<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>uncompiled.com &#187; Cryptography</title>
	<atom:link href="http://www.uncompiled.com/category/cryptography/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.uncompiled.com</link>
	<description>Technology News That You Need</description>
	<lastBuildDate>Fri, 30 Jul 2010 01:19:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Researcher Reveals Major SSL and Browser Flaws</title>
		<link>http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/</link>
		<comments>http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/#comments</comments>
		<pubDate>Fri, 30 Jul 2010 01:14:14 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Browsers]]></category>
		<category><![CDATA[Conference]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[SSL]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1413</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>LAS VEGAS&#8211;A security researcher has found a slew of fundamental problems with the way that modern browsers are designed and built, leading to serious questions about the security of these applications and the way that they handle SSL sessions. </p>
<p>The research, done by Robert Hansen of SecTheory, shows that browsers such as Firefox, Internet Explorer and Chrome have a number of architectural problems that can essentially negate the security that SSL is meant to provide for sensitive Web transactions. The techniques that Hansen has developed, which he demonstrated at the Black Hat conference here Thursday, give an attacker the ability to do any number of nasty things to a target machine, including forcing the download of an executable file, overwriting the URL field in the browser and overwrite secure HTTPS cookies with non-secure cookies. </p>
<p>In all, Hansen found 24 problems before he decided to stop looking. &#8220;I had basically had to stop the research because there were just too many issues. I didn&#8217;t have time to deal with anymore,&#8221; Hansen said. </p>
<p>A big part of the problem, Hansen said in an interview, is that browsers don&#8217;t enforce policies that would isolate the tabs in an open browser from one another. This allows an attacker who can control one of the tabs, say a normal non-SSL session, to also affect content in the other tabs, even if they&#8217;re using SSL. Hansen identified several techniques that enable him to watch an SSL-protected session and glean a lot of information about what the user is doing, based on timing certain parts of the Web session and knowing how long it takes for part of a site to load. He also can tell whether a user is logged in on a given site and use a specific technique to log the user out so he can then watch the login operation and steal the credentials.</p>
<p>&#8220;When you look at it, what does SSL really offer? What this means is that for the average user, against a determined adversary, there really is no protection,&#8221; said Hansen, who presented his findings at the Black Hat conference here Thursday. &#8220;People give SSL and TLS a lot of credit, when it shouldn&#8217;t have any at all.&#8221;</p>
<p>SSL is the main transport security used by millions of Web sites to protect data being sent from browsers to Web servers. It&#8217;s been shown to be vulnerable to a number of different attacks, including several man-in-the-middle attacks, which could be used in conjunction with some of Hansen&#8217;s techniques to completely compromise a supposedly secure Web session.</p>
<p>&#8220;The most important thing is that if an attacker can map out the domain ahead of time, he can get a really good feel for how the site is built,&#8221; Hansen said. &#8220;If there&#8217;s a side channel, I can force them to precache some of the content on the page so that I don&#8217;t see that again when they reload the page. Then, the only thing you&#8217;re seeing are the things that are interesting to the attacker. You can map out the user&#8217;s flow around the site and the attacker can force the user to make an SSL connection to them so they can tell which SSL and HTTP headers are being sent in which direction. It&#8217;s about narrowing down the number of bytes that are interesting.&#8221;</p>
<p>As troubling as the problems that Hansen found are, he emphasized that they don&#8217;t mean that the sky is falling. </p>
<p>&#8220;You still need to be a man in the middle first and there are probably easier ways to attack people once you are, but there are a lot of issues here,&#8221; he said. &#8220;If there was better jitter and padding in SSL, a lof of this wouldn&#8217;t even be possible.&#8221;</p>
<p><a href="http://threatpost.com/en_us/blogs/researcher-reveals-major-ssl-and-browser-flaws-072910">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;n=Researcher+Reveals+Major+SSL+and+Browser+Flaws&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;title=Researcher+Reveals+Major+SSL+and+Browser+Flaws" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;t=Researcher+Reveals+Major+SSL+and+Browser+Flaws" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;title=Researcher+Reveals+Major+SSL+and+Browser+Flaws" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;title=Researcher+Reveals+Major+SSL+and+Browser+Flaws&amp;srcUrl=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;srcTitle=Researcher+Reveals+Major+SSL+and+Browser+Flaws&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;title=Researcher+Reveals+Major+SSL+and+Browser+Flaws&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Researcher%20Reveals%20Major%20SSL%20and%20Browser%20Flaws%22&amp;body=Link: http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;t=Researcher+Reveals+Major+SSL+and+Browser+Flaws" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;title=Researcher+Reveals+Major+SSL+and+Browser+Flaws&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;title=Researcher+Reveals+Major+SSL+and+Browser+Flaws" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;title=Researcher+Reveals+Major+SSL+and+Browser+Flaws" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Researcher+Reveals+Major+SSL+and+Browser+Flaws+-+http://b2l.me/admsaw&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/&amp;submitHeadline=Researcher+Reveals+Major+SSL+and+Browser+Flaws&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Researcher+Reveals+Major+SSL+and+Browser+Flaws&amp;body=Link: http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/07/researcher-reveals-major-ssl-and-browser-flaws/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Police force more suspects to give up crypto keys</title>
		<link>http://www.uncompiled.com/2010/07/police-force-more-suspects-to-give-up-crypto-keys/</link>
		<comments>http://www.uncompiled.com/2010/07/police-force-more-suspects-to-give-up-crypto-keys/#comments</comments>
		<pubDate>Wed, 28 Jul 2010 16:40:05 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Legal]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1408</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Police have expanded their use of powers to force suspects to decrypt files by 50 per cent in the last year, figures released today reveal.</p>
<p>In the 12 months to March 31 this year, government officials approved 38 notices under Part III of the Regulation of Investigatory Powers Act, compared to 26 in the previous year.</p>
<p>The powers, known as section 49 notices, require suspects to hand over passwords or make files intelligible to investigators on threat of a two-year jail sentence, or five years where national security is concerned.</p>
<p>As well as obtaining more section 49 notices, police also expanded the range of crimes they were used to investigate.</p>
