<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Spohn Solutions</title>
	<atom:link href="http://spohnsolutions.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://spohnsolutions.com</link>
	<description>Navigating Business Solutions</description>
	<lastBuildDate>Wed, 25 Jan 2012 17:14:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Ivan Ristic on Web Security</title>
		<link>http://spohnsolutions.com/2011/08/15/ivan-ristic-on-web-security/</link>
		<comments>http://spohnsolutions.com/2011/08/15/ivan-ristic-on-web-security/#comments</comments>
		<pubDate>Mon, 15 Aug 2011 17:41:24 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[cookies]]></category>
		<category><![CDATA[Ivan Ristic]]></category>
		<category><![CDATA[SPDY]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[web security]]></category>

		<guid isPermaLink="false">http://spohnsolutions.com/?p=1611</guid>
		<description><![CDATA[Ivan Ristic of SSL Labs, a research division of Qualys, talks about web security and endorses Google’s new SPDY protocol, which improves performance and is secure by default.  Ristic emphasizes security should be by default, and not susceptible to mistakes by administrators and developers.   He backs the idea that all web transactions should be done...]]></description>
			<content:encoded><![CDATA[<p>Ivan Ristic of SSL Labs, a research division of Qualys, <a href="http://link.brightcove.com/services/player/bcpid1099485820001?bctid=1099472186001">talks</a> about web security and endorses Google’s new SPDY protocol, which improves performance and is secure by default.  Ristic emphasizes security should be by default, and not susceptible to mistakes by administrators and developers.   He backs the idea that all web transactions should be done over SSL, and points out that often sites that use SSL fail to ensure the cookies are secure as well, often entirely defeating the purpose of using SSL in the first place.</p>
]]></content:encoded>
			<wfw:commentRss>http://spohnsolutions.com/2011/08/15/ivan-ristic-on-web-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Token Gesture: PCI Security Standards Council Introduces Encryption</title>
		<link>http://spohnsolutions.com/2011/08/15/token-gesture-pci-security-standards-council-introduces-encryption/</link>
		<comments>http://spohnsolutions.com/2011/08/15/token-gesture-pci-security-standards-council-introduces-encryption/#comments</comments>
		<pubDate>Mon, 15 Aug 2011 16:51:53 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[credit cards]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[PAN]]></category>
		<category><![CDATA[pci]]></category>
		<category><![CDATA[security standards]]></category>
		<category><![CDATA[token]]></category>
		<category><![CDATA[tokens]]></category>

		<guid isPermaLink="false">http://spohnsolutions.com/?p=1608</guid>
		<description><![CDATA[This month the PCI Security Standards Council released a paper describing the use of tokens in place of the PAN (Primary Account Number).  While this is far from being a magic bullet that solves all security issues inherent in credit card processing, and does not remove the need for PCI certification for card processors, in...]]></description>
			<content:encoded><![CDATA[<div>This month the PCI Security Standards Council released a <a href="http://library.constantcontact.com/download/get/file/1102621924087-98/Tokenization+Guidelines+Info+Supplement.pdf">paper</a> describing the use of tokens in place of the PAN (Primary Account Number).  While this is far from being a magic bullet that solves all security issues inherent in credit card processing, and does not remove the need for PCI certification for card processors, in certain situations it could help considerably.</p>
<p>The fact is, the less frequently PANs traverse networks, the less chance they’ll be snooped.  The basic idea here is practiced all over the Internet already.  Instead of sending the PAN, encrypt it, and send a “token” instead.</p>
<p>The first analogy that comes to my mind is the use of salted hash functions to protect the contents of /etc/passwd on UNIX systems.  Many years ago /etc/passwd, a text file involved in local authentication for UNIX, actually contained the passwords of all the users.  After some time people took to encrypting the passwords with hash and salt, and later moving the encrypted contents out of /etc/passwd entirely into /etc/shadow.</p>
