<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Retina Technology Blog &#187; security</title>
	<atom:link href="http://www.retina.net/tech/category/security/feed" rel="self" type="application/rss+xml" />
	<link>http://www.retina.net/tech</link>
	<description>John Adams' views on emerging technologies, software engineering, and various hacks</description>
	<lastBuildDate>Fri, 16 Sep 2011 09:06:15 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.2</generator>
	<!-- podcast_generator="podPress/8.8.10.2" -->
	<copyright>2006-2007 </copyright>
	<managingEditor>jna@retina.net (John Adams)</managingEditor>
	<webMaster>jna@retina.net (John Adams)</webMaster>
	<ttl>1440</ttl>
	<image>
		<url>http://www.retina.net/tech/wp-content/plugins/podpress/images/powered_by_podpress.jpg</url>
		<title>Retina Technology Blog &#187; security</title>
		<link>http://www.retina.net/tech</link>
		<width>144</width>
		<height>144</height>
	</image>
	<itunes:subtitle></itunes:subtitle>
	<itunes:summary>John Adams' views on emerging technologies, software engineering, and various hacks</itunes:summary>
	<itunes:keywords></itunes:keywords>
	<itunes:category text="Technology" />
	<itunes:category text="Technology">
		<itunes:category text="Tech News" />
	</itunes:category>
	<itunes:author>John Adams</itunes:author>
	<itunes:owner>
		<itunes:name>John Adams</itunes:name>
		<itunes:email>jna@retina.net</itunes:email>
	</itunes:owner>
	<itunes:block>no</itunes:block>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://www.retina.net/tech/wp-content/plugins/podpress/images/powered_by_podpress_large.jpg" />
		<item>
		<title>Facial recognition and video search</title>
		<link>http://www.retina.net/tech/facial-recognition-and-video-search.html</link>
		<comments>http://www.retina.net/tech/facial-recognition-and-video-search.html#comments</comments>
		<pubDate>Fri, 12 Dec 2008 00:56:22 +0000</pubDate>
		<dc:creator>John Adams</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[stuff]]></category>
		<category><![CDATA[facial recognition]]></category>
		<category><![CDATA[Machine vision]]></category>
		<category><![CDATA[search engine]]></category>
		<category><![CDATA[security technologies]]></category>
		<category><![CDATA[video search engine]]></category>

		<guid isPermaLink="false">http://www.retina.net/tech/?p=171</guid>
		<description><![CDATA[Viewdle, a video search engine, launched recently, and won the 2008 LeWeb Gold prize . It&#8217;s very similar to a technology that casinos have had for years. In previous times they&#8217;d look up your face in the five-volume Griffin GOLD book, a litany of cheats. Machine vision has surpassed the book, by far. I&#8217;ve long [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://viewdle.com"><img src="http://viewdle.com/i/logo.jpg" border=0></a></p>
<p>Viewdle, a video search engine, launched recently, and won the <a href="http://www.techcrunch.com/2008/12/10/le-web-has-a-room-with-a-viewdle-startup-winners-picked/">2008 LeWeb Gold prize </a>. It&#8217;s very similar to a <a href="http://www.lasvegassun.com/news/2003/dec/29/casinos-use-controversial-database-to-catch-cheats/">technology</a> that casinos have had for years. In previous times they&#8217;d look up your face in the five-volume <i>Griffin GOLD</i> book, a litany of cheats. Machine vision has surpassed the book, by far.</p>
<p>I&#8217;ve long been fascinated by casino security. Only the military and casinos have access to massive budgets used to track, identify, and secure locations. While other corporations may have similar budgets they lack the zeal of the casinos and their lust for security technologies.</p>
<p>This application is essentially video facial recognition, combined with crowd sourced tagging. The casinos did this, but shared data between themselves across the Internet. Viewdle opens up this possibility to the public. </p>
<p><a href="http://viewdle.com/i/howitworks.png">A nice flowchart of their process is here</a>&#8230;</p>
<p>They appear to have close ties with Reuters, and Reuters is using Viewdle for their<a href="http://reuters.viewdle.com/searchm">online people search</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.retina.net/tech/facial-recognition-and-video-search.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>random media mention&#8230;</title>
		<link>http://www.retina.net/tech/random-media-mention.html</link>
		<comments>http://www.retina.net/tech/random-media-mention.html#comments</comments>
		<pubDate>Tue, 19 Aug 2008 23:36:31 +0000</pubDate>
		<dc:creator>John Adams</dc:creator>
