<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>T3H Blog</title>
	<atom:link href="http://www.triple3house.com/http:/www.triple3house.com/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.triple3house.com</link>
	<description>Blog by Ecaps Rebyc</description>
	<lastBuildDate>Wed, 10 Mar 2010 09:00:59 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Voluntary Breach Disclosure (cyber attack)</title>
		<link>http://www.triple3house.com/http:/www.triple3house.com/blog/</link>
		<comments>http://www.triple3house.com/http:/www.triple3house.com/blog/#comments</comments>
		<pubDate>Wed, 10 Mar 2010 08:59:54 +0000</pubDate>
		<dc:creator>rioux</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[voluntary breach disclosure]]></category>

		<guid isPermaLink="false">http://www.triple3house.com/?p=1308</guid>
		<description><![CDATA[Just about any one involved with cyber security in this region knows that hundred of servers operated by local governments in Japan are vulnerable to cyber-attacks; and, most entities failing to take countermeasures.
According to the Japanese Local Authorities Systems Development Center report describes that servers managed by nearly 200 prefectural and municipal governments across Japan [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.triple3house.com/wp-content/uploads/2010/03/disclosure.jpg" target="_blank"><img class="alignleft size-thumbnail wp-image-1309" title="disclosure" src="http://www.triple3house.com/wp-content/uploads/2010/03/disclosure-150x150.jpg" alt="" width="150" height="150" /></a>Just about any one involved with cyber security in this region knows that hundred of servers operated by local governments in Japan are vulnerable to cyber-attacks; and, most entities failing to take countermeasures.</p>
<p>According to the Japanese Local Authorities Systems Development Center report describes that servers managed by nearly 200 prefectural and municipal governments across Japan (and likely national-level ministries), and other government affiliated organizations, can easily be compromised.</p>
<p>About 1,400 local entities – mainly prefectural and municipal governments – belong to the center, a foundation operated under the jurisdiction of the Internal Affairs and Communications Ministry. Each year, it surveys these local entities regarding server safety and other matters. However, until now it has never publicly released information on how local governments manage their servers.</p>
<p>In fiscal 2008, the center investigated 3,467 servers operated by 647 local entities. The result showed that 193 entities, or 30 percent of those investigated, continue to use problematic servers.</p>
<p>Of these entities, 70 had so many server-related problems the center concluded they needed to urgently improve their operational environments.</p>
<p>The 495 servers contain residents&#8217; personal information, but use an old cryptographic system in which defects were detected more than a decade ago.</p>
<p>Furthermore, 27 servers loaded with basic software are still being used without updated security measures after the support period provided by a software company expired more than five years ago.</p>
<p>In both cases, the center pointed out that the use of such servers was problematic.</p>
<p>According to a post-survey questionnaire, despite being fully aware that local residents&#8217; personal information could be leaked, 54 entities of those with security problems, said they had no plans to improve their operational environments, with some saying they could not afford to do so, while others said the matter was of no importance (the later being my all time favorite, having heard it so often over the last 10 years).</p>
<p>Elsewhere, many governments are trying to establish Voluntary Breach Disclosure regulations. (Australia, <a href="http://www.priv.gc.ca/speech/2009/sp-d_20090608_ed_e.cfm" target="_blank">Canada</a>, New Zealand, <a href="http://bit.ly/BTAlC" target="_blank">United States</a>) Currently there is no common way for organizations to safely and confidentially share data about attacks they suffer, nor is there necessarily much incentive to do so.</p>
<p>Aside from the obvious privacy concerns and worries about damage to their public images in the event of a publicly disclosed hack. Many organizations have reservations about sharing their breach information with law enforcement because it is often more of a one-way street than an information-sharing arrangement. They supply their attack information to the authorities and more often than not never hear back from them.</p>
<p>But that soon could change, at least in the United States. FBI director Robert Mueller last week in a keynote address at the RSA Conference 2010 said while today it&#8217;s the exception rather than the rule for organizations to report cyber-attacks to the bureau, he <a href="http://www.darkreading.com/security/cybercrime/showArticle.jhtml?articleID=223101656" target="_blank">promised some big changes</a> that could allay privacy concerns. &#8220;We will minimize the disruption to your business. We will safeguard your privacy and your data. Where necessary, we will seek protective orders to preserve trade secrets and business confidentiality. And we will share with you what we can, as quickly as we can, about the means and methods of attack,&#8221; Mueller told attendees.</p>
<p>Well that would be a definite step in the right direction and an impetus for other to follow.</p>
<p>Source: <a href="http://bit.ly/dlLa91" target="_blank">Voluntary Breach Disclosure Rare But Valuable</a> by Kelly Jackson Higgins, <em>Dark Reading</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.triple3house.com/http:/www.triple3house.com/blog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Discipline</title>
		<link>http://www.triple3house.com/http:/www.triple3house.com/blog/</link>
		<comments>http://www.triple3house.com/http:/www.triple3house.com/blog/#comments</comments>
		<pubDate>Wed, 10 Mar 2010 07:22:08 +0000</pubDate>
		<dc:creator>rioux</dc:creator>
				<category><![CDATA[Travels]]></category>
		<category><![CDATA[Jakarta]]></category>
		<category><![CDATA[Kuala Lumpur]]></category>
		<category><![CDATA[Singapore]]></category>

		<guid isPermaLink="false">http://www.triple3house.com/?p=1300</guid>
		<description><![CDATA[Recently I travelled to Kuala Lumpur, Singapore, and Jakarta. In KL I attended a cyber security seminar – interestingly enough the so called ‘emerging’ economies are doing somewhat better overall than the ‘advanced’ economies in respect to security; I gather it comes from less legacy baggage and the benefits of years of experimenting by old [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.triple3house.com/wp-content/uploads/2010/03/jakarta1.jpg"><img class="alignleft size-thumbnail wp-image-1299" title="The sites (or  sight?)" src="http://www.triple3house.com/wp-content/uploads/2010/03/jakarta1-150x150.jpg" alt="" width="150" height="150" /></a>Recently I travelled to Kuala Lumpur, Singapore, and Jakarta. In KL I attended a cyber security seminar – interestingly enough the so called ‘emerging’ economies are doing somewhat better overall than the ‘advanced’ economies in respect to security; I gather it comes from less legacy baggage and the benefits of years of experimenting by old countries (in term of cyberspace).</p>
<p>As for Singapore, in the last year I was in SIN 14 times, but this was my first time in downtown in a long time. Given a free weekend, I walked about town and even managed to find nature among all that concrete.<a href="http://www.triple3house.com/wp-content/uploads/2010/03/jakarta2.jpg"><img class="size-thumbnail wp-image-1301 alignright" title="munchkins" src="http://www.triple3house.com/wp-content/uploads/2010/03/jakarta2-150x150.jpg" alt="" width="150" height="150" /></a></p>
<p>In Jakarta, time was precious and rain abundant – being the rainy season. Nevertheless, some of my local colleagues took time to drive me about town on an overcast, but rain free, Sunday. I took in the sites (or was it sight) and a few pictures. The highlight of the day was being mobbed by munchkins while visiting a museum.</p>
<p>PS. On blogging, it is not so much as not having time as not having the discipline to blog in a consistent manner, sorry.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.triple3house.com/http:/www.triple3house.com/blog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Warning about the threat from Chinese espionage getting old</title>
		<link>http://www.triple3house.com/http:/www.triple3house.com/blog/</link>
		<comments>http://www.triple3house.com/http:/www.triple3house.com/blog/#comments</comments>
		<pubDate>Tue, 02 Feb 2010 01:14:54 +0000</pubDate>
		<dc:creator>rioux</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[CPNI]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[cyberwarfare]]></category>
		<category><![CDATA[espionage]]></category>
		<category><![CDATA[MI5]]></category>

