<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Musings &#187; Technology &amp; Tool Thursday</title>
	<atom:link href="http://securitymusings.com/article/category/techtoolthursday/feed" rel="self" type="application/rss+xml" />
	<link>http://securitymusings.com</link>
	<description>Rants and raves from information security professionals</description>
	<lastBuildDate>Fri, 03 Sep 2010 22:08:55 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>The Cat and Mouse Game of Cryptography</title>
		<link>http://securitymusings.com/article/2096/the-cat-and-mouse-game-of-cryptography</link>
		<comments>http://securitymusings.com/article/2096/the-cat-and-mouse-game-of-cryptography#comments</comments>
		<pubDate>Thu, 19 Aug 2010 20:52:45 +0000</pubDate>
		<dc:creator>Joey Tyson</dc:creator>
				<category><![CDATA[Technology & Tool Thursday]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[general]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=2096</guid>
		<description><![CDATA[MD5 is a hashing algorithm created in 1991 and still used by many applications for certain features. But MD5 is no longer recommended for many cases due to weaknesses discovered in the last few years, opening up some scary possibilities. At the end of this year, NIST standards for cryptography used by the federal government [...]]]></description>
			<content:encoded><![CDATA[<p>MD5 is a hashing algorithm created in 1991 and still used by many applications for certain features. But MD5 is no longer recommended for many cases due to weaknesses discovered in the last few years, opening up some <a href="http://th.informatik.uni-mannheim.de/people/lucks/HashCollisions/">scary possibilities</a>. At the end of this year, NIST standards for cryptography used by the federal government will no longer permit 160-bit SHA1 hashes or 1024-bit RSA signature keys, since concerns over the long-term security of these technologies are rising.</p>
<p>With cryptographers constantly working on new algorithms and breaking old algorithms, one may get nervous about whether the foundations of today&#8217;s secure transactions are really that secure. But despite the occasional ominous forecast of a cryptographic meltdown, you can remain fairly confident in encryption technology.</p>
<p>Just as we&#8217;re constantly finding new weaknesses in various approaches, we&#8217;re constantly finding new approaches that overcome various weaknesses. For instance, scientists are working to develop &#8220;quantum computers&#8221; that perform calculations in a completely different way than today&#8217;s electronics. These new machines would be powerful enough to crack several of the strongest algorithms currently in wide use. But just this week, several researchers demonstrated that a 30-year-old algorithm, using a different type of mathematical basis, would <a href="http://www.technologyreview.com/blog/arxiv/25629/">foil any known quantum attack</a>. This approach has not been widely used due to large key sizes that would hinder performance, but computers are getting faster every year.</p>
<p>Cryptographers also work to maintain a gap between theoretical attacks and practical compromises. NIST does not wait for programs that can crack any key within seconds before deprecating an algorithm. Researchers are constantly working to build stronger systems, and often start recommending replacements when only the slightest cracks begin to show for a particular approach. Also, one type of weakness does not necessarily ruin every possible use of a given encryption method.</p>
<p>But while the mathematics behind today&#8217;s systems may be sound for the near future, strong encryption alone does not guarantee you security. In fact, most security problems come through either insecure implementations of a given approach or bad security practices built on top of strong algorithms. Keeping current with effective cryptography is important, but it&#8217;s only one part of an effective security strategy.</p>
]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/2096/the-cat-and-mouse-game-of-cryptography/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>A FAIR Analysis of Risk</title>
		<link>http://securitymusings.com/article/2075/a-fair-analysis-of-risk</link>
		<comments>http://securitymusings.com/article/2075/a-fair-analysis-of-risk#comments</comments>
		<pubDate>Thu, 12 Aug 2010 18:55:28 +0000</pubDate>
		<dc:creator>Benjamin Tomhave</dc:creator>
				<category><![CDATA[Technology & Tool Thursday]]></category>
