight interesting patterns in web applications, and a further analysis by a security professional is often required to interpret the results and their significance for the tested platform.<div class="feedflare">
<a href="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?a=cTCU6J"><img src="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?i=cTCU6J" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?a=K3C5fj"><img src="http://feeds.feedburner.com/~f/GoogleOnlineSecurityBlog?i=K3C5fj" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~4/324447250" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 01 Jul 2008 12:49:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information leakage scenarios">information leakage scenarios</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/contemporary web technologies">contemporary web technologies</category>
      <category domain="http://securityratty.com/tag/information security community">information security community</category>
      <category domain="http://securityratty.com/tag/web property">web property</category>
      <category domain="http://securityratty.com/tag/community">community</category>
      <category domain="http://securityratty.com/tag/web applications">web applications</category>
      <source url="http://feeds.feedburner.com/~r/GoogleOnlineSecurityBlog/~3/324447250/meet-ratproxy-our-passive-web-security.html">Meet ratproxy, our passive web security assessment tool</source>
    </item>
    <item>
      <title><![CDATA[Meet ratproxy, our passive web security assessment tool]]></title>
      <link>http://securityratty.com/article/bdf72a712e886694b4644a9a0db12b4c</link>
      <guid>http://securityratty.com/article/bdf72a712e886694b4644a9a0db12b4c</guid>
      <description><![CDATA[Posted by Michal Zalewski

We're happy to announce that we've just open-sourced ratproxy , a passive web application security assessment tool that we've been using internally at Google. This utility,...]]></description>
      <content:encoded><![CDATA[<span class="byline-author">Posted by Michal Zalewski</span><br /><br />We're happy to announce that we've just open-sourced <a href="http://code.google.com/p/ratproxy">ratproxy</a>, a passive web application security assessment tool that we've been using internally at Google. This utility, developed by our information security engineering team, is designed to transparently analyze legitimate, browser-driven interactions with a tested web property and automatically pinpoint, annotate, and prioritize potential flaws or areas of concern.  <br /><br />The proxy analyzes problems such as cross-site script inclusion threats, insufficient cross-site request forgery defenses, caching issues, cross-site scripting candidates, potentially unsafe cross-domain code inclusion schemes and information leakage scenarios, and much more. (A more-detailed discussion of these features and information on securing vulnerable applications is provided <a href="http://code.google.com/p/ratproxy/wiki/RatproxyDoc">here</a>.) Compared with more-traditional active crawlers, or with fully manual request inspection and modification frameworks, this approach offers several significant advantages in terms of minimized overhead; marginalized risk of site disruptions; high coverage of complex, client-driven application states in web 2.0 solutions; and insight into dynamic cross-domain trust models.<br /><br />We decided to make this tool freely available as open source because we feel it will be a valuable contribution to the information security community, helping advance the community's understanding of security challenges associated with contemporary web technologies. We believe that responsible security research brings a net overall benefit to the safety of the Web as a whole, and have released this tool explicitly to support that kind of research.<br /><br />To download the proxy, please visit this <a href="http://ratproxy.googlecode.com/files/ratproxy-1.50.tar.gz">page</a>. Also, please keep in mind that the proxy is designed solely to highlight interesting patterns in web applications, and a further analysis by a security professional is often required to interpret the results and their significance for the tested platform.<div class="feedflare">
<a href="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?a=5AvS6vw2"><img src="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?d=41" border="0"></img></a> <a href="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?a=sIWTM6AF"><img src="http://feedproxy.google.com/~f/GoogleOnlineSecurityBlog?i=sIWTM6AF" border="0"></img></a>
</div><img src="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~4/matIm4t6Uks" height="1" width="1"/>]]></content:encoded>
      <pubDate>Tue, 01 Jul 2008 12:49:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/information leakage scenarios">information leakage scenarios</category>
      <category domain="http://securityratty.com/tag/information security">information security</category>
      <category domain="http://securityratty.com/tag/contemporary web technologies">contemporary web technologies</category>
      <category domain="http://securityratty.com/tag/information security community">information security community</category>
      <category domain="http://securityratty.com/tag/web property">web property</category>
      <category domain="http://securityratty.com/tag/community">community</category>
