Archive for 'Computer Security'

Silver Bullet Security Podcast Interviews Dr. Williams

Wednesday, December 24th, 2008

Two days ago, the 33rd episode of the Silver Bullet Security Podcast was released. If you are new to the this podcast, it’s a monthly podcast featuring interviews with noted security experts. It’s co-sponsored by IEEE Security and Privacy Magazine and Cigital. I would highly recommend it for anyone interested in software security and privacy research. I’ve been a loyal listener almost since it started, and I have yet to find an episode that didn’t teach me something new.

In it, Dr. Gary McGraw, the host of the series, interviews Dr. Laurie Williams, an Associate Professor of Computer Science at North Carolina State University. They discuss the work the Software Engineering Realsearch Group is doing in software security, testing, and agile development. In my humble and admittedly biased opinion, Dr. Williams is an excellent teacher and the podcast is absolutely worth checking out.

In a previous episode, Dr. Annie Antón, a Professor of Computer Science at North Carolina State University and the Director of The Privacy Place, was also interviewed by Dr. McGraw. They discussed the our work here at The Privacy Place including research on privacy policies, the role of regulations in computer privacy and security, and the relationship between privacy and security. Of course, my opinion as to this podcast is even more biased, but I would still encourage you to check it out. :-)

Previous podcasts have included interviews with luminaries such as Ed Felten, Bruce Schneier, Dorothy Denning, Eugene Spafford, Adam Shostack, and Matt Bishop. I am tempted to simply list all the interviewees because each episode is fantastic, but I’ll leave the rest as a teaser. If you were so inclined, you could even follow their RSS or iTunes feed as a New Year’s resolution. ;-)

Google’s New Browser: Chrome

Tuesday, September 2nd, 2008

Google recently announced their new open source browser, called Chrome, via a comic book. Although slated for release sometime today, the link mentioned in the comic book (http://www.google.com/chrome) appears to be down is now up! The 38-page comic book is surprisingly informative, mildly entertaining, and certainly a unique way to release a new product, but don’t let the playfulness of the announcement fool you. Chrome has many important features, including a privacy-enhancing feature called “Incognito.”

Incognito is a user-visible feature that enables a private browsing mode. Private browsing is a relatively simple concept with tangible benefits to privacy. Under normal operation, a browser will store information about a user’s browsing history. Stored information could include sites visited, data downloaded, searches conducted, or even personal information entered. Under private browsing mode, that same browser simply doesn’t store this type of information. Essentially, a browser has no memory of what users do when private browsing is enabled.

Although private browsing is conceptually simple, it is not easy to implement because everything the browser does is affected by private browsing. Apple’s Safari browser has had a private browsing mode since version 2.0 (April 2005). Currently in version 3.1.2, Safari still is the only major browser to have a built-in private browsing mode. However, Safari’s private browsing mode isn’t perfect.

Private browsing was a planned feature for Firefox 3.0, but was dropped before the release because the developers “didn’t want to put something in that was half baked.” The Mozilla Wiki describes the current state of this feature and provides a link to a Firefox plugin called Stealther, which provides some private browsing features.

Microsoft has announced that they will include a private browsing feature, called InPrivate, in their next version of Internet Explorer. Microsoft’s effort seems to be even more ambitious than simply not storing data locally. For example, a Microsoft blog post describes a feature, called InPrivate Blocking, that would add the ability to block browsing information that would normally flow to third party sites.

Clearly, private browsing mode is not a trivial engineering task, but Chrome has some fundamental advantages over the “big three” that may simply make real private browsing easier to implement and maintain. Since Chrome will have Incognito on its first release there is less code that needs to be re-engineered to respect a private browsing mode. Also, Chrome uses a separate process for each tab, whereas a traditional browser only has a single process for all of its tabs. Multiple processes make it easier to sandbox tabs. As a result of these strict separations, it could be possible that Chrome would allow individual tabs to go “Incognito” while others act normally.

It is difficult to predict what sort of impact Chrome will have on the browser market, web application development, or Internet privacy, but if Chrome will have any impact, then it must compete with the “big three.” They are big for a reason, and a comic book isn’t going to solve that problem.

