<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Security on Alkahest</title>
    <link>https://fenris.org/categories/security/</link>
    <description>Recent content in Security on Alkahest</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Fri, 18 Dec 2009 18:05:08 +0000</lastBuildDate>
    <atom:link href="https://fenris.org/categories/security/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>&#34;Hacking&#34; predator drones</title>
      <link>https://fenris.org/2009/12/18/hacking-predator-drones/</link>
      <pubDate>Fri, 18 Dec 2009 18:05:08 +0000</pubDate>
       <guid isPermaLink="false">https://fenris.org/?p=1113</guid> 
      <description>&lt;p&gt;This just makes me sad. Two articles, one in the &lt;a href=&#34;http://online.wsj.com/article/SB126102247889095011.html&#34;&gt;WSJ&lt;/a&gt;, the other on &lt;a href=&#34;http://www.cnn.com/2009/US/12/17/drone.video.hacked/index.html&#34;&gt;CNN&lt;/a&gt;, describing how insurgents in Iraq are hacking predator drones and receiving the video feeds that the drones are sending back to U.S. ground stations. First things first, let&amp;rsquo;s fix the headlines. Both are running something like &amp;ldquo;Iraqi insurgents hacked Predator drone feeds.&amp;rdquo; That should more clearly read: &amp;ldquo;Iraqi insurgents watching the videos that the Predator drone sends out unencrypted.&amp;rdquo; Or maybe &amp;ldquo;Iraqi insurgents watch Predator drone feeds on TV.&amp;rdquo;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Great moments in . . .</title>
      <link>https://fenris.org/2009/11/11/great-moments-in/</link>
      <pubDate>Thu, 12 Nov 2009 01:39:44 +0000</pubDate>
       <guid isPermaLink="false">https://fenris.org/?p=1046</guid> 
      <description>&lt;p&gt;Minor notes, none worth their own post.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Traffic management:&lt;/strong&gt; I get a call from K around 5:30. She’s stuck behind an accident and the cops on the scene, a) don’t tell people to take a detour until they’ve been there for a half hour; and b) once the ambulance has left the scene, don’t direct traffic around the one remaining open lane. So, after waiting a half hour, K has to take a 20+ minute detour home.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Memory:&lt;/strong&gt; Once she gets in, K and I are fixing leftovers for dinner. C: “Hey, where are the mashed potatoes?” K: “Where did you put them?” “In the fridge, but I can’t find them.” “Maybe they’re in the freezer.” “Nope, not there either.” Ten minutes of looking for the potatoes. Did we throw them out on Sunday? Nope, not in the trash. Did C put them in the pantry? Nope. Can’t find ’em, can’t find ’em. Finally, K says, “wait, we fixed rice on Sunday.” There weren’t any potatoes. I would attribute it to getting old, but I’ve always been this way.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;FUD (fear, uncertainty and doubt):&lt;/strong&gt; we’re testing some things at the office – will our authentication system (active directory) honor password failure lockouts when using LDAP authentication? I ask our windows consultant to either a) answer the question, or b) enable an account lockout policy so we can test. He responds back that he can do that, but with the warning that “many Linux services aren’t well-designed for this, and repeatedly try a cached or user-provided password, so that users or service accounts may be mysteriously locked out after one attempt or at some future time when passwords change.” Which is complete and utter B.S. Signs that it’s BS? He references Linux services as opposed to open source, i.e. attempted linux dig. And I used to “own” identity management services, including authentication at a large university and if this was the case, things would have blown up within 10 minutes. I thanked him for the advice and noted that I’ve never seen this, but that it’s why we test.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;OS Performance:&lt;/strong&gt; we’re looking into some new ideas at the office. Things that &lt;em&gt;could&lt;/em&gt; be useful as a preprocessor for a host based intrusion detection system. As part of my testing, I told my laptop to audit &lt;strong&gt;all&lt;/strong&gt; syscalls made to the kernel, by &lt;strong&gt;all&lt;/strong&gt; processes on the system. CPU load spiked, system performance went through the floor, the windowing system became almost completely non-responsive. In the two minutes it took to get access to a terminal, I logged 150 MB of audit logs. On the plus side, all of the information we need can be collected. Now I just need to figure out how to keep a usable system.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Self aggrandizement:&lt;/strong&gt; talking to my technical manager, we need to write up two journal papers based on our recent work. Cool!&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I hope everyone had a good Veteran’s Day and remembered to thank the veterans in their lives.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Facebook security vulnerabilities</title>