		<category><![CDATA[analysis]]></category>
		<category><![CDATA[FAIR]]></category>
		<category><![CDATA[risk]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=2075</guid>
		<description><![CDATA[Risk assessment gets a bad rap these days, thanks in large part to a checkered past colored by qualitative analyses. Historically, risk assessments have been fuzzy, at best, and down-right inaccurate and misleading at worst. You know the ones I&#8217;m talking about: some hot shot consultant comes in, pokes around, maybe runs a couple scans, [...]]]></description>
			<content:encoded><![CDATA[<p>Risk assessment gets a bad rap these days, thanks in large part to a checkered past colored by qualitative analyses. Historically, risk assessments have been fuzzy, at best, and down-right inaccurate and misleading at worst. You know the ones I&#8217;m talking about: some hot shot consultant comes in, pokes around, maybe runs a couple scans, and then churns out a report with a bunch of High, Medium, and Low findings. However, as you dig into the results &#8211; particularly the so-called &#8220;High Risk&#8221; findings &#8211; you start finding extreme squishiness with no connection to reality, rational thought, or logic. And this is what we&#8217;re supposed to use to &#8220;better manage&#8221; security? Don&#8217;t think so&#8230;</p>
<p>Enter <a href="http://fairwiki.riskmanagementinsight.com/" target="_blank">Factor Analysis of Information Risk (FAIR)</a>, a different sort of beast altogether, created by Jack Jones of <a href="http://www.riskmanagementinsight.com/" target="_blank">Risk Management Insight (RMI)</a>. FAIR is a decision support tool that provides a means for performing a quantitative risk analysis around a given scenario. It allows you to conduct deep analysis into given asset+threat scenarios, digging into the business to arrive at accurate estimates (via ranges) for probabilities and expected losses. Loss events are divided between primary and secondary, wherein primary losses are often fairly well known (e.g. how much it costs to replace a server), whereas secondary losses can vary widely.</p>
<p>For an excellent introduction to FAIR, the RMI white paper &#8220;<a href="http://www.riskmanagementinsight.com/media/docs/FAIR_introduction.pdf" target="_blank">An Introduction to Factor Analysis of Information Risk (FAIR)</a>&#8221; is highly recommended. In it, you&#8217;ll start to see the breakdown of FAIR into its component pieces. Overall, within the context of FAIR we define risk as a derived value measuring &#8220;the probable frequency and probable magnitude of future loss.&#8221; There is much that can be said about this definition and overall approach, but I&#8217;ll leave that for another day. In the meantime, I encourage anybody with an interest in risk analysis to take a deeper look at FAIR.</p>
]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/2075/a-fair-analysis-of-risk/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why Am I So Paranoid?  Oh yeah, Black Hat is Going On</title>
		<link>http://securitymusings.com/article/2063/why-am-i-so-paranoid-oh-yeah-black-hat-is-going-on</link>
		<comments>http://securitymusings.com/article/2063/why-am-i-so-paranoid-oh-yeah-black-hat-is-going-on#comments</comments>
		<pubDate>Thu, 29 Jul 2010 17:28:39 +0000</pubDate>
		<dc:creator>Walt Turnes</dc:creator>
				<category><![CDATA[Technology & Tool Thursday]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=2063</guid>
		<description><![CDATA[Every year during the Black Hat conference, something crazy happens that makes me paranoid about things I use during my everyday life without really thinking too much about it.  Last year, it was the MD5 Collision Attack that allowed the attackers to create a rogue Certification Authority. This year, it&#8217;s ATMs.  A researcher by the [...]]]></description>
			<content:encoded><![CDATA[<p>Every year during the Black Hat conference, something crazy happens that makes me paranoid about things I use during my everyday life without really thinking too much about it.  Last year, it was the <a href="http://www.blackhat.com/presentations/bh-usa-09/BEVAND/BHUSA09-Bevand-MD5-PAPER.pdf">MD5 Collision Attack</a> that allowed the attackers to create a rogue Certification Authority. This year, it&#8217;s <a href="http://www.networkworld.com/news/2010/072810-atm-hack-gives-cash-on.html">ATMs</a>.  A researcher by the name of Barnaby Jack developed his own custom rootkit for ATM machines that could be installed by dialing into the devices and exploiting the remote management software.  This rootkit allowed him to make the machines dispense money on command, which, I&#8217;m reasonably sure, is not how they are intended to function.  Lest you think this only allows the attacker to steal from the device and not from your account, he also developed custom firmware for the machines that can record account information from its users.</p>