		<guid isPermaLink="false">http://www.triple3house.com/?p=1283</guid>
		<description><![CDATA[The UK Centre for the Protection of National Infrastructure (MI5) prepared a short &#8216;restricted&#8217; report back in 2007~08 entitled “The Threat from Chinese Espionage” &#8211; that was widely distributed to UK business organizations worldwide – to little effect.
The report of bugging and burgling by agents from the People&#8217;s Liberation Army and the Ministry of Public [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.triple3house.com/wp-content/uploads/2010/02/iStock_000011530241XSmall.jpg"><img class="alignleft size-thumbnail wp-image-1284" title="iStock_000011530241XSmall" src="http://www.triple3house.com/wp-content/uploads/2010/02/iStock_000011530241XSmall-150x150.jpg" alt="" width="150" height="150" /></a>The UK <a href="http://www.cpni.gov.uk/" target="_blank">Centre for the Protection of National Infrastructure</a> (<a href="https://www.mi5.gov.uk/" target="_blank">MI5</a>) prepared a short &#8216;restricted&#8217; report back in 2007~08 entitled “The Threat from Chinese Espionage” &#8211; that was widely distributed to UK business organizations worldwide – to little effect.</p>
<p>The report of bugging and burgling by agents from the People&#8217;s Liberation Army and the Ministry of Public Security. It warns also of electronic gifts given at exhibitions and seminars riddled with Trojans capable of creating a backdoor, ferreting and transmitting specific data, and remotely triggered malware.</p>
<p>According to CPNI “The Chinese government represents one of the most significant espionage threats to the UK because of its use of widespread electronic hacking.” UK cybersecurity experts suspect that Chinese cyberwarfare units have directed concerted hacking exercises against UK&#8217;s defence, energy, communications, and manufacturing entities.</p>
<p>In their great wisdom MI5 and CPNI believe that “any UK company might be at risk if it holds information which would benefit the Chinese.”</p>
<p>At the time of the &#8216;restricted&#8217; letter released by MI5&#8217;s DG it was observed in <a href="http://www.schneier.com/blog/archives/2007/12/mi5_sounds_alar.html" target="_blank">Schneier on Security</a> (4 December 2007) that sending a confidential letter to 300 businesses and expecting it to be kept so was not such a good idea – publicity, and lots of it, should have been the order of the day. The <a href="http://www.mps.gov.cn/n16/index.html" target="_blank">Chinese Ministry of Public Security</a> must have had a good laugh at the time (from reading their own copy); it sure did not slow them down any&#8230;</p>
<p>References:</p>
<p><a href="http://business.timesonline.co.uk/tol/business/industry_sectors/technology/article2980250.ece">MI5 alert on China’s cyberspace spy threat</a>, Exclusive: director-general of MI5 sends letter to British companies warning systems are under attack from China, From The Times, published: 1 December 2007</p>
<p><a href="http://www.nytimes.com/2010/02/01/world/europe/01spy.html" target="_blank">Britain Warned Businesses of Threat of Chinese Spying</a>, By <a href="http://topics.nytimes.com/top/reference/timestopics/people/b/john_f_burns/index.html?inline=nyt-per" target="_blank">Jonh F. Burns</a>, published: 31 January 2010<br />
<a class="a2a_dd" href="http://www.addtoany.com/share_save?linkname=&amp;linkurl=https%3A%2F%2Fwww.triple3house.com%2F"><img src="http://static.addtoany.com/buttons/share_save_171_16.png" border="0" alt="Share/Bookmark" width="171" height="16" /></a><script type="text/javascript">// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[ a2a_linkurl="https://www.triple3house.com/";a2a_show_title=1;
// ]]&gt;</script><script src="http://static.addtoany.com/menu/page.js" type="text/javascript"></script></p>
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
]]></content:encoded>
			<wfw:commentRss>http://www.triple3house.com/http:/www.triple3house.com/blog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Most are largely ignorant of cyber threats</title>
		<link>http://www.triple3house.com/http:/www.triple3house.com/blog/</link>
		<comments>http://www.triple3house.com/http:/www.triple3house.com/blog/#comments</comments>
		<pubDate>Mon, 01 Feb 2010 14:06:52 +0000</pubDate>
		<dc:creator>rioux</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[cyber threat]]></category>
		<category><![CDATA[Cybersecurity]]></category>

		<guid isPermaLink="false">http://www.triple3house.com/?p=1278</guid>
		<description><![CDATA[The Internet has opened global markets and revolutionized modern business practices. Yet, while providing new opportunities, reliance on the Web has also exposed new vulnerabilities. McAfee estimates that in 2008, “companies worldwide lost more than $1 trillion” from IP and data theft. A recently released PwC report on the rising threat of e-espionage asks: “Are [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.triple3house.com/wp-content/uploads/2010/02/iStock_000004750446XSmall.jpg"><img class="alignleft size-thumbnail wp-image-1279" title="Unusual email sign" src="http://www.triple3house.com/wp-content/uploads/2010/02/iStock_000004750446XSmall-150x150.jpg" alt="" width="150" height="150" /></a>The Internet has opened global markets and revolutionized modern business practices. Yet, while providing new opportunities, reliance on the Web has also exposed new vulnerabilities. McAfee estimates that in 2008, <a href="http://www.mcafee.com/us/about/press/corporate/2009/20090129_063500_j.html"><em>“companies worldwide lost more than $1 trillion”</em></a> from IP and data theft. A recently released <a href="http://www.pwc.com/en_US/us/it-risk-security/assets/e-espionage.pdf">PwC report on the rising threat of e-espionage</a> asks: <em>“Are companies aware and ready to respond?”</em> In general, the resounding answer is, “No.”</p>
<p>Surveys after reports after commissions unanimously demonstrate that the Internet (Web, cyberspace) is unsecured. Threats are multiplying and growing evermore successful in gaining access to desired data or results. Nevertheless, no one in is right mind stays away – yet, most do very little to protect their property, even themselves – Why?</p>
<p>One answer is ease of use – the Internet is too simple to use and yields too much benefits at a click – how can something this beneficial be this nefarious!</p>
<p>Until we find the right answer, we will continue to barrel down towards an unparalleled cataclysmic  catastrophe where not only IP or data will be lost, but lives&#8230;</p>
<p>References:</p>
<p><a href="http://www.nytimes.com/2010/02/02/us/29cyber.html">Study Finds Growing Fear of Cyberattacks</a>, by <a href="http://topics.nytimes.com/top/reference/timestopics/people/m/john_markoff/index.html?inline=nyt-per">John Markoff</a>, Published: 28 January 2010</p>
<p><a href="http://resources.mcafee.com/content/NAUnsecuredEconomiesReport">Unsecured Economies: Protecting Vital Information</a>, The first global study highlighting the vulnerability of the world’s intellectual property and sensitive information, December 2009</p>
<p><a href="http://csisa.org/files/media/csis/pubs/081208_securingcyberspace_44.pdf">Securing Cyberspace for the 44th Presidency</a>, <a href="http://csis.org/files/media/csis/pubs/081208_securingcyberspace_44.pdf">A Report of the CSIS Commission on Cybersecurity for the 44th Presidency, December 2008</a></p>
<p><a class="a2a_dd" href="http://www.addtoany.com/share_save?linkname=&amp;linkurl=https%3A%2F%2Fwww.triple3house.com%2F"><img src="http://static.addtoany.com/buttons/share_save_171_16.png" border="0" alt="Share/Bookmark" width="171" height="16" /></a><script type="text/javascript">// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[ a2a_linkurl="https://www.triple3house.com/";a2a_show_title=1;
// ]]&gt;</script><script src="http://static.addtoany.com/menu/page.js" type="text/javascript"></script></p>
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
]]></content:encoded>
			<wfw:commentRss>http://www.triple3house.com/http:/www.triple3house.com/blog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Internet surveillance is on the rise – get use to it!</title>
		<link>http://www.triple3house.com/http:/www.triple3house.com/blog/</link>
		<comments>http://www.triple3house.com/http:/www.triple3house.com/blog/#comments</comments>
		<pubDate>Fri, 29 Jan 2010 02:32:07 +0000</pubDate>
		<dc:creator>rioux</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[EFF]]></category>
		<category><![CDATA[Internet Surveillance]]></category>
		<category><![CDATA[The Onion Router]]></category>

