<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Scott Walters Exploring Stuff &#187; Security</title>
	<atom:link href="http://swalters.com/topics/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://swalters.com</link>
	<description>Looking at IT and adoption issues.</description>
	<lastBuildDate>Wed, 21 Apr 2010 04:02:02 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Privacy and the cloud</title>
		<link>http://swalters.com/2009/03/privacy-and-the-cloud/</link>
		<comments>http://swalters.com/2009/03/privacy-and-the-cloud/#comments</comments>
		<pubDate>Mon, 16 Mar 2009 00:44:31 +0000</pubDate>
		<dc:creator>ScottWalters</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Cloud Computing]]></category>
		<category><![CDATA[enterprise 2.0]]></category>
		<category><![CDATA[Google]]></category>

		<guid isPermaLink="false">http://swalters.com/?p=127</guid>
		<description><![CDATA[A problem with cloud computing, what happens if your private documents are shared with people without your permission. Admission from Google that this has now happened with their services.
http://www.realsoftwaredevelopment.com/google-shares-your-private-documents/
]]></description>
			<content:encoded><![CDATA[<p>A problem with cloud computing, what happens if your private documents are shared with people without your permission. Admission from Google that this has now happened with their services.</p>
<p>http://www.realsoftwaredevelopment.com/google-shares-your-private-documents/</p>
]]></content:encoded>
			<wfw:commentRss>http://swalters.com/2009/03/privacy-and-the-cloud/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>&#8216;Mashup&#8217; websites are a hacker&#8217;s dream come true</title>
		<link>http://swalters.com/2007/04/mashup-websites-are-a-hackers-dream-come-true/</link>
		<comments>http://swalters.com/2007/04/mashup-websites-are-a-hackers-dream-come-true/#comments</comments>
		<pubDate>Thu, 19 Apr 2007 22:03:19 +0000</pubDate>
		<dc:creator>ScottWalters</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[Hacker]]></category>
		<category><![CDATA[Mashup]]></category>
		<category><![CDATA[Web 2.0]]></category>

		<guid isPermaLink="false">http://www.swalters.com/2007/04/20/mashup-websites-are-a-hackers-dream-come-true/</guid>
		<description><![CDATA[In Mashup websites are a hacker&#8217;s dream come true Marks details some of the risks associated with Mashups in this article, as I read it he has a few major issues:

The information could be inaccurate or false
There has been little thought about security and privacy
The possibility that viruses could propagate through a mashup
The possibility that [...]]]></description>
			<content:encoded><![CDATA[<p>In <a href="http://www.newscientisttech.com/article/mg19025516.400" target="_blank">Mashup websites are a hacker&#8217;s dream come true</a> Marks details some of the risks associated with Mashups in this article, as I read it he has a few major issues:</p>
<ol>
<li>The information could be inaccurate or false</li>
<li>There has been little thought about security and privacy</li>
<li>The possibility that viruses could propagate through a mashup</li>
<li>The possibility that a mashup could be used to cause havoc by misrepresenting information.</li>
</ol>
<p>The scope for causing havoc is obvious. If you look at <a href="http://www.chicagocrime.org/">http://www.chicagocrime.org/</a> which shows crime statistics and locations on a Google map it would be a reasonable assumption that high crime areas have lower property values but what if the crime statistics feed was modified to show certain areas have higher crime levels in an attempt to artificially lower property values.</p>
<p>Marks does recommend that installation and authentication of servers with SSL certificates will alleviate some of these problems.</p>
<p><strong><em>Refs:</em></strong></p>
<p><em>Marks, Paul.; 12/May/2006; Mashup websites are a hackers dream come true.; New Scientist; <a href="http://www.newscientisttech.com/article/mg19025516.400">http://www.newscientisttech.com/article/mg19025516.400</a></em></p>
]]></content:encoded>
			<wfw:commentRss>http://swalters.com/2007/04/mashup-websites-are-a-hackers-dream-come-true/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OWASP Top Ten to secure your Web applications</title>
		<link>http://swalters.com/2007/03/owasp-top-ten-to-secure-your-web-applications/</link>
		<comments>http://swalters.com/2007/03/owasp-top-ten-to-secure-your-web-applications/#comments</comments>
		<pubDate>Wed, 28 Mar 2007 06:34:45 +0000</pubDate>
		<dc:creator>ScottWalters</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[Hacker]]></category>

