<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>The &#34;P&#34; Word?  You Know, Privacy &#38; Psecurity.</title>
	<atom:link href="http://blog.valeso.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.valeso.org</link>
	<description>The Intersection between Technology, Policy and Human Behavior.</description>
	<lastBuildDate>Wed, 03 Feb 2010 01:58:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.valeso.org' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/103db0acca98e959aa6ea61770358030?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>The &#34;P&#34; Word?  You Know, Privacy &#38; Psecurity.</title>
		<link>http://blog.valeso.org</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.valeso.org/osd.xml" title="The &#34;P&#34; Word?  You Know, Privacy &#38; Psecurity." />
	<atom:link rel='hub' href='http://blog.valeso.org/?pushpress=hub'/>
		<item>
		<title>Tor Users Urged To Update After Security Breach</title>
		<link>http://blog.valeso.org/2010/01/31/tor-users-urged-to-update-after-security-breach/</link>
		<comments>http://blog.valeso.org/2010/01/31/tor-users-urged-to-update-after-security-breach/#comments</comments>
		<pubDate>Sun, 31 Jan 2010 19:34:02 +0000</pubDate>
		<dc:creator>valeso</dc:creator>
				<category><![CDATA[+Relevant -Timely]]></category>
		<category><![CDATA[Anonymity]]></category>
		<category><![CDATA[Computer security]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[Instant messaging]]></category>
		<category><![CDATA[PSA]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://blog.valeso.org/?p=370</guid>
		<description><![CDATA[From the better-really-late-than-really-never dept. and Slashdot YRO: If you use Tor, you&#8217;re cautioned to update now due to a security breach. In a message on the Tor mailing list dated Jan 20, 2010, Tor developer Roger Dingledine outlines the issue and why you should upgrade to Tor 0.2.1.22 or 0.2.2.7-alpha now: &#8216;In early January we [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.valeso.org&blog=11551764&post=370&subd=valeso&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><em><strong>From the better-really-late-than-really-never dept. and <a href="http://yro.slashdot.org/story/10/01/22/0024210/Tor-Users-Urged-To-Update-After-Security-Breach">Slashdot YRO</a></strong>: <em>If you use Tor, you&#8217;re cautioned to update now due to a security breach. In a message on the Tor mailing list dated Jan 20, 2010, Tor developer Roger Dingledine outlines <a href="http://archives.seul.org/or/talk/Jan-2010/msg00161.html">the issue and why you should upgrade</a> to Tor 0.2.1.22 or 0.2.2.7-alpha now: &#8216;In early January we discovered that two of the seven directory authorities were compromised (moria1 and gabelmoo), along with <a href="http://metrics.torproject.org/">metrics.torproject.org</a>, a new server we&#8217;d recently set up to serve metrics data and graphs. The three servers have since been reinstalled with service migrated to other servers.&#8217; Tor users should <a href="https://www.torproject.org/download.html.en">visit the download page and update</a> ASAP.</em></em></p>
<p>Unfortunately for me on one of my computers, along with the security upgrade, there&#8217;s also a bit of <a href="http://en.wikipedia.org/wiki/Transport_Layer_Security">TLS</a> · <a href="http://www.google.com/search?q=%2Btor+%22TLS+error%3A+unexpected+close+while+renegotiating%22&amp;ie=utf-8&amp;oe=utf-8&amp;aq=t&amp;rls=org.mozilla:es-ES:official&amp;client=firefox-a">weirdness</a> happening which keeps the Tor client from ever joing the network.  Good thing I&#8217;ve got other computers with <a href="http://en.wikipedia.org/wiki/List_of_Linux_distributions">alternative OSs</a> on them that I can use for my anonymous work on the intertubes.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/valeso.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/valeso.wordpress.com/370/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/valeso.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/valeso.wordpress.com/370/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/valeso.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/valeso.wordpress.com/370/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/valeso.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/valeso.wordpress.com/370/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/valeso.wordpress.com/370/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/valeso.wordpress.com/370/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.valeso.org&blog=11551764&post=370&subd=valeso&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.valeso.org/2010/01/31/tor-users-urged-to-update-after-security-breach/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e7b86f4e1e6da751e1dff8b10626c5c1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">valeso</media:title>
		</media:content>
	</item>
		<item>
		<title>Firefox 3.6 Offers Built in Plugin Detection and Updating</title>
		<link>http://blog.valeso.org/2010/01/24/firefox-3-6-offers-built-in-plugin-detection-and-updating/</link>
		<comments>http://blog.valeso.org/2010/01/24/firefox-3-6-offers-built-in-plugin-detection-and-updating/#comments</comments>
		<pubDate>Sun, 24 Jan 2010 02:20:34 +0000</pubDate>
		<dc:creator>valeso</dc:creator>
				<category><![CDATA[Computer security]]></category>
		<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[You are the last mile]]></category>

		<guid isPermaLink="false">http://blog.valeso.org/?p=358</guid>