<p>This is similar to the process described here.  Instead of authenticating a purchase by passing the actual PAN data, the PAN is encrypted or tokenized, and then decrpyted/detokenized at the other end.  The analogy isn’t perfect, some tokens are multi-use, etc&#8230; but the basic concept is the same &#8211; encrypt the PAN so it’s not as often transmitted and stored “in the clear.”</p></div>
<p>While the idea of encrypting cardholder data is far from revolutionary, it&#8217;s at least encouraging to see the effort.  Furthermore, the fact this isn&#8217;t a new concept means it should be easy for the engineers implementing it to grasp.</p>
]]></content:encoded>
			<wfw:commentRss>http://spohnsolutions.com/2011/08/15/token-gesture-pci-security-standards-council-introduces-encryption/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft still not ready for the Internet.</title>
		<link>http://spohnsolutions.com/2011/08/15/microsoft%e2%80%99s-still-not-ready-for-the-internet/</link>
		<comments>http://spohnsolutions.com/2011/08/15/microsoft%e2%80%99s-still-not-ready-for-the-internet/#comments</comments>
		<pubDate>Mon, 15 Aug 2011 15:57:15 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[MS11-058]]></category>
		<category><![CDATA[MS11-0587]]></category>
		<category><![CDATA[remote attacks]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://spohnsolutions.com/?p=1603</guid>
		<description><![CDATA[This month Microsoft pushed 13 security bulletins to address 22 vulnerabilities in its software.  The 2 most notable vulnerable software issues were a flaw in the Windows DNS server, and 7 in their Internet Explorer browser. The IE vulnerabilities affect all supported versions of Internet Explorer up to and including IE 9. The August Patch...]]></description>
			<content:encoded><![CDATA[<p><br id="internal-source-marker_0.9598464935552329" />This month Microsoft pushed 13 security bulletins to address 22 vulnerabilities in its software.  The 2 most notable vulnerable software issues were a flaw in the Windows DNS server, and 7 in their Internet Explorer browser.</p>
<p>The IE vulnerabilities affect all supported versions of Internet Explorer up to and including IE 9. The August Patch Tuesday update purportedly fixes errors in the way IE handles objects in memory and handles JavaScript handlers.</p>
<p>According to MS11-057, Microsoft said an attacker who successfully exploited any of the vulnerabilities could gain the same user rights as the local user, and the most severe vulnerabilities could allow remote code execution if a user uses IE to visit a specially crafted webpage.</p>
<p>Jason Miller, manager of research and development at VMware’s Shavlik Technologies, said the IE flaws and the Windows DNS error allows cybercriminals to attack systems remotely. Any time there’s a public vulnerability “out in the wild, it’s important to disclose it as soon as possible,” Miller said.</p>
<p>I remember as a young system administrator, back in 2000, maintaining a policy that no Windows host was allowed to receive connections directly from the Internet.  This policy was a result of experience, because any time anyone deviated from the policy the Windows hosts in question would be compromised.  As a result, we kept all the Windows hosts behind layers of firewalls, placed Sendmail hosts in front of the Exchange server, and reverse-proxies in front of IIS servers.   At the time  I remember thinking “well&#8230; Microsoft just isn’t mature enough to play on the Internet yet, that’s why we have UNIX/Linux.”</p>
<p>Seems not a lot has changed since then.</p>
<p>“Patching administrators also must address server-side vulnerabilities. MS11-058 addresses two privately reported vulnerabilities in the Windows DNS server. The flaws affect the server side rather than a client request to a DNS server. If the company DNS servers have caching of DNS relaying enabled, the system is at risk. Otherwise, if the DNS role is not enabled, users are not at risk, although they should still deploy the patch to be on the safe side,” Miller said.</p>
<p>Remote root attacks against DNS servers are so 1999.</p>
<p>I wonder if Microsoft will ever have an operating system that doesn’t require hand holding.  My guess is as long as people vote with their dollars, the answer is “no.”</p>
