<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Jay Knight &#187; security</title>
	<atom:link href="http://jk3.us/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://jk3.us</link>
	<description>...or something along those lines</description>
	<lastBuildDate>Mon, 31 Oct 2011 21:22:03 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Your Chance to Stop REAL ID</title>
		<link>http://jk3.us/2007/05/08/your-chance-to-stop-real-id/</link>
		<comments>http://jk3.us/2007/05/08/your-chance-to-stop-real-id/#comments</comments>
		<pubDate>Tue, 08 May 2007 18:54:21 +0000</pubDate>
		<dc:creator>Jay</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://jk3.us/2007/05/08/your-chance-to-stop-real-id/</guid>
		<description><![CDATA[For the two next hours and a little bit (until 5 PM Eastern, 5/8/07), the Department of Homeland Security is accepting comments from the public about REAL ID. The Privacy Coalition has a page detailing how you can contact them &#8230; <a href="http://jk3.us/2007/05/08/your-chance-to-stop-real-id/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>For the two next hours and a little bit (until 5 PM Eastern, 5/8/07), the Department of Homeland Security is accepting comments from the public about REAL ID.  The Privacy Coalition has <a href="http://www.privacycoalition.org/stoprealid/">a page</a> detailing how you can contact them and let your voice be heard.  So please go and submit your comment to crush this silliness once and for all (What are the chances?).</p>
<p>Edit: <a href="http://www.schneier.com/blog/archives/2007/05/real_id_action.html">Bruce Schneier is smarter than me</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://jk3.us/2007/05/08/your-chance-to-stop-real-id/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>On Avoiding the Password &#039;Explosion&#039;</title>
		<link>http://jk3.us/2006/12/04/on-avoiding-the-password-explosion/</link>
		<comments>http://jk3.us/2006/12/04/on-avoiding-the-password-explosion/#comments</comments>
		<pubDate>Mon, 04 Dec 2006 21:04:57 +0000</pubDate>
		<dc:creator>Jay</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://jk3.us/2006/12/04/on-avoiding-the-password-explosion/</guid>
		<description><![CDATA[This article from the BBC states: The number of passwords and logins web users need makes it inevitable they will re-use phrases, warned the International Telecommunications Union. Re-using these identifiers puts people at serious risk of falling victim to identity &#8230; <a href="http://jk3.us/2006/12/04/on-avoiding-the-password-explosion/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://news.bbc.co.uk/2/hi/technology/6199372.stm">This article</a> from the BBC states:</p>
<blockquote><p>The number of passwords and logins web users need makes it inevitable they will re-use phrases, warned the International Telecommunications Union.</p>
<p>Re-using these identifiers puts people at serious risk of falling victim to identity theft, said the ITU report.</p>
<p>It called on regulators and businesses to find better ways for people to identify themselves to websites.</p></blockquote>
<p>This just re-iterates what I&#8217;ve said before: &#8220;<a href="http://jk3.us/2005/07/14/time-is-ripe-for-distibuted-authentication/">Time is ripe for distributed authentication</a>.&#8221;</p>
<p>OpenID already exists, is fairly well proven to avoid these problems and has support in several programming languages and content management systems.  The only barrier to overcome is getting joe internet user to understand how it works and how it benefits  them.</p>
<p>But whatever you do, please don&#8217;t leave it up to regulators.</p>
]]></content:encoded>
			<wfw:commentRss>http://jk3.us/2006/12/04/on-avoiding-the-password-explosion/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Walt Disney World fingerprints visitors</title>
		<link>http://jk3.us/2006/09/01/walt-disney-world-fingerprints-visitors/</link>
		<comments>http://jk3.us/2006/09/01/walt-disney-world-fingerprints-visitors/#comments</comments>
		<pubDate>Fri, 01 Sep 2006 15:23:23 +0000</pubDate>
		<dc:creator>Jay</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://jk3.us/2006/09/01/walt-disney-world-fingerprints-visitors/</guid>
		<description><![CDATA[Read this Boing Boing article&#8230; They were doing this when we went in June&#8230; I didn&#8217;t like it one bit. On the one hand, I was amazed that no one really cared&#8230; On the other hand, I put my fingers &#8230; <a href="http://jk3.us/2006/09/01/walt-disney-world-fingerprints-visitors/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Read <a href="http://www.boingboing.net/2006/09/01/walt_disney_world_fi.html">this Boing Boing article</a>&#8230;</p>
<p>They were doing this when <a href="http://flickr.com/photos/jk3us/sets/72157594197494219/">we went in June</a>&#8230; I didn&#8217;t like it one bit.</p>