      <link>https://fenris.org/posts/facebook-security-vulnerabilities/</link>
      <pubDate>Thu, 05 Nov 2009 15:32:19 +0000</pubDate>
       <guid isPermaLink="false">https://fenris.org/?p=1035</guid> 
      <description>&lt;p&gt;and &lt;a href=&#34;http://www.techcrunch.com/2009/11/05/massive-facebook-and-myspace-flash-vulnerability-exposes-user-data/&#34;&gt;this&lt;/a&gt; is why I like cross-posting to facebook from my blog. It&amp;rsquo;s a healthy reminder that nothing on fb is actually private. If it&amp;rsquo;s online - it&amp;rsquo;ll be exposed eventually, whether through a new exploit, or just because you &amp;ldquo;friend&amp;rdquo; someone in the future that you had written about in the past.&lt;/p&gt;
&lt;p&gt;h/t &lt;a href=&#34;http://www.heathbar.org/weblog/&#34;&gt;hsarik&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>So, this is important</title>
      <link>https://fenris.org/posts/so-this-is-important/</link>
      <pubDate>Fri, 28 Aug 2009 03:14:27 +0000</pubDate>
       <guid isPermaLink="false">https://fenris.org/?p=987</guid> 
      <description>&lt;p&gt;I&amp;rsquo;m not a big baseball fan. For that matter, there are few ball sports that interest me. But, this is important. If you recall, a few years ago (2004), there was a big furor over steroids in baseball. The government searched BALCO and found evidence of rampant steroid use by baseball players. Now I hadn&amp;rsquo;t been paying attention to this, but there has been an ongoing legal dispute over that search and how it was conducted.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Digital Amway</title>
      <link>https://fenris.org/2008/03/28/digital-amway/</link>
      <pubDate>Sat, 29 Mar 2008 02:22:52 +0000</pubDate>
       <guid isPermaLink="false">https://fenris.org/2008/03/28/digital-amway/</guid> 
      <description>&lt;p&gt;A few years ago, I was accused of using the word “interesting in subtle ways. Sometimes it means a truly novel idea that I would like to learn more about, other times, it’s a novel idea of which I’m more than a little skeptical. In both cases, I stand by the description, to me, both are interesting – but it can make it a little hard to know what I’m really thinking. So take it with a grain of salt that I just read an interesting article in the February 2008 issue of IEEE Computer on how to turn music lovers (particularly teenagers) into music distributors.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Who could have guessed?</title>
      <link>https://fenris.org/2008/03/06/who-could-have-guessed/</link>
      <pubDate>Thu, 06 Mar 2008 12:27:36 +0000</pubDate>
       <guid isPermaLink="false">https://fenris.org/2008/03/06/who-could-have-guessed/</guid> 
      <description>&lt;p&gt;Gee, &lt;a href=&#34;https://fenris.org/2008/02/25/fisa-extension-and-telecom-amnesty/&#34;&gt;nobody&lt;/a&gt; could have predicted &lt;a href=&#34;http://www.cnn.com/2008/POLITICS/03/05/senate.fbi.ap/index.html?iref=werecommend&#34;&gt;this&lt;/a&gt; I suppose:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;The FBI improperly used national security letters in 2006 to obtain personal data on Americans during terror and spy investigations, Director Robert Mueller said Wednesday.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Admittedly, Mueller goes on to say that the reports were prior to new policies being put into place, but somehow that doesn’t make me feel much better. It’s things like this that have always made me very nervous about partnerships between law enforcement and industry. I’ll try to post something about InfraGard one of these days. It’s a little scary in its own right.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Is this thing on?</title>
      <link>https://fenris.org/2008/01/15/is-this-thing-on/</link>