<p>In 2008/09 they were served in relation to counter-terrorism, possiession of indecent images of children and &#8220;domestic extremism&#8221; (a case involving activist attacks on animal testing labs). In the last 12 months, however, RIPA Part III was used to demand decryption in cases of insider dealing, illegal broadcasting, theft, excise duty evasion and aggravated burglary, the Chief Surveillance Commissioner Sir Christopher Rose said in his annual report.</p>
<p>Investigations into indecent images of children remained the &#8220;main reason&#8221; section 49 notices were served, he added.</p>
<p>Of the 17 notices obtained this year that have so far been served, six suspects complied and seven did not. The remainder are still being processed. One person suspected of possessing indecent images of children has been convicted for failing to hand over passwords.</p>
<p>The compliance rate was up on last year, the first full year since the powers were activated, when 11 out of 15 suspects served with a section 49 notice did not make their files intelligible to investigators.</p>
<p>Sir Christopher noted the discrepancy between 38 approvals granted by the National Technical Assistance Centre (NTAC) and the number of notices actually served. NTAC is a unit at GCHQ, the Cheltenham code-breaking agency.</p>
<p>&#8220;Notices, once approved, should be served without delay,&#8221; Sir Christopher said. &#8220;If delays continue, I will require an explanation.&#8221;</p>
<p>Last year The Register reported the case of the first man known to have been jailed for failing to hand over encryption keys to the police. &#8220;JFL&#8221; was a schizophrenic software developer initially charged with explosives offences that were later dropped. He was sectioned under the Mental Health Act during his prison sentence. </p>
<p><a href="http://www.theregister.co.uk/2010/07/27/ripa_iii/">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/07/police-force-more-suspects-to-give-up-crypto-keys/&amp;n=Police+force+more+suspects+to+give+up+crypto+keys&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/07/police-force-more-suspects-to-give-up-crypto-keys/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/07/police-force-more-suspects-to-give-up-crypto-keys/&amp;title=Police+force+more+suspects+to+give+up+crypto+keys" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/07/police-force-more-suspects-to-give-up-crypto-keys/&amp;t=Police+force+more+suspects+to+give+up+crypto+keys" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/07/police-force-more-suspects-to-give-up-crypto-keys/&amp;title=Police+force+more+suspects+to+give+up+crypto+keys" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/07/police-force-more-suspects-to-give-up-crypto-keys/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/07/police-force-more-suspects-to-give-up-crypto-keys/&amp;title=Police+force+more+suspects+to+give+up+crypto+keys&amp;srcUrl=http://www.uncompiled.com/2010/07/police-force-more-suspects-to-give-up-crypto-keys/&amp;srcTitle=Police+force+more+suspects+to+give+up+crypto+keys&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/07/police-force-more-suspects-to-give-up-crypto-keys/&amp;title=Police+force+more+suspects+to+give+up+crypto+keys&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Police%20force%20more%20suspects%20to%20give%20up%20crypto%20keys%22&amp;body=Link: http://www.uncompiled.com/2010/07/police-force-more-suspects-to-give-up-crypto-keys/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/07/police-force-more-suspects-to-give-up-crypto-keys/&amp;t=Police+force+more+suspects+to+give+up+crypto+keys" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/07/police-force-more-suspects-to-give-up-crypto-keys/&amp;title=Police+force+more+suspects+to+give+up+crypto+keys&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/07/police-force-more-suspects-to-give-up-crypto-keys/&amp;title=Police+force+more+suspects+to+give+up+crypto+keys" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/07/police-force-more-suspects-to-give-up-crypto-keys/&amp;title=Police+force+more+suspects+to+give+up+crypto+keys" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/07/police-force-more-suspects-to-give-up-crypto-keys/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Police+force+more+suspects+to+give+up+crypto+keys+-+http://b2l.me/adajxz&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/07/police-force-more-suspects-to-give-up-crypto-keys/&amp;submitHeadline=Police+force+more+suspects+to+give+up+crypto+keys&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Police+force+more+suspects+to+give+up+crypto+keys&amp;body=Link: http://www.uncompiled.com/2010/07/police-force-more-suspects-to-give-up-crypto-keys/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/07/police-force-more-suspects-to-give-up-crypto-keys/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Heartland ramps up first end-to-end encryption</title>
		<link>http://www.uncompiled.com/2010/07/heartland-ramps-up-first-end-to-end-encryption/</link>
		<comments>http://www.uncompiled.com/2010/07/heartland-ramps-up-first-end-to-end-encryption/#comments</comments>
		<pubDate>Thu, 01 Jul 2010 13:43:48 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Breach]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Financial]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1357</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Heartland Payment Systems, the victim last year of a massive data breach of sensitive card data, vowed after that devastating event to develop new security gear based on end-to-end encryption between itself and its merchants to prevent such a breach from occurring again. That&#8217;s now taking shape, but slowly.</p>
<p>&#8220;We have a long way to go,&#8221; acknowledges Heartland CEO Bob Carr, pointing out the so-called E3 payment terminals, intended for small-to-midsize customers, are but the first step, &#8220;with more advanced technologies coming in the summer&#8221; intended for use between Heartland&#8217;s network and much larger merchants that would require more back-end integration into processing systems. &#8220;We&#8217;re not ready to help all of them yet,&#8221; he acknowledges.</p>
<p>There is as of yet no end-to-end encryption requirement for debit- and credit-card processing, though the Payment Card Industry (PCI) Security Standards Council, which sets technical standards used by payment processors and merchants, is expected to weigh in on that topic in its upcoming PCI standard this October.</p>
<p>Unwilling to delay action after last year&#8217;s devastating discovery of a data breach that has so far cost it well over $100 million in fines and associated costs, Heartland has spearheaded its own multi-million-dollar end-to-end encryption technology effort to keep cybercriminals at bay. (Hacker Albert Gonzalez was caught and confessed to hacking Heartland&#8217;s processing network and much more, and this March was sentenced to 20 years in prison.</p>
<p>&#8220;Every single breach I know of wouldn&#8217;t have happened if our end-to-end encryption solution had been there,&#8221; Carr says. He believes Heartland is the first to come out with a commercial deployment of end-to-end encryption with merchants.</p>
<p>Carr says the definition of end-to-end encryption may end up varying, but in the case of Heartland, it means protecting card data, particularly the track data, as it&#8217;s being swiped at the merchant to the entry point to Heartland&#8217;s network, and encrypted on through Heartland&#8217;s network. However, this encryption now stops at the card brand point, such as Visa and MasterCard, and isn&#8217;t encrypted on through to the banking points.</p>
<p>Carr thinks the most vulnerable points that hackers will try to exploit are in the interconnections between merchant and payments processor, but he acknowledges that as the industry evolves to better protect these routes, hackers will undoubtedly look for the weakest link in the chain.</p>
