<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://aliceorbob.com/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Charlie, implementing ITrust</title><link>http://aliceorbob.com/blogs/charlie/default.aspx</link><description /><dc:language>en-US</dc:language><generator>CommunityServer 2.0 (Build: 60217.2664)</generator><item><title>Just for a SecPal </title><link>http://aliceorbob.com/blogs/charlie/archive/2006/09/28/1145.aspx</link><pubDate>Thu, 28 Sep 2006 02:49:00 GMT</pubDate><guid isPermaLink="false">7df12e44-10b7-4c21-b04e-61c7aa8466eb:1145</guid><dc:creator>charlie</dc:creator><slash:comments>0</slash:comments><comments>http://aliceorbob.com/blogs/charlie/comments/1145.aspx</comments><wfw:commentRss>http://aliceorbob.com/blogs/charlie/commentrss.aspx?PostID=1145</wfw:commentRss><description>Microsoft is forwarding the notion of a language for security policy. Blair Dillaway of Microsoft Research, described the Security Policy Assertion Language at a recent Grid computing conference.&lt;A&gt;&lt;IMG alt="Secure By Design" hspace=5 src="http://msdn.microsoft.com/nodehomes/graphics/80x60/security2.jpg" align=left border=0&gt;&lt;/A&gt;&lt;BR&gt;&lt;BR&gt;Speaking at GridWorld in Washington, D.C. earlier this month, Blair Dillaway described SecPal as a declarative, logic-based security language that supports distributed policy authoring and composition. It is said to be an XML dialect that works as a means for handling access control requirements, trust, authorization, and delegation policies.&lt;BR&gt;&lt;BR&gt;&lt;A href="http://www.ggf.org/GGF18/materials/353/GridUnifiedAccessControl-Microsoft-GGF18.ppt"&gt;Presentation on SecPal&lt;/A&gt; - ggf.org [PPT] &lt;img src="http://aliceorbob.com/aggbug.aspx?PostID=1145" width="1" height="1"&gt;</description></item><item><title>Thawte Crypto Challenge</title><link>http://aliceorbob.com/blogs/charlie/archive/2006/08/31/1025.aspx</link><pubDate>Thu, 31 Aug 2006 07:28:00 GMT</pubDate><guid isPermaLink="false">7df12e44-10b7-4c21-b04e-61c7aa8466eb:1025</guid><dc:creator>charlie</dc:creator><slash:comments>0</slash:comments><comments>http://aliceorbob.com/blogs/charlie/comments/1025.aspx</comments><wfw:commentRss>http://aliceorbob.com/blogs/charlie/commentrss.aspx?PostID=1025</wfw:commentRss><description>&lt;P&gt;&lt;IMG src="https://www.thawte.com/dynamic/en/images/cryptochallenge/header_x.jpg"&gt;&lt;/P&gt;
&lt;P&gt;The &lt;B&gt;&lt;I&gt;thawte&lt;/I&gt;&lt;/B&gt; Crypto Challenge gives you the chance to pit your wits against our code and other crackers around the world. If you have the skills, you too can be infamous (and win a prize while you’re at it). Crypto Challenge X is now open, so register to reveal the code and start cracking!&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.thawte.com/process/crypto/cryptoIndex"&gt;Go to the site.&lt;/A&gt;&lt;/P&gt;&lt;img src="http://aliceorbob.com/aggbug.aspx?PostID=1025" width="1" height="1"&gt;</description></item><item><title>The FBI needs help from hackers</title><link>http://aliceorbob.com/blogs/charlie/archive/2006/08/03/941.aspx</link><pubDate>Thu, 03 Aug 2006 02:22:00 GMT</pubDate><guid isPermaLink="false">7df12e44-10b7-4c21-b04e-61c7aa8466eb:941</guid><dc:creator>charlie</dc:creator><slash:comments>0</slash:comments><comments>http://aliceorbob.com/blogs/charlie/comments/941.aspx</comments><wfw:commentRss>http://aliceorbob.com/blogs/charlie/commentrss.aspx?PostID=941</wfw:commentRss><description>&lt;img src="http://www.fbi.gov/homeimag/sealglobal150.jpg" alt="" align="left" hspace="10"&gt;