      <pubDate>Wed, 16 Jan 2008 02:25:28 +0000</pubDate>
       <guid isPermaLink="false">https://fenris.org/index.php/2008/01/15/is-this-thing-on/</guid> 
      <description>&lt;p&gt;&lt;thump&gt; &lt;thump&gt; Is this thing still on?&lt;/p&gt;
&lt;p&gt;Okay, it’s been about three weeks since I’ve blogged anything. As I’ve stated before, this tends to happen when I’m too involved in living life to actually write about it. Fortunately (unfortunately?) it’s nothing terribly exciting. Let’s see:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Guitar:&lt;/strong&gt; my guitar playing has been scientifically shown to have 10% less suck than it did a month ago. However, with such a large amount of suck to begin with, we’re still not at anything that looks like good. I’m getting more fluent with the open chords and can switch between them reasonably well. I’m just starting to learn barre chords – the E barre chord to start with. There are still vast tracts of untouched suck in the barre chords. Also, I’m actually thinking of picking up some lessons – the ones at &lt;a href=&#34;http://jamplay.com&#34;&gt;jamplay.com&lt;/a&gt; seem pretty good.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Work:&lt;/strong&gt; still going well. There’s enough to do. I’m still not entirely used to billing by the (tenth of an) hour. Also, not really looking forward to flying to Ohio next week. I’ll only be gone for a day, but, ugh – who wants a 6am flight to Dayton!&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Break-in update:&lt;/strong&gt; nothing much new here. Still looking to make it harder for someone to break in. Had a neighborhood watch meeting last weekend – that’ll be good. Turns out this may be neither contractors nor kids. There are apparently some professional (stretching that word a bit) thieves working this area. There have been some eight different break-ins near by.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Non-profit work:&lt;/strong&gt; I’m convinced that whomever coined the phrase “academic politics are so sorted because the stakes are so small never worked with a non-profit. It’s just amazing the degree to which politics enters into the smallest damned thing.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;New year’s resolutions:&lt;/strong&gt; didn’t make any – never do. That said, I am trying to exercise more and cut down on my use of vulgarities. Profanity and cursing can wait until another year 🙂&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I think that’s about it for now.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Two factor authentication</title>
      <link>https://fenris.org/2007/11/06/two-factor-authentication/</link>
      <pubDate>Wed, 07 Nov 2007 02:05:42 +0000</pubDate>
       <guid isPermaLink="false">https://fenris.org/index.php/2007/11/06/two-factor-authentication/</guid> 
      <description>&lt;p&gt;A couple of weeks ago, Hunter and I were talking about passwords. More to the point, the inadequacy of passwords and why we haven’t moved beyond them yet. This touches on &lt;a href=&#34;https://fenris.org/index.php/2006/10/13/thinking-about-security-and-usability/&#34;&gt;several points that I made last year&lt;/a&gt;. Specifically, that a password that is secure enough starts to restrict its usability.&lt;/p&gt;
&lt;p&gt;In a nutshell, authentication is proving that you are who you claim to be. The standard ways of authenticating yourself are through: something you know (e.g., a password), something you have (e.g., a token) or something you are (e.g., biometrics, facial recognition, etc.). So the claim here is that the human brain is not good enough at remembering things to make “something you know secure. Unfortunately, it’s cheap and easy to implement. Two things which are always important.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Bob Ross</title>
      <link>https://fenris.org/2007/03/14/bob-ross/</link>
      <pubDate>Wed, 14 Mar 2007 20:54:24 +0000</pubDate>
       <guid isPermaLink="false">https://fenris.org/index.php/2007/03/14/bob-ross/</guid> 
      <description>&lt;p&gt;Created by “ &lt;a href=&#34;http://roboteconomist.blogspot.com/&#34;&gt;the Robot Economist&lt;/a&gt;, and for &lt;a href=&#34;http://heathbar.org/weblog/&#34;&gt;hsarik&lt;/a&gt;, it’s Bob Ross and the Joy of Painting Missiles. Click the picture for the full sized image with rotating scenery.
