<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>My Security Planet &#187; Schneier on Security &#187; July 2009</title>
	<link>http://rgaucher.info/planet/</link>
	<description>My Security Planet &#187; Schneier on Security &#187; July 2009</description>
	<generator>Gregarius 0.5.4</generator>
	<language>en</language>
	<item>
		<title>Schneier on Security: Friday Squid Blogging: Spicy Squid on a Stick</title>
		<link>http://www.schneier.com/blog/archives/2009/07/friday_squid_bl_189.html</link>
		<pubDate>Fri, 31 Jul 2009 16:16:51 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/friday_squid_bl_189.html</guid>
		<content:encoded><![CDATA[	New!... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=EHyNkoj4iFY:1guG89WAGE4:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Snake Oil Salesman</title>
		<link>http://www.schneier.com/blog/archives/2009/07/snake_oil_sales.html</link>
		<pubDate>Fri, 31 Jul 2009 13:11:17 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/snake_oil_sales.html</guid>
		<content:encoded><![CDATA[	In cryptography, we've long used the term "snake oil" to refer to crypto systems with good marketing hype and little actual security. It's the phrase I generalized into "security theater." Well, it turns out that there really is a snake oil salesman.... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=elszxnizYpQ:Y42q6D50ddk:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Eve Ensler on Security</title>
		<link>http://www.schneier.com/blog/archives/2009/07/eve_ensler_on_s.html</link>
		<pubDate>Fri, 31 Jul 2009 11:29:29 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/eve_ensler_on_s.html</guid>
		<content:encoded><![CDATA[	Interesting TED talk by Eve Ensler on security. She doesn't use any of the terms, but in the beginning she's echoing a lot of the current thinking about evolutionary psychology and how it relates to security.... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=8BI7rXfdjpo:y9uu_yL5-YA:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Nuclear Self-Terrorization</title>
		<link>http://www.schneier.com/blog/archives/2009/07/nuclear_self-te.html</link>
		<pubDate>Fri, 31 Jul 2009 06:00:51 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/nuclear_self-te.html</guid>
		<content:encoded><![CDATA[	More fearmongering. The headline is "Terrorists could use internet to launch nuclear attack: report." The subhead: "The risk of cyber-terrorism escalating to a nuclear strike is growing daily, according to a study." In the article: The claims come in a study commissioned by the International Commission on Nuclear Non-proliferation and Disarmament (ICNND), which suggests that under the right circumstances, terrorists... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=dMMyx6LztA8:OgGP5EPQa_4:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Another New AES Attack</title>
		<link>http://www.schneier.com/blog/archives/2009/07/another_new_aes.html</link>
		<pubDate>Thu, 30 Jul 2009 09:26:08 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/another_new_aes.html</guid>
		<content:encoded><![CDATA[	A new and very impressive attack against AES has just been announced. Over the past couple of months, there have been two (the second blogged about here) new cryptanalysis papers on AES. The attacks presented in the paper are not practical -- they're far too complex, they're related-key attacks, and they're against larger-key versions and not the 128-bit version that... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=nMKrhrUfFOc:SESbjPbpqLY:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Risks of Cloud Computing</title>
		<link>http://www.schneier.com/blog/archives/2009/07/risks_of_cloud.html</link>
		<pubDate>Thu, 30 Jul 2009 07:06:42 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/risks_of_cloud.html</guid>
		<content:encoded><![CDATA[	Excellent essay by Jonathan Zittrain on the risks of cloud computing: The cloud, however, comes with real dangers. Some are in plain view. If you entrust your data to others, they can let you down or outright betray you. For example, if your favorite music is rented or authorized from an online subscription service rather than freely in your custody... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=z6R4TeXjPJ0:g5JbnZJanDw:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: iPhone Encryption Useless</title>
		<link>http://www.schneier.com/blog/archives/2009/07/iphone_encrypti.html</link>
		<pubDate>Wed, 29 Jul 2009 06:16:12 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/iphone_encrypti.html</guid>
		<content:encoded><![CDATA[	Interesting, although I want some more technical details. ...the new iPhone 3GS' encryption feature is "broken" when it comes to protecting sensitive information such as credit card numbers and social-security digits, Zdziarski said. Zdziarski said it's just as easy to access a user's private information on an iPhone 3GS as it was on the previous generation iPhone 3G or first... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=ctLas8_oyO8:qV9gHwXx4qg:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: New Real Estate Scam</title>