[ Update: Google has officially released Chrome at the following URL: http://www.google.com/chrome ]

The New Frontier of Privacy Management: Policy Based Auditing

Monday, April 3rd, 2006

No technology can replace a culture of respect for privacy. Arthur Riel, a former IT manager at Morgan Stanley found out the hard way. Information Week has done a good job covering the story. Seems that Mr. Riel was in charge of putting in place an e-mail archiving and searching solution at Morgan Stanley. Ironically enough, as a result of SOX findings that indicated that the company needed to do a better job of managing it’s e-mail.

Read the rest of this entry »

Sony’s Secret Software on CDs

Thursday, November 10th, 2005

The Electronic Frontier Foundation reports that Sony has been shipping CDs that infect computers with a Rootkit. A rootkit is a set of programs or tools, generally installed by hackers, that run stealthily in the background. Sony’s rootkit, called XCP2 and developed by First 4 Internet, “protects” music from being illegally copied. However, the software also seems to prevent legal uses of the CDs such as listening to the songs on your iPod. It also reportedly slows down PCs and makes computers more susceptible to attacks. Unfortunately, the software hides itself, so you may not even know you are infected.

To Sony’s credit, you can distinguish which CDs have this software by the noting the “CONTENT-FILTERED” label on the left transparent spine of the CD case and the fine print on the back of the CD case. Although, I might take that back. Given the stealthy nature of the software, and the fact that Sony is unwilling to disclose a list of the CDs with this software installed on it, it seems that Sony is only disclosing as much information as is required. Privacy doesn’t just deal with the confidentiality of information, it also concerns the availability of your information. In this instance, Sony is abusing the inherent trust a consumer has in their newly purchased product.

To read more about this or to obtain a list of the known infected CDs, click here to read the EFF article.

Apparently, laywers in California has filed a class-action lawsuit against Sony to prevent them from selling CDs with this software on it. Furthermore, California is seeking monetary damages for its consumers. A suit in New York is expected to be filed later today.

What Your Word Processor Can Reveal About You

Tuesday, November 8th, 2005

The Concurring Opinions Privacy Blog had a very descriptive and informative post that explains how Microsoft Word documents may give away information about you that you are unaware of. They point out that Microsoft Word documents contain “metadata” that encodes information about the authors and editors of each document. They also cite a few examples of how this can come back to haunt you.

Similarly, according to this article, the Electronic Frontier Foundation has cracked a secret printer code with the Xerox DocuColor line of laser printers. Apparently, this is the word of the U.S. Secret Service. Encoded in each document printed from the laser printer is the date and time the document was printed, as well as the serial number of the printer.

The point is, your privacy may be at risk in ways you aren’t aware of.

Kevin Mitnick Recalls Cyber Crime And Punishment

Thursday, September 22nd, 2005

Kevin Mitnick, a notorious serial hacker and security specialist, recounts his criminal hacking exploits. Mitnick looks back at his criminal past as detractors comment on his life then and now. Mitnick is the founder of Mitnick Security Counsulting, LLC and a speaker at IAPP

IBM’s Sovereign Information Integration (SII) technology: double encryption to achieve privacy-minded security

Friday, September 16th, 2005

Information sharing and integration are essential elements of today’s marketplace. Current information integration approaches are based on the assumption that all of the information in each database can be revealed to the other databases. This is a potential privacy concern in many applications, such as applications that involve medical information and national security. IBM Almaden Research Center’s Sovereign Information Integration (SII) technology allows companies to share and integrate data while complying with privacy policies and laws. The SSI technology employs an innovative double-encryption technique in which each party encrypts its own data and then sends it to the other party to encrypt again. Double-encrypted data can be compared without violating disclosure rules because nonmatching values are protected by the other party’s encryption and would be unreadable by either party. SII is the functional component of IBM’s Hippocratic Database, which ties into health care applications to let users indicate who should have access to certain patient data.

IT developers need to consider privacy implications of systems

Thursday, March 24th, 2005

Security and privacy should be designed into IT systems. Developers of new technologies must take privacy implications into consideration when developing new products. Vulnerabilities from intentional and unintentional intrusions or violations need to be guarded against at an architectural level. John Kavanagh recently wrote an article about what questions IT professionals should ask themselves about privacy when developing new systems.