&lt;a href=&#34;http://bp0.blogger.com/_dqlJY9gMOQk/RfTBPlkcu3I/AAAAAAAAAAg/rmBC-ORlnCo/s1600-h/Bob-Ross-Plus-Missiles.gif&#34;&gt;&lt;img alt=&#34;bob-ross-plus-missiles.gif&#34; loading=&#34;lazy&#34; src=&#34;https://fenris.org/wp-content/uploads/2007/03/bob-ross-plus-missiles.gif&#34;&gt;&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>The FBI&#39;s national security letters</title>
      <link>https://fenris.org/2007/03/09/the-fbis-national-security-letters/</link>
      <pubDate>Sat, 10 Mar 2007 02:55:19 +0000</pubDate>
       <guid isPermaLink="false">https://fenris.org/index.php/2007/03/09/the-fbis-national-security-letters/</guid> 
      <description>&lt;p&gt;Sometime in late September or early October of 2001, I received a call from an individual identifying himself as an agent of the FBI and asking for information about the owner of an email account from the place I worked. He stated that he believed the account was relevant to a terrorist investigation. Of course, this was in the immediate aftermath of September 11th and everyone had security concerns, but I was also certain that I didn’t want to give away information to someone who shouldn’t have it. Following a fairly standard procedure, I requested his phone number, badge number and locale so that I could contact the FBI to confirm his identity. The agent gave me a lot of grief about this, noted that I was putting lives at risk by not immediately complying, etc., but I assured him that I would call right back.&lt;/p&gt;</description>
    </item>
    <item>
      <title>and people wonder why the change to DST worries me...</title>
      <link>https://fenris.org/2007/02/28/and-people-wonder-why-the-change-to-dst-worries-me/</link>
      <pubDate>Wed, 28 Feb 2007 23:38:06 +0000</pubDate>
       <guid isPermaLink="false">https://fenris.org/index.php/2007/02/28/and-people-wonder-why-the-change-to-dst-worries-me/</guid> 
      <description>&lt;p&gt;In 2005, congress mandated a change to daylight savings time, essentially, starting it three weeks earlier (March 11th, this year) and ending it three weeks later. Our local paper is requesting suggestions for what people will do with their 22 extra hours of daylight. Here’s my suggestion: spend the time fixing all of the computer problems caused by the DST change.&lt;/p&gt;
&lt;p&gt;Essentially, a change to DST is very similar to a self-inflicted Y2K problem. If you want to get a sense of how time/date issues can affect computer systems that aren’t prepared, take a look at &lt;a href=&#34;http://www.dailytech.com/article.aspx?newsid=6225&#34;&gt;this article regarding the new F-22 Raptor and it’s problems with the International Date Line&lt;/a&gt;. I wasn’t worried about Y2K because we knew about the issue for years and most modern operating systems and software had already addressed it. With the DST changes, we haven’t had nearly enough notice or preparation. Now, I’m not stocking up on canned goods, but I’m pretty certain that March 11th is going to bring about extra work.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Poindexter</title>
      <link>https://fenris.org/2006/11/24/poindexter/</link>
      <pubDate>Fri, 24 Nov 2006 17:55:40 +0000</pubDate>
       <guid isPermaLink="false">https://fenris.org/index.php/2006/11/24/poindexter/</guid> 
      <description>&lt;p&gt;It’s taken me a bit to write about Admiral Poindexter’s visit and the small group talk we had with him. Let me start by reminding folks that here’s a guy who was convicted of lying to congress. The conviction was later overturned on a technicality. He’s also very politically savvy. I once asked my father if he would ever pursue becoming a general in the army. He told me that he was hoping to make full colonel (he later retired as a lt. colonel), but that becoming a general required a literal act of congress and that you needed to become a politician. I would assume the same thing is the case with an admiral and doubly so in the case of Poindexter who managed to become the highest ranking geek in government. All of which is to say take my impressions with a grain of salt.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Admiral John Poindexter to speak at Duke University</title>