		<link>http://www.schneier.com/blog/archives/2009/07/new_real_estate.html</link>
		<pubDate>Wed, 29 Jul 2009 05:31:44 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/new_real_estate.html</guid>
		<content:encoded><![CDATA[	Clever: Nigerian scammers find homes listed for sale on these public search sites, copy the pictures and listings verbatim, and then post the information onto Craigslist under available housing rentals, without the consent or knowledge of Craigslist, who has been notified. After the posting is listed, unsuspecting individuals contact the poster, who is Nigerian, for more information on the "rental."... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=HxkR1XXGUCw:wjhDh3aWUuM:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Large Signs a Security Risk</title>
		<link>http://www.schneier.com/blog/archives/2009/07/large_signs_a_s.html</link>
		<pubDate>Tue, 28 Jul 2009 16:23:34 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/large_signs_a_s.html</guid>
		<content:encoded><![CDATA[	A large sign saying "United States" at a border crossing was deemed a security risk: Yet three weeks ago, less than a month after the station opened, workers began prying the big yellow letters off the building's facade on orders from Customs and Border Protection. The plan is to dismantle the rest of the sign this week. "At the end... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=8kSuMkqQ_QQ:zKGA4Lo9wfY:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Swiss Security Problem: Storing Gold</title>
		<link>http://www.schneier.com/blog/archives/2009/07/swiss_security.html</link>
		<pubDate>Tue, 28 Jul 2009 07:13:43 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/swiss_security.html</guid>
		<content:encoded><![CDATA[	Seems like the Swiss may be running out of secure gold storage. If this is true, it's a real security issue. You can't just store the stuff behind normal locks. Building secure gold storage takes time and money. I am reminded of a related problem the EU had during the transition to the euro: where to store all the bills... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=ctR-WdyGvpk:rPHJAnlSdm8:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Tips for Staying Safe Online</title>
		<link>http://www.schneier.com/blog/archives/2009/07/tips_for_stayin.html</link>
		<pubDate>Mon, 27 Jul 2009 16:16:34 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/tips_for_stayin.html</guid>
		<content:encoded><![CDATA[	This is funny: Tips for Staying Safe Online All citizens can follow a few simple guidelines to keep themselves safe in cyberspace. In doing so, they not only protect their personal information but also contribute to the security of cyberspace. Install anti-virus software, a firewall, and anti-spyware software to your computer, and update as necessary. Create strong passwords on your... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=8Jf5ViMW4Qc:cEcaFb2jO9s:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Base Rate Fallacy</title>
		<link>http://www.schneier.com/blog/archives/2009/07/base_rate_falla.html</link>
		<pubDate>Mon, 27 Jul 2009 06:48:58 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/base_rate_falla.html</guid>
		<content:encoded><![CDATA[	Nice description of the base rate fallacy.... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=_AKupc4RcCY:3kH4AqTj8IA:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Friday Squid Blogging: Humboldt Squid Invasion</title>
		<link>http://www.schneier.com/blog/archives/2009/07/friday_squid_bl_190.html</link>
		<pubDate>Fri, 24 Jul 2009 16:51:32 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/friday_squid_bl_190.html</guid>
		<content:encoded><![CDATA[	Yikes: Thousands of jumbo flying squid, aggressive 5-foot-long sea monsters with razor-sharp beaks and toothy tentacles, have invaded the shallow waters off San Diego, spooking scuba divers and washing up dead on beaches. They're aggressive: One diver described how one of the rust-coloured creatures ripped the buoyancy aid and light from her chest, and grabbed her with its tentacles. Very... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=uuYboOa6kmY:5jmLmbzGJFw:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: SHA-3 Second Round Candidates Announced</title>
		<link>http://www.schneier.com/blog/archives/2009/07/sha-3_second_ro.html</link>
		<pubDate>Fri, 24 Jul 2009 12:15:36 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/sha-3_second_ro.html</guid>
		<content:encoded><![CDATA[	NIST has announced the 14 SHA-3 candidates that have advanced to the second round: BLAKE, Blue Midnight Wish, CubeHash, ECHO, Fugue, Grøstl, Hamsi, JH, Keccak, Luffa, Shabal, SHAvite-3, SIMD, and Skein. In February, I chose my favorites: Arirang, BLAKE, Blue Midnight Wish, ECHO, Grøstl, Keccak, LANE, Shabal, and Skein. Of the ones NIST eventually chose, I am most surprised to... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=Wt77teH7zZw:9dyagFzKORw:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Social Security Numbers are Not Random</title>