<p>The E3 terminals, built by Voltage Security and Uniform Industrial Corp., were custom ordered by Heartland, which isn&#8217;t requiring its merchants to use them, but strongly recommending them.</p>
<p>&#8220;They do have to buy the devices,&#8221; Carr says, noting they range between $300 to $500, which Heartland will finance for six months if merchants have cash-flow issues. But one incentive for using E3 is a guarantee from Heartland that if merchants using E3 are breached, Heartland will cover fines and forensic costs related to any breach tied to the stand-alone terminals. Heartland is also offering free help to smaller merchants in filling out PCI standard conformance forms, something that can be technically bewildering to them.</p>
<p>One looming issue in end-to-end encryption is interoperability if the industry adopts more robust processes for protection through encryption. But Carr is optimistic the industry will meet the challenge, saying the PCI Security Standards Council &#8220;is listening hard and being responsive.&#8221;</p>
<p><a href="http://www.networkworld.com/news/2010/063010-heartland-end-to-end-encryption.html">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/07/heartland-ramps-up-first-end-to-end-encryption/&amp;n=Heartland+ramps+up+first+end-to-end+encryption&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/07/heartland-ramps-up-first-end-to-end-encryption/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/07/heartland-ramps-up-first-end-to-end-encryption/&amp;title=Heartland+ramps+up+first+end-to-end+encryption" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/07/heartland-ramps-up-first-end-to-end-encryption/&amp;t=Heartland+ramps+up+first+end-to-end+encryption" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/07/heartland-ramps-up-first-end-to-end-encryption/&amp;title=Heartland+ramps+up+first+end-to-end+encryption" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/07/heartland-ramps-up-first-end-to-end-encryption/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/07/heartland-ramps-up-first-end-to-end-encryption/&amp;title=Heartland+ramps+up+first+end-to-end+encryption&amp;srcUrl=http://www.uncompiled.com/2010/07/heartland-ramps-up-first-end-to-end-encryption/&amp;srcTitle=Heartland+ramps+up+first+end-to-end+encryption&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/07/heartland-ramps-up-first-end-to-end-encryption/&amp;title=Heartland+ramps+up+first+end-to-end+encryption&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Heartland%20ramps%20up%20first%20end-to-end%20encryption%22&amp;body=Link: http://www.uncompiled.com/2010/07/heartland-ramps-up-first-end-to-end-encryption/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/07/heartland-ramps-up-first-end-to-end-encryption/&amp;t=Heartland+ramps+up+first+end-to-end+encryption" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/07/heartland-ramps-up-first-end-to-end-encryption/&amp;title=Heartland+ramps+up+first+end-to-end+encryption&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/07/heartland-ramps-up-first-end-to-end-encryption/&amp;title=Heartland+ramps+up+first+end-to-end+encryption" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/07/heartland-ramps-up-first-end-to-end-encryption/&amp;title=Heartland+ramps+up+first+end-to-end+encryption" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/07/heartland-ramps-up-first-end-to-end-encryption/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Heartland+ramps+up+first+end-to-end+encryption+-+http://b2l.me/73pxs&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/07/heartland-ramps-up-first-end-to-end-encryption/&amp;submitHeadline=Heartland+ramps+up+first+end-to-end+encryption&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Heartland+ramps+up+first+end-to-end+encryption&amp;body=Link: http://www.uncompiled.com/2010/07/heartland-ramps-up-first-end-to-end-encryption/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/07/heartland-ramps-up-first-end-to-end-encryption/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SSL Certificates In Use Today Aren&#8217;t All Valid</title>
		<link>http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/</link>
		<comments>http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/#comments</comments>
		<pubDate>Tue, 29 Jun 2010 13:19:17 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Industry]]></category>
		<category><![CDATA[Infrastructure]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[SSL]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1347</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>It should be no surprise that the SSL security certificate business is big business, considering how SSL certificates are seen as being on the frontlines of securing Web transactions against fraud. But new data suggests that SSL certificates are not all being configured correctly.</p>
<p>Security research firm Qualys is attempting to paint a detailed picture of SSL deployments and their shortcomings with a new, still under-development study that aims to deliver a deeper degree of information on the state of the SSL marketplace than what is currently known. Most industry intelligence on the subject thus far has come from Netcraft research reports and from vendor reports.</p>
<p>In its study, Qualys scanned 119 million domain names, but found that only 92 million were active. Approximately 12.4 million domains failed to resolve properly and 14.6 million failed to respond. Of the active domains that did respond, nearly 34 million responded to the Qualys scan on both port 80 and port 443. Port 80 is typically used for HTTP while port 443 is typically used for HTTPS-, SSL-secured Websites.</p>
<p>Digging a layer deeper into the active sites on Port 443, Ivan Ristic, director of engineering at Qualys, said in a Webcast that he found that only about 23 million of the sites were actually running SSL.</p>
<p>SSL certificates can be generated for any domain name. It is considered to be a best practice that the name on the SSL certificate matches the name of the domain on which the SSL certificate is being used, though Ristic&#8217;s research shows that&#8217;s not always the case.</p>
<p>&#8220;Only about 3.17 percent of the domain names matched,&#8221; Ristic said. &#8220;So we have about 22 million SSL servers with certificates that are completely invalid because they do not match the domain name on which they reside.&#8221;</p>
<p>Detecting invalid SSL certificates<br />
In a preview of a talk set to be delivered at this summer&#8217;s Black Hat USA conference, Ristic explained that his company has had an SSL security-checking service available publicly for some time. However, the Qualys SSL checker required that users came to the site to check their own SSL status. With the new research conducted by Ristic, Qualys set about scanning the Internet to collect information on how sites are implementing SSL.</p>
<p>&#8220;For us, the question is: How exactly is SSL used on the Internet as a whole?&#8221; Ristic said during the Webcast. &#8220;Interestingly enough, as popular as SSL is, no one had made public the information about how it is used.&#8221;</p>
<p>According to VeriSign, there are currently approximately 193 million domain names. In terms of SSL, Netcraft reports that there are 1.5 million SSL certificates. Ristic decided to focus his research on the total number of .com, .net, .org, .biz, .us and .info domains, which total 119 million domain names in total.</p>
<p>Ristic explained that he built a virtual machine that was able to run 2,000 threads in parallel to scan those millions of domain names. The process took him two days at a speed of 1,000 servers scanned per second.</p>
<p>In response to a question from InternetNews.com about his testing hardware and software infrastructure, Ristic noted that the scanning software had been custom-written for the task.</p>