      <category domain="http://securityratty.com/tag/web applications">web applications</category>
      <source url="http://feedproxy.google.com/~r/GoogleOnlineSecurityBlog/~3/matIm4t6Uks/meet-ratproxy-our-passive-web-security.html">Meet ratproxy, our passive web security assessment tool</source>
    </item>
    <item>
      <title><![CDATA[Safari For Windows Vulnerabilities]]></title>
      <link>http://securityratty.com/article/9ee83102c8590b63a77eb14161a5008c</link>
      <guid>http://securityratty.com/article/9ee83102c8590b63a77eb14161a5008c</guid>
      <description><![CDATA[This one came out early this morning
From Secunia
Description
Some vulnerabilities and a security issue have been reported in Apple Safari, which can be exploited by malicious people to disclose...]]></description>
      <content:encoded><![CDATA[<p>This one came out early this morning. </p>
<p>From Secunia:</p>
<blockquote><p>Description:<br />
Some vulnerabilities and a security issue have been reported in Apple Safari, which can be exploited by malicious people to disclose sensitive information or to compromise a user&#8217;s system.</p>
<p>1) A boundary error within the handling of BMP and GIF images can be exploited to trigger an out-of-bounds read and disclose content in memory.</p>
<p>2) A security issue exists due to Safari automatically launching downloaded executable files from sites in a Internet Explorer 7 zone with the &#8220;Launching applications and unsafe files&#8221; option set to &#8220;Enable&#8221;, or sites in the Internet Explorer 6 &#8220;Local intranet&#8221; or &#8220;Trusted sites&#8221; zone.</p>
<p>3) An unspecified error in the handling of Javascript arrays can be exploited to cause a memory corruption when a user visits a specially crafted web page.</p>
<p>Successful exploitation of this vulnerability may allow execution of arbitrary code.</p>
<p>The vulnerabilities are reported in Safari for Windows prior to version 3.1.2.</p></blockquote>
<p>If you&#8217;re running it patch &#8216;er up. Or conversely you could just bite the bullet and get a Mac. (<i>right, and use <a href="http://www.mozilla.com/en-US/firefox/all-rc.html">Firefox</a> with <a href="https://addons.mozilla.org/en-US/firefox/addon/722">NoScript</a>. thx folks</i>)</p>
<p> <img src='http://www.liquidmatrix.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><a href="http://secunia.com/advisories/30775/">Article Link</a></p>

<p><a href="http://feeds.feedburner.com/~a/Liquidmatrix?a=34uvJ9"><img src="http://feeds.feedburner.com/~a/Liquidmatrix?i=34uvJ9" border="0"></img></a></p><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=W1a2oI"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=W1a2oI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=YYPQzi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=YYPQzi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=pmg1wi"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=pmg1wi" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=Ywqd5i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=Ywqd5i" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/Liquidmatrix?a=Lha26i"><img src="http://feeds.feedburner.com/~f/Liquidmatrix?i=Lha26i" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Liquidmatrix/~4/316387041" height="1" width="1"/>]]></content:encoded>
      <pubDate>Fri, 20 Jun 2008 14:36:54 +0000</pubDate>
      <category domain="http://securityratty.com/tag/safari">safari</category>
      <category domain="http://securityratty.com/tag/sites zone">sites zone</category>
      <category domain="http://securityratty.com/tag/zone">zone</category>
      <category domain="http://securityratty.com/tag/internet explorer">internet explorer</category>
      <category domain="http://securityratty.com/tag/apple safari">apple safari</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://securityratty.com/tag/memory corruption">memory corruption</category>
      <category domain="http://securityratty.com/tag/disclose sensitive information">disclose sensitive information</category>
      <source url="http://feeds.feedburner.com/~r/Liquidmatrix/~3/316387041/">Safari For Windows Vulnerabilities</source>
    </item>
    <item>
      <title><![CDATA[It Changed My Life: My Review of "Geekonomics"]]></title>
      <link>http://securityratty.com/article/ce5a150d2a3535e99026bfc049072487</link>
      <guid>http://securityratty.com/article/ce5a150d2a3535e99026bfc049072487</guid>
      <description><![CDATA[As I am sitting here - yes, you guessed right! - on a plane, I cannot stop thinking about the book &quot;Geekonomics&quot; ( book site ) which I just finished reading (earlier impressions here and here ). The...]]></description>