		<link>http://www.schneier.com/blog/archives/2009/07/social_security.html</link>
		<pubDate>Fri, 24 Jul 2009 10:36:20 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/social_security.html</guid>
		<content:encoded><![CDATA[	Social Security Numbers are not random. In some cases, you can predict them with date and place of birth. Abstract: Information about an individual's place and date of birth can be exploited to predict his or her Social Security number (SSN). Using only publicly available information, we observed a correlation between individuals' SSNs and their birth data and found that... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=Bra3Yokg2KM:kk2OOCsakRY:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: The Twitter Attack</title>
		<link>http://www.schneier.com/blog/archives/2009/07/the_twitter_att.html</link>
		<pubDate>Thu, 23 Jul 2009 12:07:07 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/the_twitter_att.html</guid>
		<content:encoded><![CDATA[	Excellent article detailing the Twitter attack.... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=08QQPtVNiTI:aD0wR0tAR3Y:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Mapping Drug Use by Testing Sewer Water</title>
		<link>http://www.schneier.com/blog/archives/2009/07/mapping_drug_us.html</link>
		<pubDate>Thu, 23 Jul 2009 06:09:06 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/mapping_drug_us.html</guid>
		<content:encoded><![CDATA[	I wrote about this in 2007, but there's new research: Scientists from Oregon State University, the University of Washington and McGill University partnered with city workers in 96 communities, including Pendleton, Hermiston and Umatilla, to gather samples on one day, March 4, 2008. The scientists then tested the samples for evidence of methamphetamine, cocaine and ecstasy, or MDMA. Addiction specialists... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=ZKW0BUfhEPI:yL3CqZ9KbBA:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Verifiable Dismantling of Nuclear Bombs</title>
		<link>http://www.schneier.com/blog/archives/2009/07/verifiable_dism.html</link>
		<pubDate>Tue, 21 Jul 2009 06:50:05 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/verifiable_dism.html</guid>
		<content:encoded><![CDATA[	Cryptography has zero-knowledge proofs, where Alice can prove to Bob that she knows something without revealing it to Bob. Here's something similar from the real world. It's a research project to allow weapons inspectors from one nation to verify the disarming of another nation's nuclear weapons without learning any weapons secrets in the process, such as the amount of nuclear... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=sKYfIy6GRpc:3d-CPAo6JsQ:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Cybercrime Paper</title>
		<link>http://www.schneier.com/blog/archives/2009/07/cybercrime_pape.html</link>
		<pubDate>Mon, 20 Jul 2009 07:43:16 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/cybercrime_pape.html</guid>
		<content:encoded><![CDATA[	"Distributed Security: A New Model of Law Enforcement," Susan W. Brenner and Leo L. Clarke. Abstract: Cybercrime, which is rapidly increasing in frequency and in severity, requires us to rethink how we should enforce our criminal laws. The current model of reactive, police-based enforcement, with its origins in real-world urbanization, does not and cannot protect society from criminals using computer... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=IU-UdCbMjD4:4jceHOjukfw:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Friday Squid Blogging: Bottled Water Plus Squid</title>
		<link>http://www.schneier.com/blog/archives/2009/07/friday_squid_bl_187.html</link>
		<pubDate>Fri, 17 Jul 2009 17:09:18 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/friday_squid_bl_187.html</guid>
		<content:encoded><![CDATA[	Only in Japan: Bandai toy company from Japan has finally realized that bottles of water just aren't cute. As Japan is the cute capital of the world, this just wouldn't do. To fix the problem, they developed these adorable floating squids that can be added to any bottle of water. Thank god for Japanese innovation. Of course, they're only available... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=nPTjtkLhDZk:493iBQl89SU:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Pepper Spray&amp;ndash;Equipped ATMs</title>
		<link>http://www.schneier.com/blog/archives/2009/07/pepper_sprayequ.html</link>
		<pubDate>Fri, 17 Jul 2009 14:04:04 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/pepper_sprayequ.html</guid>
