<?xml version="1.0" encoding="windows-1251"?>

<feed version="0.3" xmlns="http://purl.org/atom/ns#" xml:lang="en">
  <title>Security news</title>
  <tagline>http://www.eldos.com/blog/Security_News/</tagline>
  <id>tag:www.eldos.com,2008-05-16:1</id>
  <link rel="alternate" type="text/html" href="http://www.eldos.com/blog/Security_News/" />
  <copyright>Copyright (c) http://www.eldos.com/blog/Security_News/</copyright>
  <modified>2008-05-16T23:43:43-05:00</modified>

<entry>
  <title type="text/html">Blog moved</title>
  <link rel="alternate" type="text/html" href="http://www.eldos.com/blog/Security_News/51.php"/>
  <issued>2008-02-27T04:05:49-06:00</issued>
  <modified>2008-05-16T23:43:43-05:00</modified>
  <id>tag:www.eldos.com:Security_News/51</id>
  <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.eldos.com/blog/Security_News/">
<![CDATA[                         This blog has moved to <a href='http://mayevski.blogspot.com/' target='_blank'>Blogspot service</a>. New posts will appear there.                          ]]>
  </content>
  <link rel="related" type="text/html" href="http://www.eldos.com/blog/Security_News/51.php" title="Blog moved"/>
  <author>
    <name>Eugene Mayevski</name>
    <url>http://www.eldos.com/blog/users/1.php</url>
  </author>
</entry>

<entry>
  <title type="text/html">State of e-mail authentication</title>
  <link rel="alternate" type="text/html" href="http://www.eldos.com/blog/Security_News/50.php"/>
  <issued>2008-02-02T10:33:09-06:00</issued>
  <modified>2008-05-16T23:43:43-05:00</modified>
  <id>tag:www.eldos.com:Security_News/50</id>
  <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.eldos.com/blog/Security_News/">
<![CDATA[                         <a href='http://aotalliance.org/' target='_blank'>Authentication And Online Trust Alliance</a> has published a report that reviews current situation of e-mail authentication among large companies and ogranizations. The report says that more than a half of all e-mail is authenticated. What does this mean? <br /><br />Authentication of the sender is an important step in fight against unauthorized e-mail. Now, when so much e-mail is authenticated, it's vital that the verification takes place on all stages of e-mail processing, and that e-mail is handled properly (this includes acceptance of the valid authenticated e-mail and lowering the weight of other factors when e-mail is authenticated right). <br /><br />The most widespread authentication mechanisms are Sender ID (formerly SPF) and DKIM (formerly DomainKeys). <br /><br />MIMEBlackbox package of SecureBlackbox includes both <a href='http://www.eldos.com/sbb/desc-mime.php' target='_blank'>signing and verification of DKIM-signed e-mails</a>. <br /><br />The report itself can be found <a href='http://aotalliance.org/resources/authentication/2008%20AOTA%20Authentication%20Report%2001-30.pdf' target='_blank'>here</a>.<br /><br />You will find lots of useful information, related to authentication schemes, their supporters etc. in this report.                         ]]>
  </content>
  <link rel="related" type="text/html" href="http://www.eldos.com/blog/Security_News/50.php" title="State of e-mail authentication"/>
  <author>
    <name>Eugene Mayevski</name>
    <url>http://www.eldos.com/blog/users/1.php</url>
  </author>
</entry>

<entry>
  <title type="text/html">Obsurity in security</title>
  <link rel="alternate" type="text/html" href="http://www.eldos.com/blog/Security_News/49.php"/>
  <issued>2008-01-18T01:23:30-06:00</issued>
  <modified>2008-05-16T23:43:43-05:00</modified>
  <id>tag:www.eldos.com:Security_News/49</id>
  <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.eldos.com/blog/Security_News/">
<![CDATA[                         Here's <a href='http://www.net-security.org/news.php?id=15700' target='_blank'>the good article</a> &quot;for dummies&quot; why obscurity is not always bad. <br /><br />                         ]]>
  </content>
  <link rel="related" type="text/html" href="http://www.eldos.com/blog/Security_News/49.php" title="Obsurity in security"/>
  <author>
    <name>Eugene Mayevski</name>
    <url>http://www.eldos.com/blog/users/1.php</url>
  </author>
</entry>

