<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Peterism &#187; security</title>
	<atom:link href="http://peterchuang.com/blog/topics/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://peterchuang.com/blog</link>
	<description>NOT just random thoughts</description>
	<lastBuildDate>Mon, 13 Jun 2011 10:52:33 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>A Little Primer on Bootloaders, Encryption, and Signing</title>
		<link>http://peterchuang.com/blog/2011/05/514/</link>
		<comments>http://peterchuang.com/blog/2011/05/514/#comments</comments>
		<pubDate>Fri, 27 May 2011 17:20:13 +0000</pubDate>
		<dc:creator>Peter</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[android]]></category>
		<category><![CDATA[encryption]]></category>

		<guid isPermaLink="false">http://peterchuang.com/blog/?p=514</guid>
		<description><![CDATA[<p>A tweet from #AndroidPolice on Android booloaders and the security mechanism around it came to me through #cyanogen today.  While it&#8217;s not meant to be comprehensive, I think it does help point developers and modders in the right direction to understanding come fundamental building blocks in information security.  The fact that these security circumvention [...]]]></description>
			<content:encoded><![CDATA[<p>A tweet from <a title="#AndroidPolice" href="https://twitter.com/#!/androidpolice" target="_blank">#AndroidPolice</a> on Android booloaders and the security mechanism around it came to me through <a href="https://twitter.com/cyanogen" target="_blank">#cyanogen</a> today.  While it&#8217;s not meant to be comprehensive, I think it does help point developers and modders in the right direction to understanding come fundamental building blocks in information security.  The fact that these security circumvention techniques float about on the Net goes to show that although the underlying encryption schemes and ciphers remain intact, hackers have consistently managed to find attack vectors that &#8220;side step&#8221; these measures, hence the term &#8220;circumvention&#8221;.  It&#8217;s a proverbial game of cat and mouse perhaps calculated to cost-effectively block a majority of users while appeasing to script kiddies and modders alike.  Link to the post on Android Police <a title="So You Want To Know About Bootloaders, Encryption, Signing, And Locking? Let Me Explain" href="http://www.androidpolice.com/2011/05/27/so-you-want-to-know-about-bootloaders-encryption-signing-and-locking-let-me-explain/" target="_blank">here</a>.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fpeterchuang.com%2Fblog%2F2011%2F05%2F514%2F&amp;title=A%20Little%20Primer%20on%20Bootloaders%2C%20Encryption%2C%20and%20Signing" id="wpa2a_2"><img src="http://peterchuang.com/blog/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://peterchuang.com/blog/2011/05/514/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Microsoft urges laws to boost trust in the cloud</title>
		<link>http://peterchuang.com/blog/2010/01/423/</link>
		<comments>http://peterchuang.com/blog/2010/01/423/#comments</comments>
		<pubDate>Wed, 20 Jan 2010 22:46:53 +0000</pubDate>
		<dc:creator>Peter</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[Law]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[cloud]]></category>

		<guid isPermaLink="false">http://peterchuang.com/blog/2010/01/423/</guid>
		<description><![CDATA[<p>From CNET: In a speech Wednesday, Microsoft general counsel and senior vice president Brad Smith called on government and business to shore up confidence in cloud computing by tackling issues of privacy and security&#8211;two major concerns that have been voiced about the cloud.</p> <p>Full article.</p> ]]></description>
			<content:encoded><![CDATA[<p>From CNET:<br />
<blockquote>In a speech Wednesday, Microsoft general counsel and senior vice president Brad Smith called on government and business to shore up confidence in cloud computing by tackling issues of privacy and security&#8211;two major concerns that have been voiced about the cloud.</p></blockquote>
<p><a target="_blank" href="http://news.cnet.com/8301-1009_3-10437844-83.html?tag=newsEditorsPicksArea.0">Full article.</a></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fpeterchuang.com%2Fblog%2F2010%2F01%2F423%2F&amp;title=Microsoft%20urges%20laws%20to%20boost%20trust%20in%20the%20cloud" id="wpa2a_4"><img src="http://peterchuang.com/blog/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://peterchuang.com/blog/2010/01/423/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A5/1 Cipher Cracked</title>
		<link>http://peterchuang.com/blog/2010/01/404/</link>
		<comments>http://peterchuang.com/blog/2010/01/404/#comments</comments>
		<pubDate>Fri, 01 Jan 2010 20:36:25 +0000</pubDate>
		<dc:creator>Peter</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[programming]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[gsm]]></category>