"We need your expertise and input as we develop strategies to battle cybercrime in the 21st century," Daniel Larkin, a unit chief in the FBI's cybercrime division, said in his opening address at the annual Black Hat security conference here.&lt;br&gt;&lt;br&gt;As cybercrime has continued to become more sophisticated and organized, federal agencies have increasingly sought to partner with the private sector. Earlier this year, FBI Director Robert Mueller used the RSA Conference to send out a similar message.&lt;br&gt;&lt;br&gt;"The people we're going after are not just the script kiddies anymore. These people are making a lot of money," Larkin told the Black Hat audience of hackers and security professionals. "I am a recovering technophobe; I used to be really afraid of you all. But I realize that you all are really important."&lt;br&gt;&lt;br&gt;&lt;p&gt;Read more at: &lt;a href="http://news.com.com/FBI+calls+for+hacker+help/2100-7348_3-6101475.html?tag=st_lh"&gt;news.com&lt;/a&gt;.&lt;br&gt;&lt;/p&gt;&lt;img src="http://aliceorbob.com/aggbug.aspx?PostID=941" width="1" height="1"&gt;</description></item><item><title>ActiveX security faces storm before calm</title><link>http://aliceorbob.com/blogs/charlie/archive/2006/08/02/937.aspx</link><pubDate>Wed, 02 Aug 2006 05:14:00 GMT</pubDate><guid isPermaLink="false">7df12e44-10b7-4c21-b04e-61c7aa8466eb:937</guid><dc:creator>charlie</dc:creator><slash:comments>0</slash:comments><comments>http://aliceorbob.com/blogs/charlie/comments/937.aspx</comments><wfw:commentRss>http://aliceorbob.com/blogs/charlie/commentrss.aspx?PostID=937</wfw:commentRss><description>&lt;span class="body"&gt;
Using a custom-built data fuzzing tool, &lt;/span&gt;HD Moore&lt;span class="body"&gt;
pinpointed more than 100 vulnerabilities in the ActiveX controls
included with the default installation of Microsoft's Windows XP
operating system. Data fuzzing tools combine knowledge of the input
parameters accepted by a software package with a tenacious and
systematic mangling of the data to &lt;a href="http://www.securityfocus.com/news/11400"&gt;discover how applications react&lt;/a&gt; to various permutations, whether valid or invalid.&lt;br&gt;&lt;br&gt;Read more at &lt;a href="http://www.securityfocus.com/news/11403"&gt;SecurityFocus&lt;/a&gt;.&lt;br&gt;&lt;/span&gt;&lt;img src="http://aliceorbob.com/aggbug.aspx?PostID=937" width="1" height="1"&gt;</description></item><item><title>NASA Site Attacks</title><link>http://aliceorbob.com/blogs/charlie/archive/2006/08/02/936.aspx</link><pubDate>Wed, 02 Aug 2006 05:07:00 GMT</pubDate><guid isPermaLink="false">7df12e44-10b7-4c21-b04e-61c7aa8466eb:936</guid><dc:creator>charlie</dc:creator><slash:comments>0</slash:comments><comments>http://aliceorbob.com/blogs/charlie/comments/936.aspx</comments><wfw:commentRss>http://aliceorbob.com/blogs/charlie/commentrss.aspx?PostID=936</wfw:commentRss><description>&lt;img src="http://www.nasa.gov/images/content/152329main_s121e06583-t.jpg" align="left" hspace="10"&gt;
The Zone-H website recently &lt;a href="http://www.zone-h.org/index.php?option=com_content&amp;amp;task=view&amp;amp;id=13932&amp;amp;Itemid=30&amp;amp;msgid=710" class="bluelink"&gt;reported&lt;/a&gt; on the defacements that took place. Websites run by NASA and other agencies have been frequent targets of attacks.
&lt;br&gt;&lt;br&gt;A Chilean cracking group called Byond Hackers Crew took credit
for the defacement of a pair of NASA servers. Those machines had their
home pages replaced with the picture of a young bombing victim's face
and the message "No war."
