<?xml version="1.0" encoding="utf-8" ?>
<!DOCTYPE rss PUBLIC "-//Netscape Communications//DTD RSS 0.91//EN"
 "http://www.feedcat.net/dtd/rss-0.91.dtd">
<rss version="0.91">
<channel>
<title>Perimeter Grid</title>
<link>http://perimetergrid.com/wp</link>
<description>Building Security in a Networked World</description>
<language>en</language>
<item>
<title>DefCon 16, Day 1</title>
<link>http://perimetergrid.com/wp/2008/08/24/defcon-16-day-1/</link>
<description>Having finished up with the BlackHat briefings, it was time to go on to DefCon.  While many of the speakers from BlackHat stay on for DefCon, there&amp;#8217;s also a lot of DefCon-only presentations, usually with a more attack-oriented focus (in keeping with DefCon&amp;#8217;s nature as a hacker convention rather than a security conference like BlackHat.)
The [...]</description>
</item>
<item>
<title>BlackHat 2008, Day 2</title>
<link>http://perimetergrid.com/wp/2008/08/13/blackhat-2008-day-2/</link>
<description>The second day of BlackHat 2008 began with a keynote speech by Rod Beckstrom, the director of NCSC (the National Cyber Security Center.) Most of this consisted of painfully strained Civil War analogies and the overuse of the word &amp;#8220;Cyber&amp;#8221; to describe absolutely everything. He made some good points &amp;#8212; specifically, that in [...]</description>
</item>
<item>
<title>BlackHat 2008, Day 1</title>
<link>http://perimetergrid.com/wp/2008/08/06/blackhat-2008-day-1/</link>
<description>Today was the first day of this year&amp;#8217;s BlackHat Briefings in Las Vegas. The biggest security conference of the year, it&amp;#8217;s always an interesting place to be and often involves the release of new and previously unknown exploits.
The keynote speaker was Ian Angell, of the London School of Economics, who was speaking, ostensibly, about [...]</description>
</item>
<item>
<title>The DNS Exploit Revealed… and used</title>
<link>http://perimetergrid.com/wp/2008/07/29/the-dns-exploit-revealed-and-used/</link>
<description>So, Dan Kaminsky&amp;#8217;s DNS exploit I previously mentioned has been revealed. It turns out that what Kaminsky found was pretty much what I speculated &amp;#8212; he just had it put together into a coherent attack, and fully recognized the implications.
If I want to poison your DNS server, say, to redirect www.yourbank.com to my malicious [...]</description>
</item>
<item>
<title>The Mysterious DNS Exploit</title>
<link>http://perimetergrid.com/wp/2008/07/17/the-mysterious-dns-exploit/</link>
<description>On Tuesday, July 8th, Microsoft&amp;#8217;s usual package of patches seemed to end-users like every other Patch Tuesday &amp;#8212; some security updates to various and sundry Windows files to patch security vulnerabilities unknown.  However, it contained something very unusual this time &amp;#8212; a design change to DNS.
DNS has been around since the 1970&amp;#8217;s, so people don&amp;#8217;t [...]</description>
</item>
<item>
<title>Two-Factor Auth for World of Warcraft</title>
<link>http://perimetergrid.com/wp/2008/06/30/two-factor-auth-for-world-of-warcraft/</link>
<description>Blizzard Entertainment, makers of the phenomenally-successful multiplayer game World of Warcraft, have introduced two-factor authentication for logging into the game.  For $6.50, they&amp;#8217;ll sell you a dynamic password keychain token called the Blizzard Authenticator, which looks much like the RSA keyfobs many in the IT industry use to log into their corporate VPNs.
It may seem [...]</description>
</item>
<item>
<title>Ubuntu/Debian CRNG Cracked - SSH Vulnerable</title>
<link>http://perimetergrid.com/wp/2008/05/17/ubuntudebian-crng-cracked-ssh-vulnerable/</link>
<description>I don&amp;#8217;t usually post about newly-discovered vulnerabilities, simply because there are so many of them &amp;#8212; a dozen come out every day, especially in web applications.  However, this one has further-reaching consequences.  Security researcher HD Moore (of Metasploit fame) has discovered a vulnerability in the OpenSSL cryptographic random number generator used by Debian Linux, the [...]</description>
</item>
<item>
<title>The Black Hat Tax</title>
<link>http://perimetergrid.com/wp/2008/05/16/the-black-hat-tax/</link>
<description>Auren Hoffman at Summation has an interesting post on the &amp;#8220;black hat tax.&amp;#8221;  Essentially, how much do hackers and other online criminals actually cost us?  He estimates it at 25% of time and resources, after taking into account not just hackers but also scammers, phishers, and responding to law enforcement requests.  According to James Currier [...]</description>
</item>
<item>
<title>Charter Communications Using Ad Replacer</title>
<link>http://perimetergrid.com/wp/2008/05/16/charter-communications-using-ad-replacer/</link>
<description>A story in the New York Times tells us that Charter Communications (the United States&amp;#8217;s fourth-largest cable company) is going to start tracking user behavior and using it to sell ads.  They spin this as a potential problem because of privacy implications &amp;#8212; it means that the cable company is watching your web surfing so [...]</description>
</item>
<item>
<title>Data Hiding at the Airport</title>
<link>http://perimetergrid.com/wp/2008/05/01/data-hiding-at-the-airport/</link>
<description>According to the EFF blog, customs has taken to randomly searching electronic devices for suspicious data.  It is somewhat mysterious what they are searching them for &amp;#8212; given only a few minutes and a technically unskilled border guard doing the searching, it&amp;#8217;s hard to imagine them actually finding anything better hidden than a file on [...]</description>