		<content:encoded><![CDATA[	South Africa takes its security seriously. Here's an ATM that automatically squirts pepper spray into the face of "people tampering with the card slots." Sounds cool, but these kinds of things are all about false positives: But the mechanism backfired in one incident last week when pepper spray was inadvertently inhaled by three technicians who required treatment from paramedics. Patrick... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=KHqLl1kh7fY:4acyIGrP2to:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Privacy Salience and Social Networking Sites</title>
		<link>http://www.schneier.com/blog/archives/2009/07/privacy_salienc.html</link>
		<pubDate>Thu, 16 Jul 2009 07:05:11 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/privacy_salienc.html</guid>
		<content:encoded><![CDATA[	Reassuring people about privacy makes them more, not less, concerned. It's called "privacy salience," and Leslie John, Alessandro Acquisti, and George Loewenstein -- all at Carnegie Mellon University -- demonstrated this in a series of clever experiments. In one, subjects completed an online survey consisting of a series of questions about their academic behavior -- "Have you ever cheated on... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=7baVNs7jTok:dNYuho2oL68:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Laptop Security while Crossing Borders</title>
		<link>http://www.schneier.com/blog/archives/2009/07/laptop_security.html</link>
		<pubDate>Wed, 15 Jul 2009 13:10:47 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/laptop_security.html</guid>
		<content:encoded><![CDATA[	Last year, I wrote about the increasing propensity for governments, including the U.S. and Great Britain, to search the contents of people's laptops at customs. What we know is still based on anecdote, as no country has clarified the rules about what their customs officers are and are not allowed to do, and what rights people have. Companies and individuals... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=FJ_M3w743PU:ZKO3Vf0TciY:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Data Leakage Through Power Lines</title>
		<link>http://www.schneier.com/blog/archives/2009/07/data_leakage_th.html</link>
		<pubDate>Wed, 15 Jul 2009 07:17:58 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/data_leakage_th.html</guid>
		<content:encoded><![CDATA[	The NSA has known about this for decades: Security researchers found that poor shielding on some keyboard cables means useful data can be leaked about each character typed. By analysing the information leaking onto power circuits, the researchers could see what a target was typing. The attack has been demonstrated to work at a distance of up to 15m, but... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=0CatQdF3hLk:OGTEPPp88d8:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Poor Man's Steganography</title>
		<link>http://www.schneier.com/blog/archives/2009/07/poor_mans_stega.html</link>
		<pubDate>Tue, 14 Jul 2009 14:48:08 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/poor_mans_stega.html</guid>
		<content:encoded><![CDATA[	Hide files inside pdf documents: "embed a file in a PDF document and corrupt the reference, thereby effectively making the embedded file invisible to the PDF reader."... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=us9nf5mU-Bg:ShL9Qzv8fcE:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Gaze Tracking Software Protecting Privacy</title>
		<link>http://www.schneier.com/blog/archives/2009/07/gaze_tracking_s.html</link>
		<pubDate>Tue, 14 Jul 2009 07:20:37 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/gaze_tracking_s.html</guid>
		<content:encoded><![CDATA[	Interesting use of gaze tracking software to protect privacy: Chameleon uses gaze-tracking software and camera equipment to track an authorized reader's eyes to show only that one person the correct text. After a 15-second calibration period in which the software essentially "learns" the viewer's gaze patterns, anyone looking over that user's shoulder sees dummy text that randomly and constantly changes.... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=HQDmPx0wYkc:nOHEwfze6fk:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: North Korean Cyberattacks</title>
		<link>http://www.schneier.com/blog/archives/2009/07/north_korean_cy.html</link>
		<pubDate>Mon, 13 Jul 2009 12:45:53 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/north_korean_cy.html</guid>
		<content:encoded><![CDATA[	To hear the media tell it, the United States suffered a major cyberattack last week. Stories were everywhere. "Cyber Blitz hits U.S., Korea" was the headline in Thursday's Wall Street Journal. North Korea was blamed. Where were you when North Korea attacked America? Did you feel the fury of North Korea's armies? Were you fearful for your country? Or did... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=otAy7uPyBRM:E6Iuffzht1k:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Strong Web Passwords</title>
		<link>http://www.schneier.com/blog/archives/2009/07/strong_web_pass.html</link>
		<pubDate>Mon, 13 Jul 2009 06:38:31 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/strong_web_pass.html</guid>