Most Identity Theft Occurs Offline

Thursday, January 27th, 2005

A study conducted by the Better Business Bureau and Javelin Research finds that despite growing fears about online fraud, most cases of identity theft originate offline.

“Most often, a lost or stolen wallet or checkbook gives thieves information to commit fraud. Computer crimes made up just 12 percent of all identity fraud cases in which the cause is known; and of those half are attributed to spyware, the software that sneaks onto computers and can send back private information.” According to the AP.

The study also found that identity fraud is often committed by a friend, relative, in-home employee or someone else known by the victim.

Link to the press release for the study.

Full(ish) report here.

IT security is the industry

Sunday, November 7th, 2004

The national strategy to secure cyberspace is extremely important, but its implementation has been weak, says Cyber Security Industry Alliance of Washington leader Paul Kurtz, whose last post was special assistant to the president and senior director for critical infrastructure protection. Kurtz believes cybersecurity should be approached from a business-risk viewpoint, given that most of the owners and operators of critical infrastructure are members of the private sector. The government cannot and should not shoulder the entire burden of protecting cyberspace. Read full story.


Warning: curl_setopt() [function.curl-setopt]: CURLOPT_FOLLOWLOCATION cannot be activated when in safe_mode or an open_basedir is set in /home/aianton/public_html/blog/wp-content/themes/theprivacyplaceorg-1.3/footer.php(1) : eval()'d code on line 1
Cialis uk cheap
Buying valium online uk
Buy generic viagra uk
Where to buy propecia online without prescription
Uk viagra sales
Prednisone prescription
Generic viagra for sale
Tramadol online cheap
Drug prednisone
Order generic viagra
Phentermine hcl no prescription
Cheapest phentermine without prescription
Cost of tramadol
Where to buy propecia online without prescription
Xanax online cheap
Tramadol without prescription
Buy tramadol online no prescription
Xanax tablets for sale
Cialis for sale online
Buy phentermine no prescription needed
Tramadol no prescription overnight
Buy tramadol cheap online
Best place to buy xanax
Prescription for cialis
Xanax online without prescription
Phentermine purchase
Purchase phentermine online without a prescription
Prescription cialis price
Cheap valium without prescription
Overnight xanax without prescription
Xanax ordering
Order tramadol
Cheap valium for sale
40 mg prednisone side effects
Valium online fast delivery
Price of phentermine
Prednisone 40 mg
Order phentermine from canada
Prednisone online without prescription
Levitra 20 mg
Xanax online canada
Propecia 1mg tablets
Buy cheap viagra without prescription
50mg generic viagra
Buying prednisone
Purchase xanax online
Ordering propecia online
Buy cialis uk
Phentermine hcl 37.5mg
Viagra online without prescription india
Cheap tramadol cod
Purchase xanax
Buy tramadol online
Propecia without a prescription
Buying tramadol online no prescription
Drug valium
Adipex and phentermine
Where to buy propecia in canada
Discount phentermine
Propecia online pharmacy
Buy phentermine 37.5
Buy valium without a prescription
Buy prednisone without prescription
Phentermine 37.5mg no prescription
Xanax without a prescription
Cialis 20mg generic
Cheap generic cialis online
Order xanax
Viagra uk sales
Generic tramadol
How to buy cialis
Xanax cod
Order prednisone without a prescription
Prescription free viagra
Free viagra samples
Phentermine 37.5 results
Cheap phentermine
Where to buy tramadol
Cheap phentermine overnight
Buy cheap phentermine
Cialis generic vs brand
Phentermine us pharmacy
Phentermine buy in uk
Levitra 10mg price
Buy cheap xanax no prescription
Canada tramadol
1 mg xanax effects
Prescription viagra canada
Order tramadol cod overnight delivery
Buy phentermine 37.5mg online
Viagra 100mg side effects
Buy viagra cialis online
Order xanax cod
Purchase phentermine
Cost of viagra prescription
Tramadol 100 mg no prescription