		<guid isPermaLink="false">http://www.triple3house.com/?p=1263</guid>
		<description><![CDATA[The Electronic Frontier Foundation (EFF), whose lawyers brought the National Security Agency&#8217;s warrantless surveillance program case to court in 2008, unsurprisingly lost their case and plans to appeal. This means that the practice of funnelling Internet traffic by Telcos to government security agencies will continues unabated in the US.
This will also give leverage to security [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.triple3house.com/wp-content/uploads/2010/01/iStock_000009029979XSmall.jpg"><img class="alignleft size-thumbnail wp-image-1264" title="iStock_000009029979XSmall" src="http://www.triple3house.com/wp-content/uploads/2010/01/iStock_000009029979XSmall-150x150.jpg" alt="" width="150" height="150" /></a>The <a href="https://www.eff.org/" target="_blank">Electronic Frontier Foundation</a> (EFF), <a href="http://www.eff.org/cases/jewel">whose lawyers brought the National Security Agency&#8217;s warrantless surveillance program case to court in 2008</a>, unsurprisingly lost their case and <a href="http://www.eff.org/press/archives/2010/01/21">plans to appeal</a>. This means that the practice of funnelling Internet traffic by Telcos to government security agencies will continues unabated in the US.</p>
<p>This will also give leverage to security and law enforcement agencies to persuade ISPs (and in some case developers) to provide exploitable backdoors to access emails unimpeded and continue Internet filtering unhindered by privacy regulations. However, more damaging will be the international repercussion; countries like <a href="http://opennet.net/research/australia-and-new-zealand">Australia</a>, <a href="http://www.canada.com/Technology/Feds+give+cops+Internet+snooping+powers/1706191/story.html">Canada</a>, the <a href="http://en.wikinews.org/wiki/Project_INDECT:EU_efforts_to_one-up_US_surveillance_and_spy_technology" target="_blank">EU</a>, <a href="http://www.netzpolitik.org/2009/the-dawning-of-internet-censorship-in-germany/">Germany</a>, <a href="http://en.wikipedia.org/wiki/SORM" target="_blank">Russia</a>, <a href="http://www.thelocal.se/12334/20080610/">Sweden</a>, the <a href="http://www.theregister.co.uk/2008/05/20/central_government_database_proposed/">United Kingdom</a>, and many others around the world will be embolden in advancing greater Internet surveillance and joint the ranks of the likes of <a href="http://pewresearch.org/pubs/776/china-internet">China</a>, <a href="http://www.nokiasiemensnetworks.com/press/press-releases/provision-lawful-intercept-capability-iran">Iran</a>, and many others oppressive (draconian) governments.</p>
<p>Nothing surprising here, governments will always find at least one reason to eavesdrop on its citizens – be it to protect wayward nationals at one end of the spectrum to insecure politicians to give themselves an edge over the masses&#8217; discontent (justified or not), or simply because they can do it under the guise of prevention or perversion.</p>
<p>So get over it, short of setting-up your own clean email address servers that you access via <a href="http://tor.freehaven.net/">TOR sites</a> &#8211; governments sponsored hacking and surveillance is here to stay, and they will apply the 5Ws to fit their political or personal agenda.</p>
<p>Note: Clean email address is where you write emails in draft form, and not send them, but allow trusted contacts to also access the account, read the draft message, and type a draft response. <a href="http://www.onion-router.net/">The Onion Router</a> (TOR) – the general idea for TOR is that your connection goes through a server that then processes the encrypted connection through a series of proxy servers. The result is a virtual dead-end for anyone trying to analyze the path you took to get to your clean mail server.</p>
<p>References:</p>
<p><a href="http://www.hurriyetdailynews.com/n.php?n=internet-censorship-is-on-the-rise-2010-01-27">Internet censorship on the rise</a>, by <a href="http://www.linkedin.com/profile?authToken=gvtK&amp;viewProfile=&amp;authType=name&amp;locale=en_US&amp;key=2236546">Ersu Abalk</a>, published 27 January 2010</p>
<p><a href="http://www.crn.com.au/News/165470,top-10-technologies-to-beat-tyranny.aspx">Top 10 technologies to beat tyrann</a>y, By <a href="http://www.crn.com.au/Author/225732,iain-thomson.aspx">Iain Thomson</a>, published: 25 January 2010</p>
<p><a href="http://www.cnn.com/2010/OPINION/01/23/schneier.google.hacking/index.html">U.S. enables Chinese hacking Google</a>, by <a href="http://www.schneier.com/">Bruce Schneier</a>, Special to CNN, published 23 January 2010</p>
<p><a class="a2a_dd" href="http://www.addtoany.com/share_save?linkname=&amp;linkurl=https%3A%2F%2Fwww.triple3house.com%2F"><img src="http://static.addtoany.com/buttons/share_save_171_16.png" border="0" alt="Share/Bookmark" width="171" height="16" /></a><script type="text/javascript">// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[ a2a_linkurl="https://www.triple3house.com/";a2a_show_title=1;
// ]]&gt;</script><script src="http://static.addtoany.com/menu/page.js" type="text/javascript"></script></p>
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
]]></content:encoded>
			<wfw:commentRss>http://www.triple3house.com/http:/www.triple3house.com/blog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A house is build from the bottom up!</title>
		<link>http://www.triple3house.com/http:/www.triple3house.com/blog/</link>
		<comments>http://www.triple3house.com/http:/www.triple3house.com/blog/#comments</comments>
		<pubDate>Tue, 26 Jan 2010 07:54:49 +0000</pubDate>
		<dc:creator>rioux</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[ISAF]]></category>
		<category><![CDATA[Kei Eide]]></category>
		<category><![CDATA[Taliban]]></category>

		<guid isPermaLink="false">http://www.triple3house.com/?p=1254</guid>
		<description><![CDATA[Kei Eide, the UN special representative in Afghanistan, suggests that ISAF and the UN give into grievances expressed by Taliban leaders regarding the incontinence of being listed on the UN list of terrorists. Apparently, he does not believe that persuading rank-and-files Taliban fighters to leave terrorist organizations in exchange for schooling and employment, or simply [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.triple3house.com/wp-content/uploads/2010/01/TalibanShootWomenInKabul.jpg"><img class="alignleft size-medium wp-image-1255" title="TalibanShootWomenInKabul" src="http://www.triple3house.com/wp-content/uploads/2010/01/TalibanShootWomenInKabul-300x207.jpg" alt="" width="300" height="207" /></a><a href="http://en.wikipedia.org/wiki/Kai_Eide" target="_blank">Kei Eide</a>, the UN special representative in Afghanistan, suggests that <a href="http://www.isaf.nato.int/" target="_blank">ISAF</a> and the UN give into grievances expressed by Taliban leaders regarding the incontinence of being listed on the <a href="http://www.un.org/sc/committees/1267/consolist.shtml" target="_blank">UN list of terrorists</a>. Apparently, he does not believe that persuading rank-and-files Taliban fighters to leave terrorist organizations in exchange for schooling and employment, or simply payment to stay idly home, is a sustainable course of action. (I agree turncoats in that region are just that – turncoats that can never be trusted.)</p>
<p>Ostensibly, the reason to delist Taliban leaders is to enable reconciliation talks with people of authority instead of supporting uneducated bottom of the barrel individuals that may or may not be worth trust.</p>
<p>As it ever occurred to anyone at the UN that this approach has not, does not, will not work – there are plenty of examples since 1947 where attempts to mediate with criminals and terrorists have solve or change nothing (i.e., Palestine, Congo, Yugoslavia – Bosnia, Croatia, Kosovo).</p>
<p>Is it that easy for the UN to forget that those listed are responsible for the mass murders, rapes, destruction of homes, near ethnic (tribe) cleansing, and unbelievable discrimination against women – all reasons for the last eight years of war (security assistance).</p>
<p>There is no political solution to Afghanistan, especially if presided over by politicians of any ilk. The solution is hard work towards relative prosperity for all through sustained relevant education and honest labour – rendering Taliban rhetoric meaningless. First near self-sufficiency sustained with the manufacture of tradable products onto the world markets.</p>
<p>A house is build from the bottom up, the same applies to a country… very hard work for all concerned, something real versus likely meaningless talks from UN bureaucrats and politicians. Case in point (and that is only the now list):</p>
<p><a title="War in Somalia (2009-)" href="http://en.wikipedia.org/wiki/War_in_Somalia_%282009-%29" target="_blank">War in Somalia</a></p>
<p><a title="Insurgency in the North Caucasus" href="http://en.wikipedia.org/wiki/Insurgency_in_the_North_Caucasus" target="_blank">Insurgency in the North Caucasus</a></p>
<p><a title="Sudanese nomadic conflicts" href="http://en.wikipedia.org/wiki/Sudanese_nomadic_conflicts" target="_blank">Sudanese nomadic conflicts</a></p>
<p><a title="2008 Cambodian-Thai stand-off" href="http://en.wikipedia.org/wiki/2008_Cambodian-Thai_stand-off" target="_blank">Cambodian-Thai standoff</a></p>
<p><a title="Civil war in Ingushetia" href="http://en.wikipedia.org/wiki/Civil_war_in_Ingushetia" target="_blank">Civil war in Ingushetia</a></p>
<p><a title="Civil war in Chad (2005–present)" href="http://en.wikipedia.org/wiki/Civil_war_in_Chad_%282005%E2%80%93present%29" target="_blank">Civil war in Chad</a></p>
<p><a title="South Thailand insurgency" href="http://en.wikipedia.org/wiki/South_Thailand_insurgency" target="_blank">South Thailand insurgency</a></p>
<p><a title="Conflict in the Niger Delta" href="http://en.wikipedia.org/wiki/Conflict_in_the_Niger_Delta" target="_blank">Conflict in the Niger Delta</a></p>
<p><a title="Sa'dah  insurgency" href="http://en.wikipedia.org/wiki/Sa%27dah_insurgency" target="_blank">Sa&#8217;dah insurgency</a></p>
<p><a title="War in North-West Pakistan" href="http://en.wikipedia.org/wiki/War_in_North-West_Pakistan" target="_blank">War in North-West Pakistan</a></p>
<p><a title="Balochistan conflict" href="http://en.wikipedia.org/wiki/Balochistan_conflict" target="_blank">Baluchistan conflict</a></p>
<p><a title="Iraq War" href="http://en.wikipedia.org/wiki/Iraq_War" target="_blank">Iraq War</a></p>
<p>Reference:</p>
<p><a href="http://www.nytimes.com/2010/01/25/world/asia/25taliban.html?scp=1&amp;sq=mission%20leader%20says%20move%20would%20be%20step%20toward%20opening%20negotiations&amp;st=cse" target="_blank">U.N. Seeks to Drop Some Taliban From Terror List</a>, by <a title="More Articles by Dexter Filkins" href="http://topics.nytimes.com/top/reference/timestopics/people/f/dexter_filkins/index.html?inline=nyt-per" target="_blank">Dexter Filkins</a>, published:  24 January 2010</p>
<p><a class="a2a_dd" href="http://www.addtoany.com/share_save?linkname=&amp;linkurl=https%3A%2F%2Fwww.triple3house.com%2F"><img src="http://static.addtoany.com/buttons/share_save_171_16.png" border="0" alt="Share/Bookmark" width="171" height="16" /></a><script type="text/javascript">// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
a2a_linkurl="https://www.triple3house.com/";a2a_show_title=1;
// ]]&gt;</script><script src="http://static.addtoany.com/menu/page.js" type="text/javascript"></script></p>
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
]]></content:encoded>
			<wfw:commentRss>http://www.triple3house.com/http:/www.triple3house.com/blog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Make your password &#8211; HackMe &#8211; why don&#8217;t you&#8230;</title>
		<link>http://www.triple3house.com/http:/www.triple3house.com/blog/</link>
		<comments>http://www.triple3house.com/http:/www.triple3house.com/blog/#comments</comments>
		<pubDate>Fri, 22 Jan 2010 02:12:07 +0000</pubDate>
		<dc:creator>rioux</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Biometrics]]></category>
		<category><![CDATA[password]]></category>
		<category><![CDATA[RockYou]]></category>