		<content:encoded><![CDATA[	Interesting paper from HotSec '07: "Do Strong Web Passwords Accomplish Anything?" by Dinei Florêncio, Cormac Herley, and Baris Coskun. ABSTRACT: We find that traditional password advice given to users is somewhat dated. Strong passwords do nothing to protect online users from password stealing attacks such as phishing and keylogging, and yet they place considerable burden on users. Passwords that are... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=-y-5fXHSQyY:qQDrOo9mhcI:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Friday Squid Blogging: Humboldt Squid Caught Off Seattle</title>
		<link>http://www.schneier.com/blog/archives/2009/07/friday_squid_bl_188.html</link>
		<pubDate>Fri, 10 Jul 2009 16:45:42 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/friday_squid_bl_188.html</guid>
		<content:encoded><![CDATA[	A hundred-pounder. They're still moving North.... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=hv_gdVkuc8w:fGZfjmie-Tk:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Lost Suitcases in Airport Restrooms</title>
		<link>http://www.schneier.com/blog/archives/2009/07/lost_suitcases.html</link>
		<pubDate>Fri, 10 Jul 2009 12:45:03 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/lost_suitcases.html</guid>
		<content:encoded><![CDATA[	Want to cause chaos at an airport? Leave a suitcase in the restroom: Three incoming flights from London were cancelled and about 150 others were delayed for up to three hours, while the army's bomb squad carried out its investigation, before giving the all-clear at about 5pm. Passengers were told to leave the arrivals hall, main check-in area at the... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=PsF0zCU6kFY:SPiKX_wx4_I:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Making an Operating System Virus Free</title>
		<link>http://www.schneier.com/blog/archives/2009/07/making_an_opera.html</link>
		<pubDate>Fri, 10 Jul 2009 09:44:29 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/making_an_opera.html</guid>
		<content:encoded><![CDATA[	Commenting on Google's claim that Chrome was designed to be virus-free, I said: Bruce Schneier, the chief security technology officer at BT, scoffed at Google's promise. "It's an idiotic claim," Schneier wrote in an e-mail. "It was mathematically proved decades ago that it is impossible -- not an engineering impossibility, not technologically impossible, but the 2+2=3 kind of impossible --... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=x_ivFwoqTMY:wURLoW3aBRM:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: NSA Building Massive Data Center in Utah</title>
		<link>http://www.schneier.com/blog/archives/2009/07/nsa_building_ma.html</link>
		<pubDate>Fri, 10 Jul 2009 05:52:57 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/nsa_building_ma.html</guid>
		<content:encoded><![CDATA[	They're expanding: The years-in-the-making project, which may cost billions over time, got a $181 million start last week when President Obama signed a war spending bill in which Congress agreed to pay for primary construction, power access and security infrastructure. The enormous building, which will have a footprint about three times the size of the Utah State Capitol building, will... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=8-5nPoYj5mk:ZkUI-edH3rs:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: The ATM Vulnerability You Won't Hear About</title>
		<link>http://www.schneier.com/blog/archives/2009/07/the_atm_vulnera.html</link>
		<pubDate>Thu, 09 Jul 2009 12:56:14 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/the_atm_vulnera.html</guid>
		<content:encoded><![CDATA[	The talk has been pulled from the BlackHat conference: Barnaby Jack, a researcher with Juniper Networks, was to present a demonstration showing how he could jackpot a popular ATM brand by exploiting a vulnerability in its software. Jack was scheduled to present his talk at the upcoming Black Hat security conference being held in Las Vegas at the end of... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=Dj3-TDluo6c:6OW88l5Rz90:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Homomorphic Encryption Breakthrough</title>
		<link>http://www.schneier.com/blog/archives/2009/07/homomorphic_enc.html</link>
		<pubDate>Thu, 09 Jul 2009 06:36:38 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/homomorphic_enc.html</guid>
		<content:encoded><![CDATA[	Last month, IBM made some pretty brash claims about homomorphic encryption and the future of security. I hate to be the one to throw cold water on the whole thing -- as cool as the new discovery is -- but it's important to separate the theoretical from the practical. Homomorphic cryptosystems are ones where mathematical operations on the ciphertext have... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=oRqXQ-pz97Q:VxPcnvDVNrc:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Spanish Police Foil Remote-Controlled Zeppelin Jailbreak</title>