<p>These types of inventive techniques are discussed at Black Hat every year; there seems to be no end to the ways technology can be exploited for less than noble intentions.  As security professionals, it makes our job a constant uphill battle.  But, it also serves as a reminder that all of us &#8211; not just those of us that work in this field &#8211; need to be mindful of how technology fits into our lives.  There&#8217;s an off chance that the ATM hack may wind up hitting you at some point &#8211; there&#8217;s not much you can do about that.  But, you can take the time to check your account balances to look for irregularities as often as you&#8217;d like.  It&#8217;s not a perfect solution, but short of putting all of your money in a mattress, it&#8217;s at least a step in the right direction.</p>
]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/2063/why-am-i-so-paranoid-oh-yeah-black-hat-is-going-on/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Brief Look at O5Logon</title>
		<link>http://securitymusings.com/article/2011/a-brief-look-o5logon</link>
		<comments>http://securitymusings.com/article/2011/a-brief-look-o5logon#comments</comments>
		<pubDate>Fri, 09 Jul 2010 03:35:21 +0000</pubDate>
		<dc:creator>Nick Staples</dc:creator>
				<category><![CDATA[Technology & Tool Thursday]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=2011</guid>
		<description><![CDATA[For authentication, newer versions of Oracle (11g+) use a session agreement and key exchange scheme known as O5Logon. It has some of the same weaknesses of authentication as the O3Logon used in previous versions of Oracle.
An example transcript of the default auth process:
1) Client connects to Server:
2) Client sends Username to Server
3) Server generates a [...]]]></description>
			<content:encoded><![CDATA[<p>For authentication, newer versions of Oracle (11g+) use a session agreement and key exchange scheme known as O5Logon. It has some of the same weaknesses of authentication as the O3Logon used in previous versions of Oracle.</p>
<p>An example transcript of the default auth process:<br />
1) Client connects to Server:<br />
2) Client sends Username to Server<br />
3) Server generates a ServerSessionID and encrypts it with AES. The key is the PasswordHash. It sends this encrypted ServerSessionID and the PasswordSalt to the Client<br />
4) Client tries to generate a password hash using the PasswordSalt and the provided password. It decrypts the ServerSessionID using this ClientPasswordHash<br />
5) Client generates a ClientSessionID and encrypts it with AES. The key is the ClientPasswordHash. It combines ServerSessionID and ClientSessionID to make another key which it uses to directly encrypt the provided password. It sends this encrypted password and encrypted ClientSessionID to the Server.</p>
<p>A more in-depth breakdown of the steps involved can be found <a href="http://www.petefinnigan.com/weblog/archives/00001102.htm">here</a>.</p>
<p>So, although there is a lot going on, the <a href="http://www.petefinnigan.com/weblog/archives/00001097.htm">password</a> itself is never really sent in clear text. This scheme also prevents against replay attacks, since the session IDs are different each time. The drawback is the fact that capturing all of the transmissions can allow an attacker to brute force the password in an offline environment. This is possible because guessing the hash will allow an attacker to simply decrypt the password sent from the client by sniffing the transmissions and comparing them later.</p>
<p>I think it&#8217;s possible to gain the same reply protection without exposing the password like that, but it would almost certainly take more steps. This scheme was probably designed to be very fast while providing protection against the most common attack scenarios. In comparison, TLS-based authentication is an alternative to O5Logon for Oracle, and does all sorts of cert. exchanging and flippidy floppidy. It provides better protection, but at the potential expense of being overkill if you just want decently secure authentication, and I think that&#8217;s one reason it&#8217;s an option instead of the default. In general, O5Logon is fine if the user chooses a strong password. As usual, the most critical link in the security chain is the individual.</p>