<p>&#8220;The hardware was nothing special &#8212; I&#8217;m using a virtual server in the cloud and it&#8217;s just a medium-sized box,&#8221; Ristic said. &#8220;The trick to why the tests are quick is that it&#8217;s only a couple of network packets that are being exchanged, and that&#8217;s enough to determine if the server on the other side is capable of supporting the protocol.&#8221;</p>
<p>As part of the complete report that he is working on, Ristic said that he&#8217;ll be doing a deeper analysis of 720,000 SSL certificates that he uncovered in his initial scan and considers valid. The plan is to collect up to 300 data points on each SSL server to better understand how the certificates are deployed and configured.</p>
<p><a href="http://www.esecurityplanet.com/features/article.php/3890171/SSL-Certificates-In-Use-Today-Arent-All-Valid.htm">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;n=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;title=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;t=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;title=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;title=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid&amp;srcUrl=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;srcTitle=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;title=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22SSL%20Certificates%20In%20Use%20Today%20Aren%27t%20All%20Valid%22&amp;body=Link: http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;t=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;title=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;title=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;title=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid+-+http://b2l.me/7j2qh&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/&amp;submitHeadline=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=SSL+Certificates+In+Use+Today+Aren%27t+All+Valid&amp;body=Link: http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/06/ssl-certificates-in-use-today-arent-all-valid/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Brazilian banker&#8217;s crypto baffles FBI</title>
		<link>http://www.uncompiled.com/2010/06/brazilian-bankers-crypto-baffles-fbi/</link>
		<comments>http://www.uncompiled.com/2010/06/brazilian-bankers-crypto-baffles-fbi/#comments</comments>
		<pubDate>Mon, 28 Jun 2010 13:08:29 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Legal]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1341</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>Cryptographic locks guarding the secret files of a Brazilian banker suspected of financial crimes have defeated law enforcement officials.</p>
<p>Brazilian police seized five hard drives when they raided the Rio apartment of banker Daniel Dantas as part of Operation Satyagraha in July 2008. But subsequent efforts to decrypt files held on the hardware using a variety of dictionary-based attacks failed even after the South Americans called in the assistance of the FBI.</p>
<p>The files were encrypted using Truecrypt and an unnamed algorithm, reportedly based on the 256-bit AES standard. In the UK, Dantas would be compelled to reveal his passphrase under threat of imprisonment, but no such law exists in Brazil.</p>
<p>The Brazilian National Institute of Criminology (INC) tried for five months to obtain access to the encrypted data without success before turning over the job to code-breakers at the FBI in early 2009. US computer specialists also drew a blank even after 12 months of efforts to crack the code, Brazil&#8217;s El Globo newspaper reports.</p>
<p>The case is an illustration of how care in choosing secure (hard-to-guess) passwords and applying encryption techniques to avoid leaving file fragments that could aid code breakers are more important in maintaining security than the algorithm a code maker chooses. In other cases, law enforcement officials have defeated suspects&#8217; use of encryption because of weak cryptographic trade craft or poor passwords, rather than inherent flaws in encryption packages.</p>
<p><a href="http://www.theregister.co.uk/2010/06/28/brazil_banker_crypto_lock_out/">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/06/brazilian-bankers-crypto-baffles-fbi/&amp;n=Brazilian+banker%27s+crypto+baffles+FBI&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/06/brazilian-bankers-crypto-baffles-fbi/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/06/brazilian-bankers-crypto-baffles-fbi/&amp;title=Brazilian+banker%27s+crypto+baffles+FBI" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/06/brazilian-bankers-crypto-baffles-fbi/&amp;t=Brazilian+banker%27s+crypto+baffles+FBI" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/06/brazilian-bankers-crypto-baffles-fbi/&amp;title=Brazilian+banker%27s+crypto+baffles+FBI" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/06/brazilian-bankers-crypto-baffles-fbi/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/06/brazilian-bankers-crypto-baffles-fbi/&amp;title=Brazilian+banker%27s+crypto+baffles+FBI&amp;srcUrl=http://www.uncompiled.com/2010/06/brazilian-bankers-crypto-baffles-fbi/&amp;srcTitle=Brazilian+banker%27s+crypto+baffles+FBI&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/06/brazilian-bankers-crypto-baffles-fbi/&amp;title=Brazilian+banker%27s+crypto+baffles+FBI&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Brazilian%20banker%27s%20crypto%20baffles%20FBI%22&amp;body=Link: http://www.uncompiled.com/2010/06/brazilian-bankers-crypto-baffles-fbi/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/06/brazilian-bankers-crypto-baffles-fbi/&amp;t=Brazilian+banker%27s+crypto+baffles+FBI" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/06/brazilian-bankers-crypto-baffles-fbi/&amp;title=Brazilian+banker%27s+crypto+baffles+FBI&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/06/brazilian-bankers-crypto-baffles-fbi/&amp;title=Brazilian+banker%27s+crypto+baffles+FBI" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/06/brazilian-bankers-crypto-baffles-fbi/&amp;title=Brazilian+banker%27s+crypto+baffles+FBI" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/06/brazilian-bankers-crypto-baffles-fbi/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Brazilian+banker%27s+crypto+baffles+FBI+-+http://b2l.me/7b82t&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/06/brazilian-bankers-crypto-baffles-fbi/&amp;submitHeadline=Brazilian+banker%27s+crypto+baffles+FBI&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Brazilian+banker%27s+crypto+baffles+FBI&amp;body=Link: http://www.uncompiled.com/2010/06/brazilian-bankers-crypto-baffles-fbi/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/06/brazilian-bankers-crypto-baffles-fbi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Introducing TGP&#8230;</title>
		<link>http://www.uncompiled.com/2010/06/introducing-tgp/</link>
		<comments>http://www.uncompiled.com/2010/06/introducing-tgp/#comments</comments>
		<pubDate>Mon, 14 Jun 2010 13:58:12 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Computer Science]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Release]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1303</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>This is what I&#8217;ve been talking about&#8230; Here is the first part of the docs I wrote up &#8211; make sure you see that I&#8217;m not<br />
yet supporting huge files unless you have huge RAM.  **.Net 4.0 Client profile is required to run this.**</p>
<p>Right now the install bits are only available on the pilot site at: http://www.owa.hammerofgod.com in the downloads<br />
section.   I have to wait on Raging Haggis to return from Canada before posting on<br />
www.hammerofgod.com<http ://www.hammerofgod.com> .</p>
<p>Here&#8217;s a bit from the TGP Overview document included with the install and on the web site.  Please read through it<br />
before asking silly questions. :)</p>