<entry>
  <title type="text/html">New cool gadget - smartcard with biometrics</title>
  <link rel="alternate" type="text/html" href="http://www.eldos.com/blog/Security_News/48.php"/>
  <issued>2007-12-06T06:31:15-06:00</issued>
  <modified>2008-05-16T23:43:43-05:00</modified>
  <id>tag:www.eldos.com:Security_News/48</id>
  <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.eldos.com/blog/Security_News/">
<![CDATA[                         The manufacturer has offered the smart-card which authenticates it's user biometrically (using a fingerprint). This is an additional protection level, which combines &quot;what user has&quot; (smartcard), &quot;what user knows&quot; (PIN) with &quot;what user is&quot; (fingerprint). Quite reliable solution...<br /><br />The only thing I wish this card could do is optionally give away the fingerprint, working as a fingerprint scanner. This particular card doens't do this, but I believe we'll see such cards soon.<br /><br />Read the <a href='http://www.net-security.org/secworld.php?id=5657' target='_blank'>description</a> of the card. <br /><br />                         ]]>
  </content>
  <link rel="related" type="text/html" href="http://www.eldos.com/blog/Security_News/48.php" title="New cool gadget - smartcard with biometrics"/>
  <author>
    <name>Eugene Mayevski</name>
    <url>http://www.eldos.com/blog/users/1.php</url>
  </author>
</entry>

<entry>
  <title type="text/html">How to find people</title>
  <link rel="alternate" type="text/html" href="http://www.eldos.com/blog/Security_News/47.php"/>
  <issued>2007-12-04T02:39:07-06:00</issued>
  <modified>2008-05-16T23:43:43-05:00</modified>
  <id>tag:www.eldos.com:Security_News/47</id>
  <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.eldos.com/blog/Security_News/">
<![CDATA[                         This information is not about computer security, but rather about people privacy. Yet it's very important for business and personal tasks.<br /><br />It's a common task when you need to know more about some person. Google seems to be the obvious approach. But is it the best one? There are numerous less known ways and the site (below) seems to offer the whole section about this topic. <br /><br />The article I came across is <a href='http://lifehacker.com/software/feature/how-to-track-down-anyone-online-329033.php' target='_blank'>here</a>                         ]]>
  </content>
  <link rel="related" type="text/html" href="http://www.eldos.com/blog/Security_News/47.php" title="How to find people"/>
  <author>
    <name>Eugene Mayevski</name>
    <url>http://www.eldos.com/blog/users/1.php</url>
  </author>
</entry>

<entry>
  <title type="text/html">What's new in upcoming SBB 6</title>
  <link rel="alternate" type="text/html" href="http://www.eldos.com/blog/Security_News/46.php"/>
  <issued>2007-12-02T12:54:28-06:00</issued>
  <modified>2008-05-16T23:43:43-05:00</modified>
  <id>tag:www.eldos.com:Security_News/46</id>
  <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.eldos.com/blog/Security_News/">
<![CDATA[                         SecureBlackbox 6 will be presented in a week or two. What news do we have for the users?<br /><br />First of all, it's a code that was carefully checked for possible weak places and security vulnerabilities. While there were not much security fixes, some places in the code could affect the performance of the system, if they dealt with specialy prepared data. Obviously, I can't tell much until SBB 6 is released. <br /><br />Another important addition is introduction of Elliptic Curve Cryptography (ECC or EC cryptography) mathematics and algorithms. As written in one of the previous blog posts, EC cryptography promises better speed on much shorter keys. It is considered to be the algorithm set of choice in the next 15-20 years. SecureBlackbox is one of the first security toolsets to provide EC crypto support.<br /><br />One more thing is various improvements in SSH and SFTP protocols. SSH components are one of the most used components in SecureBlackbox. And it's not a surprise, as demand for secure remote access and secure file exchange grows. SecureBlackbox with it's <a href='http://www.eldos.com/sbb/desc-sftp.php' target='_blank'>SFTPBlackbox</a> package is the leading component collection for SFTP support, with unbeated combination of numerous features and low price. <br /><br />Finally, we have plans to re-write the source code of ActiveX edition, in order to remove the mess with secondary interfaces in various controls. In SecureBlackbox 5 and before each control implemented a number of interfaces (such as IElSftpClientX, IElSftpClientX2, IElSftpClientX3 etc.). In SecureBlackbox 6 there will be new interfaces and new controls. This will let the users easily call various functions from scripting environments and will reduce the number of lines of code, needed to use the components. Of course, for compatibility with existing applications and user code the old interfaces will be available too. <br /><br />See our <a href='http://www.eldos.com/news/' target='_blank'>News section</a> for upcoming news about SecureBlackbox 6.                         ]]>
  </content>
  <link rel="related" type="text/html" href="http://www.eldos.com/blog/Security_News/46.php" title="What's new in upcoming SBB 6"/>
  <author>
    <name>Eugene Mayevski</name>
    <url>http://www.eldos.com/blog/users/1.php</url>
  </author>
</entry>