		<description><![CDATA[From Mozilla is mo-better dept: Of the many incremental improvements that v3.6 offers over v3.5, my favorite is the built in plugin detection that works on a per page basis. Considering that out-of-date, easily exploited plugins are one way to lose control of your computer (and the valuable information that you store on it), this [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.valeso.org&blog=11551764&post=358&subd=valeso&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><strong><a href="http://www.mozilla.com?from=sfx&amp;uid=303499&amp;t=559"><img src="http://sfx-images.mozilla.org/firefox/3.6/120x240_green.png" border="0" alt="Spread Firefox Affiliate Button" hspace="8" align="right" /></a>From <a href="http://www.mozilla.com">Mozilla</a> is mo-better dept</strong>: Of the <a href="http://www.mozilla.com/en-US/firefox/3.6/releasenotes/">many incremental improvements</a> that v3.6 offers over v3.5, my favorite is the <a href="http://theunfocused.net/2009/10/06/firefox-3-6-knows-when-your-plugins-are-out-of-date/">built in plugin detection</a> that works on a per page basis.</p>
<p>Considering that out-of-date, easily exploited plugins are one way to lose control of your computer (and the valuable information that you store on it), this is a nice touch, and an easy way to keep everything important up to date.</p>
<p>For minimalists and control freaks like me, there&#8217;s an even easier way that&#8217;s been available for a while now: run Mozilla&#8217;s online <a href="http://www.mozilla.com/plugincheck/">Plugin Check service</a> as your start page &#8211; that way you know which of your plugins are enabled and their status before you venture out into the big bad web.  And it even works with older versions of Firefox in case you&#8217;re not able to upgrade.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/valeso.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/valeso.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/valeso.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/valeso.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/valeso.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/valeso.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/valeso.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/valeso.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/valeso.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/valeso.wordpress.com/358/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.valeso.org&blog=11551764&post=358&subd=valeso&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.valeso.org/2010/01/24/firefox-3-6-offers-built-in-plugin-detection-and-updating/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e7b86f4e1e6da751e1dff8b10626c5c1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">valeso</media:title>
		</media:content>

		<media:content url="http://sfx-images.mozilla.org/firefox/3.6/120x240_green.png" medium="image">
			<media:title type="html">Spread Firefox Affiliate Button</media:title>
		</media:content>
	</item>
		<item>
		<title>Upside to Google&#8217;s Adventures in China?</title>
		<link>http://blog.valeso.org/2010/01/20/upside-to-googles-adventures-in-china/</link>
		<comments>http://blog.valeso.org/2010/01/20/upside-to-googles-adventures-in-china/#comments</comments>
		<pubDate>Wed, 20 Jan 2010 19:06:28 +0000</pubDate>
		<dc:creator>valeso</dc:creator>
				<category><![CDATA[+Relevant -Timely]]></category>
		<category><![CDATA[Computer security]]></category>
		<category><![CDATA[Consumer]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Cryptography (the lack thereof)]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[You are the last mile]]></category>

		<guid isPermaLink="false">http://blog.valeso.org/?p=350</guid>
		<description><![CDATA[From the silver-lining dept and Slashdot: Here&#8217;s one possible outcome of Google&#8217;s recent spate of problems with the Chinese government: They&#8217;ve now decided to make HTTPS the default transport option for their Gmail service. While this move didn&#8217;t get as much attention as all the other &#8220;big issue&#8221; stories, it is a minor victory of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.valeso.org&blog=11551764&post=350&subd=valeso&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><em><strong><img class="alignleft size-full wp-image-354" title="lock_128_hot" src="http://valeso.files.wordpress.com/2010/01/lock_128_hot.png?w=128&#038;h=128" alt="Automagic SSL for Gmail?" width="128" height="128" border="0">From the silver-lining dept and <a href="http://it.slashdot.org/story/10/01/13/2150245/Gmail-Moves-To-HTTPS-By-Default">Slashdot</a></strong>:  Here&#8217;s one possible outcome of Google&#8217;s recent <a href="http://yro.slashdot.org/story/10/01/12/2329231/Google-Hacked-May-Pull-Out-of-China">spate</a> of <a href="http://tech.slashdot.org/story/10/01/15/0013239/IE-0-Day-Flaw-Used-In-Chinese-Attack">problems</a> with the Chinese government: They&#8217;ve now decided to make <a href="http://en.wikipedia.org/wiki/HTTPS">HTTPS</a> the <a href="http://gmailblog.blogspot.com/2010/01/default-https-access-for-gmail.html">default transport option</a> for their Gmail service. </em></p>