]]></content:encoded>
			<wfw:commentRss>http://spohnsolutions.com/2011/08/15/microsoft%e2%80%99s-still-not-ready-for-the-internet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TW Telecom Awarded 5 Year Contract With Texas</title>
		<link>http://spohnsolutions.com/2011/08/12/tw-telecom-awarded-5-year-contract-with-texas/</link>
		<comments>http://spohnsolutions.com/2011/08/12/tw-telecom-awarded-5-year-contract-with-texas/#comments</comments>
		<pubDate>Fri, 12 Aug 2011 19:30:03 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Telecom Blog]]></category>
		<category><![CDATA[telecom]]></category>
		<category><![CDATA[texas]]></category>
		<category><![CDATA[time warner]]></category>
		<category><![CDATA[TW telecom]]></category>

		<guid isPermaLink="false">http://spohnsolutions.com/?p=1599</guid>
		<description><![CDATA[Time Warner Telecom was just awarded a five-year contract with the State of Texas. Under the terms of contract, TW Telecom will supply Ethernet, converged and VPN solutions to all of Texas&#8217; state agencies and departments.&#160; According to Nick Summit, Regional Vice President at TW Telecom, &#8220;The State of Texas has long been an important...]]></description>
			<content:encoded><![CDATA[<p>Time Warner Telecom was just awarded a five-year contract with the State of Texas. Under the terms of contract, TW Telecom will supply Ethernet, converged and VPN solutions to all of Texas&#8217; state agencies and departments.&nbsp;</p>
<p>According to Nick Summit, Regional Vice President at TW Telecom, &#8220;The State of Texas has long been an important customer of TW Telecom. We are pleased to expand our relationship with the various departments and agencies across the State of Texas and look forward to delivering our unique set of capabilities, innovative solutions and world-class customer care to the State.&#8221;</p>
<p>Having built out fiber network infrastructure throughout Texas as well as providing services for the state government, Texas has been an ongoing growth market for TW Telecom.</p>
<p>Those network bets are paying off. Over the past year, the service provider has secured contracts with a host of large business, government and even carrier customers including Gehan Homes, the Army at its Fort Bliss station in El Paso, and data center provider Core NAP.</p>
]]></content:encoded>
			<wfw:commentRss>http://spohnsolutions.com/2011/08/12/tw-telecom-awarded-5-year-contract-with-texas/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AT&amp;T to Purchase T-Mobile &#8230; the Saga</title>
		<link>http://spohnsolutions.com/2011/08/12/att-to-purchase-t-mobile-the-saga/</link>
		<comments>http://spohnsolutions.com/2011/08/12/att-to-purchase-t-mobile-the-saga/#comments</comments>
		<pubDate>Fri, 12 Aug 2011 18:55:50 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Telecom Blog]]></category>
		<category><![CDATA[ATT]]></category>
		<category><![CDATA[T-mobile]]></category>
		<category><![CDATA[telecom]]></category>
		<category><![CDATA[telecommunications]]></category>

		<guid isPermaLink="false">http://spohnsolutions.com/?p=1596</guid>
		<description><![CDATA[In the continuing saga of AT&#38;T to purchase T-Mobile USA&#8230; AT&#38;T filed additional information with the FCC to support its proposal to acquire T-Mobile USA. Among the benefits justifying the purchase, AT&#38;T claims wireless pricing will fall and service quality would rise if the purchase is approved. Since initial announcement of their intention in March,...]]></description>
			<content:encoded><![CDATA[<div>In the continuing saga of AT&amp;T to purchase T-Mobile USA&#8230;</p>
<p>AT&amp;T filed additional information with the FCC to support its proposal to acquire T-Mobile USA. Among the benefits justifying the purchase, AT&amp;T claims wireless pricing will fall and service quality would rise if the purchase is approved.</p>
<p>Since initial announcement of their intention in March, AT&amp;T has been trying justify the purchase by proving the merger would benefit consumers with lower prices and improved service. A couple weeks ago the FCC asked the company for more information regarding the deal.  AT&amp;T, in their letter, said the deal would “relieve significant capacity constraints faced by both companies and lead to improved service quality.” The data include analyses of 15 major markets, including metropolitan centers such as New York, L.A., and San Francisco.<br />