		<guid isPermaLink="false">http://www.swalters.com/2007/04/18/owasp-top-ten-to-secure-your-web-applications/</guid>
		<description><![CDATA[Revised OWASP Top TenOWASP is the Open Web Application Security Project (OWASP) which defines standards and reports on vulnerabilities. Its latest list of the top 10 potential security vulnerabilities is an interesting read, particularly how certain vulnerabilities have dropped off the list and new vulnerabilities have arisen.
One of the obvious issues with ebusiness is that [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://builder.com.com/5100-6389_14-6159742.html?tag=sc" target="_blank">Revised OWASP Top Ten</a>OWASP is the Open Web Application Security Project (OWASP) which defines standards and reports on vulnerabilities. Its latest list of the top 10 potential security vulnerabilities is an interesting read, particularly how certain vulnerabilities have dropped off the list and new vulnerabilities have arisen.</p>
<p>One of the obvious issues with ebusiness is that its still an emerging technology and as the technology itself moves ahead so do vulnerabilities. Possibly one of the biggest unrealised issues with bricks and mortar organisations as they depend more and more on ebusiness technologies is their vulnerability to issues like these.</p>
<p><strong><em>Refs:</em></strong></p>
<p><em>Olzak, Tom.; Lock it down: Use the revised OWASP Top Ten to secure your web applications &#8212; Part 1.; <a href="http://builder.com.com/5100-6371_14-6166717.html?tag=nl.e601">http://builder.com.com/5100-6371_14-6166717.html?tag=nl.e601</a></em></p>
<p><em>Open Web Application Security Project (OWASP) website; <a href="http://www.owasp.org/">http://www.owasp.org/</a></em></p>
]]></content:encoded>
			<wfw:commentRss>http://swalters.com/2007/03/owasp-top-ten-to-secure-your-web-applications/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Military Intelligence Goes Web 2.0</title>
		<link>http://swalters.com/2007/03/military-intelligence-goes-web-20/</link>
		<comments>http://swalters.com/2007/03/military-intelligence-goes-web-20/#comments</comments>
		<pubDate>Wed, 28 Mar 2007 04:05:00 +0000</pubDate>
		<dc:creator>ScottWalters</dc:creator>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[Mashup]]></category>
		<category><![CDATA[Web 2.0]]></category>

		<guid isPermaLink="false">http://www.swalters.com/2007/02/28/military-intelligence-goes-web-20/</guid>
		<description><![CDATA[Interesting item on use of web technologies for intelligence. Most of the issues raised would be applicable to the general ebusiness area.
&#8220;The Defense Intelligence Agency is seeing mushrooming use of various Web 2.0 technologies, which are becoming increasingly critical to accomplishing missions that require analysts to share intelligence, said Lewis Shepherd, chief of the DIAs [...]]]></description>
			<content:encoded><![CDATA[<p>Interesting item on use of web technologies for intelligence. Most of the issues raised would be applicable to the general ebusiness area.</p>
<blockquote><p>&#8220;The Defense Intelligence Agency is seeing mushrooming use of various Web 2.0 technologies, which are becoming increasingly critical to accomplishing missions that require analysts to share intelligence, said Lewis Shepherd, chief of the DIAs requirements and research group at the Pentagon. &#8221; &#8211; Havenstein</p></blockquote>
<p>The use of mashups is interesting and is the equivalent of commercially sensitive material using mashup technology for a normal business.</p>
<p><strong><em>Refs:</em></strong></p>
<p><em>Havenstein, Heather.; Military Intelligence Goes Web 2.0.; Computerworld.; </em> http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=284174</p>
]]></content:encoded>
			<wfw:commentRss>http://swalters.com/2007/03/military-intelligence-goes-web-20/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bot Herders Selling Stolen Financial Data to Criminals</title>
		<link>http://swalters.com/2007/03/bot-herders-selling-stolen-financial-data-to-criminals/</link>
		<comments>http://swalters.com/2007/03/bot-herders-selling-stolen-financial-data-to-criminals/#comments</comments>
		<pubDate>Wed, 28 Mar 2007 02:37:39 +0000</pubDate>
		<dc:creator>ScottWalters</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[hackers]]></category>

		<guid isPermaLink="false">http://www.swalters.com/2007/03/20/bot-herders-selling-stolen-financial-data-to-criminals/</guid>
		<description><![CDATA[Ebusiness means part of your business is in a place where you may be subject to criminal activity that has very low costs of entry, can attack from anywhere in the world, and is very difficult to track and control.
&#8220;You can buy a U.S. identity &#8212; a credit card, bank account, Social Security, date of [...]]]></description>
			<content:encoded><![CDATA[<p>Ebusiness means part of your business is in a place where you may be subject to criminal activity that has very low costs of entry, can attack from anywhere in the world, and is very difficult to track and control.</p>
<blockquote><p>&#8220;You can buy a U.S. identity &#8212; a credit card, bank account, Social Security, date of birth &#8212; for US$20,&#8221; by Huger</p></blockquote>
<p>I liked this article about botnets and how they can be used for identity theft. The quote makes me wonder how the business clearly identifies that the person it is dealing with is indeed the person it thinks it is dealing with.</p>
<p><strong><em>Refs:</em></strong></p>
<p><em>Messmer, Ellen; 19/Mar/2007.; Bot Herders Selling Stolen Financial Data to Criminals.;  Chief Security Officer Online;   <a href="http://www2.csoonline.com/blog_view.html?CID=32583">http://www2.csoonline.com/blog_view.html?CID=32583</a></em></p>
]]></content:encoded>
			<wfw:commentRss>http://swalters.com/2007/03/bot-herders-selling-stolen-financial-data-to-criminals/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