&lt;img src="http://aliceorbob.com/aggbug.aspx?PostID=936" width="1" height="1"&gt;</description></item><item><title>Netscape.com falls victim to cross-site scripting attack</title><link>http://aliceorbob.com/blogs/charlie/archive/2006/07/27/923.aspx</link><pubDate>Thu, 27 Jul 2006 05:20:00 GMT</pubDate><guid isPermaLink="false">7df12e44-10b7-4c21-b04e-61c7aa8466eb:923</guid><dc:creator>charlie</dc:creator><slash:comments>0</slash:comments><comments>http://aliceorbob.com/blogs/charlie/comments/923.aspx</comments><wfw:commentRss>http://aliceorbob.com/blogs/charlie/commentrss.aspx?PostID=923</wfw:commentRss><description>&lt;img src="http://media-images.nscpcdn.com/media/avatars/defaultUser05.png" align="left" border="5" hspace="5"&gt;
&lt;p&gt;Fans of the website &lt;a href="http://digg.com"&gt;Digg.com&lt;/a&gt; have hacked the
&lt;a href="http://www.netscape.com/" target="_blank" title="Netscape.com"&gt;Netscape.com&lt;/a&gt;
service using a cross-site scripting attack.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The site was recently relaunched as a
&lt;a href="http://www.vnunet.com/2159504" title="Users vent spleen at new Netscape"&gt;social book-marking
service&lt;/a&gt;. It is generally considered a copy of the popular
&lt;a href="http://www.digg.com/" target="_blank" title="Digg.com"&gt;Digg.com&lt;/a&gt;
website.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Netscape visitors on Wednesday were presented with pop-up messages, one of
which stated: 'This site sucks. Go here instead'. Clicking on the message led
users to Digg.com.&lt;/p&gt;&lt;img src="http://aliceorbob.com/aggbug.aspx?PostID=923" width="1" height="1"&gt;</description></item><item><title>Best practices for security in ASP.NET 2.0</title><link>http://aliceorbob.com/blogs/charlie/archive/2006/07/21/905.aspx</link><pubDate>Fri, 21 Jul 2006 00:34:00 GMT</pubDate><guid isPermaLink="false">7df12e44-10b7-4c21-b04e-61c7aa8466eb:905</guid><dc:creator>charlie</dc:creator><slash:comments>0</slash:comments><comments>http://aliceorbob.com/blogs/charlie/comments/905.aspx</comments><wfw:commentRss>http://aliceorbob.com/blogs/charlie/commentrss.aspx?PostID=905</wfw:commentRss><description>&lt;p&gt;Check out the &lt;a href="http://msdn.microsoft.com/practices/Topics/security/default.aspx"&gt;patterns and practices site for security in .NET&lt;/a&gt;.&lt;br&gt;&lt;/p&gt;&lt;p&gt;Don't just rely on some of the built-in features of ASP.NET. For example, the &lt;a href="http://www.gotdotnet.com/codegallery/codegallery.aspx?id=48f35de8-cd92-4ac6-9144-12d5a13f22ff" target="_blank" title="Click to go there"&gt;ASP.NET 2.0 Internet Security Reference Implementation&lt;/a&gt;
uses custom functions to encode input because ASP.NET’s
Server.HtmlEncode "only encodes &amp;lt;&amp;gt;"&amp;amp; characters. This is not
sufficient to protect against all possible attacks.&amp;nbsp; The authors also
reference the &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=9A2B9C92-7AD9-496C-9A89-AF08DE2E5982&amp;amp;displaylang=en" target="_blank"&gt;Microsoft Anti-Cross Site Scripting Library V1.0&lt;/a&gt;&amp;nbsp;to fight against unproven (aka evil) input.&lt;img alt=""&gt;&lt;/p&gt;&lt;p&gt;Likewise, the app discourages the use of &lt;a href="http://msdn2.microsoft.com/en-us/library/4hx47hfe.aspx" target="_blank"&gt;DataBinder.Eval()&lt;/a&gt;
when displaying content from the database. "While Eval is sometimes
safe to use on purely static data, it is best to avoid it completely as
it has the potential to allow an attacker to execute arbitrary code on
the host server." &lt;br&gt;&lt;/p&gt;&lt;img src="http://aliceorbob.com/aggbug.aspx?PostID=905" width="1" height="1"&gt;</description></item><item><title>Searching for malicious software</title><link>http://aliceorbob.com/blogs/charlie/archive/2006/07/19/900.aspx</link><pubDate>Wed, 19 Jul 2006 01:22:00 GMT</pubDate><guid isPermaLink="false">7df12e44-10b7-4c21-b04e-61c7aa8466eb:900</guid><dc:creator>charlie</dc:creator><slash:comments>0</slash:comments><comments>http://aliceorbob.com/blogs/charlie/comments/900.aspx</comments><wfw:commentRss>http://aliceorbob.com/blogs/charlie/commentrss.aspx?PostID=900</wfw:commentRss><description>&lt;p&gt;
H. D. Moore, creator of the &lt;a href="http://dw.com.com/redir?destUrl=http%3A%2F%2Fmetasploit.com%2F&amp;amp;siteId=3&amp;amp;oId=2060-10789_3-6095213&amp;amp;ontId=10784&amp;amp;lop=nl.ex"&gt;Metasploit hacking tool&lt;/a&gt;, has crafted a search engine that finds malicious software using queries on &lt;a href="http://www.google.com"&gt;Google&lt;/a&gt;. This &lt;a href="http://dw.com.com/redir?destUrl=http%3A%2F%2Fmetasploit.com%2Fresearch%2Fmisc%2Fmwsearch%2Findex.html&amp;amp;siteId=3&amp;amp;oId=2060-10789_3-6095213&amp;amp;ontId=10784&amp;amp;lop=nl.ex"&gt;"Malware" search engine&lt;/a&gt; finds Web sites hosting malicious files after a person enters the name of a virus or Trojan horse.