<p><em>Each Thursday, Security Musings features a security-related technology or tool. Featured items do not imply a recommendation by Gemini Security Solutions. For more information about how Gemini Security Solutions can help you solve your security issues, <a href="http://geminisecurity.com/company/contact/">contact us</a>!</em></p>
]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/2011/a-brief-look-o5logon/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Ensure your code is secure by using a Security API</title>
		<link>http://securitymusings.com/article/1999/ensure-your-code-is-secure-by-using-a-security-api</link>
		<comments>http://securitymusings.com/article/1999/ensure-your-code-is-secure-by-using-a-security-api#comments</comments>
		<pubDate>Thu, 01 Jul 2010 20:28:50 +0000</pubDate>
		<dc:creator>Tim Donaworth</dc:creator>
				<category><![CDATA[Technology & Tool Thursday]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=1999</guid>
		<description><![CDATA[There’s no need to go and reinvent the wheel when coding. Many good developers will have a plethora of custom or public libraries of code to do all the functions they need. One area where this type of stockpiling code really shines is in security APIs. For the longest time I’d followed Microsoft’s Enterprise Library, [...]]]></description>
			<content:encoded><![CDATA[<p>There’s no need to go and reinvent the wheel when coding. Many good developers will have a plethora of custom or public libraries of code to do all the functions they need. One area where this type of stockpiling code really shines is in security APIs. For the longest time I’d followed <a href="http://msdn.microsoft.com/en-us/library/ff648951.aspx">Microsoft’s Enterprise Library</a>, specifically for its security namespace. Being a .NET developer primarily this was all good.</p>
<p>But lately I’ve been branching out my coding endeavors, as well as watching the Microsoft Enterprise Library continue to grow; A little too large for my taste as of lately. This is where the<a href="http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API"> OWASP ESAPI</a> (Enterprise Security API) comes into play.</p>
<p>It’s fairly lightweight, supports many languages, and is a set of foundational security controls that developers don’t have to keep remaking over and over.</p>
<blockquote><p>Allowing for language-specific differences, all OWASP ESAPI versions have the same basic design:</p>
<ul>
<li><strong>There is a set of security control interfaces.</strong> They define for example types of parameters that are      passed to types of security controls.</li>
</ul>
<ul>
<li><strong>There is a reference implementation for each security      control.</strong> The logic is not organization‐specific and the logic is not application‐specific. An example: string‐based input validation.</li>
</ul>
<ul>
<li><strong>There are optionally your own implementations for each      security control.</strong> There may be application logic contained in these classes which may be      developed by or for your organization. An example: enterprise      authentication.</li>
</ul>
</blockquote>
<p>I’ve just recently started using the ESAPI, but do have a history with some of OWASP’s<a href="http://securitymusings.com/article/1712/learning-from-others-mistakes"> other projects</a>. I’d advise anyone looking to lock down some of their controls and ensure they have the proper guidelines in place to take a look at the ESAPI from OWASP.</p>
]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/1999/ensure-your-code-is-secure-by-using-a-security-api/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacking Pages in Firefox with the HackBar</title>
		<link>http://securitymusings.com/article/1980/hacking-pages-in-firefox-with-the-hackbar</link>
		<comments>http://securitymusings.com/article/1980/hacking-pages-in-firefox-with-the-hackbar#comments</comments>
		<pubDate>Thu, 24 Jun 2010 14:24:29 +0000</pubDate>
		<dc:creator>Joey Tyson</dc:creator>
				<category><![CDATA[Technology & Tool Thursday]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=1980</guid>
		<description><![CDATA[A few months ago, I described how the Firefox add-on HttpFox could be used for basic traffic monitoring. Another helpful add-on that complements nicely with HttpFox is called HackBar.