      <link>https://fenris.org/2006/11/13/admiral-john-poindexter-to-speak-at-duke-university/</link>
      <pubDate>Mon, 13 Nov 2006 04:06:24 +0000</pubDate>
       <guid isPermaLink="false">https://fenris.org/index.php/2006/11/13/admiral-john-poindexter-to-speak-at-duke-university/</guid> 
      <description>&lt;p&gt;In case you are looking for something interesting to do next week, go to Love Auditorium at Duke University on November 15th at 5pm. Admiral John Poindexter will be giving a talk: “ &lt;a href=&#34;http://www.provost.duke.edu/speaker_series/current_speakers.html&#34;&gt;A Vision for Countering Terrorism Through Information and Privacy Protection Technologies for the 21st Century&lt;/a&gt;. It should be an interesting and thought provoking discussion of where Poindexter draws the line between security and privacy.&lt;/p&gt;
&lt;p&gt;I’ll be meeting with Poindexter and a small group at 3pm – quite the birthday present.&lt;/p&gt;</description>
    </item>
    <item>
      <title>North Korean nuclear test</title>
      <link>https://fenris.org/2006/11/06/north-korean-nuclear-test/</link>
      <pubDate>Tue, 07 Nov 2006 00:03:14 +0000</pubDate>
       <guid isPermaLink="false">https://fenris.org/index.php/2006/11/06/north-korean-nuclear-test/</guid> 
      <description>&lt;p&gt;Well, it seems that we finally know what happened with the &lt;a href=&#34;http://www.abc.net.au/science/news/stories/2006/1763160.htm&#34;&gt;North Korean nuclear test that fizzled&lt;/a&gt;. They apparently mistranslated the &lt;a href=&#34;http://www.washingtonpost.com/wp-dyn/content/article/2006/11/03/AR2006110300019.html&#34;&gt;Arabic documents the U.S. posted online&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Okay, so neither of those is really very funny. On the one hand, the U.S. posted a whole host of Arabic documents from Iraq that had never been examined before in the vague hope that someone would be able to find evidence that Iraq had a WMD program before we invaded. This was idiotic. It’s equivalent to my posting an entire database of personal information in the hopes that someone online could determine if there were social security numbers in it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Biometrics - fingerprint scanners</title>
      <link>https://fenris.org/2006/10/23/biometrics-fingerprint-scanners/</link>
      <pubDate>Mon, 23 Oct 2006 14:00:05 +0000</pubDate>
       <guid isPermaLink="false">https://fenris.org/index.php/2006/10/23/biometrics-fingerprint-scanners/</guid> 
      <description>&lt;p&gt;I recently had a small argument with a vendor selling biometric fingerprint scanners tied to your credit card number. He said that they were the greatest and most secure thing ever; I said that there weren’t any standards and that the security of the devices was questionable.&lt;/p&gt;
&lt;p&gt;I wish I had seen &lt;a href=&#34;http://youtube.com/watch?v=zEXGetKk0Gg&#34;&gt;this&lt;/a&gt; earlier.&lt;/p&gt;
&lt;div style=&#34;position: relative; padding-bottom: 56.25%; height: 0; overflow: hidden;&#34;&gt;
			&lt;iframe allow=&#34;accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share; fullscreen&#34; loading=&#34;eager&#34; referrerpolicy=&#34;strict-origin-when-cross-origin&#34; src=&#34;https://www.youtube.com/embed/zEXGetKk0Gg?autoplay=0&amp;amp;controls=1&amp;amp;end=0&amp;amp;loop=0&amp;amp;mute=0&amp;amp;start=0&#34; style=&#34;position: absolute; top: 0; left: 0; width: 100%; height: 100%; border:0;&#34; title=&#34;YouTube video&#34;&gt;&lt;/iframe&gt;
		&lt;/div&gt;</description>
    </item>
    <item>
      <title>Thinking about security and usability</title>
      <link>https://fenris.org/2006/10/13/thinking-about-security-and-usability/</link>
      <pubDate>Sat, 14 Oct 2006 03:06:24 +0000</pubDate>
       <guid isPermaLink="false">https://fenris.org/index.php/2006/10/13/thinking-about-security-and-usability/</guid> 
      <description>&lt;p&gt;IT security (and for that matter, other security concerns too) are often seen as conflicting with usability. There is something to that. If you take any given technology and turn up the level of security it provides, you will almost always decrease the usability of the system.&lt;/p&gt;