<p>While this move didn&#8217;t get as much attention as all the other &#8220;big issue&#8221; stories, it is a minor victory of sorts for NGOs and activists whose activities might attract the attention of the Chinese government.  By making secure transmission the default, non-tech-savvy users no longer have to <a title="Manually configuring HTTPS for Gmail" href="http://blog.valeso.org/2008/09/05/all-your-gmail-are-ours-point-and-click-gmail-hack/">go through this</a> to protect their communications.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/valeso.wordpress.com/350/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/valeso.wordpress.com/350/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/valeso.wordpress.com/350/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/valeso.wordpress.com/350/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/valeso.wordpress.com/350/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/valeso.wordpress.com/350/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/valeso.wordpress.com/350/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/valeso.wordpress.com/350/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/valeso.wordpress.com/350/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/valeso.wordpress.com/350/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.valeso.org&blog=11551764&post=350&subd=valeso&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.valeso.org/2010/01/20/upside-to-googles-adventures-in-china/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e7b86f4e1e6da751e1dff8b10626c5c1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">valeso</media:title>
		</media:content>

		<media:content url="http://valeso.files.wordpress.com/2010/01/lock_128_hot.png" medium="image">
			<media:title type="html">lock_128_hot</media:title>
		</media:content>
	</item>
		<item>
		<title>Neither &quot;God&quot; Nor &quot;Password&quot; Shall Ye Use: Most Common Hotmail Passwords Revealed</title>
		<link>http://blog.valeso.org/2009/10/08/neither-god-nor-password-most-common-hotmail-password-revealed/</link>
		<comments>http://blog.valeso.org/2009/10/08/neither-god-nor-password-most-common-hotmail-password-revealed/#comments</comments>
		<pubDate>Fri, 09 Oct 2009 01:27:07 +0000</pubDate>
		<dc:creator>valeso</dc:creator>
				<category><![CDATA[Email]]></category>
		<category><![CDATA[General incompetence]]></category>
		<category><![CDATA[Ranting and raving...]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[You are the last mile]]></category>

		<guid isPermaLink="false">https://www.vaultletsoft.com/privacy/blog/?p=267</guid>
		<description><![CDATA[From Wired and the dept-of-deja-vu-dept: A researcher who examined 10,000 Hotmail, MSN and Live.com passwords that were recently exposed online has published an analysis of the list and found that “123456? was the most commonly used password, appearing 64 times. Forty-two percent of the passwords used lowercase letters from “a to z”; only 6 percent [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.valeso.org&blog=11551764&post=267&subd=valeso&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><em><strong>From <a href="http://www.wired.com/threatlevel/2009/10/10000-passwords/">Wired</a> and the <a href="http://modernl.com/article/top-10-most-common-passwords">dept-of-deja-vu-dept</a></strong>: A researcher who examined 10,000 Hotmail, MSN and Live.com passwords that were recently exposed online has published an analysis of the list and found that “123456? was the most commonly used password, appearing 64 times.</em></p>
<p><em>Forty-two percent of the passwords used lowercase letters from “a to z”; only 6 percent mixed alpha-numeric and other characters.</em></p>
<p>That&#8217;s right, only 6% used mixed alpha-numerics, and this isn&#8217;t the first time that <a href="http://www.google.com/search?hl=en&amp;client=firefox-a&amp;rls=org.mozilla%3Aen-US%3Aofficial&amp;hs=Psj&amp;q=most+common+passwords&amp;aq=0&amp;oq=most+common+password">it&#8217;s been documented</a> just how dunderheaded some people can be when it comes to doing the Right Thing™.</p>
<p>Great Zeus on high, how hard can it be to come up with a decent password?<a title="Only 66,000,000 hits on Google?  Is that all?" href="http://www.google.com/search?q=how+to+create+a+strong+password"> Not too hard</a>, I dare say&#8230;</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/valeso.wordpress.com/267/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/valeso.wordpress.com/267/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/valeso.wordpress.com/267/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/valeso.wordpress.com/267/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/valeso.wordpress.com/267/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/valeso.wordpress.com/267/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/valeso.wordpress.com/267/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/valeso.wordpress.com/267/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/valeso.wordpress.com/267/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/valeso.wordpress.com/267/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.valeso.org&blog=11551764&post=267&subd=valeso&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.valeso.org/2009/10/08/neither-god-nor-password-most-common-hotmail-password-revealed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e7b86f4e1e6da751e1dff8b10626c5c1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">valeso</media:title>
		</media:content>
	</item>
		<item>
		<title>A(nother) Brief Hiatus from Blogging: Development &amp; Testing VaultletSuite 2 Go, v2.9</title>
		<link>http://blog.valeso.org/2009/09/05/another-brief-hiatus-from-blogging-development-testing-vaultletsuite-2-go-v2-9/</link>