The analysis focuses on how the merger would lower costs and pricing as AT&amp;T and T-Mobile gain efficiencies after combining their networks, whether that reflects reality after the event of a merger remains to be seen.</p>
<p>Sprint responded by dismissing AT&amp;T’s analysis. Sprint Senior VP of Government Affairs, Vonya McCann, said “AT&amp;T’s do-over submission is a last-ditch attempt to distract regulators, politicians, and consumers from the fact that it has failed to provide any evidence that its proposed takeover of T-Mobile yields meaningful benefits.”</p>
<p>McCann maintains AT&amp;T’s new statement does not change the negative consequences of the takeover. In fact, the merge would raise prices, reduce innovation, and decrease investment.<br />
The FCC normally reviews mergers within 180 days, but gave AT&amp;T an extension to file additional information. Now that AT&amp;T has given more data regarding the proposed merger, the FCC is expected to restart the clock. The deal must also receive approval from the Department of Justice.</p>
<p>Telecom in the US is like an accordion, with the split into the regional Bell operating centers (RBOC) in the 80’s to now, when we come full circle and once again head toward monopoly.</p></div>
]]></content:encoded>
			<wfw:commentRss>http://spohnsolutions.com/2011/08/12/att-to-purchase-t-mobile-the-saga/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Amazon Web Services Announces IAM (Identity and Access Management)</title>
		<link>http://spohnsolutions.com/2011/08/09/amazon-web-services-announces-iam-identity-and-access-management/</link>
		<comments>http://spohnsolutions.com/2011/08/09/amazon-web-services-announces-iam-identity-and-access-management/#comments</comments>
		<pubDate>Tue, 09 Aug 2011 21:03:55 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Active Directory]]></category>
		<category><![CDATA[AWS]]></category>
		<category><![CDATA[cloud]]></category>
		<category><![CDATA[LDAP]]></category>

		<guid isPermaLink="false">http://spohnsolutions.com/?p=1591</guid>
		<description><![CDATA[Amazon was one of the first players to take cloud services seriously, and more importantly, to offer them to us.  As an early adopter of EC2 and S3, I was excited to read on August 3rd they have added the ability for us to include our existing LDAP and Active Directory federations into their own...]]></description>
			<content:encoded><![CDATA[<p>Amazon was one of the first players to take cloud services seriously, and more importantly, to offer them to us.  As an early adopter of EC2 and S3, I was excited to read on August 3rd they have added the ability for us to include our existing LDAP and Active Directory federations into their own <a href="http://aws.amazon.com/iam/">security model</a>.<br />
For example, before if I wished to allow a user access to a home directory in Amazon&#8217;s cloud, I&#8217;d have had to create an AWS identity to manage.  Since single sign on is a goal most IT shops (and in my case consultants) aspire to, it&#8217;s nice to be able to extend existing LDAP/AD trees into the cloud.  Now, I can grant access to users locally in LDAP or Active Directory, and it will enable access with temporary security credentials which can sign AWS requests.</p>
<p>IAM enables you to control access to AWS service APIs and specific resources. IAM also enables you to add granular conditions which control exactly how a user can use AWS, such as time of day, their  IP address, or even if the connection is SSL or not.<br />
IAM can be used to grant your employees, and applications access to AWS service APIs, using your existing identity systems such as LDAP or Active Directory.<br />
It is now possible to enable your mobile and browser-based applications to securely access AWS resources by requesting temporary security credentials that only grant access to specific AWS resources, for a a specified period of time.</p>
]]></content:encoded>
			<wfw:commentRss>http://spohnsolutions.com/2011/08/09/amazon-web-services-announces-iam-identity-and-access-management/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Reddit Founder Accused of IP Theft</title>
		<link>http://spohnsolutions.com/2011/07/20/reddit-founder-accused-of-ip-theft/</link>