&lt;/p&gt;&lt;p&gt;
To find the malicious software the tool uses a fingerprint
of the executable and then searches for it. However, those who do try it won't find much. Google has
not indexed most malware yet and the signature database is still very small,
according to the &lt;a href="http://metasploit.com/research/misc/mwsearch/index.html"&gt;Malware search site&lt;/a&gt;.
&lt;/p&gt;&lt;p&gt;
Launch of the site comes shortly after researchers at Websense Security Labs said they had been able to &lt;a href="http://dw.com.com/redir?destUrl=http%3A%2F%2Fwww.websense.com%2Fsecuritylabs%2Falerts%2Falert.php%3FAlertID%3D547&amp;amp;siteId=3&amp;amp;oId=2060-10789_3-6095213&amp;amp;ontId=10784&amp;amp;lop=nl.ex"&gt;find thousands of examples of malicious code&lt;/a&gt; using Google's search technology. 
&lt;/p&gt;&lt;p&gt;Most of what Websense found were malicious files posted to&amp;nbsp; newsgroups with false names, designed to trick a user.
&lt;/p&gt;&lt;p&gt;Being able to find malicious software on Google shows the
potential to embed strings within binaries that
match search terms in order to dupe users into running malicious code,
Websense said in an &lt;a href="http://www.websense.com/securitylabs/incidents/"&gt;alert last week&lt;/a&gt;. &lt;/p&gt;&lt;img src="http://aliceorbob.com/aggbug.aspx?PostID=900" width="1" height="1"&gt;</description></item><item><title>Threat Analysis and Modeling Tool v. 2.0 (RTM) is available</title><link>http://aliceorbob.com/blogs/charlie/archive/2006/07/09/863.aspx</link><pubDate>Sun, 09 Jul 2006 05:36:00 GMT</pubDate><guid isPermaLink="false">7df12e44-10b7-4c21-b04e-61c7aa8466eb:863</guid><dc:creator>charlie</dc:creator><slash:comments>0</slash:comments><comments>http://aliceorbob.com/blogs/charlie/comments/863.aspx</comments><wfw:commentRss>http://aliceorbob.com/blogs/charlie/commentrss.aspx?PostID=863</wfw:commentRss><description>&lt;span&gt;Microsoft Threat Analysis &amp;amp; Modeling tool allows non-security subject 
matter experts to enter already known information including business 
requirements and application architecture which is then used to produce a 
feature-rich threat model. Along with automatically identifying threats, the 
tool can produce valuable security artifacts.&lt;br&gt;&lt;/span&gt;&lt;img src="http://msdn.microsoft.com/security/graphics/graphic_glossy.jpg" alt="just an image" align="left" hspace="10"&gt;&lt;br&gt;The Threat Analysis and Modeling Tool 
v2.0 is now available &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=334ad466-8b53-4440-8ff0-6ac8142d9198&amp;amp;displaylang=en"&gt;here&lt;/a&gt;. 
