<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Paranoid Prose &#187; Paranoid Peeps</title>
	<atom:link href="http://www.paranoidprose.com/category/paranoid-peeps/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.paranoidprose.com</link>
	<description>reading to keep you up at night</description>
	<lastBuildDate>Thu, 29 Jul 2010 13:10:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>truecrypt (and good passwords) 1, fbi 0</title>
		<link>http://www.paranoidprose.com/2010/06/30/truecrypt-and-good-passwords-1-fbi-0/</link>
		<comments>http://www.paranoidprose.com/2010/06/30/truecrypt-and-good-passwords-1-fbi-0/#comments</comments>
		<pubDate>Wed, 30 Jun 2010 21:51:18 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[Paranoid Peeps]]></category>
		<category><![CDATA[best practices]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[useful stuff]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=337</guid>
		<description><![CDATA[Looks like open source disk encryption software TrueCrypt has shown its mettle in a cybercrime case out of Brazil.   The Brazilian police seized 500 TrueCrypt protected drives from the apartment of Daniel Dantas, a Rio banker accused of financial crimes.  In Brazil, there is no law compelling defendants to reveal passwords to encrypted evidence, so the Brazilian [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_339" class="wp-caption alignleft" style="width: 310px"><a href="http://www.paranoidprose.com/wp-content/uploads/2010/06/locked-door-sign.jpg"><img class="size-medium wp-image-339" title="locked-door-sign" src="http://www.paranoidprose.com/wp-content/uploads/2010/06/locked-door-sign-300x201.jpg" alt="" width="300" height="201" /></a><p class="wp-caption-text">Daniel Dantas did...</p></div>
<p>Looks like open source disk encryption software <a href="http://www.truecrypt.org/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.truecrypt.org/?referer=');">TrueCrypt</a> has shown its mettle in a<a href="http://g1.globo.com/English/noticia/2010/06/not-even-fbi-can-de-crypt-files-daniel-dantas.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/g1.globo.com/English/noticia/2010/06/not-even-fbi-can-de-crypt-files-daniel-dantas.html?referer=');"> cybercrime case </a>out of Brazil.   The Brazilian police <a href="http://www.theregister.co.uk/2010/06/28/brazil_banker_crypto_lock_out/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.theregister.co.uk/2010/06/28/brazil_banker_crypto_lock_out/?referer=');">seized 500 TrueCrypt protected drives from the apartment of Daniel Dantas, a Rio banker accused of financial crimes</a>.  In Brazil, there is no law compelling defendants to reveal passwords to encrypted evidence, so the Brazilian crime lab attempted to break the encryption for five months with no success.  They then turned to the US FBI, who ran dictionary attacks against the encryption for another year.  No joy.  As a result of the banker&#8217;s good password practices, the 500 drives with potential evidence were reduced to really ugly paperweights.</p>
<p>While this was a loss for the good guys, it does provide security professionals with some valuable information.  First, choosing a strong (long non dictionary word with special characters, numbers and the like) password is still an integral part of good basic meat and potatos security practice.  Second, if the FBI is unable to crack a TrueCrypt protected drive without the user having chosen a boneheaded password, it seems like the program  is a good and cost effective choice for protecting personal data as well as in small business environments.  The only thing missing for bigger business is some sort of key management and recovery scheme&#8230; sounds like an opportunity for an entrepeneurial crypto programmer.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2010%2F06%2F30%2Ftruecrypt-and-good-passwords-1-fbi-0%2F&amp;linkname=truecrypt%20%28and%20good%20passwords%29%201%2C%20fbi%200" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2010_2F06_2F30_2Ftruecrypt-and-good-passwords-1-fbi-0_2F_amp_linkname=truecrypt_20_28and_20good_20passwords_29_201_2C_20fbi_200&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2010/06/30/truecrypt-and-good-passwords-1-fbi-0/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>what happens in vegas gets blogged in vegas</title>
		<link>http://www.paranoidprose.com/2010/06/15/what-happens-in-vegas-gets-blogged-in-vegas/</link>
		<comments>http://www.paranoidprose.com/2010/06/15/what-happens-in-vegas-gets-blogged-in-vegas/#comments</comments>
		<pubDate>Tue, 15 Jun 2010 20:07:20 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[Paranoid Peeps]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=315</guid>