		<guid isPermaLink="false">http://www.triple3house.com/?p=1242</guid>
		<description><![CDATA[In a recent NY Times article Amichai Shulman, the chief technology officer at Imperva examined a list of 32 million accounts that an unknown hacker stole last month from RockYou – they found that the 32 million accounts shared about 5000 passwords.
I have been maintaining for almost 20 years that the safest user/password access combo, [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.triple3house.com/wp-content/uploads/2010/01/passwords1.jpg"><img class="alignleft size-full wp-image-1244" title="passwords" src="http://www.triple3house.com/wp-content/uploads/2010/01/passwords1.jpg" alt="" width="190" height="378" /></a>In a recent NY Times article <a href="http://www.imperva.com/company/management.html" target="_blank">Amichai Shulman</a>, the chief technology officer at <a href="http://www.imperva.com/index.html" target="_blank">Imperva</a> examined a list of 32 million accounts that an unknown hacker stole last month from <a href="http://www.rockyou.com/" target="_blank">RockYou</a> – they found that the 32 million accounts shared about 5000 passwords.</p>
<p>I have been maintaining for almost 20 years that the safest user/password access combo, and now the easiest now, is the ten passwords at your fingertips and the one user ID in your face – a simple choice now that almost all laptops have built-in fingerprint reader and camera, or can be added via the USB port.</p>
<p>If the sign-in provider is too lazy to add the few lines of code needed to take advantage of biometrics, let someone come up with a elegant face recognition to user ID and fingerprint to password conversion application that generates unique user ID and password based on an individual&#8217;s biometrics (contact me if you want to know how it works).</p>
<p>We have the technology people, let&#8217;s get with the program&#8230;</p>
<p>References:</p>
<p><a href="http://www.nytimes.com/2010/01/21/technology/21password.html" target="_blank">If Your Password Is 123456, Just Make It HackMe</a> by <a href="http://topics.nytimes.com/top/reference/timestopics/people/v/ashlee_vance/index.html?inline=nyt-per" target="_blank">Ashlee Vance</a>, Published: January 20, 2010</p>
<p><a href="http://singularityhub.com/2009/12/29/facial-recognition-door-lock-and-time-clock-for-less-than-500/" target="_blank">Facial Recognition Door Lock and Time Clock for Less than $500</a> by Aaron Saenz, Published: December 29, 2009</p>
<p><a href="http://www.techcrunch.com/2009/12/14/rockyou-hack-security-myspace-facebook-passwords/" target="_blank">RockYou Hack: From Bad To Worse</a> by <a href="http://www.techcrunch.com/author/nik/" target="_blank">Nik Cubrilovic</a> Published: December 14, 2009</p>
<p><a href="http://singularityhub.com/2009/05/06/biometrics-turns-your-ear-into-your-password/" target="_blank">Biometrics Turns Your Ear Into Your Password</a> by Drew Halley, Published: May 6, 2009</p>
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<p><a class="a2a_dd" href="http://www.addtoany.com/share_save?linkname=&amp;linkurl=https%3A%2F%2Fwww.triple3house.com%2F"><img src="http://static.addtoany.com/buttons/share_save_171_16.png" border="0" alt="Share/Bookmark" width="171" height="16" /></a><script type="text/javascript">// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
a2a_linkurl="https://www.triple3house.com/";a2a_show_title=1;
// ]]&gt;</script><script src="http://static.addtoany.com/menu/page.js" type="text/javascript"></script></p>
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
]]></content:encoded>
			<wfw:commentRss>http://www.triple3house.com/http:/www.triple3house.com/blog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>C4ISTAR</title>
		<link>http://www.triple3house.com/http:/www.triple3house.com/blog/</link>
		<comments>http://www.triple3house.com/http:/www.triple3house.com/blog/#comments</comments>
		<pubDate>Wed, 20 Jan 2010 02:07:52 +0000</pubDate>
		<dc:creator>rioux</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[C4ISTAR]]></category>
		<category><![CDATA[command]]></category>
		<category><![CDATA[communications]]></category>
		<category><![CDATA[computers]]></category>
		<category><![CDATA[control]]></category>
		<category><![CDATA[cyber warfare]]></category>
		<category><![CDATA[intelligence]]></category>
		<category><![CDATA[reconnaissance]]></category>
		<category><![CDATA[surveillance]]></category>