		<guid isPermaLink="false">http://peterchuang.com/blog/2010/01/404/</guid>
		<description><![CDATA[<p>German researcher Karsten Nohl has cracked the encryption used for GSM.&#160; His team has made information and tools needed to replicate the attack with a somewhat modest set up.&#160;&#160;&#160; The A5/1&#8242;s 64-bit encryption key used in GSM is simply too short for the kind of computing power widely available today.&#160; Considering that the technology [...]]]></description>
			<content:encoded><![CDATA[<p>German researcher Karsten Nohl has cracked the encryption used for GSM.&nbsp; His team has made information and tools needed to replicate the attack with a somewhat modest set up.&nbsp;&nbsp;&nbsp; The A5/1&#8242;s 64-bit encryption key used in GSM is simply too short for the kind of computing power widely available today.&nbsp; Considering that the technology is over 20 years old, however, it&#8217;s robustness is still remarkable.</p>
<p>Here&#8217;s the <a target="_blank" href="http://reflextor.com/trac/a51/">A5/1 Cracking Project&#8217;s website</a>.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fpeterchuang.com%2Fblog%2F2010%2F01%2F404%2F&amp;title=A5%2F1%20Cipher%20Cracked" id="wpa2a_6"><img src="http://peterchuang.com/blog/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://peterchuang.com/blog/2010/01/404/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Iraqi insurgents hack US drones with $26 software</title>
		<link>http://peterchuang.com/blog/2009/12/402/</link>
		<comments>http://peterchuang.com/blog/2009/12/402/#comments</comments>
		<pubDate>Wed, 30 Dec 2009 22:01:07 +0000</pubDate>
		<dc:creator>Peter</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[encryption]]></category>

		<guid isPermaLink="false">http://peterchuang.com/blog/2009/12/402/</guid>
		<description><![CDATA[<p>A report from The Register said that hours of unencrypted surveillance video feeds were intercepted by the Iraqi insurgents.&#160; A laptop containing the video feeds were discovered late 2008, but it&#8217;s not clear from the report when those feeds were intercepted.</p> <p>Why were those video feeds unencrypted?&#160; Granted even the strongest encryption scheme to [...]]]></description>
			<content:encoded><![CDATA[<p>A report from The Register said that hours of unencrypted surveillance video feeds were intercepted by the Iraqi insurgents.&nbsp; A laptop containing the video feeds were discovered late 2008, but it&#8217;s not clear from the report when those feeds were intercepted.</p>
<p>Why were those video feeds unencrypted?&nbsp; Granted even the strongest encryption scheme to date isn&#8217;t unbreakable, given enough technical know-how, processing power, and time.&nbsp; My guess is that the contractor or subcontractor supplying the camera or the transceiver forgot to turn encryption on, and no one caught the fatal error.</p>
<p>Here&#8217;s the <a target="_blank" href="http://www.theregister.co.uk/2009/12/17/us_drones_hacked/">full story</a>.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fpeterchuang.com%2Fblog%2F2009%2F12%2F402%2F&amp;title=Iraqi%20insurgents%20hack%20US%20drones%20with%20%2426%20software" id="wpa2a_8"><img src="http://peterchuang.com/blog/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://peterchuang.com/blog/2009/12/402/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Free Linux Server Backup Using Dropbox</title>
		<link>http://peterchuang.com/blog/2009/11/338/</link>
		<comments>http://peterchuang.com/blog/2009/11/338/#comments</comments>
		<pubDate>Sat, 28 Nov 2009 19:46:49 +0000</pubDate>
		<dc:creator>Peter</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[apache]]></category>
		<category><![CDATA[backup]]></category>
		<category><![CDATA[dropbox]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[ubuntu]]></category>