		<description><![CDATA[End of July?  Vegas?   Security folk and shady folk in one place?   Stifling heat?  You know I&#8217;m there&#8230; (If anyone points out that &#8220;it&#8217;s a dry heat&#8221; I reserve the right to throw something heavy and possibly explosive). I&#8217;m planning a Vegas double header this July, attending both Security B-Sides and DefCon.  I&#8217;m planning to blog/tweet [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="vegas!" src="http://www.textually.org/textually/archives/2010/01/13/las-vegas.jpeg" alt="" width="217" height="158" />End of July?  Vegas?   Security folk and shady folk in one place?   Stifling heat?  You <em>know</em> I&#8217;m there&#8230; (If anyone points out that &#8220;it&#8217;s a <em>dry</em> heat&#8221; I reserve the right to throw something heavy and possibly explosive).</p>
<p>I&#8217;m planning a Vegas double header this July, attending both <a href="http://www.securitybsides.com/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.securitybsides.com/?referer=');"><strong>Security B-Sides</strong></a><strong> and </strong><a href="http://defcon.org/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/defcon.org/?referer=');"><strong>DefCon</strong></a>.  I&#8217;m planning to blog/tweet during the festivities and would love to meet up with any of my readers&#8230; dm me (@alberg) when you are there&#8230; and if you are <strong>not</strong> planning to attend, consider it &#8211; both of these events are great places to learn security-fu, meet your peers (as well as many people whom you would not typically meet up with), and for the corporate types amongst us (myself included), they are very cost effective uses of your training budget dollars.</p>
<p>Nickel slot machines, here I come!</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2010%2F06%2F15%2Fwhat-happens-in-vegas-gets-blogged-in-vegas%2F&amp;linkname=what%20happens%20in%20vegas%20gets%20blogged%20in%20vegas" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2010_2F06_2F15_2Fwhat-happens-in-vegas-gets-blogged-in-vegas_2F_amp_linkname=what_20happens_20in_20vegas_20gets_20blogged_20in_20vegas&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2010/06/15/what-happens-in-vegas-gets-blogged-in-vegas/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>We&#8217;re from the NSA and we&#8217;re here to help you&#8230;</title>
		<link>http://www.paranoidprose.com/2009/11/20/were-from-the-nsa-and-were-here-to-help-you/</link>
		<comments>http://www.paranoidprose.com/2009/11/20/were-from-the-nsa-and-were-here-to-help-you/#comments</comments>
		<pubDate>Fri, 20 Nov 2009 19:18:37 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[Paranoid Peeps]]></category>
		<category><![CDATA[best practices]]></category>
		<category><![CDATA[online security]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=50</guid>
		<description><![CDATA[The NSA is one of the most secretive of the US Government&#8217;s TLAs (three letter agencies), which makes sense since it is charged with intercepting, decrypting and analyzing communications for the intelligence community.  However, in addition to its role in SIGINT, the NSA is also tasked with helping the government and private industry secure systems [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.nsa.gov" onclick="pageTracker._trackPageview('/outgoing/www.nsa.gov?referer=');"><img class="alignleft size-full wp-image-53" title="nsa_seal" src="http://www.paranoidprose.com/wp-content/uploads/2009/11/nsa_seal.jpeg" alt="nsa_seal" width="125" height="124" /></a>The <a href="http://www.nsa.gov/" onclick="pageTracker._trackPageview('/outgoing/www.nsa.gov/?referer=');">NSA</a> is one of the most secretive of the US Government&#8217;s TLAs (three letter agencies), which makes sense since it is charged with intercepting, decrypting and analyzing communications for the intelligence community.  However, in addition to its role in <a href="http://www.nsa.gov/sigint/index.shtml" onclick="pageTracker._trackPageview('/outgoing/www.nsa.gov/sigint/index.shtml?referer=');">SIGINT</a>, the NSA is also tasked with helping the government and private industry secure systems against cyber attack (<a href="http://www.nsa.gov/ia/index.shtml" onclick="pageTracker._trackPageview('/outgoing/www.nsa.gov/ia/index.shtml?referer=');">information assurance</a>).  