HackBar adds a toolbar underneath the main address bar that can be toggled on or off with the F9 key. When enabled, the toolbar provides a miniature [...]]]></description>
			<content:encoded><![CDATA[<p>A few months ago, I described how the Firefox add-on <a href="http://securitymusings.com/article/1786/monitor-network-traffic-in-firefox-with-httpfox">HttpFox</a> could be used for basic traffic monitoring. Another helpful add-on that complements nicely with HttpFox is called <a href="https://addons.mozilla.org/en-US/firefox/addon/3899/">HackBar</a>.</p>
<p>HackBar adds a toolbar underneath the main address bar that can be toggled on or off with the F9 key. When enabled, the toolbar provides a miniature console of sorts for various testing tasks. A resizable textbox gives you plenty of room for editing URIs, and you can also issue POST requests or spoof the referrer. Menus across the top of the bar provide common functions for working with different types of data, such as hash algorithms or encoding and decoding in Base64, URI format, and even hexadecimal.</p>
<p>Using HackBar has its limits, and for comprehensive penetration testing you&#8217;ll probably need better tools. But if you just want to poke around a web application or send a quick POST request, HackBar is pretty handy to have around. Combined with HttpFox, you may be surprised at how much testing you can accomplish right in your browser.</p>
<p><em>Each Thursday, Security Musings features a  security-related  technology or tool. Featured items do not imply a  recommendation by  Gemini Security Solutions. For more information about  how Gemini  Security Solutions can help you solve your security issues,  <a href="http://geminisecurity.com/company/contact/">contact us</a>!</em></p>
]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/1980/hacking-pages-in-firefox-with-the-hackbar/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Researching DLP Solutions</title>
		<link>http://securitymusings.com/article/1957/researching-dlp-solutions</link>
		<comments>http://securitymusings.com/article/1957/researching-dlp-solutions#comments</comments>
		<pubDate>Thu, 17 Jun 2010 18:30:03 +0000</pubDate>
		<dc:creator>Benjamin Tomhave</dc:creator>
				<category><![CDATA[Technology & Tool Thursday]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[Technology]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=1957</guid>
		<description><![CDATA[I recently had a project to help spec out a DLP project for a  customer from a high-level perspective. Having never done anything with  DLP previously I embarked on a research mission. What I found was  interesting. There&#8217;s not much out there on the intarwebs. As such, I  thought I&#8217;d offer [...]]]></description>
			<content:encoded><![CDATA[<p>I recently had a project to help spec out a DLP project for a  customer from a high-level perspective. Having never done anything with  DLP previously I embarked on a research mission. What I found was  interesting. There&#8217;s not much out there on the intarwebs. As such, I  thought I&#8217;d offer a few quick suggestions, just in case you want to go  research solutions, too.</p>
<ol>
<li><a href="http://securosis.com/tag/dlp" target="_blank">Start with  Securosis!</a> Their reports are freely available, comprehensive, and  more informative than anything else I found.</li>
<li>Search for Gartner and Forrester reports. While these analyst firms  charge for their reports, vendors will often post them for free.  Specifically, try these search strings:
<ul>
<li> &#8220;forrester wave content security suites&#8221;</li>
<li> &#8220;gartner magic quadrant data loss prevention&#8221;</li>
</ul>
</li>
<li>Beware DLP (as in <a href="http://en.wikipedia.org/wiki/Digital_Light_Processing" target="_blank">Digital  Light Processing</a>) from Texas Instruments. You might need to use  advanced search functions to -television -TI and so on.</li>
</ol>
<p>Happy hunting!</p>
]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/1957/researching-dlp-solutions/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenVPN and two-factor authentication</title>
		<link>http://securitymusings.com/article/1942/openvpn-and-two-factor-authentication</link>
		<comments>http://securitymusings.com/article/1942/openvpn-and-two-factor-authentication#comments</comments>
		<pubDate>Thu, 10 Jun 2010 11:02:49 +0000</pubDate>
		<dc:creator>Laura Raderman</dc:creator>
				<category><![CDATA[Technology & Tool Thursday]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=1942</guid>
		<description><![CDATA[Many people have used OpenVPN for a simple and effective VPN solution, but did you know that you can use it for real two-factor VPN authentication?  How you do that depends on the two-factor solution you are using.  There is support for PKCS11 token stores, and Windows CAPI, with patches submitted for OS [...]]]></description>
			<content:encoded><![CDATA[<p>Many people have used OpenVPN for a simple and effective VPN solution, but did you know that you can use it for real two-factor VPN authentication?  How you do that depends on the two-factor solution you are using.  There is support for PKCS11 token stores, and Windows CAPI, with <a href="http://thread.gmane.org/gmane.network.openvpn.devel/3631">patches submitted for OS X&#8217;s Keychain</a>.  In order to get the OS X patch into the testing/stable branch of OpenVPN, it needs <a href="http://thread.gmane.org/gmane.network.openvpn.devel/3631/focus=3696">more testers</a> though (please help!).  So, if your token supports one of the above, and most do, you can use OpenVPN as a (relatively) inexpensive two-factor VPN.  The tokens are still rather expensive however <img src='http://securitymusings.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />   </p>