&lt;br&gt;&lt;br&gt;These are the main features of the package:&lt;br&gt;&lt;ul&gt;&lt;li&gt;TreeView Navigation with visibility to all nodes at all 
times&lt;/li&gt;&lt;li&gt;Wizard based threat model creation&lt;/li&gt;&lt;li&gt;Default Attack library 
with descriptive countermeasure guidance&lt;/li&gt;&lt;li&gt;Automatic Threats and Use Cases 
generation&lt;/li&gt;&lt;li&gt;Consolidated Call Flow (System Flow), Attack Surface, Threat 
Tree are some of the few visualizations available, which can all be exported to 
Visio&lt;/li&gt;&lt;li&gt;Exportable Analytics and Reports to HTML&lt;/li&gt;&lt;li&gt;Import v1.0 
Threat Model (models created using Torpedo v1)&lt;/li&gt;&lt;li&gt;Export countermeasures 
and attack test cases to Visual Studio Team Foundation Server 
(TFS)&lt;/li&gt;&lt;li&gt;Import SDM Deployment Reports from VSTA&lt;/li&gt;&lt;li&gt;Copy Paste and 
Drag-&amp;amp;-Drop features&lt;/li&gt;&lt;li&gt;Enhanced Find Feature&lt;/li&gt;&lt;li&gt;Video 
Tutorials&lt;/li&gt;&lt;/ul&gt;Go to the &lt;a href="http://msdn.microsoft.com/security/securecode/threatmodeling/acetm/"&gt;Application Threat Modeling site&lt;/a&gt;, to get started.&lt;br&gt;&lt;img src="http://aliceorbob.com/aggbug.aspx?PostID=863" width="1" height="1"&gt;</description></item><item><title>Device Security Manager Powertoy for Windows Mobile 5.0 Released!</title><link>http://aliceorbob.com/blogs/charlie/archive/2006/07/06/843.aspx</link><pubDate>Thu, 06 Jul 2006 00:52:00 GMT</pubDate><guid isPermaLink="false">7df12e44-10b7-4c21-b04e-61c7aa8466eb:843</guid><dc:creator>charlie</dc:creator><slash:comments>0</slash:comments><comments>http://aliceorbob.com/blogs/charlie/comments/843.aspx</comments><wfw:commentRss>http://aliceorbob.com/blogs/charlie/commentrss.aspx?PostID=843</wfw:commentRss><description>&lt;P&gt;This test tool helps developers of Windows Mobile applications test various security policies for Windows Mobile devices. It is designed as a desktop application that ships with a preset list of “security configurations”. &lt;IMG alt="Cell phones" hspace=5 src="http://i.i.com.com/cnwk.1d/i/rev/fd/cellphones.jpg" align=right border=0&gt;&lt;/P&gt;
&lt;P&gt;A security configuration can be thought of as a template, which contains a collection of individual policies and settings. For example, a security configuration could define policies such as whether unsigned applications are allowed to execute, whether RAPI is disabled etc. &lt;/P&gt;
&lt;P&gt;Using this tool, the developer can provision a Windows Mobile device with different configurations, and then test the application’s behavior under these configurations. This tool can be used either on an emulator or an unlocked Windows Mobile device.&lt;/P&gt;
&lt;P&gt;&lt;o:p&gt;You can &lt;A href="http://www.microsoft.com/downloads/details.aspx?FamilyID=7e92628c-d587-47e0-908b-09fee6ea517a&amp;amp;amp;displaylang=en"&gt;download the tool here&lt;/A&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;&lt;o:p&gt;source: &lt;A href="http://blogs.msdn.com/mikehall/archive/2006/07/05/657436.aspx"&gt;http://blogs.msdn.com/mikehall/archive/2006/07/05/657436.aspx&lt;/A&gt;&lt;A href="http://blogs.msdn.com/mikehall/default.aspx"&gt;&lt;/A&gt;&lt;/o:p&gt;&lt;/P&gt;&lt;img src="http://aliceorbob.com/aggbug.aspx?PostID=843" width="1" height="1"&gt;</description></item><item><title>Apple issues another OS X security update</title><link>http://aliceorbob.com/blogs/charlie/archive/2006/06/29/827.aspx</link><pubDate>Thu, 29 Jun 2006 09:15:00 GMT</pubDate><guid