<p>Also, feel free to hack it up as much as you would like.  I know this is full disclosure, so feel free to zing them at<br />
me, or if you prefer, I can work with you on any issues you might have.</p>
<p>Remember, this is totally free, so my ability to handle custom requests will be limited.  For those looking to break<br />
it, I would look at fuzzing the XML documents and the &#8220;drag and drop public XML&#8221; parsing feature.</p>
<p>If you have questions or challenges about any of the security, I would ask to keep it on the list so that everyone can<br />
get the full benefit of productive security development.   The read-me should pretty much lay everything out for you.<br />
If not, we&#8217;ll take it up from there.</p>
<p>t</p>
<p>TGP &#8211; &#8220;Thor&#8217;s Godly Privacy&#8221;<br />
06/13/10 v1.1.06</p>
<p>TGP is a small yet very powerful encryption utility.  With all eyes on &#8220;the cloud,&#8221; I decided to write an encryption<br />
application better suited to an environment where portability and security were, at the least, challenging.   In cloud<br />
computing, not only is the use of file structures becoming more abstract, but the very concept of a &#8220;file server&#8221; is<br />
becoming more and more ubiquitous.</p>
<p>As such, I designed TGP with &#8220;encryption for the cloud&#8221; in mind.  That means that not only does TGP do everything your<br />
normal PGP-type applications do, but it does things a bit differently &#8211; differently in a way that can change the way<br />
you work with your encrypted data.  At the simplest level, this is done by encrypting data into byte arrays, and then<br />
converting those byte arrays into Base64 encoded text wrapped inside XML tags.  In this way, not only do you get your<br />
typical file-based encrypted representation of your data, but you also get data that you can copy and paste directly<br />
into any email, mailing list, blog-page, or social networking site.</p>
<p>What I think is interesting about this is that if we choose to, we no longer have to be the custodians of our encrypted<br />
data &#8211; we don&#8217;t have to worry about actually housing the files: we can just post them to the internet and let someone<br />
else assume the burden of storing the files for us.</p>
<p>If I want to share encrypted files with someone or secure my own files, all I have to do is TGP encrypt the data I<br />
want, and post it to a mailing list somewhere.  In the case of a list like Bugtraq or Full Disclosure, the data is<br />
actually automatically replicated out to any number of archive sites, thus distributing my data for me.  I can<br />
literally be anywhere in the world and just do a quick search for my post to retrieve my data.  And since the TGP<br />
public key files are also text representations of encrypted key data, I can do the same with my keys.</p>
<p>Normally, you want to keep your private keys as safe as possible.  This is still the case with TGP.  However, it is<br />
trivial to build as many private keys as you wish to use for anything you want to use them for.  TGP Private Key files<br />
are password protected and individually salted, so with a strong passphrase you have very reasonable assurance that no<br />
one is going to get to your key any time soon.  So, you can create a private key with a strong password, post that, and<br />
then, say, encrypt a scan of your passport and post that.  Then if you are ever in a pinch while travelling or<br />
something like that, you can simply use Google or Bing to access your data wherever you are.</p>
<p>Of course, that&#8217;s just an example, but I think it illustrates the power of encrypted file structures like this.  You<br />
can literally use Facebook to post encrypted documents that you don&#8217;t have to maintain.</p>
<p>That&#8217;s really the main different between TGP and an application like PGP.  That and of course, TGP is free, and<br />
personally, I think PGP is tardware.  It&#8217;s bloated, it&#8217;s far too expensive, it&#8217;s hard to use, and if you don&#8217;t watch<br />
your licensing, you can get screwed hard like I did when I didn&#8217;t want to buy the extended support and one day my<br />
encrypted drives stopped working until I paid them.  That doesn&#8217;t fly.  TGP also doesn&#8217;t require that you are an admin<br />
to install.  However, the .NET installer for the 4.0 client profile does &#8211; that&#8217;s not my doing.  Regardless, here are<br />
the file structures TGP uses:</p>
<p>Things that still suck about TGP<br />
Currently TGP uses a memory stream for the destination of the AES cryptostream.  This sucks because it makes the<br />
maximum file one can encrypt based on available memory.  It&#8217;s not a huge deal, but it does keep you from encrypting a<br />
gigabyte file.  I&#8217;ll be changing that soon.</p>
<p>[Description: Description: Description: TimSig]<br />
Timothy &#8220;Thor&#8221; Mullen<br />
Hammer of God<br />
thor () hammerofgod com<mailto :thor () hammerofgod com><br />
www.hammerofgod.com<http ://www.hammerofgod.com><br />
[cid:image002.png@01CB0B06.EED273B0]</p>
<p><a href="http://seclists.org/fulldisclosure/2010/Jun/294">Source</a>      </http></mailto></http></p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/06/introducing-tgp/&amp;n=Introducing+TGP...&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/06/introducing-tgp/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/06/introducing-tgp/&amp;title=Introducing+TGP..." rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/06/introducing-tgp/&amp;t=Introducing+TGP..." rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/06/introducing-tgp/&amp;title=Introducing+TGP..." rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/06/introducing-tgp/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/06/introducing-tgp/&amp;title=Introducing+TGP...&amp;srcUrl=http://www.uncompiled.com/2010/06/introducing-tgp/&amp;srcTitle=Introducing+TGP...&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/06/introducing-tgp/&amp;title=Introducing+TGP...&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Introducing%20TGP...%22&amp;body=Link: http://www.uncompiled.com/2010/06/introducing-tgp/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/06/introducing-tgp/&amp;t=Introducing+TGP..." rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/06/introducing-tgp/&amp;title=Introducing+TGP...&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/06/introducing-tgp/&amp;title=Introducing+TGP..." rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/06/introducing-tgp/&amp;title=Introducing+TGP..." rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/06/introducing-tgp/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Introducing+TGP...+-+http://b2l.me/3pnta&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/06/introducing-tgp/&amp;submitHeadline=Introducing+TGP...&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Introducing+TGP...&amp;body=Link: http://www.uncompiled.com/2010/06/introducing-tgp/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/06/introducing-tgp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Archive project will digitize WWII Enigma messages</title>
		<link>http://www.uncompiled.com/2010/06/archive-project-will-digitize-wwii-enigma-messages/</link>
		<comments>http://www.uncompiled.com/2010/06/archive-project-will-digitize-wwii-enigma-messages/#comments</comments>
		<pubDate>Sat, 05 Jun 2010 13:11:08 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Military]]></category>
		<category><![CDATA[Nostalgia]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1277</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>During World War II, Britain&#8217;s brightest minds routinely decoded encrypted German military messages, an effort believed to have significantly shortened the war and saved the country further devastation.</p>