				<category><![CDATA[conferences]]></category>
		<category><![CDATA[media]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[defcon]]></category>
		<category><![CDATA[podcast]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[wallofsheep]]></category>

		<guid isPermaLink="false">http://www.retina.net/tech/?p=115</guid>
		<description><![CDATA[My discoveries with the Wall of Sheep at Defcon 16 and it&#8217;s application to Twitter security were mentioned on the August 12, 2008 Data Security Podcast. They called me one of the &#8220;good guys&#8221;. Heh! You can listen to it here: http://datasecurityblog.wordpress.com/2008/08/11/data-security-podcast-episode-13-aug-11-2008/]]></description>
			<content:encoded><![CDATA[<p>My discoveries with the <a href="http://www.wallofsheep.com">Wall of Sheep</a> at <a href="http://www.defcon.org">Defcon 16</a> and it&#8217;s application to <a href="http://www.twitter.com">Twitter</a> security were mentioned on the August 12, 2008 Data Security Podcast.</p>
<p>They called me one of the &#8220;good guys&#8221;. Heh!</p>
<p>You can listen to it here:</p>
<p><a href="http://datasecurityblog.wordpress.com/2008/08/11/data-security-podcast-episode-13-aug-11-2008/">http://datasecurityblog.wordpress.com/2008/08/11/data-security-podcast-episode-13-aug-11-2008/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.retina.net/tech/random-media-mention.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DNS Patches released today for many platforms</title>
		<link>http://www.retina.net/tech/dns-patches-released-today.html</link>
		<comments>http://www.retina.net/tech/dns-patches-released-today.html#comments</comments>
		<pubDate>Tue, 08 Jul 2008 22:08:03 +0000</pubDate>
		<dc:creator>John Adams</dc:creator>
				<category><![CDATA[application security]]></category>
		<category><![CDATA[operations]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[systems administration]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[secuonis]]></category>

		<guid isPermaLink="false">http://www.retina.net/tech/?p=67</guid>
		<description><![CDATA[If you&#8217;re responsible for DNS at your organization, I urge you to immediately download updates for your DNS servers and patch them, today. Dan Kaminsky and other members of the DNS community announce that they are releasing patches for an extremely serious cache resolver issue impacting many vendors of DNS software, including ISC BIND and [...]]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;re responsible for DNS at your organization, I urge you to immediately download updates for your DNS servers and patch them, <strong>today</strong>. Dan Kaminsky and other members of the DNS community announce that they are releasing patches for an extremely serious cache resolver issue impacting many vendors of DNS software, including ISC BIND and Microsoft DNS.</p>
<p>The CERT advisory is <a href="http://www.kb.cert.org/vuls/id/800113">here</a>.</p>
<p>A partial overview, from <a href="http://securosis.com/publications/DNS-Executive-Overview.pdf">the PDF</a> released by Secuonis&#8230;</p>
<p><em><br />
On July 8th, technology vendors from across the industry will simultaneously release  patches for their products to close a major vulnerability in the underpinnings of the Internet. While most home users will be automatically updated, it&#8217;s important for all businesses to immediately update their networks. This is the largest synchronized security update in the history of the Internet, and is the result of hard work and dedication across dozens of organizations. </p>
<p>Earlier this year, professional security research Dan Kaminsky discovered a major issue in how Internet addresses are managed (Domain Name System, or DNS). This issue was in the design of DNS and not limited to any single product. DNS is used by every computer on the Internet to know where to ﬁnd other computers. Using this issue, an attacker could easily take over portions of the Internet and redirect users to arbitrary, and malicious, locations. For example, an attacker could target an Internet Service Provider (ISP), replacing the entire web &#8212; all search engines, social networks, banks, and other sites &#8212; with their own malicious content. Against corporate environments, an attacker could disrupt or monitor operations by rerouting network trafﬁc trafﬁc, capturing emails and other sensitive business data. <br />
</em><br />