		<comments>http://blog.valeso.org/2009/09/05/another-brief-hiatus-from-blogging-development-testing-vaultletsuite-2-go-v2-9/#comments</comments>
		<pubDate>Sat, 05 Sep 2009 15:42:50 +0000</pubDate>
		<dc:creator>valeso</dc:creator>
				<category><![CDATA[+Relevant -Timely]]></category>
		<category><![CDATA[Blogging]]></category>
		<category><![CDATA[Computer security]]></category>
		<category><![CDATA[Shameless self promotion]]></category>

		<guid isPermaLink="false">https://www.vaultletsoft.com/privacy/blog/?p=264</guid>
		<description><![CDATA[From the at-least-they’re-not-chainsaws-we’re-juggling department: For those of you keeping score, it’s been a while since I’ve blogged on privacy or security issues. That would be because we’re currently finishing up development and testing the latest version of the VaultletSuite 2 Go, v2.9. Stay tuned for more “P” Word once v2.9 goes into production!<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.valeso.org&blog=11551764&post=264&subd=valeso&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:left;"><em><strong>From the at-least-they’re-not-chainsaws-we’re-juggling department</strong></em>: For those of you keeping score, it’s been a while since I’ve blogged on privacy or security issues.</p>
<p style="text-align:left;">That would be because we’re currently finishing up development and testing the latest version of the VaultletSuite 2 Go, v2.9.</p>
<p style="text-align:left;">Stay tuned for more “P” Word once v2.9 goes into production!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/valeso.wordpress.com/264/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/valeso.wordpress.com/264/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/valeso.wordpress.com/264/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/valeso.wordpress.com/264/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/valeso.wordpress.com/264/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/valeso.wordpress.com/264/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/valeso.wordpress.com/264/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/valeso.wordpress.com/264/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/valeso.wordpress.com/264/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/valeso.wordpress.com/264/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.valeso.org&blog=11551764&post=264&subd=valeso&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.valeso.org/2009/09/05/another-brief-hiatus-from-blogging-development-testing-vaultletsuite-2-go-v2-9/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e7b86f4e1e6da751e1dff8b10626c5c1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">valeso</media:title>
		</media:content>
	</item>
		<item>
		<title>Keystroke Loggers Are Back &#8211; This Time in Real Time</title>
		<link>http://blog.valeso.org/2009/08/24/keystroke-loggers-are-back-this-time-in-real-time/</link>
		<comments>http://blog.valeso.org/2009/08/24/keystroke-loggers-are-back-this-time-in-real-time/#comments</comments>
		<pubDate>Tue, 25 Aug 2009 01:51:31 +0000</pubDate>
		<dc:creator>valeso</dc:creator>
				<category><![CDATA[Computer security]]></category>
		<category><![CDATA[Consumer]]></category>
		<category><![CDATA[Cryptography]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Shameless self promotion]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[You are the last mile]]></category>

		<guid isPermaLink="false">https://www.vaultletsoft.com/privacy/blog/?p=249</guid>
		<description><![CDATA[From Slashdot, the New York Times and the what&#8217;s-olde-is-new-dept: The NY Times has a story&#8230; on a weapon now being wielded by bad guys (most likely in Eastern Europe, according to the Times): Trojan horse keyloggers that report back in real-time. Real-time keyloggers were first discovered in the wild last year, but the &#8230;Times article [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.valeso.org&blog=11551764&post=249&subd=valeso&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><a title="Have you been offered a Trojan Horse lately?" href="http://en.wikipedia.org/wiki/Trojan_horse"><img src="https://www.vaultletsoft.com/images/trojan-horse-200x302.jpg" border="1&lt;/a&gt;" alt="" hspace="8" vspace="8" width="200" height="302" align="left" /></a><em><strong>From <a href="http://it.slashdot.org/story/09/08/23/2015208/Real-Time-Keyloggers">Slashdot</a>, the <a href="http://bits.blogs.nytimes.com/2009/08/20/how-hackers-snatch-real-time-security-id-numbers/">New York Times</a> and the <a href="https://www.vaultletsoft.com/privacy/blog/?p=25">what&#8217;s-olde-is-new</a>-dept</strong>: The NY Times has a story&#8230; on a weapon now being wielded by bad guys (most likely in Eastern Europe, according to the Times): <a href="http://bits.blogs.nytimes.com/2009/08/20/how-hackers-snatch-real-time-security-id-numbers/">Trojan horse keyloggers that report back in real-time</a>. Real-time keyloggers were <a href="http://www.computerweekly.com/Articles/2008/01/31/229191/two-factor-banking-security-systems-threatened-by-trojan.htm">first discovered in the wild last year</a>, but the &#8230;Times article should bring new attention to the threat.</em></p>
<p>So now that the Bad Guys™ are hoovering up your validation credentials in real-time (not &#8220;real&#8221; real-time, but faster than before), they&#8217;ve managed to break one particular implementation of a <a href="http://en.wikipedia.org/wiki/Two-factor_authentication">Two-Factor Authentication</a> scheme.</p>