</item>
<item>
<title>Ad Replacers Let Dan Kaminsky RickRoll the Entire Web</title>
<link>http://perimetergrid.com/wp/2008/04/23/ad-replacers-let-dan-kaminsky-rickroll-the-web/</link>
<description>I&amp;#8217;ve talked before about ad replacers, where ISPs dynamically edit the contents of web traffic for their customers, replacing ads on web sites with ads of their own. This is a threat to the business model of the internet, as if done on a wide scale it would render small, advertiser-supported websites unable to [...]</description>
</item>
<item>
<title>Surveillance and Ubiquity</title>
<link>http://perimetergrid.com/wp/2008/04/10/surveillance-and-ubiquity/</link>
<description>HexView has an article about tracking vehicles with RFID tire pressure monitors. The devices are found in tires and transmit tire pressure to the engine control module, which sounds innocuous enough, but to prevent modules from reading neighboring cars&amp;#8217; tires by accident, they also transmit a unique ID. Thus, you can follow a [...]</description>
</item>
<item>
<title>Blacklists and Cross-Site Scripting</title>
<link>http://perimetergrid.com/wp/2008/04/08/blacklists-and-cross-site-scripting/</link>
<description>Microsoft gets a lot of criticism over Internet Explorer not being &amp;#8220;standards-compliant.&amp;#8221; However, it&amp;#8217;s actually not so simple, for a variety of reasons. One of them is that the web itself is not very standards-compliant &amp;#8212; while IE8 has a standards-compliant-browser mode, it has to offer an IE7 rendering fallback mode because most [...]</description>
</item>
<item>
<title>Mom lets 9-year-old take subway home alone!</title>
<link>http://perimetergrid.com/wp/2008/04/03/mom-lets-9-year-old-take-subway-home-alone/</link>
<description>The Today Show has a cover story today entitled &amp;#8220;Mom lets 9-year-old take subway home alone.&amp;#8221; The controversy over this &amp;#8212; that is, the fact that there is any &amp;#8212; is a wonderful example of how poorly people assess risk in modern society. What this woman, Lenore Skenazy, has done to stir up [...]</description>
</item>
<item>
<title>Ad Replacers and the Future of the Internet</title>
<link>http://perimetergrid.com/wp/2008/03/10/ad-replacers-and-the-future-of-the-internet/</link>
<description>A company named Phorm (formerly 121Media) has introduced a new product for ISPs.  The idea is that the ISP installs this product (basically a transparent proxy) on their network, and as their customers surf the web, the OIX  proxy replaces advertisements on web pages with advertisements on the Phorm network.  To make it more palatable, [...]</description>
</item>
<item>
<title>Whole-Disk Encryption Cracked</title>
<link>http://perimetergrid.com/wp/2008/02/28/whole-disk-encryption-cracked/</link>
<description>Early this week, some researchers at Princeton University&amp;#8217;s Center for Information Technology Policy released a fascinating video of whole-disk encryption being cracked quite quickly and easily.
Whole-disk encryption products &amp;#8212; such as PGP Whole Disk Encryption, TrueCrypt System Encryption, and Windows Vista&amp;#8217;s BitLocker &amp;#8212; work by encrypting the entire hard disk with a symmetric key, save [...]</description>
</item>
<item>
<title>Deterring the Internal Attacker</title>
<link>http://perimetergrid.com/wp/2008/02/18/deterring-the-internal-attacker/</link>
<description>On January 21st, 2008, the major French bank Société Générale lost $7.09 billion attempting to unwind unauthorized trading positions taken by Jérôme Kerviel, a futures trader with the bank. Kerviel had taken positions worth $73.3 billion, far above not only his trading limits but the bank&amp;#8217;s entire market capitalization. The loss taken [...]</description>
</item>
<item>
<title>ASUS Eee PC and Linux vmsplice Vulnerabilities</title>
<link>http://perimetergrid.com/wp/2008/02/11/asus-eee-pc-and-linux-vmsplice-vulnerabilities/</link>
<description>It wasn&amp;#8217;t a good weekend for Linux.
The ultraportable ASUS Eee PC has seen quite a bit of publicity lately. With prices starting as low as $300, it&amp;#8217;s about as cheap as laptops get, and runs on a solid-state drive instead of a hard disk. Of course, to get such a low price, it [...]</description>
</item>
<item>
<title>OS-Based Mitigations Against Common Attacks</title>
<link>http://perimetergrid.com/wp/2008/02/04/os-based-mitigations-against-common-attacks/</link>
<description>In my last post about finding a job in information security, when discussing application security, I off-handedly mentioned several mitigation technologies &amp;#8212; GS, DEP, SAL, and ASLR. These are technologies developed by OS vendors to provide system-wide protection against common attacks, and are things every application developer should know about when dealing with native [...]</description>
</item>
<item>
<title>How to Get a Job in Information Security</title>
<link>http://perimetergrid.com/wp/2008/01/31/how-to-get-a-job-in-information-security/</link>
<description>Don Parker at SecurityFocus has an article called Skills for the Future about how to get a job in information security. He outlines one path, and while I don&amp;#8217;t deny it&amp;#8217;s a good one, and probably the most common, it&amp;#8217;s not the only way, either.
There are quite a few different areas of specialization within [...]</description>
</item>
</channel>
</rss>