		<link>http://www.schneier.com/blog/archives/2009/07/spanish_police.html</link>
		<pubDate>Wed, 08 Jul 2009 13:54:40 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/spanish_police.html</guid>
		<content:encoded><![CDATA[	Sometimes movie plots actually happen: ...three people have been arrested after police discovered their plan to free a drug trafficker from an island prison using a 13-foot airship carrying night goggles, climbing gear and camouflage paint. [...] The arrested men had setup an elaborate surveillance operation of the prison that involved a camouflaged tent, powerful binoculars, telephoto lenses, and motion... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=L2lNrbQtLk0:K8Nc5dxdeYY:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Court Limits on TSA Searches</title>
		<link>http://www.schneier.com/blog/archives/2009/07/court_limits_on.html</link>
		<pubDate>Wed, 08 Jul 2009 06:42:14 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/court_limits_on.html</guid>
		<content:encoded><![CDATA[	This is good news: A federal judge in June threw out seizure of three fake passports from a traveler, saying that TSA screeners violated his Fourth Amendment rights against unreasonable search and seizure. Congress authorizes TSA to search travelers for weapons and explosives; beyond that, the agency is overstepping its bounds, U.S. District Court Judge Algenon L. Marbley said. "The... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=IBdYTTbA7GA:KloSb7F0Hc4:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Why People Don't Understand Risks</title>
		<link>http://www.schneier.com/blog/archives/2009/07/why_people_dont.html</link>
		<pubDate>Tue, 07 Jul 2009 13:50:35 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/why_people_dont.html</guid>
		<content:encoded><![CDATA[	Yesterday's Minneapolis Star Tribune had the front-page headline: "Co-sleeping kills about 20 infants each year." (The headline in the web article is different.) The only problem is, in either case, there's no additional information with which to make sense of the statistic. How many infants don't die each year? How many infants die each year in separate beds? Is the... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=_vpAHVI3g1U:KsoeDoDnS6o:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: More Low-Tech Security Solutions</title>
		<link>http://www.schneier.com/blog/archives/2009/07/more_low-tech_s.html</link>
		<pubDate>Tue, 07 Jul 2009 07:31:35 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/more_low-tech_s.html</guid>
		<content:encoded><![CDATA[	Anti-theft lunch bags, for those who have a problem with their lunches being stolen. Only works until the thief figures it out, though.... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=wQ4KAlaYheQ:LB_Qv27WxvA:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Pocketless Trousers to Protect Against Bribery</title>
		<link>http://www.schneier.com/blog/archives/2009/07/pocketless_trou.html</link>
		<pubDate>Mon, 06 Jul 2009 13:30:21 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/pocketless_trou.html</guid>
		<content:encoded><![CDATA[	I wonder if it will work. Nepal's anti-corruption authority has come up with a novel solution to rampant bribe-taking at the country's only international airport -- the pocketless trouser. The authority said it was issuing the new, bribe-proof garment to all airport officials after uncovering widespread corruption at Kathmandu's Tribhuvan International Airport.... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=EadXmmNq_bQ:RrITy1hlVCA:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Terrorist Risk of Cloud Computing</title>
		<link>http://www.schneier.com/blog/archives/2009/07/terrorist_risk.html</link>
		<pubDate>Mon, 06 Jul 2009 06:12:45 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/terrorist_risk.html</guid>
		<content:encoded><![CDATA[	I don't even know where to begin on this one: As we have seen in the past with other technologies, while cloud resources will likely start out decentralized, as time goes by and economies of scale take hold, they will start to collect into mega-technology hubs. These hubs could, as the end of this cycle, number in the low single... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=xChXRE18AWQ:EZGN3p7KXGk:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Friday Squid Blogging: Office Squid</title>
		<link>http://www.schneier.com/blog/archives/2009/07/friday_squid_bl_186.html</link>
		<pubDate>Fri, 03 Jul 2009 16:31:44 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/friday_squid_bl_186.html</guid>
		<content:encoded><![CDATA[	Office squid.... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=3p7iHiU31Ig:NwHyx94cZME:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: The Pros and Cons of Password Masking</title>
		<link>http://www.schneier.com/blog/archives/2009/07/the_pros_and_co.html</link>
		<pubDate>Fri, 03 Jul 2009 13:42:16 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/the_pros_and_co.html</guid>