<p>The mathematicians and cryptography experts at Bletchley Park broke the code used by Germany&#8217;s Enigma machine, a complex encryption device used across the German military. By January 1940, Britain was decoding the majority of the Enigma-encrypted radio messages intercepted by its signal intelligence stations.</p>
<p>Since then, buildings on the 25-acre Bletchley Park estate have fallen into disrepair: At one stage the site was close to being demolished to make way for a supermarket and housing development, and efforts to raise money to preserve it have struggled.</p>
<p>Existing funds have been consumed by emergency infrastructure repairs such as keeping the roofs of buildings from caving in, said Simon Greenish, director and CEO of Bletchley Park Trust. Preserving the core of Bletchley Park&#8217;s heritage &#8212; the intercepted messages &#8212; was far down the list of priorities, he said.</p>
<p>Those messages are still in the building&#8217;s archive after more than six decades, neatly typed on trimmed slips of paper and glued into fragile, decaying books. Also in the archive are drawers full of maps and a system of index cards used to classify messages by subject.</p>
<p>With the archive building&#8217;s roof among those that needed fixing earlier this year, the flimsy documents stored there &#8220;really ought to be properly dealt with,&#8221; Greenish said.</p>
<p>That is starting to happen, with the launch of a project to digitize the documents in the archive and make them accessible to the public.</p>
<p>Hewlett-Packard has donated servers, storage and five of its latest enterprise-level Scanjet scanners to get the project going, said Laura Seymour, marketing manager for HP&#8217;s LaserJet and enterprise solutions. The company has also assigned consultants to help train volunteers and Bletchley staff on the equipment.</p>
<p>Volunteers will use HP&#8217;s Scanjet 7000 to scan the index cards used to classify messages. Once the cryptanalysts had decoded a message, a summary of it would be written on an index card and filed under a subject heading to make it easy to find groups of related messages. The cards &#8212; which number in the tens of thousands &#8212; are handwritten in cursive, often on both sides.</p>
<p>The Scanjet 7000 can scan both sides of the cards quickly in batches. The scanner can detect if a card has been incorrectly fed or if two cards are stuck together. A larger flatbed scanner, such as HP&#8217;s N9120, will be used for the books containing the actual messages. The pages of those books will have to be turned by hand in order to scan them since they are too fragile for automated page-turning scanners.</p>
<p>Another bit of technology can help compensate if an index card&#8217;s writing is fading. HP&#8217;s Kofax Virtual rescan software inspects the material, then adjusts its brightness and contrast for clarity so that the image is more readable, said Mander Thiara, a specialist with HP&#8217;s imaging and printing group.</p>
<p><a href="http://www.networkworld.com/news/2010/060510-archive-project-will-digitize-wwii.html">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/06/archive-project-will-digitize-wwii-enigma-messages/&amp;n=Archive+project+will+digitize+WWII+Enigma+messages&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/06/archive-project-will-digitize-wwii-enigma-messages/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/06/archive-project-will-digitize-wwii-enigma-messages/&amp;title=Archive+project+will+digitize+WWII+Enigma+messages" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/06/archive-project-will-digitize-wwii-enigma-messages/&amp;t=Archive+project+will+digitize+WWII+Enigma+messages" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/06/archive-project-will-digitize-wwii-enigma-messages/&amp;title=Archive+project+will+digitize+WWII+Enigma+messages" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/06/archive-project-will-digitize-wwii-enigma-messages/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/06/archive-project-will-digitize-wwii-enigma-messages/&amp;title=Archive+project+will+digitize+WWII+Enigma+messages&amp;srcUrl=http://www.uncompiled.com/2010/06/archive-project-will-digitize-wwii-enigma-messages/&amp;srcTitle=Archive+project+will+digitize+WWII+Enigma+messages&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/06/archive-project-will-digitize-wwii-enigma-messages/&amp;title=Archive+project+will+digitize+WWII+Enigma+messages&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Archive%20project%20will%20digitize%20WWII%20Enigma%20messages%22&amp;body=Link: http://www.uncompiled.com/2010/06/archive-project-will-digitize-wwii-enigma-messages/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/06/archive-project-will-digitize-wwii-enigma-messages/&amp;t=Archive+project+will+digitize+WWII+Enigma+messages" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/06/archive-project-will-digitize-wwii-enigma-messages/&amp;title=Archive+project+will+digitize+WWII+Enigma+messages&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/06/archive-project-will-digitize-wwii-enigma-messages/&amp;title=Archive+project+will+digitize+WWII+Enigma+messages" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/06/archive-project-will-digitize-wwii-enigma-messages/&amp;title=Archive+project+will+digitize+WWII+Enigma+messages" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/06/archive-project-will-digitize-wwii-enigma-messages/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Archive+project+will+digitize+WWII+Enigma+messages+-+http://b2l.me/zdvc2&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/06/archive-project-will-digitize-wwii-enigma-messages/&amp;submitHeadline=Archive+project+will+digitize+WWII+Enigma+messages&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Archive+project+will+digitize+WWII+Enigma+messages&amp;body=Link: http://www.uncompiled.com/2010/06/archive-project-will-digitize-wwii-enigma-messages/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/06/archive-project-will-digitize-wwii-enigma-messages/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenSSL updates fix vulnerabilities</title>
		<link>http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/</link>
		<comments>http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/#comments</comments>
		<pubDate>Thu, 03 Jun 2010 18:52:24 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Open-Source]]></category>
		<category><![CDATA[Release]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1271</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>The OpenSSL developers have released versions 0.9.8o and 1.0.0a, fixing two security problems. A flaw in the ASN.1 parser can be exploited to write to invalid memory addresses using specially crafted &#8220;Cryptographic Message Syntax&#8221; (CMS) structures. The flaw potentially allows arbitrary code to be injected in order to compromise a system. CMS is not enabled by default in the 0.9.8 branch of OpenSSL, but it is enabled in the 1.0.0 branch.</p>
<p>An uninitialised buffer in the EVP_PKEY_verify_recover() function in version 1.0.0 can be exploited to make an invalid RSA key appear to be valid. Since very few applications have used this recently-introduced function, the scope of this problem is limited. The OpenSSL developers say that pkeyutl is currently one of the only OpenSSL tools to access this function.</p>