Exact details on this are being withheld for the safety of the Internet; I prefer full disclosure, but that doesn&#8217;t seem to be the case here given that the hole is so large and vulnerability so widespread. </p>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.retina.net/tech/dns-patches-released-today.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Enigma / RSA</title>
		<link>http://www.retina.net/tech/enigma.html</link>
		<comments>http://www.retina.net/tech/enigma.html#comments</comments>
		<pubDate>Wed, 09 Apr 2008 09:46:56 +0000</pubDate>
		<dc:creator>John Adams</dc:creator>
				<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.retina.net/tech/?p=43</guid>
		<description><![CDATA[I have been a long-time lover of security, cryptography, and freedom. Today I wore my EFF sweatshirt into the NSA booth at the RSA Security Expo. The NSA laughed at me. Little did their booth occupants know that the EFF had gone after them recently over the AT&#38;T domestic wiretapping affair, shown to the word [...]]]></description>
			<content:encoded><![CDATA[<p>I have been a long-time lover of security, cryptography, and freedom.</p>
<p><img class="alignleft" src="http://farm3.static.flickr.com/2203/2400038930_87eb54a6ab.jpg?v=0" alt="enigma" /></p>
<p>Today I wore my EFF sweatshirt into the NSA booth at the RSA Security Expo. The NSA laughed at me. Little did their booth occupants know that the EFF had gone after them recently over the AT&amp;T domestic wiretapping affair, shown to the word by Mark Klein. He was awarded an EFF Pioneer Award this year for his actions.</p>
<p>In any event, they had an Enigma, and oh boy, do I love enigma. It is the time when the world learned of cryptograhpy, security, and the first time that an army of cryptographers fought a machine to save the lives of the Allies. </p>
<p>Sure sure, I hate the NSA, but I dealt with them to talk to their Museum Curator, who let me play with the Enigma for a few. The kerchunk-kerchunk sound of the rotors turning and the lamps lighting on the front panel of the device scared me for a moment. The messages encrypted by this machine killed thousands of people, stumped engineers across the world, and caused many convoy ships to sink in the atlantic. We are all in debt to the men who risked their lives to capture this machine and decode it&#8217;s secrets.</p>
<p>Some photos from today&#8217;s RSA conference are now available online, here: <a href="http://flickr.com/photos/netik/sets/72157604450150163/">Enigmas at RSA Conference (Set)</a></p>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.retina.net/tech/enigma.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Site Insecurity</title>
		<link>http://www.retina.net/tech/site-insecurity.html</link>
		<comments>http://www.retina.net/tech/site-insecurity.html#comments</comments>
		<pubDate>Mon, 07 Jan 2008 21:32:23 +0000</pubDate>
		<dc:creator>John Adams</dc:creator>
				<category><![CDATA[application security]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[web development]]></category>
		<category><![CDATA[Cross Site Scripting]]></category>
		<category><![CDATA[XREF]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.retina.net/tech/site-insecurity.html</guid>
		<description><![CDATA[Over at Chris Shiflett&#8217;s blog (he&#8217;s the author of Essential PHP Security) he&#8217;s got a nice writeup on foiling cross-site scripting attacks on web sites. While this is an older article ( from 2004 ), it still addresses many dangerous issues that developers continue to create in production code. One of our developers here recently [...]]]></description>
			<content:encoded><![CDATA[<p>Over at Chris Shiflett&#8217;s blog (he&#8217;s the author of <a href="http://phpsecurity.org/">Essential PHP Security</a>) he&#8217;s got a <a href="http://shiflett.org/articles/foiling-cross-site-attacks" title="Foiling Cross Site Scripting Attacks">nice writeup</a> on foiling cross-site scripting attacks on web sites.</p>
<p>While this is an older article ( from 2004 ), it still addresses many dangerous issues that developers continue to create in production code.</p>
<p>One of our developers here recently wrote a fairly large scripting system to deliver advertising to customers that was vulnerable to at least four XSS attacks, and I spent a fair amount of time sanitizing input and securing her code.</p>
<p>Do you accept input from users? Are you ensuring that you strip_tags (to block XSS/XSRF), escaping strings (to block SQL injection) and sanitizing all user input before storing or displaying it? If not, you might be vulnerable.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.retina.net/tech/site-insecurity.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