<p>Not bad, but the real threat is quite a bit less esoteric: continuous reporting of keystrokes gives miscreants a larger window of time to operate in.  The dangers presented by keystroke loggers could be largely mitigated by using some not-so-common sense: <a title="The Security Ecosystem &amp; Preventative Medicine (online version)" href="https://www.vaultletsoft.com/ppt/preventative-medicine-html">Keeping your computer clean and healthy</a> and maybe even switching to a <a title="Linux" href="http://en.wikipedia.org/wiki/Linux">minority</a> · <a title="OS X" href="http://en.wikipedia.org/wiki/OS_X">operating system</a> (while keeping your newly developed good habits) means that you&#8217;ve just eliminated a large majority of your security threats.</p>
<p>So you think getting people to &#8220;do the right thing&#8221; by their computers and data is impossible?  It wasn&#8217;t too long ago that people weren&#8217;t washing their hands before eating or preparing food, nor were they covering their mouths when they sneezed.</p>
<p>Good computer hygiene practices <em>can</em> be learned.  <em>And</em> understood.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/valeso.wordpress.com/249/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/valeso.wordpress.com/249/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/valeso.wordpress.com/249/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/valeso.wordpress.com/249/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/valeso.wordpress.com/249/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/valeso.wordpress.com/249/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/valeso.wordpress.com/249/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/valeso.wordpress.com/249/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/valeso.wordpress.com/249/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/valeso.wordpress.com/249/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.valeso.org&blog=11551764&post=249&subd=valeso&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.valeso.org/2009/08/24/keystroke-loggers-are-back-this-time-in-real-time/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e7b86f4e1e6da751e1dff8b10626c5c1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">valeso</media:title>
		</media:content>

		<media:content url="//www.vaultletsoft.com/images/trojan-horse-200x302.jpg" medium="image" />
	</item>
		<item>
		<title>Guess What?  Many Social Security Numbers Can Be Guessed</title>
		<link>http://blog.valeso.org/2009/07/08/guess-what-many-social-security-numbers-can-be-guessed/</link>
		<comments>http://blog.valeso.org/2009/07/08/guess-what-many-social-security-numbers-can-be-guessed/#comments</comments>
		<pubDate>Wed, 08 Jul 2009 19:39:47 +0000</pubDate>
		<dc:creator>valeso</dc:creator>
				<category><![CDATA[+Relevant -Timely]]></category>
		<category><![CDATA[Consumer]]></category>
		<category><![CDATA[Cryptography (the lack thereof)]]></category>
		<category><![CDATA[General incompetence]]></category>
		<category><![CDATA[ID]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[Policy]]></category>

		<guid isPermaLink="false">https://www.vaultletsoft.com/privacy/blog/?p=241</guid>
		<description><![CDATA[From Slashdot, Wired, and the when-is-a-secret-not-a-secret-dept: The nation&#8217;s Social Security numbering scheme has left millions of citizens vulnerable to privacy breaches, according to researchers at Carnegie Mellon University, who for the first time have used statistical techniques to predict Social Security numbers solely from an individual&#8217;s date and location of birth. Knowing someone&#8217;s SSN is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.valeso.org&blog=11551764&post=241&subd=valeso&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.vaultletsoft.com/images/ssn-card-252x152.gif" alt="Your SSN's fairly predictable" border="0" hspace="8" vspace="8" align="right" /><em><strong>From <a href="http://yro.slashdot.org/story/09/07/06/2215218/Social-Security-Numbers-Can-Be-Guessed">Slashdot</a>, <a href="http://www.wired.com/wiredscience/2009/07/predictingssn/">Wired</a>, and the when-is-a-secret-not-a-secret-dept</strong>: The nation&#8217;s Social Security numbering scheme has left millions of citizens vulnerable to privacy breaches, according to researchers at Carnegie Mellon University, who for the first time have used statistical techniques to predict Social Security numbers solely from an individual&#8217;s date and location of birth.</em></p>
<p>Knowing someone&#8217;s SSN is a key part of <a title="More on identity theft" href="https://www.vaultletsoft.com/privacy/blog/?s=identity+theft">identity theft</a>.  Just by knowing this easily obtained (or guessed secret) means that somebody can assume your identity, rob you blind, and then leave you with years of pain and suffering trying to document that you weren&#8217;t the one who ran up tens of thousands of dollars of bad debt.</p>
<p>Protecting your not-so-secret SSN is impossible due to the fact that everybody with a financial interest in &#8220;knowing you&#8221; (worse than the biblical sense) has easy access to this number.  Further complicating matters is the fact that these same entities have <a href="http://en.wikipedia.org/wiki/Externality">no financial incentive</a> to protect it because <em>they&#8217;re not the one who pays the price</em> for wrecking your financial life.  You do.</p>