		<comments>http://spohnsolutions.com/2011/07/20/reddit-founder-accused-of-ip-theft/#comments</comments>
		<pubDate>Wed, 20 Jul 2011 18:49:44 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[Aaron Swartz]]></category>
		<category><![CDATA[demand progress]]></category>
		<category><![CDATA[Harvard]]></category>
		<category><![CDATA[IP theft]]></category>
		<category><![CDATA[JSTOR]]></category>
		<category><![CDATA[MIT]]></category>
		<category><![CDATA[reddit]]></category>

		<guid isPermaLink="false">http://spohnsolutions.com/?p=1583</guid>
		<description><![CDATA[Aaron Swartz, co-founder of news site Reddit, was indicted Tuesday on charges of breaking into the MIT network and stealing documents from JSTOR, an archive of academic journal articles.  Specifically, the indictment charges Swartz with wire fraud, unlawfully obtaining information from a “protected” computer, and recklessly damaging a protected computer.  If found guilty the penalty...]]></description>
			<content:encoded><![CDATA[<p>Aaron Swartz, co-founder of news site Reddit, was indicted Tuesday on charges of breaking into the MIT network and stealing documents from JSTOR, an archive of academic journal articles.  Specifically, the indictment charges Swartz with wire fraud, unlawfully obtaining information from a “protected” computer, and recklessly damaging a protected computer.  If found guilty the penalty is a hefty 35 years in prison and up to 1 million dollars fine.</p>
<p>According to prosecution, Swartz obtained access via a wiring closet in the basement of an MIT building. From there he accessed JSTOR and downloaded some 4.8 million articles. According to the indictment Swartz intended to make all of these journal articles free via a file sharing site.  Of the 4.8 million some 1.7 million were accessible “for pay.”</p>
<p>Some background on Swartz.  Swartz is an online political activist and programmer.  He is founder of the nonprofit Demand Progress, a civil liberties advocate group.  According to the current executive director of Demand Progress the indictment “makes no sense” and called the charges “bizarre. It&#8217;s like trying to put someone in jail for allegedly checking too many books out of the library.”</p>
<p>According to JSTOR “We stopped this downloading activity, and the individual responsible, Mr. Swartz, was identified,” the statement said. “We secured from Mr. Swartz the content that was taken, and received confirmation that the content was not and would not be used, copied, transferred, or distributed.”</p>
<p>Now, regardless of your opinion on to what degree this is activism, and what degree this is theft, a couple of statements I’m reading just don’t make sense.  For one, JSTOR claims that such a massive download harmed their servers.  Really?  Please explain to me how he physically damaged servers by using them for what they’re intended for, namely making files available for download.</p>
<p>The other thing that really annoys me is the comment by JSTOR “We secured from Mr. Swartz the content that was taken.”  Ok, so you know the content is digital, right?  If we follow the analogy that his crime is akin to checking out too many library books, this makes sense, but the thing is they didn’t need to get their books back.  The articles in question are digital.</p>
<p>If JSTOR and or MIT plan on suing Mr. Swartz, they should at least be clear that they are suing him for “intending to make copyrighted materials public.”  So, he didn’t actually even commit the crime yet, he just intended on it.</p>
<p>The elephant in the room, at least for me is how they were able to act so quickly and apprehend Swartz before he had a chance to make the files available.  To me, this stinks of setup.  Swartz is a political activist, and unfortunately in this and many other countries that makes him a target.   Given the political climate surrounding new legislation that could make it criminal to even <a href="http://www.scribd.com/doc/55146943/Protect-Ip-Summary">play copyrighted material over 10 times on youtube</a>, one could see how Swartz could have a target painted on his back.  Furthermore, During the time of the theft, Swartz ironically was a fellow at Harvard University, through which he could have accessed JSTOR services.  Curious, no?</p>
<p>In any case, Swartz was released on $100,000 bail and a trial date of September 9th.</p>