If you go to the agency&#8217;s web site, you&#8217;ll find a number of configuration guides which provide security advice for products such as <a href="http://www.nsa.gov/ia/guidance/security_configuration_guides/operating_systems.shtml" onclick="pageTracker._trackPageview('/outgoing/www.nsa.gov/ia/guidance/security_configuration_guides/operating_systems.shtml?referer=');">computer operating systems</a>, <a href="http://www.nsa.gov/ia/guidance/security_configuration_guides/database_servers.shtml" onclick="pageTracker._trackPageview('/outgoing/www.nsa.gov/ia/guidance/security_configuration_guides/database_servers.shtml?referer=');">database servers</a>, and<a href="http://www.nsa.gov/ia/guidance/security_configuration_guides/cisco_router_guides.shtml" onclick="pageTracker._trackPageview('/outgoing/www.nsa.gov/ia/guidance/security_configuration_guides/cisco_router_guides.shtml?referer=');"> Cisco routers</a>.  These guides are a great use of our tax dollars (IMHO) &#8211; they help protect government systems from attack and (with some modifications) are helpful to private industry.  So why am I telling you this?</p>
<p>This week, we&#8217;ve seen some press wondering whether Microsoft&#8217;s and the NSA might have cooperated to place <a href="http://www.computerworld.com/s/article/9141182/Microsoft_denies_it_built_backdoor_in_Windows_7" onclick="pageTracker._trackPageview('/outgoing/www.computerworld.com/s/article/9141182/Microsoft_denies_it_built_backdoor_in_Windows_7?referer=');">secret back doors in Windows 7 </a>to allow the spooks to access all of our computers (as well as those of the bad guys). Hackles were raised when a senior NSA official testified before Congress that the agency had &#8220;assisted&#8221; Microsoft with security for the new OS release.   According to the NSA and Microsoft, the assistance provided was limited to the production of a security configuration guide for the new OS and did not include any special access methods for the agency.</p>
<p>So, is Microsoft helping the NSA get access to millions of computers worldwide?  Probably not&#8230; Microsoft would be risking its customer base worldwide if news of such a backdoor were to leak.   But this incident does reveal a perceptual conflict in the NSA&#8217;s information assurance and SIGINT missions.  Maybe it is time for the government to separate the jobs of protecting information and gathering information.</p>
<p>One of the issues that the private sector has with taking security advice from the NSA is the perception that the NSA is in the business of protecting (and swiping) state level secrets.   After all, widget production figures don&#8217;t need the same level of protection as the nuclear launch codes.  I think a lot of security professionals pass the NSA documents by because of this perception.  What would be really great would be a separate release of private sector versions of these types of documents from a less ominous and more civilian oriented agency.  For example, the <a href="http://technet.microsoft.com/en-us/library/ee712767.aspx" onclick="pageTracker._trackPageview('/outgoing/technet.microsoft.com/en-us/library/ee712767.aspx?referer=');">Windows 7 Security Compliance Management Toolkit</a> (which the NSA assisted in preparing) could be a starting point for much less complicated sets of instructions aimed at:</p>
<ul>
<li>Home users</li>
<li>Educational institutions</li>
<li>Small and medium sized businesses</li>
<li>Large enterprises</li>
<li>Critical Infrastructure Providers</li>
<li>Financial Institutions</li>
</ul>
<p>I&#8217;ll take this a step further&#8230; I would like to see these documents form the basis of a description of the minimum level of due care that any enterprise handling the information owned by others or controlling critical infrastructure must meet.  Having some very basic standards (and some teeth to back them up) would do two things:</p>
<ul>
<li>Provide incentives to enterprises to secure their systems</li>
<li>Provide a generally accepted security baseline</li>
<li>Provide small and medium sized businesses who don&#8217;t have a high level of security expertise in house with a clear and concise roadmap (and instructions) as to what they need to do.</li>
</ul>
<p><a href="http://www.computerworld.com/s/article/9141182/Microsoft_denies_it_built_backdoor_in_Windows_7" onclick="pageTracker._trackPageview('/outgoing/www.computerworld.com/s/article/9141182/Microsoft_denies_it_built_backdoor_in_Windows_7?referer=');"> </a>I think that there would need to be private sector involvement in developing these documents, of course.  It would be a large undertaking, but I think it would also be a large step in the fight against cybercrime and cyberwarfare.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2009%2F11%2F20%2Fwere-from-the-nsa-and-were-here-to-help-you%2F&amp;linkname=We%26%238217%3Bre%20from%20the%20NSA%20and%20we%26%238217%3Bre%20here%20to%20help%20you%26%238230%3B" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2009_2F11_2F20_2Fwere-from-the-nsa-and-were-here-to-help-you_2F_amp_linkname=We_26_238217_3Bre_20from_20the_20NSA_20and_20we_26_238217_3Bre_20here_20to_20help_20you_26_238230_3B&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2009/11/20/were-from-the-nsa-and-were-here-to-help-you/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>kitty porn</title>