<p>So what to do?  Put a <a title="A Baker’s Dozen of Identity Theft and Privacy Protecting Tips for 2008" href="https://www.vaultletsoft.com/privacy/blog/?p=71">freeze</a> on your credit and lift it manually everytime you need access to modifiy your lines of credit? Pay an outrageous sum to <a title="THEY'll SELL..." href="http://www.equifax.com/">the</a> · <a title="...YOUR INFORMATION..." href="http://www.transunion.com/">big</a> · <a title="...TO ANYBODY WHO PAYS" href="http://www.experian.com/">three</a> so that they report any &#8220;suspicious&#8221; activity related to your credit history?</p>
<p>What&#8217;s really needed is a fundamental change in thinking: Up until now, business and government have confused your <a title="Define Digital Identity" href="http://en.wikipedia.org/wiki/Digital_identity">Identity</a> with <a title="Define Authentication" href="http://en.wikipedia.org/wiki/Authentication">Authentication</a>.  They are <em>not</em> the same thing!  While the former might identify you within a database, the later confirms that you are indeed the account holder (yourself) through the use of a secret that only you would know.  For a more concrete example, think of your email address and the password that you use to access your email: the address identifies you, your secret password authenticates that you are the email account holder (more or less).</p>
<p>As you can see, much has to change before this problem gets fixed.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/valeso.wordpress.com/241/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/valeso.wordpress.com/241/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/valeso.wordpress.com/241/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/valeso.wordpress.com/241/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/valeso.wordpress.com/241/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/valeso.wordpress.com/241/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/valeso.wordpress.com/241/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/valeso.wordpress.com/241/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/valeso.wordpress.com/241/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/valeso.wordpress.com/241/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.valeso.org&blog=11551764&post=241&subd=valeso&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.valeso.org/2009/07/08/guess-what-many-social-security-numbers-can-be-guessed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e7b86f4e1e6da751e1dff8b10626c5c1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">valeso</media:title>
		</media:content>

		<media:content url="http://www.vaultletsoft.com/images/ssn-card-252x152.gif" medium="image">
			<media:title type="html">Your SSN's fairly predictable</media:title>
		</media:content>
	</item>
		<item>
		<title>Coming Soon to an Airport Near You: Mandatory TSA Porn?</title>
		<link>http://blog.valeso.org/2009/05/20/coming-soon-to-an-airport-near-you-mandatory-tsa-porn/</link>
		<comments>http://blog.valeso.org/2009/05/20/coming-soon-to-an-airport-near-you-mandatory-tsa-porn/#comments</comments>
		<pubDate>Thu, 21 May 2009 02:17:17 +0000</pubDate>
		<dc:creator>valeso</dc:creator>
				<category><![CDATA[General incompetence]]></category>
		<category><![CDATA[Hardware]]></category>
		<category><![CDATA[Humor]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[Ranting and raving...]]></category>
		<category><![CDATA[Security theatre]]></category>
		<category><![CDATA[The monster under the bed]]></category>

		<guid isPermaLink="false">https://www.vaultletsoft.com/privacy/blog/?p=237</guid>
		<description><![CDATA[From Slashdot and the whatcha-got-on-under-all-that dept: &#8220;Not content to simply follow the &#8216;anything to protect American lives&#8217; mantra, freshman Representative Jason Chaffetz (R-Utah) has introduced a bill to prohibit mandatory full body scans at airports. Chaffetz states, &#8216;The images offer a disturbingly accurate view of a person&#8217;s body underneath clothing &#8230; Americans should not be [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.valeso.org&blog=11551764&post=237&subd=valeso&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><a title="Image from EPIC's Backscatter X Ray Page" href="http://epic.org/privacy/airtravel/backscatter/"><img src="http://epic.org/privacy/airtravel/backscatter/woman.jpg" border="1" alt="" hspace="8" vspace="8" width="125" height="181" align="left" /></a><strong>From <a href="http://tech.slashdot.org/article.pl?sid=09/05/20/150234">Slashdot</a> and the whatcha-got-on-under-all-that dept</strong>:  <em>&#8220;Not content to simply follow the &#8216;anything to protect American lives&#8217; mantra, freshman Representative Jason Chaffetz (R-Utah) has <a href="http://thomas.loc.gov/cgi-bin/query/z?c111:H.R.2027:"> introduced a bill</a> to <a href="http://www.cnn.com/2009/POLITICS/05/19/chaffetz.iraq/index.html">prohibit mandatory full body scans</a> at airports. Chaffetz states, &#8216;The images offer a disturbingly accurate view of a person&#8217;s body underneath clothing &#8230; Americans should not be required to expose their bodies in this manner in order to fly.&#8217;</em></p>
<p>Sounds like the dreaded and shopworn &#8220;<a href="https://www.vaultletsoft.com/privacy/blog/?cat=32">monster under the bed</a>&#8221; is back.  Again.</p>
<p>So let&#8217;s try another little thought experiment: It could be amusing, if not enlightening, to propose that *every single one* of the TSA&#8217;s employees (sorry, no excuses) be body scanned by these devices, and then have those images made available online, if not simply displayed at random in public places like, say, an airport.  Just to see how they would react.</p>