&lt;p&gt;Consider passwords. If people are allowed to choose their own passwords, they will typically choose something very usable for them. They’ll pick their dog’s name, their wife’s name, their userid, etc. These passwords don’t provide much security. To compensate, we often turn up the security knob and require “stronger passwords, e.g., minimum of six characters with no dictionary words and multiple “character classes.&lt;/p&gt;</description>
    </item>
    <item>
      <title>for the record, Kip Hawley is an idiot</title>
      <link>https://fenris.org/2006/10/01/for-the-record-kip-hawley-is-an-idiot/</link>
      <pubDate>Sun, 01 Oct 2006 18:05:43 +0000</pubDate>
       <guid isPermaLink="false">https://fenris.org/index.php/2006/10/01/for-the-record-kip-hawley-is-an-idiot/</guid> 
      <description>&lt;p&gt;I missed this when it came out last week, but apparently, a gentleman named &lt;a href=&#34;http://flyertalk.com/forum/showthread.php?t=606142&#34;&gt;Ryan Bird&lt;/a&gt; was detained at the airport last week for writing “ &lt;a href=&#34;http://www.kiphawleyisanidiot.com/&#34;&gt;Kip Hawley is an idiot&lt;/a&gt; on his plastic baggie filled with toiletries. Apparently, the security trolls highly educated and diligent TSA employees took the statement to be a threat or at least behavior that they didn’t approve of and detained Mr. Bird – while telling him that he didn’t have 1st Amendment Rights at the TSA checkpoint.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Presentation</title>
      <link>https://fenris.org/2006/09/25/presentation/</link>
      <pubDate>Tue, 26 Sep 2006 01:14:14 +0000</pubDate>
       <guid isPermaLink="false">https://fenris.org/index.php/2006/09/25/presentation/</guid> 
      <description>&lt;p&gt;I survived giving my presentation today – in spite of the fact that I showed up to the wrong hotel, in the wrong part of the city. I blame my boss. I mentioned that the talk was at the Sheraton Imperial (although I hadn’t looked to see where that was yet) and he said, oh yeah, the one down on Campus Walk road. Get to the hotel on Campus Walk – oops, that’s the Millenium. Call my administrative assistant, she looks up the location and it’s 15 miles away.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Oops...</title>
      <link>https://fenris.org/2006/09/24/oops/</link>
      <pubDate>Mon, 25 Sep 2006 01:22:30 +0000</pubDate>
       <guid isPermaLink="false">https://fenris.org/index.php/2006/09/24/oops/</guid> 
      <description>&lt;p&gt;Checking my schedule for tomorrow, I realized that I have to give a talk at a major “human studies conference about security risks in web-based surveys. Unfortunately, I haven’t actually prepared anything. I’ve got my slides from the last time I did the talk, but I really wanted to do something more interesting and interactive this time – preferably with audience volunteers wearing silly hats. I may still try to put something together in the morning. I have an idea – but no sense of the feasibility.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Stock spam</title>
      <link>https://fenris.org/2006/09/24/stock-spam/</link>
      <pubDate>Sun, 24 Sep 2006 22:26:26 +0000</pubDate>
       <guid isPermaLink="false">https://fenris.org/index.php/2006/09/24/stock-spam/</guid> 
      <description>&lt;p&gt;One of the disadvantages of having so many email accounts is the number of spam you get. Recently, I’ve been noticing an increase in stock spam making it through my spam filters. I’ve been wondering how effective the spam is and whether or not one could make money shorting these stocks.&lt;/p&gt;
&lt;p&gt;Apparently, I’m not the only one. The local paper carried a NYT article titled “ &lt;a href=&#34;http://www.newsobserver.com/104/story/490154.html&#34;&gt;Many people fall for stock spam&lt;/a&gt;. In the article, the author describes the work of &lt;a href=&#34;http://papers.ssrn.com/sol3/papers.cfm?abstract-id=920553&#34;&gt;Frieder and Zittrain&lt;/a&gt;. Frieder and Zittrain found that pink sheet stocks that were heavily touted in spam were significantly more likely to be traded than non-touted stocks. Purchasing these stocks would lead a 5.25% loss within two days. For the most heavily touted stocks, the average loss was almost 8% in two days.&lt;/p&gt;</description>