		<content:encoded><![CDATA[	Usability guru Jakob Nielsen opened up a can of worms when he made the case for unmasking passwords in his blog. I chimed in that I agreed. Almost 165 comments on my blog (and several articles, essays, and many other blog posts) later, the consensus is that we were wrong. I was certainly too glib. Like any security countermeasure, password... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=fsfs9QTfe1Y:TyJgR2v-xrQ:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: The Insecurity of Secrecy</title>
		<link>http://www.schneier.com/blog/archives/2009/07/the_insecurity.html</link>
		<pubDate>Fri, 03 Jul 2009 07:18:49 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/the_insecurity.html</guid>
		<content:encoded><![CDATA[	Good essay -- "The Staggering Cost of Playing it 'Safe'" -- about the political motivations for terrorist security policy. Senator Barbara Boxer has led an effort to at least put together a public database of ash storage sites so that people can judge the risk to the areas where they live. However, even this effort has been blocked not by... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=7s4BsKkSSEM:YWXNj9aYBXA:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Information Leakage from Keypads</title>
		<link>http://www.schneier.com/blog/archives/2009/07/information_lea_1.html</link>
		<pubDate>Thu, 02 Jul 2009 12:09:30 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/information_lea_1.html</guid>
		<content:encoded><![CDATA[	Can anyone guess the entry codes for these door locks? There are 10,000 possible four-digit codes, but you only have to try 24 on these keypads. The first is most likely 1986 or 1968. The second is almost certainly 1234.... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=8CMRDBV_dQM:2vPq5FJ37vA:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: More Security Countermeasures from the Natural World</title>
		<link>http://www.schneier.com/blog/archives/2009/07/more_security_c.html</link>
		<pubDate>Thu, 02 Jul 2009 06:11:41 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/more_security_c.html</guid>
		<content:encoded><![CDATA[	The plant caladium steudneriifolium pretends to be ill so mining moths won't eat it. She believes that the plant essentially fakes being ill, producing variegated leaves that mimic those that have already been damaged by mining moth larvae. That deters the moths from laying any further larvae on the leaves, as the insects assume the previous caterpillars have already eaten... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=Akatti1JGRo:vaSPDO8kYa4:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: MD6 Withdrawn from SHA-3 Competition</title>
		<link>http://www.schneier.com/blog/archives/2009/07/md6.html</link>
		<pubDate>Wed, 01 Jul 2009 14:27:35 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/md6.html</guid>
		<content:encoded><![CDATA[	In other SHA-3 news, Ron Rivest seems to have withdrawn MD6 from the SHA-3 competition. From an e-mail to a NIST mailing list: We suggest that MD6 is not yet ready for the next SHA-3 round, and we also provide some suggestions for NIST as the contest moves forward. Basically, the issue is that in order for MD6 to be... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=-aSxHoKmtMY:7TJaMtcYfdA:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: New Attack on AES</title>
		<link>http://www.schneier.com/blog/archives/2009/07/new_attack_on_a.html</link>
		<pubDate>Wed, 01 Jul 2009 11:49:18 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/new_attack_on_a.html</guid>
		<content:encoded><![CDATA[	There's a new cryptanalytic attack on AES that is better than brute force: Abstract. In this paper we present two related-key attacks on the full AES. For AES-256 we show the first key recovery attack that works for all the keys and has complexity 2119, while the recent attack by Biryukov-Khovratovich-Nikolic works for a weak key class and has higher... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=R53Uxrrev8Q:H0GzKgHtnXU:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>
<item>
		<title>Schneier on Security: Security, Group Size, and the Human Brain</title>
		<link>http://www.schneier.com/blog/archives/2009/07/security_group.html</link>
		<pubDate>Wed, 01 Jul 2009 06:51:56 -0500</pubDate>
		<guid>http://www.schneier.com/blog/archives/2009/07/security_group.html</guid>
		<content:encoded><![CDATA[	If the size of your company grows past 150 people, it's time to get name badges. It's not that larger groups are somehow less secure, it's just that 150 is the cognitive limit to the number of people a human brain can maintain a coherent social relationship with. Primatologist Robin Dunbar derived this number by comparing neocortex -- the "thinking"... <a href="http://feeds.feedburner.com/~ff/schneier/excerpts?a=4L3K5b538sY:qPTwWXLFUIk:dnMXMwOfBR0"><img alt="" src="http://feeds.feedburner.com/~ff/schneier/excerpts?d=dnMXMwOfBR0" /></a> ]]></content:encoded>
</item>


</channel>
</rss>