		<guid isPermaLink="false">http://peterchuang.com/blog/?p=338</guid>
		<description><![CDATA[<p>I don&#8217;t need to tell you how important data backups are.  These days, several online backup services based on cloud computing are available for either free with some limited storage to a affordable monthly fee for unlimited storage.  Carbonite, Mozy, Blackblaze, and Dropbox are a few excellent examples.  There are advantages and disadvantages of [...]]]></description>
			<content:encoded><![CDATA[<p>I don&#8217;t need to tell you how important data backups are.  These days, several online backup services based on cloud computing are available for either free with some limited storage to a affordable monthly fee for unlimited storage.  <a href="http://carbonite.com" target="_blank">Carbonite</a>, <a href="http://mozy.com" target="_blank">Mozy</a>, <a href="http://blackblaze.com" target="_blank">Blackblaze</a>, and <a href="http://dropbox.com" target="_blank">Dropbox</a> are a few excellent examples.  There are advantages and disadvantages of these various services.  I use 3 out of the 4 mentioned, depending on the type of data, frequency of changes, , and how often I need to access them, etc.  For my VPS host at <a href="http://rapidvps.com" target="_blank">RapidVPS</a> which runs on Ubuntu, I use Dropbox because Dropbox has a fairly decent support for Linux.</p>
<p>Here&#8217;s a <a href="http://wiki.dropbox.com/TipsAndTricks/TextBasedLinuxInstall" target="_blank">pretty good instruction</a> at Dropbox.  I didn&#8217;t follow the instruction exactly, but I&#8217;ve repeated the step enough times to know that it works for the most part.  I had some problems with my Python 2.6 installation after incrementally upgrading from 8.04 -&gt; 8.10 -&gt; 9.04 -&gt; 9.10, but it&#8217;s all good now.  Anyway, on my VPS host, I set up several cron jobs to dump mysql databases and svn repos, rsync contents of some /var/www and tar-gzip contents of /etc, /root, and /var/log.  I don&#8217;t need to keep multiple versions of the backups because dropbox automatically takes care of incremental backup and versioning.  One thing to be aware, however, is that Dropbox doesn&#8217;t encrypt data, either in the transmission or storage, so you might want throw something like <a href="http://www.truecrypt.org/" target="_blank">TrueCrypt </a>or <a href="http://www.gnupg.org/" target="_blank">GnuPG </a>in the mix.</p>
<p>Once backups are set-up with Dropbox, you can even subscribe to the backup/revision history RSS feed(s) provided by Dropbox to stay on top of the status.</p>
<p>Several other useful resources:</p>
<ul>
<li><a rel="shadowbox" href="http://pragmattica.wordpress.com/2009/05/10/encrypting-your-dropbox-seamlessly-and-automatically/">Encrypting Your Dropbox Seamlessly and Automatically</a></li>
<li><a rel="shadowbox" href="http://dailymoe.blogspot.com/2009/01/dropbox-with-personal-encryption.html">Dropbox With Personal Encryption</a></li>
</ul>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fpeterchuang.com%2Fblog%2F2009%2F11%2F338%2F&amp;title=Free%20Linux%20Server%20Backup%20Using%20Dropbox" id="wpa2a_10"><img src="http://peterchuang.com/blog/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://peterchuang.com/blog/2009/11/338/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>TLS Vulnerability to MITM Attack</title>
		<link>http://peterchuang.com/blog/2009/11/279/</link>
		<comments>http://peterchuang.com/blog/2009/11/279/#comments</comments>
		<pubDate>Thu, 05 Nov 2009 22:15:15 +0000</pubDate>
		<dc:creator>Peter</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[tls]]></category>

		<guid isPermaLink="false">http://peterchuang.com/blog/2009/11/279/</guid>
		<description><![CDATA[<p>TLS is the underlying technology used by modern browsers and web servers to encrypt data communicated between them.  (Since TLS is a transport layer facility, it can be used in any other application layer protocols like SMTP, POP, etc, in addition to HTTP.)  While the encryption itself has been regarded as &#8220;secure enough&#8221; by [...]]]></description>
			<content:encoded><![CDATA[<p>TLS is the underlying technology used by modern browsers and web servers to encrypt data communicated between them.  (Since TLS is a transport layer facility, it can be used in any other application layer protocols like SMTP, POP, etc, in addition to HTTP.)  While the encryption itself has been regarded as &#8220;secure enough&#8221; by online banking services (encryption relying on 4096-bit public key as of 2009), among others, there is another type of attack which is independent of the strength of the encryption used &#8211; man-in-the-middle (MITM) attack.</p>
<p>Here&#8217;s a <a href="http://extendedsubset.com/?p=8" target="_blank">blog post</a> demonstrating one way it can be done.  Browser security patches should be on their way.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fpeterchuang.com%2Fblog%2F2009%2F11%2F279%2F&amp;title=TLS%20Vulnerability%20to%20MITM%20Attack" id="wpa2a_12"><img src="http://peterchuang.com/blog/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://peterchuang.com/blog/2009/11/279/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Department of Defense New Guidance On Open Source Software</title>
		<link>http://peterchuang.com/blog/2009/10/256/</link>
		<comments>http://peterchuang.com/blog/2009/10/256/#comments</comments>
		<pubDate>Tue, 27 Oct 2009 21:38:10 +0000</pubDate>
		<dc:creator>Peter</dc:creator>
				<category><![CDATA[Computers]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://peterchuang.com/blog/2009/10/256/</guid>
		<description><![CDATA[<p>The Department of Defense CIO office has released a new guideline which is aimed at easing open source software adoption.</p> <p>Department of Defense CIO David Wennergren&#8217;s revised guidance (PDF)</p> ]]></description>
			<content:encoded><![CDATA[<p>The Department of Defense CIO office has released a new guideline which is aimed at easing open source software adoption.</p>
<p><a href="http://powdermonkey.blogs.com/files/2009oss.pdf">Department of Defense CIO David Wennergren&#8217;s revised guidance</a> (PDF)</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fpeterchuang.com%2Fblog%2F2009%2F10%2F256%2F&amp;title=Department%20of%20Defense%20New%20Guidance%20On%20Open%20Source%20Software" id="wpa2a_14"><img src="http://peterchuang.com/blog/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://peterchuang.com/blog/2009/10/256/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