<p>I&#8217;d bet good money that a significant portion of them would have a problem with that, if not stage an outright revolt against their employer for using a technology on them that&#8217;s as invasive as this is.</p>
<p>Perhaps then they might get a bit of insight as to why some of us resent having to &#8220;drop trouser&#8221; in a public place.  And to what end would we travelers be obligated to participate in this dehumanizing security farce?  Ah yes, that most wiley and elusive &#8220;monster under the bed&#8221;.</p>
<p>I feel better already knowing that the TSA&#8217;s on the case.</p>
<p>Let the TSA what you think signing the Privacy Coalition&#8217;s <a href="http://privacycoalition.org/stopwholebodyimaging/">Stop Whole Body Imaging</a> petition.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/valeso.wordpress.com/237/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/valeso.wordpress.com/237/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/valeso.wordpress.com/237/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/valeso.wordpress.com/237/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/valeso.wordpress.com/237/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/valeso.wordpress.com/237/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/valeso.wordpress.com/237/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/valeso.wordpress.com/237/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/valeso.wordpress.com/237/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/valeso.wordpress.com/237/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.valeso.org&blog=11551764&post=237&subd=valeso&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.valeso.org/2009/05/20/coming-soon-to-an-airport-near-you-mandatory-tsa-porn/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e7b86f4e1e6da751e1dff8b10626c5c1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">valeso</media:title>
		</media:content>

		<media:content url="http://epic.org/privacy/airtravel/backscatter/woman.jpg" medium="image" />
	</item>
		<item>
		<title>From April Fools to April&#039;s Close: Conficker&#039;s History in 150 Words or Less</title>
		<link>http://blog.valeso.org/2009/04/30/from-april-fools-to-aprils-close-conficker-in-150-words-or-less/</link>
		<comments>http://blog.valeso.org/2009/04/30/from-april-fools-to-aprils-close-conficker-in-150-words-or-less/#comments</comments>
		<pubDate>Thu, 30 Apr 2009 16:13:30 +0000</pubDate>
		<dc:creator>valeso</dc:creator>
				<category><![CDATA[+Relevant -Timely]]></category>
		<category><![CDATA[Computer security]]></category>
		<category><![CDATA[General incompetence]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[You are the last mile]]></category>

		<guid isPermaLink="false">https://www.vaultletsoft.com/privacy/blog/?p=225</guid>
		<description><![CDATA[From the that&#8217;s-quite-a-joke-you-got-there-dept: 60 Minutes said that &#8220;The Internet is infected&#8220;.  Meanwhile, Conficker was getting quite a bit of press in other venues too.  Towards the end of May, Univision interviewed me about the danger it represented.  Many [Windows] computer users waited for the impending doom and then&#8230; &#8230;nothing happened. And many had a good [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.valeso.org&blog=11551764&post=225&subd=valeso&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p><em><strong>From </strong></em><em><strong>the that&#8217;s-quite-a-joke-you-got-there-dept</strong>: </em>60 Minutes said that &#8220;<a href="http://www.cbsnews.com/stories/2009/03/27/60minutes/main4897053.shtml">The Internet is infected</a>&#8220;.  Meanwhile, Conficker was getting <a title="Millions of hits on Google, in just about any language too" href="http://www.google.com/search?q=conficker&amp;hl=en">quite a bit</a> of press in other venues too.  Towards the end of May, Univision <a href="https://www.vaultletsoft.com/about/news/index.html#14">interviewed me</a> about the danger it represented.  Many [Windows] computer users waited for the impending doom and then&#8230;</p>
<p>&#8230;<a href="http://news.bbc.co.uk/2/hi/technology/7976099.stm">nothing happened</a>. And many had a <a href="http://www.infoworld.com/d/adventures-in-it/conficker-worm-ends-life-we-know-it-film-11-769">good laugh</a>.</p>
<p>Except that <a href="http://news.bbc.co.uk/2/hi/technology/7991422.stm">something important did happen</a>, and quietly too: Conficker began <a href="http://www.networkworld.com/news/2009/041009-conficker-awakens-starts.html">calling home and morphing</a> into something else.  And an interesting homemade <a href="http://www.confickerworkinggroup.org/infection_test/cfeyechart.html">diagnostic eyechart</a> was published.  And <a href="http://tech.slashdot.org/article.pl?sid=09/04/02/1721252&amp;from=rss">discussed</a>.</p>
<p>The important thing to remember is that people were warned and had ample opportunity to mitigate their risk &#8211; As far back as January 2009, <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9126038">1 in 3 Windows PCs were still vulnerable</a> to Conficker, a full 80 days <em>after</em> a patch was published by Microsoft.  That means the patch was issued in October of 2008.</p>
<p>Talk about a slow motion train wreck that could have easily been avoided.</p>