<p>To use the CAPI functionality, add cryptoapicert &#8220;<em>thumbprint</em>&#8221; to the client&#8217;s command line or configuration file.</p>
<p>To use the KeyChain functionality, add keychaincert &#8220;<em>thumbprint</em>&#8221; to your configuration file or command line.</p>
<p>In both cases, <em>thumbprint</em> needs to be in quotes and is the MD5 or SHA1 hash of the certificate to use.<br />
ex. &#8220;MD5: f8 72 98&#8230;.&#8221;</p>
<p>To use the PKCS11 functionality, you use two options:<br />
pkcs11-providers /usr/lib/pkcs11/ (or other path to the pkcs11 library)<br />
and<br />
pkcs11-id &#8216;<em>serialized id</em>&#8216;<br />
Where <em>serialized id</em> is a unique serial number that you can find by using the &#8220;openvpn &#8211;show-pkcs11-ids /usr/lib/pkcs11/&#8221; command</p>
<p>You&#8217;re now all set up to use two-factor authentication with OpenVPN on multiple operating systems.  OpenVPN has more detailed information on the PKCS11 functionality at the <a href="http://www.openvpn.net/index.php/open-source/documentation/howto.html#pkcs11">HOWTO</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/1942/openvpn-and-two-factor-authentication/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>CAPICOM is dead!  Long live&#8230;um&#8230;not being able to sign in the browser!</title>
		<link>http://securitymusings.com/article/1922/capicom-is-dead-long-live-um-not-being-able-to-sign-in-the-browser</link>
		<comments>http://securitymusings.com/article/1922/capicom-is-dead-long-live-um-not-being-able-to-sign-in-the-browser#comments</comments>
		<pubDate>Thu, 03 Jun 2010 21:12:43 +0000</pubDate>
		<dc:creator>Walt Turnes</dc:creator>
				<category><![CDATA[Technology & Tool Thursday]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=1922</guid>
		<description><![CDATA[For a while now, CAPICOM has been declared deprecated by Microsoft, as it is only implemented in 32-bit, with no plans to roll out a 64-bit version.  Microsoft&#8217;s Official Recommendation for replacing CAPICOM is to &#8220;use the .NET Framework to implement security features&#8221;.  This is a fine solution for desktop applications, server-side code, [...]]]></description>
			<content:encoded><![CDATA[<p>For a while now, CAPICOM has been declared deprecated by Microsoft, as it is only implemented in 32-bit, with no plans to roll out a 64-bit version.  Microsoft&#8217;s <a href='http://msdn.microsoft.com/en-us/library/cc778518%28v=VS.85%29.aspx'>Official Recommendation</a> for replacing CAPICOM is to &#8220;use the .NET Framework to implement security features&#8221;.  This is a fine solution for desktop applications, server-side code, web services, and a whole host of other applications.  However, there doesn&#8217;t seem to be any equivalent support for the functionality the CAPICOM ActiveX control enables within a browser.</p>
<p>The client platform Microsoft wants you to use to run client code in the Browser is <a href='http://www.silverlight.net'>Silverlight</a>, a browser add-on similar to Flash or ActiveX.  Silverlight uses many of the .NET APIs;  however, the support for the System.Security.Cryptography.X509Certificates namespace does not include support for the X509Store class (i.e., how you would enumerate the user&#8217;s digital certificates).  Nor is there any support for the System.Security.Cryptography.Pkcs namespace, which would allow PKCS7 signatures and encryption to be executed within the browser.  Both of these functions are available in the full .NET libraries, just not within Silverlight.</p>
<p>ActiveX as a technology is still alive and kicking, so it seems like the only way around this deprecation (and the corresponding corporate aversion to using CAPICOM) is to roll your own ActiveX control that replicates the functionality you need, using CryptoAPI calls.  While not particularly difficult to do, it&#8217;s far more likely to introduce bugs and security holes in your application via home grown code than by using something as tried and tested as CAPICOM.</p>
<p>Now, there&#8217;s a possibility that I&#8217;ve missed something here, and there is still a way to enumerate certificate stores and perform signatures within the browser while not using CAPICOM.  If so, please tell me what it is.</p>
]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/1922/capicom-is-dead-long-live-um-not-being-able-to-sign-in-the-browser/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>DLP &#8211; Data Loss Prevention</title>
		<link>http://securitymusings.com/article/1823/dlp-data-loss-prevention</link>
		<comments>http://securitymusings.com/article/1823/dlp-data-loss-prevention#comments</comments>
		<pubDate>Thu, 06 May 2010 11:47:13 +0000</pubDate>
		<dc:creator>Laura Raderman</dc:creator>
				<category><![CDATA[Technology & Tool Thursday]]></category>

		<guid isPermaLink="false">http://securitymusings.com/?p=1823</guid>
		<description><![CDATA[With the release of OpenDLP, more and more people are hearing about DLP.  What is it and how does it work?