      <content:encoded><![CDATA[<p>As I am sitting here - <em>yes, you guessed right!</em> - on a plane, I cannot stop thinking about <a href="http://www.amazon.com/Geekonomics-Real-Cost-Insecure-Software/dp/0321477898">the book "Geekonomics"</a>(<a href="http://geekonomicsbook.com/">book site</a>)&nbsp; which I just finished reading (earlier impressions <u><a href="http://chuvakin.blogspot.com/2008/05/paranoia-acting-up-or-just-being.html">here</a></u> and <u><a href="http://chuvakin.blogspot.com/2008/04/on-geekonomics.html">here</a></u>). The way it ends, BTW, just kicks you in the balls, hard (look up what Mr Petrov did on Sept 26, 1983 and why, if you are already curious)!</p> <p>Call me easily impressible, call me naive, darn, call me "out of touch with current security issues," but this book struck a major, major chord with me. It really did.</p> <p>Now, I have experienced as much poor quality and insecure software as the next guy. I am never ever surprised about some feature in MS Office (or other application, really) just flat out not working or not working as expected or not working every time.</p> <p>I suspect that, by now, every human on Earth who ever laid their hands on a computer knows:</p> <p><strong>software = might NOT work.</strong></p> <p>Now, we expect roads, bridges, toasters, chainsaws, bicycles, cars (until they put software in them...) to work and work they do. And if they don't - the company who manufactures them usually makes them work for us fast - or goes away, cut down by the "benevolent" axe of capitalism. Now, software is <strong>totally</strong> different (<a href="http://chuvakin.blogspot.com/2007/05/are-you-mad-are-we-all.html">my thinking</a> about this one).</p> <p>And <strong>everybody</strong> knows it. But nobody was brave enough to take a hard look at this and analyze how that simple fact affected, affects and will affect our society. And, for my extra-paranoid readers: "... and how it might <em>end</em> that very society."</p> <p>Until "<a href="http://www.amazon.com/Geekonomics-Real-Cost-Insecure-Software/dp/0321477898">Geekonomics</a>!"</p> <p>This book might not reveal any secrets about how software works to an IT professional (it will reveal how law works though!), but it will explain why bad software is everywhere, why we are stuck with it, why it will not improve by itself and - sorry for a hysterical note here! - how <em>we might all fucking di</em>e because of it. It then unemotionally predicts why more people will certainly die because of bad software. It studies the complicated dynamics of today's software market such as who is more at fault for bad software - buyers who agree to buy or vendors who make it (or both). It also suggests that many of today's regulations and compliance "thingies" are a little misguided (e.g. in a battle a PCI DSS-compliant enterprise and a 0-day-wielding hacker, any sane person will bet on an 0-day). It is also very well-written; it won't bore an experienced IT&nbsp; or security pro and it will not overwhelm a mere IT user.</p> <p>First, it explains why the software is the "foundation of our civilization" today, and how it will be more so in the future. Next, it casts a look at "innovation" and ponders how innovation-driven software development relates to the&nbsp; fact that users don't touch 90% of features of a typical software. In the third chapter is presents the view of the "0wned world" where "only the stupid [cybercriminals] get caught."&nbsp; Next chapters looks at how government oversight works in other areas (e.g. FDA), how it might work - and how it might fail (and did fail in the past). While doing it, the book dispels the "government will just&nbsp; make it worse" myth (basically, because some things are really bad and quickly streaming towards worse already). The amazing chapter 5 gives the clearest explanation of litigation (torts, etc) that I have ever seen (the book is worth reading just for chapter 5 alone!). Chapter 6 takes a super-pessimistic look at open-source software (no comment - just read it). Finally, several possible future - "the way forward" - is discussed. </p> <p>Another thing I would like to mention about this book is that a reader should keep in mind that it is not about "<em>insecure"</em> software: it is about bad quality, <em>unsafe</em> software in general and less about "hackable" software. The author chose to not make this distinction very clear, perhaps on purpose.</p> <p>So, everybody in software business, security business - in fact, just everybody who uses a computer - <strong>MUST READ THIS BOOK!</strong> Seriously, understanding the point made there might be a matter of life or death for some (all?) of us.</p> <p>As a conclusion, if you want the visual image of the future to end my review, here it is: it is not "Terminator" future (where machines kill people out of evil) that we must fear and work to prevent, but "Robocop" future (where they do due to software bugs).</p> <p><a href="http://lh6.ggpht.com/anton.chuvakin/SEiKbme3mxI/AAAAAAAADtA/InRvJpCVEmM/s1600-h/Robocop_VS_Terminator3.jpg"><img style="border-top-width: 0px; border-left-width: 0px; border-bottom-width: 0px; border-right-width: 0px" height="158" alt="Robocop_VS_Terminator" src="http://lh3.ggpht.com/anton.chuvakin/SEiKccFpWvI/AAAAAAAADtE/l2uUeX0GPUo/Robocop_VS_Terminator_thumb1.jpg?imgmax=800" width="102" border="0"></a> </p> <p>Go <u><a href="http://www.amazon.com/Geekonomics-Real-Cost-Insecure-Software/dp/0321477898">read the darn book!</a></u>&nbsp; And support <u><a href="http://geekonomicsbook.com/">liability for software manufactures</a></u>. Also, in a few days, <u><a href="http://www.killedbysoftware.info/">check this out</a></u> (not yet but hover over the link to get a preview...)</p> <p></p> <div class="wlWriterSmartContent" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:6334589f-e6fe-4213-9ef3-0e6d357731e9" style="padding-right: 0px; display: inline; padding-left: 0px; padding-bottom: 0px; margin: 0px; padding-top: 0px">Technorati tags: <a href="http://technorati.com/tags/book%20review" rel="tag">book review</a>, <a href="http://technorati.com/tags/security" rel="tag">security</a>, <a href="http://technorati.com/tags/geekonomics" rel="tag">geekonomics</a></div>  <div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=Y8jIfI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=Y8jIfI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=BcyQMI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=BcyQMI" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=9YDtlI"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=9YDtlI" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/305699346" height="1" width="1"/>]]></content:encoded>