<entry>
  <title type="text/html">MD5 hash collision</title>
  <link rel="alternate" type="text/html" href="http://www.eldos.com/blog/Security_News/45.php"/>
  <issued>2007-12-02T12:42:08-06:00</issued>
  <modified>2008-05-16T23:43:43-05:00</modified>
  <id>tag:www.eldos.com:Security_News/45</id>
  <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.eldos.com/blog/Security_News/">
<![CDATA[                         The researchers have demonstrated the collision in hashes of two real-world files. While the files, as written, should be prepared in a special way before hash calculation, MD5 is hardly a reliable integrity checking algorithm. The Vulnerability Analysis part is the most interesting one in the story. <br /><br /><a href='http://www.win.tue.nl/hashclash/SoftIntCodeSign/' target='_blank'>Read the article</a>                         ]]>
  </content>
  <link rel="related" type="text/html" href="http://www.eldos.com/blog/Security_News/45.php" title="MD5 hash collision"/>
  <author>
    <name>Eugene Mayevski</name>
    <url>http://www.eldos.com/blog/users/1.php</url>
  </author>
</entry>

<entry>
  <title type="text/html">Graphic passwords, the scientific approach</title>
  <link rel="alternate" type="text/html" href="http://www.eldos.com/blog/Security_News/44.php"/>
  <issued>2007-11-05T12:01:55-06:00</issued>
  <modified>2008-05-16T23:43:43-05:00</modified>
  <id>tag:www.eldos.com:Security_News/44</id>
  <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.eldos.com/blog/Security_News/">
<![CDATA[                         Various authentication schemes, that rely on human's image recognition and memorizing capabilities are known for certain time. The user can select several pictures from the given list, or build the sequences of the images, or even draw something. <br />To my understanding, most of such schemes were introduced without serious scientific analysis of their strength. <br /><br />Recently the new approach has been announced. You will find a very interesting, detailed and scientific-looking description of the scheme in<a href='http://www.cs.ncl.ac.uk/research/pubs/inproceedings/papers/998.pdf' target='_blank'>this paper (PDF document).</a>                          ]]>
  </content>
  <link rel="related" type="text/html" href="http://www.eldos.com/blog/Security_News/44.php" title="Graphic passwords, the scientific approach"/>
  <author>
    <name>Eugene Mayevski</name>
    <url>http://www.eldos.com/blog/users/1.php</url>
  </author>
</entry>

<entry>
  <title type="text/html">Speech Recognition and Voice Recognition - what is the difference?</title>
  <link rel="alternate" type="text/html" href="http://www.eldos.com/blog/Security_News/43.php"/>
  <issued>2007-10-14T06:48:07-05:00</issued>
  <modified>2008-05-16T23:43:43-05:00</modified>
  <id>tag:www.eldos.com:Security_News/43</id>
  <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.eldos.com/blog/Security_News/">
<![CDATA[                         This is the question that you would hardly ask yourself, mixing these two terms. So did I. Aren't they both about the same? <br /><br />But recently I came across the small article which describes the differences between several similar yet different terms and technologies. <br /><br /><a href='http://www.articledashboard.com/Article/Key-Differences-Between-Speech-Recognition-and-Voice-Recognition/323709' target='_blank'>Read the article</a>.                         ]]>
  </content>
  <link rel="related" type="text/html" href="http://www.eldos.com/blog/Security_News/43.php" title="Speech Recognition and Voice Recognition - what is the difference?"/>
  <author>
    <name>Eugene Mayevski</name>
    <url>http://www.eldos.com/blog/users/1.php</url>
  </author>
</entry>

<entry>
  <title type="text/html">Introduction to DRM</title>
  <link rel="alternate" type="text/html" href="http://www.eldos.com/blog/Security_News/39.php"/>
  <issued>2007-10-14T02:47:13-05:00</issued>
  <modified>2008-05-16T23:43:43-05:00</modified>
  <id>tag:www.eldos.com:Security_News/39</id>
  <content type="text/html" mode="escaped" xml:lang="en" xml:base="http://www.eldos.com/blog/Security_News/">
<![CDATA[                         Digital Rights Management (DRM) is about how to give people rights to do this and prevent them from doing that with the information that you own. <br /><br />DRM is often confused with encryption and vice versa. It is important to understand, that encrypting the data doesn't necessarily give you protection for your data. The one who can decrypt it (legitimately) becomes the possessor of the information and copy and distribute it (no matter if he has the rights to do this). Encryption can't prevent distribution. But DRM can. Can it? <br /><br />Here's <a href='http://www.articlecube.com/Article/Introduction-to-Digital-Rights-Management-/121251' target='_blank'>the article</a> that gives you the basic understanding of what DRM does.                          ]]>
  </content>
  <link rel="related" type="text/html" href="http://www.eldos.com/blog/Security_News/39.php" title="Introduction to DRM"/>
  <author>
    <name>Eugene Mayevski</name>
    <url>http://www.eldos.com/blog/users/1.php</url>
  </author>
</entry>



</feed>