		<link>http://www.paranoidprose.com/2009/08/07/kitty-porn/</link>
		<comments>http://www.paranoidprose.com/2009/08/07/kitty-porn/#comments</comments>
		<pubDate>Fri, 07 Aug 2009 22:00:38 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[Paranoid Peeps]]></category>
		<category><![CDATA[worst practices]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=43</guid>
		<description><![CDATA[The saddest thing about this story is that as a cat owner, I can half believe the guy.  This is just the kind of thing that *my* cats would do if I didn&#8217;t make with the treats.]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="Iz on yr cmptr dwnldg porn" src="http://media.nbcmiami.com/images/600*450/080709+cat.jpg" alt="" width="182" height="136" />The saddest thing about <a href="http://www.nbcmiami.com/news/local-beat/Man-Naughty-Kitty-Downloaded-Kiddie-Porn-52640667.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.nbcmiami.com/news/local-beat/Man-Naughty-Kitty-Downloaded-Kiddie-Porn-52640667.html?referer=');">this story</a> is that as a cat owner, I can half believe the guy.  This is just the kind of thing that *my* cats would do if I didn&#8217;t make with the treats.</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2009%2F08%2F07%2Fkitty-porn%2F&amp;linkname=kitty%20porn" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2009_2F08_2F07_2Fkitty-porn_2F_amp_linkname=kitty_20porn&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2009/08/07/kitty-porn/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>is your ipod working for the mob??</title>
		<link>http://www.paranoidprose.com/2009/07/17/is-your-ipod-working-for-the-mob/</link>
		<comments>http://www.paranoidprose.com/2009/07/17/is-your-ipod-working-for-the-mob/#comments</comments>
		<pubDate>Fri, 17 Jul 2009 22:14:50 +0000</pubDate>
		<dc:creator>alberg</dc:creator>
				<category><![CDATA[Paranoid Peeps]]></category>
		<category><![CDATA[people]]></category>

		<guid isPermaLink="false">http://www.paranoidprose.com/?p=15</guid>
		<description><![CDATA[I take this as a good omen for the starting of my blog&#8230; today, Apple Insider reports on a gentleman from St. Louis, MO who filed a 128 page lawsuit against Apple Computer &#8211; and with good reason! It seems that the Mafia and Apple conspired to placed devices in his iPod to not only [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 228px"><img title="Ipod" src="http://www.electronichouse.com/images/slideshow/ipod_nano_fire.jpg" alt="DANGER!" width="218" height="123" /><p class="wp-caption-text">DANGER!</p></div>
<p>I take this as a good omen for the starting of my blog&#8230; today, <a href="http://www.appleinsider.com/articles/09/07/17/a_hrefmailtoneilappleinsider_comneil_hughes_a.html" onclick="pageTracker._trackPageview('/outgoing/www.appleinsider.com/articles/09/07/17/a_hrefmailtoneilappleinsider_comneil_hughes_a.html?referer=');">Apple Insider reports</a> on a gentleman from St. Louis, MO who filed a 128 page lawsuit against Apple Computer &#8211; and with good reason!  It seems that the Mafia and Apple conspired to placed devices in his iPod to not only track his location, but also to inject threatening messages into his music.  All of this was allegedly in furtherance of a plot dating back to 2000 in which the plaintiff was threatened by the Mob that if he didn&#8217;t go to New York and get into fashion modeling for them, he would be killed.</p>
<p>I for one applaud this brave American&#8217;s willingness to take on Apple&#8230; and the Mafia&#8230; and reality.  It is about time that we iPod owners can stop having to worry about being forced to become fashion models!  Power to the paranoid!</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save?linkurl=http%3A%2F%2Fwww.paranoidprose.com%2F2009%2F07%2F17%2Fis-your-ipod-working-for-the-mob%2F&amp;linkname=is%20your%20ipod%20working%20for%20the%20mob%3F%3F" onclick="pageTracker._trackPageview('/outgoing/www.addtoany.com/share_save?linkurl=http_3A_2F_2Fwww.paranoidprose.com_2F2009_2F07_2F17_2Fis-your-ipod-working-for-the-mob_2F_amp_linkname=is_20your_20ipod_20working_20for_20the_20mob_3F_3F&amp;referer=');"><img src="http://www.paranoidprose.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.paranoidprose.com/2009/07/17/is-your-ipod-working-for-the-mob/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