    </item>
    <item>
      <title>racial profiling for terrorism</title>
      <link>https://fenris.org/2006/08/22/racial-profiling-for-terrorism/</link>
      <pubDate>Tue, 22 Aug 2006 22:53:26 +0000</pubDate>
       <guid isPermaLink="false">https://fenris.org/index.php/2006/08/22/racial-profiling-for-terrorism/</guid> 
      <description>&lt;p&gt;I’ve heard and read a number of people saying “political correctness be damned, we should use racial profiling to identify terrorists. The problem I’ve always had with this is that it makes no sense. Try the following test, identify the terrorist:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;young muslim male&lt;/li&gt;
&lt;li&gt;young muslim female&lt;/li&gt;
&lt;li&gt;asian male or female&lt;/li&gt;
&lt;li&gt;caucasian male or female&lt;/li&gt;
&lt;li&gt;black male or female&lt;/li&gt;
&lt;li&gt;hispanic male or female&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If you said that 1 and 2 have been terrorists and therefore we should profile them, you are partially right. However, what about all of the asian terrorists (e.g. Fillipinos)? Caucasians? Hmm, the IRA, David Koresh, Timmothy McVeigh, etc. As near as I can guess, the only racial groups that shouldn’t be profiled would be blacks and hispanics. This can’t work.&lt;/p&gt;</description>
    </item>
    <item>
      <title>things that make a security officer cry</title>
      <link>https://fenris.org/2006/08/14/things-that-make-a-security-officer-cry/</link>
      <pubDate>Mon, 14 Aug 2006 19:33:35 +0000</pubDate>
       <guid isPermaLink="false">https://fenris.org/index.php/2006/08/14/things-that-make-a-security-officer-cry/</guid> 
      <description>&lt;p&gt;I spent a lot of time last week looking at an application in order to assess its security. The thing that was troubling me was that this is a web application and the primary form for data entry was defined like:&lt;/p&gt;
&lt;p&gt;form name=foo method=post action=&lt;/p&gt;
&lt;p&gt;This means that the nothing happens when you hit submit on the form – at least not in the html world. So, I took a closer look and found that each of the buttons (submit and clear) actually had a field “onclick=’doSomething();&amp;rsquo; attribute.&lt;/p&gt;</description>
    </item>
    <item>
      <title>a nomenclature question</title>
      <link>https://fenris.org/2006/08/08/a-nomenclature-question/</link>
      <pubDate>Tue, 08 Aug 2006 16:49:29 +0000</pubDate>
       <guid isPermaLink="false">https://fenris.org/index.php/2006/08/08/a-nomenclature-question/</guid> 
      <description>&lt;p&gt;given that the vulnerability and the patches haven’t yet been released, does &lt;a href=&#34;http://www.us-cert.gov/current/current_activity.html#msvuls&#34;&gt;this&lt;/a&gt; constitute a “-1 day exploit?&lt;/p&gt;</description>
    </item>
    <item>
      <title>Password security question</title>
      <link>https://fenris.org/2006/07/19/password-security-question/</link>
      <pubDate>Wed, 19 Jul 2006 15:00:21 +0000</pubDate>
       <guid isPermaLink="false">https://fenris.org/index.php/2006/07/19/password-security-question/</guid> 
      <description>&lt;p&gt;I wonder if &lt;a href=&#34;https://fenris.org/index.php/www.realuser.com&#34;&gt;these folks&lt;/a&gt; have read the recent &lt;a href=&#34;http://www.nytimes.com/2006/07/18/health/psychology/18face.html?_r=1&amp;amp;8dpc&amp;amp;oref=slogin&#34;&gt;article&lt;/a&gt; in the NY Times regarding prosopagnosia?&lt;/p&gt;
&lt;p&gt;The company Passfaces has a password replacement technology that uses the brain’s ability to recognize faces. The idea is that the user selects a set of faces. They are then presented with a series of options where each of their faces is hidden in a group of other faces. By correctly selecting their faces, they authenticate themselves. The company says that using Passfaces will reduce calls to a help desk because people can remember faces for years without seeing them. There’s a demo which allows you to test how easy the system is.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