		<guid isPermaLink="false">http://www.triple3house.com/?p=1210</guid>
		<description><![CDATA[Computer security researchers found strong evidence of the digital fingerprints of the authors, suspected to by Chinese, in the software programs used in attacks against Google. It apparently attacked Google’s source code – akin to the modifications of Cisco Systems source code found in Cisco routers knockoffs that have appeared on the market.
However, I think [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.triple3house.com/wp-content/uploads/2010/01/iStock_000007420736XSmall.jpg"><img class="alignleft size-thumbnail wp-image-1211" title="iStock_000007420736XSmall" src="http://www.triple3house.com/wp-content/uploads/2010/01/iStock_000007420736XSmall-150x150.jpg" alt="" width="150" height="150" /></a>Computer security researchers found strong evidence of the digital fingerprints of the authors, suspected to by Chinese, in the software programs used in attacks against <a title="More information about Google Inc" href="http://www.google.co.jp/intl/en/about.html">Google</a>. It apparently attacked Google’s source code – akin to the modifications of Cisco Systems source code found in <a href="http://tech.slashdot.org/article.pl?sid=06/10/24/1819200">Cisco routers knockoffs</a> that have appeared on the market.</p>
<p>However, I think that experts are giving Chinese hackers too much credit by assuming, in general, that the attacker gain access externally, unaided, to Google’s jewels. I would make a small wager that it was (a) an insider’s job or (b) a combo job (most probable) where malfeasants have an insider drop keyholes (<a href="http://en.wikipedia.org/wiki/Trojan_horse_%28computing%29">Trojan horse</a>) among the <a title="Herman Hollerith" href="http://en.wikipedia.org/wiki/Herman_Hollerith">Hollerith</a> cards or modify some code (<a href="http://en.wikipedia.org/wiki/Backdoor_%28computing%29">backdoor</a>)…</p>
<p>The theft of intellectual property through modified software (application) and co-opted hardware (knockoff or compromised) is about to become a standard cost-of-doing business, not only in China, but worldwide, in just about every industry.</p>
<p>At first governments will mostly support it as an extension of their Intelligence Services, like China, which is committed to make great techno-economic strides to keep the masses busy – too many idle hands only create problems – e.g., look at the Middle East. Their Cyber-Intelligence units will pass on the gathered tidbits from their info-warfare (IW) endeavors to their industries.</p>
<p>(Several countries have well defined <a href="http://en.wikipedia.org/wiki/C4ISTAR">C<sup>4</sup>ISTAR</a> units capable of waging cyber-warfare – has seen recently during the cyber attacks on <a href="http://isc.sans.org/diary.html?storyid=5974">Estonia (2007)</a> during the <a title="Bronze Soldier of Tallinn" href="http://en.wikipedia.org/wiki/Bronze_Soldier_of_Tallinn">Bronze Soldier of Tallinn</a> incident and <a href="http://isc.sans.org/diary.html?storyid=4903">Georgia (2008)</a> during the<a href="http://en.wikipedia.org/wiki/2008_South_Ossetia_War"> South Ossetia war</a>. These cyber-warriors are the evolution of the <a href="http://en.wikipedia.org/wiki/Cold_war">Cold War</a>’s tactical and strategic <a href="http://en.wikipedia.org/wiki/Signals_intelligence_in_modern_history">SigInt</a> operators gifted with patience and blessed with luck that intercepted, decoded, and analyzed signals and/or data to gain some sort of advantage on their targets.)</p>
<p>Eventually, since all things digital reign supreme in the commercial world, organizations will draft individuals to penetrate the competition as workers to drop <a href="http://en.wikipedia.org/wiki/Malware">malware</a> in the cogs to gleam a perceived advantage. Malware to spy and reveal business secrets; or, to erode slowly an opponent’s business model; or, simply siphoned off intellectual property for later nefarious use.</p>
<p>Cybersecurity technologists capable of certifying and fingerprint applications as secure (given certain environments) and able to recognize any modifications, especially unauthorized one, will be worth their weight in platinum. They will have to be digital detectives of the caliber of Sir <a title="Arthur Conan Doyle" href="http://en.wikipedia.org/wiki/Arthur_Conan_Doyle">Arthur Conan Doyle</a>’s <a href="http://en.wikipedia.org/wiki/Sherlock_holmes">Sherlock Holmes</a>, the imaginary sleuth famous for his clever use of incisive observation, deductive reasoning, and forensic skills to defeat malfeasants.</p>
<p>Let the <em>bon temps</em> role!</p>
<p>References:</p>
<p><a href="http://www.nytimes.com/2010/01/20/technology/20code.html" target="_blank">Fearing Hackers Who Leave No Trace</a>, by <a title="More Articles by John Markoff" href="http://topics.nytimes.com/top/reference/timestopics/people/m/john_markoff/index.html?inline=nyt-per">John Markoff</a> and <a title="More Articles by Ashlee Vance" href="http://topics.nytimes.com/top/reference/timestopics/people/v/ashlee_vance/index.html?inline=nyt-per">Ashlee Vance</a>, published: January 19, 2010</p>
<p><a href="http://www.nytimes.com/2010/01/20/technology/20cyber.html">Evidence Found for Chinese Attack on Google</a>, by <a title="More Articles by John Markoff" href="http://topics.nytimes.com/top/reference/timestopics/people/m/john_markoff/index.html?inline=nyt-per">John Markoff</a>, published: January 19, 2010</p>
<p><a href="http://www.thedarkvisitor.com/2009/08/china-cyber-warfare-weapon-of-mass-destruction/" target="_blank">China: Cyber warfare, weapon of mass destruction?</a> Published by <a href="http://www.thedarkvisitor.com/author/heike/">Heike</a> August 8, 2008</p>
<p><a class="a2a_dd" href="http://www.addtoany.com/share_save?linkname=&amp;linkurl=https%3A%2F%2Fwww.triple3house.com%2F"><img src="http://static.addtoany.com/buttons/share_save_171_16.png" border="0" alt="Share/Bookmark" width="171" height="16" /></a><script type="text/javascript">// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
// < ![CDATA[
a2a_linkurl="https://www.triple3house.com/";a2a_show_title=1;
// ]]&gt;</script><script src="http://static.addtoany.com/menu/page.js" type="text/javascript"></script></p>
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
]]></content:encoded>
			<wfw:commentRss>http://www.triple3house.com/http:/www.triple3house.com/blog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Industrial Espionage</title>
		<link>http://www.triple3house.com/http:/www.triple3house.com/blog/</link>
		<comments>http://www.triple3house.com/http:/www.triple3house.com/blog/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 01:30:08 +0000</pubDate>
		<dc:creator>rioux</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Biometrics]]></category>
		<category><![CDATA[cybercrimes]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Industrial Espionage]]></category>

		<guid isPermaLink="false">http://www.triple3house.com/?p=1190</guid>
		<description><![CDATA[
The recent hacking of Google left corporate networks, worldwide, questioning their cyber security, justifiably so. How malware find their way into networks is not as important as taking measures to make everyone aware of the possibility and implementing strict countermeasures automatically, back by strict penalties for not following security rules that reflect realities.
One improvement is [...]]]></description>
			<content:encoded><![CDATA[<p><strong><a href="http://www.triple3house.com/wp-content/uploads/2010/01/iStock_000003915879XSmall.jpg"><img class="alignleft size-thumbnail wp-image-1191" title="Fingerprint reader" src="http://www.triple3house.com/wp-content/uploads/2010/01/iStock_000003915879XSmall-150x150.jpg" alt="" width="150" height="150" /></a></strong></p>
<p>The recent hacking of Google left corporate networks, worldwide, questioning their cyber security, justifiably so. How malware find their way into networks is not as important as taking measures to make everyone aware of the possibility and implementing strict countermeasures automatically, back by strict penalties for not following security rules that reflect realities.</p>
<p>One improvement is to abandon the user/password methods and replace it with <a href="http://en.wikipedia.org/wiki/Biometrics" target="_blank">biometrics</a>. Regardless of what the industry says the deployment of the technology is not difficult at all, just slightly troublesome for people. Although not the perfect deterrent, biometrics can reduce greatly email accounts highjacking, corporate networks penetrations, and even credit cards cloning.</p>
<p>Simple enrolment procedures of employees’ several biometrics measurement can take less than one (1) minute. A computer connected to a USB device such as a fingerprint reader or a camera biometrics can harvest and verify one’s ID faster than typing in a user/password combo. (Currently, 99% of all computers in used worldwide have at least one USB port.)</p>
<p>As for credit/debit cards, the chip on most of them can store enough information to enable solid biometrics ID at most point-of-sale interfaces.</p>
<p>However, no system connected to the Internet (cyberspace) will ever be 100% secured against a determine malfeasant! Additional organization-wide measures such as establishing sustainable Information Security Management Systems and reliable corporate governance are needed. Further, these measures must be backed by frequent independent audits conducted by trusted third party using such standard as ISOs 20000 (Information Technology Infrastructure Library), 24762 (Disaster Recovery), 27001 (Information Security Management System), 28000 (Supply Chain Management Security), 38500 (Governance of Enterprise IT), and BS 25999 (Business Continuity Management or ISO 22399).</p>
<p>One problem solved, now to the next generation of cybercrimes – <a href="http://www.cybercrime-institute.com/" target="_blank">the one committed by robots and AIs in the ever-growing virtual world</a>… stay tuned!</p>
<p>References:</p>
<p><strong> </strong><a href="http://www.nytimes.com/2010/01/14/technology/14google.html" target="_blank">In Rebuke of China, Focus Falls on Cybersecurity</a> by <a title="More Articles by Miguel Helft" href="http://topics.nytimes.com/top/reference/timestopics/people/h/miguel_helft/index.html?inline=nyt-per" target="_blank">Miguel Helft</a> and <a title="More Articles by John Markoff" href="http://topics.nytimes.com/top/reference/timestopics/people/m/john_markoff/index.html?inline=nyt-per" target="_blank">John Markoff</a> Published: January 13, 2010</p>
<p><a href="http://www.nytimes.com/2010/01/18/technology/internet/18defend.html" target="_blank">Companies Fight Endless War Against Computer Attacks</a><strong> </strong>by <a title="More Articles by Steve Lohr" href="http://topics.nytimes.com/top/reference/timestopics/people/l/steve_lohr/index.html?inline=nyt-per" target="_blank">Steve Lohr</a> Published: January 17, 2010</p>
<p><a href="http://www.nytimes.com/2010/01/19/technology/companies/19google.html?partner=rss&amp;emc=rss" target="_blank">Hackers Said to Breach Gmail Accounts in China</a> by <a title="More Articles by Edward Wong" href="http://topics.nytimes.com/top/reference/timestopics/people/w/edward_wong/index.html?inline=nyt-per" target="_blank">Edward Wong</a> Published: January 18, 2010</p>
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<p><a class="a2a_dd" href="http://www.addtoany.com/share_save?linkname=&amp;linkurl=https%3A%2F%2Fwww.triple3house.com%2F"><img src="http://static.addtoany.com/buttons/share_save_171_16.png" border="0" alt="Share/Bookmark" width="171" height="16" /></a><script type="text/javascript">// < ![CDATA[
a2a_linkurl="https://www.triple3house.com/";a2a_show_title=1;
// ]]&gt;</script><script src="http://static.addtoany.com/menu/page.js" type="text/javascript"></script></p>
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
]]></content:encoded>
			<wfw:commentRss>http://www.triple3house.com/http:/www.triple3house.com/blog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Slavery!</title>
		<link>http://www.triple3house.com/http:/www.triple3house.com/blog/</link>
		<comments>http://www.triple3house.com/http:/www.triple3house.com/blog/#comments</comments>
		<pubDate>Thu, 14 Jan 2010 02:05:57 +0000</pubDate>
		<dc:creator>rioux</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Benjamin Sknner]]></category>
		<category><![CDATA[slavery]]></category>