]]></content:encoded>
			<wfw:commentRss>http://spohnsolutions.com/2011/07/20/reddit-founder-accused-of-ip-theft/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyberspace, the DoD&#8217;s 5th Domain</title>
		<link>http://spohnsolutions.com/2011/07/19/cyberspace-the-dods-5th-domain/</link>
		<comments>http://spohnsolutions.com/2011/07/19/cyberspace-the-dods-5th-domain/#comments</comments>
		<pubDate>Tue, 19 Jul 2011 18:08:09 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[5th Domain]]></category>
		<category><![CDATA[cyber warfare]]></category>
		<category><![CDATA[Cyberspace]]></category>
		<category><![CDATA[Department of Defense]]></category>
		<category><![CDATA[DoD]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[leon panetta]]></category>
		<category><![CDATA[William Lynn]]></category>

		<guid isPermaLink="false">http://spohnsolutions.com/?p=1580</guid>
		<description><![CDATA[Years ago I remember sitting around at the office with a former boss of mine, who literally scoffed at the idea of foreign governments or independent agents using the Internet as a medium of warfare against the US.  I told him to “strap in” because it was already happening, and it would only become more...]]></description>
			<content:encoded><![CDATA[<div>Years ago I remember sitting around at the office with a former boss of mine, who literally scoffed at the idea of foreign governments or independent agents using the Internet as a medium of warfare against the US.  I told him to “strap in” because it was already happening, and it would only become more prevalent.</p>
<p>Well how about that?  Last week the Wiliam Lynn of the Department of Defense released a 40 page  unclassified version of its first-ever cyberspace operations strategy.  It’s a new domain, if you will, for our military branches formerly just land, water, air, and space … and now cyber-space.</p>
<p>Perhaps due to the fact the agency was victim to the attack in March, when foreign attackers stole 24,000 odd sensitive files from the Pentagon?  No wait, maybe it was the fact we’ve lost data regarding missile tracking systems?  How about satellite navigation?  Unmanned drones?   Jet fighters?  The answer is an unequivocal “yes.”  We have lost data about all of those things to foreign hackers.</p>
<p>Since the version released was the civilian, not secret version, it doesn’t go into a ton of detail.  It basically stresses increased network resilience and generally being prepared in the event something truly horrible comes our way from cyber-space.  It doesn’t go into details, and it says nothing about offensive maneuvering.</p>
<p>According to Lynn “The cyberthreats we face are urgent, sometimes uncertain and potentially devastating as adversaries constantly search for vulnerabilities,” Lynn said in a statement. &#8220;Our infrastructure, logistics network and business systems are heavily computerized. With 15,000 networks and more than seven million computing devices, the [Defense Department] continues to be a target in cyberspace for malicious activity.”</p>
<p>Soldiers will be prepared for various wartime scenarios such as &#8220;degraded cyberspace operations for extended periods and disruption during a mission.&#8221;  I wonder if these soldiers will be fueled by typical mess hall fare, or will they live on a diet of Red Bull and Hot Pockets?  Will “Reveille” be sounded for these particular soldiers at 4 in the afternoon?  Will they wear normal military dress or will Slayer shirts suffice?  I digress&#8230;</p>
<p>Besides training cyber-soldiers, the DoD has deployed a system of sensors and other software to gather intelligence, a giant intrusion detection network if you will.</p></div>
]]></content:encoded>
			<wfw:commentRss>http://spohnsolutions.com/2011/07/19/cyberspace-the-dods-5th-domain/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Android Malware, David and Goliath, etc&#8230;</title>
		<link>http://spohnsolutions.com/2011/07/13/android-malware-david-and-goliath-etc/</link>
		<comments>http://spohnsolutions.com/2011/07/13/android-malware-david-and-goliath-etc/#comments</comments>
		<pubDate>Wed, 13 Jul 2011 15:50:45 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[android]]></category>
		<category><![CDATA[dream droid]]></category>
		<category><![CDATA[droid dream]]></category>