<p>Of course, if you&#8217;re running Linux or OS X, you probably snickered, felt superior and/or laughed up your sleeve, because you ducked this one.  This time.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/valeso.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/valeso.wordpress.com/225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/valeso.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/valeso.wordpress.com/225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/valeso.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/valeso.wordpress.com/225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/valeso.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/valeso.wordpress.com/225/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/valeso.wordpress.com/225/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/valeso.wordpress.com/225/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.valeso.org&blog=11551764&post=225&subd=valeso&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.valeso.org/2009/04/30/from-april-fools-to-aprils-close-conficker-in-150-words-or-less/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e7b86f4e1e6da751e1dff8b10626c5c1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">valeso</media:title>
		</media:content>
	</item>
		<item>
		<title>Google Warns: The Internet May Harm Your Computer?</title>
		<link>http://blog.valeso.org/2009/02/12/google-warns-the-internet-may-harm-your-computer/</link>
		<comments>http://blog.valeso.org/2009/02/12/google-warns-the-internet-may-harm-your-computer/#comments</comments>
		<pubDate>Fri, 13 Feb 2009 02:28:33 +0000</pubDate>
		<dc:creator>valeso</dc:creator>
				<category><![CDATA[+Relevant -Timely]]></category>
		<category><![CDATA[General incompetence]]></category>
		<category><![CDATA[Humor]]></category>
		<category><![CDATA[Shameless self promotion]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">https://www.vaultletsoft.com/privacy/blog/?p=208</guid>
		<description><![CDATA[From WashingtonPost.com&#8217;s Security Fix: A glitch in a computer security program embedded deeply into Google&#8217;s search engine briefly prevented users of the popular search engine from visiting any Web sites turned up in search results this morning. Instead, Google users were redirected to page that warned: &#8220;This site may harm your computer.&#8221; Why, of course [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.valeso.org&blog=11551764&post=208&subd=valeso&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div style="text-align:left;"><a href="http://www.google.com/search?q=this+site+may+harm+your+computer"><img src="http://www.vaultletsoft.com/images/google-goof-500x207.jpg" border="1" alt="" hspace="8" vspace="8" /></a></div>
<p><em><strong>From WashingtonPost.com&#8217;s <a href="http://voices.washingtonpost.com/securityfix/2009/01/google_this_internet_will_harm.html">Security Fix</a></strong>: A glitch in a computer security program embedded deeply into Google&#8217;s search engine briefly prevented users of the popular search engine from visiting any Web sites turned up in search results this morning. Instead, Google users were redirected to page that warned: &#8220;This site may harm your computer.&#8221;</em></p>
<p>Why, of course the the <a href="http://en.wikipedia.org/wiki/Intertubes">Intertubes</a> can damage your computer.  Especially if you&#8217;re running an unpatched version of Windows as &#8220;administrator&#8221;, with no firewall, no anti-virus, and browsing with insanely out of date versions of Internet Explorer and flash, among others.</p>
<p>This is the default position I take when teaching &#8220;Practical Privacy and Simple Security&#8221; for people working in adverse conditions: assume that it&#8217;s insecure until you&#8217;ve taken the appropriate steps to assure otherwise.</p>
<p>Fortunately, in this case it was just a minor string matching goof writ large.</p>
<p>Doubly fortunate is that it&#8217;s <a title="Slide from Practical Privacy and Simple Security presentation" href="https://www.vaultletsoft.com/ppt/ppss2hrs/img42.png">not that hard</a> to <a href="https://www.vaultletsoft.com">protect the valuable information</a> that lives on your computer&#8217;s <a title="Great hard drive encryption software" href="http://www.truecrypt.org">hard drive</a> and enters and exits through your network connection.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/valeso.wordpress.com/208/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/valeso.wordpress.com/208/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/valeso.wordpress.com/208/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/valeso.wordpress.com/208/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/valeso.wordpress.com/208/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/valeso.wordpress.com/208/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/valeso.wordpress.com/208/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/valeso.wordpress.com/208/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/valeso.wordpress.com/208/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/valeso.wordpress.com/208/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.valeso.org&blog=11551764&post=208&subd=valeso&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://blog.valeso.org/2009/02/12/google-warns-the-internet-may-harm-your-computer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/e7b86f4e1e6da751e1dff8b10626c5c1?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">valeso</media:title>
		</media:content>

		<media:content url="http://www.vaultletsoft.com/images/google-goof-500x207.jpg" medium="image" />
	</item>
	</channel>
</rss>