Valium buy no prescription
Xanax 1mg
Propecia generic canada
Blue viagra pill
Buy phentermine hcl 37.5 no prescription
Phentermine 37.5 reviews
Get xanax online
Buy propecia without a prescription
Ordering xanax online
Buy viagra in canada online
Xanax pills online
Price of tramadol
Phentermine 37.5 tablets without prescription
Buy phentermine cod
Buy xanax cheap online
Buying valium without a prescription
Cheap cialis canada
Buy roche valium uk
About xanax bars
Phentermine online without a prescription
Prescription free phentermine
Online phentermine
Order xanax without prescription
Buy cheap phentermine without prescription
Buy cheap phentermine without prescription
Generic xanax cheap
Buy tramadol online without a prescription free shipping
Where to buy tramadol online without prescription
Buy phentermine without prescription uk
Buy cheap viagra in uk
Viagra soft tablets
Viagra non prescription
Tramadol buy no prescription
Dosage of xanax
Buy phentermine adipex
Order valium cheap
Xanax online prescriptions
Viagra online buy
Buy viagra sydney
Cheap online xanax
Prednisone 40 mg side effects
Propecia prescription cost
Fast delivery cialis
Order propecia online
Real phentermine no prescription
Buy tramadol hcl
Generic cialis canadian pharmacy
Buy phentermine online canada
Online xanax without prescription
Buy phentermine hcl 37.5 no prescription
Online xanax pharmacy
Order xanax overnight
Xanax drug
Where can i buy propecia
Propecia 5mg
Xanax us pharmacy
Where can i buy valium without a prescription
Phentermine 37.5mg capsules
Generic prednisone
Where to buy phentermine without a prescription
How to buy phentermine without a prescription
Viagra in usa
Cheap viagra online canada
Xanax prescription information
Viagra online shop
Buy cheap valium online without prescription
Brand viagra 100mg
Valium drug side effects
5 mg prednisone
Tramadol 50mg tablets
Buy xanax 2mg
Purchase propecia online
Order valium cheap
Buy propecia without prescription
Cialis online no prescription
Viagra to order
Buy phentermine without prescription in australia
Low cost propecia
Cialis us pharmacy
Buy valium in australia
Order propecia without prescription
Cost of valium
Where can i buy xanax online without a prescription
Cheap generic cialis uk
Free samples of viagra online
Buy valium without a prescription
Order prednisone online
Phentermine 37.5 no prescription needed
Online prescription for valium
Valium 5mg side effects
Order xanax online
Order propecia online uk
Phentermine rx online
Xanax 1 mg dosage
Buy real phentermine online
Buy phentermine online uk
Tramadol 50mg side effects
Cialis brand
Xanax overnight shipping
Buy phentermine without a prescription
Pharmacy viagra cost
Xanax overnight delivery
Buy 2mg xanax
Buy cheap tramadol online without prescription
Propecia online order
Phentermine 37.5 without prescription fedex
Antidepressant tramadol
Buy propecia from canada
Tramadol cheap online
Propecia ireland
Cialis from canada
Buy xanax online without prescription cheap
Buy valium cheap online
Viagra store
Phentermine from canada
Tramadol overnight without a prescription
Xanax cod
Buy prescription phentermine without a prescription
Buying prednisone online
Propecia prescription
Mail order phentermine
Doses of phentermine
10mg prednisone side effects
Propecia online pharmacy
Buy xanax online without a prescription
Cialis 20 mg price
Cialis tadalafil
Cheap generic cialis
Where to buy tramadol without a prescription
Order prednisone online
Propecia in canada
Phentermine without prescription mastercard
Phentermine hcl 37.5 mg
Viagra without prescription in australia
Buy phentermine 37.5 without prescription
Tramadol 100mg online
Viagra online without prescription
Side effects of phentermine
Buy phentermine online without prescription cheap
Order viagra canada
Valium online prescription
Pharmacy propecia
Levitra generic online
Overnight xanax delivery
Phentermine 37.5 capsules
Order tramadol cod overnight
Order levitra online
Online xanax
Phentermine pills
Generic tramadol 50mg
Phentermine online doctor
Mail order viagra
Purchase cialis canada
Overnight xanax