		<category><![CDATA[hippoSMS]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[smart phones]]></category>
		<category><![CDATA[Zeus]]></category>
		<category><![CDATA[zitmo]]></category>

		<guid isPermaLink="false">http://spohnsolutions.com/?p=1576</guid>
		<description><![CDATA[In case you&#8217;re blissfully unaware of mobile phone news, allow me to tell you one of the biggest headlines. Google-backed Android and Apple&#8217;s iPhone are in a battle to determine dominance in the cell phone market. Incumbent iPhone has been criticized of being the behemoth player in the market, the Goliath to Android&#8217;s Open Source...]]></description>
			<content:encoded><![CDATA[<p>In case you&#8217;re blissfully unaware of mobile phone news, allow me to tell you one of the biggest headlines.  Google-backed Android and Apple&#8217;s iPhone are in a battle to determine dominance in the cell phone market.  </p>
<p>Incumbent iPhone has been criticized of being the behemoth player in the market, the Goliath to Android&#8217;s Open Source David.  Apple have been accused of being heavy handed, charging fees for those who would write apps for their platform, and being overly critical of what is allowed past their sentries, and into the Apple App store.  They&#8217;ve even been slammed for charging an additional 30% of each sale, the capitalist evil of it all!</p>
<p>In short, Apple has been acting as Apple always has.  They keep their hardware and software linked.  In what many view as the stupidest thing Apple ever did, back in the 80&#8242;s unlike Windows they didn&#8217;t enter into agreements with outside hardware makers.  The result was Windows growing to a giant buggy monopoly, while Apple stayed small &#8211; yet functional.  </p>
<p>What we see today in the iPhone vs. Android battle reminds me not of Android being the underdog, the Linux if you will, to Apple&#8217;s Microsoft.   What we&#8217;re seeing in these Android app marketplaces is all of the confusion and security-hole-ridden infestation of a Microsoft bloated giant, without the benefits of the peer oversight usually associated with Open Source projects.  </p>
<p>I must confess that when I first learned and downloaded Google&#8217;s Open Source Android code way back when, I was excited that just maybe the community would have a shot at the mobile phone market.  What we have instead is utter chaos. </p>
<p>Is it the money?  Probably.</p>
<p>Unlike the Linux kernel, and major Open Source distributions, these Android app marketplaces seem to lack code review.  Not intending on throwing out the baby with the bathwater here. The conspiracy theorist in me almost thinks Apple has hired a clandestine team of hackers to write and distribute Android malware via backwater app stores in order to sully the name of Android for people who don&#8217;t understand the difference between Android and the various marketplaces that peddle Android apps. </p>
<p>About a month ago Android made the news because of the Dream Droid Lite set of malware, an encore to the Dream Droid set from a month before that.  Now we have a new round of Android malware. </p>
<p>Similar to the Droid Dream this new malware doesn&#8217;t rely on the user to manually launch the infected app to start it. Like a proper virus the malware can change its next connection time and the command-and-control server the Trojan &#8220;mothership&#8221; uses to communicate with the malware on the infected device. It can initiate an app download and create several install-related prompts that direct the victim to download other apps, send the user to malicious web addresses, and even update itself.</p>
<p>Obviously, Android users can protect themselves by downloading apps only from trusted sources and developers known by name and perhaps rating.  In short the user has to treat their phone like it were a Windows based computer.  I don&#8217;t know about you, but as much as I like the computer like features of my smart phone, I like that ultimately it isn&#8217;t a computer first, it&#8217;s a phone.  I have enough computers in my life to worry about, and Im willing to bet most of you do as well. </p>
<p>Without further ado, the latest two stars in the world of Android malware are …</p>
<p>HippoSMS:  Researchers at North Caroline State University found this one on alternative app markets in China.  It&#8217;s designed to incur charges by sending SMS messages to a hard-coded premium-rated number.  Yikes!</p>