		<guid isPermaLink="false">http://www.triple3house.com/?p=1170</guid>
		<description><![CDATA[Like warring on each other for no other apparent reason than political gain was not bad enough, slavery goes on without abating. According to Time Magazine&#8217;s article “South Africa&#8217;s New Slave Trade and the Campaign to Stop It” by By E. Benjamin Skinner (Monday, Jan. 18, 2010) there are more slaves today worldwide than at [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.triple3house.com/wp-content/uploads/2010/01/skinner.jacket.jpg"><img class="alignleft size-full wp-image-1169" title="skinner.jacket" src="http://www.triple3house.com/wp-content/uploads/2010/01/skinner.jacket.jpg" alt="" width="275" height="416" /></a>Like warring on each other for no other apparent reason than political gain was not bad enough, slavery goes on without abating. According to Time Magazine&#8217;s article <a href="http://www.time.com/time/magazine/article/0,9171,1952335,00.html?xid=rss-topstories" target="_blank"><em>“</em><em>South Africa&#8217;s New Slave Trade and the Campaign to Stop It”</em></a> by By E. Benjamin Skinner (Monday, Jan. 18, 2010) there are more slaves today <span style="text-decoration: underline;"><em><strong>worldwide</strong></em></span> than at any point in human history despite dozen international conventions banning slavery.</p>
<p>In addition, please purchase and read<em> “A Crime So Monstrous: Face-to-Face with Modern-Day Slavery”</em> by E. Benjamin Skinner – a shockingly revealing and powerful book that goes far to point out our governments ineffectual rhetorics and the UNHCR impotence.</p>
<p>It is available in bookstore, as well as:</p>
<ul>
<li><a href="http://www.amazon.com/gp/redirect.html?ie=UTF8&amp;location=http%3A%2F%2Fwww.amazon.com%2FCrime-Monstrous-Face-Face-Modern-Day%2Fdp%2F0743290070%3Fie%3DUTF8%26s%3Dbooks%26qid%3D1196786448%26sr%3D8-1&amp;tag=acrsomo-20&amp;linkCode=ur2&amp;camp=1789&amp;creative=9325" target="_blank">Amazon</a></li>
<li><a href="http://search.barnesandnoble.com/booksearch/isbnInquiry.asp?z=y&amp;EAN=9780743290074&amp;itm=1" target="_blank">Barnes 	&amp; Noble</a></li>
<li><a href="http://www.booksamillion.com/ncom/books?id=3967863845611&amp;isbn=0743290070" target="_blank">Books-A-Million</a></li>
<li><a href="http://www.borders.com/online/store/TitleDetail?sku=0743290070" target="_blank">Borders</a></li>
<li><a href="http://www.overstock.com/Books-Movies-Music-Games/A-Crime-So-Monstrous/2580383/product.html" target="_blank">Overstock</a></li>
<li><a href="http://www.powells.com/biblio/62-9780743290074-0" target="_blank">Powell&#8217;s</a></li>
<li><a href="http://www.amazon.com/gp/redirect.html?ie=UTF8&amp;location=http%3A%2F%2Fwww.amazon.com%2FCrime-Monstrous-Face-Face-Modern-Day%2Fdp%2F0743290070%3Fie%3DUTF8%26s%3Dbooks%26qid%3D1196786849%26sr%3D1-1%26%2334%3B%20target%3D%26%2334%3B%5Fblank%26%2334%3B&amp;tag=acrsomo-20&amp;linkCode=ur2&amp;camp=1789&amp;creative=9325">Waldenbooks</a></li>
</ul>
<p>Note: <em>25% of U.S. royalties go to <a href="http://www.freetheslaves.net/" target="_blank">Free The Slaves</a>, a group that uses holistic, locally-based strategies through global partners to fight slavery, rehabilitate slaves and eradicate bondage. 25% of U.K. royalties go to the group&#8217;s British sister, <a href="http://www.antislavery.org/" target="_blank">Anti-Slavery International</a>, the world&#8217;s oldest human rights organization.</em></p>
<p>Benjamin Skinner discusses the challenges of writing about the slave trade on NPR&#8217;s <em>Day to Day</em> &#8211; <a href="http://j.mp/2Uis0" target="_blank">http://j.mp/2Uis0</a> &#8211; unbelievable, and yet not surprising.</p>
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<p><!--Session data--></p>
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<p><a class="a2a_dd" href="http://www.addtoany.com/share_save?linkname=&amp;linkurl=https%3A%2F%2Fwww.triple3house.com%2F"><img src="http://static.addtoany.com/buttons/share_save_171_16.png" border="0" alt="Share/Bookmark" width="171" height="16" /></a><script type="text/javascript">// < ![CDATA[
// < ![CDATA[
a2a_linkurl="https://www.triple3house.com/";a2a_show_title=1;
// ]]&gt;</script><script src="http://static.addtoany.com/menu/page.js" type="text/javascript"></script></p>
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
]]></content:encoded>
			<wfw:commentRss>http://www.triple3house.com/http:/www.triple3house.com/blog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://www.triple3house.com/wp-content/uploads/2010/01/20080311_day_08.mp3" length="4297375" type="audio/mpeg" />
		</item>
		<item>
		<title>Study finds that UNICEF program failed to help kids</title>
		<link>http://www.triple3house.com/http:/www.triple3house.com/blog/</link>
		<comments>http://www.triple3house.com/http:/www.triple3house.com/blog/#comments</comments>
		<pubDate>Wed, 13 Jan 2010 03:23:46 +0000</pubDate>
		<dc:creator>rioux</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Lancet]]></category>
		<category><![CDATA[UNICEF]]></category>