Fundamentally, security is about protecting important data &#8211; whatever that data happens to be &#8211; a formula, a trade secret, social security numbers, etc.  We have all kinds of tools and techniques to [...]]]></description>
			<content:encoded><![CDATA[<p>With the release of <a href="http://code.google.com/p/opendlp/">OpenDLP</a>, more and more people are hearing about DLP.  What is it and how does it work?</p>
<p>Fundamentally, security is about protecting important data &#8211; whatever that data happens to be &#8211; a formula, a trade secret, social security numbers, etc.  We have all kinds of tools and techniques to help us encrypt and protect our data from someone outside of the company, but what about from people inside the company, people who go against company policy and use gmail, rapidshare, or other convenient tools to let them work at home or on the road?  While seemingly innocent, these users are the ones that can cause the most problems.</p>
<p><strong><span id="more-1823"></span></strong>DLP or Data Loss Prevention is not one tool, but a set of tools that allows management to watch, prevent, and react to any &#8220;sensitive&#8221; data being where it should not be, or being transmitted in a non-permissible way (i.e. unencrypted).  There are three main parts to DLP:</p>
<ul>
<li>Data in Motion &#8211; network traffic, anytime data is being transferred from one place to another.</li>
<li>Data in Use &#8211; when users are actually *using* the data, such as in memory</li>
<li>Data at Rest &#8211; when the data is being stored, such as on a hard drive or on removable media</li>
</ul>
<p>A DLP solution has to consider all of these.  Some companies may choose to only implement one type of DLP based on their threats and risks.</p>
<p>DLP solutions typically start with a definition of what is &#8220;sensitive&#8221; data.  A social security number or a credit card number is pretty easy to pick out of &#8220;random&#8221; data.  A trade secret &#8211; not so much.  This is probably the most difficult part of the process, and continual refinement is necessary to a successful solution.  Second, management must define what uses are acceptable and not acceptable for that data.  Is it OK if that data is sent via encrypted e-mail, but not uploaded to a web page?  These two pieces of information make up the policies or rules that the DLP solution must enforce.</p>
<p>Once sensitive data is defined, the solution must start looking at the data.  Generally, for data in transit, this is done with proxies &#8211; web proxies, FTP proxies, e-mail gateways, etc.  The software sniffs all traffic and flags those that are in violation of the &#8220;rules&#8221;. Data at rest DLP solutions tend to use agents that look through file servers and disks for the data and flag anywhere it finds the data that it shouldn&#8217;t be.  Data in use is generally found on end-user systems as an agent that prevents you from copying files to a USB device, etc.</p>
<p>Finally, management has to decide what to do with offenses.  Does the DLP system just flag the offense?  Does it prevent the offense?  Who does it report the offense to?  What happens to the user who offended the system?  These are all policy questions that must be addressed in parallel with implementing a DLP solution.</p>
<p>DLP is a hard problem to solve.  There are many difficult choices and issues to be addressed that are more than just &#8220;what software do we use&#8221;.  A full evaluation of your goals up front will help you select the &#8220;right&#8221; implementation for your organization.</p>
]]></content:encoded>
			<wfw:commentRss>http://securitymusings.com/article/1823/dlp-data-loss-prevention/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