isPermaLink="false">7df12e44-10b7-4c21-b04e-61c7aa8466eb:827</guid><dc:creator>charlie</dc:creator><slash:comments>0</slash:comments><comments>http://aliceorbob.com/blogs/charlie/comments/827.aspx</comments><wfw:commentRss>http://aliceorbob.com/blogs/charlie/commentrss.aspx?PostID=827</wfw:commentRss><description>Apple has released a security update to its OS X 10.4 operating&lt;img src="http://images.apple.com/macosx/images/indexautomatoricon20050412.gif" alt="automator" align="right" hspace="10"&gt; system. Some of the &lt;a href="http://docs.info.apple.com/article.html?artnum=303973"&gt;five patches in security update 10.4.7&lt;/a&gt;
address vulnerabilities that could allow a remote attacker to gain
access to a compromised system, and one addresses a buffer-overflow
flaw within ClamAV, a third-party antivirus application that is popular
among Mac users. The other vulnerabilities involve Launchd, a flaw
publicly exposed by the &lt;a href="http://reviews.cnet.com/4520-3513_7-6457383-1.html?tag=txt"&gt;Mac virus InqTana.b earlier this year&lt;/a&gt;. Other vulnerablities involve OpenLDAP, ImageIO, and AFP. Additional information on the 10.4.7 patches can be obtained from &lt;a href="http://docs.info.apple.com/article.html?artnum=61798"&gt;Apple's security update site&lt;/a&gt; and from &lt;a href="http://news.com.com/Apple+updates+Mac+OS+to+squash+bugs/2100-1002_3-6088787.html?tag=cd.top"&gt;News.com&lt;/a&gt;.
    &lt;img src="http://aliceorbob.com/aggbug.aspx?PostID=827" width="1" height="1"&gt;</description></item><item><title>Attack code for Windows flaw heightens risk</title><link>http://aliceorbob.com/blogs/charlie/archive/2006/06/27/823.aspx</link><pubDate>Tue, 27 Jun 2006 09:44:00 GMT</pubDate><guid isPermaLink="false">7df12e44-10b7-4c21-b04e-61c7aa8466eb:823</guid><dc:creator>charlie</dc:creator><slash:comments>0</slash:comments><comments>http://aliceorbob.com/blogs/charlie/comments/823.aspx</comments><wfw:commentRss>http://aliceorbob.com/blogs/charlie/commentrss.aspx?PostID=823</wfw:commentRss><description>&lt;P&gt;&lt;B&gt;Computer code that exploits a "critical" vulnerability in Windows has been released on the Internet, prompting Microsoft to issue a security advisory. &lt;/B&gt;
&lt;P&gt;The attack code takes advantage of a flawed Windows routing and remote access &lt;IMG alt="" src="http://msdn.microsoft.com/nodehomes/graphics/headlines/70x70_windows_vista.gif" align=left border=0&gt;component for which Microsoft released a patch two weeks ago, the company said in its &lt;A href="http://dw.com.com/redir?destUrl=http%3A%2F%2Fwww.microsoft.com%2Ftechnet%2Fsecurity%2Fadvisory%2F921923.mspx&amp;amp;siteId=3&amp;amp;oId=2100-1002-6088277&amp;amp;ontId=1009&amp;amp;lop=nl.ex" target=_blank&gt;&lt;FONT color=#0403ad&gt;advisory published late Friday&lt;/FONT&gt;&lt;/A&gt;. The company is not aware of any actual cyberattacks that use the exploit code, it said. &lt;/P&gt;
&lt;P&gt;&lt;A href="http://news.com.com/2100-1002_3-6088277.html?part=rss&amp;amp;tag=6088277&amp;amp;subj=news"&gt;Source: News.com&lt;/A&gt;&lt;/P&gt;&lt;img src="http://aliceorbob.com/aggbug.aspx?PostID=823" width="1" height="1"&gt;</description></item><item><title>PGP &amp;amp; GPG</title><link>http://aliceorbob.com/blogs/charlie/archive/2006/06/27/822.aspx</link><pubDate>Tue, 27 Jun 2006 09:39:00 GMT</pubDate><guid isPermaLink="false">7df12e44-10b7-4c21-b04e-61c7aa8466eb:822</guid><dc:creator>charlie</dc:creator><slash:comments>0</slash:comments><comments>http://aliceorbob.com/blogs/charlie/comments/822.aspx</comments><wfw:commentRss>http://aliceorbob.com/blogs/charlie/commentrss.aspx?PostID=822</wfw:commentRss><description>&lt;P&gt;"PGP (Pretty Good Privacy), as most &lt;A href="http://slashdot.org/"&gt;Slashdot&lt;/A&gt; readers know, is one of the most popular &lt;IMG class=ledeImg height=138 hspace=10 src="http://i.i.com.com/cnwk.1d/i/ne/p/2006/060626_microsoftemail_184x138.jpg" width=184 align=right border=0&gt;software encryption programs ever. It is so good and so effective that in the early 1990s the FBI launched a multi-year investigation against Phil Zimmerman, the creator of PGP, for possible violation of federal export laws, especially ITAR (International Traffic in Arms Regulation). After many years of investigation, the FBI ultimately dropped its case against Zimmerman. Even though PGP is synonymous with end-user encryption, there have only been a few books written on the subject. Jump to 2006, and PGP &amp;amp; GPG: Email for the Practical Paranoid is a welcome title." &lt;A href="http://books.slashdot.org/books/06/06/26/1336200.shtml"&gt;Read the rest of Ben's review&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Source: &lt;A href="http://slashdot.org/"&gt;http://slashdot.org/&lt;/A&gt;&lt;/P&gt;&lt;img src="http://aliceorbob.com/aggbug.aspx?PostID=822" width="1" height="1"&gt;</description></item><item><title>Check out the top 100 Network Security Tools</title><link>http://aliceorbob.com/blogs/charlie/archive/2006/06/23/820.aspx</link><pubDate>Fri, 23 Jun 2006 14:40:00 GMT</pubDate><guid isPermaLink="false">7df12e44-10b7-4c21-b04e-61c7aa8466eb:820</guid><dc:creator>charlie</dc:creator><slash:comments>0</slash:comments><comments>http://aliceorbob.com/blogs/charlie/comments/820.aspx</comments><wfw:commentRss>http://aliceorbob.com/blogs/charlie/commentrss.aspx?PostID=820</wfw:commentRss><description>&lt;A href="http://www.insecure.org/myworld.html"&gt;Fyodor&lt;/A&gt;&amp;nbsp;asked users from the &lt;A href="http://seclists.org/#nmap-hackers"&gt;nmap-hackers&lt;/A&gt; mailing list to share their favorite tools, and &lt;IMG class=ledeImg height=138 alt="just a pretty picture" hspace=15 src="http://i.i.com.com/cnwk.1d/i/ne/pg/fd_2005/051201_security_184x138.jpg" width=184 align=right border=0&gt;3,243 people responded. This allowed&amp;nbsp;him to expand the list to 100 tools, and even subdivide them into categories. Anyone in the security field would be well advised to go over the list and investigate tools they are unfamiliar with.&amp;nbsp;You will discover several powerful new tools this way. Any newbie, not knowing where to start should go to &lt;A href="http://sectools.org/"&gt;this site&lt;/A&gt;.&lt;img src="http://aliceorbob.com/aggbug.aspx?PostID=820" width="1" height="1"&gt;</description></item><item><title>Cryptography for kids</title><link>http://aliceorbob.com/blogs/charlie/archive/2006/06/15/809.aspx</link><pubDate>Thu, 15 Jun 2006 15:23:00 GMT</pubDate><guid isPermaLink="false">7df12e44-10b7-4c21-b04e-61c7aa8466eb:809</guid><dc:creator>admin</dc:creator><slash:comments>0</slash:comments><comments>http://aliceorbob.com/blogs/charlie/comments/809.aspx</comments><wfw:commentRss>http://aliceorbob.com/blogs/charlie/commentrss.aspx?PostID=809</wfw:commentRss><description>&lt;P&gt;Still young, but you want to be a codemaker or codebreaker? Check out the &lt;A href="http://www.nsa.gov/kids/"&gt;CryptoKids site&lt;/A&gt;.&lt;IMG height=252 alt="Image: Crypto Cat. Her quote is 'When a secret needs to be kept, you have to find a way to protect it!'" hspace=20 src="http://www.nsa.gov/kids/bios/images/BioShot_CC_html.gif" width=302 align=right&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://aliceorbob.com/aggbug.aspx?PostID=809" width="1" height="1"&gt;</description></item></channel></rss>