		<guid isPermaLink="false">http://www.triple3house.com/?p=1164</guid>
		<description><![CDATA[A UNICEF program that spend US$27 million to decrease child deaths from disease in West Africa has failed, according to a new study that found a higher survival rate in some regions that were not included in the program.
The UN childcare&#8217;s agency pursued strategies like vaccinating children, giving them vitamin A pills, and distributing mosquito [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.triple3house.com/wp-content/uploads/2010/01/African-Children.jpg"><img class="alignleft size-thumbnail wp-image-1165" title="African Orphanage" src="http://www.triple3house.com/wp-content/uploads/2010/01/African-Children-150x150.jpg" alt="" width="150" height="150" /></a>A UNICEF program that spend US$27 million to decrease child deaths from disease in West Africa has failed, according to a new study that found a higher survival rate in some regions that were not included in the program.</p>
<p>The UN childcare&#8217;s agency pursued strategies like vaccinating children, giving them vitamin A pills, and distributing mosquito nets to protect them against malaria form 2001 to 2005 in parts of 11 countries. The aim was to reduce the death rate by at least 25 % by the end of 2006.</p>
<p>An analysis of the program in Benin, Ghana, and Mali found children in areas where it was not in effect had a better chance of surviving past age 5 than children who were covered by it. The study was published online Tuesday in the British medical journal Lancet – see here <a href="http://j.mp/5PLrLp" target="_blank">http://j.mp/5PLrLp</a>.</p>
<p>Why am I not surprised&#8230;</p>
<p><a class="a2a_dd" href="http://www.addtoany.com/share_save?linkname=&amp;linkurl=https%3A%2F%2Fwww.triple3house.com%2F"><img src="http://static.addtoany.com/buttons/share_save_171_16.png" border="0" alt="Share/Bookmark" width="171" height="16" /></a><script type="text/javascript">// < ![CDATA[
a2a_linkurl="https://www.triple3house.com/";a2a_show_title=1;
// ]]&gt;</script><script src="http://static.addtoany.com/menu/page.js" type="text/javascript"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://www.triple3house.com/http:/www.triple3house.com/blog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Move Your Money &#8211; A great idea</title>
		<link>http://www.triple3house.com/http:/www.triple3house.com/blog/</link>
		<comments>http://www.triple3house.com/http:/www.triple3house.com/blog/#comments</comments>
		<pubDate>Sat, 02 Jan 2010 03:35:45 +0000</pubDate>
		<dc:creator>rioux</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Huffington Post]]></category>
		<category><![CDATA[It's A Wonderful Life]]></category>
		<category><![CDATA[Move Your Money]]></category>

		<guid isPermaLink="false">http://www.triple3house.com/?p=1156</guid>
		<description><![CDATA[On the Huffington Post website, founder Arianna Huffington introduces what she calls the &#8220;move your money&#8221; campaign. The idea is to get all Americans to close their accounts at big banks and transplant their personal finances to smaller banks. The budding cause has its own web site, moveyourmoney.info, including a link where you can plug [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-thumbnail wp-image-1158" title="It's A Wonderful Life" src="http://www.triple3house.com/wp-content/uploads/2010/01/MV5BMTYwMjUwNTMzNl5BMl5BanBnXkFtZTYwOTg0OTY5._V1._SX285_SY400_-150x150.jpg" alt="It's A Wonderful Life" width="150" height="150" />On the <a href="http://www.huffingtonpost.com/" target="_blank">Huffington Post</a> website, founder Arianna Huffington <a href="http://www.huffingtonpost.com/arianna-huffington/move-your-money-a-new-yea_b_406022.html">introduces</a> what she calls the &#8220;move your money&#8221; campaign. The idea is to get all Americans to close their accounts at big banks and transplant their personal finances to smaller banks. The budding cause has its own web site, <a href="http://www.moveyourmoney.info/">moveyourmoney.info</a>, including a link where you can plug in your zip code and find a list of smaller banks.</p>
<p>Huffington singles out the Big Four banks (that would be Bank of America, Citi, JP Morgan Chase and Wells Fargo) for particular ire, pointing out that they&#8217;ve curbed business lending even since receiving TARP money. She urges Americans to bank their money at community banks instead of these TARP-receiving behemoths.</p>
<p>I hope this campaign makes enough of an impact for the big banks to notice. At the end of the day, even if this campaign doesn&#8217;t succeed in making the Big Four don&#8217;t change their ways, if more Americans wind up at banks that make them feel like valued customers, that&#8217;s a good thing. In addition, it would serve has a revenge for the rest of us in the world that cannot participate, but paid just the same – here is a change of Americans to do something for the rest of the world that does not involve propping up a war machine in support of decrepit unappreciative corrupted governments.</p>
<p>If you can please make that resolution for 2010 – <a href="http://moveyourmoney.info/">Move Your Money</a>!</p>
<p>PS. I love the reference to the 1946 classic Frank Capra film <em><a href="http://www.imdb.com/title/tt0038650/">It&#8217;s a Wonderful Life</a> </em>–<em> just brilliant.</em></p>
<p><a class="a2a_dd" href="http://www.addtoany.com/share_save?linkname=&amp;linkurl=https%3A%2F%2Fwww.triple3house.com%2F"><img src="http://static.addtoany.com/buttons/share_save_171_16.png" width="171" height="16" border="0" alt="Share/Bookmark"/></a><script type="text/javascript">a2a_linkurl="https://www.triple3house.com/";a2a_show_title=1;</script><script type="text/javascript" src="http://static.addtoany.com/menu/page.js"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://www.triple3house.com/http:/www.triple3house.com/blog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New OWASP Top 10, with new approach</title>
		<link>http://www.triple3house.com/http:/www.triple3house.com/blog/</link>
		<comments>http://www.triple3house.com/http:/www.triple3house.com/blog/#comments</comments>
		<pubDate>Mon, 14 Dec 2009 01:26:00 +0000</pubDate>
		<dc:creator>rioux</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[Top 10]]></category>

		<guid isPermaLink="false">http://www.triple3house.com/?p=1140</guid>
		<description><![CDATA[The Open Web Application Security Project (OWASP) has released a new Top 10 most critical Web application security risk. Top Ten 2010 version provides a powerful awareness document to mitigate Web application security risk.
Further, this time around the Top 10 are presented from a risk-base approach, thus playing to a wider audience.
You can download the [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-1141" title="owasp_logo" src="http://www.triple3house.com/wp-content/uploads/2009/12/owasp_logo.jpg" alt="owasp_logo" width="115" height="115" />The Open Web Application Security Project (OWASP) has released a new Top 10 most critical Web application security risk. Top Ten 2010 version provides a powerful awareness document to mitigate Web application security risk.</p>
<p>Further, this time around the Top 10 are presented from a risk-base approach, thus playing to a wider audience.</p>
<p>You can download the Release Candidate version here &#8212; <a href="http://www.owasp.org/images/0/0f/OWASP_T10_-_2010_rc1.pdf" target="_blank">http://www.owasp.org/images/0/0f/OWASP_T10_-_2010_rc1.pdf</a></p>
<p>Really worth the time.</p>
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<p><a class="a2a_dd" href="http://www.addtoany.com/share_save?linkname=&amp;linkurl=https%3A%2F%2Fwww.triple3house.com%2F"><img src="http://static.addtoany.com/buttons/share_save_171_16.png" width="171" height="16" border="0" alt="Share/Bookmark"/></a><script type="text/javascript">a2a_linkurl="https://www.triple3house.com/";a2a_show_title=1;</script><script type="text/javascript" src="http://static.addtoany.com/menu/page.js"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://www.triple3house.com/http:/www.triple3house.com/blog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Vulnerability in SSL &#8211; Resolved (?)</title>
		<link>http://www.triple3house.com/http:/www.triple3house.com/blog/</link>
		<comments>http://www.triple3house.com/http:/www.triple3house.com/blog/#comments</comments>
		<pubDate>Fri, 27 Nov 2009 07:00:40 +0000</pubDate>
		<dc:creator>rioux</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Security Vulnerability]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[TLS]]></category>

		<guid isPermaLink="false">http://www.triple3house.com/?p=1135</guid>
		<description><![CDATA[Security Now! Steve Gibson and Leo Laporte this week plow into a recently discovered serious vulnerability in the fundamental SSL protocol that provides virtually all of the Internet&#8217;s communications security: SSL &#8211; the Secure Sockets Layer. Steve explains exactly how an attacker can inject his or her own data into a new SSL connection and [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-thumbnail wp-image-1138" title="stripped bicycle" src="http://www.triple3house.com/wp-content/uploads/2009/11/iStock_000002700094XSmall-150x150.jpg" alt="stripped bicycle" width="150" height="150" />Security Now! Steve Gibson and Leo Laporte this week plow into a recently discovered serious vulnerability in the fundamental SSL protocol that provides virtually all of the Internet&#8217;s communications security: SSL &#8211; the Secure Sockets Layer. Steve explains exactly how an attacker can inject his or her own data into a new SSL connection and have that data authenticated under an innocent client&#8217;s credentials.</p>
<p>This is an excellent podcast that should be listen too by all involved with SSL and/or TLS.</p>
<p>High quality  (64 kbps) mp3 audio file URL: <a href="http://media.GRC.com/sn/SN-223.mp3" target="_blank">http://media.GRC.com/sn/SN-223.mp3</a></p>
<p>Quarter size (16 kbps) mp3 audio file URL: <a href="http://media.GRC.com/sn/sn-223-lq.mp3" target="_blank">http://media.GRC.com/sn/sn-223-lq.mp3</a></p>
<p>The transcript can be found here: <a href="http://www.grc.com/sn/sn-223.htm" target="_blank">http://www.grc.com/sn/sn-223.htm</a></p>
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<p><a class="a2a_dd" href="http://www.addtoany.com/share_save?linkname=&amp;linkurl=https%3A%2F%2Fwww.triple3house.com%2F"><img src="http://static.addtoany.com/buttons/share_save_171_16.png" width="171" height="16" border="0" alt="Share/Bookmark"/></a><script type="text/javascript">a2a_linkurl="https://www.triple3house.com/";a2a_show_title=1;</script><script type="text/javascript" src="http://static.addtoany.com/menu/page.js"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://www.triple3house.com/http:/www.triple3house.com/blog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://media.GRC.com/sn/SN-223.mp3" length="38308032" type="audio/mpeg" />
<enclosure url="http://media.GRC.com/sn/sn-223-lq.mp3" length="9577152" type="audio/mpeg" />
		</item>
		<item>
		<title>Vulnerability in the SSL protocol</title>
		<link>http://www.triple3house.com/http:/www.triple3house.com/blog/</link>
		<comments>http://www.triple3house.com/http:/www.triple3house.com/blog/#comments</comments>
		<pubDate>Tue, 17 Nov 2009 14:01:53 +0000</pubDate>
		<dc:creator>rioux</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[SSL vulnerability]]></category>
		<category><![CDATA[TLS vulnerability]]></category>