<p>On the one hand, I was amazed that no one really cared&#8230; On the other hand, I put my fingers in those machines just like everyone else.</p>
]]></content:encoded>
			<wfw:commentRss>http://jk3.us/2006/09/01/walt-disney-world-fingerprints-visitors/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>You vs. Your software:  The Battle Over Your Computer</title>
		<link>http://jk3.us/2006/05/04/you-vs-your-software-the-battle-over-your-computer/</link>
		<comments>http://jk3.us/2006/05/04/you-vs-your-software-the-battle-over-your-computer/#comments</comments>
		<pubDate>Thu, 04 May 2006 19:21:42 +0000</pubDate>
		<dc:creator>Jay</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[life]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://jk3.us/2006/05/04/you-vs-your-software-the-battle-over-your-computer/</guid>
		<description><![CDATA[Go read the excellent article by Bruce Schneier discussing who actually has control over your computer and who you can trust. If you don&#8217;t typically think about this stuff, now is a good time to start: There&#8217;s a battle raging &#8230; <a href="http://jk3.us/2006/05/04/you-vs-your-software-the-battle-over-your-computer/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Go read <a title="Who Owns Your Computer?" href="http://www.schneier.com/blog/archives/2006/05/who_owns_your_c.html">the excellent article</a> by Bruce Schneier discussing who actually has control over your computer and who you can trust.  If you don&#8217;t typically think about this stuff, now is a good time to start:</p>
<blockquote><p>There&#8217;s a battle raging on your computer right now &#8212; one that pits you against worms and viruses, Trojans, spyware, automatic update features and digital rights management technologies. It&#8217;s the battle to determine who owns your computer.</p></blockquote>
<p>Installing Software on your computer (or sometimes just sticking a CD in) is roughly analogous to letting someone live in your house.  Once they&#8217;re invited in, they have access to anything in it while you&#8217;re not looking.  They may even secretly leave unwanted gifts behind after they&#8217;re gone.  Be careful about what makes its way inside.</p>
<p>Go now, and take your computer back.</p>
]]></content:encoded>
			<wfw:commentRss>http://jk3.us/2006/05/04/you-vs-your-software-the-battle-over-your-computer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Time is ripe for distributed authentication</title>
		<link>http://jk3.us/2005/07/14/time-is-ripe-for-distibuted-authentication/</link>
		<comments>http://jk3.us/2005/07/14/time-is-ripe-for-distibuted-authentication/#comments</comments>
		<pubDate>Fri, 15 Jul 2005 02:30:43 +0000</pubDate>
		<dc:creator>Jay</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://jk3.us/?p=13</guid>
		<description><![CDATA[I, along with all member of Spread Firefox, received an email explaining that their server had been accessed by an attacker: We don&#8217;t have any evidence that the attackers obtained personal information about site users, and we believe they accessed &#8230; <a href="http://jk3.us/2005/07/14/time-is-ripe-for-distibuted-authentication/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I, along with all member of <a href="http://spreadfirefox.com/">Spread Firefox</a>, received an email explaining that their server had been accessed by an attacker:</p>
<blockquote><p>We don&#8217;t have any evidence that the attackers obtained personal information about site users, and we believe they accessed the machine to use it to send spam.  However, it is possible that the attackers acquired information site users provided to the site.</p></blockquote>
<p>&#8230; and a little later in the email &#8230;</p>
<blockquote><p>We recommend that you change your Spread Firefox password and the password of any accounts where you use the same password as your Spread Firefox account. </p></blockquote>
<p>This is a great reason that a distributed authentication standard needs to be accepted and used across the web&#8230; and soon.  A distributed single sign on solution would prevent things like this happening&#8230; not preventing servers from being compromised, but preventing attackers from finding usernames and passwords that are potentially (and probably) identical to the credentials used to authenticate on other sites.</p>
<p>Of the potential solutions I&#8217;ve seen, I think I like <a href="http://openid.net/">OpenID</a> the best.  But I would like to see people critique and suggest improvements.  The solution needs to work, of course, but it should also be simple and extensible.</p>
<p>It&#8217;s time that we stop trusting every site we use with sensitive information.</p>
]]></content:encoded>
			<wfw:commentRss>http://jk3.us/2005/07/14/time-is-ripe-for-distibuted-authentication/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic page generated in 0.373 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2012-05-15 03:56:15 -->