<p>Zitmo:  A banking trojan, this piece of trash poses as a banking activation application, and then forwards all your SMS messages to a remote web server in hopes that one-time passwords banks send to customers for an extra authentication factor can be first be grabbed by the knuckleheads that birthed this crap. </p>
<p>I understand that choice is an important thing in the marketplace, and that before you install anything anywhere, CAVEAT EMPTOR.  Still, for now I&#8217;m happy me and my iPhone don&#8217;t have to worry about it. </p>
]]></content:encoded>
			<wfw:commentRss>http://spohnsolutions.com/2011/07/13/android-malware-david-and-goliath-etc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>White List, Black List, Forensics.  Finding a Needle in a Haystack.</title>
		<link>http://spohnsolutions.com/2011/07/06/white-list-black-list-forensics-finding-a-needle-in-a-haystack/</link>
		<comments>http://spohnsolutions.com/2011/07/06/white-list-black-list-forensics-finding-a-needle-in-a-haystack/#comments</comments>
		<pubDate>Wed, 06 Jul 2011 20:13:02 +0000</pubDate>
		<dc:creator>Dan</dc:creator>
				<category><![CDATA[Security Blog]]></category>
		<category><![CDATA[black list]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[RDS]]></category>
		<category><![CDATA[SPAM]]></category>
		<category><![CDATA[VIrus]]></category>
		<category><![CDATA[white list]]></category>

		<guid isPermaLink="false">http://spohnsolutions.com/?p=1573</guid>
		<description><![CDATA[A common theme in information security, since its inception, has been the concept of white lists and black lists. Whether the threat is from a virus or SPAM, typically people start by building black lists. Databases of “fingerprints” for viruses, or known SPAM messages. Eventually the black list gets so large people revert to white...]]></description>
			<content:encoded><![CDATA[<p>A common theme in information security, since its inception, has been the concept of white lists and black lists.  Whether the threat is from a virus or SPAM, typically people start by building black lists.  Databases of “fingerprints” for viruses, or known SPAM messages.  Eventually the black list gets so large people revert to white lists &#8211; that is, assume everything is suspect unless it’s on a list of known acceptable entities.  For example, when the volume of SPAM becomes too great, one sure fire way to block it is to only allow people in your address book to send you mail.  There are even services built around this concept, such as spamarrest. </p>
<p>Recently, the concept of the white list has made it’s way into data forensics.  So called “data reduction software” can reduce the time it takes to search a system, by removing known-good files, such as operating system files.  Computer forensics software like AccessData’s Forensic Toolkit automate the screening of files for specific profiles and signatures during a forensic investigation.</p>
<p>When a drive shows up in the office of a computer forensics team, the first thing to be done after cloning the drive is to eliminate as much information as possible from the research, in order to enable the researcher to focus on what’s important.  Limiting the set of information to be studied means more time is spent looking at what is important, and less time weeding through typical files associated with Windows or other known software.  In fact, NIST has created a National Software Reference Library, designed to collect software and incorporate file profiles from the software into a Reference Data Set (RDS). The RDS is a collection of digital signatures of known, traceable software applications. It currently contains data for about 11,000 software applications.</p>
<p>At Spohn consulting we employ a similar technique when searching a client’s network for malware.  We have a database of known good ports and after we collect information from all the hosts on the network we can rather quickly eliminate the fingerprints of known good services and processes, which enables us to focus on what isn’t normal.   </p>
]]></content:encoded>
			<wfw:commentRss>http://spohnsolutions.com/2011/07/06/white-list-black-list-forensics-finding-a-needle-in-a-haystack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