		<guid isPermaLink="false">http://www.triple3house.com/?p=1115</guid>
		<description><![CDATA[SSL and TLS protocols renegotiation vulnerability
Vulnerability exists in SSL and TLS protocols that may allow attackers to execute an arbitrary HTTP transaction. This issue affects SSL version 3.0 and newer and TLS version 1.2, and older versions.
The Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols are commonly used to provide authentication, encryption, integrity, [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.informationweek.com/news/security/vulnerabilities/showArticle.jhtml?articleID=221600478" target="_blank"><img class="alignleft size-thumbnail wp-image-1116" title="iStock_000009831886XSmall" src="http://www.triple3house.com/wp-content/uploads/2009/11/iStock_000009831886XSmall-150x150.jpg" alt="iStock_000009831886XSmall" width="150" height="150" />SSL and TLS protocols renegotiation vulnerability</a></p>
<p>Vulnerability exists in SSL and TLS protocols that may allow attackers to execute an arbitrary HTTP transaction. This issue affects SSL version 3.0 and newer and TLS version 1.2, and older versions.</p>
<p>The Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols are commonly used to provide authentication, encryption, integrity, and non-repudiation services to network applications such as HTTP, IMAP, POP3, and LDAP. Vulnerability in the way SSL and TLS protocols allow renegotiation requests may allow an attacker to inject plaintext into an application protocol stream. This could result in a situation where the attacker may be able to issue commands to the server that appear to be coming from a legitimate source.</p>
<p>According to the <a href="http://www.phonefactor.com/" target="_blank">PhoneFactor</a>&#8217;s Marsh Ray and Steve Dispensa, and Nasko Oskov of <a href="http://www.microsoft.com/" target="_blank">Microsoft</a><em> </em><em> </em>:</p>
<input id="gwProxy" type="hidden" />
<p><!--Session data--></p>
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<p style="margin-bottom: 0in;">
<input id="gwProxy" type="hidden" /><!--Session data-->SSL and TLS renegotiation are vulnerable to an attack in which the attacker forms a TLS connection with the target server, injects content of his choice, and then splices in a new TLS connection from a client.  The server treats the client&#8217;s initial TLS handshake as a renegotiation and thus believes that the initial data transmitted by the attacker is from the same entity as the subsequent client data.</p>
<p style="margin-bottom: 0in;">TLS[RFC5246]allows either the client or the server to initiate renegotiation – a new handshake which establishes new cryptographic parameters. Unfortunately, although the new handshake is carried out over the protected channel established by the original handshake, there is no cryptographic connection between the two. This creates the opportunity for an attack in which the attacker who can intercept a client&#8217;s transport layer connection can inject traffic of his own as a prefix to the client&#8217;s interaction with the server.</p>
<p style="margin-bottom: 0in;">To start the attack, the attacker forms a TLS connection to the server (perhaps in response to an initial intercepted connection from the client).  He then sends any traffic of his choice to the server. This may involve multiple requests and responses at the application layer, or may simply be a partial application layer request intended to prefix the client&#8217;s data.  He then allows the client&#8217;s TLS handshake to proceed with the server.  The handshake is in the clear to the attacker but encrypted over the attacker&#8217;s channel to the server.</p>
<p style="margin-bottom: 0in;">Once the handshake has completed, the client communicates with the server over the new channel.  The attacker cannot read this traffic, but the server believes that the initial traffic to and from the attacker is the same as that to and from the client.</p>
<p style="margin-bottom: 0in;">If certificate-based client authentication is used, the server will believe that the initial traffic corresponds to the authenticated client identity. Even without certificate-based authentication, a variety of attacks may be possible in which the attacker convinces the server to accept data from it as data from the client. For instance, if HTTPS [RFC2818] is in use with HTTP cookies [REF], the attacker may be able to generate a request of his choice validated by the client&#8217;s cookie.</p>
<p style="margin-bottom: 0in;"><strong>This attack can be prevented by cryptographically binding renegotiation handshakes to the enclosing TLS channel, thus allowing the server to differentiate renegotiation from initial negotiation, as well as preventing renegotiations from being spliced in between connections.  An attempt by an attacker to inject himself as described above will result in a mismatch of the extension and can thus be detected.</strong></p>
<input id="gwProxy" type="hidden" />
<p>For a list of systems affected systems visit <a href="http://www.kb.cert.org/vuls/" target="_blank">CERT-US</a></p>
<p>References</p>
<p><a href="http://extendedsubset.com/?p=8" target="_blank">http://extendedsubset.com/?p=8</a><br />
<a href="http://www.links.org/?p=780" target="_blank">http://www.links.org/?p=780</a><br />
<a href="http://www.links.org/?p=786" target="_blank">http://www.links.org/?p=786</a><br />
<a href="http://www.links.org/?p=789" target="_blank">http://www.links.org/?p=789</a><br />
<a href="http://blogs.iss.net/archive/sslmitmiscsrf.html" target="_blank">http://blogs.iss.net/archive/sslmitmiscsrf.html</a><br />
<a href="http://www.ietf.org/mail-archive/web/tls/current/msg03948.html" target="_blank">http://www.ietf.org/mail-archive/web/tls/current/msg03948.html</a><br />
<a href="https://bugzilla.redhat.com/show_bug.cgi?id=533125" target="_blank">https://bugzilla.redhat.com/show_bug.cgi?id=533125</a><br />
<a href="http://lists.gnu.org/archive/html/gnutls-devel/2009-11/msg00014.html" target="_blank">http://lists.gnu.org/archive/html/gnutls-devel/2009-11/msg00014.html</a><br />
<a href="http://cvs.openssl.org/chngview?cn=18790" target="_blank">http://cvs.openssl.org/chngview?cn=18790</a><br />
<a href="http://www.links.org/files/no-renegotiation-2.patch" target="_blank">http://www.links.org/files/no-renegotiation-2.patch</a><br />
<a href="http://blog.zoller.lu/2009/11/new-sslv3-tls-vulnerability-mitm.html" target="_blank">http://blog.zoller.lu/2009/11/new-sslv3-tls-vulnerability-mitm.html</a><br />
<a href="https://svn.resiprocate.org/rep/ietf-drafts/ekr/draft-rescorla-tls-renegotiate.txt" target="_blank">https://svn.resiprocate.org/rep/ietf-drafts/ekr/draft-rescorla-tls-renegotiate.txt</a></p>
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<input id="gwProxy" type="hidden" />
<input id="jsProxy" onclick="jsCall();" type="hidden" />
<p><a class="a2a_dd" href="http://www.addtoany.com/share_save?linkname=&amp;linkurl=https%3A%2F%2Fwww.triple3house.com%2F"><img src="http://static.addtoany.com/buttons/share_save_171_16.png" width="171" height="16" border="0" alt="Share/Bookmark"/></a><script type="text/javascript">a2a_linkurl="https://www.triple3house.com/";a2a_show_title=1;</script><script type="text/javascript" src="http://static.addtoany.com/menu/page.js"></script></p>
]]></content:encoded>
			<wfw:commentRss>http://www.triple3house.com/http:/www.triple3house.com/blog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