<p><a href="http://www.h-online.com/security/news/item/OpenSSL-updates-fix-vulnerabilities-1014786.html">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;n=OpenSSL+updates+fix+vulnerabilities&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;title=OpenSSL+updates+fix+vulnerabilities" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;t=OpenSSL+updates+fix+vulnerabilities" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;title=OpenSSL+updates+fix+vulnerabilities" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;title=OpenSSL+updates+fix+vulnerabilities&amp;srcUrl=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;srcTitle=OpenSSL+updates+fix+vulnerabilities&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;title=OpenSSL+updates+fix+vulnerabilities&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22OpenSSL%20updates%20fix%20vulnerabilities%22&amp;body=Link: http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;t=OpenSSL+updates+fix+vulnerabilities" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;title=OpenSSL+updates+fix+vulnerabilities&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;title=OpenSSL+updates+fix+vulnerabilities" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;title=OpenSSL+updates+fix+vulnerabilities" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=OpenSSL+updates+fix+vulnerabilities+-+http://b2l.me/yxgcu&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/&amp;submitHeadline=OpenSSL+updates+fix+vulnerabilities&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=OpenSSL+updates+fix+vulnerabilities&amp;body=Link: http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/06/openssl-updates-fix-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Should we be encrypting backups?</title>
		<link>http://www.uncompiled.com/2010/06/should-we-be-encrypting-backups/</link>
		<comments>http://www.uncompiled.com/2010/06/should-we-be-encrypting-backups/#comments</comments>
		<pubDate>Wed, 02 Jun 2010 13:42:19 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Data Recovery]]></category>
		<category><![CDATA[Infrastructure]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Storage]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1228</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>We all know that data protection regulations are gaining teeth. As we discussed before, it is becoming more difficult to keep data losses private, and the damage to reputation and other penalties incurred following data breaches are now significant.</p>
<p>Data protection laws in particular are being tightened up, with the potential for large financial penalties to be imposed for the loss or leakage of data. Fines may come not only from general data protection bodies, but also individual industry regulators in verticals such as financial services or healthcare. Data breach notification laws, pioneered very effectively by California, are planned for Europe. These have shown that the real cost of a data loss is the clean-up afterwards. Companies suffer from the loss of reputation and trust in a brand, as well as having to foot the bill for fraud monitoring, credit protection and possible recompense for those people affected.</p>
<p>Now, you may well be thinking: &#8220;That&#8217;s all well and good, but how does it affect me?&#8221; Legislation is effectively raising the bar and sending a message that dealing with risks posed by a data breach is important, and that the efforts made to secure the data held will be used to determine the level of penalties should a breach occur. So doing nothing may be an option, but it will probably be a very expensive one. Accepting this, how can you approach what for many is a very murky problem – and can encryption help?</p>
<p>That old chestnut, off-site backup, is the traditional starting point for data protection. However this does involve risk at multiple points: transporting the backups, holding them at a third party, and then being able to recover the data at a future time. Encryption of the backed-up data certainly appears to be part of the solution: it enables safe transport and storage, providing the passwords or keys are kept separate from the data itself, of course.</p>
<p>However, backup is only half of the answer when it comes to data protection and availability &#8211; the flip-side is restoration of data if required. At this point, encryption makes things harder, not easier. How many companies have implemented a system to guarantee that encrypted information can be retrieved and restored? To do so requires a comprehensive catalogue of backups, combined with encryption key or password management information. It may be a challenge keeping records, especially as the retention periods for these data sets can extend into years and decades.</p>
<p>As a system of many interacting steps, many of which are complex and temperamental, the whole of the problem may seem like much more than the sum of its parts. Keeping a firm grip on encrypted data will be dependent on process, documentation and management tools. Regular testing of restore capability must also be part of the process, ideally as part of formal Governance, Risk and Compliance (GRC) procedures.</p>
<p>It is tempting to focus efforts on testing restores on fairly recent active data. After all, there are whole libraries of the old stuff! But is this really going to be enough? Indeed, if it can’t be guaranteed that old, encrypted data can be restored at some point in the future, is there really any point in keeping it at all?</p>
<p>Long-term access to backup data has many associated risks. For example, job rotation and rapid technology obsolescence mean that this is often left as a problem for somebody else to solve. The physical condition of the tape may deteriorate. Tape readers may become obsolete (even NASA has this problem). Encryption adds to the complexity of the problem of data restoration, and as with all the other issues this must be tackled to ensure long-term retrieval is viable. Process is as vital in ensuring success as the technology used, perhaps even more so as technology changes frequently but people are slow to change – as, to be fair, is the data.</p>
<p>We&#8217;re not claiming to have all the answers here. But as encryption once again piques the interest of the media, it is worth considering the practicalities and ramifications when it comes to this fundamental area of data protection – that of backup and restore. Whatever approach is followed to encrypting backups, key management will likely become the over-riding issue to ensure that access to the data is still possible after many years. Tough as it sometimes can be, most organisations would not think of running important systems without backups and recovery plans in place. But neglecting the same with encrypted data and keys, lays a business open to losing access to important data with a very difficult path to recovery.</p>
<p>Have you ever had a data wipe-out from lost keys? Has encryption saved your bacon? </p>
<p><a href="http://www.theregister.co.uk/2010/06/01/encrypting_backups/">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/06/should-we-be-encrypting-backups/&amp;n=Should+we+be+encrypting+backups%3F&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/06/should-we-be-encrypting-backups/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/06/should-we-be-encrypting-backups/&amp;title=Should+we+be+encrypting+backups%3F" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/06/should-we-be-encrypting-backups/&amp;t=Should+we+be+encrypting+backups%3F" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/06/should-we-be-encrypting-backups/&amp;title=Should+we+be+encrypting+backups%3F" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/06/should-we-be-encrypting-backups/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/06/should-we-be-encrypting-backups/&amp;title=Should+we+be+encrypting+backups%3F&amp;srcUrl=http://www.uncompiled.com/2010/06/should-we-be-encrypting-backups/&amp;srcTitle=Should+we+be+encrypting+backups%3F&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/06/should-we-be-encrypting-backups/&amp;title=Should+we+be+encrypting+backups%3F&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22Should%20we%20be%20encrypting%20backups%3F%22&amp;body=Link: http://www.uncompiled.com/2010/06/should-we-be-encrypting-backups/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/06/should-we-be-encrypting-backups/&amp;t=Should+we+be+encrypting+backups%3F" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/06/should-we-be-encrypting-backups/&amp;title=Should+we+be+encrypting+backups%3F&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/06/should-we-be-encrypting-backups/&amp;title=Should+we+be+encrypting+backups%3F" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/06/should-we-be-encrypting-backups/&amp;title=Should+we+be+encrypting+backups%3F" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/06/should-we-be-encrypting-backups/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Should+we+be+encrypting+backups%3F+-+http://b2l.me/ymcsg&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/06/should-we-be-encrypting-backups/&amp;submitHeadline=Should+we+be+encrypting+backups%3F&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=Should+we+be+encrypting+backups%3F&amp;body=Link: http://www.uncompiled.com/2010/06/should-we-be-encrypting-backups/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/06/should-we-be-encrypting-backups/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>McAfee buys Trust Digital for iPhone enterprise safety</title>
		<link>http://www.uncompiled.com/2010/05/mcafee-buys-trust-digital-for-iphone-enterprise-safety/</link>
		<comments>http://www.uncompiled.com/2010/05/mcafee-buys-trust-digital-for-iphone-enterprise-safety/#comments</comments>
		<pubDate>Wed, 26 May 2010 13:51:25 +0000</pubDate>
		<dc:creator>mstanisl</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[McAfee]]></category>
		<category><![CDATA[Mobile]]></category>

		<guid isPermaLink="false">http://www.uncompiled.com/?p=1222</guid>
		<description><![CDATA[         ]]></description>
			<content:encoded><![CDATA[<p>McAfee has bought privately-held enterprise mobility management and security startup Trust Digital. The terms of the deal, announced Tuesday, were undisclosed.</p>
<p>The agreement will allow McAfee to offer a wider range of enterprise-targeted mobile security products for smartphone platforms, including iPhone OS, Android, Web OS, Windows Mobile and Symbian. Trust Digital&#8217;s technology will be integrated into McAfee&#8217;s ePolicy Orchestrator management console technology. This symbiosis will guard against such risks as malicious downloads of applications onto smartphone devices.</p>
<p>McAfee&#8217;s pitch is that its technology will make the roll-out of iPhone and Android smartphones in enterprises safer. It&#8217;s unclear how many of Trust Digital&#8217;s 40 workers will be offered jobs with McAfee.</p>
<p><a href="http://www.theregister.co.uk/2010/05/26/mcafee_smartphone_security_purchase/">Source</a>      </p>


<div class="shr-bookmarks shr-bookmarks-center">
<ul class="socials">
		<li class="shr-blogger">
			<a href="http://www.blogger.com/blog_this.pyra?t&amp;u=http://www.uncompiled.com/2010/05/mcafee-buys-trust-digital-for-iphone-enterprise-safety/&amp;n=McAfee+buys+Trust+Digital+for+iPhone+enterprise+safety&amp;pli=1" rel="nofollow" class="external" title="Blog this on Blogger">Blog this on Blogger</a>
		</li>
		<li class="shr-comfeed">
			<a href="http://www.uncompiled.com/2010/05/mcafee-buys-trust-digital-for-iphone-enterprise-safety/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://www.uncompiled.com/2010/05/mcafee-buys-trust-digital-for-iphone-enterprise-safety/&amp;title=McAfee+buys+Trust+Digital+for+iPhone+enterprise+safety" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://www.uncompiled.com/2010/05/mcafee-buys-trust-digital-for-iphone-enterprise-safety/&amp;t=McAfee+buys+Trust+Digital+for+iPhone+enterprise+safety" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
		<li class="shr-googlebookmarks">
			<a href="http://www.google.com/bookmarks/mark?op=add&amp;bkmk=http://www.uncompiled.com/2010/05/mcafee-buys-trust-digital-for-iphone-enterprise-safety/&amp;title=McAfee+buys+Trust+Digital+for+iPhone+enterprise+safety" rel="nofollow" class="external" title="Add this to Google Bookmarks">Add this to Google Bookmarks</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://www.uncompiled.com/2010/05/mcafee-buys-trust-digital-for-iphone-enterprise-safety/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-googlereader">
			<a href="http://www.google.com/reader/link?url=http://www.uncompiled.com/2010/05/mcafee-buys-trust-digital-for-iphone-enterprise-safety/&amp;title=McAfee+buys+Trust+Digital+for+iPhone+enterprise+safety&amp;srcUrl=http://www.uncompiled.com/2010/05/mcafee-buys-trust-digital-for-iphone-enterprise-safety/&amp;srcTitle=McAfee+buys+Trust+Digital+for+iPhone+enterprise+safety&amp;snippet=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Add this to Google Reader">Add this to Google Reader</a>
		</li>
		<li class="shr-linkedin">
			<a href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http://www.uncompiled.com/2010/05/mcafee-buys-trust-digital-for-iphone-enterprise-safety/&amp;title=McAfee+buys+Trust+Digital+for+iPhone+enterprise+safety&amp;summary=%20%20%20%20%20%20%20%20%20&amp;source=uncompiled.com" rel="nofollow" class="external" title="Share this on LinkedIn">Share this on LinkedIn</a>
		</li>
		<li class="shr-mail">
			<a href="mailto:?subject=%22McAfee%20buys%20Trust%20Digital%20for%20iPhone%20enterprise%20safety%22&amp;body=Link: http://www.uncompiled.com/2010/05/mcafee-buys-trust-digital-for-iphone-enterprise-safety/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this to a friend?">Email this to a friend?</a>
		</li>
		<li class="shr-myspace">
			<a href="http://www.myspace.com/Modules/PostTo/Pages/?u=http://www.uncompiled.com/2010/05/mcafee-buys-trust-digital-for-iphone-enterprise-safety/&amp;t=McAfee+buys+Trust+Digital+for+iPhone+enterprise+safety" rel="nofollow" class="external" title="Post this to MySpace">Post this to MySpace</a>
		</li>
		<li class="shr-pingfm">
			<a href="http://ping.fm/ref/?link=http://www.uncompiled.com/2010/05/mcafee-buys-trust-digital-for-iphone-enterprise-safety/&amp;title=McAfee+buys+Trust+Digital+for+iPhone+enterprise+safety&amp;body=%20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Ping this on Ping.fm">Ping this on Ping.fm</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://www.uncompiled.com/2010/05/mcafee-buys-trust-digital-for-iphone-enterprise-safety/&amp;title=McAfee+buys+Trust+Digital+for+iPhone+enterprise+safety" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://www.uncompiled.com/2010/05/mcafee-buys-trust-digital-for-iphone-enterprise-safety/&amp;title=McAfee+buys+Trust+Digital+for+iPhone+enterprise+safety" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://www.uncompiled.com/2010/05/mcafee-buys-trust-digital-for-iphone-enterprise-safety/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=McAfee+buys+Trust+Digital+for+iPhone+enterprise+safety+-+http://b2l.me/w3eke&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-yahoobuzz">
			<a href="http://buzz.yahoo.com/submit/?submitUrl=http://www.uncompiled.com/2010/05/mcafee-buys-trust-digital-for-iphone-enterprise-safety/&amp;submitHeadline=McAfee+buys+Trust+Digital+for+iPhone+enterprise+safety&amp;submitSummary=%20%20%20%20%20%20%20%20%20&amp;submitCategory=science&amp;submitAssetType=text" rel="nofollow" class="external" title="Buzz up!">Buzz up!</a>
		</li>
		<li class="shr-yahoomail">
			<a href="http://compose.mail.yahoo.com/?Subject=McAfee+buys+Trust+Digital+for+iPhone+enterprise+safety&amp;body=Link: http://www.uncompiled.com/2010/05/mcafee-buys-trust-digital-for-iphone-enterprise-safety/ (sent via shareaholic)%0D%0A%0D%0A----%0D%0A %20%20%20%20%20%20%20%20%20" rel="nofollow" class="external" title="Email this via Yahoo! Mail">Email this via Yahoo! Mail</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://www.uncompiled.com/2010/05/mcafee-buys-trust-digital-for-iphone-enterprise-safety/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