      <pubDate>Thu, 05 Jun 2008 13:53:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/software manufactures">software manufactures</category>
      <category domain="http://securityratty.com/tag/typical software">typical software</category>
      <category domain="http://securityratty.com/tag/software development">software development</category>
      <category domain="http://securityratty.com/tag/insecure">insecure</category>
      <category domain="http://securityratty.com/tag/insecure software">insecure software</category>
      <category domain="http://securityratty.com/tag/bad software">bad software</category>
      <category domain="http://securityratty.com/tag/bad">bad</category>
      <category domain="http://securityratty.com/tag/open-source software">open-source software</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/305699346/it-changed-my-life-my-review-of.html">It Changed My Life: My Review of "Geekonomics"</source>
    </item>
    <item>
      <title><![CDATA[Protecting the web-surfing public]]></title>
      <link>http://securityratty.com/article/fa7b809858e4ea40c1b3d99fb2fcae7d</link>
      <guid>http://securityratty.com/article/fa7b809858e4ea40c1b3d99fb2fcae7d</guid>
      <description><![CDATA[Save the diag url in your favs for when you suspect a unsafe site. I checked my site, came out clean and spiffy


clipped from wiki.ittoolbox.com

Google Safe Browsing Diagnostic Page (268 views

...]]></description>
      <content:encoded><![CDATA[<div > Save the diag url in your favs for when you suspect a unsafe site.<br/>I checked my site, came out clean and spiffy. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/5C238144-45DD-4A39-90C9-29EDFC1C8BE0/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/08a6b060-f333-47a1-bf80-e3cdc4877712/5C238144-45DD-4A39-90C9-29EDFC1C8BE0/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://wiki.ittoolbox.com/index.php/Google_Safe_Browsing_Diagnostic_Page" href="http://wiki.ittoolbox.com/index.php/Google_Safe_Browsing_Diagnostic_Page" style="font-size: 11px;">wiki.ittoolbox.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://wiki.ittoolbox.com/index.php/Google_Safe_Browsing_Diagnostic_Page -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Google Safe Browsing Diagnostic Page <SPAN class="small">(268 views)</SPAN></div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://wiki.ittoolbox.com/index.php/Google_Safe_Browsing_Diagnostic_Page --><P>Google&#8217;s Safe Browsing Diagnostic Page has been introduced in response to an increased effort by <A title="Yahoo" href="http://wiki.ittoolbox.com/index.php/Yahoo">Yahoo</A> and <A title="McAfee VirusScan" href="http://wiki.ittoolbox.com/index.php/McAfee_VirusScan"> McAfee</A>, the security company, to provide this for <A title="Yahoo" href="http://wiki.ittoolbox.com/index.php/Yahoo">Yahoo</A> surfers, to secure Web search engine results. <A title="Google" href="http://wiki.ittoolbox.com/index.php/Google">Google</A> has introduced this feature to provide Web masters comprehensive information on sites listed as malicious, thereby protecting the web-surfing public even further and protect the web-surfer from sites with spam, spyware, adware and other malicious software that can infect and damage a user’s PC.<br />
</P></td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://wiki.ittoolbox.com/index.php/Google_Safe_Browsing_Diagnostic_Page --><P>To use the new tool, a site URL is added to the end of this URL<BR /> <CODE><A rel="nofollow" title="http://www.google.com/safebrowsing/diagnostic?site=" class="external free" href="http://www.google.com/safebrowsing/diagnostic?site=">http://www.google.com/safebrowsing/diagnostic?site=</A></CODE><BR /> and the information is provided to the user.<br />
</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/5C238144-45DD-4A39-90C9-29EDFC1C8BE0/blog/" title="blog or email this clip"><img src="http://content6.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Thu, 05 Jun 2008 10:19:23 +0000</pubDate>
      <category domain="http://securityratty.com/tag/site url">site url</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/url">url</category>
      <category domain="http://securityratty.com/tag/google">google</category>
      <category domain="http://securityratty.com/tag/unsafe site">unsafe site</category>
      <category domain="http://securityratty.com/tag/diagnostic page">diagnostic page</category>
      <category domain="http://securityratty.com/tag/google safe">google safe</category>
      <category domain="http://securityratty.com/tag/malicious">malicious</category>
      <category domain="http://securityratty.com/tag/yahoo">yahoo</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=469">Protecting the web-surfing public</source>
    </item>
  </channel>
</rss>
